Skip to main content
Skip to content
Legal Documents

Privacy Policy

Last updated: January 21, 2026

Table of Contents

1. Introduction

Welcome to Shurq ("Company," "we," "our," or "us"). Shurq Ltd is a company registered in England and Wales, committed to protecting your personal information and your right to privacy. This Privacy Policy describes how we collect, use, store, protect, and share your personal information when you use our website, platform, and services (collectively, the "Services").

This Privacy Policy applies to all information collected through our Services, as well as any related services, sales, marketing, or events. We encourage you to read this privacy policy carefully as it will help you understand what we do with the information that we collect.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this privacy policy, please do not access or use our Services.

Important Notice: This policy was last updated on January 21, 2026. We may update this privacy policy from time to time. The updated version will be indicated by an updated "Last Updated" date and the updated version will be effective as soon as it is accessible.

2. Information We Collect

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us. The personal information we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use.

2.1 Personal Information You Provide

We collect the following categories of personal information that you provide to us:

  • Account Information: When you register for an account, we collect your name, email address, username, password, and other registration details.
  • Profile Information: Information you add to your profile such as company name, job title, profile picture, and professional background.
  • Payment Information: When you make a purchase, we collect payment card details, billing address, and transaction history. Payment processing is handled securely by our payment processor, Stripe, and we do not store complete credit card numbers on our servers.
  • Communication Data: When you contact us via email, support tickets, or other channels, we collect the content of your messages, your contact details, and any attachments you provide.
  • Survey and Feedback Data: If you participate in surveys, promotions, or provide feedback, we collect your responses and any information you choose to share.
  • Marketing Preferences: Your preferences for receiving marketing communications and your communication preferences.

2.2 Amazon Seller Data

When you connect your Amazon Seller Central account to our Services, we access certain data through Amazon's official Selling Partner API (SP-API). This integration is essential for providing our analytics and optimization services. The data we access includes:

  • Product and Inventory Data: Product listings, ASINs, SKUs, pricing information, inventory levels, and product attributes.
  • Advertising Data: Sponsored Products, Sponsored Brands, and Sponsored Display campaign data including impressions, clicks, spend, sales, ACoS, and keyword performance metrics.
  • Sales and Orders: Order history, revenue data, units sold, returns, and refunds.
  • Search Terms and Keywords: Search term reports, keyword rankings, organic and paid search performance data.
  • Account Health: Account health metrics, policy compliance status, and performance notifications.
  • Brand Analytics: Search frequency rank, click share, conversion share, and market basket analysis (where available based on your Amazon account type).

Data Access Scope: We request only the minimum necessary API permissions required to provide our Services. By default, we use read-only access to your Amazon data. We never make changes to your Amazon Seller Central account, advertising campaigns, or product listings without your explicit written authorization and confirmation for each specific action.

2.3 Automatically Collected Information

When you access or use our Services, we automatically collect certain information about your device, browsing actions, and usage patterns. This information is collected using cookies, web beacons, and similar tracking technologies. The information we collect includes:

  • Device Information: Device type, operating system, unique device identifiers, browser type and version, screen resolution, and device settings.
  • Network Information: Internet Protocol (IP) address, internet service provider, mobile carrier, and network type.
  • Usage Data: Pages visited, features used, time spent on pages, click patterns, navigation paths, and interaction with content.
  • Location Data: Approximate geographic location based on IP address (country, region, city level). We do not collect precise GPS location data.
  • Referral Data: Information about the website or source that referred you to our Services, including search terms used.
  • Performance Data: Page load times, error logs, and diagnostic information to help us improve our Services.

2.4 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Amazon: Data received through the Amazon SP-API as described above.
  • Payment Processors: Transaction confirmations and payment status from Stripe.
  • Analytics Providers: Aggregated analytics data from services like Google Analytics.
  • Social Media Platforms: If you connect your social media accounts or interact with our social media presence.
  • Business Partners: Information from partners with whom we offer co-branded services or engage in joint marketing activities.

3. How We Use Your Information

We use the personal information we collect for various business and commercial purposes. We process your information based on legitimate business interests, the fulfillment of our contract with you, compliance with our legal obligations, and/or your consent.

3.1 Service Delivery and Operations

  • To create, maintain, and secure your account
  • To provide our analytics, reporting, and optimization services
  • To process your transactions and manage billing
  • To sync and analyze your Amazon seller data
  • To generate insights, recommendations, and reports
  • To enable features like keyword tracking, campaign management, and performance monitoring

3.2 Communication and Support

  • To respond to your inquiries, support requests, and feedback
  • To send service-related notifications, updates, and alerts
  • To provide technical support and troubleshooting assistance
  • To communicate about account activity, security alerts, and policy changes

3.3 Marketing and Promotional Purposes

  • To send marketing communications about our products, services, and promotions (with your consent)
  • To personalize your experience and deliver relevant content
  • To conduct surveys, contests, and promotional activities
  • To measure the effectiveness of our marketing campaigns

You can opt out of marketing communications at any time by clicking the "unsubscribe" link in our emails or by contacting us directly.

