Privacy Policy
Effective 14 August 2026 · Version 1.0 · Controller: Secew, LLC Secew, Strazheska Akademika St, 5, apt. 15, 03126 Kyiv, Ukraine · registration number 45498326, registered 18 July 2024 · support@secew.com
This policy explains what data GlassBox by Secew collects, why, how it is used, where it is stored, how it is protected, who it is shared with, and when it is deleted. It applies to the GlassBox web application and to this website. It is written to meet Amazon's Data Protection Policy and Acceptable Use Policy for Selling Partner API providers, and the EU General Data Protection Regulation.
1. Who we are
Secew is an independent software company registered in Kyiv, Ukraine, in July 2024. We build and operate GlassBox, analytics software for Amazon selling partners. We are the data controller for the account and website data described in section 2.1, and a data processor acting on the selling partner's instructions for the Amazon information described in section 2.2.
We are not affiliated with, endorsed by, or sponsored by Amazon.
2. What we collect
2.1 Data about you as our customer (we are the controller)
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, work email address, password hash, company name, role, language and interface preferences. | You, at sign-up. |
| Billing data | Billing name and address, VAT number, plan, invoice history, payment status. We never see or store your card number. | You, and our payment provider. |
| Support data | Messages you send us and our replies. | You. |
| Technical logs | IP address, browser type, timestamps, pages and API endpoints requested, error traces. | Generated automatically when you use the service. |
| Website enquiries | What you type into the contact or quote form on this website. | You. |
2.2 Data from your Amazon accounts (we are the processor)
When you authorise GlassBox, it reads data from your own Amazon selling account. In the language of Amazon's policies, this is Information, and it belongs to you. We process it only to provide the service to you.
| Category | Examples |
|---|---|
| Advertising data | Campaign, ad group, keyword and target structure; bids; search term, advertised-product and purchased-product report metrics; negative keywords. |
| Search Query Performance | Query-level funnel metrics for your ASINs, from Amazon Brand Analytics. |
| Catalogue data | Your ASINs, parent-child relationships, variation attributes, titles, images, sales ranks, list prices. |
| Pricing and fees | Current offers and Buy Box position for your ASINs, and fee estimates for them. |
| Inventory data | FBA quantities by country, listing quantities. |
| Financial data | Financial events aggregated per SKU and fee type: referral fees, fulfilment fees, storage, refunds, reimbursements. |
| Credentials | The OAuth refresh tokens and client credentials you supply so the application can act for you. Stored encrypted; never displayed after entry; never logged. |
What we deliberately do not collect. GlassBox does not request or hold personally identifiable information about Amazon customers. It does not call the Orders API, does not request restricted data tokens, and holds no buyer names, addresses, phone numbers, email addresses or order-level identifiers. It requests no Selling Partner API role whose purpose is access to personally identifiable information about Amazon customers.
2.3 Data from your own business systems (optional)
If you choose to connect your own inventory, ERP or e-commerce system using your own credentials, we receive what you configure it to send — typically supplier names, purchase order dates and quantities, carton dimensions, unit costs and stock counts. That is your business data about your own suppliers. It is not Amazon information, it stays in your isolated database, and it is used only to produce your own lead-time and cost figures.
3. How we use it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the service: computing recommendations, running the approval queue, exporting or executing approved actions. | 2.2, 2.3 | Performance of a contract, and our documented instructions from you as processor. |
| Account management, authentication, support. | 2.1 | Performance of a contract. |
| Billing, invoicing, tax compliance. | Billing data | Contract, and legal obligation. |
| Security, abuse prevention, debugging, capacity planning. | Technical logs | Legitimate interest in operating a secure service. |
| Answering an enquiry you sent us. | Website enquiries | Steps taken at your request before entering a contract. |
| Service notices about outages, breaking changes and policy updates. | Work email | Legitimate interest in keeping customers informed. These are not marketing. |
We do not use your data for advertising, we do not profile you, we do not sell any of it, and we do not make automated decisions with a legal or similarly significant effect on you — every change GlassBox proposes to your Amazon account requires a human to approve it.
We do not use your data to train models. Not ours, and not anyone else's: our model provider processes our requests under instructions that prohibit training on them.
4. Where it is stored
- The application and its databases run on a virtual server rented from IONOS SE, in Germany (European Union). We operate no other production location.
- Backups of the database are kept Germany (EU), on the same provider. Whatever the answer, credentials inside a backup stay encrypted exactly as they are in the live database, and the key that decrypts them is not in the backup.
- Each customer's Amazon information lives in its own separate database — in our deployment, its own database file. There is no shared table holding several customers' Amazon data.
- Some of our processors operate outside the European Economic Area (see section 6). Where personal data is transferred there, it is covered by the European Commission's standard contractual clauses together with the additional measures those clauses require.
