Privacy Policy

Last updated: September 27, 2026

1. Introduction

Rilk LLC (“Rilk,” “we,” “us,” or “our”) operates the multi-channel inventory management platform available at rilk.ai (the “Service”). This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights as a seller and data subject.

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

2. Data We Collect

2.1 Account Data

When you register for Rilk, we collect your name, email address, company name, and a password. We also store account configuration, feature settings, and subscription tier.

2.2 Marketplace Data (via OAuth)

When you connect a marketplace or sales channel, you authorize Rilk to access certain marketplace data on your behalf. This data includes:

  • Orders — order numbers, statuses, line items, quantities, marketplace fees
  • Customer PII — buyer name, shipping address, email (where provided by marketplace); used solely to generate shipping labels and maintain your order records
  • Product/Catalog data — ASINs, SKUs, titles, images, pricing, inventory quantities
  • Financial/Settlement data — settlement amounts, fee breakdowns per order
  • FBA data — inbound shipment status, FBA inventory levels, removal orders

2.3 Google API Data (Gmail, Sheets, Drive)

When you connect your Google account via OAuth, you authorize Rilk to access Gmail (for email import), Google Sheets (for scheduled data exports), and Google Drive (read-only, for listing available spreadsheets). We access only the data necessary to provide these features and do not use Google data for advertising or share it with third parties.

Limited Use disclosure. Rilk’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, for the restricted scopes Rilk requests (https://mail.google.com/ and drive.readonly):

  • We use Google user data only to provide or improve the user-facing features that the data was granted for — sending and importing your business email, and exporting your data to your own spreadsheets.
  • We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
  • We do not use Google user data for serving advertisements, and we never sell it.
  • We do not allow humans to read Google user data unless we have your affirmative consent for a specific message, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

2.4 Operational Data

We collect data you enter while using the Service: purchase orders, vendor records, warehouse bin assignments, serial number logs, shipping carrier credentials (OAuth tokens for UPS, FedEx, USPS), and shipping label history.

2.5 Security & Audit Data

We log authentication events (login attempts, successes, failures) including IP address, browser, operating system, and device type. This data is used for security monitoring and account lockout enforcement. We do not use this data for advertising or profiling.

2.6 Technical Data

We collect standard server log data: IP addresses, request paths, timestamps, and error codes. This data is used for monitoring, debugging, and security.

2.7 Public Website Data

On our public pages — listed in Section 11 — three third-party components collect data about your visit and send it directly from your browser: a Meta (Facebook) advertising pixel, Google Ads conversion tracking, and a review badge served by SourceForge (Slashdot Media). Between them they receive your IP address, browser and device information, the address (URL) of the page you are viewing, the referring URL, and Meta and Google cookie identifiers. None of them run anywhere inside the Service, so none ever see account, marketplace, Google-account, buyer, or order data. Section 11 describes what each one sends, what we never send, and how to opt out.

On our public pages we also record visit events on our own servers; Section 11.5 describes them.

3. How We Use Your Data

We use your data exclusively to provide and improve the Service:

  • Display your orders, inventory, and financials in the Rilk dashboard
  • Generate shipping labels by passing your buyer’s shipping address to carrier APIs (UPS, FedEx, USPS, Amazon Buy Shipping) — at your explicit instruction
  • Sync inventory quantities back to your connected marketplaces
  • Export data to Google Sheets on your configured schedule — at your explicit instruction
  • Provide warehouse, serial number, and picking workflow functionality
  • If you use the Amazon Settlement Analyzer, calculate and show you the adjustments, charges and credits on your most recent Amazon settlements
  • Send you transactional emails (account setup, password reset, shipping confirmations)
  • Detect and respond to security threats (account lockout, anomaly detection)
  • Comply with legal obligations

We do not sell the data described in Sections 2.1 through 2.6. We do not use your account data, your marketplace data, or your buyers’ personal data for advertising, and we do not use it to build advertising profiles. We do not share marketplace data with any third party except as described in Section 4.

