XP Strategy Corp Website Privacy Policy
Effective Date: September 14, 2026 · Last Updated: September 14, 2026
XP Strategy Corp (“XP Strategy,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit https://xpstrategy.com/ or any website, landing page, funnel, form, or other online service operated by XP Strategy that links to this Privacy Policy (collectively, the “Site”), and when you otherwise interact with us in the ways described below.
XP Strategy is a United States advertising agency that helps businesses plan, manage, and optimize advertising on Amazon, Walmart, and Target, including their advertising platforms. Because of the nature of our work, we handle two very different kinds of information, and this Privacy Policy is careful to keep them separate. It governs the personal information we collect as a business in our own right (for example, from Site visitors, prospective clients, business contacts, event participants, and job applicants). It does not govern the client business data and advertising-account data that we access and process on behalf of our clients under a service agreement, which is addressed in Section 19 and governed primarily by the client contract.
By using the Site, you acknowledge the practices described in this Privacy Policy.
1. Introduction, Scope, and Our Roles
Who we are. XP Strategy Corp is a New Jersey corporation, with its principal place of business at 1405 NJ-35, Suite 209, Ocean Township, NJ 07712. You can reach our privacy contact at privacy@xpstrategy.com or at the mailing address in Section 21.
What this policy covers. This Privacy Policy applies to personal information we collect and process:
- Through the Site and its forms, funnels, and landing pages.
- Through marketing, advertising, sales, and prospecting activities.
- Through business operations, including managing relationships with prospective clients, clients, vendors, partners, and business contacts.
- Through recruiting and evaluating job applicants.
What this policy does not cover. This Privacy Policy does not govern information that XP Strategy processes solely on behalf of a client in connection with advertising management, consulting, account analysis, reporting, or related professional services. That information, including data accessed inside a client’s Amazon, Walmart, or Target advertising and marketplace accounts, is governed by our agreement with the applicable client and, where appropriate, a separate data-processing agreement. Section 19 describes how we treat that information.
Our roles (controller and processor). Data protection laws distinguish between the party that decides why and how personal information is processed and the party that processes it on another’s instructions. Those roles matter here:
- For personal information collected through the Site and through our own marketing, sales, prospecting, recruiting, and business operations, XP Strategy is the “controller” (and, under California law, the “business”). This Privacy Policy describes how we act in that role.
- For information we access and process on behalf of a client to deliver contracted services, including data inside the client’s own marketplace and advertising accounts, XP Strategy acts as a “processor” (and, under California law, a “service provider” or “contractor”). In that role we act only on the client’s documented instructions, and the client, as controller, is primarily responsible for the notices and rights owed to the individuals whose data appears in those accounts.
Territorial scope. The Site is operated from the United States and is directed to business audiences in the United States. It is not directed to the general public in the European Economic Area (EEA) or the United Kingdom (UK). Where we nonetheless process personal information of individuals in California and other U.S. states, or of individuals in the EEA or UK, the corresponding provisions of this Privacy Policy (Sections 9, 10, 11, and 14) apply to that processing.
Key definitions. In this Privacy Policy, “personal information” (or “personal data”) means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “Sensitive information” or “sensitive personal information” means the narrower categories treated as sensitive under applicable law, such as government identifiers, precise geolocation, account credentials, racial or ethnic origin, health information, biometric data, and the contents of certain communications. Terms such as “sale,” “share,” “targeted advertising,” “profiling,” “processing,” “controller,” “processor,” “service provider,” and “consumer” have the meanings given to them in the specific laws referenced in this Privacy Policy.
2. Categories of Personal Information We Collect
We collect the categories of personal information described below. Not every category is collected about every individual, and much of it is optional.
A. Identifiers and contact information. Name, business name, job title or role, business email address, telephone number, mailing or business address, and similar contact details you provide through contact forms, lead forms, booking tools, or correspondence.
B. Commercial and marketing information. The services you are interested in, the marketplaces or platforms you sell on, website or store addresses, information about your products, sales, and advertising activity, budget indications, marketing goals, meeting and booking details, the stage of a prospective engagement, and the content of your inquiry or free-text message.
