Privacy Policy

Last updated: 9 July 2026

1. Who we are

ReclaimHQ is operated by ReclaimHQ LTD, a company registered in England and Wales (company no. 17042386, 4 Leckwith Drive, Bridgend, CF31 4JH). We are the data controller for the personal data described in this policy and are registered with the Information Commissioner's Office (ICO). If you have any questions about this policy, contact us at hello@reclaimhq.uk.

2. What data we collect

When you use ReclaimHQ, we collect:

  • Account information: your name, email address, company name, and password (hashed). If you link a Discord account for support, we store your Discord user ID.
  • Amazon order data: removal order IDs, product names, ASINs, SKUs, tracking numbers, shipment dates, reimbursement records, customer return records, inventory data, support case content, and related Amazon Marketplace information that you import via the Chrome extension or that is retrieved via the Amazon Selling Partner API on your behalf after you authorise access.
  • Payment information: processed securely by Stripe. We do not store your card details.
  • AI conversation data: messages exchanged with the Tarquin claims assistant and the Susi support assistant, including your inputs and AI-generated responses. Conversations are stored so your chat history is available to you.
  • Security and service logs: your IP address, browser user agent, approximate location (country), and a device identifier, recorded in our append-only security audit log when you sign in or perform sensitive actions. We do not use third-party analytics or advertising trackers.
  • Support content: support tickets, bug reports, and feature requests you submit, including messages exchanged in our Discord support channels.
  • Affiliate payout details: if you join our affiliate programme, the invoicing details you provide and the bank details we need to pay you (bank details are encrypted at rest).

3. How we use your data

We use your data to:

  • Provide and improve the ReclaimHQ service, including syncing your marketplace data, tracking claim deadlines, and drafting claims with the AI assistant.
  • Process your subscription payments via Stripe.
  • Send transactional and service emails (account confirmation, password resets, billing receipts, claim-deadline alerts).
  • Respond to support requests via email and Discord.
  • Occasionally invite you to leave a review, and send marketing emails where permitted (every marketing email carries a one-click unsubscribe).
  • If you choose to join a liquidation operator's organisation, share your removal stock data (products, quantities, conditions, costs, and photos) with that operator from a dispatch date you control.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Lawful bases for processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract: providing the service you subscribe to, including account management, syncing your marketplace data, processing your claims data, billing, and transactional email.
  • Legitimate interests: security logging and the audit trail, fraud and abuse prevention (including rate limiting), service emails about problems affecting your account, review invitations, and the first-party rhq_aff referral/affiliate attribution cookie set when you arrive via a referral link (see section 9).
  • Consent: marketing emails, and sharing your data with a liquidation operator you choose to join.
  • Legal obligation: retaining accounting and billing records as required by UK tax law.

Where we rely on consent, you can withdraw it at any time.

5. Data storage and security

Your data is stored securely using Supabase (PostgreSQL) with row-level security policies ensuring you can only access your own data. All connections are encrypted via TLS. Passwords are hashed using bcrypt. API keys are stored as one-way hashes.

Application-level encryption:commercially sensitive fields, including cost of goods (COG), target sale prices, removal fees, recovery amounts, and invoice filenames, are encrypted at rest using AES-256-GCM with per-user encryption keys. Each user's data is encrypted with a unique key, meaning that even platform administrators browsing the database cannot read your commercial figures. Data is only decrypted in memory when served to your authenticated session.

The Chrome extension does not store your Amazon credentials, it only imports the order data you choose to send to ReclaimHQ.

6. Amazon Marketplace data

When you connect your Amazon Seller Central account to ReclaimHQ, we access your Amazon Marketplace data solely to provide the ReclaimHQ service to you. This includes removal order data, reimbursement records, inventory information, customer return records, and financial transaction data.

  • Purpose limitation: We use your Amazon data only to provide, maintain, and improve the ReclaimHQ service for your account. We do not use your Amazon data for advertising, profiling, or any purpose unrelated to the service you have authorised.
  • No competitive use: ReclaimHQ Ltd and members of its team operate their own Amazon selling businesses. We will never use your Amazon Marketplace data, including your product catalogue, ASINs, SKUs, suppliers, cost prices, sales, or inventory, to inform, source, or benefit our own (or any other party's) selling activity, to identify or replicate products, or to compete with you in any way. Internal access is limited to operating and supporting the service and is recorded in a tamper-evident audit log.
  • No sale or sharing: We do not sell, rent, license, or share your Amazon Marketplace data with any third party, except as necessary to operate the service (for example, encrypted storage via our database provider).
  • Data retention: Marketplace data linked to an active subscription is retained for the duration of your subscription to provide continuity of service. After your subscription lapses, marketplace records are automatically and permanently deleted once they are more than 18 months old (see section 11).
  • Revocation and deletion: Disconnecting your Amazon account (or any other integration) stops the sync and revokes our access tokens immediately. Marketplace records already imported into your account remain available to you until you ask us to delete them, which you can do at any time by emailing hello@reclaimhq.uk (actioned within 30 days), or until the automatic 18-month purge described above removes them after your subscription lapses.
  • Security: All Amazon data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Commercially sensitive fields are additionally encrypted using AES-256-GCM with per-user encryption keys, as described in section 5.

