Privacy Policy

Last updated: May 2026

1. Who We Are

The Inner Circle FBA ("we", "us", "our") is a private Amazon FBA mentoring and leads community operated by Lew Hull, based in the United Kingdom. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For data protection queries, contact us at: support@theinnercirclefba.com

2. Data We Collect

We collect and process the following types of personal data:

  • Identity & Contact Data: Your name and email address, collected when you purchase a membership or contact us.
  • Payment Data: Payment card details are processed by Stripe and are not stored by us. We retain transaction records (amount, date, subscription status) for accounting purposes.
  • Discord Data: Your Discord username, user ID, and account information collected when you authorise Discord access as part of onboarding.
  • Usage Data: Information about how you interact with our website, including IP address, browser type, pages visited, and referral source (collected via cookies and analytics tools).
  • Communications: Any messages you send to us via email or Discord.

3. How We Use Your Data

We use your personal data to:

  • Process your membership and manage your subscription (legal basis: contract performance)
  • Grant and manage your access to our Discord community (legal basis: contract performance)
  • Send you service-related communications, such as billing updates and membership changes (legal basis: contract performance)
  • Respond to your enquiries and support requests (legal basis: legitimate interests)
  • Improve our website and services through analytics (legal basis: legitimate interests)
  • Comply with our legal and regulatory obligations (legal basis: legal obligation)

4. Third Parties We Share Data With

We share your data only where necessary with trusted third parties:

We do not sell your personal data to any third parties.

5. Cookies & Affiliate Tracking

Our website uses essential cookies required for the site to function (including a session cookie for the member portal and a 30-day referral-attribution cookie when you arrive via a member's share link). We may also use analytics cookies (such as those set by Vercel Analytics) to understand how visitors use our site.

Affiliate cookies set by third parties: When you click an outbound link to a partner we have an affiliate relationship with — including Amazon Associates UK, software providers (SellerAmp, Sellerboard, Profit Protector Pro, Sagemailer), business-banking partners (Tide, American Express), and cashback platforms (TopCashback, Quidco, Honey, Pouch) — that partner may set a cookie on your browser to attribute any subsequent purchase or sign-up back to The Inner Circle FBA. We do not set or have access to these cookies; they are governed by each partner's own privacy policy. See our affiliate disclosure for full details.

You can control cookies through your browser settings. Note that disabling cookies may affect site functionality.

6. Data Retention

We retain your personal data for as long as your membership is active and for a period of 7 years thereafter for accounting and legal compliance purposes. Discord access is revoked upon cancellation. You may request earlier deletion of your data (see Your Rights below).

7. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — request we limit how we use your data
  • Right to portability — request your data in a portable format
  • Right to object — object to processing based on legitimate interests

To exercise any of these rights, contact us at support@theinnercirclefba.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. All payment processing is handled by Stripe and is never stored on our own servers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via Discord or email. Continued use of our Service after changes constitutes acceptance of the updated policy.

10. Amazon Selling Partner API (SP-API) Access

Members on paid tiers may choose to connect their Amazon Seller Central account to The Inner Circle FBA via Amazon's Login With Amazon (LWA) authorisation flow. This connection is entirely optional. The terms below apply only if you grant this consent.

What we access: we read only the data needed to compute the dashboard, repricer recommendations, and accounting exports we offer:

  • Finance and Accounting role — financial events (shipments, refunds, fees, reimbursements, ad spend, storage fees) for the seller's own account.
  • Inventory and Order Tracking role — current FBA inventory summaries (fulfillable, inbound, reserved quantities) for the seller's own ASINs.
  • Pricing role — competitive pricing and Buy Box data for the seller's own ASINs, used to generate repricing recommendations.
  • Product Listing role — product titles and SKU↔ASIN mappings to label dashboard rows with recognisable product names.

What we do NOT access: we never request or read buyer personally-identifiable information (names, email addresses, shipping addresses), payment instrument data, order-personalisation messages, or any data outside the seller's own account.

How it's stored: the long-lived refresh token issued by Amazon is encrypted at rest using AES-256-GCM with a key held separately as an environment variable. Synced records (financial events, inventory snapshots, cost-of-goods you enter) are stored in our managed PostgreSQL database (Supabase, EU region) which itself encrypts every table at rest as part of its baseline. Data is used only to render your own dashboard — never aggregated, anonymised, sold, or used in model training.

How long we keep it: for the duration of your active membership. If you disconnect your Amazon account or cancel your membership, we delete your synced Amazon data within 30 days. Earlier deletion is available on request via the email address below.

How to disconnect: click "Disconnect" on the Amazon connection card inside your dashboard. This wipes our copy of your refresh token immediately and stops any further sync runs against your account.

