AgentXray Blog Pricing

Privacy Policy

What AgentXray stores about a seller, what it never asks Amazon for, and how long anything is kept after a disconnect.

Privacy Policy

Last updated: 24 April 2026

This Privacy Policy explains how AgentXray handles personal data. We have tried to write it in plain English. If anything is unclear, email us at [email protected] and we will explain.


1. Who we are

AgentXray is a SaaS platform operated by Avanta Global EOOD, a sole-shareholder limited liability company registered in the Republic of Bulgaria (the "Company", "we", "us", or "our"). We build research and analytics tools for Amazon sellers.

For the purposes of the EU General Data Protection Regulation (GDPR), Avanta Global EOOD is the data controller for account data we collect about you directly (e.g. signup, billing), and a data processor for Amazon seller data that you connect to the platform through SP-API.


2. What data we collect

We collect only what we need to run the service.

2.1 Account data (you give us directly)

2.2 Amazon seller data (you connect via SP-API OAuth)

When you connect your Amazon Seller Central account, Amazon issues us an OAuth token that grants access to specific data on your behalf. We request only the scopes our features need. The categories we access are:

We do NOT request restricted-role scopes. In particular, we do not access Personally Identifiable Information (PII) about your buyers (buyer names, shipping addresses, email, phone numbers). If a feature in the future needs this, we would apply for the specific restricted role, update this policy, and ask you to re-consent.

2.3 Usage data (collected automatically)

2.4 Content you create

We do not buy personal data about you from external data brokers.


3. How we use your data

We use your data only for the following purposes:

  1. Provide the service. Authenticate you, show you your own Amazon data, run analytics, send the API calls you trigger.
  2. Operate and improve the platform. Keep things running, fix bugs, measure aggregated usage (e.g. "how many people ran the X report this week"), investigate abuse.
  3. Communicate with you. Account notifications, security alerts, billing receipts, scheduled reports you opt in to. Marketing emails only with your opt-in, and always unsubscribable.
  4. Comply with law. Tax records, responding to valid legal requests.
  5. Security. Detect and prevent fraud, abuse, and unauthorised access.

We do not use your Amazon seller data to train AI models or share it with other customers. Ever.


4. Legal basis for processing (GDPR Art. 6)

Processing activity Legal basis
Creating and maintaining your account Contract performance (Art. 6(1)(b))
Processing your Amazon seller data inside the app Contract performance (Art. 6(1)(b))
Sending service emails (billing, security, outage) Contract performance
Sending marketing emails Consent (Art. 6(1)(a)) — you can withdraw anytime
Analytics and product improvement (aggregated) Legitimate interests (Art. 6(1)(f))
Abuse and fraud detection Legitimate interests
Responding to legal requests, keeping tax records Legal obligation (Art. 6(1)(c))

You can object to processing based on legitimate interests — see Section 9.


5. Third-party processors (sub-processors)

We use a small number of carefully chosen vendors to run the platform. Each one only receives the minimum data needed.

Processor Purpose Data sent Location
External market data provider Historical pricing and ranking data ASIN lookups you trigger. No account or seller data. EU
Resend Transactional email delivery Your email address + the email content we send EU / US
Anthropic AI content generation (Claude models) Prompts you submit to AI features + any context attached by you. No Amazon seller data is included unless you paste it into a prompt. US
OpenRouter AI model gateway (routing to third-party LLMs) Prompts you submit to AI features US
Google (OAuth) "Sign in with Google" authentication Your Google email and basic profile (name, avatar) US / Global
Amazon (SP-API) Source of your seller data (you connect this) OAuth token; API calls we make on your behalf Global
Stripe (if billing enabled) Payments Billing name, address, card data (we never see the card) Global
Cloudflare DNS, CDN, DDoS protection, WAF IP address, request metadata Global
Our VPS provider Hosting (compute, storage) All application data EU

When we add or change a sub-processor, we update this list. If the change materially affects how your data is handled, we notify customers at least 30 days in advance so you can object.

A full list with current contact details is available on request at [email protected].


6. Data retention

Data type Retention
Account data (active account) Kept while your account is active
Amazon seller data (active account) Rolling 24 months of historical data
Data after you cancel Deleted 90 days after cancellation (grace period to let you re-activate or export)
Amazon Information (SP-API data) Deleted within 30 days of account closure, except where retention is required by law (per Amazon Data Protection Policy §3.2)
Raw server logs 30 days
Aggregated, anonymised analytics Indefinite (cannot be linked back to you)
Billing and invoice records 10 years (legal retention requirement in the EU)
Backups Overwritten on a rolling 30-day cycle

You can ask us to delete your data earlier — see Section 9.


7. Data sharing

We do not sell your data. Full stop.

We share data only in these narrow cases:

  1. Sub-processors (Section 5) acting on our instructions under a data processing agreement.
  2. Law enforcement, when we receive a valid subpoena, court order, or equivalent legal instrument, and only the specific data requested. We will try to notify you first unless legally prohibited.
  3. Corporate transactions (merger, acquisition, sale of assets). In that case the acquirer steps into our shoes and you will be notified at least 30 days before any change to how your data is handled, and given the option to delete your account first.
  4. With your explicit consent, for any case not listed above.