Amazon Settlement Analyzer. For the Analyzer we fetch only your most recent Amazon settlement reports — no orders, no buyer information, no listings and no inventory — and we use them only to show you the adjustments on those settlements in your account. We never use the settlement data or your Analyzer results for advertising or retargeting, we never send them to Meta, Google Ads or any other advertising service, we do not include them in emails, and we do not combine them with other sellers’ data. How long we keep them is in Section 7.

This section covers the data we hold for your account. Public-website visit data is separate and is described in Section 11.

4. Data Sharing and Sub-Processors

We share data only to operate the Service. Below are the third parties (“sub-processors”) that may process your data:

Sub-ProcessorPurposeData Shared
Amazon Web Services (AWS)Cloud hosting, database, logsAll data (encrypted at rest)
Google (Sheets/Drive API)Scheduled data exportsProduct/order data you choose to export — at your instruction only
UPSShipping label generationBuyer shipping address, package dimensions — at your instruction only
FedExShipping label generationBuyer shipping address, package dimensions — at your instruction only
USPS / Stamps.comShipping label generationBuyer shipping address, package dimensions — at your instruction only
DHLShipping label generationBuyer shipping address, package dimensions — at your instruction only
StripePayment processingBilling name, email, payment method
BrevoTransactional and campaign emailName, email address
GroqAI-assisted features: support chat, transcription and review of recorded calls, catalog organisation, and payment-email parsingText you submit to AI-assisted features, audio of recorded calls where call recording is enabled, product catalog data you ask us to organise, and sample payment emails you ask us to parse — at your instruction only
LabelaryShipping label renderingBuyer name and address — at your instruction only

We do not share buyer PII with any party other than shipping carriers, and only at the point you explicitly print a label.

Meta, Google Ads, and Slashdot Media (SourceForge) are not in this table: the advertising pixel, the conversion tracking tag, and the review badge on our public pages receive no Customer Personal Data and are disclosed in Section 11.

5. Data Storage and Security

  • All data is stored in Aurora PostgreSQL on AWS (us-east-2), encrypted at rest using AES-256
  • All data in transit is encrypted via TLS 1.2 or higher
  • The database has no public internet endpoint — accessible only from the application backend inside a private VPC
  • Marketplace OAuth tokens and Google OAuth tokens are stored encrypted with AES-256-GCM
  • Passwords are stored as bcrypt hashes — plaintext passwords are never stored or logged
  • Access to production infrastructure requires multi-factor authentication
  • Application and security logs are retained in AWS CloudWatch for at least 12 months
  • When Rilk staff open your account data through our internal admin tools, we record who accessed it, when, which account, and which categories of personal data were shown — the field names, never the values
  • These staff-access records are kept for 400 days

6. Security Incident Notification

If we confirm a security breach affecting your data, we will notify you without undue delay — within 72 hours of confirmation — by email to your account’s registered contact address. The notification will describe what happened, the categories of data involved, what we have done to contain and remediate the incident, and any steps we recommend you take. Where applicable law requires notice to regulators or other parties, we will provide it on the timeline the law requires.

7. Data Retention

We retain your data while your account is active and after it is closed, unless the law or a marketplace’s terms require us to delete it. You may ask us to delete other data at any time; we will respond within 30 days.

Audit logs and security logs (login history, account lockout events) are retained for at least 12 months.

Buyer personal data received from Amazon is deleted no later than 30 days after the related order is delivered, and within 30 days of a verified deletion request or of your closing your account.

Settlement data fetched for the Amazon Settlement Analyzer, and the results calculated from it, are deleted no later than 30 days after you connect your Amazon account to the Analyzer, and at the same time we delete the Amazon authorization we hold, which disconnects your Amazon account. This does not apply if you continue to the full Service within those 30 days; your Amazon data is then kept as described in the rest of this section.