C. Communications content. The contents of emails, form submissions, text messages (where applicable), and, where used and where consent is obtained if required, recordings and transcripts of calls, video meetings, or webinars (for example, through meeting-recording tools such as Fathom or Zoom).
D. Internet, network, and device information. Internet Protocol (IP) address, browser type and version, device type, operating system, referring and exit URLs, pages and content viewed, links clicked, clickstream and navigation activity, form interactions, session information, and cookie, pixel, and similar online or advertising identifiers.
E. Approximate geolocation. General geographic location (such as city, state, or region) derived from an IP address. We do not intentionally collect precise geolocation through the Site.
F. Marketing and engagement information. How you interact with our emails and other communications, marketing attribution and campaign-source information, event and webinar registrations, survey responses, testimonials, and feedback.
G. Professional and employment information of business contacts. Professional details associated with business prospects and contacts, such as company, role, and business context. We note this category expressly because California’s exemptions for business-to-business contacts and for professional context sunset on January 1, 2023, so California-resident business contacts are now fully covered by California privacy law and are not treated as out of scope.
H. Job-applicant information. Where you apply for a position, resumes, work history, qualifications, references, and related application materials. We may use tools that assist in evaluating job applications, including AI-assisted review, as described in Sections 10 and 11. A human makes all final hiring decisions.
I. Inferences. Limited inferences drawn from the above, such as apparent service interest or marketing preferences.
J. Billing and payment information. Where you become a client, billing contact details and transaction records associated with our services. The Site does not process payments. Billing for professional services is handled separately under the client service agreement, and XP Strategy does not collect payment-card numbers through the Site.
Sensitive information. For a business-to-business agency, our honest position is that we collect little or no sensitive personal information through the Site. We do not intentionally collect government identification numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, biometric identifiers, or similar sensitive categories through general Site forms, and we ask that you not submit them (see the caution in Section 4). Payment and billing information is handled as described in category J above; the Site does not process payments, and billing for professional services is handled separately under the client service agreement. To the extent any sensitive information is nonetheless collected, we treat it in accordance with applicable law.
Statutory category mapping (California). Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, “CCPA/CPRA”), applies, the categories above correspond to the following enumerated statutory categories: identifiers; customer-records information; commercial information; internet or other electronic network activity information; audio, electronic, visual, or similar information (for example, recorded calls, video meetings, and webinars); approximate geolocation information; professional or employment-related information; and inferences. We describe the sources, purposes, and disclosures of these categories throughout this Privacy Policy and in Section 9.
Client business data (handled as a processor). Separately, and outside the consumer-rights mechanics of this Privacy Policy, we handle client business data such as advertising performance metrics, sales and margin data, product identifiers and ASINs, listing and campaign data, and account credentials or API access tokens for a client’s own marketplace and advertising accounts. We handle that data as a processor on the client’s behalf, as described in Section 19, and it is governed by the client agreement rather than by this Privacy Policy.
3. Sources of the Information
We obtain personal information from the following sources:
- Directly from you. Through Site forms, funnels, and landing pages, email, telephone, text messages (where applicable), booked calls and consultations, and event, webinar, or resource registrations.
- Automatically. Through cookies, pixels, tags, local storage, software development kits, server logs, and similar technologies as you interact with the Site and our communications (see Section 6).
- From third parties. From analytics and advertising providers, social-media and business-networking platforms, event organizers, referral partners, publicly available sources, and business directories. We use only the third-party sources actually engaged; we do not list vendors or data brokers we do not use.
- From prospecting and public sources. From publicly available and business-networking sources used for business-to-business prospecting (for example, professional networks such as LinkedIn), where applicable.
- In the course of client work (processor activity). For account-level work, from within a client’s own Amazon, Walmart, or Target advertising accounts, accessed under the client’s authorization. This is processor activity described in Section 19 and is not collection of personal information for our own purposes.
4. Purposes for Which We Use Information
We use personal information for the following purposes:
- Operate, maintain, secure, and improve the Site and our communications.
- Respond to inquiries, consultation requests, and correspondence, and provide quotes, audits, analyses, proposals, recommendations, and service plans.
- Evaluate whether our services may be appropriate for a prospective client and manage the pre-sales relationship.
