RemworthAll legal documents

Remworth Privacy Policy

Last updated: September 29, 2026

This Privacy Policy is publicly available at remworth.com and is reviewed and updated at least once every 12 months, and whenever a material change in our data practices requires it. It explains how NSR ONE, LLC, a New York limited liability company, doing business as Remworth ("Remworth," "we," "us," or "our"), collects, uses, stores, protects, shares, and deletes Personal Information in connection with the Remworth hosted software platform, applications, and websites at remworth.com and app.remworth.com (the "Service").

Capitalized terms not defined here have the meanings given in our Terms of Service.


1. Who We Are

Remworth is a US-based business-to-business software-as-a-service platform for Amazon FBA sellers. On your own authorization, the Service connects to your Amazon Seller Central account through Amazon's Selling Partner API ("SP-API") and provides bookkeeping and profit-and-loss analytics, inventory tracking, product-sourcing analysis, and automated repricing.

For Personal Information that we control, the data controller is:

NSR ONE, LLC (a New York limited liability company), doing business as Remworth

Privacy contact: [email protected] Legal notices: [email protected] General support: [email protected]

Remworth is not affiliated with, endorsed by, or sponsored by Amazon.


2. EU/UK Representatives and Data Protection Contact

Remworth is a US-first product. We do not currently target or offer the Service to residents of the European Economic Area ("EEA") or the United Kingdom ("UK").

If and when we offer the Service to EEA or UK residents, we will appoint an EU representative under Article 27 of the EU General Data Protection Regulation ("EU GDPR") and a UK representative under Article 27 of the UK GDPR, and we will publish their contact details in this Policy.

We have not appointed a statutory Data Protection Officer, as we are not currently required to. You may reach our data protection contact at any time at [email protected] for questions about this Policy or our processing of your Personal Information.


3. Scope and Audience

The Service is intended solely for businesses and their authorized users who are at least 18 years old. It is not directed to consumers or to children, and it is not a consumer-facing product.

This Policy is global-ready. Region-specific rights are addressed in clearly labeled subsections:

  • US state privacy rights are addressed in Section 17.
  • EEA/UK GDPR rights are addressed in Section 18.

3.1 Controller vs. seller-controlled Amazon buyer data

Remworth acts in two capacities:

  • Remworth as controller. For your account, team, billing, website, and marketing data, Remworth determines the purposes and means of processing and acts as a controller. This Policy governs that data.

  • You (the seller) as controller of your Amazon book-of-record. When you connect your Amazon account, Remworth processes your Amazon Information (defined below) on your behalf and under your instructions, acting as your processor / service provider. You are the controller of that data. Our processing of Customer Data on your behalf is governed by our Data Processing Addendum ("DPA").

If an Amazon buyer or other end consumer wishes to exercise rights over their Personal Information relating to a transaction, that request should be directed to the relevant Amazon seller, who is the controller. Remworth does not have a direct relationship with Amazon buyers and, as described in Section 13, does not collect or store Amazon buyer identity data. Where a seller instructs us, we will provide reasonable assistance to help the seller respond to such requests.


4. Categories of Personal Information We Collect

We collect the following categories of Personal Information. The categories below use recognizable California Consumer Privacy Act ("CCPA") category language.

CCPA category Examples in the Service
Identifiers Business email address, name, company name, role, team-member records, account and user identifiers, IP address, and your own ship-from contact name, postal address, and phone number used to generate Amazon inbound shipments.
Commercial information Subscription plan and status, purchase and usage history, row-pack usage counters, your supplier and operations records (purchase orders, inbound shipments including your own ship-from name, postal address, and phone number, supplier invoice files, receiving photos).
Financial information Stripe customer/subscription identifiers, plan and billing status, and (optionally, and only if you choose to record it for your own cashback bookkeeping) the last four digits of a payment card. We do not store full payment card numbers.
Internet or other electronic network activity Server log data and usage counters. On our public marketing pages only: Hotjar's analytics identifiers and the Reddit Pixel's advertising identifier (a random cookie value) - never inside the application (Section 12).
Geolocation (coarse) Coarse ship-to geography derived from your Amazon orders (city, state/region, postal code, country) and, for the sourcing scanner, an optional coarse search location (postal code or coordinates) that you provide.
Sensitive Personal Information Your Amazon SP-API credentials and your Aura API key, stored encrypted at rest; your multi-factor authentication secret (TOTP seed), stored encrypted at rest, and recovery-code hashes.
Inferences Analytics and aggregated metrics we derive from the above to provide your bookkeeping, sourcing, and inventory features to you.

