Spekco

Privacy Policy

Last updated: April 27, 2026

1. Introduction

This Privacy Policy describes how 440 Technologies LLC ("Company," "we," "us") collects, uses, and protects information when you use the Spekco platform ("Service"). By using the Service, you consent to the practices described here.

2. Information We Collect

Account information: When you sign up, we collect your name, email address, company name, and password (stored securely hashed).

Business data: Information you enter into the Service, including customer records, service tickets, product listings, orders, appointments, and payment details.

Payment information: Payment card details are collected and processed by our payment processor, Stripe. We do not store full card numbers on our servers.

Usage data: We automatically collect information about how you interact with the Service, including IP addresses, browser type, pages visited, and timestamps.

Communications: If you contact us for support, we retain the correspondence to help resolve your issue.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related notifications
  • Send transactional emails (verification, password resets, billing receipts)
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use your data for advertising purposes.

4. Data Sharing

We share information only in these limited circumstances:

  • Service providers (subprocessors): We use third-party services to operate the platform: AWS (hosting, us-east-1), Neon (Postgres database hosting, us-east-1), Stripe (payment processing), Square (POS payment processing), Resend (transactional email), Twilio (SMS, when enabled), EasyPost (shipping carrier rates and label fulfillment), QuickBooks Online (accounting export, when the tenant enables sync), Upstash (Redis cache), UploadThing (file uploads), and Amazon Selling Partner API (when the tenant connects an Amazon seller account). These providers access data only as needed to perform their services and operate under signed Data Processing Agreements.
  • Legal requirements: We may disclose information if required by law, regulation, or legal process.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

5. Your Customers' Data

When your customers use the customer portal, their information (name, email, phone, service history, orders) is stored within your account. You are the data controller for your customers' data; we act as a data processor on your behalf. You are responsible for informing your customers about how their data is used and obtaining any required consents.

6. Amazon Marketplace Integration

When a tenant connects an Amazon seller account to Spekco via the Amazon Selling Partner API (SP-API), we receive marketplace data on the tenant's behalf to power order fulfillment, inventory sync, listing management, and accounting reconciliation. The integration is opt-in per tenant and can be disconnected at any time.

What we collect from Amazon:

  • The seller's public Selling Partner ID and authorized marketplace IDs
  • Long-Lived Access (LWA) refresh and access tokens, encrypted at the application layer with AES-256-GCM in addition to storage-layer encryption
  • Order metadata (order ID, totals, items, status, shipped-at timestamps)
  • Buyer name and shipping address per Fulfilled-by-Merchant (FBM) order, used solely to render shipping labels via Amazon Buy Shipping (we do not propagate this data to other subprocessors or use it for marketing)
  • FBA inventory snapshots, listing status, returns reports, settlement reports

What we do not collect: Buyer payment methods, financial instruments, review content, advertising metrics, or any data Amazon does not surface via the standard order / inventory / listings / finances / notifications endpoints. Buyer email addresses are received only as Amazon-aliased proxy addresses; we do not receive direct buyer email addresses.

Retention: Buyer name and shipping address columns on order records are automatically nulled within 31 to 90 days of order shipment. Refresh and access tokens are retained while the Amazon connection is active and scrubbed within 72 hours of disconnection. Order metadata (without buyer-PII columns) is retained while the tenant subscription is active and deleted on tenant offboarding.

Recipients: Amazon marketplace data is consolidated under a single "Amazon Marketplace" customer record before being pushed to QuickBooks Online; no per-buyer PII is propagated to QuickBooks. Buyer name and address are rendered onto shipping label PDFs that are stored in S3 with private-bucket access controls and signed URLs scoped per tenant; the rendered label is the operator's working artifact.

Full technical details (encryption methods, access controls, deletion procedures) are documented in our Amazon SP-API Data Protection Plan, which was submitted as part of our SP-API developer registration with Amazon and is available upon request via our contact page.

7. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit and at rest
  • Secure credential storage using modern hashing algorithms
  • Role-based access controls
  • Regular security assessments and monitoring

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. If you close your account, we will delete your data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., billing records).

9. Cookies & Tracking

The Service uses essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising pixels. Usage analytics, if collected, are first-party only.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict certain processing

To exercise these rights, contact us. We will respond within 30 days.

11. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.

12. International Data Transfers

The Service is hosted in the United States (AWS us-east-1). If you access the Service from outside the US, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the Service. Your continued use after changes take effect constitutes acceptance.

14. Contact

If you have questions or concerns about this Privacy Policy, contact us.

440 Technologies LLC
Saint Charles, Missouri, United States

Privacy Policy — Spekco