- Provide, administer, and manage our advertising-management, consulting, reporting, content, and related services and the associated client relationships.
- Send administrative, service-related, educational, and marketing communications, including newsletters, nurture sequences, and event invitations, subject to the choices described in Sections 6, 9, and 13.
- Personalize Site content and communications, and measure Site traffic, advertising performance, and marketing attribution.
- Conduct analytics, research, benchmarking, and business planning.
- Detect, investigate, and prevent fraud, misuse, security incidents, and unlawful activity, and debug and maintain the Site.
- Protect the rights, property, safety, and security of XP Strategy, our personnel, our clients, and other users.
- Recruit and evaluate job applicants, including through tools that assist applicant evaluation, with a human making the final hiring decision (see Sections 10 and 11).
- Comply with legal, regulatory, tax, accounting, and contractual obligations, and establish, exercise, or defend legal claims.
- Carry out any other purpose disclosed at the time of collection or to which you consent.
Purpose limitation. We will not process personal information for materially different, incompatible, or unrelated purposes without providing additional notice or, where required, obtaining your consent.
Client-account limitation. We do not use our access to client marketplace or advertising accounts for our own marketing purposes, and we process client business data only in accordance with the client’s instructions and our agreement with the client.
5. Legal Bases for Processing (EEA and UK)
Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies to our processing of your personal information, we rely on one or more of the following legal bases:
- Consent (Article 6(1)(a)) for optional marketing communications, non-essential cookies and similar technologies, and any special-category data we ask to process. You may withdraw consent at any time, without affecting the lawfulness of processing already carried out.
- Performance of a contract or pre-contract steps (Article 6(1)(b)) to respond to your inquiry, evaluate a potential engagement, and deliver services you request.
- Legitimate interests (Article 6(1)(f)) to operate, promote, secure, and improve the Site and our services, to conduct business-to-business prospecting and marketing, to conduct analytics, and to protect against fraud and security risks, where those interests are not overridden by your interests or fundamental rights. You may object to processing based on legitimate interests as described in Section 10.
- Legal obligation (Article 6(1)(c)) to meet our legal, tax, accounting, regulatory, and record-keeping obligations.
- Special-category data (Article 9): we do not intentionally collect special-category data through the Site. Where any such data is processed, we rely on a specific Article 9 condition, most commonly your explicit consent.
Where providing personal information is a statutory or contractual requirement, or is necessary to enter into a contract, we will indicate this at the point of collection, and we will explain the consequences of not providing it (generally, that we may be unable to respond to your request or provide the relevant service).
6. Cookies, Analytics, and Advertising Technologies
The Site may use cookies and similar technologies, such as pixels, tags, local storage, and server logs, to support essential functions, remember preferences, understand Site usage, measure marketing performance, and, where enabled, deliver or measure advertising.
Categories of technologies we use:
- Strictly necessary technologies that support security and the basic operation of the Site.
- Functional technologies that remember your selections and improve usability.
- Performance and analytics technologies that help us understand how visitors find and use the Site.
- Advertising and targeting technologies that help measure campaigns, build audiences, and, where enabled, present relevant advertising.
- Social-media technologies that support sharing and interaction with third-party networks, which may set their own cookies.
Rough durations vary by technology: some cookies are session cookies that expire when you close your browser, while others are persistent cookies that remain for a defined period.
Specific tools currently in use. The Site currently uses Google Analytics and Google Tag Manager, deployed through the MonsterInsights plugin, to measure Site traffic and understand how visitors find and use the Site. The Site does not currently use the Meta Pixel, any other social-media advertising pixel, or any other advertising or targeting pixel. We may adopt additional analytics, advertising, or marketing technologies in the future, and we will update this Privacy Policy when we do.
Consent for non-essential cookies. The Site does not currently deploy a cookie consent banner or consent-management platform. As noted in the territorial-scope discussion in Section 1, the Site is directed to business audiences in the United States and is not directed to the general public in the EEA or UK. Where applicable law requires opt-in consent before non-essential cookies or similar technologies are set, we will obtain that consent through an appropriate consent mechanism and will update this Privacy Policy and the Site accordingly.