3.4 Analytics and Improvement

  • To analyze usage patterns and trends to improve our Services
  • To develop new features, products, and services
  • To conduct research and analysis for business intelligence
  • To monitor and analyze the effectiveness of our Services
  • To identify and fix bugs, errors, and technical issues

3.5 Security and Compliance

  • To detect, prevent, and address fraud, abuse, and security threats
  • To enforce our terms, conditions, and policies
  • To comply with legal obligations and respond to lawful requests
  • To protect the rights, property, and safety of Shurq, our users, and the public

5. Data Sharing and Disclosure

We value your privacy and are committed to protecting your personal information. We do not sell your personal information to third parties. We may share your information only in the following circumstances:

5.1 Service Providers

We engage trusted third-party companies and individuals to perform services on our behalf. These service providers have access to your personal information only to perform specific tasks and are obligated to protect your information. Our service providers include:

  • Cloud Infrastructure: Amazon Web Services (AWS) for secure data hosting and storage
  • Payment Processing: Stripe for secure payment transactions
  • Email Services: SendGrid for transactional and marketing emails
  • Customer Support: Intercom for live chat and support ticket management
  • Analytics: Google Analytics and Mixpanel for usage analytics
  • Error Monitoring: Sentry for error tracking and debugging

5.2 Business Transfers

If Shurq is involved in a merger, acquisition, asset sale, bankruptcy, or reorganization, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your information.

5.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal requests by public authorities. This includes:

  • Complying with court orders, subpoenas, or legal processes
  • Responding to requests from law enforcement or regulatory agencies
  • Protecting and defending our legal rights or property
  • Preventing or investigating possible wrongdoing
  • Protecting the personal safety of users or the public

5.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so. This may include sharing data with integration partners or other services you choose to connect with your Shurq account.

5.5 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you. This data may be used for industry analysis, benchmarking, research, and other purposes.

6. Data Security

We implement comprehensive security measures designed to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security practices include:

6.1 Technical Safeguards

  • Encryption: All data transmitted between your browser and our servers is encrypted using 256-bit TLS/SSL encryption. Data at rest is encrypted using AES-256 encryption.
  • Secure Infrastructure: Our Services are hosted on enterprise-grade infrastructure with multiple layers of security, including firewalls, intrusion detection systems, and DDoS protection.
  • Access Controls: We implement strict role-based access controls, multi-factor authentication, and the principle of least privilege for all system access.
  • Regular Security Testing: We conduct regular vulnerability assessments, penetration testing, and security audits to identify and address potential weaknesses.

6.2 Organizational Measures

  • Employee Training: All employees receive regular security awareness training and are bound by confidentiality obligations.
  • Background Checks: We conduct background checks on employees with access to sensitive systems and data.
  • Incident Response: We maintain a comprehensive incident response plan to quickly detect, respond to, and recover from security incidents.
  • Vendor Management: We carefully vet third-party vendors and require them to maintain appropriate security measures.

6.3 Compliance and Certifications

  • Security Audits: We conduct regular security assessments and are working toward SOC 2 Type II certification.
  • GDPR Compliance: We maintain compliance with the General Data Protection Regulation (GDPR) for EU/EEA users.
  • PCI DSS: Payment processing is handled by PCI DSS-compliant service providers.

Security Reminder: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you share information at your own risk. We encourage you to use strong, unique passwords and enable two-factor authentication on your account.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the type of data and the purpose of processing.

7.1 Retention Periods

7.2 Account Deletion

When you request deletion of your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal, regulatory, or legitimate business purposes. After deletion, your data cannot be recovered.

8. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information. We are committed to honoring these rights and making it easy for you to exercise them.

8.1 Rights for All Users

All Shurq users have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to certain exceptions.
  • Data Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
  • Opt-Out: Opt out of marketing communications at any time.
  • Withdraw Consent: Withdraw consent for processing based on consent.

8.2 Additional Rights for EEA/UK Residents (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the GDPR:

  • Restriction: Request restriction of processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests or for direct marketing.
  • Automated Decision-Making: Not be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
  • Lodge a Complaint: File a complaint with your local data protection authority (e.g., the UK Information Commissioner's Office).

8.3 Additional Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Know: Request disclosure of the categories and specific pieces of personal information we have collected.
  • Delete: Request deletion of personal information we have collected.
  • Opt-Out of Sale: Opt out of the "sale" of personal information (note: we do not sell personal information).
  • Non-Discrimination: Not be discriminated against for exercising your privacy rights.
  • Correct: Request correction of inaccurate personal information.
  • Limit Use of Sensitive Information: Limit the use and disclosure of sensitive personal information.

8.4 How to Exercise Your Rights

To exercise any of these rights, you may:

  • Submit a request through your account settings
  • Email us at legal@shurq.com
  • Contact us using the details in the "Contact Us" section below

We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request. In some cases, we may be unable to fulfill your request due to legal obligations or legitimate business reasons, in which case we will explain the reason.

9. International Data Transfers

Shurq is headquartered in the United Kingdom, and we process and store data primarily in the UK and European Union. However, we may transfer your personal information to countries outside your country of residence, including to service providers located in the United States and other countries.

9.1 Transfer Safeguards

When we transfer personal information internationally, we ensure appropriate safeguards are in place:

  • Adequacy Decisions: Transfers to countries recognized as providing adequate data protection.
  • Standard Contractual Clauses: EU-approved standard contractual clauses for transfers to other countries.
  • Data Processing Agreements: Contractual commitments with all processors to protect your data.
  • Additional Measures: Technical and organizational measures to ensure data protection during transfer.

9.2 UK-Specific Transfers

For transfers from the UK, we rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses, as appropriate, to ensure your data receives equivalent protection.

10. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at legal@shurq.com.

If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post the updated policy on our website
  • Notify you of material changes via email or through a prominent notice on our Services

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information. Your continued use of our Services after any changes indicates your acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

General Privacy Inquiries

Email: legal@shurq.com

Subject Line: Privacy Inquiry

Data Protection Officer

Email: legal@shurq.com

For: GDPR-related requests

Postal Address

Shurq Ltd
Data Protection Team
London, United Kingdom

We aim to respond to all legitimate requests within 30 days. Occasionally, it may take longer if your request is particularly complex or you have made multiple requests, in which case we will notify you and keep you updated.

Have Questions?

Contact our team for any inquiries about our privacy practices