Privacy Policy
Last Updated: 2026-05-03
1. About This Policy
This Privacy Policy describes how Databrill UK Limited, a company registered in England and Wales (“Databrill”, “we”, “us”, “our”), collects, uses, and shares personal information in connection with the Databrill Core software-as-a-service product and associated software, libraries, command-line tools, web interfaces, and documentation (together, the “Service”).
Databrill Core is a business-to-business product. The Service is sold to organizations (“Customers”) that use it to extract data from Amazon Selling Partner and Advertising APIs into a database the Customer controls. This Policy applies to:
- Personal information about Customer’s authorized users of the Service (people who log in and use the product).
- Personal information about visitors to the Databrill Core marketing pages and signed-up account holders.
- Personal information that the Service processes on behalf of Customers when extracting data from Amazon’s APIs (for example, buyer names and addresses included in order or settlement records).
Different parts of this Policy apply to each of those groups. Section 2 explains who is responsible for which data.
If you are an end consumer of one of Databrill’s Customers (for example, a buyer whose order data appears in the Customer’s Amazon account), Databrill processes that information on the Customer’s behalf. Please contact the Customer first; we will support the Customer in responding to you.
2. Data Controller and Data Processor
Databrill is the data controller for:
- Account and contact information you provide when signing up, including name, work email address, organization name, role, and authentication credentials.
- Billing information (handled by our payment processor; we do not store full card numbers).
- Product telemetry, including log records, usage events, and diagnostic information about your interaction with the Service.
- Communications you send us (support requests, sales inquiries).
Databrill is a data processor, acting on the Customer’s instructions, for:
- Amazon Information that the Service extracts on the Customer’s behalf, including any personal information of buyers or third parties contained in Amazon orders, shipments, returns, settlements, advertising data, or other Amazon API responses.
- Customer Data stored in a Customer Database that Databrill manages (the Managed Database option). Where the Customer uses the Bring-Your-Own-Database option, Databrill writes data into the Customer’s database but does not host or operate that database.
The processor terms governing Databrill’s handling of Amazon Information and Customer Data are set out in the Data Processing Addendum (DPA), available on request and incorporated by reference into the agreement between Databrill and the Customer.
3. Information We Collect
3.1 Information You Provide
When you create an account or use the Service, we collect:
- Identifiers and contact details: name, work email, organization name, job title where provided.
- Authentication credentials and OAuth tokens for Amazon Selling Partner and Advertising accounts that you authorize.
- Database connection details if you use the Bring-Your-Own-Database option, including hostnames, ports, database names, and the credentials needed to write to your database.
- Billing details, including billing address and the limited card details our payment processor needs to process payment.
- Communications you send us, including support tickets, emails, and feedback.
3.2 Information Collected Automatically
When you use the Service we automatically collect:
- Log data: IP address, browser type and version, operating system, device type, referrer, and timestamps of requests.
- Usage data: pages and features accessed, sync jobs run, query patterns, and similar product-telemetry events that help us operate and improve the Service.
- Cookies and similar technologies: see Section 9.
3.3 Amazon Information
When the Service runs on the Customer’s behalf, it extracts data from Amazon’s Selling Partner API and Advertising API. That data may include personal information of third parties (for example, buyer names and shipping addresses on order records, or recipient details on return records). Databrill processes this information solely on the Customer’s instructions and only as necessary to provide the Service.
3.4 Information from Third Parties
We may receive information about you from third-party sources where you have authorized them to share it with us, including identity providers used for single sign-on, our payment processor, and Amazon when you authorize the Service to connect to your Amazon accounts.
4. How We Use Information
We use personal information for the following purposes, in each case relying on the legal bases set out in Section 5.
To provide the Service:
- Authenticate users and operate accounts.
- Connect to Amazon’s APIs on the Customer’s behalf and write the resulting data into a Customer Database.
- Track sync status, surface errors, and operate alerts and notifications.
- Process payments and manage subscriptions.
To operate, secure, and improve the Service:
- Monitor performance, diagnose issues, and prevent abuse.
- Detect and respond to security incidents.
- Analyze usage to improve features, performance, and reliability.
To communicate with you:
- Respond to support requests and account inquiries.
- Send service-related notices (for example, security advisories, outages, terms changes, billing notices).
- Send product update emails to account holders. You can opt out of non-essential product emails at any time using the unsubscribe link.
To comply with law:
- Meet legal, regulatory, accounting, and tax obligations.
- Respond to lawful requests from public authorities.
We do not sell personal information. We do not use Amazon Information for advertising or marketing. We do not use Amazon Information or Customer Data to train any machine-learning model without the Customer’s prior written consent.
5. Legal Bases for Processing (UK GDPR / EU GDPR)
We rely on the following legal bases:
- Performance of a contract: to provide the Service to a Customer under our Terms of Service.
- Legitimate interests: to operate, secure, and improve the Service; to communicate with account holders; and to enforce our Terms. We balance our legitimate interests against your rights and freedoms before relying on this basis.