Sale or share considerations. The Site does not currently deploy advertising or targeting pixels. Depending on applicable law, some uses of analytics cookies may nonetheless be considered targeted advertising, sharing, or a sale of personal information (including cross-context behavioral advertising) even when XP Strategy does not receive money in exchange for the information. See Section 9 for how to opt out.
Controlling cookies. You may be able to control cookies through your browser settings, and blocking certain technologies may affect Site functionality. You can also use the platform and industry opt-out tools described in Section 7. As described in Section 12, the Site does not currently respond to the Global Privacy Control (GPC) or other universal opt-out signals.
7. Your Advertising Choices
Several industry groups let you limit interest-based advertising across participating companies. You can review and set your preferences through the Digital Advertising Alliance at optout.aboutads.info, the Network Advertising Initiative at optout.networkadvertising.org, and, in Europe, Your Online Choices at youronlinechoices.eu. You can also manage ad and privacy settings directly within platforms such as Google. These controls are specific to each browser and device, so you may need to repeat them in more than one place, and opting out limits interest-based targeting rather than stopping all advertising.
8. How We Disclose Information
We disclose personal information to the categories of recipients described below. We do not disclose personal information except as described in this Privacy Policy.
A. Service providers and processors. We disclose information to vendors that support website hosting and infrastructure, data storage, forms and funnels, customer-relationship management and marketing automation, email and text-message delivery, scheduling and meeting-recording tools, analytics, security, recruitment, and professional services (such as legal, accounting, and insurance advisors). The current list of these providers is available to clients on request. These providers act as our service providers or processors under contracts that restrict their use of personal information to the purposes of providing services to XP Strategy and that require appropriate confidentiality and security protections, consistent with California service-provider requirements and GDPR Article 28 data-processing terms.
B. Analytics partners. We use analytics providers, such as Google, that collect information through cookies and similar technologies to help us understand Site usage and measure marketing performance. Depending on the arrangement and applicable law, some analytics activity may be treated as a “sale” or “share” of personal information for cross-context behavioral advertising rather than as a service-provider relationship. That processing may also be governed by the provider’s own privacy policy. The Site does not currently use advertising or targeting pixels.
C. Business partners. We may disclose information to referral partners, event partners, contractors, or consultants only when reasonably necessary to respond to a request, provide an agreed service, organize an event, or pursue a specific business relationship you have engaged in. We limit what we share to what is reasonably necessary for that purpose, and we expect these partners to protect the information and use it only for the agreed purpose.
D. Sub-processors and onward transfers. Where our service providers engage sub-processors, we require that the protections and use restrictions described in this Privacy Policy and in our contracts flow down to those sub-processors. We maintain a current internal sub-processor list, which is available to clients on request.
E. Legal and safety disclosures. We may disclose information when we reasonably believe disclosure is necessary to comply with law, regulation, subpoena, court order, or governmental request; enforce an agreement; protect legal rights; detect or prevent fraud or security incidents; or protect the safety, rights, or property of XP Strategy or another person.
F. Business transactions. Information may be disclosed or transferred as part of a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar business transaction. Where required, we will provide notice or obtain consent before information becomes subject to materially different privacy practices.
G. With your direction or consent. We may disclose information when you direct us to do so or otherwise provide consent.
Client confidential data. We do not disclose client confidential business data except to authorized sub-processors that are reasonably necessary to deliver services, under confidentiality obligations, as further described in Section 19.
9. Sale or Sharing, Targeted Advertising, and Profiling
Our position. XP Strategy does not sell personal information for money. The Site does not currently use the Meta Pixel or any other advertising or targeting pixel. However, some state privacy laws define “sale” and “share” broadly, and the use of analytics cookies (for example, Google Analytics) may be treated as a “sale,” a “share,” or “targeted advertising” under those laws even when no money changes hands.
Categories involved. Where such activity occurs, the categories of personal information potentially involved are internet and network activity information and online identifiers, disclosed to analytics providers such as Google. Apart from that context, XP Strategy does not sell or share the categories of personal information described in Section 2.
Your opt-out rights. Where applicable law provides them, you may opt out of the sale or sharing of personal information, opt out of targeted advertising, and opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise these rights, email privacy@xpstrategy.com, or use the browser and industry advertising controls described in Sections 6 and 7. As described in Section 12, the Site does not currently respond to the Global Privacy Control or other universal opt-out signals. A “Limit the Use of My Sensitive Personal Information” link is not required because XP Strategy does not collect sensitive personal information for those purposes.
