Privacy Policy
Last revised: September 6, 2026 • Compliant with GDPR, CCPA, and enterprise zero-training standards
1. Introduction & Core Philosophy
At AmpliRank, we believe enterprise privacy is not an afterthought or a marketing claim — it is an architectural requirement. This Privacy Policy details how AmpliRank (“we”, “our”, or “us”) collects, processes, stores, and protects information when you use our website, AI brand intelligence platform, command center, and APIs.
Our architecture enforces strict multi-tenant isolation, cryptographic auditability, and absolute separation between your competitive intelligence data and public foundation-model training datasets.
2. Zero Model Training on Customer Data
Foundation Model Commercial Commitments
AmpliRank accesses third-party foundation models (including OpenAI GPT models, Anthropic Claude, Google Gemini, and Perplexity) exclusively via commercial enterprise API agreements. Under these agreements:
- Your prompt queries, brand definitions, and competitive sets are never used to train or fine-tune public foundation models.
- Customer inquiries submitted through our automated polling pipelines are not retained by AI model vendors beyond transient request-processing requirements.
- Prompt panels remain the confidential intellectual property of your workspace.
3. Information We Collect
We collect only the information necessary to provide and secure the Service:
A. Account & Workspace Data
When registering an account, we collect your name, business email address, and hashed authentication credentials. Passwords are protected using bcrypt cryptographic hashing with rigorous UTF-8 boundary defense. We do not store plaintext passwords.
B. Intelligence Configuration & Brand Panels
Your workspace configuration includes tracked brand names, competitor domains, buyer prompt collections, audience tags, and polling frequency preferences. All such records are bound strictly to your unique workspace identifier.
C. API & Webhook Credentials
REST API access keys are cryptographically generated and stored solely as irreversible SHA-256 hashes. Outbound webhook secrets are protected and utilized solely for HMAC-SHA256 signature generation.
4. Cookies & Tracking Technologies
AmpliRank respects user privacy by keeping tracking to an absolute minimum:
- Essential Session Cookies: We utilize secure HTTP-only cookies strictly for session authentication and CSRF defense.
- No Third-Party Advertising Trackers: We do not deploy third-party advertising cookies, retargeting pixels, or behavioral cross-site trackers on our marketing website or within our application.
- No Sale of Personal Data: We do not sell, rent, or trade your personal information or workspace intelligence to data brokers or advertisers under any circumstances.
5. Subprocessors & Infrastructure Partners
AmpliRank partners with industry-leading infrastructure providers to ensure high availability, low latency, and robust physical and digital security:
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Edge compute (Workers), TLS termination, CDN & WAF | Global Edge Network |
| Neon, Inc. | Serverless PostgreSQL database (AES-256 at rest, TLS 1.3) | United States / EU |
| Stripe, Inc. | Payment processing and subscription billing (PCI-DSS Level 1) | United States |
| Resend, Inc. | Transactional email delivery (workspace invitations, alerts) | United States |
6. Data Retention & Customer Rights (GDPR / CCPA)
Depending on your location, you hold statutory rights regarding your personal information, including:
- Right of Access & Portability: You may request a complete export of your workspace brand records and captured evidence.
- Right to Rectification: You may correct or update your profile details and workspace settings at any time.
- Right to Erasure (“Right to be Forgotten”): Upon workspace closure or verified request, we initiate cascading deletion of all workspace-scoped records from our production database within 30 days.
7. Data Security Safeguards
We implement comprehensive technical and organizational safeguards:
- End-to-end transport layer security (TLS 1.3) across all network ingress and egress.
- AES-256 encryption at rest across all database clusters.
- Cryptographic compare-and-set (CAS) integrity fingerprints for audit briefs and reports.
- Strict role-based workspace authorization and serializable transactions preventing multi-tenant data collisions.
8. Contact Us & Data Protection Officer
For questions regarding this Privacy Policy, data processing agreements (DPAs), or exercising your privacy rights, please contact our Data Protection Officer:
AmpliRank Privacy Office
Email: privacy@amplirank.com
Security: security@amplirank.com
Syntarix Corporation • AmpliRank Platform