Sub-processors for SP-API data: Supabase (PostgreSQL hosting, EU region) and Vercel (serverless compute, EU region). No other third party processes Amazon Information.

For our internal incident response procedure governing this data, see Data Handling.

11. Chrome Extension (Inner Circle Companion)

Members may install the Inner Circle Companion Chrome extension (current version 2.1). It surfaces profit, ROI, fees, sales velocity, Buy Box ownership, risk flags, seller-account eligibility and your own stock on Amazon UK product pages, adds a compact quick view to Amazon UK search pages, assists with ungating on Seller Central, opens a sourcing sidebar on eleven UK retailer sites, and can check your restock watches from your own browser. The terms below apply only if you install and connect the extension. This section is kept word-for-word consistent with the extension's Chrome Web Store data disclosures.

What the extension reads on Amazon UK product pages: the ASIN from the URL and, from the page, the displayed price, product title, brand byline, main image URL, the category text in the product details, sibling variation ASINs, the "bought in past month" badge, the offer/seller count and the maximum of the quantity selector. It does not read reviews, your Amazon account details, your basket, or anything unrelated to the product on screen.

On Amazon UK search, browse, best-seller and brand-store pages: the ASIN and title of each result card, to place IP-claim warnings and a quick view of rank and sales.

What is sent to our servers automatically when you are connected: every product page you open is logged to your own dashboard history (ASIN, product title, the prices in the calculator inputs and the monthly-sales figure shown). The brand byline is sent for the IP-claim watchlist check; the bought-badge figure and sibling ASINs are sent with the sales-data request; the quantity-selector maximum and seller count are sent for sales-velocity modelling. On search pages, up to 50 ASINs per request are sent for the quick view. On Seller Central Manage Inventory pages, up to 50 ASINs are sent to fetch your Repricer rules. On the eleven retailer sites, the product title (first eight words) is sent on product pages to find the matching Amazon listing, and anything you type into the sidebar's search box is sent as a search. All of this goes to theinnercirclefba.com over HTTPS and nowhere else.

Sent only when you click: Save COG (the cost you typed), Watch, Save to Deals (title, brand, image URL and every figure on screen), Log Win, the ungating outcome you choose to log, and Apply this price in the Repricer overlay.

What we store: per-ASIN viewing history (so we can show "you viewed this 5× before"), buy prices you save (as ex-VAT, so they survive VAT-mode changes), deals and wins you log, and verdict snapshots for the personal accuracy feedback loop. All of this is stored in our managed PostgreSQL database (Supabase, EU region) under your Discord ID. It is used only to render your own dashboard — never aggregated, anonymised, sold, or used to train models.

Authentication: the extension uses Chrome's chrome.identity.launchWebAuthFlow API to complete a one-time handshake with our dashboard. Your Discord login happens in our normal web flow — the extension never sees your Discord password or session cookie. The result is an opaque bearer token (prefix eict_) stored in chrome.storage.local on your machine. Server-side we keep only sha256(token); we cannot recover the original token if it leaks from your machine.

Seller Central helpers: the extension activates on sellercentral.amazon.co.uk and sellercentral-europe.amazon.com. Ungating helper: on listing-restriction application pages it reads the ASIN and inspects the form's structure (file inputs, required checkboxes, required fields, submit button). Only when you click our "Submit application" button, and only on forms with no invoice upload and no empty required field, does it tick the required checkboxes and press Amazon's submit button. It never fills in text fields, never uploads anything, and never submits on a timer. When it sees an invoice-required form it sends the ASIN plus a fixed label to our community ungating database automatically so the database can self-correct. Repricer overlay: on Manage Inventory pages it reads ASIN-shaped strings on the page, fetches your Repricer rule and recommended price for each, and shows them in a panel; clicking Apply this price changes that listing's price through your own Selling Partner API connection. No seller credentials, sales reports, order data or customer data are read.

Retailer sourcing sidebar: on argos.co.uk, bmstores.co.uk, homebargains.co.uk, therange.co.uk, diy.com, boots.com, superdrug.com, tesco.com, sainsburys.co.uk, groceries.morrisons.com and ebay.co.uk, the extension reads the page heading and price to decide whether you are on a product page. On product pages it opens a sidebar and, when connected, sends the product title to find the matching Amazon listing; on other pages it only waits for the right-click "IC Companion Search" menu item. Result thumbnails are loaded from Amazon's image CDN without cookies or referrer.

Connect via Extension (retailer accounts): on the dashboard's Reverse Search page you can click "Connect via Extension" for Costco UK, eany.io, Toolstation, Screwfix, Booker or Weldricks. Only on that explicit click, the extension reads every cookie your browser holds for that retailer's domain — including its login session cookie — and sends them to our server, where they are encrypted at rest and used solely to fetch your trade prices for Reverse Search. Nothing is read from those domains at any other time. You can disconnect a retailer from the same page.