Minors. XP Strategy does not knowingly sell or share the personal information of consumers under 16 years of age without opt-in consent, as described in Section 18.
No financial incentives. XP Strategy does not offer financial incentives or price or service differences in exchange for personal information.
10. Your U.S. State Privacy Rights and Appeal Process
Depending on where you live and subject to applicable exceptions, you may have the right to:
- Confirm whether we process your personal information and request access to it.
- Request correction of inaccurate personal information.
- Request deletion of personal information.
- Obtain a portable copy of certain personal information.
- Opt out of the sale or sharing of personal information and of targeted advertising.
- Opt out of certain profiling in furtherance of decisions that produce legal or similarly significant effects.
- Limit the use or disclosure of sensitive personal information (California), where applicable.
- Receive equal service and not be discriminated or retaliated against for exercising a privacy right.
Applicable laws. These rights arise under a growing set of U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); the New Jersey Data Privacy Act, effective January 15, 2025, which as the law of our home state we identify prominently; and the comprehensive state privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon (OCPA), Texas (TDPSA), Montana (MCDPA), Florida (Florida Digital Bill of Rights), Delaware, Iowa, Nebraska, New Hampshire, Tennessee, Minnesota, and Maryland (MODPA), together with the laws of Indiana, Kentucky, and Rhode Island that take effect on January 1, 2026. Each of these laws applies only to the extent its terms and thresholds cover XP Strategy’s processing.
Automated decision-making and applicant screening. We use tools that may assist in evaluating job applications, including AI-assisted review. A human makes all final hiring decisions, so these are not decisions made solely by automated means.
How to submit a request. To exercise a privacy right, email privacy@xpstrategy.com or write to XP Strategy Corp at the address in Section 21, using the request mechanics and verification described in Section 20. We may need to verify your identity before completing certain requests.
Response timelines. We generally respond to verifiable state-law requests within 45 days, with an extension where permitted by law and with notice to you. Requests are handled free of charge, except that we may charge a reasonable fee or decline to act on manifestly unfounded or excessive requests, as permitted by law.
Appeals. If we decline to act on your request, you may appeal by emailing privacy@xpstrategy.com with “Privacy Appeal” in the subject line. We will review the appeal and respond in writing with our decision, and the reasons for it, within the period required by applicable law (for New Jersey and the Virginia-model laws, generally within 45 to 60 days). If your appeal is denied, you may contact the attorney general or applicable regulator in your state. California residents may also contact the California Privacy Protection Agency or the California Attorney General.
Limits. These rights are not absolute. We may decline or limit a request where permitted by law, including where information must be retained to complete a transaction, provide a requested service, protect security, comply with law, exercise or defend legal rights, or preserve records required for legitimate business purposes.
A note on applicability. Some of the privacy laws referenced above may not currently apply to XP Strategy based on its size or the volume of information it processes, because many of these laws apply only to entities that meet consumer-count or data-sale-revenue thresholds. Where a law does not strictly apply, XP Strategy nonetheless aims to honor the core rights described above as a matter of good practice.
11. EEA and UK Individual Rights (GDPR and UK GDPR)
If you are located in the EEA or the UK and the GDPR or UK GDPR applies to our processing of your personal information, you have the following rights, subject to the conditions and exceptions in those laws:
- Access to your personal information and information about how we process it.
- Rectification of inaccurate or incomplete personal information.
- Erasure of personal information in certain circumstances.
- Restriction of processing in certain circumstances.
- Data portability for information you provided to us where processing is based on consent or contract and is carried out by automated means.
- Objection to processing based on our legitimate interests, and an absolute right to object to processing for direct marketing.
- Rights regarding automated decision-making and profiling that produces legal or similarly significant effects. We do not make decisions producing such effects solely by automated means. Where we use tools that assist in evaluating job applications, including AI-assisted review, a human makes all final hiring decisions.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Complaints. You have the right to lodge a complaint with a supervisory authority, such as an EU data protection authority in your country of residence or work, or the UK Information Commissioner’s Office (ICO). We would appreciate the chance to address your concerns before you do so; please contact privacy@xpstrategy.com.
