Amazon Data Protection Policy

Company: Astronaut Party Inc., 2426 Greenwich St., San Francisco, CA 94123 · Contact: data@astronautparty.com
Effective Date: September 2, 2026 · Last Reviewed: September 2, 2026

Astronaut Party Inc. (“Astronaut Party,” “we”) operates the Moonmap platform. This page describes the controls we maintain to protect Amazon Information — as defined in Amazon's Data Protection Policy — that we access, store, or process through the Amazon Ads API and the Amazon Selling Partner API. It supplements our Privacy Policy.

Network Controls

Astronaut Party operates a fully managed, deny-by-default cloud perimeter: all compute runs on Vercel's managed edge/serverless platform and all data resides in Supabase's managed PostgreSQL — we run no self-managed, publicly routable hosts or network hardware. Network protection (firewalling, isolation, and DDoS mitigation) is provided and certified by these providers (ISO 27001 / SOC 2).

The database is not directly reachable from the public internet by application users; all access flows through authenticated HTTPS endpoints governed by session authentication, application-level authorization, and PostgreSQL Row-Level Security, so no Amazon Information is publicly accessible and access is restricted to approved, authenticated users. All endpoints are served exclusively over TLS with hardened security headers. Production is isolated from development and staging in separate, independently credentialed environments.

Company devices that may access Amazon Information run full-disk encryption and automatically-updated, built-in malware protection that standard users cannot disable, governed by a device-security policy that all personnel with access to Amazon Information acknowledge before access and at least annually thereafter. Access to systems handling Amazon Information is restricted to approved personnel with a documented business need, who acknowledge our data-protection and device-security policies before access and at least annually thereafter. Access is reviewed at least quarterly and revoked within one business day of role change or departure.

Reporting a Security Vulnerability

We take the security of our platform and of the data we process seriously, and we welcome reports from security researchers and others. If you believe you have found a security vulnerability in Moonmap, or an issue affecting the Amazon Information or customer data we process, please email data@astronautparty.com with a description of the issue and, where possible, steps to reproduce it.

We will acknowledge your report within 5 business days, investigate promptly, and keep you informed of our progress toward a resolution. We ask that you give us a reasonable opportunity to remediate the issue before disclosing it publicly, and that you avoid accessing or modifying other users' data during your research. We will not pursue or support legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.

If a security incident affects Amazon Information, we will investigate, remediate, and notify affected parties and Amazon in accordance with applicable requirements and timelines.

Contact

Questions about this policy or our handling of Amazon Information: data@astronautparty.com.

© 2026 Astronaut Party Inc. All rights reserved.

Moonmap
PrivacyTerms© 2026 Astronaut Party Inc.