Privacy Policy
What AgentXray stores about a seller, what it never asks Amazon for, and how long anything is kept after a disconnect.
Privacy Policy
Last updated: 24 April 2026
This Privacy Policy explains how AgentXray handles personal data. We have tried to write it in plain English. If anything is unclear, email us at [email protected] and we will explain.
1. Who we are
AgentXray is a SaaS platform operated by Avanta Global EOOD, a sole-shareholder limited liability company registered in the Republic of Bulgaria (the "Company", "we", "us", or "our"). We build research and analytics tools for Amazon sellers.
- Legal entity: Avanta Global EOOD
- Operating brand: AgentXray
- Website: https://agentxray.ai
- Registered office: [To be added — company registered office in Bulgaria]
- General contact: [email protected]
- Privacy / DPO contact: [email protected]. Mark the subject line "Privacy Request" or "DPO".
For the purposes of the EU General Data Protection Regulation (GDPR), Avanta Global EOOD is the data controller for account data we collect about you directly (e.g. signup, billing), and a data processor for Amazon seller data that you connect to the platform through SP-API.
2. What data we collect
We collect only what we need to run the service.
2.1 Account data (you give us directly)
- Email address
- Name (first and last, if provided)
- Password (stored as a PBKDF2-HMAC-SHA256 hash — we never see the plaintext)
- Internal tenant identifier (
tenant_id) we generate to isolate your workspace - Billing contact details if you subscribe to a paid plan (name, billing address, VAT ID where applicable). Payment card data is handled directly by our payment processor — we never store full card numbers.
2.2 Amazon seller data (you connect via SP-API OAuth)
When you connect your Amazon Seller Central account, Amazon issues us an OAuth token that grants access to specific data on your behalf. We request only the scopes our features need. The categories we access are:
- Orders — order IDs, SKUs, quantities, order status, fulfilment channel, order totals, timestamps
- Inventory — SKU, ASIN, quantity on hand, inbound/reserved/unfulfillable quantities, warehouse location
- Listings / Catalog — your product listings (titles, ASINs, SKUs, prices, attributes)
- Financial events — settlements, fees, refunds, adjustments, reserves
- Account health — policy compliance metrics, performance scores, notifications
- Reports — reports you or we generate via the Reports API for any of the above
We do NOT request restricted-role scopes. In particular, we do not access Personally Identifiable Information (PII) about your buyers (buyer names, shipping addresses, email, phone numbers). If a feature in the future needs this, we would apply for the specific restricted role, update this policy, and ask you to re-consent.
2.3 Usage data (collected automatically)
- IP address (truncated for analytics, retained in full in raw logs for up to 30 days for security purposes)
- User-agent string
- Pages / endpoints visited, HTTP status codes, response times
- Session cookies (see Section 11)
- Errors and stack traces triggered by your session (to debug bugs)
2.4 Content you create
- Research queries, saved lists, notes, and any content you generate inside the app
- AI prompts and outputs you run through our assistant features (subject to the third-party AI processor rules in Section 5)
We do not buy personal data about you from external data brokers.
3. How we use your data
We use your data only for the following purposes:
- Provide the service. Authenticate you, show you your own Amazon data, run analytics, send the API calls you trigger.
- Operate and improve the platform. Keep things running, fix bugs, measure aggregated usage (e.g. "how many people ran the X report this week"), investigate abuse.
- Communicate with you. Account notifications, security alerts, billing receipts, scheduled reports you opt in to. Marketing emails only with your opt-in, and always unsubscribable.
- Comply with law. Tax records, responding to valid legal requests.
- Security. Detect and prevent fraud, abuse, and unauthorised access.
We do not use your Amazon seller data to train AI models or share it with other customers. Ever.
4. Legal basis for processing (GDPR Art. 6)
| Processing activity | Legal basis |
|---|---|
| Creating and maintaining your account | Contract performance (Art. 6(1)(b)) |
| Processing your Amazon seller data inside the app | Contract performance (Art. 6(1)(b)) |
| Sending service emails (billing, security, outage) | Contract performance |
| Sending marketing emails | Consent (Art. 6(1)(a)) — you can withdraw anytime |
| Analytics and product improvement (aggregated) | Legitimate interests (Art. 6(1)(f)) |
| Abuse and fraud detection | Legitimate interests |
| Responding to legal requests, keeping tax records | Legal obligation (Art. 6(1)(c)) |
You can object to processing based on legitimate interests — see Section 9.
