Privacy Policy
Last updated: 7 September 2026
Amino Engine is an email marketing platform for e-commerce brands. This policy covers two different relationships, and it matters which one you are in:
If you are a brand using Amino Engine — we are the controller of your account information (your name, your email, your billing details, how you use the app). Part 1 is about you.
If you are a subscriber of a brand that uses Amino Engine — you got an email from a brand, not from us. We are that brand's processor: we hold and send their list on their instructions. The brand decides what you receive and why they have your address. Part 2 explains what we hold and what to do about it. For most requests, the brand is who to ask — and we will help them answer you.
Amino Engine is operated by [LEGAL ENTITY NAME], [BUSINESS ADDRESS], United States.
Part 1 — If you are a brand using Amino Engine
What we collect about you
Account information. Your name, your email address, your password (stored only as a hash — we cannot read it), your brand name, your website, and the answers you give during onboarding (what you sell, your industry, roughly how big your list is). You give us all of this directly.
Billing information. Your plan, your subscription status, your invoices, and what you have bought. Card details go straight to Stripe and never touch our servers — we hold a Stripe customer reference, not a card number.
Usage information. Which screens you open, what you build, what you send, and the technical logs our servers keep (request paths, timestamps, error traces). We use it to run the service, to support you, and to see whether the product works.
Sending reputation data. How your mail performs: deliveries, bounces, complaints, opens and clicks in aggregate. We need this to keep the shared sending infrastructure healthy, and we look at it when deciding whether an account has to be slowed or paused.
Internal alerts. When something notable happens on an account — a large new customer, a purchase, a fulfilment task — we post a short message to our internal Slack. Those messages carry the brand name and a metric, never subscriber data and never message content.
Why we use it
- To provide the service you signed up for (contract).
- To bill you and collect payment (contract).
- To keep the platform, and everyone else's deliverability, safe from abuse (legitimate interests).
- To support you, and to tell you about changes to the service (contract / legitimate interests).
- To meet legal obligations, including tax and anti-abuse rules (legal obligation).
We may send you product and marketing email about Amino Engine. You can opt out of the marketing kind at any time; service and billing messages you cannot opt out of while you have an account.
Cookies we set on the app
The app at app.aminoengine.com sets exactly two cookies, and neither is used for
advertising:
| Cookie | Purpose | Lifetime |
|---|---|---|
ae_session |
Keeps you signed in. Signed, httpOnly, SameSite=Lax. |
12 hours |
ae_theme |
Remembers light or dark mode so the page does not flash on load. Readable by the page because the theme switch reads it back. | 1 year |
We do not run third-party advertising or analytics trackers inside the app. [CONFIRM before launch if any marketing analytics is added to the signed-in app.]
How long we keep it
We keep your account data while your account is open. When you close it, we delete or anonymise it, except billing and tax records, which we keep for as long as the law requires. See Data export when you leave in the Terms.
Part 2 — If you are a subscriber of a brand that uses Amino Engine
You are here because a brand you gave your address to sends its email through us. That brand decides what it sends you and why it has your data. We store it and deliver it for them, and we do not use it for anything of our own.
What the brand's account holds about you
Contact record. Your email address, and whatever the brand collected — name, phone number, any attributes or tags they added, and notes they wrote.
Consent record. Whether you agreed to marketing email, when, and the exact wording you were shown at the time. We store that sentence verbatim rather than a pointer to a template somebody could later edit, because "they consented" is not an answer and "here is what they were shown, on this date" is.
Message history. Which emails were sent to you, and what happened to each one: delivered, bounced, opened, clicked, marked as spam, unsubscribed.
Shop events. If the brand connected their store, we receive events about what you did there — pages viewed, products viewed, cart updated, checkout started, order created, order paid, refunded, and similar. Order events include the order total and line items.
Website behaviour, if the brand installed our tracker. The brand can put a small script on their site. When it runs it sends us, for that brand only:
- an anonymous visitor id it generated at random and stored in a cookie
(
_ae_id, 1 year) — not derived from anything about you; - the page URL, the referring URL, and the store's origin;
- UTM parameters in the link you arrived on (
source,medium,campaign,term,content,id); - your time zone;
- cart and order activity on the site.
Our server looks at the User-Agent on the request and records one word —
mobile, tablet, desktop or bot. The raw User-Agent string is not
stored. We store a device word, not a fingerprint.
If you clicked a link in one of the brand's emails, the anonymous id can be linked to your contact record so the brand can see that you visited. If you visit without clicking an email, the visit stays anonymous.
Opting out of the tracker. The tracker respects an opt-out cookie (_ae_off)
on the brand's own site. The brand can also simply not install it. It is their
site, so their site's cookie notice is where it should be described.
What we do not do
- We do not sell or rent your data. To anyone. Ever.
- We do not combine one brand's contacts with another brand's. Every brand's data is isolated at the database level, and a query on one account cannot return another account's rows.
- We do not use your data to train models, build our own marketing list, or advertise to you.
- We do not store the raw User-Agent, your IP address as a profile attribute, or any special-category data. Do not put health information into a contact record — see our Acceptable Use Policy.
