Privacy Policy
This policy explains what data Sellerio accesses through the Amazon Selling Partner API (SP-API) and Amazon Advertising API, how that data is used, and how it's protected. Sellerio does not sell seller data, and does not use it for any purpose beyond powering the account holder's own operational dashboards.
What data is accessed
| Source | Data | Purpose |
|---|---|---|
| Amazon SP-API | Orders, order line items, shipping status, ASIN/SKU catalog data | Order tracking, inventory deduction, revenue reporting |
| Amazon Advertising API | Campaign, ad group, keyword, and search-term performance (spend, clicks, sales) | Bid optimization, negative-keyword management, ad profit & loss reporting |
| Google Sheets API | Values in the specific Google Sheet spreadsheet an account holder chooses to connect, plus the connecting user's Google account email address | Two-way sync of the account holder's own order, inventory, and listing data between Sellerio and their chosen spreadsheet, for offline review/editing and bulk export |
Sellerio does not request access to Amazon buyer personal information beyond what's required to fulfill and report on orders (e.g. shipping status), and does not use SP-API or Advertising API data for advertising, marketing, or any purpose outside the account holder's own operations.
Sellerio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Sheets access is used exclusively to read and write the one spreadsheet an account holder explicitly connects, for that account holder's own data sync — never for advertising, never for training any model, and never shared with or sold to any third party.
How data is stored
- Data is stored in a private, access-controlled database that is not bound to any public network interface — it cannot be reached directly from the internet, and is not indexed or exposed by any public-facing page.
- All access to Sellerio requires an authenticated staff login with a role-based permission level enforced on every request; there is no public sign-up or anonymous access to any account data.
- Refresh tokens and API credentials are never exposed to the browser or included in any client-side response — only masked placeholders are ever returned to the interface once a credential is saved. Credentials are configured via environment variables and are never hardcoded or committed to source control. This applies equally to Amazon SP-API/Advertising API tokens and to Google OAuth tokens issued when an account holder connects a Google Sheet — Google access and refresh tokens are stored encrypted, scoped to that account holder's own organization, and are never returned to any client.
- All traffic between Sellerio and Amazon's APIs, and between a user's browser and Sellerio, is encrypted in transit (HTTPS/TLS).
- Uploaded files containing account data are served through an authenticated route requiring a valid session, not a publicly browsable directory.
Data retention
Order, inventory, and advertising data is retained for as long as the account remains active, to support historical reporting (e.g. year-over-year comparisons). Data for a disconnected or removed brand can be deleted on request.
Revoking access
An account holder can revoke Sellerio's access to their Amazon account at any time, either from within Sellerio (Remove/Disconnect on the relevant connection) or directly through Amazon — via Seller Central's Manage Apps & Services page, or the Solution Provider Portal's Manage Authorizations page. Revoking access stops all further API calls immediately; previously synced data already stored in Sellerio is not automatically deleted and can be removed on request.
Google Sheets access can be revoked the same way — from within Sellerio (Disconnect on the Google Sheets Sync settings page) or directly through Google, via Google Account > Security > Third-party apps & services. Revoking access immediately stops all further reads or writes to that spreadsheet.
Third parties
Seller data accessed through Amazon's and Google's APIs is not sold, rented, or shared with any third party. Sellerio uses the following third-party infrastructure to operate:
- Hosting — the application and database run on Hostinger's Cloud Startup plan.
- AI-assisted features — optional AI listing analysis and SKU analysis features send relevant product data to Anthropic's Claude API to generate recommendations; this is used only for the account holder's own listing optimization, not for any other purpose.
- Google Sheets API — used solely to read/write the spreadsheet an account holder explicitly connects, for that account holder's own order/inventory/listing data sync.
Changes to this policy
If this policy changes in a way that affects how Amazon seller data is handled, the "Last updated" date above will be revised and account holders will be notified.
Contact
Rangili Mart (operating Sellerio)
For privacy questions or data deletion requests: contact@mysellerio.com