Privacy Policy
Effective Date: March 11, 2026 | Last Updated: March 11, 2026
1. Who We Are
SellerBlaze ("we", "us", or "our") is a profit analytics platform built exclusively for Amazon India sellers. We are accessible at https://sellerblaze.com. For any privacy-related inquiries, contact us at support@sellerblaze.com.
2. Data We Collect
We collect only the data necessary to provide our service:
- Account Data: Your name, email address, and encrypted password when you register.
- Amazon SP-API Order & Finance Data: Order history, financial events, settlement reports, fees, returns, and product information retrieved via the Amazon Selling Partner API on your behalf.
- Amazon Advertising Data: Ad spend, clicks, impressions, ACOS, ROAS, and campaign-level data retrieved via the Amazon Advertising API on your behalf, used solely for analytics and reporting within your account.
- Personally Identifiable Information (PII): We may receive buyer shipping addresses (postal codes only) as part of order data for the purpose of calculating shipping zone estimates. No buyer names, phone numbers, or full addresses are stored or used beyond this purpose.
- Usage Data: Basic server logs (timestamps, IP addresses) for security and debugging purposes.
3. How We Use Your Data
All data retrieved from Amazon SP-API and the Amazon Advertising API is used for analytics and reporting only — exclusively to provide the SellerBlaze service to you.
- To calculate your profit, fees, and margins from Amazon order and settlement data.
- To display analytics, P&L dashboards, and fee breakdowns within your account.
- To report on advertising spend, ACOS, ROAS, clicks, and impressions within your account.
- To sync data from Amazon SP-API on your behalf using credentials you authorise.
- To respond to support requests sent to our support email.
We do not use your data for advertising, profiling, AI training, or any purpose other than providing analytics and reporting within the SellerBlaze service.
4. Data Retention
We retain data only as long as necessary to provide the service:
- Amazon order, finance & advertising data is retained for 24 months from the date of sync to support historical analytics. Data older than 24 months is automatically purged.
- Account data (name, email, encrypted password) is retained for the lifetime of your account and deleted within 7 business days of account deletion.
- SP-API & Advertising API tokens are retained only while your Amazon account is connected and deleted immediately upon disconnection or account deletion.
- Buyer PII (shipping postal codes used transiently for zone calculations) is not stored in identifiable form. Any incidental PII in raw API responses is purged within 30 days of receipt.
- You may request immediate deletion of all your account data by emailing support@sellerblaze.com. Deletion requests are actioned within 7 business days.
5. Data Sharing and Third Parties
We do not sell, rent, or trade your data to any third party under any circumstances.
We use the following infrastructure providers to operate the service:
- OVH (VPS hosting): Our server infrastructure. Data is stored on servers located in Europe.
- Amazon SP-API: Data is retrieved from Amazon on your behalf using OAuth tokens you authorise.
No other third-party services receive your data.
6. Data Security
- Encryption at rest: Amazon SP-API and Advertising API tokens are encrypted using AES-256-CBC before storage. The encryption key is stored separately from the database.
- Encryption in transit: All data in transit is protected by TLS 1.2+ / HTTPS (Let's Encrypt). Plain HTTP is redirected to HTTPS.
- Password security: Passwords are hashed using bcryptjs with 12 rounds — never stored in plain text.
- Restricted access: Access to your data is restricted to your authenticated session only, using short-lived JWT tokens (15-minute expiry). Server access is limited to a single authorized administrator via SSH key authentication.
- No shared infrastructure: SellerBlaze runs on a dedicated VPS — your data is not co-mingled with other applications.
7. Amazon SP-API Compliance
SellerBlaze accesses Amazon seller data exclusively through the Amazon Selling Partner API (SP-API) under the permissions you grant during the OAuth authorisation flow. We comply fully with Amazon's Acceptable Use Policy and Data Protection Policy for SP-API applications. Data retrieved via SP-API is used solely to provide analytics to the authorising seller and is never shared with other sellers or third parties.
8. Your Rights
- Access: You can view all your data within the SellerBlaze dashboard at any time.
- Correction: You can update your account details from the Settings page.
- Deletion: You can request full account and data deletion by emailing support@sellerblaze.com.
- Revocation: You can revoke SellerBlaze's access to your Amazon account at any time from Seller Central → Apps & Services.
9. Cookies
SellerBlaze does not use tracking cookies or advertising cookies. We use only essential session-related storage (JWT tokens in browser memory) required for authentication.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users. Continued use of SellerBlaze after changes constitutes acceptance of the updated policy.
11. Contact Us
For any privacy-related questions, data requests, or concerns, please contact us at:
- General & Support: support@sellerblaze.com
- Privacy & Compliance: support@sellerblaze.com