Unsubscribing
Every marketing email we send carries an unsubscribe link and a
List-Unsubscribe header, so the one-click button in Gmail, Apple Mail and Outlook
works. The link goes to a page at the brand's tracking domain (/u/) and
takes effect immediately — no login, no "are you sure", no re-confirmation email.
Once you unsubscribe, that brand cannot email you marketing again through us, and re-importing your address does not undo it.
Your rights
Depending on where you live, you have rights over your data: to see it, correct it, delete it, take a copy elsewhere, object to processing, and complain to a regulator. Under the GDPR and UK GDPR those rights sit against the brand as controller; under the CCPA/CPRA and other US state laws the brand is the business; under PIPEDA in Canada the brand is the organisation.
Ask the brand first. They hold the relationship and the tooling to answer you, and every one of these requests is something they can do inside the app.
If you cannot reach them, or you want us to chase it, write to support@aminoengine.com with the brand's name and the address they mail. We will pass it on and make sure it is actioned. We may need to check you are who you say you are before we do anything.
How deletion actually works
This one is worth being straight about, because it is the only place we keep anything after an erasure.
When a brand erases you, we destroy what identifies you: your name, phone,
attributes, notes, message bodies, the browser identifiers linked to you, and the
personal details inside cart snapshots. Your contact row itself is anonymised
rather than deleted — the address becomes an unusable placeholder at a reserved
.invalid domain — because deleting the row would also delete the record that you
bounced or complained, which is how a brand's next import would mail you again.
And we keep one thing about you: a one-way hash of your email address on a never-send list. It cannot be reversed into your address. Its only job is that if somebody uploads a list with you on it tomorrow, we recognise you and refuse to send. Forgetting you must not un-forget that you said stop. GDPR Article 17(3) allows this, and Recital 26 is why the hash is lawful to keep.
If you would rather we did not keep even that, tell us and we will explain the consequence before we do anything.
Retention
Contact records, consent records and message history are kept while the brand's account is active, and are deleted or anonymised when it closes. Raw website and shop events are retained while the account is active; we are adding an automatic trim and will state the period here when it is live. [SET RETENTION PERIOD FOR RAW EVENTS once the retention job ships — do not publish a number before then.]
Suppression entries — the hashes above — are kept indefinitely, by design.
Both audiences
Where your data lives, and who else touches it
Amino Engine is hosted in the United States, and our mail servers are in Canada. Data is processed in both places, and support staff may access it from the United States.
We use a small number of vendors to run the service. They are listed, with what each one does and where it sits, on our Sub-processors page. We do not add one without updating that page.
International transfers
If you are in the EU, the UK or Switzerland, your data will be transferred to the United States and Canada. We rely on the Standard Contractual Clauses (and the UK Addendum) for transfers where no adequacy decision covers them, and Canada benefits from an EU adequacy decision for commercial organisations. The terms are in our Data Processing Addendum, which any customer can enter into with us.
Meta (Facebook and Instagram) advertising data
Added 7 September 2026.
If a brand connects their Meta advertising to Amino Engine, we act on that brand's instructions to read and manage their ads. This section says exactly what that means, because Meta requires us to and because it is worth being plain about.
What we ask Facebook for. Permission to read and manage advertising for the accounts the person chooses, to list the ad accounts and business portfolios they have access to, and to read the Page an ad runs under and the comments on that ad. We ask for nothing else. We never ask for, and never receive, a person's password, friends, messages, photos, or anything from their personal profile.
What we store about the person who connects. Their Facebook display name and their numeric Facebook user id — the same id that appears in the address bar of their own ads — and which permissions they actually granted. Nothing else about them.
What we store about the advertising. A copy of the ad accounts, Pages, pixels, audiences, campaigns, ad sets, ads and creatives as Meta describes them; the daily spend, impressions, clicks, purchases and return-on-spend from Meta's reporting; the account activity log; and Meta's stated reasons for rejecting an ad. This is business data about a company's advertising, not about its customers.
Where the login lives. The credential that lets us act on a brand's ads is held encrypted, on a separate machine with no public address, and is never shown on any screen, in any report, or in any log.
Why we hold it. Only to provide the advertising service the brand connected us for. We do not sell it, we do not use it to build any separate dataset, and we never blend one brand's Meta data with another's.
How long. While the connection is active. When a brand disconnects, or asks us to delete it, or removes Amino Engine from their Facebook profile, all of the above is deleted.
How to have it deleted. Disconnect inside the app under Ads, or write to support@aminoengine.com. The step-by-step instructions, and the full list of what is deleted and what is kept, are on our Meta data deletion page.
Security
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. Access to production systems is limited to people who need it. Every brand's data is separated at the database level with row-level security, and the application connects with a role that cannot read across that boundary. DKIM signing keys are encrypted at rest.
No system is perfectly secure. If we discover a breach affecting your data we will tell you, and where you are a customer we will do it within 72 hours of becoming aware — see the DPA.
Children
The service is not for anyone under 18, and brands must not use it to market to minors. We do not knowingly collect data about children. If you believe we have, write to us and we will delete it.
Changes
We will update this policy as the product changes. The "Last updated" date at the top always reflects the current version, and we will tell customers by email before a material change takes effect.
Questions, or a rights request: support@aminoengine.com