Privacy Policy

Effective date: September 22, 2026

Note: This policy applies to the SellerForge web platform at sellerforge.ai. For our free Chrome extension, see the Forge Companion Privacy Policy.

1. Introduction

SellerForge ("we", "us", or "our") operates the SellerForge platform at sellerforge.ai — an AI-powered SaaS tool for Amazon sellers. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our website and services, including when you connect your Amazon account via Login with Amazon (LWA) or the Amazon Selling Partner API (SP-API) and Amazon Advertising API.

By using SellerForge or authorizing our application through Amazon, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service and revoke any Amazon account authorizations you have granted.

2. Information We Collect

2.1 Account information

When you create a SellerForge account, we collect your name and email address, plus a hashed password if you sign up with an email address rather than with Google. If you subscribe to a paid plan, billing information is collected by our payment processor, Stripe — we do not store your full payment card details.

2.2 Login with Amazon (LWA) — OAuth authorization

SellerForge uses Amazon's Login with Amazon (LWA) service to authenticate and authorize access to your Amazon seller and advertising accounts. When you connect your Amazon account, we receive:

  • An OAuth access token and refresh token used to make API calls on your behalf
  • Your Amazon account identifier (used to link your SellerForge account to your Amazon profile)
  • Your name and email address as provided by Amazon, if included in the authorized scopes

These tokens are stored securely and used solely to access Amazon APIs on your behalf within SellerForge. We do not use LWA tokens to access any Amazon data beyond what is required to operate the features you use.

2.3 Amazon Advertising API data

If you connect your Amazon Advertising account, we access the following data via the Amazon Advertising API on your behalf to power SellerForge's advertising intelligence features:

  • Advertising profiles, campaigns, ad groups, and ad targeting settings
  • Keyword bids, match types, and negative keywords
  • Advertising performance metrics: impressions, clicks, spend, sales, ACOS, ROAS, and conversion rates
  • Sponsored Products, Sponsored Brands, and Sponsored Display campaign data
  • Budget settings and pacing data

This data is used to provide AI-powered advertising analysis, bid recommendations, campaign optimization suggestions, and performance reporting within your SellerForge account. It is not shared with other users or sold to third parties.

2.4 Amazon Selling Partner API (SP-API) data

If you connect your Amazon seller account via SP-API, we may access order data, inventory levels, listing details, account health metrics, and feedback data to power SellerForge's seller tools. This data is used only within your account.

2.5 Uploaded files and documents

Files you upload to SellerForge (such as invoices, letters of authorization, or other appeal documents) are stored securely in our cloud storage and used solely to provide AI-powered analysis within your account.

2.6 Usage data

We collect standard usage information such as pages visited, features used, and actions taken within the platform to help us diagnose issues and improve the service. This includes session recordings and information collected through cookies and similar technologies, described in Section 10.

3. How We Use Your Information

  • To authenticate your identity and maintain your SellerForge session
  • To connect to Amazon's APIs and retrieve your seller and advertising data on your behalf
  • To provide AI-powered advertising analysis, bid recommendations, and campaign optimization
  • To power the Plan of Action (POA) builder, listing audit, inventory management, and other SellerForge features
  • To generate AI responses using your account data as context (processed via Anthropic's Claude API)
  • To process your subscription and send billing receipts
  • To send transactional emails related to your account
  • To diagnose technical issues and improve platform performance
  • To measure our marketing and advertising, credit sign-ups to the campaigns and partners that referred them, and pay affiliate commissions (see Sections 6 and 10)
  • To send your SellerForge data to AI assistants you connect, as you direct (see Section 11)
  • To comply with applicable laws and Amazon's API usage policies

We do not sell your personal data or your Amazon account data for money. We do share limited information about your visits and sign-up with advertising partners to measure and improve our ads (see Sections 6.3 and 10). Some privacy laws treat that as "selling" or "sharing" personal information. You can opt out at any time with Cookie settings or a Global Privacy Control signal (see Section 10).