Public-website visit data collected by the components in Sections 11.1 to 11.3 is held by Meta, by Google, and by Slashdot Media (SourceForge) under their own retention practices; Rilk does not store it, beyond the server logs in Section 2.6. The sign-up measurement events we record ourselves are kept as described in Section 11.5.

8. Your Rights

You have the right to:

  • Access — request a copy of all data we hold about you and your account
  • Correction — request that we correct inaccurate data
  • Deletion — request deletion of your account and personal data, subject to the retention described in section 7
  • Portability — request an export of your data in a machine-readable format
  • Revoke OAuth Access — disconnect any marketplace or Google account at any time from your Rilk settings; Rilk will immediately stop accessing that service’s API

To exercise any of these rights, contact us at support@rilk.ai. We will respond within 30 days.

9. Amazon SP-API Data Usage

Rilk is an Amazon-authorized application. We access Amazon Selling Partner API data only as authorized by you through the OAuth flow. Amazon SP-API data is used solely to provide inventory management, order fulfillment, and shipping services, and the Amazon Profit Calculator and Settlement Analyzer, to you (the authorized seller). We comply with Amazon’s Developer Data Protection Policy (DPP):

  • SP-API data is not used for advertising or marketing
  • Buyer PII is displayed only to the authorized seller and their employees
  • SP-API data is not sold or shared with non-essential third parties
  • You may revoke Rilk’s SP-API access at any time through your Amazon Seller Central account under Apps & Services

10. Google API Data Usage

Rilk’s use of Google API data adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data (Gmail, Sheets, Drive) is used only to provide the features you explicitly configured
  • We do not use Google data for advertising, market research, or email campaigns
  • We do not sell or share Google data with third parties
  • You may revoke Google access at any time from your Email Config settings or from your Google Account permissions page

“Google data” in this section means Google user data obtained through Google APIs — Gmail, Sheets and Drive. The Google Ads conversion tracking described in Section 11.2 is a separate Google product that runs only on our public marketing pages; it never receives Google user data, and nothing in this section is changed by it.

10.1 How we protect Google user data

Google user data — message content and metadata retrieved from Gmail, spreadsheet contents written to or read from Google Sheets, and the file names and ids listed from Google Drive — is treated as sensitive data and protected by the following mechanisms:

  • Encryption in transit — all traffic between Rilk and Google APIs, and between your browser and Rilk, uses TLS 1.2 or higher. Gmail access uses IMAP and SMTP over TLS with OAuth (XOAUTH2), so when you connect with Google sign-in no password is transmitted or stored. If you instead choose to connect a mailbox with an app password, that password is stored encrypted with AES-256-GCM and used only to authenticate to your mail server.
  • Encryption at rest — Google data stored by Rilk resides in Aurora PostgreSQL (AWS us-east-2) encrypted with AES-256. Google OAuth refresh and access tokens are additionally encrypted at the application layer with AES-256-GCM using a key held in AWS Secrets Manager, so a database copy alone cannot be used to reach your Google account.
  • Network isolation — the database and the servers that hold Google data have no public internet endpoint; they are reachable only from the Rilk backend inside a private VPC, and administrative access requires multi-factor authentication over a bastion host.
  • Access control — Google data is scoped to the account that connected the mailbox and is returned only to signed-in users of that account, enforced on every query. Rilk personnel do not read Google user data except with your affirmative consent for a specific message, where necessary for security (such as investigating abuse), where required by law, or in aggregated and anonymized form for internal operations.
  • Least privilege — Rilk requests only the permissions its features require, uses them only for the features you configured, and never for advertising, model training, resale, or market research.
  • Retention and deletion — removing a mailbox from Email Config revokes Rilk’s token with Google and deletes the stored access and refresh tokens, ending all access to that mailbox immediately. Message content already imported into your Rilk account is kept with the rest of your account data as described in section 7, and is deleted on request. Rilk does not copy or retain the contents of your spreadsheets or a list of your Drive files; file names are read to populate the export picker at the moment you open it.
  • Monitoring and assessment — access to production systems is logged and retained, infrastructure and container images are scanned continuously for vulnerabilities, and Rilk undergoes independent security assessment, including the annual Cloud Application Security Assessment (CASA) required for Google restricted scopes.