- Consent: where required, for example for non-essential marketing emails or non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation: where processing is required to comply with applicable law.
Where Databrill processes personal information as a processor on the Customer’s behalf, the Customer is responsible for identifying the legal basis for that processing.
6. Sharing Personal Information
We share personal information with:
- Subprocessors that help us operate the Service, including cloud infrastructure providers, managed-database providers, email and notification providers, payment processors, and customer-support tooling providers. Subprocessors are bound by data-protection obligations no less protective than those in our DPA. A current list of subprocessors is available on request and is updated from time to time.
- Amazon, when the Service exchanges OAuth tokens, requests reports, or otherwise interacts with Amazon’s APIs on the Customer’s behalf.
- Professional advisers, including lawyers, accountants, and auditors, where we need their advice and they are bound by professional confidentiality.
- Authorities or other third parties, where required by law, court order, or other valid legal process, or where we need to protect our rights, property, or safety, or those of others.
- Acquirers, in the event of a merger, acquisition, financing, sale of assets, or similar transaction. We will notify Customers before personal information is transferred and becomes subject to a different privacy policy.
We do not sell personal information.
7. International Transfers
Databrill is established in the United Kingdom. Some of our subprocessors are established in the European Economic Area, the United States, and other jurisdictions. Where we transfer personal information out of the United Kingdom or the European Economic Area, we use appropriate transfer mechanisms, including the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), and the EU Standard Contractual Clauses, as applicable. Copies are available on request.
8. Retention
We keep personal information only for as long as necessary for the purposes described in this Policy.
- Account, contact, and billing information: for the duration of the account and for a period afterwards as required by law (for example, accounting and tax record-keeping requirements in the United Kingdom).
- Log and usage data: typically retained for a rolling period appropriate to security and operational needs (for example, 90 days), with longer retention only where required for incident investigation or legal obligations.
- Amazon Information held on the Customer’s behalf: retained only for as long as necessary to provide the Service, and deleted or returned in accordance with the DPA and Amazon’s Data Protection Policy on termination of the Customer’s subscription or on the Customer’s written request.
- Communications you send us: retained for a reasonable period to support our records of customer interactions and to address future inquiries.
9. Cookies and Similar Technologies
The Databrill Core product uses a small number of first-party cookies and similar technologies (including a small amount of browser localStorage) that are strictly necessary to operate the Service, including authentication, session management, security, and remembering your interface preferences (such as your dark / light mode choice and whether you are currently signed in, so the navigation bar can render the correct button without a flash on page load). These do not require consent under UK and EU law because they are strictly necessary.
Where we use any non-essential cookies (for example, optional analytics), we will request consent first and offer a way to manage your preferences. The marketing pages may use a small number of analytics cookies, governed by our Cookie Policy.
You can configure your browser to block or delete cookies. If you block strictly necessary cookies, parts of the Service may not work.
10. Your Rights
Depending on where you are located, you may have the following rights in respect of personal information that Databrill holds about you as controller:
- Access: request a copy of the personal information we hold.
- Rectification: ask us to correct information that is inaccurate or incomplete.
- Erasure: ask us to delete information, subject to limited exceptions.
- Restriction: ask us to restrict processing in certain circumstances.
- Objection: object to processing based on our legitimate interests.
- Portability: receive certain information in a structured, commonly-used, machine-readable format.
- Withdraw consent: where processing is based on consent.
- Complain to a supervisory authority: in the United Kingdom, the Information Commissioner’s Office (ico.org.uk).
To exercise these rights, contact us at the address in Section 13. We will respond within the time required by applicable law (typically one month under UK GDPR).
If you are an end consumer (for example, a buyer whose data appears in a Customer’s Amazon account), please contact the Customer first; they are the controller of that data and we will support them in responding to you.
11. Security
We implement administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Safeguards include encryption of credentials at rest, encryption in transit (HTTPS / TLS) between the Service and Amazon’s APIs and between the Service and Customer endpoints, role-based access controls, and audit logging of access to sensitive systems. Specific security commitments are described in the Documentation and the DPA.
No system is perfectly secure. If we become aware of a personal data breach affecting personal information we hold, we will notify affected Customers and, where required, supervisory authorities, in accordance with applicable law and the DPA.
12. Children
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children under 16 (or any higher minimum age in your jurisdiction). If you believe we have collected personal information from a child, please contact us so we can delete it.
13. Contact
For privacy questions or to exercise your rights, contact us at:
- Email: privacy@databrill.com
- Postal: Databrill UK Limited
If we are unable to resolve your concern, you have the right to complain to a data-protection supervisory authority. In the United Kingdom, that is the Information Commissioner’s Office (ico.org.uk).
14. Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date at the top of this page reflects the most recent revision. Where the changes are material, we will give you reasonable advance notice (for example, by email to account holders or by a notice in the product) before they take effect.