Controller and representative. XP Strategy Corp is the controller of the personal information described in this Privacy Policy. XP Strategy has not appointed a representative in the EEA or UK under Article 27 of the GDPR; a representative is required only where the applicable thresholds are met. We are not required to appoint a Data Protection Officer and have not designated one; you may direct all inquiries to privacy@xpstrategy.com.
Requirement to provide data. Where provision of personal information is a statutory or contractual requirement, or is necessary to enter into a contract, we will tell you at the point of collection and explain the consequences of not providing it.
Response timeline. We aim to respond to rights requests within one month, with an extension of up to two further months for complex or numerous requests, and with notice to you.
12. Do Not Track and Global Privacy Control (Universal Opt-Out Signals)
Do Not Track. There is no uniform industry standard for how websites should respond to browser “Do Not Track” (DNT) signals. For that reason, the Site does not respond to DNT signals.
Global Privacy Control and universal opt-out signals. Several state privacy laws require covered businesses to recognize the Global Privacy Control (GPC) and other universal opt-out mechanisms as valid requests to opt out of the sale or sharing of personal information and of targeted advertising. The Site does not currently detect or respond to GPC or other universal opt-out signals. If you wish to opt out, you may email privacy@xpstrategy.com or use the browser and industry advertising controls described in Sections 6 and 7. If we implement recognition of universal opt-out signals in the future, we will update this Privacy Policy.
13. Email, Telephone, and Text-Message Marketing
Email. You may unsubscribe from marketing emails by using the unsubscribe link in the message. Consistent with the CAN-SPAM Act, our marketing emails use accurate sender and subject information, identify the message as an advertisement where required, include a valid physical postal address, and honor unsubscribe requests promptly, and in any event within 10 business days.
Marketing choices generally. Even after you opt out of marketing, we may continue sending non-promotional communications concerning an existing business relationship, a requested consultation, a legal matter, or a service. Submitting a contact form authorizes XP Strategy to respond to the inquiry using the contact information provided. Submitting a form does not, by itself, create consent for recurring automated marketing messages unless the form separately and clearly requests that consent.
Text messaging (SMS). XP Strategy does not currently operate an SMS or text-messaging marketing program, and submitting a form does not enroll you in one. If we introduce text messaging in the future, participation will be optional and based on your express prior written opt-in, separate from any email consent and not required as a condition of any purchase or service. We will present the applicable program terms at that time, disclose the expected message frequency, note that message and data rates may apply, and maintain consent records. You will be able to reply STOP to opt out at any time and HELP for help. Our SMS practices are intended to follow the Telephone Consumer Protection Act (TCPA) prior-express-written-consent standard and applicable CTIA Messaging Principles and carrier (10DLC application-to-person) requirements. We note that the FCC’s “one-to-one consent” rule was vacated by the U.S. Court of Appeals for the Eleventh Circuit in January 2025 and never took effect, so we do not rely on it; our consent practices follow the prior TCPA prior-express-written-consent standard.
No sharing of SMS opt-in data. XP Strategy does not sell, rent, or share mobile phone numbers or SMS text-messaging opt-in data and consent with third parties or affiliates for their own marketing or promotional purposes. We may share this information only with service providers that help us operate the messaging program, such as our SMS or communications platform, and they may use it solely to provide that service to XP Strategy. Carriers are not liable for delayed or undelivered messages.
Client-directed campaigns. For marketing campaigns that we operate on a client’s behalf, the client, as controller, is responsible for the lawful basis and consent for those communications, and XP Strategy acts on the client’s documented instructions.
14. International Data Transfers
XP Strategy is based in the United States. If you access the Site or provide information from another country, your information may be transferred to and processed in the United States or in another country whose privacy laws may differ from those in your jurisdiction. Our service providers and personnel may also access information from outside your country. XP Strategy’s own operations may include team members or contractors located outside the United States, whose access is subject to confidentiality and data-processing obligations.