4. How to Revoke Amazon Account Access

You may disconnect your Amazon account from SellerForge at any time in two ways:

  1. Within SellerForge: Go to your account settings and select "Disconnect Amazon Account." This will delete your stored OAuth tokens and stop all API access immediately.
  2. Directly with Amazon: Visit amazon.com/ap/adam (Login with Amazon — Manage Your Apps & Devices), find "SellerForge," and revoke access. Amazon will invalidate all tokens associated with our application.

After revocation, we will delete any cached Amazon access tokens within 24 hours. Historical data already stored in your SellerForge account (such as performance reports) will remain available in your account until you delete your account or request data deletion.

5. Data Storage and Security

Your data is stored using Supabase, a SOC 2-compliant cloud database platform. All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Amazon OAuth tokens are stored encrypted and accessed only by server-side application code — never exposed client-side.

Access to production data is restricted to authorized personnel only. We conduct regular reviews of access controls and security practices.

No method of transmission over the internet is 100% secure. While we take industry-standard precautions, we cannot guarantee absolute security.

6. Third-Party Services

We use the companies below to run SellerForge, to measure our marketing, and to connect services you choose. For each one, we list what it receives and why.

6.1 Amazon

  • Amazon (Login with Amazon / Advertising API / SP-API) — to authenticate users and access advertising and seller data on your behalf. Amazon's data is governed by Amazon's Privacy Notice.

6.2 Services that run SellerForge

  • Supabase — cloud database, authentication, and file storage. It holds your account data, your Amazon data, and the files you upload.
  • Vercel — hosts our website and app. Vercel handles every request to sellerforge.ai, which includes your IP address and browser details, and keeps server logs.
  • Railway — runs the background jobs that sync and process your Amazon data.
  • Amazon Web Services (AWS) — message queues that receive the notifications and advertising data Amazon sends for your account.
  • Anthropic (Claude API) — AI-powered features send relevant portions of your data to Anthropic's API for processing. This is governed by Anthropic's Privacy Policy.
  • DataForSEO — keyword and search-ranking data. When you use keyword research, rank tracking, or competitor features, we send DataForSEO the keywords, ASINs, and marketplace involved.
  • Stripe — payment processing. Stripe's Privacy Policy governs all payment data.
  • Resend — transactional and support email delivery, including messages you submit through the authenticated Help Center. This is governed by Resend's Privacy Policy.
  • Google (sign-in and email) — if you sign in with Google, Google shares your name, email address, and profile picture with us. Messages you send through our contact and bug-report forms are delivered to us through Gmail.
  • Upstash — rate limiting that protects the service from abuse. It keeps short-lived counters keyed to an IP address, an email address, or an account ID.
  • Sentry — error monitoring. When something breaks, the error report can include technical details about the request. We remove cookies and authorization headers before reports are sent.

6.3 Analytics, advertising, and affiliate partners

These run on our website and in the app, subject to your cookie choices. Section 10 explains those choices and the cookies these tools use.

  • PostHog — product analytics, session recordings, and error tracking. Once you sign in, PostHog links your activity to your SellerForge user ID and email address. Some events also note the marketplace or product (ASIN) involved. Our Stripe account also sends subscription and invoice events to PostHog (such as your plan, amounts, payment status, and billing email) so we can analyze revenue.
  • Google (Google Analytics and Google Ads) — records page views and actions such as signing up and subscribing, to measure site traffic and our Google ads and to build ad audiences.
  • Meta (Facebook and Instagram) — the Meta Pixel runs in your browser, and our servers also send events through Meta's Conversions API, to measure and improve our ads on Meta. The pixel records the pages you visit and actions such as button clicks. At key steps, such as signing up, starting a trial, connecting Amazon, and subscribing, our servers send Meta your IP address, browser details, and Meta cookie IDs. If you're signed in, they also send your email address, name, SellerForge user ID, and country (from your billing address or IP address), hashed first. For paid subscriptions we also send the amount paid and your hashed billing city, state, and postal code.
  • LinkedIn — the LinkedIn Insight Tag records page views and actions such as starting a trial or subscribing, to measure our LinkedIn ads and build ad audiences.
  • OpenAI — the OpenAI ads pixel records page views and sign-ups to measure our advertising with OpenAI.
  • Rewardful — runs our affiliate program. If you arrive through a partner's referral link, Rewardful records the referral. If you then subscribe, the referral is passed to Stripe, and Rewardful uses the related subscription and payment records to credit and pay the partner.