Amazon Information means data we obtain from Amazon's Selling Partner API on your authorization, including order IDs, SKUs/ASINs, quantities, sale amounts, fees, settlements, refunds, reimbursements, removals, inventory ledger, and listing/catalog data. Coarse ship-to geography (city, state/region, postal code, country) is a separate, expressly-named category — the only buyer-derived data we retain, described in its own row above — and is not part of "Amazon Information." See Sections 12 and 13 for how Amazon Information is limited and how buyer data is handled.


5. Sources of Personal Information

We obtain Personal Information from:

  • Directly from you, when you create an account, configure your organization and team, upload supplier or receiving files, enter billing details, or contact support.
  • Automatically through the Service, including server log data, IP address, and usage counters. On our marketing site, Hotjar and the Reddit Pixel set the first-party cookies listed in our Cookie Policy; the application sets none. Cloudflare's cookieless Web Analytics beacon measures page views and load performance; it sets no cookie and assigns no identifier.
  • From Amazon's SP-API, on your authorization, once you connect your Amazon Seller Central account.
  • From our Subprocessors and vendors, such as billing status from our payment processor.

6. Purposes and Legal Bases for Processing

We process Personal Information only for the purposes below. For individuals protected by the EU/UK GDPR, the applicable legal basis for each purpose is identified. We do not rely on a single blanket legal basis.

Purpose GDPR legal basis
Creating and administering your account; providing the Service (bookkeeping, inventory, sourcing, repricing); processing your Amazon Information to deliver your analytics; billing and managing your subscription and row-pack usage. Performance of a contract with you.
Securing the Service; preventing, detecting, and investigating fraud and abuse; maintaining service integrity, reliability, and audit logs; product analytics and product improvement. Legitimate interests — namely our interest in operating a secure, reliable, and improving Service and protecting Customers against fraud and misuse, balanced against your rights.
Meeting tax, accounting, and other legal obligations; responding to lawful requests; retaining financial book-of-record where required. Compliance with a legal obligation, and where applicable our and your legitimate interest in maintaining accurate financial records.
Sending marketing email, where you have opted in. Consent, which you may withdraw at any time by unsubscribing or emailing [email protected].
Understanding how visitors use our marketing pages and measuring our Reddit advertising (Hotjar and the Reddit Pixel, marketing pages only). Legitimate interests in promoting and improving the Service; both tools stay off on a Global Privacy Control or Do Not Track signal, and the pixel can be switched off at any time (Section 11).

7. Data Minimization and Purpose Limitation

We collect only the Personal Information we need for the purposes described in this Policy, and we use it only for those purposes or compatible purposes permitted by law. Notably, we do not collect Amazon buyer identity data (see Section 13), and we limit Amazon Information to what is necessary to provide your own service and to meet legal and tax obligations (see Section 12).


8. Data Lifecycle

This Policy addresses the full lifecycle of Personal Information:

  • Collection — Sections 4 and 5.
  • Use — Sections 6 and 7.
  • Storage and protection — Sections 14 and 15.
  • Sharing — Sections 9 to 12.
  • Retention and deletion — Section 14.

We process Amazon Information in compliance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy ("Amazon DPP") and with applicable privacy and data-protection law.


