Skip to main content

Data Processing & Privacy Guidelines

Effective Date: January 1, 2024Last Updated: December 2024

This document answers frequently asked questions about our data processing and collection practices. For additional information, please refer to our Privacy Policy.

1. Data Collection and Processing

What types of data do you collect and process?

Detail Page collects information related to customer search volumes as a whole, not as any individual user. No personal, customer, or consumer information is collected, used, or stored. Furthermore, we do not handle or process any sensitive data from brands as part of our services but use publicly available information processed via our patented software to provide value.

How do you ensure that only necessary data is collected?

We collect this data from within Amazon's systems, APIs, and via other publicly available sources. Web crawling is used only when necessary (e.g., to verify content is live on site). Data for general searches from Google are obtained using their API. We follow the terms & conditions as outlined by each site.

What is the purpose of collecting and processing this data?

We use collected information to revise content on the product detail page to be more in line with customer expectations vs what they search for.

2. Data Storage and Security

Where is the data stored?

Amazon Web Services (AWS).

What encryption methods do you use for data at rest and in transit?

AWS primarily uses the Advanced Encryption Standard (AES) with 256-bit keys as its encryption method for data at rest and in transit, across most of its services, including S3, RDS, and EBS, making it the industry standard for encryption strength.

How do you ensure the security of your data storage infrastructure?

By using the highest industry standards and AWS as vendor, we're able to ensure the security of our data.

Do you perform regular security audits and vulnerability assessments?

We leverage AWS's audited cloud infrastructure and supplement it with additional security controls and periodic vulnerability assessments.

3. Data Access and Control

Who within your organization has access to the collected data?

Only our Customer Service Manager and their direct supervisor have access as part of their job duties.

How do you control and monitor access to this data?

Access to Vendor Central / Seller Central and Web Services is provided only to authorized employees using two-factor authentication of both an authenticator app and their DetailPage email address login. Access to both are revoked upon change of job as part of the email revocation process.

What measures are in place to prevent unauthorized access?

Our data storage employs several measures to prevent unauthorized access, including: strong encryption of data both in transit and at rest, two-factor authentication, granular access controls for sharing files, login procedures, and the ability to set specific permissions for individual users and groups.

4. Data Retention and Deletion

What is your data retention policy?

Data is stored for the term of the agreement, plus 1 year post unless otherwise specified in the customer's agreement.

How can we request the deletion of our data from your systems?

Requests should be sent to: dataczar@detailpage.com

Do you have a process for ensuring data is securely deleted when no longer needed?

Yes. Data is audited monthly and files that have not been used for 1 year or more are deleted.

5. Compliance and Legal

Are you compliant with relevant data protection regulations (e.g., GDPR, CCPA)?

We are in compliance with these regulations as we do not collect any information covered by GDPR and/or CCPA. No personal, customer, or consumer information is gathered or stored.

6. Third-Party Sharing and Sub-processors

Do you share collected data with any third parties or sub-processors?

No. We process all data internally.

How do you vet and manage third-party partners?

N/A. We process all data internally.

7. Incident Response and Breach Notification

At Detail Page, we prioritize the security and privacy of our clients and their data. As a company, we do not gather, collect, store, or process any personally identifiable information (PII). However, we maintain strict security protocols to protect all information and ensure a secure environment for our operations.

Our process for responding to security incidents includes the following steps:

  1. Immediate Containment and Assessment: If a security incident occurs, our team promptly assesses the scope and nature of the issue, containing any potential risk to prevent further exposure.
  2. Root Cause Analysis and Remediation: We conduct a thorough investigation to determine the root cause, applying immediate remediation measures to eliminate vulnerabilities. This may include updating software, enhancing firewall protections, and implementing additional safeguards.
  3. Enhanced Security Measures: Post-incident, we conduct a comprehensive review to strengthen our security framework, updating protocols and tools as necessary to mitigate future risks.
  4. Communication and Transparency: While we do not handle PII, we remain committed to transparency. We document all security incidents and, if applicable, notify impacted stakeholders with relevant information via email.

8. AI Usage and Privacy

How does Detail Page use AI in its services?

AI is an integral part of our process for content creation and search optimization. It analyzes publicly available written and image content from retail websites to identify optimization opportunities. All AI-generated output is reviewed by client legal and brand teams before being published to retailer sites.

What data does the AI access or process?

The AI uses only publicly available information from retailer websites as input data. We do not use or store any private, personal, or client-owned data unless explicitly authorized. All AI outputs undergo internal and client review before publication.

How does Detail Page protect client data and maintain AI isolation?

We use a "walled garden" architecture that combines publicly available information with proprietary training data. Each client receives its own dedicated AI instance, ensuring that data and queries remain fully isolated and are never used to train any general model. This design guarantees that all analysis respects client privacy and confidentiality.

What steps are taken to ensure fairness, ethics, and risk management in AI?

Detail Page maintains a documented AI Ethics and Risk Management framework. We conduct ongoing bias and harms testing to minimize potential negative impact, and we continually evaluate and refine our AI systems for transparency, accuracy, and fairness. Clients can request access to our AI Ethics and Bias Testing documentation for review.

Where is the AI hosted and how is data secured?

Our infrastructure is hosted on Amazon Web Services (AWS). AWS uses the Advanced Encryption Standard (AES-256) for data at rest and in transit across core services (including S3, RDS, and EBS). This encryption standard meets or exceeds industry best practices for security and compliance.

Do you have feedback and monitoring mechanisms in place?

Yes, Detail Page has feedback and monitoring mechanisms designed to detect and respond to any signs of abusive behavior or unintended, harmful outputs. We encourage users to report any issues, and our monitoring system actively reviews outputs to ensure they meet our ethical and safety standards. This helps us continuously improve our AI to provide safe, reliable insights.

Contact Us

If you have any questions about our data processing practices or would like to request data deletion, please contact us at dataczar@detailpage.com or through our contact form.