Legal
Privacy Policy
What we collect when you turn a product link into a video, who else touches that data, and how to get it back or deleted.
Last updated: July 28, 2026
The short version
We collect the minimum needed to run the service: your email, the product links you submit, the photos we pull from those links, and the shots we render for you. We do not sell your data and we do not use your product photos to train any model of our own.
The one thing worth reading carefully is who else sees your data. Rendering happens on Volcengine Ark (ByteDance) in China, which means the product photo you select leaves the EEA. If that is a problem for your compliance posture, stop here and email us before you upload anything.
What we collect
Account data. Your email address, a hashed password (or your Google identity if you sign in with Google), your plan, and your remaining credits.
Content you submit. The marketplace URLs you paste, the product title and gallery images we retrieve from those public listing pages, the photo you select as the first frame, and your shot settings (camera move, lighting, background, ratio, duration).
Content we generate. The rendered video files, thumbnails, and any ad copy produced for image creatives.
Billing data. Waffo Pancake, our Merchant of Record, holds your card details — we never see or store a card number. We keep your subscription order ID and invoice history.
Technical data. Server logs containing IP address, user agent, timestamps and error traces, plus a rate-limit counter keyed to your account.
How we use it
- To render the shots you ask for and deliver them to your dashboard.
- To meter credits, bill you, and honour refunds.
- To authenticate you and keep your account secure.
- To debug failures. When a render fails we log the stage, the error code and the prompt so we can fix it — that log includes the product title you submitted.
- To send transactional email: receipts, password resets, and service notices.
We do not use your product photos or rendered shots as training data, and we do not put them in marketing material without asking you first, in writing, for that specific asset.
Legal basis (EEA / UK)
We rely on performance of a contract for everything needed to deliver renders and bill you; on legitimate interests for security logging, abuse prevention and product debugging; and on consent for optional marketing email, which you can withdraw at any time from the unsubscribe link.
Who else sees your data
We use the following sub-processors. Two of them are in China, which is a transfer outside the EEA without an adequacy decision — we rely on Standard Contractual Clauses and we are telling you plainly rather than burying it.
| Processor | What it receives | Region |
|---|---|---|
| Supabase | Account database, authentication, and storage of your product photos and rendered shots | EU / US (per project region) |
| Vercel | Application hosting, CDN delivery, and request logs | Global edge network |
| Volcengine Ark (ByteDance) | Seedance video rendering and Seedream image generation — receives the product photo you select | China |
| DeepSeek | Ad copy generation for image creatives — receives the product title and features, never your photos | China |
| Inngest | Background job orchestration — receives job metadata and image URLs, not your account credentials | US |
| ScraperAPI | Fetching public marketplace listing pages on your behalf | US |
| Waffo Pancake | Merchant of Record — payment processing, tax collection, invoicing, and subscription management | US / Global |
| Upstash | Rate limiting — stores a hashed request counter keyed to your account | Global |
We will update this list before adding a new processor. If you want notice by email when that happens, write to privacy@amazvid.com.
How long we keep it
- Rendered shots and source photos — kept while your account is active so you can re-download them. Delete a job from your dashboard and the files are removed from storage within 30 days.
- Account data — kept until you delete your account, then removed within 30 days.
- Invoices and tax records — retained for as long as tax law requires, typically 7 years, even after account deletion. We cannot delete these on request.
- Server logs — 90 days.
Your rights
You can request access, correction, deletion, a portable export, or restriction of processing. Email privacy@amazvid.com from your account address and we will respond within 30 days at the latest, usually much sooner.
You can delete your account yourself from Settings. Deletion removes your account data and media, but does not reverse charges already made or refund unused credits — see the refund policy for that.
If you are in the EEA or UK and think we have handled your data badly, you have the right to complain to your local supervisory authority. We would appreciate the chance to fix it first.
Security
Data is encrypted in transit (TLS) and at rest. Access to production data is limited to the people who need it to operate the service. Row-level security is enforced in the database so one account cannot read another account's jobs or media.
No system is perfect. If we discover a breach affecting your data, we will notify you and the relevant authority within 72 hours of becoming aware of it.
Children
AmazVid is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, email privacy@amazvid.com and we will remove it.
Changes to this policy
If we make a change that materially affects how your data is handled, we will email account holders at least 14 days before it takes effect. Minor clarifications are published here with an updated date. Questions go to support@amazvid.com.
Questions about this page?
A human replies to every message. If something here is unclear or you think it treats you unfairly, tell us — we would rather fix the policy than argue about it.