9. Who We Share Your Information With

We share Personal Information with the service providers ("Subprocessors") and other third parties listed below, only as needed to provide, secure, operate, and market the Service. We do not sell your Personal Information. The one disclosure that certain U.S. state laws treat as "sharing" for cross-context behavioral advertising is the Reddit Pixel on our public marketing pages (row 12 and Section 10); it never involves anything from inside the application. Rows 1-11 match the subprocessor list in our DPA; Reddit acts as an independent controller and is listed separately there.

# Third party Purpose Data involved Location
1 Railway (Railway Corp.) Cloud application hosting and the PostgreSQL database All application data United States
2 Cloudflare, Inc. DNS, CDN, DDoS protection, Cloudflare R2 object storage for encrypted database backups, supplier invoice files and receiving photos, and the cookieless Cloudflare Web Analytics beacon that measures page views and load performance on both the marketing site and the application All data at rest in backups and uploaded files; page request and performance data. The beacon sets no cookie, assigns no identifier, and has no access to your financial or Amazon data United States
3 Stripe, Inc. Payment processing and subscription/billing management (PCI-DSS Level 1) Customer name, email, company, and billing metadata; full card numbers are handled by Stripe and are NOT stored by Remworth United States
4 Microsoft Corporation (Microsoft 365 / Microsoft Graph) Transactional email delivery (password reset, sign-up, team invitations) Recipient email address and message content United States
5 Keepa GmbH Amazon product catalog, price, and rank reference data Product identifiers (ASINs) only; no Personal Data Germany / European Union
6 OpenAI, L.L.C. AI-assisted product-identity matching and packaging-photo identification Supplier/product titles and product-packaging photos you upload during receiving; no buyer or end-consumer Personal Data United States
7 DataForSEO LLC Product search data (Google Shopping / Amazon) for the sourcing scanner Search terms and an optional coarse search location (postal code or coordinates) United States / European Union
8 Aura (goaura.com) Automated repricing, using your own Aura API key SKU, cost, and minimum/maximum price United States
9 Shipping carriers — UPS, FedEx, USPS, DHL, and OnTrac Inbound-shipment tracking Tracking numbers for your own inbound shipments United States
10 Google LLC Google Fonts (web font delivery to the application only; our marketing site uses self-hosted fonts) IP address and browser/user-agent data sent when a font file is requested United States
11 Hotjar Ltd (part of the Contentsquare group) Behaviour analytics on public marketing pages only - aggregate usage, heatmaps, and session recordings of those pages; never runs on the authenticated application Marketing-page visitor usage: interactions, device and browser details, approximate IP-derived location. No financial or Amazon data Malta / European Union
12 Reddit, Inc. - an independent controller, not a subprocessor Advertising measurement on our public marketing pages only, through the Reddit Pixel: tells Reddit when a visitor reaches remworth.com, views the pricing page, or clicks a trial button, so Reddit can report which of our ads brought visitors and deliver our ads to similar audiences; never runs on the authenticated application Marketing-page visits: the page address, a random browser identifier Reddit sets in a first-party cookie (90 days), a click identifier when you arrive from a Reddit ad, IP address, device and browser details. No name, email, financial, or Amazon data United States

We may also disclose Personal Information to comply with law or valid legal process, to enforce our agreements, to protect the rights, safety, and property of Remworth, our Customers, or others, or in connection with a merger, acquisition, financing, or sale of assets (in which case we will require the recipient to honor this Policy).

Reddit, Inc. (row 12) acts as an independent controller for the data the Reddit Pixel sends it, under Reddit's own Privacy Policy (https://www.reddit.com/policies/privacy-policy) and advertising terms; we have no access to Reddit's user data. If we ever engage another third party that acts as an independent or joint controller rather than a subprocessor, we will name it here and update this Policy before that processing begins.


10. "Sale," "Share," and Targeted Advertising Disclosure

We do not sell your Personal Information. One activity, on our public marketing pages only, meets some U.S. state laws' definition of "sharing" for cross-context behavioral advertising, and it is described here in full.

