Skip to content
Data Governance & Privacy

Privacy Policy

Last revised: September 6, 2026 • Compliant with GDPR, CCPA, and enterprise zero-training standards

1. Introduction & Core Philosophy

At AmpliRank, we believe enterprise privacy is not an afterthought or a marketing claim — it is an architectural requirement. This Privacy Policy details how AmpliRank (“we”, “our”, or “us”) collects, processes, stores, and protects information when you use our website, AI brand intelligence platform, command center, and APIs.

Our architecture enforces strict multi-tenant isolation, cryptographic auditability, and absolute separation between your competitive intelligence data and public foundation-model training datasets.

2. Zero Model Training on Customer Data

Foundation Model Commercial Commitments

AmpliRank accesses third-party foundation models (including OpenAI GPT models, Anthropic Claude, Google Gemini, and Perplexity) exclusively via commercial enterprise API agreements. Under these agreements:

  • Your prompt queries, brand definitions, and competitive sets are never used to train or fine-tune public foundation models.
  • Customer inquiries submitted through our automated polling pipelines are not retained by AI model vendors beyond transient request-processing requirements.
  • Prompt panels remain the confidential intellectual property of your workspace.

3. Information We Collect

We collect only the information necessary to provide and secure the Service:

A. Account & Workspace Data

When registering an account, we collect your name, business email address, and hashed authentication credentials. Passwords are protected using bcrypt cryptographic hashing with rigorous UTF-8 boundary defense. We do not store plaintext passwords.

B. Intelligence Configuration & Brand Panels

Your workspace configuration includes tracked brand names, competitor domains, buyer prompt collections, audience tags, and polling frequency preferences. All such records are bound strictly to your unique workspace identifier.

C. API & Webhook Credentials

REST API access keys are cryptographically generated and stored solely as irreversible SHA-256 hashes. Outbound webhook secrets are protected and utilized solely for HMAC-SHA256 signature generation.

4. Cookies & Tracking Technologies

AmpliRank respects user privacy by keeping tracking to an absolute minimum:

  • Essential Session Cookies: We utilize secure HTTP-only cookies strictly for session authentication and CSRF defense.
  • No Third-Party Advertising Trackers: We do not deploy third-party advertising cookies, retargeting pixels, or behavioral cross-site trackers on our marketing website or within our application.
  • No Sale of Personal Data: We do not sell, rent, or trade your personal information or workspace intelligence to data brokers or advertisers under any circumstances.

5. Subprocessors & Infrastructure Partners

AmpliRank partners with industry-leading infrastructure providers to ensure high availability, low latency, and robust physical and digital security:

SubprocessorPurposeLocation
Cloudflare, Inc.Edge compute (Workers), TLS termination, CDN & WAFGlobal Edge Network
Neon, Inc.Serverless PostgreSQL database (AES-256 at rest, TLS 1.3)United States / EU
Stripe, Inc.Payment processing and subscription billing (PCI-DSS Level 1)United States
Resend, Inc.Transactional email delivery (workspace invitations, alerts)United States

6. Data Retention & Customer Rights (GDPR / CCPA)

Depending on your location, you hold statutory rights regarding your personal information, including:

  • Right of Access & Portability: You may request a complete export of your workspace brand records and captured evidence.
  • Right to Rectification: You may correct or update your profile details and workspace settings at any time.
  • Right to Erasure (“Right to be Forgotten”): Upon workspace closure or verified request, we initiate cascading deletion of all workspace-scoped records from our production database within 30 days.

7. Data Security Safeguards

We implement comprehensive technical and organizational safeguards:

  • End-to-end transport layer security (TLS 1.3) across all network ingress and egress.
  • AES-256 encryption at rest across all database clusters.
  • Cryptographic compare-and-set (CAS) integrity fingerprints for audit briefs and reports.
  • Strict role-based workspace authorization and serializable transactions preventing multi-tenant data collisions.

8. Contact Us & Data Protection Officer

For questions regarding this Privacy Policy, data processing agreements (DPAs), or exercising your privacy rights, please contact our Data Protection Officer:

AmpliRank Privacy Office

Email: privacy@amplirank.com

Security: security@amplirank.com

Syntarix Corporation • AmpliRank Platform