11. Cookies and Website Advertising

Rilk uses session cookies to keep you logged in and remember your preferences. Inside the Service — every page you reach after signing in — we use no advertising cookies, no tracking pixels, and no third-party analytics that profile you across other websites.

11.1 The Meta pixel on our public pages

On our public pages only — the rilk.ai home page and the rest of our marketing site (product, feature, integration, use-case, pricing, comparison, and resource and blog pages), this Privacy Policy, our Terms of Service, our coming-soon page, our booking page, our free tools (the Amazon profit calculator and the Amazon settlement analyzer), and our sign-up page — we run the Meta (Facebook) pixel. We use it to measure how our advertising performs and to show ads to people who have already visited our site. The pixel sends Meta your IP address, browser and device information, the page URL you are viewing, the referring URL, and Meta cookie identifiers.

The pixel does not run:

  • anywhere inside the Service — no page you reach after signing in loads it
  • on any page you reach after you finish signing up, including the page that confirms your email address

Our sign-up page. The pixel does run on our sign-up page and the sign-up window on the Amazon profit calculator, so that we can measure our advertising and avoid showing ads to people who have already signed up. It sends Meta the same visit data listed above and, when a sign-up completes, a “registration completed” signal with no details attached. It does not send your email address, your name, your company name, your phone number, or anything else you type into the form: we have turned off Meta’s automatic advanced matching, which would otherwise collect form fields, and we attach no personal information to any event we send.

What we never send to Meta. No marketplace or Amazon Selling Partner API data, no Google-account data from your connected mailbox or Sheets, no buyer or customer personal data, no order, product, inventory, or financial data, and no account or login data. Meta receives only the public-page visit data described above, which is why Meta is not listed as a sub-processor in Section 4.

Your choices. You can control how Meta uses the data it receives about you from our site in Meta’s Off-Facebook Activity settings and Meta’s Ad Preferences. Blocking third-party cookies in your browser, or using a tracker-blocking extension, also stops the pixel from loading. You can also ask us to stop this collection by emailing support@rilk.ai. None of these choices affect your access to the Service.

California residents. We have enabled Meta’s Limited Data Use setting, which restricts how Meta may process the data it receives from visitors it identifies as being in California. Section 11.4 sets out the choices that apply to every component described in this section.

11.2 Google Ads conversion tracking

On the same public pages listed in section 11.1 — our home page and marketing site, this Privacy Policy, our Terms of Service, our coming-soon page, our booking page, our free tools (the Amazon profit calculator and the Amazon settlement analyzer), and our sign-up page — we also run Google Ads conversion tracking. We use it to measure whether a Google ad click led to a completed sign-up. It sends Google your IP address, browser and device information, the page URL you are viewing, the referring URL, and Google cookie identifiers, including the identifier Google uses to link a prior ad click to your visit.

Google Ads conversion tracking does not run:

  • anywhere inside the Service — no page you reach after signing in loads it
  • on any page you reach after you finish signing up, including the page that confirms your email address

Our sign-up page. Like the Meta pixel, it does run on our sign-up page and the sign-up window on the Amazon profit calculator, so we can tell whether a completed sign-up followed an ad click. It sends Google the same visit data listed above and, when a sign-up completes, a “conversion” signal with no details attached. It does not send your email address, your name, your company name, your phone number, or anything else you type into the form.

No ad personalization or remarketing. We have turned off Google’s ad personalization and remarketing signals for this tag (allow_google_signals and allow_ad_personalization_signals are both off) — it is used only to measure ad performance, not to build an audience or show you ads elsewhere.

What we never send to Google Ads. No marketplace or Amazon Selling Partner API data, no Google-account data from your connected mailbox or Sheets (see Section 10 — this is a separate, unrelated Google product), no buyer or customer personal data, no order, product, inventory, or financial data, and no account or login data. Google Ads receives only the public-page visit data described above, which is why it is not listed as a sub-processor in Section 4.