6.4 Services you choose to connect

  • Slack and webhooks — if you connect Slack or add a webhook for alerts, we send alert messages, which can include product and account details, to the Slack channel or web address you choose.
  • AI assistants (MCP) — if you connect Claude, ChatGPT, Cursor, or another AI assistant, we send it the SellerForge data it requests. See Section 11.

Advertising and analytics partners may use the information they receive for their own purposes, under their own privacy policies. Services you choose to connect handle your data under their own terms.

7. Amazon API Data Usage Restrictions

SellerForge's use of Amazon API data is subject to Amazon's API usage policies. Specifically:

  • Amazon Advertising API data is used exclusively to provide advertising management and analytics features to the account holder who authorized access
  • We do not use Amazon API data to build competing products, train machine learning models for purposes unrelated to your account, or share aggregated Amazon data with any third party
  • We do not cache Amazon API data beyond what is necessary for the platform to function
  • We comply with Amazon's data deletion requirements — upon account closure or access revocation, Amazon-sourced data is deleted per Section 8 below

8. Data Retention

We retain your account data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where retention is required by applicable law.

Amazon OAuth tokens are deleted immediately upon disconnecting your Amazon account. Cached Amazon API data (such as historical advertising reports) is retained for the duration of your subscription and deleted within 30 days of account closure or access revocation.

To request deletion of your data, email info@sellerforge.ai with the subject line "Data Deletion Request." We will process your request within 30 days.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict certain processing activities
  • Receive a portable copy of your data
  • Withdraw consent at any time (including revoking Amazon account access)

To exercise any of these rights, contact us at info@sellerforge.ai.

10. Cookies and Similar Technologies

Our website and app use cookies, local storage, pixels, and similar technologies. Some are essential. Others support analytics, advertising, and our affiliate program, and several of those are set by the companies named in Section 6.3. They run on our public pages and inside the signed-in app.

Your consent

If you visit from the EU, EEA, UK, or Switzerland (based on your IP address), we ask first. Until you choose "Accept all" in our cookie banner, we use only essential cookies, and our servers don't send your information to advertising partners. Everywhere else, the analytics, advertising, and affiliate tools described below are on by default, and you can turn them off by choosing "Reject non-essential". Wherever you are, you can change your choice at any time (see Your choices, below).

We also treat a Global Privacy Control signal from your browser as a request to opt out of advertising. While your browser sends it, the ad pixels don't load and our servers don't send your information to advertising partners. If you're signed in, we also record it on your account.

Essential

These keep you signed in, secure the Amazon connection process, and remember choices you make, such as your display theme, your cookie choice, and your answers to our sign-up questions. Our free listing audit tool also uses a visitor ID, kept for up to a year, to apply its usage limits. SellerForge can't work without these, so they're always on.

Our attribution and testing cookies

These count as analytics cookies, so they follow your cookie choice. They record how you found us: the campaign tags on the link you followed, the site that referred you, the page you landed on, and a Google Ads click ID if there is one. They last up to 90 days. If you sign up, we save this information with your account so we can see which marketing leads to sign-ups. Another cookie remembers which version of a page you saw during a test.

Product analytics (PostHog)

When analytics is allowed, PostHog runs in your browser. It records the pages you view, what you click, how pages perform, and errors you run into. It also makes session recordings of how you move through pages, along with technical messages your browser logs. Recordings are set to hide the text on each page and anything you type, and to leave out product images from Amazon. PostHog receives your IP address and can use it to estimate your approximate location. Once you sign in, it links this activity to your SellerForge user ID and email address. Session recordings are deleted after 30 days. Separately, our servers send PostHog records of key account events, such as signing up or connecting Amazon; those don't use cookies in your browser.

Advertising

When advertising is allowed, the Meta Pixel, the Google Analytics and Google Ads tags, the LinkedIn Insight Tag, and the OpenAI ads pixel load on our website and in the app. They set or read their own cookies and send those companies the pages you visit, your IP address and browser details, and actions such as signing up, starting a trial, or subscribing. We use them to measure our advertising and to build ad audiences, such as people who have visited our site. These companies may link this information to accounts you have with them and use it under their own privacy policies. Section 6.3 describes what each one receives, including the events our servers send to Meta, which follow the same choice.