Certain US state privacy laws define a "sale" or "share" broadly, to include disclosures made for cross-context behavioral (targeted) advertising even without payment. Under those definitions, the Reddit Pixel on remworth.com "shares" marketing-page visit data (Section 9, row 12) with Reddit, which uses it to measure our advertising and to deliver our ads to similar audiences on Reddit. You can opt out of that disclosure at any time (Section 11), and we honor the Global Privacy Control signal automatically (Section 20). No other sale, sharing, or targeted-advertising activity exists on any Remworth surface; nothing from inside the application, and none of your Amazon Information, is ever disclosed this way.

As an unconditional boundary, no measurement, analytics, or advertising technology of any kind runs on app.remworth.com or on any page displaying your financial data or Amazon Information - today or in future - other than the cookieless Cloudflare beacon described in Section 9, which assigns no identifier. Anything we ever add is confined to our unauthenticated marketing site (see Section 12). We do not knowingly "sell" or "share" the Personal Information of individuals we know to be under 16.


11. Your Right to Opt Out of Sharing and Targeted Advertising

You can opt out of the Reddit Pixel disclosure described in Section 10 in any of these ways, none of which requires an account:

  • visit https://remworth.com/privacy-choices/ and choose Opt out of ad measurement - the choice is stored in that browser and the pixel is not loaded on your later visits;
  • turn on Global Privacy Control in your browser or a browser extension - we honor it automatically (Section 20);
  • turn on your browser's Do Not Track setting, which we treat the same way on the marketing pages;
  • email [email protected] (Sections 17 and 19) - because the pixel runs in your browser, we will confirm your request and point you to the browser-side switch above.

Opting out stops the disclosure for the browser you opt out in. You will still see advertising on Reddit, including ours, but your visits to our site will no longer inform it. We do not sell Personal Information, we do not use it for targeted advertising ourselves, and no other sharing activity exists on any Remworth surface.

If we ever add another such activity, we will update this Policy and put the required opt-out mechanisms in place before it begins. You can raise any privacy request at any time by emailing [email protected] (see Sections 17 and 19).


12. Amazon Information — Purpose Limitation and Firewall

We apply a strict purpose limitation to your Amazon Information. Amazon Information is used only to provide you your own Service and to meet legal, tax, and accounting requirements. Specifically, Amazon Information is:

  • Never sold, licensed, or shared for any third party's own purposes;
  • Never used to market to, target, or re-target Amazon buyers or any end consumers;
  • Never fed to advertising, analytics, or AI tools for their own purposes, and never used to train third-party models;
  • Never aggregated across sellers for sale or for any cross-seller commercial product.

No advertising or analytics tag runs on the application. Behaviour analytics (Hotjar) and advertising measurement (the Reddit Pixel) run only on our unauthenticated marketing site at remworth.com and are never present on app.remworth.com, on any authenticated page, or on any page that displays your financial data or Amazon Information. Cloudflare's cookieless beacon records page views and load performance on both surfaces, assigns no identifier, and has no access to the data displayed on the page. No tool of any kind measures behaviour inside a signed-in session. This firewall is a core commitment of the Service and reflects our obligations under the Amazon DPP.


13. Buyer Personal Information

We do not collect or store Amazon buyer names, street addresses, email addresses, phone numbers, or gift messages. The only buyer-derived data we retain is coarse ship-to geography — city, state/region, postal code, and country — which is used solely for your own sales analytics.

If we ever inadvertently receive buyer Personal Information beyond this coarse geography, we will delete or anonymize it within 30 days of order delivery, consistent with the Amazon DPP.


14. Data Retention

We retain Personal Information only for as long as necessary for the purposes for which it was collected, according to the following per-category periods and criteria. We do not apply a blanket "as long as necessary" period.