For transfers of personal information from the EEA or UK to countries that have not received an adequacy decision, we rely on appropriate safeguards, which may include the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement or Addendum, and, where a recipient is certified, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. A copy of the relevant transfer mechanism is available on request through privacy@xpstrategy.com. Transfers of client business data follow the transfer terms in the applicable client agreement or data-processing agreement.
By using the Site or submitting information to us, you understand that your information may be transferred, processed, and stored in the United States and other countries as described above.
15. Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, taking into account the nature of the information and our legal and business needs:
- Prospect and inquiry data is generally retained for the duration of the sales cycle plus a reasonable follow-up period.
- Client-relationship data is generally retained for the duration of the engagement plus the periods required for legal, tax, accounting, insurance, and dispute-resolution purposes.
- Marketing data is retained until you unsubscribe or opt out, plus a reasonable period to honor and document your choices.
- Job-applicant data is retained for the recruitment process and any period required by law.
When personal information is no longer reasonably required, we delete, anonymize, aggregate, or securely destroy it, as further described in Section 19. Legal-hold and record-keeping requirements may require us to retain certain information for longer, for example to comply with contracts, tax obligations, or to establish, exercise, or defend legal claims. Residual copies may persist in backups or archives for a limited period before they are overwritten in the ordinary course. Client business data is retained, returned, or deleted at the end of the engagement in accordance with the client agreement, as described in Section 19.
16. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information and client data against unauthorized access, loss, misuse, alteration, or disclosure, appropriate to the nature of the information and the risk. These safeguards include access controls, least-privilege access permissions, and encryption of data in transit.
Client account credentials and API access. Because we access clients’ Amazon, Walmart, and Target advertising accounts to deliver services, we apply particular care to account credentials and API access tokens. These are stored using access-restricted methods, made available only to personnel who need them, and revoked when an engagement ends or a team member’s role changes.
Vendors and personnel. We conduct reasonable due diligence on service providers and impose contractual security and confidentiality obligations on our vendors, employees, and contractors, who are subject to confidentiality obligations and receive security guidance appropriate to their roles. Where required, our handling of client advertising data is aligned with the applicable platform data-protection and acceptable-use requirements, such as those of the Amazon, Walmart, and Target advertising platforms.
No website, transmission method, or storage system is completely secure, and we cannot guarantee absolute security.
17. Data Breach Handling and Notification
We maintain an incident-response process and investigate suspected security incidents involving personal information. If a breach of personal information occurs, we will provide notifications consistent with the New Jersey breach-notification law (N.J.S.A. 56:8-161 et seq.) and other applicable state breach-notification statutes. As New Jersey law requires, we will report the breach to the New Jersey Division of State Police in advance of notifying affected residents, and will then notify affected residents in the manner and within the timeframes the statute requires.
Where a breach involves personal information of individuals in the EEA or UK, we will, where the GDPR or UK GDPR applies, notify the competent supervisory authority within 72 hours of becoming aware of the breach where feasible, and notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
For incidents involving a client’s accounts or data that we process as a processor, we will promptly notify the affected client in accordance with the applicable data-processing agreement so the client, as controller, can meet its own notification obligations. We maintain records of security incidents and remediation.
18. Children’s Privacy
The Site is intended for business users and is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided personal information to us, contact privacy@xpstrategy.com and we will investigate and take appropriate action, including deleting the information where required. Consistent with California law and other state teen-protection provisions, we do not knowingly sell or share the personal information of consumers under 16 years of age without opt-in consent. A parent or guardian may contact us at privacy@xpstrategy.com to request review or deletion of a child’s information.
19. Client Data Confidentiality and Advertising-Account Access
This section addresses how XP Strategy treats confidential client business data and access to clients’ advertising and marketplace accounts. This is central to our work, and we take it seriously.
Confidentiality commitment. When XP Strategy receives authorized access to client advertising accounts, marketplace accounts, performance data, reports, product information, sales and margin data, ASINs, account credentials, or related business information, we treat that information as confidential. We process it only to provide the agreed services and under the applicable service agreement and any non-disclosure or data-processing agreement, not under the consumer-facing terms of this Privacy Policy.
Our role. For account-level and client business data, XP Strategy acts as the client’s service provider or processor. We do not sell, share, or use client data for our own marketing, and we do not use one client’s data to benefit another client.
