← Back to SellerStream
Privacy Policy
Effective date: May 26, 2026 · Last updated: September 24, 2026
1. Introduction and scope
This Privacy Policy ("Policy") describes how J Weiner Services Inc, a company organized under the laws of the United States, which operates the SellerStream platform, applications, website, and related products and services (collectively, the "Service"), collects, uses, discloses, retains, and protects information in connection with the Service. In this Policy, "SellerStream", "we", "us", and "our" refer to J Weiner Services Inc; "you" and "your" refer to the account holder and any user authorized to access the Service on the account holder's behalf.
SellerStream is a business-to-business analytics and bulk-operations platform for professional Amazon third-party sellers and operates as a Solution Provider under the Amazon Selling Partner API ("SP-API"). The Service is intended solely for business use; it is not directed to children and is not intended for personal, family, or household purposes.
This Policy is published at https://ppcpilot.net/privacy and is accessible without authentication. By creating an account, accessing the Service, or authorizing SellerStream to access an Amazon selling account, you acknowledge that you have read and understood this Policy.
2. Definitions
- "Amazon Information" means any information SellerStream receives from the Amazon SP-API (and, where authorized, the Amazon Advertising API) or from a seller's authorization grant, including advertising, sales-and-traffic, and inventory report data retrieved on the Authorizing Seller's behalf, and the account-level identifiers required to scope each API request. Amazon Information is a distinct, restricted category of data, separate from User Content.
- "Authorizing Seller" (or "Seller") means the Amazon selling-account holder who authorizes the Service to access Amazon Information via the SP-API.
- "Personal Data" means information that identifies, relates to, or can reasonably be linked to an identified or identifiable natural person, and includes "personal information" as defined under applicable United States state privacy laws.
- "User Content" means files and data you upload to the Service, such as advertising bulk-operation exports, profit-and-loss spreadsheets, and mapping files.
- "Usage Data" means technical and operational data generated by your use of the Service, such as log records.
- "Sub-processor" means a third party engaged by SellerStream to process data on our behalf in order to operate the Service.
- "Data Subject" means the individual to whom Personal Data relates.
3. Information we collect
We collect only the information reasonably necessary to provide the Service:
- Account Data. A username, a password hash (we do not store passwords in plaintext), two-factor authentication secrets and recovery-code hashes where enrolled, and an email address. The email address is used to verify the account at registration, to enable self-service password reset, and to send essential transactional and security notices; we verify it by confirmation link before an account is activated. If you elect to enable SMS as a backup two-factor method, we also collect the mobile telephone number you provide, solely to deliver sign-in verification codes.
- Payment Data. If you purchase prepaid AI balance or a subscription, our payment processor collects and processes your payment details. We receive only a customer identifier and transaction metadata (such as the plan or balance top-up purchased); we do not receive or store your payment-card number.
- User Content. Files you upload to the Service for processing, stored on a per-account basis and not accessible to other users of the Service.
- Amazon Information. Where you authorize the SP-API connection, we retrieve Amazon Information as described in Section 5. You may alternatively provide equivalent data by uploading Amazon reports as User Content.
- Usage Data. Standard web-server logs (timestamp, IP address, user agent, requested URL, and response status) collected for security monitoring and abuse prevention. These logs are not used for marketing.
4. How we use information
We use the information described above to: (a) provide, operate, maintain, and secure the Service; (b) authenticate users and protect accounts; (c) process payments and manage prepaid AI and subscription balances; (d) send transactional and security communications; (e) provide customer support; (f) analyze and improve the reliability and performance of the Service; and (g) comply with legal obligations and enforce our agreements.
We do not use Personal Data for behavioral advertising, and we do not sell or rent Personal Data. Additional use limitations that apply specifically to Amazon Information are set out in Section 5.
5. Amazon Information
Amazon Information is used solely to provide the Service to the Authorizing Seller and for no other purpose. We do not sell it, use it for advertising, combine it across sellers, or use it to train machine-learning models.
When you authorize SellerStream to access your Amazon selling account, you permit us to retrieve and process the following categories of Amazon Information on your behalf, limited to the accounts, marketplaces, and scopes you authorize. Once an account is connected, some of this retrieval runs on a recurring schedule rather than only while you are signed in:
- Sales and traffic reports, at daily whole-account granularity and at weekly per-SKU and per-child-ASIN granularity, including ordered and shipped sales and units, sessions and page views, Featured Offer (Buy Box) percentage, unit-session percentage, and the refunded-unit and A-to-z claim figures those reports contain;
- Order records, retrieved as a recent sample so you can confirm the connection is working. We retain only the Amazon order identifier, dates, status, fulfilment channel, marketplace, item counts, and order total. We do not retain buyer names, shipping addresses, or contact details;
- Listing and catalogue data: the attributes, marketplace status, and open listing issues of your listings, and the parent-child variation structure of your catalogue;
- FBA inventory planning data, including available, inbound, reserved, and in-transfer units and recent shipped-unit history;
- Brand Analytics Search Query Performance data for ASINs you specify, where your account is enrolled in Brand Registry and has granted the corresponding role;
- Account-level identifiers and marketplace participation required to scope each API request to the correct seller; and
- Where you separately authorize the Amazon Advertising API, advertising reports for Sponsored Products, Sponsored Brands, and Sponsored Display. SellerStream does not hold Advertising API access as at the date of this Policy, and no advertising data is retrieved unless and until you grant that separate authorization.