7. Third-party services

We use the following third-party services to operate ReclaimHQ:

  • Supabase, database, authentication, and file storage (our primary data store).
  • Vercel, application hosting and serverless compute.
  • Stripe, payment processing. Card details go directly to Stripe and never touch our servers.
  • Resend, transactional and service email delivery.
  • Anthropic, AI model provider powering the Tarquin claims assistant and Susi support assistant. Conversation content and relevant order and case context are sent to Anthropic's API to generate responses. Anthropic's commercial terms exclude using our customers' data to train its models.
  • Upstash, rate limiting and abuse prevention infrastructure. Processes IP addresses and hashed identifiers (such as hashed email addresses and user IDs).
  • Discord, our primary support channel. Paying customers link a Discord account; we store your Discord user ID and support conversations take place on Discord's platform.
  • Trustpilot, review invitations. If we invite you to leave a review, Trustpilot receives your name and email address.
  • Ship24 and UPS, carrier tracking used to estimate parcel arrival dates for liquidation operators. They receive tracking numbers only.
  • Google, optional Google Drive invoice sync (only when you connect it) and "Sign in with Google".
  • eBay, optional resale integration. Only if you connect your own eBay account; listing content and order data then pass between ReclaimHQ and eBay under your authorisation.

Amazon and eBay act on your own authorisation as platforms you have chosen to connect. Each service processes data under its own data-processing terms consistent with UK GDPR. We maintain a canonical, up-to-date list of our subprocessors at reclaimhq.uk/subprocessors.

8. International transfers

Some of our providers process data outside the UK. Vercel, Stripe, Anthropic, Resend, Upstash, Discord, and Trustpilot are US-based or process data in the United States. Where personal data leaves the UK, we rely on safeguards recognised under UK GDPR: the UK Addendum or International Data Transfer Agreement (IDTA) incorporated with each provider's standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it.

9. Cookies

We use first-party cookies only. We do not use third-party advertising or cross-site tracking cookies, and we do not sell your data.

  • Authentication and security cookies (strictly necessary): keep you logged in and protect your account. The service cannot function without these.
  • Referral and affiliate attribution cookie (rhq_aff / referral cookie): if you arrive via a referral or affiliate link, we set this first-party cookie for up to 90 days to record which referrer or affiliate introduced you, so we can credit them if you subscribe. We set it on the basis of our legitimate interest in running our own referral programme (not third-party advertising): it contains only an attribution code, is never used for advertising or profiling, and is not shared with third parties. You can clear or block it at any time via your browser, and it does not affect your ability to sign up or use ReclaimHQ.

10. Your rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access, request a copy of your personal data.
  • Rectification, correct inaccurate data.
  • Erasure, request deletion of your data.
  • Portability, receive your data in a machine-readable format. You can export your order and claims data as CSV from within the app at any time, and we will provide a fuller export on request.
  • Restriction, ask us to limit how we process your data.
  • Objection, object to processing of your data, including any processing based on legitimate interests.
  • Withdraw consent, at any time, where processing is based on consent.

To exercise any of these rights, email hello@reclaimhq.uk. We action requests within one month.

You also have the right to complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concerns first, so please consider contacting us at hello@reclaimhq.uk before raising a complaint.

11. Data retention

We retain your account data for as long as your account is active. Marketplace data linked to an active subscription is retained for the duration of your subscription to provide continuity of service. After a subscription lapses, core marketplace records (removal orders and their items, reimbursements, customer returns, and inbound shipments) are automatically and permanently deleted once they are more than 18 months old. Other imported records (such as support case transcripts and inventory ledger data) are deleted when you request deletion. If you cancel your subscription and request account deletion, we will delete your data within 30 days of the request. Billing records may be retained for up to 7 years as required by UK tax law. Deleted records may persist in encrypted database backups for a short period until backup rotation completes.

12. Security logging and incident response

We maintain append-only security audit logs that record authentication events, data exports, account changes, and administrative actions. These logs are retained for a minimum of 90 days and are protected by integrity controls.

In the event of a personal data breach, we will notify the ICO within 72 hours of becoming aware of it where feasible, as UK GDPR requires, and we will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email. Continued use of the service after changes constitutes acceptance of the updated policy.