Authorization and platform terms. Our access to a client’s Amazon, Walmart, or Target advertising and marketplace accounts is based on access the client grants to its own accounts. We adhere to each platform’s applicable data-protection and acceptable-use terms. The client remains responsible for ensuring it has authority to grant access, maintaining appropriate account permissions, complying with platform requirements, providing accurate instructions, and removing or modifying access when appropriate.
Access controls and segregation. We apply need-to-know access limitations, restrict access to personnel who require it to deliver services, and revoke access when an engagement ends or a role changes. We keep client data segregated between clients and do not commingle it.
Return or deletion; DPA. At the end of an engagement, client data is returned or deleted in accordance with the client agreement. A data-processing agreement is available to clients on request.
Aggregated and de-identified insights. We may aggregate or de-identify information so that it no longer reasonably identifies a specific individual, client, account, or device, and we may use and disclose that information for lawful purposes such as analytics, research, benchmarking, and describing our work. Where we do so, such insights are anonymized and are not attributable to a specific client. We do not attempt to re-identify de-identified information except as permitted by law.
20. Exercising Your Rights: Requests, Verification, and Authorized Agents
How to submit a request. You may submit a privacy request by emailing privacy@xpstrategy.com or writing to the address in Section 21. Please provide enough information for us to locate the relevant records and to understand your request.
Verification. To protect your information, we take reasonable steps to verify your identity before acting on certain requests, using a process proportionate to the sensitivity of the information and the risk of harm from unauthorized access. We will not require you to create an account solely to submit a request, and we will use information you provide for verification only for that purpose.
Authorized agents. Where the law permits (including under CCPA/CPRA), you may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may require you to verify your identity directly or confirm that you authorized the agent.
Timelines and cost. We respond within the timeframes described in Sections 10 and 11 (generally 45 days for U.S. state-law requests, extendable; approximately one month for GDPR requests). We handle requests free of charge, except that we may charge a reasonable fee or decline manifestly unfounded, repetitive, or excessive requests as permitted by law.
Appeals and escalation. If we decline your request, you may appeal as described in Section 10, and, where applicable, escalate to your state attorney general, the California Privacy Protection Agency, or an EEA or UK supervisory authority.
Requests concerning client-controlled data. If your request actually concerns personal information that we process on behalf of a client (as a processor), we will refer the request to, or coordinate with, the relevant client as the controller, and we will inform you where we have done so.
21. Third-Party Websites and Platforms; Governing Law; Changes to This Policy; Contact
Third-party websites and platforms. The Site may link to or integrate with third-party services, including Amazon, Walmart, Target, Google, LinkedIn, YouTube, podcast platforms, social networks, software providers, and client websites. We do not control and are not responsible for the content, security, or privacy practices of those services, and referencing them does not mean we adopt their obligations. Your interactions with those services are governed by their own terms and privacy policies.
Aggregated and de-identified information. As described in Section 19, we may aggregate or de-identify information so that it no longer reasonably identifies you or your device, and we may use and disclose that information for any lawful purpose.
Governing law and venue. This Privacy Policy, and any dispute arising out of or relating to it or to your use of the Site, are governed by the laws of the State of New Jersey, without regard to its conflict-of-laws rules. The state and federal courts located in Monmouth County, New Jersey have exclusive jurisdiction and venue over any such dispute, to the extent permitted by applicable law.
Accessibility. We want this Privacy Policy to be usable by everyone. If you rely on assistive technology and have trouble accessing any part of it, or you would like it provided in an alternative format, contact us at privacy@xpstrategy.com and we will work to provide the information in a way that works for you.
Changes to this Privacy Policy. We may update this Privacy Policy periodically. When we make changes, we will revise the “Last Updated” date above. If changes are material, we may provide additional notice as required by law.
Contact us. Questions, concerns, and privacy requests may be directed to:
XP Strategy Corp
1405 NJ-35, Suite 209, Ocean Township, NJ 07712
Email: privacy@xpstrategy.com
Website: https://xpstrategy.com/
EEA and UK residents may also contact their local data protection authority or the UK Information Commissioner’s Office, and California residents may contact the California Privacy Protection Agency or the California Attorney General, as described in Sections 10 and 11.