Privacy & data protection

Privacy Policy

This policy explains how Keluoshi Marketplace Analytics handles information when providing read-only advertising and commerce analytics powered by authorized Amazon Ads API and Selling Partner API connections.

Effective: August 15, 2026 Last updated: August 15, 2026 Version 1.0

Hefei Keluoshi Cross-border E-commerce Co., Ltd. ("Keluoshi," "we," "us," or "our") operates Keluoshi Marketplace Analytics (the "Service"). We respect the confidentiality of seller and advertising information and process it only for the purposes described below.

Read-only analytics The Service analyzes authorized reports and does not change bids, budgets, campaigns, listings, or orders.
No buyer PII requested The current Service does not request buyer names, addresses, phone numbers, emails, or payment details.
No sale of data We do not sell Amazon Information or personal information and do not use it for behavioral advertising.
No site tracking This privacy-policy page sets no cookies and contains no analytics, advertising pixels, or contact forms.

Scope

This Privacy Policy applies to the Service and this public policy website. It covers information processed through connections that an authorized Amazon selling partner or advertiser enables for the Service. It does not govern Amazon's own services, GitHub's hosting services, or an AI assistant or other third-party client that you independently choose to connect.

The Service is designed for business users and currently supports analytics for the United States, Canada, United Kingdom, and Australia marketplaces.

Data we handle

Authorization and account information

We process authorization credentials and tokens required to access the Amazon APIs, together with identifiers such as advertising profile IDs, marketplace IDs, account labels, country, currency, and time zone. Passwords for your Amazon account are not provided to or stored by the Service.

Advertising analytics data

We may process campaign, ad group, keyword, target, search-term, placement, SKU, and ASIN identifiers and labels, together with aggregated performance metrics such as impressions, clicks, spend, attributed orders, units, and sales.

Seller sales and traffic data

We may process aggregated daily and ASIN-level business metrics, including ordered-product sales, units ordered, sessions, page views, Buy Box percentage, and unit-session percentage.

Service and security records

We may record synchronization times, completion status, record counts, errors, authentication events, and other limited technical information needed to operate and secure the Service. We design logs to avoid Amazon customer personally identifiable information and do not intentionally place access tokens or temporary report download links in application logs.

The current Service does not request restricted SP-API operations and is not designed to collect Amazon customer PII such as buyer names, shipping addresses, email addresses, phone numbers, gift messages, or payment information.

Data sources

We receive information from:

  • Amazon Ads API and Amazon Selling Partner API after an authorized account grants access;
  • the person or organization configuring and operating the Service; and
  • the hosting, database, authentication, and security systems used to run the Service.

We do not use scraping to obtain the Amazon Information covered by this policy.

How we use data

We process information to:

  • authenticate authorized API connections and retrieve requested reports;
  • normalize, store, and analyze advertising, sales, and traffic metrics;
  • calculate performance measures such as ACOS, ROAS, TACOS, CTR, CPC, and conversion rate;
  • produce daily briefs and read-only search-term, placement, product, and account analyses;
  • respond to support, privacy, and security requests;
  • detect abuse, troubleshoot failures, maintain availability, and protect the Service; and
  • comply with applicable law and Amazon developer agreements and policies.

We do not use Amazon Information for targeted advertising, data brokerage, or unrelated marketing. We do not use it to train a general-purpose artificial intelligence model.

How data is shared

We disclose information only as reasonably necessary to:

  • Amazon: to authenticate the connection, request reports, and comply with Amazon API requirements;
  • infrastructure providers: to host, store, secure, monitor, or support the Service under appropriate confidentiality and data-protection terms;
  • user-selected clients: when you direct the Service to return requested analytics to a connected AI assistant, MCP client, or other tool; and
  • legal and safety recipients: when required by law or reasonably necessary to protect rights, safety, users, or the Service.

A third-party client you choose may process the information it receives under its own terms and privacy policy. Review that provider's settings and policy before enabling the connection.

We do not sell personal information or Amazon Information. We do not share personal information for cross-context behavioral advertising.

International data transfers

The Service may process information in countries other than the country in which it was collected, including where Keluoshi or its approved service providers operate. Where required, we use recognized safeguards for international transfers, such as contractual protections, and apply appropriate technical and organizational security measures.

Security

We use administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, disclosure, or destruction. Measures include access controls based on least privilege, encrypted transport using HTTPS/TLS, encryption at rest where information is stored, secret-management controls, separation of production credentials from source code, monitoring, backups, vulnerability management, and credential rotation.

No method of transmission or storage is completely secure. If we identify a security incident, we will investigate, contain, and provide notices as required by applicable law and relevant Amazon policies.

Retention and deletion

We retain information only for as long as needed for the purposes described in this policy, subject to Amazon's Data Protection Policy and applicable legal, tax, accounting, security, and dispute-resolution obligations.

  • Amazon API credentials are retained only while the applicable connection remains authorized or as needed to complete revocation and security procedures.
  • Non-PII Amazon analytics data is retained for no longer than 18 months unless a longer period is required by applicable law, and may be deleted earlier when it is no longer needed.
  • The current Service does not intentionally collect Amazon customer PII. If such data is received unexpectedly, we will restrict access and delete it promptly in accordance with Amazon requirements and applicable law.
  • Security and operational logs are retained for the period reasonably needed to detect, investigate, and document security events and to meet applicable requirements.

After deletion from active systems, residual copies may remain temporarily in encrypted backups until they are overwritten under the normal backup lifecycle. We may preserve limited information when required by law or necessary to establish, exercise, or defend legal claims.

To request deletion, email hello@kawamii.com. We may need to verify that the requester is authorized to act for the relevant account. We aim to complete verified requests within 30 days, unless a different period is required or permitted by law.

Your choices and privacy rights

You can stop future collection by disconnecting the Service, revoking its authorization through the relevant Amazon account controls, or asking us to disable the connection. Depending on your location and applicable law, you may also have rights to request access, correction, deletion, restriction, portability, or objection, or to withdraw consent without affecting earlier lawful processing.

Submit a request using the contact details below. Authorized agents may make a request where permitted by law. You may also have the right to complain to your local data-protection authority. We will not discriminate against you for exercising an applicable privacy right.

This public website

This page does not set cookies, run analytics, display advertising, use tracking pixels, or submit forms. It is hosted using GitHub Pages. GitHub may automatically process limited technical information, such as IP address and request metadata, to deliver and secure the page. That processing is governed by the GitHub General Privacy Statement.

Children's privacy

The Service is intended for businesses and adults and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so that we can take appropriate action.

Changes to this policy

We may update this policy to reflect changes in the Service, law, or applicable platform requirements. We will post the revised policy on this page and update the "Last updated" date. If a change materially affects how we handle information, we will provide additional notice when required.

Contact us

For privacy questions, requests, or complaints, contact the organization responsible for the Service:

Hefei Keluoshi Cross-border E-commerce Co., Ltd.

Operator of Keluoshi Marketplace Analytics

Email: hello@kawamii.com