5. Third-party processors (sub-processors)
We use a small number of carefully chosen vendors to run the platform. Each one only receives the minimum data needed.
| Processor | Purpose | Data sent | Location |
|---|---|---|---|
| External market data provider | Historical pricing and ranking data | ASIN lookups you trigger. No account or seller data. | EU |
| Resend | Transactional email delivery | Your email address + the email content we send | EU / US |
| Anthropic | AI content generation (Claude models) | Prompts you submit to AI features + any context attached by you. No Amazon seller data is included unless you paste it into a prompt. | US |
| OpenRouter | AI model gateway (routing to third-party LLMs) | Prompts you submit to AI features | US |
| Google (OAuth) | "Sign in with Google" authentication | Your Google email and basic profile (name, avatar) | US / Global |
| Amazon (SP-API) | Source of your seller data (you connect this) | OAuth token; API calls we make on your behalf | Global |
| Stripe (if billing enabled) | Payments | Billing name, address, card data (we never see the card) | Global |
| Cloudflare | DNS, CDN, DDoS protection, WAF | IP address, request metadata | Global |
| Our VPS provider | Hosting (compute, storage) | All application data | EU |
When we add or change a sub-processor, we update this list. If the change materially affects how your data is handled, we notify customers at least 30 days in advance so you can object.
A full list with current contact details is available on request at [email protected].
6. Data retention
| Data type | Retention |
|---|---|
| Account data (active account) | Kept while your account is active |
| Amazon seller data (active account) | Rolling 24 months of historical data |
| Data after you cancel | Deleted 90 days after cancellation (grace period to let you re-activate or export) |
| Amazon Information (SP-API data) | Deleted within 30 days of account closure, except where retention is required by law (per Amazon Data Protection Policy §3.2) |
| Raw server logs | 30 days |
| Aggregated, anonymised analytics | Indefinite (cannot be linked back to you) |
| Billing and invoice records | 10 years (legal retention requirement in the EU) |
| Backups | Overwritten on a rolling 30-day cycle |
You can ask us to delete your data earlier — see Section 9.
7. Data sharing
We do not sell your data. Full stop.
We share data only in these narrow cases:
- Sub-processors (Section 5) acting on our instructions under a data processing agreement.
- Law enforcement, when we receive a valid subpoena, court order, or equivalent legal instrument, and only the specific data requested. We will try to notify you first unless legally prohibited.
- Corporate transactions (merger, acquisition, sale of assets). In that case the acquirer steps into our shoes and you will be notified at least 30 days before any change to how your data is handled, and given the option to delete your account first.
- With your explicit consent, for any case not listed above.
8. International transfers
Our primary infrastructure sits in the European Union. However, some sub-processors (Anthropic, OpenRouter, Stripe, Google, Cloudflare) operate in or route through the United States or other non-EEA jurisdictions.
When your data leaves the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
- EU-US Data Privacy Framework certification where the processor is listed, and/or
- Additional safeguards (encryption in transit and at rest, pseudonymisation where feasible).
You can request a copy of the SCCs we have in place with any specific sub-processor.
9. Your rights
Under GDPR (and equivalent laws in other jurisdictions) you have the following rights. You can exercise any of them by emailing [email protected] with the subject "Privacy Request". We respond within 30 days.
- Access. Get a copy of the personal data we hold about you.
- Rectification. Ask us to correct inaccurate data.
- Erasure ("right to be forgotten"). Ask us to delete your data. We will honour this unless we have a legal obligation to retain it (e.g. tax records).
- Portability. Get your data in a machine-readable format (JSON / CSV) so you can move it elsewhere.
- Restriction. Ask us to stop certain processing while we investigate a dispute.
- Objection. Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent. For any processing based on consent, you can withdraw it at any time. It does not affect processing that already happened.
- Lodge a complaint with your local EU data protection authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
We do not charge a fee for these requests unless they are manifestly excessive.
Self-service account deletion
You can delete your account at any time from Settings → Danger Zone → Delete account. The flow requires password re-entry and a typed confirmation to prevent accidental deletion.
When you delete your account:
- Immediately: your login is disabled, your Amazon Seller Central refresh tokens are revoked, any active subscription is canceled at the end of the current billing period, and your email address is freed for re-registration.
