Legal

Privacy Policy

This Privacy Policy explains how Holowave uses Login with Amazon and the Amazon Advertising API to access and manage advertising data for Holowave's own business operations.

Last updated: August 31, 2026

1. Scope of this policy

Holowave uses the Amazon Advertising API primarily through an AI Agent operated for Holowave's internal use. The AI Agent may run in an environment separate from the holowave.cc website. This website provides this publicly accessible Privacy Policy and is not a consumer-facing Login with Amazon service.

2. Authorization through Amazon

Holowave uses Amazon OAuth and Login with Amazon to obtain the account holder's explicit authorization before accessing Amazon Advertising API data. Holowave accesses only the accounts and permissions included in the authorization granted through Amazon.

3. Data we may access

Within the scope authorized by the account holder and permitted by Amazon, Holowave may access advertising profiles and accounts, campaigns, ad groups, advertisements, targeting settings, keywords, search terms, budgets, bids, placements, and advertising performance and reporting data. We may also process identifiers and technical information required to authenticate API requests and associate results with the correct authorized account.

4. How we use the data

Amazon Advertising data is used only to analyze advertising performance, prepare reports and recommendations, optimize campaigns, and manage Holowave's authorized Amazon advertising activity. The AI Agent may assist with these tasks under Holowave's direction. We do not use the data for purposes unrelated to advertising analysis, optimization, or management.

5. Sale and disclosure of data

Holowave does not sell Amazon Advertising data or personal information. We do not disclose such data to third parties except to service providers that process data on Holowave's behalf and are subject to appropriate confidentiality and security obligations, or where disclosure is required by law.

6. Data security

Holowave takes reasonable administrative, technical, and organizational measures to protect OAuth access and refresh tokens, API credentials, and data obtained through the Amazon Advertising API. These measures include limiting access to authorized systems and personnel, protecting credentials from public disclosure, and using secure connections where applicable. No method of transmission or storage is completely secure, but we work to reduce unauthorized access, loss, alteration, or misuse.

7. Data retention and deletion

OAuth credentials are retained only while the authorization is active and they are needed for the purposes described above. Advertising data and derived reports are retained only for as long as reasonably necessary for Holowave's advertising analysis, optimization, recordkeeping, and security needs.

When authorization is revoked or the data is no longer required, Holowave will stop new API access and delete active OAuth tokens and associated stored Amazon Advertising data within 30 days, unless a longer period is required by law. Residual copies in protected backups are removed through the ordinary backup rotation process and are not used for new processing.

8. Revoking Amazon authorization

The account holder may revoke Holowave's access at any time through the Amazon account settings or the relevant Amazon authorization management page. Revocation prevents future access through the revoked authorization. The account holder may also contact Holowave to request deletion of associated stored data.

9. Changes to this policy

We may update this Privacy Policy when our practices, services, or legal obligations change. The current version will remain available at this URL, and the date at the top of the page will identify the latest update.

10. Contact

For privacy questions, authorization concerns, or data deletion requests, contact Holowave at alexmimi@live.cn.