Affiliate referrals (Rewardful)

When affiliate tracking is allowed and you arrive through a partner's referral link, Rewardful sets a cookie that remembers the referral for 60 days so the partner can be credited if you subscribe.

Email

Emails we send through Resend may include open and click tracking, which tells us whether a message was opened or a link in it was clicked.

Embedded videos

Some pages include YouTube videos. A video doesn't load until you press play. After that, YouTube (Google) may collect information under its own privacy policy.

Your choices

Use (also linked at the bottom of our website) to accept or reject non-essential cookies at any time. Rejecting turns off analytics, advertising, and affiliate tracking in that browser and removes the cookies those tools set on our domain. If you're signed in, we also record your choice on your account, so it applies to events we send later without your browser, such as for a subscription renewal.

You can also block or delete cookies in your browser settings. If you block essential cookies, you won't be able to sign in. To adjust ad personalization with the ad companies themselves, use your Google (My Ad Center), Meta, and LinkedIn account settings, or Google's opt-out browser add-on for Google Analytics. Our site doesn't respond to the older "Do Not Track" signal.

11. AI Assistant Connectors (MCP)

SellerForge offers a connector, built on the Model Context Protocol (MCP), that lets you use SellerForge from third-party AI assistants such as Claude, ChatGPT, Cursor, and Claude Code. Nothing is shared with an AI assistant unless you connect one. You connect either by signing in to SellerForge and approving access (OAuth) or by creating an API key in Settings → Connections. Each connection is limited to one SellerForge workspace and the permissions you approve.

What the assistant receives

When the assistant uses a SellerForge tool, we send it what that tool returns for the connected workspace. Depending on the request, this can include sales, order, and profit figures; advertising campaigns, keywords, and search terms; inventory levels; account health metrics; reimbursements; customer feedback themes and review excerpts from Amazon; listing audits; product details such as ASINs and titles; Plan of Action and escalation records you created in SellerForge; and the status of changes waiting for approval. SellerForge does not request Amazon buyers' names, addresses, or contact details from Amazon.

Why

To answer your questions and carry out the tasks you give the assistant. If you grant the "propose" permission, the assistant can stage changes, such as bid, budget, or negative-keyword changes, in your SellerForge approval queue. If your plan includes it and you grant the "apply" permission, the assistant can apply a change that has already been approved. Applied changes go through the same caps, guardrails, and kill-switch as the SellerForge app.

Who receives it

The assistant you connected and the company that provides it, for example Anthropic for Claude and Claude Code, OpenAI for ChatGPT, and Anysphere for Cursor. Once data reaches the assistant, that company's privacy policy and your settings with it govern how the data is used, stored, and shared. SellerForge does not control this, so review those terms before you connect.

What we keep, and for how long

For each connection we store the assistant's name (or the label you gave an API key), the permissions you granted, and when the connection was created and last used. We store connection tokens and API keys only in hashed form, and we show an API key only once, when you create it. We record which tools a connection calls and when, to run, secure, and improve the connector, but we don't keep a separate copy of the data returned to the assistant. Changes staged or applied through the connector appear in your approval queue and change history like any other change. Access tokens expire after one hour, and a connection that goes unused for 90 days expires. API keys expire on the date you choose, or never if you choose no expiry. Connection records are deleted with your account (see Section 8).

Revoking access

You can revoke a connected assistant or an API key at any time in Settings → Connections. It stops working immediately. Workspace owners and admins can also revoke connections that teammates created. Revoking access doesn't delete data the assistant has already received; use that assistant's own controls, such as deleting the conversation, to remove it.

12. Children's Privacy

SellerForge is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice within the platform at least 14 days before the change takes effect. Continued use of SellerForge after the effective date of changes constitutes acceptance of the updated policy.

14. Contact

For privacy-related questions, data requests, or concerns about our use of Amazon account data, contact us at:

SellerForge
info@sellerforge.ai

SellerForge is not affiliated with, endorsed by, or sponsored by Amazon.com, Inc. Amazon, Sponsored Products, and related marks are trademarks of Amazon.com, Inc.