Restock watches: if you set restock watches in the dashboard, the extension's background worker fetches each watched product page from your own browser (with your logged-in session on that site, so regional stock is seen) every five minutes, and once whenever the worker starts, and reports in-stock / out-of-stock and price back to your dashboard. Only URLs you chose to watch are fetched, and only on sites the extension already has permission for.

Permissions explained:

  • storage — the bearer token, a five-minute cache of your name and tier for the popup, your batch-ungating queue, and a five-minute cache of the public IP-claim watchlist. Page-scoped storage also holds your saved cost per ASIN, the panel's collapsed state, a ten-minute cache of the last sales data, a thirty-minute ASIN memory on Seller Central and a per-session "sidebar hidden" flag.
  • identity — required by chrome.identity.launchWebAuthFlow for the one-time handshake.
  • contextMenus — the right-click "IC Companion Search" item on the eleven retailer sites.
  • cookies — used only by Connect via Extension, on your explicit click, for the six retailer domains listed above.
  • alarms — the five-minute restock-watch timer.
  • Host permissions — amazon.co.uk (product and search overlays), the two Seller Central hosts (ungating helper and Repricer overlay), theinnercirclefba.com (our API and dashboard), the eleven retailer sites (sourcing sidebar and restock checks), and the six retailer cookie domains (Connect via Extension).

How to disconnect / uninstall: click Disconnect in the extension popup to wipe the token from your machine; the extension can then make no further requests on your behalf. To remove the extension entirely, go to chrome://extensions, find Inner Circle Companion, and click Remove. To delete the data we stored about your viewing history, saved buy prices, deals and connected retailers, email support@theinnercirclefba.com from your registered address and we will erase it within 30 days.

Data we never collect: we never read or transmit your browsing history outside the sites listed above, bookmarks, passwords, autofill data, payment methods, content from other tabs, your Amazon order history, your Amazon basket, or your buyer messages. The extension's single purpose is to help you make Amazon UK sourcing decisions on the page you are already looking at.

12. Inner Circle FBA Mobile App (iOS & Android)

This section supplements (does not replace) the rest of this policy. The mobile app is a thin native shell around theinnercirclefba.com — all login, dashboard, leads, scan-lookup and account activity follow the same data-handling rules as the website. Three mobile-specific data flows are disclosed below.

Camera access (barcode scanning):

  • No images or video are captured. The camera feed is processed live, on-device, by Google ML Kit. Frames never leave your phone.
  • What we receive: only the numeric barcode digits (8–14 digits). We send those to the Amazon Selling Partner API to look up the matching product.
  • What we don't receive: any image data, GPS location, ambient sound, or other sensor readings.
  • Permission control: Settings → Inner Circle FBA → Camera. Revoking it disables scanning; the rest of the app works fine.

Push notifications:

  • What we store: an opaque device token (a random string assigned by Google FCM / Apple APNS per app install), the platform (ios/android), and timestamps. Stored against your Discord ID.
  • What we use it for: notifying you about Buy Box price drops, competitor exits, and Amazon-joined-listing events on deals you have explicitly saved to watch. No marketing or promotional pushes.
  • What we don't do: sell or share tokens with anyone (including advertisers). Tokens are not used for analytics or attribution.
  • Permission control: the permission prompt fires only after you deliberately tap "Enable alerts" — never on launch. Revoke at any time via Settings → Inner Circle FBA → Notifications.
  • Token lifecycle: tokens get rotated by Google/Apple on reinstall. Old tokens are kept (marked revoked) for diagnostic trace, then auto-purged after 90 days.

Third-party SDKs in the mobile app:

  • Google Firebase Cloud Messaging — used only if you opt into push. No Firebase Analytics or Crashlytics.
  • Google ML Kit Barcode Scanning — runs entirely on-device. No data transmitted.
  • Apple Push Notification service — only contacted by Apple's OS after you grant push permission.

Data we never collect from the mobile app: your contacts, photo library, calendar, microphone, location, camera images, browsing history outside our domain, other apps installed on your device, biometric data, advertising identifiers (no IDFA on iOS, no AAID on Android), or device hardware fingerprints.

How to delete your mobile app data: tap "Disable alerts" in the app or revoke notification permission in your device Settings. To purge all push tokens for your account, email support@theinnercirclefba.com — processed within 7 days. Deleting your Inner Circle FBA account (see section 7) automatically purges all mobile-side data including tokens.

Children: the mobile app is not directed at children under 16. We do not knowingly collect data from anyone under 16.

13. Contact

For any privacy-related questions or to exercise your rights, contact us at:

support@theinnercirclefba.com