Account security and payments
Recovery and subscriptions
We store one-way hashes of recovery codes and credential-version records to provide email-free password recovery and invalidate old sessions. Raw recovery codes are shown once and are not retained.
When you subscribe, Stripe receives your account email and billing identifiers to process recurring payments and provide its hosted customer portal. We store Stripe customer/subscription identifiers, payment-access status, billing-period dates and processed webhook IDs. Card numbers and raw webhook payloads are not stored in our application database. Seller, Keepa and advertising responses are not sent to Stripe.
01 · Controller
Who is responsible
XANON LTD is the controller of personal information processed to operate amazonGPT. Privacy and security enquiries may be sent to security@amazongpt.app. Account support and product requests should use the authenticated support area.
02 · Information
Data we handle
- Account identity, including your email address, password hash, role and session records.
- Encrypted Amazon Selling Partner, Amazon Ads and user-supplied Keepa credentials.
- Connection metadata such as seller labels, marketplaces, advertiser profile IDs, countries, currencies and connection status.
- Live Amazon seller, Amazon Ads and Keepa responses needed to answer the request you make.
- Confirmed write-action details and outcomes, privacy-minimised tool activity metadata, and bug or feature requests you submit.
- Operational security information such as timestamps, request identifiers, errors and limited server logs.
Orders, listings, stock snapshots, finance history, Ads campaign reads and downloaded Ads reports are processed to answer your request and are not copied into amazonGPT’s application database.
03 · Purposes
How we use information
We use this information to authenticate users, connect services at the user’s direction, return requested answers, execute explicitly confirmed changes, secure and troubleshoot the service, prevent abuse, provide support, meet contractual requirements and respond to incidents. Our bases under applicable UK data-protection law may include performing our contract, legitimate interests in operating and securing the service, consent where required, and legal obligations.
05 · Retention
How long we keep it
Encrypted connection credentials and profile metadata remain until the connection or account is removed or the grant is revoked. Amazon Ads write audits are automatically deleted after the configured retention period, currently 90 days. Other security, support and transaction records are kept only as long as reasonably necessary for the stated purpose, dispute handling, security, contractual duties and legal obligations. Live read responses and report downloads are not persisted in the application database.
Disconnecting a service removes the stored credential for that connection. Amazon may also require you to revoke the grant in the relevant Amazon account.
06 · Security
How we protect information
We use encryption in transit, server-side credential encryption at rest, access controls, least-privilege operational access, signed sessions and confirmations, rate limits, private database networking, restricted logs and incident-response procedures. No internet service can guarantee absolute security. Report suspected issues through our security page.
07 · Choices
Your rights and controls
You can disconnect linked services from the account dashboard and can contact us to request access, correction, deletion, restriction or another right available under applicable law. We may need to verify your identity and may retain limited information where law, fraud prevention, security or a contractual duty requires it.
amazonGPT is intended for business users who are at least 18 years old. We may update this notice when the product, providers or legal requirements change; the current version and date will remain published here.
Effective and last updated: 3 September 2026