Privacy Policy
This policy explains the personal information handled when you visit NichePro, create an account, use research and Book Lab tools, subscribe, or join the affiliate program.
- Mailing address
- info@nichepro.app
- Legal contact
- info@nichepro.app
- Website
- https://www.nichepro.app
This deployment has not published all required operator details. No sample values are shown. Configure the following variables before public launch:
LEGAL_ENTITY_JURISDICTIONLEGAL_ENTITY_REGISTRATION_NUMBERLEGAL_EU_REP_STATUS
1. Scope and roles
Multimedia Publishing LLC operates the NichePro service. For personal information collected through the public website, accounts, billing, support, and affiliate program, Multimedia Publishing LLC generally acts as the controller or business that determines why and how the information is used.
This policy applies to the NichePro website, web application, related emails, and public referral and affiliate pages. It does not govern third-party websites, Amazon or Kindle Direct Publishing, Stripe-hosted pages, or services that publish their own privacy notices.
Workspace owners and team members should not upload personal information that they are not authorized to use. If a workspace processes information for another organization, that organization remains responsible for its own notices, legal basis, and instructions.
Back to top2. Information we collect
The information collected depends on the features you use. NichePro does not store full payment-card numbers, card verification codes, or bank credentials; those details are handled by Stripe.
- Account and identity data: email address, authentication identifiers, first and last name, phone number, country, language, timezone, and account preferences.
- Workspace and billing data: workspace membership and role, legal or company name, billing and invoice email, address, country, tax or VAT identifiers, Italian fiscal code, PEC email or electronic-invoice recipient code when supplied, Stripe customer and subscription references, invoice references, plan, currency, and subscription status.
- Product content: niches, keywords, marketplaces, ASINs, book ideas, research inputs, prompts, project settings, uploaded or entered text, generated titles, descriptions, covers, tables of contents, validation results, and edits or selections you save.
- Usage and technical data: pages and features used, timestamps, request status, browser or device information, session and security records, approximate location inferred from network or billing data, and diagnostic information needed to operate and secure the service.
- Affiliate data: applicant name and email, audience type and size, primary channel, website, application message, locale, affiliate link or coupon, referrer, user agent, click and checkout events, conversion and commission records, and related Stripe invoice or subscription references.
- Communications: messages, support requests, account-deletion confirmation, survey or feedback responses, and email-delivery events.
- Public marketplace data: book listings, categories, ranks, prices, ratings, reviews, keywords, publishers, and other information available from Amazon or data providers. This data is mainly about publications, but may include author, reviewer, or publisher names that are publicly displayed.
3. Sources of information
- Directly from you when you register, complete settings, subscribe, create a project, apply as an affiliate, or contact us.
- Automatically from your browser and the service through essential cookies, preference storage, server logs, authentication records, and affiliate referral events.
- From workspace owners or administrators who invite you or manage workspace membership.
- From Stripe for subscription, invoice, tax, payment status, and fraud-prevention information; NichePro receives provider references and status data rather than complete card details.
- From Amazon public pages and specialized research providers such as Keepa, DataForSEO, ScraperAPI, and Bright Data when a feature requests marketplace research.
4. Why we use information and our legal bases
| Purpose | Examples | EEA/UK legal basis |
|---|---|---|
| Provide the service | Authenticate users, maintain workspaces, run research and generation tools, save projects, and provide requested results. | Performance of a contract or steps requested before entering a contract. |
| Billing and subscriptions | Create Stripe Checkout sessions, manage plans, calculate tax, issue or retain billing records, and prevent duplicate or fraudulent transactions. | Contract; legal obligations; legitimate interests in secure billing. |
| Improve and protect NichePro | Debug failures, measure feature reliability, prevent abuse, maintain audit records, and improve workflows and prompts. | Legitimate interests, balanced against user rights; consent where law requires it. |
| Communicate | Send authentication, billing, security, trial, service, and requested support messages; send product updates only when allowed and according to preferences. | Contract, legitimate interests, legal obligations, or consent depending on the message. |
| Affiliate program | Review applications, attribute referrals, calculate commissions, detect misuse, and administer payouts. | Steps before a contract, contract, and legitimate interests; consent for storage where required. |
| Compliance and claims | Respond to lawful requests, enforce terms, preserve evidence, protect users, and meet tax, accounting, and consumer-law duties. | Legal obligation and legitimate interests in establishing or defending legal claims. |
5. Service providers and disclosures
We disclose only the information reasonably needed for the relevant service. Provider availability and routing may vary by feature, deployment, marketplace, and account configuration.