5. How it is protected
- Encryption in transit. TLS on every connection: browser to service, service to Amazon, service to every processor.
- Encryption at rest for secrets. API keys, OAuth refresh tokens and any key you supply are encrypted before storage using authenticated symmetric encryption. The master key is supplied through the deployment environment, is never stored in the database, and is not captured by database backups — a copy of the database on its own decrypts nothing. Secrets are never written to logs and are not shown again after entry.
- Isolation by construction. One database per selling account — a separate database file in our deployment — so a bug in a query cannot return another customer's rows.
- Least privilege. Staff access to customer data is granted per task, logged, and withdrawn when the task ends.
- Full audit trail. Every proposal, approval, rejection, export and execution is recorded with timestamp, actor and the evidence behind it, and is visible to you.
- Session security. Passwords are stored as scrypt hashes with a per-user salt, never in a recoverable form. Session cookies are restricted to our own site. Every response carries a content security policy, and the pages that handle authorisation callbacks run under a stricter one still.
- Incident response. If a breach affects your data, we notify you without undue delay, and Amazon within 24 hours of discovery where Amazon information is involved, as Amazon's Data Protection Policy requires. The notice states what happened, what data was affected, and what we are doing.
No system is perfectly secure, and we do not claim ours is. We claim that these controls are in place and that we will tell you promptly if they fail.
7. How long it is kept, and how it is deleted
| Data | Retention |
|---|---|
| Amazon reports and derived analysis | While your subscription is active, up to the history limit written into your quote. Where you work from your own uploaded files without a subscription, they are kept until you delete them or ask us to. |
| Recommendations and audit log | While your subscription is active. The audit log is retained for the life of the account because it is the record of what was done to your Amazon account. |
| Credentials you supplied | Until you remove them, or until the account is deleted, whichever is first. |
| Account and support data | While your account exists, then 30 days. |
| Technical logs | 90 days, then deleted. |
| Invoices and tax records | As long as tax law requires. These contain billing details, not Amazon information. |
On cancellation. Data is retained for 30 days so you can return or export it, then deleted.
On request. Write to support@secew.com from the email address on the account. We delete within 30 days and confirm in writing when it is done. Deleting an account deletes its database — reports, recommendations, audit log and stored credentials together. Daily backups rotate automatically; historical recovery archives are retained separately and do not expire through daily rotation. A deletion request includes an explicit check of those archives and cloud copies. We remove or rewrite every copy that contains the account before confirming completion within the stated 30-day period.
If you revoke authorisation in Amazon. The application immediately loses the ability to read or write anything in your account. Data already held is then treated under the cancellation rule above.
8. Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your personal data, to correct it, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing rests on consent. Similar rights exist under Ukrainian law.
Write to support@secew.com. We answer within 30 days, free of charge. We may ask you to confirm your identity before acting, to make sure we are not handing your data to somebody else.
You also have the right to complain to a supervisory authority in the country where you live or work. We would rather you told us first, so we can fix it.
9. Amazon-specific commitments
For Amazon information specifically, and in addition to everything above, we commit to the following. Each corresponds to a clause of Amazon's Acceptable Use Policy.
- We are clear and honest about what data we access and why. The complete list of endpoints and reports we call is published on the Data and AI page.
- We are explicit about calculations and about any use of artificial intelligence, including accuracy and data freshness. That disclosure is here.
- We request no information that is not necessary for the application to function, and no role whose purpose is access to buyer personal data.
- We obtain Amazon information only from Amazon, through interfaces you authorised or files you supplied. We do not use, offer or promote any external service that vends data derived from Amazon's websites.
- We do not aggregate data across selling partners to provide or sell to anyone.
- We do not promote, publish or share insights about Amazon's business, and we do not use such insights for our own purposes.
- We do not disclose your information to other users, affiliates or outside parties, except where required to perform the activity you asked for.
- We perform due diligence on every party we share data with and require security standards at least as strict as our own.
- We never ask for your Seller Central username or password, and never accept access keys belonging to another provider.
- We act only for selling partners who have granted permission through Amazon's own authorisation flow.
11. Children
GlassBox is a business tool, not directed at children, and not available to anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
When we change this policy we update the version and date at the top. For changes that materially affect how your data is handled — a new processor, a new category of data, a new purpose — we notify account holders by email at least 30 days before the change takes effect, and the Data and AI page is updated first. Previous versions are available on request.
13. How to contact us
Secew · LLC Secew · Strazheska Akademika St, 5, apt. 15, 03126 Kyiv, Ukraine · registration number 45498326, registered 18 July 2024
All privacy questions, access requests and deletion requests: support@secew.com. We reply within two business days and complete requests within 30 days.