- Within 30 days: all personal data and Amazon Information are hard-deleted from production databases. This includes data collected via the Amazon Selling Partner API (orders, inventory, listings, fees, account-health snapshots), in line with the Amazon Data Protection Policy.
- Within 30 days: the encrypted off-site backups containing your data age out of the rolling backup cycle (local copies age out within 7 days).
Billing and invoice records are retained for 10 years as required by EU tax law (see §6). If you change your mind during the 30-day window, email [email protected] with the subject "Restore account" — we can recover your account up until the hard-delete cron runs.
10. Security
We take security seriously. Our current controls include:
- TLS 1.2+ on every connection to the platform, with HSTS,
X-Frame-Options: DENY,nosniffand a strict referrer policy on responses. - Application-level encryption (Fernet, AES-128-CBC + HMAC-SHA256) for the sensitive material: Amazon SP-API refresh tokens, access tokens and LWA client secrets. The key is held in the service environment, never in the database, so a database dump alone yields no usable credentials.
- PBKDF2-HMAC-SHA256 at 600,000 iterations for password hashing, with a per-user salt. No plaintext passwords anywhere.
- Principle of least privilege. The application connects to the database as a dedicated role that can read and write application data but cannot alter the schema, is not a database superuser, and cannot bypass row-level access rules. Schema changes run separately under a privileged connection the application never uses. Direct human database access is restricted to named operators and logged.
- Multi-factor authentication on the administrative accounts that control our infrastructure. Verified on 2026-08-03: the Google Workspace tenant (2-step verification enabled) and the DNS/CDN provider account (TOTP enabled, backup codes issued). Enrolment on the remaining operator accounts is tracked internally.
- Network protection via Cloudflare in front of the origin and a host firewall (ufw) that exposes only ports 22, 80 and 443.
- SSH password authentication is disabled entirely; access is key-only, and fail2ban blocks brute-force attempts.
- Backups: the database is dumped daily, gzipped, encrypted with
age, and copied off-site to Cloudflare R2 with an integrity check on upload. Local copies are kept 7 days, off-site copies 30 days. - Incident response plan reviewed every 6 months.
We do not claim full-disk encryption on the host. We have asked our hosting provider for a written attestation and have not received one, so we treat the underlying disk as unencrypted and protect the sensitive fields at the application layer instead, as described above.
No system is 100% secure. If we experience a personal data breach, we will notify the relevant supervisory authority within 72 hours where required, and affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
11. Cookies and tracking
AgentXray uses the minimum set of cookies and browser-storage entries needed to run the service. A full audit is maintained internally; the categories you encounter are listed below.
Strictly necessary (no consent required, cannot be disabled):
amalyze_token,amalyze_refresh_token,amalyze_user— your authentication tokens and cached profile, stored in browser localStorage so we don't have to ask you to log in on every page. Cleared on logout.redirect_after_login— short-lived sessionStorage entry so we can return you to the page you were on after signing in. Discarded when you close the tab.agentxray_consent_v1— your recorded choice on the cookie banner, so we don't ask you again on every visit.consent_id— an HTTP cookie linking an anonymous visitor to a row in our consent ledger. Required to give effect to your consent decision. HttpOnly, Secure, SameSite=Lax, 1-year expiry.
Functional (preferences — used to remember how you've configured the app):
theme— your light/dark theme preference.admin_sidebar_collapsed— admin sidebar collapsed/expanded state.amalyze_onboarding— whether you've completed or skipped the first-run onboarding wizard.savedKeywords— keywords you have starred for later use.
Analytics: Plausible — cookie-free and aggregate — plus one first-party counter of our own. From 2026-08-28, when you arrive from an AI answer engine (ChatGPT, Perplexity, Claude, Copilot, Gemini), the page reports that fact once so we can count how often those engines cite us. It sends the referring address and the page you landed on; the server keeps only a daily tally per engine and per page, and discards anything that is not one of those engines. No cookie, no identifier, no IP address, nothing about you is stored. We do not use Google Analytics, GA4, Facebook Pixel, Hotjar, Mixpanel, Segment, Amplitude, LinkedIn Insight, or TikTok Pixel. (The Google Ads conversion tag described under Advertising is loaded via Google's gtag.js script with analytics storage disabled — it measures ad clicks, not browsing.)
