Privacy Policy
1. What data we handle
- Account data. Your email address and password. Authentication is handled by Supabase, which stores your login password as a bcrypt hash — never in plain text. Where an owner can reveal a team member's password, that value is encrypted at rest with a key held outside the database.
- The Amazon Date Range Transaction reports you upload. The transaction files Amazon provides. The computed analytics and per-SKU rows are saved to your store so your history and forecast can build over time; the raw report file itself is not retained after analysis.
- Team & role data. If you're an owner, the employee accounts you create and the page/visibility permissions you assign.
We do not seek out Amazon shopper personal information, and we do not sell or rent your data to anyone.
2. How we use it
Data is used solely to operate the service for you: to authenticate your account, compute your profit analytics, store your store's history, and enforce the team access you configure. We don't use your business data to train models for other customers or to build a competing product.
3. Security & storage
- In transit: all traffic is served over HTTPS/TLS.
- At rest: account and analytics data live in a managed Postgres database (Supabase) with encryption at rest and row-level security that scopes each row to its owner or assigned employee.
- Credentials: login passwords are hashed (bcrypt) by Supabase Auth; the recoverable team passwords an owner can reveal are additionally encrypted with a key kept outside the database.
- Access control: employees never see raw money figures unless an owner grants it; financial masking is enforced on the server, not just the interface.
- Subprocessors: Supabase (authentication + database), our hosting provider (application hosting), and an email provider used to send account-confirmation messages.
4. Amazon data
Today, the only Amazon data in the service is what you upload — your own Date Range Transaction reports. A live Amazon Selling Partner API (SP-API) connection is planned, not yet active. If and when you authorize an SP-API connection, we will access only the data needed to provide the service, use it solely on your behalf, retain it no longer than necessary, and handle it in line with Amazon's Acceptable Use Policy and Data Protection Policy. We will never use Amazon-sourced data to build audiences or a competing product.
5. Retention & deletion
Raw report uploads are transient and are not retained after analysis. Saved analytics persist for as long as your account is active so your history and forecast remain useful. You can request deletion of your account and its stored data at any time by emailing us, and we will remove it.
6. Contact
Questions, or a data-deletion request? Email help@accreza.com and we'll respond.