Legal
Privacy Policy
What SellerCycle collects from your Amazon seller account and your warehouse floor, what we do with it, who else touches it, and how to get it deleted.
Effective September 3, 2026
01
Who we are
SellerCycle is operated by SellerCycle, Inc.. We provide software that reconciles Amazon FBA removal shipments against what physically arrives at a warehouse, and prepares reimbursement claims for the difference.
This policy covers the SellerCycle web application, its API, and the mobile scanning app. Our customer is the business that holds the Amazon seller account (referred to here as “you”); their staff are users within that account.
02
What we collect
Account and team data. Company name, plan, your users’ names, email addresses, roles, and a phone number used once to verify a new signup. Passwords are stored only as hashes; we never see the plaintext.
Amazon report data, when you connect your account. We pull four FBA reports through Amazon’s Selling Partner API: removal shipments, removal orders, customer returns, and reimbursements. These contain SKUs, ASINs, FNSKUs, quantities, order identifiers, removal and shipment identifiers, license plate numbers, disposition and reason codes, reimbursement amounts, and the warehouse addresses Amazon shipped to.
Warehouse operations data. Warehouse names and addresses you enter, scans your workers record, photographs of received boxes and their contents, notes, and the reimbursement cases your team files.
Technical data. Server logs (IP address, user agent, request paths, timestamps) kept for security and debugging, and an append-only audit log of state-changing actions taken in the product.
03
Buyer data
SellerCycle is not designed to process Amazon buyer personal information, and we do not collect buyer names, shipping addresses, email addresses, or phone numbers. We do not request any Amazon role that grants access to Personally Identifiable Information.
One exception you should know about. Amazon’s FBA customer returns report includes a free-text “customer comments” field written by the buyer, which explains why a unit came back. We store that field alongside the return it belongs to, because the reason for a return is what determines whether a reimbursement claim is valid. Buyers occasionally type identifying details into that box. We do not index, mine, or share this field, it is visible only to users within your own account, and it is deleted with the rest of your data on request.
05
Managed filing and Seller Central credentials
If you opt into our managed filing service, a SellerCycle filing specialist submits Seller Support cases on your behalf. That requires signing into Seller Central as you, so the service asks you to store a Seller Central password.
This is optional, off by default, and designed to be narrow:
- we ask you to create a secondary Seller Central user inside your own business account with only the permissions filing requires, never your owner login;
- the password is encrypted at rest with AES-256-GCM under the same Secret Manager master key as your Amazon authorization;
- it can only be read while your managed-service grant is live, and every read is written to an access log you can request;
- it is deleted when you cancel the managed service or ask us to remove it.
We never ask for, store, or transmit multi-factor authentication codes. If you would rather we did not hold a Seller Central credential at all, do not enable managed filing — every other part of SellerCycle works without it, and your team files its own cases from claims we prepare.
06
How we use it
We use your data only to operate the product you are paying for:
- reconciling removals against receipts, and flagging the discrepancies;
- preparing and tracking reimbursement claims;
- showing your team its own operational history and audit trail;
- transactional email — invitations, password resets, and alerts such as your Amazon authorization needing to be reconnected;
- security, abuse prevention, billing, and support.
We do not sell your data. We do not use your Amazon report data to train machine-learning models, we do not pool it with other sellers’ data to build market analytics, and we do not share it with your competitors.
08
How we protect it
- All traffic is encrypted in transit over TLS.
- Amazon authorizations and Seller Central credentials are encrypted at rest with AES-256-GCM; the master key lives in Google Cloud Secret Manager, separate from the database.
- Every record is scoped to one tenant and enforced on every query; users see only the warehouses their role assigns them.
- State-changing actions are written to an append-only audit log, including connecting and disconnecting your Amazon account.
- Access to production data is limited to staff who need it, and credential reads are logged.
No system is perfect. If you believe you have found a vulnerability, write to security@sellercycle.ai and we will respond.
09
Retention and deletion
We keep your operational data for as long as your account is active, because reimbursement claims depend on months of history — Amazon itself allows claims for a window measured in months, and a shipment received in March may only become claimable in June.
Beyond that:
- Disconnecting Amazon deletes the stored authorization immediately. Reports already imported remain, because they are your operational records.
- Deleting your account — write to privacy@sellercycle.ai. We delete your data within 90 days of verifying the request, across primary storage and backups as they roll over.
- Audit and billing records are retained where law requires, stripped of anything not needed for that purpose.
10
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it. Most of this you can do yourself in the product — exports, user management, disconnecting Amazon — and for anything else, write to privacy@sellercycle.ai. We respond within 30 days.
Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or the CCPA, including the right to complain to your data protection authority. We honor these requests regardless of where you are.
11
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will email the account owner before it takes effect and update the effective date above. Continuing to use SellerCycle after that date means the new policy applies.
12
Contact
SellerCycle, Inc., operator of SellerCycle.
- Privacy and data requests: privacy@sellercycle.ai
- Security reports: security@sellercycle.ai
- Everything else: support@sellercycle.ai