Privacy Policy
Last updated: October 8, 2026
This policy covers the warehouse management service and web application Monarchouse WMS (wms.monarchouse.com, including the former address returns.monarchouse.com) operated by Monarchouse Corporation (“Monarchouse”). We are a third-party logistics (3PL) company that stores inventory, fulfills and ships orders (including B2B shipments), and receives, inspects, photographs, and dispositions returned goods on behalf of our clients (brands and sellers).
1. Information we collect
- Client account information: name, email address, password (stored hashed), and sign-in history of client users.
- Returns data: SKU, quantity, condition grade, inspection notes, product photos, tracking numbers, order numbers, and return reasons for returned units; product catalogs uploaded by the client.
- Amazon data (only if the client connects their account): when a client explicitly authorizes us through Amazon’s own consent page, we retrieve that client’s FBA Customer Returns and Removal Order reports through the Amazon Selling Partner API. These contain LPN, FNSKU, SKU, order ID, return reason, and Amazon’s disposition. We do not request or store buyer names, addresses, emails, or payment information.
- Technical information: IP address, browser information, and audit logs used to operate and secure the service.
2. How we use it
We use this information only to (a) identify, inspect, and process the client’s returns, (b) show processing results and photos to that client, (c) calculate service fees, and (d) keep the service secure. We do not use it for advertising, profiling, or sale to third parties.
3. Sharing
A client’s data is visible only to that client. We do not sell or share it. Our infrastructure providers, Vercel (application hosting, US) and Supabase (PostgreSQL database, AWS us-west-1), store and process data under standard service terms and do not access or use it. We disclose data to other third parties only when required by law.
4. Protection of Amazon information
Information received through the Amazon Selling Partner API is handled in accordance with Amazon’s Acceptable Use Policy and Data Protection Policy. It is encrypted in transit with TLS; authorization tokens are encrypted at rest with AES-256. Access is limited to administrators with a job need and requires multi-factor authentication. A client can revoke the connection at any time in Seller Central or by asking Monarchouse; the stored token is deleted immediately on revocation.
5. Retention
Returns records and photos are kept for the duration of the client’s service agreement and up to 24 months afterwards, then deleted. Amazon report data contains no buyer personal information; it is kept only as long as needed to identify and reconcile the client’s returns and is deleted with the client’s other records. Audit logs are kept for 12 months. Clients may request deletion at any time.
6. Security incidents
If we become aware of a security incident involving client data or Amazon information, we notify affected clients (and, for Amazon information, security@amazon.com) within 24 hours.
7. Your rights
Clients may request access to, correction, deletion, or export of their data by emailing hello@monarchouse.com.
8. Changes
Changes to this policy are posted on this page with an updated date.
Monarchouse Corporation · Buena Park, California, USA · hello@monarchouse.com · (562) 383-0041 · Privacy Policy · Terms of Service