We may also disclose information to professional advisers, insurers, auditors, authorities, courts, or transaction counterparties when reasonably necessary for compliance, security, a corporate transaction, or legal claims. We do not disclose personal information to data brokers for payment.
| Provider | Role | Information involved |
|---|---|---|
| Vercel | Website, hosting, serverless functions, and delivery | Requests, network and diagnostic data, and application payloads handled by hosted functions. |
| Supabase | Database, authentication, session management, and storage | Accounts, sessions, workspaces, saved projects, settings, and application records. |
| Stripe | Checkout, subscriptions, invoices, tax, payment status, and billing portal | Identity and billing details, customer and subscription references, transaction status, tax and fraud-prevention data. |
| OpenAI | AI-assisted text analysis, generation, translation, and cover-image drafts | Prompts, selected project context, generated output, and technical request data. Do not submit sensitive personal information in prompts. |
| Resend | Transactional and service email delivery | Recipient email, message content, and delivery events. |
| Keepa | Amazon catalog, price, rank, rating, and product-history data | ASINs, marketplace, and research queries. |
| DataForSEO | Search, keyword, and ranking data | Keywords, marketplace or location settings, and research job identifiers. |
| ScraperAPI and Bright Data | Retrieval of public Amazon pages and review data | Public URLs, ASINs, marketplace requests, and technical job data. |
| Render | Background worker hosting where enabled | Research job identifiers, provider requests, results, and operational logs. |
6. AI features and marketplace research
NichePro uses automated systems to analyze research inputs and generate recommendations, text, and image drafts. Generated material may be inaccurate, incomplete, similar to existing material, or unsuitable for publication. Users should review outputs and avoid entering health, financial, government-identification, or other sensitive personal information in prompts.
AI features assist editorial work; they do not make solely automated decisions about a user that produce legal or similarly significant effects. Automated security, fraud, billing, or access signals may help apply documented rules or flag an issue, while important adverse account actions remain subject to the applicable rule and available review. An authenticated user can raise a question through Privacy Choices or use the legal contact shown on this page.
Marketplace research may send a keyword, ASIN, public URL, marketplace, language, or related job parameters to the provider selected for that feature. NichePro is not affiliated with Amazon or Kindle Direct Publishing, and third-party marketplace services remain governed by their own terms and privacy practices.
We do not use account content to train a proprietary general-purpose model. External AI providers process submitted content under the applicable service configuration and contract; their retention and model-training controls may vary, so only submit material you are authorized to process.
Back to top8. Retention and account deletion
We retain personal information only for as long as reasonably necessary for the purposes described here, including providing an active account, maintaining security and audit records, administering affiliate commissions, complying with tax and accounting duties, resolving disputes, and enforcing agreements. Different records therefore have different retention periods.
When you delete your account through account settings, NichePro attempts to cancel subscriptions for workspaces you administer and deletes the Supabase authentication user. Related records configured with cascade deletion are removed, while collaborative, billing, security, affiliate, or legal records may be retained, de-identified, or have the user reference removed where necessary for other users, statutory retention, fraud prevention, or legal claims.
Stripe and other providers retain information under their own legal duties and retention policies. Backup copies may persist for a limited recovery cycle before being overwritten. A specific statutory retention period applies where required by tax, accounting, payment, or corporate law.
Back to top9. Security and international transfers
We use access controls, row-level database policies, server-side secrets, signed Stripe webhooks, encrypted transport, provider vaults for card data, and operational monitoring designed to protect information. No service can guarantee absolute security, and users are responsible for protecting credentials and workspace access.
NichePro and its providers may process information in the United States and other countries. Where EEA, UK, Swiss, or other transfer rules apply, transfers must rely on an available legal mechanism, such as an adequacy decision, approved contractual clauses, or another lawful safeguard, together with supplementary measures where appropriate.
Back to top10. EEA, UK, Switzerland, and Italy rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and ask for information about transfer safeguards. You may also object to direct marketing at any time. Some requests may be limited when retention is required by law or needed for legal claims or the rights of others.
We may need to verify identity and clarify the request. Authorized representatives must show valid authority. We respond within the period required by applicable law and explain any lawful extension or refusal.
Authenticated users can submit a privacy-rights request through the NichePro Privacy Choices center. A submission or receipt confirms that the request was received; it does not guarantee an automatic outcome and does not remove identity verification, legal exceptions, or the rights of other people.
People in Italy may complain to the Garante per la protezione dei dati personali. People elsewhere in the EEA may complain to the supervisory authority where they live, work, or believe an infringement occurred. UK and Swiss residents may contact their respective data-protection authorities.
11. United States and California privacy rights
Residents of California and other U.S. states may have rights to know or confirm processing, access, correct, delete, or obtain a portable copy of personal information, and to appeal certain decisions, subject to the scope and exceptions of the applicable state law.
Based on the current service configuration, NichePro does not sell personal information for money and does not share personal information for cross-context behavioral advertising. It does not use sensitive personal information to infer characteristics or for purposes outside those permitted by applicable law. Because no cross-context behavioral advertising is active, a Global Privacy Control signal does not change current advertising behavior; if those practices change, legally required opt-out signals will be processed.
California residents will not receive discriminatory treatment for exercising applicable privacy rights. An authorized agent may submit a request, but we may verify both the agent's authority and the consumer's identity. Metrics and category disclosures required by law will be provided when the relevant statutory thresholds apply.
Back to top12. Children
NichePro is a business and publishing-research service not directed to children under 13. Users must also meet the minimum age required to enter a binding contract where they live. We do not knowingly sell or share the personal information of children for behavioral advertising. If you believe a child submitted personal information without appropriate authorization, use the contact details shown on this page when available.
Back to top13. Changes and contact
We may update this policy when the service, providers, or law changes. Material changes will be communicated through the service, email, or another appropriate channel before they take effect when required. The version identifier on this page identifies the current published text.
Privacy requests should use the operator contact details displayed near the top of this page when configured. Account deletion is also available from authenticated account settings. If no dedicated contact detail is displayed, the deployment has not published one and must configure the legal contact before treating this page as its sole rights-request channel.
Back to top