Privacy Policy

Last updated June 16, 2026

1. Who we are

SellerOS provides analytics and operations tooling for Amazon sellers. This policy explains what data we process, why, how we protect it, and how long we keep it. It applies to our website, application, and any data we access on a seller's behalf through the Amazon Selling Partner API ("SP-API").

2. Data we process

  • Account data — your name, email, hashed password, workspace and role.
  • Amazon business data — orders, finances, inventory, listings, advertising and catalog data retrieved from SP-API for the seller account you connect.
  • Buyer personal information (PII) — SellerOS requests only non-PII Amazon roles and does not access buyer names, addresses, phone numbers, email or gift messages. If a future feature ever required buyer PII, we would apply for the specific restricted role and update this policy before doing so.
  • Usage data — product/feature interactions used to operate and improve the service.

3. How we use data

We process Amazon data solely to provide the features you enable (research, analytics, inventory, pricing, advertising, etc.) for your own seller account. We do not sell your data, and we never use one seller's data to benefit another.

4. How we protect data

  • Encryption in transit — TLS 1.2+ for all connections.
  • Encryption at rest — sensitive secrets such as Amazon refresh tokens are encrypted with AES-256-GCM before storage.
  • Access control — unique accounts, role-based permissions, least-privilege access, and optional multi-factor authentication.
  • Minimization — we store only the fields a feature needs, and exclude PII from application logs.

See our Security overview for details.

5. Data retention & deletion

  • Buyer PII is deleted within 30 days of order delivery, unless a longer period is legally required — in which case it is archived encrypted.
  • Non-PII order data is retained for at most 18 months.
  • Security logs are retained for at least 12 months.
  • When you disconnect Amazon or close your account, associated Amazon data is deleted.

6. Sharing & subprocessors

We share data only with infrastructure subprocessors needed to run the service, under data-processing agreements, and we never sell your data. AI-assisted features (e.g. the Listing Optimizer) send only listing text — never buyer PII or order data — to our AI model provider, Anthropic (Claude). We disclose data only if required by law.

7. Your rights

You may request access to, export of, correction of, or deletion of your personal data. Contact privacy@selleros.app and we will respond within 30 days.

8. Contact

Privacy questions: privacy@selleros.app. Security issues: security@selleros.app.