Legal
Privacy policy
How Marketville Ltd, trading as Ecommerceville handles the data that Ecommerceville Stock Monitor collects, why it holds it, where it lives and how to get it removed.
Last updated 6 October 2026.
Who we are
Ecommerceville Stock Monitor is operated by Marketville Ltd, trading as Ecommerceville, a company registered in Scotland under number SC793345, of 34 Brown Street, Glasgow, Scotland, G2 8PD. For the purposes of UK data protection law we are the data controller for the information described below, except where we act as a processor on behalf of a client whose Amazon account we manage.
Questions about this policy, and any request about your data, go to info@ecommerceville.com.
What this policy covers
It covers the Ecommerceville Stock Monitor application: the data it collects from connected Amazon accounts, the data it holds about the people who use it, and the reports it produces. It does not cover Amazon’s own handling of your data, which is governed by Amazon’s terms and privacy notices, or anything you send us outside the application.
Enquiries made through our main website at ecommerceville.com are covered by that site’s own privacy notice instead. The two exist side by side because they describe different things: that one is about a contact form, this one is about an application connected to your Amazon account.
What the application collects
Everything below is collected either from an Amazon account that has authorised us, or from the people at our own company who use the application.
- Amazon selling data. Inventory levels and inbound shipments; product, SKU and ASIN details; listing status and listing problems; units sold and revenue by product and by day; sessions, page views, conversion and Buy Box share; order counts and totals; estimated Amazon fees; Vine and Subscribe & Save figures where they apply.
- Amazon advertising data. Advertiser profile details, campaign names and states, budgets, and daily impressions, clicks, spend, attributed sales, orders and units — for Sponsored Products, Sponsored Brands and Sponsored Display.
- Authorisation credentials. The refresh token Amazon issues when an account authorises us, the selling partner or advertiser identifier it belongs to, its region, and the dates it was granted and expires. These are what let the application request reports; they are not usable to sign in to Seller Central.
- Client contact details. A contact name and email address for each managed account, so reports reach the right person.
- Accounts for our own staff. Name, work email address, role, a hashed password, and sign-in records including failed attempts and the time of last sign-in.
- Access logs. A record of significant actions taken in the application — who did what, to which account, and when, together with the originating IP address.
- Business conversation excerpts. Where a client has discussed a specific product with us over WhatsApp, the application stores a short extract of that message, who said it, when, and the conversation it came from, so that a stock report can show what was last said about the listing it is reporting on. It stores extracts of business conversations with the client, not message histories, and not conversations with anyone else.
What it never collects
No Amazon buyer personal information
The application holds nothing that identifies a seller’s customers: no buyer names, no delivery or billing addresses, no email addresses, no telephone numbers, no payment details, no gift messages. It requests none of Amazon’s restricted data permissions, which are what make those fields visible to an application at all.
One report it downloads — the order report, which it uses to total daily sales — is capable of carrying buyer details for applications that hold those permissions. This one reads five columns from it: the purchase date, the order and item status, the quantity, the item price and the currency. What is written to the database from it is a day, a number of units and an amount. The rest of the file is never parsed and never stored.
It also does not collect special category data, it does not profile individuals, it does not use the data to train machine learning models, and it does not sell data to anyone under any circumstances.
Why we process it, and on what basis
- To produce the reports a client has engaged us for — stock, listings, sales and advertising. Our basis is performance of our contract with that client.
- To run and secure the application — sign-ins, access logs, diagnosing faults. Our basis is our legitimate interest in operating a secure service, balanced against the limited and work-related nature of what is logged.
- To meet legal and tax obligations where retained records are required. Our basis is legal obligation.
We do not rely on consent for any of the above, and there is no marketing use of this data, so there is nothing here to opt out of beyond withdrawing the Amazon authorisation itself.
Where it is stored
Collected data is held in a PostgreSQL database hosted by Supabase in the European Union (Paris). The application itself is served by Vercel. Data is encrypted in transit using TLS, and encrypted at rest by the hosting provider.
Who else handles it
We use a small number of suppliers who store or process data on our behalf. They act on our instructions, under contract, and may not use the data for their own purposes.
- Supabase
- Hosts the PostgreSQL database in which all collected data is stored. — European Union (Paris)
- Vercel
- Hosts and serves the application itself. Does not store collected data. — European Union and United States edge network
- Amazon Web Services
- Underlies both of the above. — European Union
Beyond these, we share data only with the client the data belongs to, and where we are legally required to disclose it. Where any transfer outside the UK or EEA occurs, it is covered by the UK International Data Transfer Addendum or Standard Contractual Clauses.
How long we keep it
- Amazon selling data
- 36 months from collection
- Amazon advertising data
- 36 months from collection
- Conversation excerpts
- 6 months, and removed sooner once the message falls outside the reporting window
- Access logs
- 12 months
- Authorisation tokens
- Deleted as soon as authorisation is withdrawn
- After an engagement ends
- All of that client’s data is deleted within 90 days, sooner on request
How it is protected
- Encryption. TLS in transit; encryption at rest in the database.
- Access control. Named accounts for each member of staff, with roles, hashed passwords and automatic lockout after repeated failed sign-ins. No shared logins.
- Database isolation. Row-level security is enabled on the tables holding collected data, and the anonymous and public database roles have no access to them.
- Credential handling. Amazon refresh tokens and API keys are held as server-side secrets. They are never exposed to a browser, never written into reports and never logged.
- Audit trail. Significant actions are recorded with the person, the account and the time.
- Read-only access. Every call the application makes to Amazon reads. It does not create, edit or delete listings, change prices, alter inventory, place orders or make changes to campaigns, and it asks for none of the restricted permissions that would expose buyer personal information.
- Two-step sign-in. Every account that can reach this data is protected by a password and a time-based code from an authenticator app, not a password alone.
- Incidents. We hold a written incident response plan with a named contact, reviewed every six months. Any incident touching Amazon data or credentials is reported to Amazon within 24 hours of detection; any personal data breach that puts people at risk is reported to the Information Commissioner’s Office within 72 hours. Affected clients are told directly, in both cases, rather than waiting for the investigation to finish.
- Dependencies. The software the application is built on is reviewed for known vulnerabilities, and anything affecting the data described here is patched promptly.
Your rights
Under UK data protection law you may ask us to:
- confirm what personal data we hold about you, and give you a copy;
- correct anything inaccurate;
- delete it, where we have no continuing need or legal duty to keep it;
- restrict or object to how we are using it;
- provide it in a portable, machine-readable form.
Write to info@ecommerceville.com. We answer within one month. There is no charge, and we will not ask for a reason.
Withdrawing Amazon authorisation
A seller can withdraw our access at any time, without telling us first, from Seller Central under Apps and Services → Manage Your Apps. Collection stops immediately and the stored authorisation is deleted.
Withdrawing access stops anything new being collected; it does not by itself erase what was collected before. To have that removed as well, email info@ecommerceville.com and we will delete it and confirm in writing. See also the support page.
Children
The application is a business tool. It is not directed at children, and we do not knowingly collect data about anyone under 18.
Changes to this policy
We will update this page when what we do changes, and the date at the top will change with it. Where a change materially affects how we handle a client’s data, we will tell that client directly rather than relying on them noticing.
Contacting us, and complaining
- Data protection enquiries
- info@ecommerceville.com
- General support
- info@ecommerceville.com
- Registered office
- 34 Brown Street, Glasgow, Scotland, G2 8PD
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first so we can put it right, but you are not obliged to.