Privacy Policy
Effective August 25, 2026
What RankHopper stores about you and your Amazon account, where it goes, how long it stays and how to get it removed.
1. Who this covers
This policy is [Founder: legal entity name]’s (“RankHopper”, “we”) account of how the RankHopper web application handles information about the people who use it and the Amazon seller accounts they connect. It goes with the Terms of Service.
2. Where the data comes from
- Amazon, through the authorization you grant on Amazon’s own consent screens for the Selling Partner API and the Amazon Ads API. We pull reports on a schedule; Amazon is the source, and receives from us only the approved changes described in the terms.
- You: what you type, upload and approve.
- The app itself: sign-in attempts, pull and purge records, and error reports.
We do not hold buyer personal data. The order rows we pull carry no buyer name, email, phone or address: those columns are refused by name before a row is stored, and we hold no Amazon restricted-data role that would expose them.
Information from Amazon’s APIs is handled under Amazon’s Data Protection Policy and Acceptable Use Policy and used only to provide the service to the seller it came from.
3. What is stored
| Account | Your email address and a hashed password, your workspace name, your role, invites you send or accept, and onboarding progress. |
|---|---|
| Amazon authorization | The refresh token from each Amazon consent, encrypted, plus the selling partner id, advertising profile id, marketplace, region and connection status. |
| Amazon seller reports | Search Query Performance, Sales & Traffic, Market Basket, Repeat Purchase and Search Catalog Performance reports; your listings; order rows (order and item ids, SKU, quantities and amounts, no buyer fields); settlement and financial events; returns, reimbursements, storage fees and the inventory ledger. The raw report files are archived alongside the rows built from them. |
| Amazon advertising | Sponsored Products and Brands reports (search terms, campaigns, targeting, placements, advertised products), a daily snapshot of your campaign, ad group, keyword and negative state, and the changes we detect between snapshots. |
| What you enter | Unit costs and expenses, goals and a maximum ad budget, brand terms and keyword rules, product groups and targets, notes and decisions on actions, custom reports and dashboards, feedback you leave, and files you upload (advertising history). |
| What the service produces | Recommendations and their grades, approved manifests and the journal of each write made to Amazon, chat threads with the analyst, and the audit trail of every pull and purge. |
| Access requests | The email address you enter on the landing page to request access, with its source, an optional referral code and hashes of your network address and browser, kept until you ask us to remove it or the account under that address is deleted. |
| Operational logs | Sign-in attempts (email and IP address, kept seven days), operator support sessions, and error reports with secrets removed. |
4. What it is used for
- Computing the diagnostics, figures, recommendations and grades shown in your workspace.
- Applying a change to Amazon after a person on your team approves it, and journaling that change so it can be audited and undone.
- Answering your questions in the analyst chat.
- Signing you in, keeping your workspace separate from every other, and protecting the service.
- Finding and fixing errors.
We do not sell your data, use it for advertising, or combine one workspace’s data with another’s. There is no aggregate or anonymized use across sellers.
5. Who processes it
| Provider | Role | What it receives |
|---|---|---|
| Supabase | Database and authentication, hosted in the United States (us-east-2) | Everything in the table above. Sends sign-in, invite and password emails. |
| Vercel | Application hosting and scheduled jobs | Requests to the app and the data the app processes while serving them. |
| Anthropic | The language model behind recommendations and the analyst chat | Computed figures with their labels, search-term and keyword text, notes you wrote on actions, your questions and the thread they belong to. Never credentials, raw report files or account exports. |
| Sentry | Error reporting, where configured | Error messages and stack traces with tokens, keys, cookies and codes scrubbed. No IP addresses, no session replay. |
That is the whole list. We will update it here before adding a provider. Our own operators can open your workspace read-only to help with a support question; each such session is logged before access is granted and the log cannot be edited.
6. How long it stays
- Amazon-derived data is deleted by a scheduled purge once it is older than 17 months, inside Amazon’s 18-month limit for solution providers. Every run records what it removed.
- What you entered (costs, goals, notes, decisions, reports, chat threads) stays until you delete it in the app or ask us to remove the workspace.
- Sign-in attempt records are deleted after seven days.
Disconnecting Amazon in Settings deletes the stored token at once and stops every pull. You can also revoke RankHopper in Seller Central (Apps & Services) and in the Ads console. Either way, once the workspace has no Amazon connection left, its Amazon-derived data is deleted 30 days later unless you reconnect; your own notes, settings and reports stay.
Deleting a workspace is on request: email us from an owner’s address and we remove every row the workspace owns, the archived report files, and the sign-in of any member who belongs to no other workspace, within 30 days, and keep a record of what was removed and when.
7. How it is protected
- Data is encrypted in transit and at rest.
- Every workspace table is scoped with row-level security, so one seller's session cannot read another's rows; this is tested against real sign-ins, not assumed.
- The Amazon refresh token is encrypted with AES-256-GCM before it is stored, and the column holding it is not readable by the app's signed-in roles at all; it is decrypted only on the server, at the moment a token is exchanged.
- Changes to Amazon are confined to one write module with a fixed list of endpoints, capped, journaled, and verified by reading Amazon back.
- Ten failed sign-ins lock an address for 30 minutes.
- Error reports have tokens, keys, cookies and authorization codes removed before they leave the server.
8. Your rights
You can ask for a copy of the data we hold about you or your workspace, have it corrected, or have it deleted, by emailing the address below. We answer within 30 days. If you are in a jurisdiction that grants you further rights, those apply too.
10. Children
RankHopper is for businesses selling on Amazon and is not directed at anyone under 18. We do not knowingly collect information from children.
11. Changes to this policy
When this policy changes the effective date at the top moves, and for a material change, a new provider included, we notify account owners by email first.
12. Contact
Privacy questions and data requests
[Founder: legal entity name]
[Founder: mailing address]
RankHopper · Privacy Policy · Effective August 25, 2026