Data Governance & Operational Privacy

Privacy & Data Governance Policy

How CALI ECOMMANAGEMENT LLC handles client store access, catalog intelligence, advertising spend data, and marketplace analytics with enterprise confidentiality and California compliance rigor.

Last Updated: September 2026
State of California, United States
Entity: CALI ECOMMANAGEMENT LLC

Zero Credential Custody

We never request or store root seller passwords. All operational access is granted via delegated secondary user permissions.

Secondary Access Only

Zero Data Monetization

We never sell, rent, broker, or trade client catalog data, supplier information, or sales volumes to any third-party brokers or advertisers.

Anti-Brokerage Guarantee

Diagnostic Confidentiality

Store URLs and metrics submitted for diagnostic audits are used exclusively to produce your growth roadmap, protected under mutual NDA standards.

Strict NDA Standards

California Privacy Rigor

Operating from California, we adhere to CCPA/CPRA standards, providing transparent data disclosure, audit trails, and prompt deletion on request.

CCPA / CPRA Compliant
SECTION 01Operational Scope

1. Scope & Operational Role

This Privacy & Data Governance Policy explains how CALI ECOMMANAGEMENT LLC (“CALI ECOMMANAGEMENT”, “we”, “us”, or “our”) collects, uses, protects, and governs personal and commercial information collected through our website (https://caliecommangement.com), our diagnostic audit submission tools, and during the course of ongoing marketplace management engagements.

We operate as a dedicated e-commerce management agency providing operational oversight, listing optimization, Sponsored Ads / PPC management, inventory reconciliation, and policy defense across major commercial marketplaces, including Amazon (Seller & Vendor Central), TikTok Shop, Walmart Marketplace, eBay, and Shopify.

Because our work involves interfacing with client seller portals, catalog feeds, and advertising spend metrics, we treat commercial data governance with the same rigorous confidentiality as customer personal data.

SECTION 02Data Collection Categories

2. Information We Collect

Depending on how you interact with our website and advisory services, we collect information across two distinct stages:

A. Website Inquiries & Free Store Audit Submissions

When you submit an inquiry form or request a confidential store audit on our website, you provide:

  • Contact Identification: Full name, business email address, and direct telephone number.
  • Brand & Channel Footprint: Brand name, company website URL, and active marketplace store links (Amazon storefront, TikTok Shop handle, Walmart seller link, or Shopify domain).
  • Self-Reported Operational Scope: Active channels managed, approximate active SKU count, approximate monthly revenue bracket, and primary growth bottlenecks (e.g., ad TACoS, Buy Box suppression, stockouts).
  • Diagnostic Notes: Specific operational challenges or goals submitted via freeform text fields.

B. Active Retainer Engagements (Contracted Clients Only)

Upon formal onboarding under an executed Master Services Agreement (MSA), we receive authorized, secondary access to necessary portal modules:

  • Secondary Delegated Permissions: Named operator access granted via platform partner consoles (e.g., Amazon User Permissions, TikTok Shop Partner delegation, Shopify Staff accounts).
  • Operational Catalog & Feed Data: Listing hierarchies, parent-child variations, inventory SKU quantities, inbound FBA/WFS shipment data, and suppression notifications.
  • Advertising Campaign Telemetry: Historical ad spend, keyword bid tables, Sponsored Products / Brands metrics, TACoS ratios, and attribution reporting.
  • Seller Support Communications: Case log threads, policy warnings, and Safe-T claim documentation necessary to resolve account health issues.
SECTION 03Strict Boundary

3. What We Deliberately Never Collect or Store

To eliminate credential vulnerability and financial exposure, we strictly enforce an anti-custody architecture:

  • Root / Master Passwords: We NEVER ask for, accept, or store your primary seller portal login credentials or master account passwords. All access must be provisioned via delegated secondary user permissions.
  • Banking & Disbursement Routing: We never access, record, or modify your marketplace bank deposit accounts, ACH routing numbers, tax identification numbers (SSN/EIN), or payout methods.
  • Consumer Payment Card Data: Retail transactions occur directly between the consumer and the respective marketplace (Amazon, TikTok, Walmart, etc.). We never hold, process, or transmit consumer credit card numbers.
SECTION 04Operational Purpose

4. How Data Powers Operations

All collected information is utilized strictly to deliver, evaluate, and safeguard your marketplace operations. Specific uses include:

  • Diagnostic Audits: Evaluating listing SEO indexing, search volume gaps, Buy Box suppression, ad wastage, and inventory strandedness.
  • Listing & Catalog Management: Building structured parent-child variations, backend search terms, A+ content, and flat-file inventory feeds.
  • PPC & Advertising Management: Conducting negative keyword harvesting, bid optimizations, dayparting schedules, and TACoS reporting.
  • Customer Inquiry SLAs: Responding to buyer messages, returns, and dispute cases within mandatory marketplace SLA response windows (sub-24hr).
  • Performance Reporting: Compiling bi-weekly GMV summaries, advertising efficiency reports, and executive roadmap reviews.
SECTION 05Confidentiality Guarantee

5. Non-Disclosure & Anti-Brokerage Guarantee

We do not sell, rent, license, trade, or monetize client store metrics, catalog information, customer lists, or contact details under any circumstance.

