1. Scope and responsible entity
This policy applies to the AL ANSB public website and product-opportunity and commercial-feasibility application. The approved legal-entity name and contact method are displayed only when configured.
Independent stores, operating-system providers, linked market sources and external support services process information under their own terms and policies.
2. Account, authentication and device data
The service may process account information, authentication data, password-security records, device identifiers, registered-device status and device history for account access, security and device-control functions.
Authentication secrets and service credentials must not be exposed in pages, logs or client-side code.
3. Product evidence and scan inputs
Submitted evidence may include product titles, descriptions, links, barcode information, images, PDF documents, package details, product attributes and user corrections.
Uploaded materials may be commercially sensitive. Users should submit only authorised content and remove unrelated personal or confidential information.
4. Analysis, reports and saved opportunities
The service may process product-scan data, evidence assessments, market-analysis inputs, selected markets and channels, landed costs, commercial assumptions, source results, generated reports and saved opportunities.
Saved opportunities may include user-selected status, notes and report-linked information required to track a commercial decision.
5. Plans, credits and purchases
The service may process plan and credit records, reservations, consumption, subscription records, transaction history, purchase-validation records, restoration requests, product identifiers and store transaction status.
Eligible Apple App Store and Google Play records are validated through supported backend workflows; those providers also process information under their own policies.
6. Technical data
Server logs, security logs, error logs, request metadata, session information and browser-storage records may be processed to operate, secure, diagnose and maintain the service.
Logs should be limited to operationally necessary data and must not contain passwords, private keys, purchase tokens or other secrets.
7. AI processing and market sources
Submitted evidence and analysis inputs may be processed by configured AI services to support product identification, evidence review and commercial analysis. Approved processors and transfer arrangements require production legal and technical review.
Third-party market sources may receive ordinary request data such as IP address, user agent or request metadata when accessed by an approved backend or provider.
8. Purposes of processing
Information may be used to authenticate users, control devices, process evidence, identify products, run requested analyses, generate reports, manage opportunities, administer plans and credits, validate purchases, restore subscriptions, prevent misuse, secure the service and provide support.
Information should not be repurposed for advertising or unrelated profiling unless configuration, notices and consent controls are updated.
9. Cookies and browser storage
Public informational pages do not require advertising or analytics storage by default. Essential session, authentication, security, device, preference or consent storage may be used only when the deployed service actually requires it.
The Cookie Policy must be updated before optional analytics or advertising technology is introduced.
10. Retention
Retention should reflect operational need, account status, scan and report lifecycle, transaction-record requirements, security obligations and applicable law.
Production schedules require approval. Data should be deleted or anonymised when no longer required, subject to valid legal, security, dispute or transaction needs.
11. Security
The service should use access control, encrypted transport, secret management, input validation, safe file handling, logging controls, database protection and monitoring appropriate to the information processed.
No internet service can guarantee absolute security. Users should protect credentials and devices and report suspected unauthorised access through the configured contact method.
12. User rights
Depending on applicable law, users may have rights of access, correction, deletion, restriction, objection, portability or consent withdrawal. Exact rights and procedures require jurisdiction-specific legal review.
Requests should use the configured privacy or support channel and may require identity verification.
13. Eligibility, updates and contact
The service is intended for users able to enter binding account and commercial arrangements; age and business-user rules require legal review.
This policy may change when services, processors, laws or data practices change. The approved effective date and contact method must come from production configuration.
