Your choices. You can control how Google uses the advertising data it receives about you at Google’s Ad Settings. A tracker-blocking browser extension, or a browser setting that blocks requests to Google’s tag domain, stops this tag from loading. Blocking third-party cookies limits what Google can link across sites, but does not by itself stop this tag: the ad-click identifier it stores is kept in a first-party cookie set by our own site. You can also ask us to stop this collection by emailing support@rilk.ai. None of these choices affect your access to the Service.

11.3 The SourceForge review badge

In the footer of our marketing pages only — the rilk.ai home page and the marketing pages beneath it, such as our product, feature, integration, use-case, pricing and comparison pages — we display a review badge from SourceForge, a software directory operated by Slashdot Media. It runs on fewer pages than the Meta pixel described in section 11.1: it does not run on our sign-up page, this Privacy Policy, our Terms of Service, our coming-soon page, or our booking page. The badge shows our SourceForge rating and links to our listing there, so visitors can read or write a review. It is loaded from SourceForge’s own servers, which means that when the badge loads, Slashdot Media receives your IP address, your browser and device information, and the full address (URL) of the page you are viewing, together with the standard information every browser sends with a request. We do not put personal information into the addresses of our public pages.

The badge does not run:

  • anywhere inside the Service — no page you reach after signing in loads it
  • on any page you reach after you finish signing up, including the page that confirms your email address

No cookies, and nothing about you. The badge sets no cookies and stores nothing in your browser. It sends no marketplace or Amazon Selling Partner API data, no Google data, no buyer or customer personal data, no order, product, inventory, or financial data, and no account or login data. It sends nothing you type into a form, and it sends nothing at all unless you load a page that displays it. Slashdot Media receives only the public-page visit data described above, which is why it is not listed as a sub-processor in section 4.

Your choices. A tracker-blocking or script-blocking browser extension stops the badge from loading, and nothing is sent to Slashdot Media when it does not load. You can also ask us to stop this collection by emailing support@rilk.ai. Neither choice affects your access to the Service. How Slashdot Media uses what it receives is governed by its own privacy policy at slashdotmedia.com/privacy-statement. If you click through to our SourceForge listing, you leave our site and SourceForge’s own terms and privacy policy apply.

11.4 Your state privacy choices

This section applies to all three components described in sections 11.1 to 11.3.

Selling personal information. We do not sell personal information for money.

Do Not Track and Global Privacy Control. Our website does not currently respond to browser Do Not Track or Global Privacy Control signals. Use the controls described in sections 11.1, 11.2 and 11.3, or email us at support@rilk.ai, to limit this collection. None of these choices affect your access to the Service.

11.5 Our own visit and sign-up measurement

When you view a page of our public website, we record on our own servers that the page was viewed. On the Amazon profit calculator we also record when the calculator shows a result, when you click the ASIN lookup and when you open the sign-up window. Each record holds a random visit identifier (kept in your browser’s session storage, which is cleared when you close the tab), the page path, and any campaign tags (utm parameters) and Google ad-click identifier (gclid) in the link you arrived by.

When you sign up, we save on your account any campaign tags and ad-click identifier from the link you arrived by. If you sign up in the same browser session as a visit to our public website, we link that visit’s records to your account and record when you sign up and when you confirm your email. For every account, we record the date and time it first connects to Amazon, and no data from Amazon.

We use these records only to measure which of our ads and pages lead to sign-ups and to active and paying accounts. They are stored with our hosting provider (Section 4) and are not sent to Meta, Google or any other third party.

Records not linked to an account are deleted after 90 days. Records linked to an account, and the tags saved on it, are kept as described in Section 7.

12. Children’s Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have collected data from a minor, contact us immediately at support@rilk.ai.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top and, for material changes, notify you by email or in-app notification. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

For questions about this Privacy Policy or to exercise your rights:

Email: support@rilk.ai

Website: https://rilk.ai