Changes we submit on your behalf. Some features do more than read. When you review and approve a proposed change in the Title Optimizer, SellerStream submits that change to Amazon on your behalf, which updates the product title and Item Highlights on the affected listing. No change is submitted without your explicit approval of that specific change; we record the previous values immediately before submitting, so that every change is traceable and can be reverted; and no other feature writes to your Amazon account.
We process Amazon Information only to provide the features you use, and we do not: (a) sell, rent, or otherwise disclose Amazon Information for value; (b) use Amazon Information to serve, target, or inform advertising to you or any third party; (c) aggregate or combine one Seller's Amazon Information with another Seller's data for benchmarking or any other cross-tenant purpose; or (d) use Amazon Information to train or fine-tune large language models or other machine-learning models without your explicit consent. In practice no Amazon Information is used to train or fine-tune any model at all, by us or by any of our AI sub-processors.
Where an optional AI-assisted feature is used, the information sent to the relevant AI sub-processor is described in Section 7. AI features operate only when you invoke them.
We handle Amazon Information in accordance with the Amazon Data Protection Policy. If you revoke the Service's authorization (through Amazon Seller Central's authorization manager or by contacting us), we will cease retrieving new Amazon Information immediately and will delete cached Amazon Information within 30 days of the revocation, as further described in Section 9.
6. How we share and disclose information
We do not sell, rent, or trade Personal Data or Amazon Information. We disclose information only as follows:
- Sub-processors. We share information with the Sub-processors listed in Section 7, each engaged to perform a specific function on our behalf and contractually restricted to processing the information only as necessary to provide that function.
- Legal process and protection. We may disclose information where we have a good-faith belief that doing so is reasonably necessary to (i) comply with applicable law, regulation, legal process, or a valid governmental request; (ii) enforce our agreements or investigate potential violations; or (iii) protect the rights, property, safety, or security of SellerStream, our users, or the public.
- Business transfers. If SellerStream is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy.
- With your direction. We share information with third parties where you direct or consent to the disclosure.
7. Sub-processors
We engage the following Sub-processors to operate the Service. Amazon Information is shared with a Sub-processor only to the extent necessary to provide the Service:
- Stripe: payment processing for balance top-up and subscription purchases. See Stripe's privacy policy.
- Anthropic: the optional AI Copilot, the Daily Sales Report's AI insights, and other opt-in AI-assisted features. Transmitted to Anthropic's Claude API are the prompt text, the User Content you choose to include, and, for features that analyse your Amazon results, aggregated figures such as period totals rather than the underlying report data. Content sent through the API is not used to train Anthropic's models. See Anthropic's privacy policy.
- Google: the Gemini API, used for optional AI-assisted features including video and listing-content review, and only when you invoke them. See Google's privacy policy.
- OpenAI: an alternative model provider for certain optional AI-assisted features, used only when you invoke them. See OpenAI's privacy policy.
- Resend: delivery of transactional email (account verification and password-reset messages). See Resend's privacy policy.
- Twilio: delivery of SMS sign-in verification codes, only if you enable SMS two-factor authentication. See Twilio's privacy policy.
- Cloudflare R2: encrypted, off-platform storage of database backups and of a copy of settlement reports retrieved from Amazon.
- Railway: managed-container hosting and the persistent database volume on which the Service runs. See Railway's security documentation.
8. Data security
We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, alteration, and disclosure, including:
- Encryption in transit. All traffic to
ppcpilot.net is encrypted using TLS 1.2 or higher, with HTTP Strict Transport Security enabled to prevent protocol downgrade.
- Encryption at rest. Amazon SP-API refresh tokens are encrypted at the application layer using authenticated symmetric encryption (AES-128) with the encryption key held separately from the database.
- Authentication. Passwords are stored as salted PBKDF2 hashes. Two-factor authentication using a time-based one-time password (TOTP) is mandatory, with optional SMS or email as an additional user-selected factor. Password rotation is enforced.
- Access controls. Access to stored data is enforced on a least-privilege basis and isolated per user; one user cannot read, list, or delete another user's data. Administrative access is limited to authorized personnel and is recorded in an audit log.
- Monitoring and abuse prevention. Credential-sensitive routes are rate-limited, and security-relevant events are logged and reviewed. Credentials, secrets, and personal data are not written to application code or operational logs; sensitive fields are redacted.
- Vulnerability management. We monitor for security vulnerabilities, keep dependencies current, and apply security updates on a risk-prioritized basis.