Data category Retention
Account data (identity, team records) Kept for the life of the account and as needed to meet legal, tax, and accounting obligations.
Financial book-of-record (Amazon Information and your financial records) Retained while your account is active and for as long as needed for your accounting, tax, and legal obligations — a permitted retention basis under the Amazon DPP. You can export it and request deletion.
Non-personal Amazon Information (order IDs, SKUs, revenue, fees, and similar financial figures) Retained while your account is active and as needed to provide the Service. Consistent with the Amazon Data Protection Policy, we do not retain such non-personal Amazon Information beyond 18 months from its retrieval, except where a legal, tax, or accounting obligation — including your own bookkeeping and record-keeping, which is a core purpose of the Service — requires longer retention. On account closure or Amazon disconnection, Amazon Information is deleted within 30 days, subject to those legal/tax carve-outs; backup copies age out within 30 days.
Buyer Personal Information Not collected or stored. Any buyer Personal Information inadvertently received is deleted or anonymized within 30 days of order delivery.
Database backups 30 days.
Stored SP-API credentials and Aura API key Deleted promptly on Amazon disconnect, team off-boarding, or account closure.
Associated Amazon Information on disconnect/off-boarding/closure Deleted within 30 days, subject to legal/tax retention carve-outs.
Security and support access logs Retained at least 12 months.
Free-trial records (a one-way hash of the Amazon seller ID connected to a subscribing account, and of the card identifier Stripe provides for each free trial) Kept after account closure, solely to enforce one free trial per business. We store only the hash, never the seller ID or any card number.

Self-serve deletion. An account owner can delete their organization at any time from Settings → Delete account (you must remove your team members first). Doing so immediately cancels your subscription, disconnects Amazon, and wipes your stored SP-API credentials and Aura API key, and it schedules permanent deletion of all associated Personal Information and Amazon Information after a 30-day recoverable grace period, during which the owner can restore the account using a link we email at the time of deletion. An individual team member can remove their own account at any time from Settings (self off-board). You may also request deletion by emailing [email protected]. On deletion, stored credentials are wiped immediately; associated Personal Information and Amazon Information are permanently deleted after the 30-day grace period; backup copies age out within about 30 days; all subject to the legal, tax, and accounting retention carve-outs above. This aligns with our practice of deleting stored credentials promptly and associated Amazon Information within 30 days on Amazon disconnection, team off-boarding, or account closure.


15. Security

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information, including:

  • In transit: TLS 1.2+ / HTTPS for all traffic and third-party calls.
  • At rest: Your SP-API credentials, Aura API key, and multi-factor authentication secret are encrypted with Fernet (AES-128-CBC + HMAC-SHA256) using rotating keys held only in environment configuration — never in the database or source code. Passwords are hashed with bcrypt; multi-factor recovery codes are stored as hashes. The database is hosted on Railway, and nightly database backups are stored in an access-isolated Cloudflare R2 bucket with 30-day retention.
  • Access and isolation: Mandatory multi-factor authentication (TOTP) for all accounts. Authenticated sessions use signed JSON Web Tokens that expire within 24 hours and are revoked on password change, enforced on every request; an explicit logout additionally revokes the presented token server-side. We enforce strict per-organization data isolation and least-privilege team roles. Internal administrative and support access is limited to designated administrator accounts; support access to your data is through a dedicated read-only, audit-logged interface; administrative operations that modify your data are audit-logged; and no administrative or support surface exposes decrypted secrets.

No method of transmission or storage is completely secure, but we work to protect your information and to continually improve our safeguards.


16. International Data Transfers

The Service is hosted in the United States, and Personal Information is processed there and in the countries where our Subprocessors operate (see Section 9).

Where we transfer Personal Information of individuals in the EEA or UK to the United States or other countries, we rely on appropriate safeguards — the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs. We do not rely on the EU-US Data Privacy Framework.

You may request a copy of the relevant safeguards by emailing [email protected].


