Amboras

Legal

Privacy Policy

Last updated: July 2026

We at Amboras take the protection of personal data seriously. This Privacy Policy explains how Amboras, Inc. collects, uses, and protects personal data in connection with our AI-native commerce platform, which enables merchants to create, host, operate, and optimize online storefronts (the "Services").

1. Scope: Who This Policy Covers

This policy applies to: (a) merchants and their staff who register for or use the Services; and (b) visitors to amboras.com.

If you are a visitor to or customer of a storefront operated by one of our merchants (that is, a shop running on Amboras, rather than amboras.com itself), this policy does not apply to you. The merchant is the controller of your personal data; Amboras processes your data only on the merchant's behalf and instructions, as described in Section 6. Please consult that merchant's privacy policy for their disclosures, legal bases, and opt-out options.

2. Controller

The controller responsible for the data processing described in this policy is:

Amboras, Inc.
1111B S Governors Ave, STE 84587
Dover, DE 19904, United States
Email: contact@amboras.com

3. Data We Collect

3.1 Account Information

When you create an account we collect your name, email address, password (stored hashed), company name, and billing information.

3.2 Store and Business Data

We collect and process the content and configuration of the storefronts you build and operate on Amboras, including storefront design, copy, images, product catalogs, pricing, offers, orders, and store settings. Where you connect a third-party platform (such as Shopify) for migration or integration, we collect the store content and encrypted API credentials needed to provide that integration.

3.3 Usage Data

We automatically collect information about how you use the platform, including IP address, browser and device information, pages visited, and features used.

3.4 AI Interaction Data

We collect your prompts, instructions, and interactions with our AI systems, and telemetry about the actions our AI systems take on your store (including variants generated and test outcomes), in order to provide and improve the Services.

3.5 Your Customers' Data (Processed on Your Behalf)

In operating your storefront, we process personal data relating to your storefront visitors and customers, including analytics events (sessions, funnels, conversions), order and fulfilment details, contact details, and email engagement data. We process this data as your processor, as described in Section 6, not for our own purposes.

4. How We Use Your Data

We use personal data to: provide, operate, and maintain the Services, including hosting your storefront and operating AI and autonomous optimization features; process payments and manage your subscription; communicate with you about your account and the Services; provide customer support; detect and prevent fraud, abuse, and security incidents; comply with legal obligations; and, with your consent where required, send marketing communications.

Service improvement and AI. We use usage data, AI interaction data, and performance telemetry to evaluate, secure, and improve the Services, including our optimization systems. Where we do so, we use data that has been aggregated or de-identified wherever practicable. We do not use your storefront content, your customers' personal data, or your prompts to train generative AI foundation models, and our AI sub-processors are contractually prohibited from using data we submit via their APIs to train their models.

5. Legal Bases for Processing

Where the EU or UK GDPR or similar laws apply, we process personal data on the following bases: performance of a contract (providing the Services); legitimate interests (improving and securing the Services, preventing fraud, communicating with business users); legal obligation (tax, accounting, and regulatory compliance); and consent (marketing communications, non-essential cookies, and where otherwise required).

6. Merchant Customer Data: Our Role as Processor

For personal data relating to your storefront visitors and customers, you are the controller and Amboras is your processor. We process that data only to provide the Services to you and on your documented instructions, under our Data Processing Addendum ("DPA"), which forms part of our agreement with you.

As the controller, you are responsible for: providing legally required privacy notices to your customers; establishing a lawful basis for the processing; obtaining any required consents (including cookie and tracking consents); and honoring data-subject rights and opt-out signals. If your customer contacts us directly with a privacy request, we will direct them to you and provide reasonable assistance as required by the DPA.

7. Data Sharing and Sub-Processors

We share personal data with the following categories of service providers, each bound by a written data-processing agreement and permitted to process personal data only on our documented instructions:

Hosting and infrastructure: Fly.io (application hosting), Vercel (frontend hosting), Supabase (managed PostgreSQL, authentication), GitHub (source-code storage for per-store deployments). Product analytics: PostHog (see Section 10). Payments: Stripe, for Amboras subscription billing only; we never receive or store your full card number. Transactional and storefront email: Resend. AI processing: Anthropic (Claude models) and OpenAI (speech-to-text); these providers do not use data submitted via their APIs to train their models. Customer support: Intercom, Slack. Error monitoring: Sentry, Datadog.

Storefront payments. Payments made by your customers on your storefront are processed by payment providers (such as Stripe or PayPal) under accounts belonging to you and agreements between you and those providers. Amboras does not receive or store your customers' full card details.

Connected platforms. Where you connect a third-party platform such as Shopify, data exchanged with that platform is also subject to its privacy policy.

Legal requirements and corporate events. We may disclose personal data where required by law, to protect our rights, safety, and property or those of others, or in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

We may add or replace sub-processors as the Services evolve. If a change materially expands how your personal data is processed, we will update this policy per Section 15, and, where the DPA applies, follow its sub-processor change procedure.

8. Data Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, hashed credential storage, access controls and authentication, security assessments, employee training, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal-data breach occurs, we will notify affected merchants and, where legally required, regulators and individuals without undue delay.