All internal personnel assigned to client accounts—including operations managers, catalog engineers, and PPC strategists—are bound by strict confidentiality agreements. Your supplier identities, landed product costs, margin formulas, and unreleased SKU plans remain your exclusive commercial trade secrets.

Aggregated or anonymized platform benchmarking metrics (e.g., general category conversion trends) may only be used internally to optimize our software and operational SOPs, and will never identify your brand, store, or proprietary sales volume.

SECTION 06Integrations & Subprocessors

6. Marketplace APIs & Authorized Subprocessors

In order to operate your stores and provide seamless communications, we interact with select secure enterprise services:

  • Official Marketplace APIs: Amazon Selling Partner API (SP-API), TikTok Shop Partner Center, Walmart Marketplace Developer Portal, and Shopify Admin API. All API calls comply with each platform's respective Data Protection Policy (DPP) and Acceptable Use Policy (AUP).
  • Transactional Email Infrastructure (Resend): Audit requests and inquiry submissions submitted through our website forms are dispatched securely via Resend directly to our operations team inbox. Resend processes data strictly as an encrypted email relay.
  • Calendar Scheduling (Cal.com): When booking an introductory discovery call, appointment details are managed securely via Cal.com's encrypted scheduling infrastructure.
  • Direct Client Operations Channels (Slack): Clients subscribed to our Growth and Scale retainers are provisioned dedicated, private Slack Connect channels for real-time daily communications.
SECTION 07Technical Protections

7. Security & Credential Hygiene

We implement physical, administrative, and technical safeguards engineered specifically for e-commerce agency workflows:

  • Encryption in Transit & at Rest: All web traffic and form submissions use TLS 1.3 encryption. Operational reports and catalog archives are stored on AES-256 encrypted cloud storage.
  • Mandatory Multi-Factor Authentication (MFA): All workstations and agency user accounts require hardware or app-based 2FA to access client consoles.
  • Role-Based Access Controls (RBAC): Only the designated operations lead and catalog specialist assigned to your account are granted secondary access to your seller portal.
  • Continuous Session Auditing: Automated session timeouts and workstation security policies prevent unauthorized portal access.
SECTION 08Lifecycle & Termination

8. Data Retention & Clean Offboarding Protocol

We retain data only as long as necessary to fulfill the specific purpose for which it was gathered:

  • Store Audit Submissions: Diagnostic form data is retained for 90 days following audit delivery to facilitate follow-up inquiries, after which it is permanently purged unless the client proceeds to a retainer agreement.
  • Offboarding Access Revocation: Upon termination or conclusion of a management retainer, we promptly assist client administrators in deleting all secondary delegated user permissions. Within 30 days of formal offboarding, all client operational exports and ad campaign files are securely scrubbed from our systems.
SECTION 09State Regulatory Rights

9. California Privacy Rights (CCPA / CPRA)

If you are a resident of California or represent a business entity operating under California jurisdiction, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), affords you specific rights regarding your personal information:

Right to Know & Access

Request disclosure of the specific categories and pieces of personal information collected about you.

Right to Deletion

Request permanent deletion of your personal data, subject to legal accounting retention requirements.

Right to Non-Discrimination

We never deny services, charge differing retainers, or provide varying service quality if you exercise privacy rights.

Right to Opt-Out

Because we never sell personal information, no opt-out exclusion mechanism is necessary.

To exercise any California privacy rights, submit a verified request to Noomoh194@gmail.com with the subject line “California Privacy Request”.

SECTION 10Inquiries & Governance

10. Contact Our California Operations Desk

If you have inquiries, audit verification questions, or formal governance requests concerning this Privacy Policy, please contact our California headquarters directly:

CALI ECOMMANAGEMENT LLC — Privacy & Compliance Office
Physical Operations: 9747 Businesspark Ave #255, California, USA
Compliance Email: Noomoh194@gmail.com
Operations Phone: +1 (619) 771-2691
Operating Hours: 8:00 AM – 6:00 PM PST (Monday – Friday)

We review and update this policy periodically to reflect evolving marketplace API protocols and privacy regulations. Any material modifications will be posted to this page with an updated effective revision timestamp.