17. Your Rights — United States

Subject to your state's law and applicable exceptions, you may have the following rights regarding your Personal Information:

  • Right to know / access the categories and specific pieces of Personal Information we process about you.
  • Right to delete Personal Information we hold about you.
  • Right to correct inaccurate Personal Information.
  • Right to data portability — to obtain a copy in a portable format.
  • Right to opt out of the sale of Personal Information.
  • Right to opt out of the sharing of Personal Information for cross-context behavioral advertising.
  • Right to opt out of targeted advertising.
  • Right to opt out of profiling that produces legal or similarly significant effects (see Section 25).
  • Right to limit the use and disclosure of sensitive Personal Information (see Section 22).
  • Right to appeal a decision on your request (see Section 19).
  • Right to non-discrimination for exercising your rights (see Section 23).

18. Your Rights — EEA and UK

If you are in the EEA or UK, you may have the following rights under the EU/UK GDPR, subject to applicable conditions and exceptions:

  • Access to your Personal Data;
  • Rectification of inaccurate or incomplete data;
  • Erasure ("right to be forgotten");
  • Restriction of processing;
  • Data portability;
  • Objection to processing based on legitimate interests or to direct marketing;
  • Withdrawal of consent at any time, where processing is based on consent (without affecting prior processing).

You also have the right to lodge a complaint with a supervisory authority, such as the UK Information Commissioner's Office (ICO) or your EU lead data protection authority. We would, however, appreciate the chance to address your concerns first at [email protected].


19. How to Exercise Your Rights

You can submit a privacy request in any of the following ways:

  • Email [email protected];
  • Delete your data yourself in the Service: an account owner can delete the entire organization from Settings → Delete account (after removing team members first), and an individual team member can remove their own account from Settings at any time. Account deletion cancels your subscription, disconnects Amazon, wipes stored credentials immediately, and schedules permanent deletion after a 30-day recoverable grace period, during which the owner can restore the account using a link we email at the time of deletion (see Section 14).

Verification. To protect your information, we will take reasonable steps to verify your identity before acting on a request, typically by confirming control of the account email and matching request details to our records. We may decline requests we cannot reasonably verify.

Authorized agents. You may use an authorized agent to submit a request on your behalf where permitted by law; we may require proof of authorization and verification of your identity.

Timelines. We will acknowledge your request within approximately 10 business days. For US state-law requests, we will respond within 45 days and, where reasonably necessary, may extend our response by one additional 45-day period, notifying you of the extension and the reason. For EEA/UK GDPR requests, we will respond without undue delay and within one month of receipt, extendable by up to two further months for complex or numerous requests, with notice of any extension and the reasons for it. If we deny a request, you may appeal by replying to our decision or emailing [email protected]; we will respond to appeals within 60 days.

You may also contact your state Attorney General if you have concerns about our handling of your request.


20. Global Privacy Control and Opt-Out Preference Signals

We honor Global Privacy Control (GPC) and the browser Do Not Track setting automatically. When your browser sends the signal to remworth.com, our marketing pages do not load the Reddit Pixel or Hotjar, and we treat the signal as a valid request to opt out of sharing and targeted advertising for that browser, with no further action from you. The application has no such processing for a signal to act on.


21. Your Privacy Choices and Requests About Sensitive Personal Information

Our Your Privacy Choices page is at https://remworth.com/privacy-choices/, linked from the footer of every marketing page; it covers the one sharing activity described in Section 10. You may also ask us to limit the use of your sensitive Personal Information (Section 22), or exercise any other right described in Sections 17 and 18, by emailing [email protected]. We respond on the timelines in Section 19.


22. Sensitive Personal Information

Your encrypted Amazon SP-API credentials and Aura API key are treated as sensitive Personal Information. We use them only to provide the Service to you and never sell or share them. Where your state grants the right, you may request that we limit our use of sensitive Personal Information to what is necessary to provide the Service, or (in states that require opt-in consent) decline our use of sensitive Personal Information for any secondary purpose. We do not use sensitive Personal Information for advertising, profiling, or any purpose beyond providing and securing the Service.


