Privacy Policy
Last updated: 10 August 2026
This Privacy Policy explains how Liberty UpGrowth LLC ("Liberty UpGrowth", "we", "us") collects, uses, stores and protects information. It covers two clearly separate categories of data:
- Website data — information you send us through this website, our forms and our contact channels.
- Client Amazon account data — information we access on behalf of our clients through the Amazon Selling Partner API (SP-API) and the Amazon Ads API, in order to provide the services they have contracted from us.
1. Data controller
The controller of your personal data is Liberty UpGrowth LLC, with its principal address at 99 Wall Street #1068, New York, New York 10005 (USA). Business registration number 30-1420915.
Our registered agent is Registered Agents Inc, registered office at 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110 (USA), for the receipt of notices and service of process.
For any question about this policy or about how we handle data, contact us at contacto@libertyupgrowth.es.
When we act on behalf of a client to manage their Amazon advertising or their Amazon integrations, the client is the controller of that data and Liberty UpGrowth acts as a processor, following the client's documented instructions and the applicable Amazon policies.
2. Website data
2.1 What we collect
- Identification and contact data: name, phone number and email address.
- Business data: the brand or company name and the answers you give in our forms, such as whether you already sell on Amazon and how many SKUs you manage.
- Technical data: IP address, browser and device information and usage metrics, where applicable.
2.2 Why we use it
- Responding to your enquiry: to contact you, prepare an account audit and discuss whether our services fit your case.
- Providing and improving our services: internal analysis to improve our processes and the quality of our communications.
- Security and fraud prevention: preventing automated submissions, abuse and unauthorised use.
- Measurement and analytics: understanding how the site is used and how it performs, subject to your cookie preferences.
2.3 Legal basis
- Consent: when you voluntarily submit a form or accept optional cookies.
- Legitimate interest: to keep the site secure, prevent fraud and improve our services.
- Pre-contractual measures: to handle requests related to our services before a possible engagement.
3. Amazon Selling Partner API (SP-API) data
3.1 What we access
When a client authorises our application from their own Seller Central account, we access only the operational catalogue and order data needed to run the integration they have contracted:
- Catalogue references: SKUs, ASINs and listing attributes such as titles, bullets, images and variations
- Inventory levels and replenishment thresholds
- Prices, margins and pricing rules
- Order statuses and shipment tracking numbers, in order to return them to Amazon
- Feed submission results and processing reports
3.2 What we do not access
We do not request, access, store or process Personally Identifiable Information (PII) belonging to shoppers. This includes names, shipping addresses, phone numbers, email addresses and any other buyer-identifying data. We do not request the SP-API roles that grant access to restricted data, and we do not download or retain restricted reports.
If, in the future, a specific service required access to restricted data, it would only happen after a separate written agreement with the client, with a new authorisation granted by them, and under the additional requirements of the Amazon Data Protection Policy. This policy would be updated beforehand.
3.3 What we do with it
SP-API data is used exclusively to operate the client's own integration: synchronising stock between their systems and Amazon, applying their pricing rules, uploading and updating listings, pulling orders into their system, returning tracking numbers, and producing their operational reporting. We do not use it for any other purpose.
4. Amazon Ads API data
4.1 What we access
When a client grants us access to their advertising account, we access the campaign data required to manage and report on their advertising:
- Campaign, ad group, keyword and product targeting configuration
- Bids, budgets and placement settings
- Performance metrics: impressions, clicks, spend, attributed sales, ACOS, TACOS, ROAS and impression share
- Aggregated search term reports
4.2 What we do with it
Advertising data is used exclusively to plan, launch, optimise and report on the campaigns of the client the data belongs to. Specifically, we use it to adjust bids, budgets and targeting according to the rules agreed with that client, to identify search terms worth scaling or negating, and to produce their performance reports.
4.3 Strict separation between advertisers
We never use one advertiser's data to benefit another, and we do not aggregate, benchmark or cross-reference data across clients. Each client's advertising data is kept logically separated, is accessible only to the team members assigned to that account, and is never shared with third parties, resold or used to build products or datasets offered to others.
5. Authorisation and revocation
Access to both APIs is granted by the client through Amazon's official authorisation flows, from their own account, and always with the minimum set of permissions the contracted work requires. We never ask for or store Seller Central or Amazon Ads usernames or passwords.
The client may revoke that authorisation at any time, directly from their Amazon account and without going through us. Once revoked, or once the engagement ends, we stop accessing their data and delete or return it as described in section 7.
6. Security
We apply technical and organisational measures appropriate to the data we handle, including:
- Encryption of all data in transit using TLS 1.2 or above
- Encryption of stored data at rest
- Access control on a least-privilege basis, restricted to the personnel who need it for their work
- Multi-factor authentication on the systems that hold API credentials
- Credentials stored in a dedicated secrets manager, never in source code or spreadsheets
- Logging of access to and processing of client data
- Regular review of permissions and revocation of access when a team member no longer needs it
No system is completely secure, and we cannot guarantee absolute security. We do, however, maintain an incident response procedure, and in the event of a security incident affecting Amazon Information we will notify Amazon and the affected clients without undue delay, in line with the Amazon Data Protection Policy and applicable law.
7. Data retention
- Website data: kept for as long as needed to handle your enquiry and the commercial relationship, and afterwards for the periods required by legal obligations or to defend against claims.
- SP-API and Ads API data: kept only for as long as the engagement lasts and only to the extent needed to provide the service, including the historical series required for the client's own reporting.
- On termination: when the engagement ends or the authorisation is revoked, we delete the client's data from our systems, or return it to them first if they ask us to, except where a legal obligation requires us to retain it.
8. Third parties and subprocessors
We do not sell data and we do not share it with third parties for commercial purposes. To operate our services we rely on infrastructure and tooling providers acting as processors — hosting, databases, and analytics — which access data only to provide the contracted service and under our instructions.
Clients may request the current list of subprocessors involved in their service at the contact address in section 1.
9. International transfers
Depending on the providers involved, some data may be processed or hosted in countries other than your own, including transfers between the European Economic Area and the United States. In those cases we put in place appropriate safeguards to ensure an adequate level of protection under applicable law, such as the European Commission's Standard Contractual Clauses.
10. Your rights
Depending on where you are, you may request access to your personal data, as well as its rectification, erasure, restriction or portability, and you may object to certain processing. To exercise these rights, write to contacto@libertyupgrowth.es and we will respond within the periods set by law.
If you are in the European Economic Area, you also have the right to lodge a complaint with your national data protection authority.
Where we act as a processor for a client, requests relating to that client's data should be addressed to the client, and we will assist them in responding.
11. Cookies
We may use cookies and similar technologies for the operation of the site, analytics and measurement. You can find more information and manage your preferences from the cookie notice shown on the website.
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or for legal reasons. We will publish the updated version on this page and change the "Last updated" date above.
13. Contact
For any question about this Privacy Policy or about how we process data, contact us at contacto@libertyupgrowth.es.