8. International transfers

Our primary infrastructure sits in the European Union. However, some sub-processors (Anthropic, OpenRouter, Stripe, Google, Cloudflare) operate in or route through the United States or other non-EEA jurisdictions.

When your data leaves the EEA, we rely on:

You can request a copy of the SCCs we have in place with any specific sub-processor.


9. Your rights

Under GDPR (and equivalent laws in other jurisdictions) you have the following rights. You can exercise any of them by emailing [email protected] with the subject "Privacy Request". We respond within 30 days.

We do not charge a fee for these requests unless they are manifestly excessive.

Self-service account deletion

You can delete your account at any time from Settings → Danger Zone → Delete account. The flow requires password re-entry and a typed confirmation to prevent accidental deletion.

When you delete your account:

Billing and invoice records are retained for 10 years as required by EU tax law (see §6). If you change your mind during the 30-day window, email [email protected] with the subject "Restore account" — we can recover your account up until the hard-delete cron runs.


10. Security

We take security seriously. Our current controls include:

We do not claim full-disk encryption on the host. We have asked our hosting provider for a written attestation and have not received one, so we treat the underlying disk as unencrypted and protect the sensitive fields at the application layer instead, as described above.

No system is 100% secure. If we experience a personal data breach, we will notify the relevant supervisory authority within 72 hours where required, and affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms.


11. Cookies and tracking

AgentXray uses the minimum set of cookies and browser-storage entries needed to run the service. A full audit is maintained internally; the categories you encounter are listed below.

Strictly necessary (no consent required, cannot be disabled):

Functional (preferences — used to remember how you've configured the app):

Analytics: Plausible — cookie-free and aggregate — plus one first-party counter of our own. From 2026-08-28, when you arrive from an AI answer engine (ChatGPT, Perplexity, Claude, Copilot, Gemini), the page reports that fact once so we can count how often those engines cite us. It sends the referring address and the page you landed on; the server keeps only a daily tally per engine and per page, and discards anything that is not one of those engines. No cookie, no identifier, no IP address, nothing about you is stored. We do not use Google Analytics, GA4, Facebook Pixel, Hotjar, Mixpanel, Segment, Amplitude, LinkedIn Insight, or TikTok Pixel. (The Google Ads conversion tag described under Advertising is loaded via Google's gtag.js script with analytics storage disabled — it measures ad clicks, not browsing.)

Advertising: a handful of cookies, and only if you accept them. From 2026-08-19 we advertise on Reddit (_rdt_uuid); from 2026-08-27 briefly on Meta — Facebook and Instagram — (_fbp, and _fbc if you arrived by clicking one of their ads; switched off 2026-08-28); and from 2026-08-30 on Google Search (_gcl_au, and _gcl_aw if you arrived by clicking a Google ad). Accepting the cookie banner loads those trackers; they exist so we can tell which ads brought people here. If you decline, none of them loads. Details and the withdrawal button are in the Cookie Policy. Before 2026-08-19 no advertising cookie was set and this policy said so; the consent banner was re-issued on each of those dates rather than reusing older answers.

Your application data and Amazon-derived data are never used for advertising and never leave our infrastructure for that purpose. What is shared with Reddit, Meta or Google is limited to the advertising cookie values, IP address, browser user agent, the page address the event happened on, and — for account holders, on Reddit and Meta only — a one-way SHA-256 hash of the email address, never the address itself; Google receives no email in any form. No advertising tracker loads on /app or /backoffice at all, regardless of consent, so nothing you do inside the product is reported to an advertising network.

Google click id (gclid), from 3 September 2026. If you arrive by clicking one of our Google Search ads, the ad's link carries a click identifier that Google created. We store that identifier on our servers, for up to 90 days, for one purpose: to tell Google that the click led to a signup, so we can see which ads work. It is Google's own identifier being returned to Google — it is not shared with anyone else, it is never joined to your Amazon data, and it says nothing about you that Google did not already know when it sent you here. We report a signup this way only if you accepted cookies; if you declined, or never answered, nothing is sent and the identifier is deleted. Ninety days is also the point at which Google stops recognising it, so we keep it for exactly as long as it can be used and no longer.

Withdraw consent

You can withdraw your cookie consent at any time. Scroll to the bottom of this page and click Withdraw cookie consent: we clear the locally-stored consent flag, log the withdrawal in our consent ledger, and re-display the cookie banner on your next page load. Withdrawal is exactly as easy as giving consent in the first place.


12. Amazon Seller Data Handling (prominent section)

Because this platform handles data from Amazon Seller Central, some specific commitments:


13. Children

AgentXray is a B2B product. It is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we have, email us and we will delete it.


14. Changes to this policy

We will update this policy when the service changes or when the law requires.

Previous versions of this policy are available on request.


15. Contact

If you are in the EU and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority.