Plain-English summary
- We collect name, email, country, optional org for reservations and investor inquiries.
- Payment data goes straight to Stripe. We never see your card number.
- We don't run ad tracking. No Google Analytics. No Facebook pixel. No third-party trackers on this site.
- We use our hosting (GitHub Pages, Vercel) to serve pages and process forms. Standard server logs are kept 30 days.
- You can request your data, ask us to delete it, or correct it any time: legal@ameka.ai.
1. Who we are
"Ameka" means Ameka, Inc., a Delaware corporation with its principal place of business in Pasadena, California. For privacy questions: legal@ameka.ai.
2. What we collect
Reservations
- Name, email, country, optional studio/organisation.
- Selected tier and reservation reference (AMK-XXXXX).
- Stripe payment metadata (last 4, brand, billing ZIP) — we do not see your full card.
Investor inquiries
- Name, email, optional fund/firm, LinkedIn URL.
- Self-reported accreditation status and expected check size.
- Free-form notes that you write.
Site visits
- Standard server logs: IP, User-Agent, requested path, timestamp. Used to keep the site online and prevent abuse. Kept 30 days.
- We do not set marketing cookies. We do not use Google Analytics, Facebook Pixel, TikTok pixel, Segment, or any cross-site tracker. The site uses only one functional cookie set by GitHub Pages for cache and one by Vercel for routing the API.
3. Why we collect it
- Fulfil reservations and refunds.
- Respond to investor and press inquiries.
- Email you Bench Notes if you subscribe.
- Comply with US tax, KYC/AML, and export-control law.
4. Who else sees it
We share data only with the small set of vendors that help us run the business:
- Stripe — payment processing. stripe.com/privacy.
- GitHub (Pages) — static site hosting. GitHub privacy.
- Vercel — API hosting. vercel.com/legal/privacy-policy.
- Namecheap — domain registration.
- JPMorgan Chase — banking for segregated deposit account.
- Outside legal, tax, and accounting professionals under confidentiality obligations.
- Law enforcement when legally compelled by a valid order.
We do not sell or rent your personal data to anyone. Ever.
5. Your rights
Wherever you live, you can ask us to:
- Confirm what we hold about you.
- Provide a portable copy.
- Correct anything inaccurate.
- Delete your data (unless we need it to comply with law).
- Stop sending you marketing email (you can unsubscribe with one click).
Email legal@ameka.ai with your request. We respond within 30 days. EU/UK readers: this is your GDPR / UK-GDPR right. California readers: this is your CCPA / CPRA right. We treat these requests the same regardless of where you live.
6. Security
We follow standard practice: TLS everywhere, no plain-text password storage (we don't have accounts yet — the reservation flow does not require a password), encrypted secrets in our hosting provider, principle of least privilege on tokens.
7. Retention
- Reservation data: kept while your reservation is active and 7 years after for tax/audit.
- Investor inquiries: kept for as long as you remain in our investor pipeline, then deleted on request.
- Server logs: 30 days.
- Stripe receipts: as long as Stripe's policy requires (typically 7 years).
8. Children
Ameka does not knowingly collect data from anyone under 16. If you believe we have, email legal@ameka.ai and we will delete it.
9. Changes
We will email reservation holders if we make a material change to this policy, at least 30 days before it takes effect.
Questions? legal@ameka.ai.