Privacy
Privacy Policy
The short version. We collect as little as we can. Nothing on this website contacts a third party until you say so. The application processes the data our customers give it to run their Minimum Advertised Price programs, and the public prices it reads on their behalf. We do not sell or share personal information, and we honour the Global Privacy Control signal.
1. Who we are
EagleEnforce™ is operated by LaFountain Design, doing business as EcommEagle®, 170 Highland Rd, Ste 1, Massena, NY 13662. We are the "business" for the personal information of website visitors and of the people who hold accounts with us, and a "service provider" for the data our customers upload or connect. Contact: support@ecommeagle.com.
2. What we collect
Visitors to this website
- Server logs. Our web server records requests with a truncated IP address, the page requested, the time, and the browser type, for security and to keep the site running. Logs are deleted after 30 days.
- Your consent choice. One first-party cookie named
ee_consentstores whether you allowed analytics. Storing a refusal is strictly necessary and does not require consent. - Analytics, only if you allow it. With your permission we load Google Analytics 4 with IP anonymisation, Google signals off and advertising features off. Without permission the script is never requested.
- Email you send us. If you write to us we keep the correspondence to reply and for our records.
Account holders
- Account data: name, email address, password (hashed), organisation name, role, notification preferences, and security events such as sign-ins and two-factor codes.
- Support tickets and any files you attach to them.
- Plan and usage: which plan your organisation is on and counts of products and listings watched. We do not process payment card data ourselves.
Customer content (processed on our customers' behalf)
- Catalog data: products, SKUs, identifiers, MAP and MSRP prices, images, imported from a CSV or read from the customer's own store.
- Dealer records: business names, store domains, marketplace seller IDs, business addresses, phone numbers, contact email addresses and notes the customer enters about the dealers it sells through.
- Monitoring data: publicly advertised prices, listing URLs and titles read from dealer websites, and, on confirmation of a violation, evidence captures (a screenshot and the page as served) of those public pages.
- Marketplace data: when a customer connects a marketplace account, offer and seller data returned by that marketplace's official API under the customer's authorisation.
- Notices: the content of notices the customer approves and we send on their behalf, and delivery records.
3. How we use it
- To provide the service: monitor listings, detect and verify MAP violations, keep evidence, and run the enforcement workflow our customers configure.
- To operate accounts: sign-in, security, two-factor authentication, notifications the account holder chooses, support.
- To keep the service safe: rate limiting, abuse prevention, audit logs of administrative actions.
- To understand how the website is used, only with your consent.
- To meet legal obligations and enforce our terms.
We do not use customer content to train models, build profiles of dealers across customers, or for advertising.
4. Cookies and consent
This website sets one strictly necessary cookie (ee_consent) and, with your permission, Google Analytics cookies. The application additionally sets session and security cookies needed to keep you signed in and to protect against cross-site request forgery. There are no advertising or cross-site tracking cookies.
| Category | Purpose | Consent |
|---|---|---|
| Necessary | Sign-in session, CSRF protection, security, the record of your consent choice | Not required |
| Preferences | Remembered interface settings; in the app, loading Google Maps for the dealer map | Asked |
| Analytics | Google Analytics 4, anonymised | Asked |
| Marketing | Not used | Never enabled |
You can change your choice at any time with the Privacy choices link in the footer of every page. If your browser sends a Global Privacy Control signal we treat it as a valid opt-out of any sale or sharing of personal information, apply it immediately, and do not ask you to reconsider it. After you decline analytics we will not ask again for at least twelve months.
5. Service providers
We share data only with providers who process it for us under contract, and only what each one needs:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| DigitalOcean | Hosting, database, storage | All service data, encrypted at rest | United States |
| Twilio SendGrid | Transactional email (verification codes, notifications, notices approved by customers) | Email address and message content | United States |
| Google Maps Platform | Geocoding of dealer business addresses entered by customers; the map display in the app | Business addresses; the map loads in your browser only with Preferences consent | United States |
| Google Analytics | Website usage statistics | Anonymised usage data, only with Analytics consent | United States |
| Amazon, eBay, Walmart | Marketplace data through their official APIs | Only when a customer connects an account, under that customer's authorisation | United States |
We may also disclose information when the law requires it, to protect our rights or the safety of others, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.
6. We do not sell or share personal information
We have not sold or shared personal information as those terms are defined in the California Consumer Privacy Act, and we do not intend to. We do not use sensitive personal information for anything other than providing the service.
7. If you are a dealer or seller
Our customers are brands. If a brand uses EagleEnforce to monitor prices, it may enter your business's name, store domain, marketplace seller ID, business address and business contact details, and EagleEnforce reads the prices you advertise publicly. We process that on the brand's instructions as its service provider. Requests about that data are best directed to the brand; if you contact us instead we will forward your request and help the brand respond. Our crawler identifies itself and respects robots.txt; see our crawler page for how to limit it.
8. Retention
- Website server logs: 30 days.
- Account data: for the life of the account and 90 days after closure, then deleted or anonymised.
- Customer content, monitoring data and evidence: for the life of the customer's subscription, within the evidence retention period of the customer's plan, and deleted within 90 days of the subscription ending unless the customer asks for earlier deletion.
- Audit and security logs: up to 24 months.
9. Security
Data is encrypted in transit and at rest. Credentials for connected stores are encrypted with keys held outside the database. Sign-in uses two-factor authentication; administrative access requires a second factor and is logged. No method is perfect; if we learn of a breach affecting you we will notify you as the law requires.
10. Your rights
If you are a California resident you have the right to know what personal information we collect and how we use it, to access it, to correct it, to delete it, to opt out of sale or sharing (which we do not do), to limit use of sensitive personal information, and not to be discriminated against for exercising these rights. Residents of other U.S. states with privacy laws, and visitors from the European Economic Area, the United Kingdom and Switzerland, have similar rights including access, correction, deletion, portability, restriction and objection, and the right to complain to a supervisory authority.
To exercise a right, email support@ecommeagle.com with "Privacy request" in the subject. We will verify the request using the email address on your account or, for non-account holders, by confirming details only you would know. An authorised agent may act for you with written permission. We respond within 45 days and do not charge for reasonable requests.
11. International visitors
Our servers are in the United States. If you use the service from outside the United States your information is transferred to and processed there. For EEA and UK data we rely on standard contractual clauses with our providers.
12. Children
The service is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children.
13. Changes
When we change this policy we update the effective date above and, for material changes, notify account holders by email or in the application before the change takes effect.
14. Contact
LaFountain Design, doing business as EcommEagle®
170 Highland Rd, Ste 1, Massena, NY 13662
Email support@ecommeagle.com.