Privacy Policy
Last updated: September 8, 2026
1. What we collect
Account data: your email address, an optional display name, and a salted password hash (we never store your plaintext password). Work data: the CSV reports you upload, the normalized rows derived from them, audit findings, and your claim ledger entries. Billing data: your Stripe customer ID, subscription ID, plan, and billing period dates. We do not receive or store your card details - Stripe processes payments directly.
2. What we do NOT do
We do not connect to your Amazon account, do not access Seller Central, do not sell or share your data with advertisers, agencies, or data brokers, and do not use your business data to train any models. There are no third-party analytics or advertising scripts in the product.
3. Where data lives
All work data is stored in the application database on the server where this Service is deployed (SQLite on your hosting), not on third-party cloud storage. When you delete a store, its uploaded rows, findings, and cases are removed from the database.
4. Processors
The only external processor is Stripe, Inc., which handles subscription payments and the customer portal. Stripe receives your email address (as the customer identifier) and payment details you enter at checkout under its own privacy policy. No other external service receives your data by default.
5. Retention
Your data is retained while your account is active. Deleting a store removes its data; deleting your account removes your account record. Expired backups, if the operator configures any, follow the operator's backup schedule and are outside application control.
6. Your rights
You can export your claim ledger as CSV (Pro) or copy letter text at any time. To request deletion of your account or to exercise other rights, contact us using the address below; we respond within 30 days.
7. Security
Sessions use signed, httpOnly cookies. Passwords are hashed with bcrypt. Transport security (HTTPS) is terminated by the reverse proxy in front of the application - enable it in production.
8. Contact
Questions about this policy: see the support address listed in the footer. The operator identity is the entity configured in the site configuration of this deployment.
Edit before launch - Company Legal Name LLC · Edit before launch - 123 Main St, Wilmington, DE 19801, USA · support@example.com
This template is provided as part of the application source. It is not legal advice - have a professional review before launch. (Edit before launch: company details live in src/config/site.ts.)