23. Non-Discrimination and No Financial-Incentive Program

We will not discriminate or retaliate against you for exercising any privacy right — for example, by denying the Service, charging a different price, or providing a different level or quality of service, except as permitted by law.

We do not operate any financial-incentive, loyalty, or data-for-discount program, and we do not offer any price or service difference in exchange for the retention or sale of Personal Information. Accordingly, we provide no Notice of Financial Incentive.


24. Minors

The Service is a business product intended for users 18 years of age or older. It is not directed to children, and we do not knowingly collect or process the Personal Information of children under 16. If we learn that we have inadvertently collected such information, we will delete it.


25. Automated Decision-Making

Remworth's AI-assisted product-identity matching and automated-repricing features are Customer-controlled tools that produce suggestions and analytical support. They do not make solely-automated decisions that produce legal or similarly significant effects on any data subject. Accordingly, the automated decision-making and profiling opt-out obligations under GDPR Article 22 and equivalent US state "automated decision-making technology" (ADMT) provisions are not triggered.

If we ever change these features so that they make solely-automated decisions with legal or similarly significant effects, we will update this Policy and provide any required notices and opt-out or opt-in mechanisms beforehand.


26. Cookies and Analytics

The application uses strictly-necessary first-party browser storage only: a local-storage authentication token (not a cookie), plus small interface-preference keys. No analytics, session-recording, or advertising tool runs inside the application. On our public marketing pages we use Hotjar for behaviour analytics - aggregate usage, heatmaps, and session recordings of those pages, with keystroke input suppressed - and the Reddit Pixel for advertising measurement (Sections 9 and 10); neither is ever present on the application, both stay off when your browser sends Global Privacy Control or Do Not Track, and the pixel can be switched off at https://remworth.com/privacy-choices/. Cloudflare's cookieless beacon measures page views and load performance on both surfaces, sets no cookie and assigns no identifier. Google Fonts is requested by the application only. Opt-out routes and full details are in our Cookie Policy.


27. Marketing Email

Where permitted, we may send you marketing email about the Service. You can unsubscribe at any time using the link in the message or by emailing [email protected], and we will honor your request within 10 business days. Transactional and service messages (for example, password reset, sign-up, team invitations, billing, and security notices) are necessary to operate the Service and are not subject to marketing opt-out.


28. Payment and Billing Data

Payments and subscriptions are processed by Stripe, Inc., a PCI-DSS Level 1 service provider. We receive and store billing metadata such as your Stripe customer/subscription identifiers, plan, and billing status. We do not store full payment card numbers; card data is handled directly by Stripe. If you choose to record the last four digits of a card for your own cashback bookkeeping, that information is used only for your records and is never used to charge you.


29. Whether Providing Data Is Required

Some Personal Information is necessary to use the Service:

  • Account email and password are required to create and secure your account; without them, you cannot use the Service.
  • Payment/billing information is required to subscribe and to purchase row-pack usage; without it, we cannot provide paid features.
  • Amazon connection (SP-API authorization) is required to use the analytics, bookkeeping, inventory, and sourcing features that rely on Amazon Information; without it, those features will not function.

You may choose not to provide optional information (such as receiving photos or the last four digits of a card), but related features may be unavailable.


30. Security-Incident Handling

We maintain an incident-response process to detect, investigate, and respond to security incidents. If a security incident affecting your Personal Information occurs, we will notify affected Customers, individuals, and regulators as, and within the timeframes, required by applicable law and our contractual commitments, including the Amazon DPP.


31. Changes to This Policy and How to Contact Us

We review this Policy at least every 12 months and may update it from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice by email or within the Service. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.

For any questions, requests, or concerns about this Policy or your Personal Information:

NSR ONE, LLC (doing business as Remworth) Privacy: [email protected] Legal: [email protected] Support: [email protected]

PrivacyTermsDPACookies© 2026 NSR ONE, LLC — Remworth