9. Data Retention

We retain account data for the duration of your subscription plus 90 days after cancellation to allow reactivation, after which it may be permanently deleted. Usage data, analytics, and logs are retained for up to 2 years for service improvement and security. Data we process as your processor is retained in accordance with the DPA and deleted or returned on termination, subject to legal retention obligations. You may request deletion at any time at contact@amboras.com; verified requests are actioned within 30 days, subject to legal retention obligations.

10. Cookies, Analytics, and Tracking

10.1 Cookies on amboras.com

We use a small number of first-party cookies and equivalent technologies strictly to operate the service: authentication cookies (strictly necessary), consent-state cookies (remember your banner choices), and product-analytics cookies (PostHog, set only after consent where consent is required). You can clear cookies via your browser settings; rejecting non-essential cookies does not prevent the product from working.

10.2 Product Analytics (PostHog)

We use PostHog to understand product usage and debug issues, collecting page views, feature clicks, and session identifiers, configured with IP anonymization and a short retention window. We do not use PostHog for cross-site behavioral advertising. PostHog acts as our processor under a written DPA.

10.3 Advertising Pixels on amboras.com

As of the last-updated date above, we do not run the Meta Pixel, Meta Conversions API, Google Ads pixel, Google Analytics, or any equivalent advertising tracker on amboras.com, and we do not build audiences or run retargeting against our own visitors. If we add any such tool, we will update this policy and re-collect consent where required.

10.4 First-Party Storefront Analytics

The Services include first-party analytics that measure sessions, funnels, conversions, and revenue on merchant storefronts. This data belongs to the merchant, is processed by Amboras as the merchant's processor, and is not used by Amboras for advertising or shared across merchants except in aggregated, de-identified form to operate and improve the Services.

10.5 Merchant-Configured Tracking on Storefronts (Meta Pixel, Meta CAPI, Google Ads)

Merchants may connect their own advertising pixels to their storefront. When a merchant enables this: the pixel identifier and server-side access token belong to the merchant's advertising account, not Amboras; we store these credentials encrypted at rest (server-side tokens are never sent to the browser) and use them only to forward storefront events on the merchant's instruction; the merchant is the controller (or co-controller with Meta or Google) for data collected through these tools, and Amboras acts solely as a processor; and data forwarded is governed by Meta's Business Tools Terms, Meta's Custom Audiences Terms, and Google Ads Data Processing Terms respectively. Merchants are contractually required under our Terms of Service to maintain their own privacy policy, obtain valid consent where required, and honor opt-out signals such as Global Privacy Control.

10.6 Do Not Track and GPC

Amboras.com honors the Global Privacy Control signal as a valid opt-out of "sale" or "sharing" under applicable US state law. Because the DNT header has no common industry meaning, we do not respond to it separately.

11. Your Privacy Rights (EEA, UK, and Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights in respect of personal data for which Amboras is the controller: access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests (including direct marketing); and withdrawal of consent at any time, without affecting prior processing. To exercise these rights, contact contact@amboras.com; we will respond within one month. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the ICO). Where Amboras acts as a processor of your data (Section 6), please direct your request to the relevant merchant.

12. US State Privacy Rights

12.1 California (CCPA/CPRA)

California residents have the right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, non-discrimination, and data portability. We do not sell personal information and have not done so in the preceding 12 months, and we do not share personal information for cross-context behavioral advertising. Categories collected in the past 12 months: identifiers (name, email, credentials, IP address); commercial information (subscription and payment history); internet activity (product usage); professional information (company details); and inferences (usage patterns). Sensitive personal information is limited to account credentials (hashed), used solely for authentication and security. Business purposes: providing and improving the Services, payments, support, security and fraud prevention, legal compliance, and consented marketing. Retention is as described in Section 9. California residents may use an authorized agent with written authorization and identity verification. To exercise rights, email contact@amboras.com with "California Privacy Rights" in the subject line.

12.2 Other States

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws have similar rights to access, delete, correct, and opt out of certain processing. Contact us to exercise them.

12.3 Verification

We verify identity before processing rights requests and may request additional information to do so. We respond to verified requests within 45 days or as otherwise required by law.

13. International Data Transfers

Amboras is based in, and primarily stores and processes data in, the United States. Where we transfer personal data originating in the EEA, UK, or Switzerland to the United States or other third countries, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA, and Swiss equivalents) incorporated into our DPA, together with supplementary measures where appropriate.

14. Children's Privacy

The Services are business tools and are not directed at children. We do not knowingly collect personal information from children under 16 (or the higher age applicable in your jurisdiction). If you believe we have collected such information, contact us at contact@amboras.com and we will delete it.

15. Changes to This Policy

We may update this policy to reflect changes in our practices, the Services, or legal requirements. We will notify you of material changes by email at least 30 days before they take effect and by posting notice on our website, and will update the "Last Updated" date at the top of this page.

16. Contact

Amboras, Inc., 1111B S Governors Ave, STE 84587, Dover, DE 19904, United States. Email: contact@amboras.com. California residents: include "California Privacy Rights" in the subject line.