Privacy Policy
Membrane Inc. (“Membrane”, “we”, “us”) operates membrane.agency — a platform where recurring back-office jobs for e-commerce brands are run by software agents with a named human operator in the loop, and where every action taken on a customer's business is logged and explained. This policy describes what data we collect, how we use, store, protect, share, and delete it. It covers visitors to this website and customers of the service, including data we access in the software accounts a customer connects (such as Amazon Seller Central).
1. Who we are
Membrane Inc., 651 N Broad St, Suite 206, Middletown, DE 19709, United States. For anything in this policy, contact [email protected]. We respond to privacy requests within one month, free of charge.
2. Data we collect
- Account data — name, work email, password (stored as a salted hash), company name and store URL, and the content of forms you submit on this site.
- Connected-application data — data in the software accounts you connect so that jobs can run: for example orders, product listings, inventory, advertising, financial statements, reports, and messages. What we can access is limited to the permissions you grant in each application's own authorization flow. See section 4 for Amazon specifics.
- Usage data — how the product is used (pages, actions, session replays) and technical logs (IP address, browser, timestamps), collected inside the signed-in product for analytics and security.
- Marketing-site data — the public pages of this site (everything outside the signed-in product) carry Google Analytics and advertising tags that record pages viewed, referral source, and approximate location, and measure which ads led to a visit. These run on the public pages only. The signed-in product carries no advertising tags and no third-party visitor tracking of any kind.
- Payment data — handled by our payment processor (Stripe); we do not store card numbers.
- Communications — email and support conversations with us.
3. How we use data
- To run the jobs you request and produce their deliverables — reports, analytics, and executed changes on your connected accounts, each one logged with its reason.
- To compute analytics about your own business: sales, traffic, conversion, fees, inventory, and the root causes behind changes in them.
- To operate, secure, and improve the service; to bill; to provide support; to meet legal obligations.
Three standing commitments. Analytics are computed per customer, on that customer's own data — we do not aggregate data across customers, benchmark one customer against another, or sell data to anyone. Data from connected applications is shown only to the account's owner and the operators they authorize. And we do not use your data to develop, improve, or train generalized AI or machine-learning models.
4. Data from Amazon Selling Partner accounts
When you connect an Amazon Seller Central account, we access it through Amazon's Selling Partner API under the roles Amazon has granted our application and the authorization you give in Amazon's own consent flow. We use this access to run the jobs you have engaged us for — account monitoring and analytics, listing and catalog management, inventory and fulfillment coordination, buyer messaging, and financial recovery.
- What we access: orders, listings, inventory, financial events and settlement reports, sales and traffic reports, and buyer messages related to your account — only as needed by the jobs you run.
- How we handle it: in line with Amazon's Data Protection Policy and Acceptable Use Policy. Amazon data is encrypted in transit and at rest, access is restricted to the people and systems that need it for your account, and it is never aggregated across sellers, never used for our own trading purposes, and never sold or shared with any party other than you and the operators you authorize.
- How long we keep it: for as long as the connection is active and the data is needed to run your jobs and keep the action log you rely on. When you disconnect an account or close your workspace, we delete the connected-application data from live systems within 30 days, with encrypted backups expiring within 90 days.
5. Storage and protection
The service runs on Amazon Web Services. Data is encrypted in transit (TLS) and at rest. Access follows least privilege: staff and operators see only the accounts they work on, protected by multi-factor authentication. Systems are monitored, and we maintain an incident response plan: if a security incident affects your data, we notify you — and, where Amazon data is involved, Amazon — within the timelines our agreements and applicable law require.
6. Who we share data with
We share data only with the parties below, and never sell it:
| Recipient | Purpose |
|---|---|
| The account owner and their authorized operators | The named operator(s) assigned to your jobs see your connected accounts to do the work you engaged. |
| Amazon Web Services (hosting) | Infrastructure the service runs on. |
| Stripe (payments) | Billing and payment processing. |
| PostHog (product analytics, EU-hosted) | Usage analytics and session replay inside the signed-in product. |
| Sentry (error monitoring) | Detecting and fixing errors in the service. |
| AI model providers (e.g. Anthropic) | Running the software agents that execute jobs, under agreements that prohibit using your data to train their models. |
| Google Workspace (business email) | Our own email and support correspondence. |
| Google (Analytics, Ads) and LinkedIn (Insight Tag) | Marketing measurement on the public pages of this site — traffic analytics and ad attribution. These receive no data from inside the signed-in product. |
We may also disclose data where the law requires it, or to protect the rights, safety, or property of Membrane, our customers, or others.
7. Retention and deletion
We keep personal data only as long as needed for the purposes above: account data for the life of your account, connected-application data per section 4, and billing records for as long as tax and accounting law requires. When a retention period ends — or when you ask us to delete data we no longer need — it is removed from live systems and expires from encrypted backups on their rotation schedule.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent, and lodge a complaint with your data-protection authority. Write to [email protected] and we will act on your request within one month.
9. Cookies
The public pages of this site set analytics and advertising cookies through Google Analytics, Google Ads, and the LinkedIn Insight Tag, as described in section 2. You can refuse them with your browser's cookie controls or any tracker blocker; the pages work normally without them. The signed-in product sets no advertising cookies — it uses cookies and similar storage strictly to keep you signed in and to run the product analytics described in section 2.
10. Changes to this policy
When this policy changes, we update this page and its effective date, and — for changes that materially affect how your data is handled — notify customers by email before the change takes effect.