- Incident response. We maintain a documented incident-response process. Where a security incident involves Amazon Information, we will notify Amazon at
security@amazon.com within 24 hours of detection.
Support access. Authorized personnel may access your account where reasonably necessary to provide support, reproduce a reported issue, or verify correct operation of the Service. Such access is (a) limited to personnel authenticated with their own multi-factor-protected credentials; (b) limited to what is necessary for the stated purpose; (c) recorded in an audit log; and (d) never used to sell your data, disclose it to other customers, or benchmark you against other sellers. If you prefer that we request your consent before each support access, you may notify us and we will record that preference on your account.
No method of transmission or storage is completely secure; however, the foregoing controls are maintained on an ongoing basis, and we review them periodically.
9. Data retention and deletion
We retain information only for as long as necessary for the purposes described in this Policy or as required by law:
- Amazon Information. Deleted within 30 days of the earliest of: (a) your revocation of the Service's SP-API authorization; (b) closure or deletion of your SellerStream account; or (c) a deletion request from Amazon. Where Amazon directs deletion by notice (for example, on termination), live instances and data are deleted within 90 days.
- Non-personal Amazon data. Retained for no longer than 18 months, and deleted earlier upon any of the triggers above.
- Account Data and two-factor secrets. Retained for the life of the account and deleted within 30 days of account deletion.
- User Content. Retained while it remains visible in the in-app Saved Runs and Sessions lists, until you delete it or it is removed on your request; bulk deletion of older items is available on request.
- Payment records. Retained as required by applicable tax and accounting law (typically seven years), then deleted.
- Usage Data. Retained for 30 days, then rotated out.
- System backups. System backups are point-in-time copies of our database and stored data, kept so that the Service can be restored after a failure. They are held by our hosting provider, Railway, and on Cloudflare R2. Copies held on Cloudflare R2 are encrypted at rest. When information is deleted in accordance with this Section, a system backup made before, or shortly after, the deletion may still contain that information until the backup expires and is deleted. At present, daily database backups on Cloudflare R2 are retained for approximately 30 days and Railway's scheduled volume backups for up to approximately one month. Settlement reports retrieved from Amazon are also copied to Cloudflare R2 on an ongoing basis rather than as point-in-time backups; that copy is deleted together with the original.
You may request deletion of all of your data, including Amazon Information, User Content, and Account Data, using the contact details in Section 16.
10. Cookies and session storage
The Service uses a first-party session cookie for authentication, marked HttpOnly, Secure (in production), and SameSite=Lax. If you choose to trust a device at sign-in, a first-party trusted-device cookie is stored for up to 30 days so that device can skip the second-factor challenge. We do not use third-party advertising cookies or third-party analytics trackers on the Service, and the marketing pages presented before sign-in do not load third-party trackers.
11. International data transfers
SellerStream is operated from the United States, and our Sub-processors may process data in the United States and other jurisdictions. Where you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws different from those of your jurisdiction. Where required, such transfers are made on the basis of appropriate safeguards or the necessity of the transfer for the performance of our agreement with you.
12. Your rights and how to exercise them
Depending on your jurisdiction, you may have rights over your Personal Data, including the rights to access, correct, delete, and receive a portable copy of your Personal Data; to object to or restrict certain processing; to withdraw consent; and, under United States state privacy laws, to opt out of the sale or sharing of Personal Data (which we do not engage in) and to be free from discrimination for exercising your rights.
To exercise any of these rights, contact us using the details in Section 16. We will respond within the timeframes required by applicable law: within 30 days for requests under the EU/UK General Data Protection Regulation and within 45 days for requests under the California Consumer Privacy Act. We may need to verify your identity before fulfilling certain requests. If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority.
13. Children's privacy
The Service is offered solely to businesses and professional sellers, and account holders must be of legal age to enter into a binding contract. The Service is not directed to children, and we do not knowingly collect Personal Data from anyone under the age of 16. If we become aware that we have inadvertently done so, we will delete it without undue delay. If you believe a minor may have provided us Personal Data, please contact us using the details in Section 16.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date above, and we will provide notice through a reasonable channel (such as an in-app notice or email) to active users at least 14 days before material changes take effect. Your continued use of the Service after the effective date of an update constitutes acceptance of the updated Policy.
15. Governing law
This Policy is governed by and construed in accordance with the laws of the United States and the state in which J Weiner Services Inc is incorporated, without regard to conflict-of-law principles. Where applicable, the rights afforded to Data Subjects in the European Economic Area and the United Kingdom apply to Personal Data received from those jurisdictions.
For privacy questions, data-access requests, and deletion requests:
Security incidents involving Amazon Information are handled in accordance with the incident-response process referenced in Section 8.
This Policy reflects our good-faith implementation of the Amazon Data Protection Policy and Acceptable Use Policy and applicable data-protection laws. It does not constitute legal advice.