Advertising: a handful of cookies, and only if you accept them. From 2026-08-19 we advertise on Reddit (_rdt_uuid); from 2026-08-27 briefly on Meta — Facebook and Instagram — (_fbp, and _fbc if you arrived by clicking one of their ads; switched off 2026-08-28); and from 2026-08-30 on Google Search (_gcl_au, and _gcl_aw if you arrived by clicking a Google ad). Accepting the cookie banner loads those trackers; they exist so we can tell which ads brought people here. If you decline, none of them loads. Details and the withdrawal button are in the Cookie Policy. Before 2026-08-19 no advertising cookie was set and this policy said so; the consent banner was re-issued on each of those dates rather than reusing older answers.
Your application data and Amazon-derived data are never used for advertising and never leave our infrastructure for that purpose. What is shared with Reddit, Meta or Google is limited to the advertising cookie values, IP address, browser user agent, the page address the event happened on, and — for account holders, on Reddit and Meta only — a one-way SHA-256 hash of the email address, never the address itself; Google receives no email in any form. No advertising tracker loads on /app or /backoffice at all, regardless of consent, so nothing you do inside the product is reported to an advertising network.
Google click id (gclid), from 3 September 2026. If you arrive by clicking one of our Google Search ads, the ad's link carries a click identifier that Google created. We store that identifier on our servers, for up to 90 days, for one purpose: to tell Google that the click led to a signup, so we can see which ads work. It is Google's own identifier being returned to Google — it is not shared with anyone else, it is never joined to your Amazon data, and it says nothing about you that Google did not already know when it sent you here. We report a signup this way only if you accepted cookies; if you declined, or never answered, nothing is sent and the identifier is deleted. Ninety days is also the point at which Google stops recognising it, so we keep it for exactly as long as it can be used and no longer.
Withdraw consent
You can withdraw your cookie consent at any time. Scroll to the bottom of this page and click Withdraw cookie consent: we clear the locally-stored consent flag, log the withdrawal in our consent ledger, and re-display the cookie banner on your next page load. Withdrawal is exactly as easy as giving consent in the first place.
12. Amazon Seller Data Handling (prominent section)
Because this platform handles data from Amazon Seller Central, some specific commitments:
- PII protection. We do not request or store buyer PII (no buyer names, no buyer addresses, no buyer email, no buyer phone numbers). The SP-API scopes we request are limited to our own operational needs (orders, inventory, listings, finances, reports on your own data).
- No restricted-role access. We have not applied for — and do not currently hold — restricted SP-API roles that grant access to buyer PII. If that changes we will update this policy and require your re-consent.
- Isolation. Your Amazon seller data is isolated per
tenant_id, enforced in the application's query layer and covered by cross-tenant regression tests that run in our deploy gate. We do not currently use PostgreSQL row-level security, so we describe this as an application-layer control rather than a database-enforced one. - Token handling. OAuth refresh tokens, access tokens and LWA client secrets are all encrypted at the application layer before being written to the database. Access tokens are additionally short-lived and are refreshed rather than reused past expiry.
- Revocation. You can revoke our access at any time — both from inside AgentXray (disconnect account) and from Seller Central directly (Manage Your Apps → Revoke). Disconnecting marks the credential revoked immediately and sends a revocation call to Amazon. When we detect a revoked token, we stop calling SP-API on your behalf.
- Retention. Your Amazon seller data is deleted within 30 days of account closure, in line with the Amazon Data Protection Policy, and earlier on request.
- No sale, no resale, no training data. We do not sell your Amazon data, share it with third parties outside the sub-processors listed in Section 5, or use it to train AI models.
13. Children
AgentXray is a B2B product. It is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we have, email us and we will delete it.
14. Changes to this policy
We will update this policy when the service changes or when the law requires.
- For material changes (e.g. new categories of data, new sub-processors that meaningfully change where data goes) we will email registered users at least 30 days before the change takes effect.
- For minor changes (typos, clarifications) we will update the "Last updated" date at the top.
Previous versions of this policy are available on request.
15. Contact
- General privacy questions / exercise your rights: [email protected] (subject: "Privacy Request")
- Data Protection Officer: Avanta Global EOOD, [email protected] (subject: "DPO")
- Postal address: Avanta Global EOOD, [To be added — company registered office in Bulgaria]
If you are in the EU and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority.