- We collect the minimum needed to reprice your listings: your account details, a token that lets us act on your marketplace account, and your product, price and cost data.
- Your costs, margins and prices are never pooled with another seller's. Each seller's pricing decisions are made from their own data and from offer prices the marketplace already shows the public.
- We never sell your data, never share it for advertising, and never let our AI provider train on it.
- Disconnect a marketplace and we delete its access token immediately; close your account and your data goes within [30] days.
01 Who we are
Marginfly is an autonomous repricing service for independent e-commerce sellers, operated by [legal entity name], a [Florida] limited liability company registered at [registered address]. In this policy "Marginfly", "we" and "us" mean that company, and "you" means the seller whose account is connected to the service.
For anything in this policy, write to info@marginfly.io. If you are in the UK or EU, we are the data controller for your account data and, for the marketplace data we process on your instruction, your processor.
02 What we collect
Account information
Your name, work email address, company or store name, and a password you choose. We store the password only as a
scrypt hash — we cannot read it, and we will never ask you for it.
Marketplace connection
When you connect a marketplace we receive an authorization token from that marketplace — for Amazon, a Selling Partner API refresh token and your selling partner ID. The token is encrypted before it is stored and is used only to read your listings and competitive offer data and to update your prices. We never receive or store your Amazon, Walmart or Shopify password.
Listing and pricing data
SKUs, ASINs, product titles, your current prices, inventory quantities, the unit costs and margin floors you enter, sales velocity, and the competing offers the marketplace publishes for your listings. Every price decision we make is stored with the data it was based on, so you can audit it.
Billing
Subscriptions are processed by Stripe. Stripe holds your card details; we receive only your customer and subscription identifiers, plan, and payment status. Card numbers never touch our servers.
Technical logs
IP address, browser type, pages requested, timestamps, and error diagnostics — kept to run the service, spot abuse, and fix faults.
03 How we use it
- To reprice your listings — read competitive data, decide a price inside the floor and ceiling you set, and write that price back to the marketplace.
- To show you what happened — the dashboard, the decision log, and the reason recorded against every price change.
- To bill you and manage your subscription.
- To support you when you ask us a question, and to send service notices such as a failed price update or a connection that needs reauthorizing.
- To keep the service safe and working — monitoring, debugging, fraud and abuse prevention.
- To improve Marginfly, using aggregated statistics that do not identify you or your products.
We do not use your data for automated decisions about you — only about the prices you asked us to manage.
04 What we never do
One seller's non-public data never influences another seller's price. Your costs, margin floors and prices are walled inside your own account and are never pooled, aggregated into a shared signal, or shown to anyone else — including in anonymized form.
The only competitive data our agent uses is the offer information a marketplace already publishes to every shopper and seller. This is a deliberate design decision as much as a privacy commitment, and the software enforces it: each account's data is separated at the database level, and the pricing engine receives one listing's context at a time.
We also never sell or rent your data, never share it with advertisers or data brokers, and never allow a model provider to train on it.
05 AI pricing decisions
Marginfly uses a large language model from Anthropic to weigh pricing context that fixed rules handle badly. For each decision we send one listing's numbers: product title, your current price, your margin floor and ceiling, stock on hand, recent sales pace, and the published competing offers.
No names, email addresses, customer details or payment data are ever included. Anthropic processes this under its commercial terms as our service provider and does not train models on it. A deterministic guardrail — not the model — has the final say on every price, and no price can fall below the floor you set.
06 Who else processes your data
These are our subprocessors. We will update this list before adding a new one.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon | Selling Partner API — read offers, update prices | Listing, price and offer data; access token | United States |
| Anthropic | Pricing decisions | Listing-level pricing context, no personal data | United States |
| Stripe | Payments and subscriptions | Billing contact, card data held by Stripe | United States |
| Render | Application and database hosting | All service data at rest | [US region] |
| Sentry | Error monitoring | Diagnostics, IP address | United States |
| Resend | Service email | Name, email address | United States |
| Google Workspace | Business email and support | Anything you send us | United States |
We also disclose data where the law requires it, and if Marginfly is ever acquired, your data may transfer to the buyer under this same policy — we will tell you before that happens.
07 Amazon data
Data we receive through Amazon's Selling Partner API is handled under Amazon's Acceptable Use Policy and Data Protection Policy. In practice: tokens are encrypted at rest, access is limited to the systems that need it, data is transmitted only over TLS, and we retain Amazon information no longer than we need it to provide repricing to you.
Disconnecting your Amazon account in Settings deletes the stored token immediately and stops all repricing for those listings. Marginfly requests only the Pricing and Product Listing roles; we do not request, receive or store customer names, addresses or order personal information.
08 Legal bases for processing
If UK or EU law applies to you, we rely on:
- Contract — running the service you signed up for, including repricing and billing.
- Legitimate interests — keeping the service secure, preventing abuse, and improving the product, balanced against your rights.
- Legal obligation — tax, accounting and lawful requests.
- Consent — where we ask for it, such as optional product emails. You can withdraw it at any time.
[Counsel to confirm this section and whether a UK/EU representative is required.]
09 Cookies
The application sets one cookie: a signed session cookie that keeps you logged in. It is
HttpOnly, SameSite=Lax, and served only over HTTPS. Clearing it signs you out.
We use no advertising cookies, no third-party trackers, and no cross-site profiling. [If analytics are added to the marketing site, disclose them here.]
10 How long we keep things
| Data | Kept for |
|---|---|
| Account and billing records | While your account is open, then [7] years for tax and accounting |
| Marketplace access tokens | Deleted the moment you disconnect or close the account |
| Listing and price decision log | [90] days rolling, then aggregated |
| Technical and error logs | [30] days |
| Support conversations | [24] months |
When you close your account we delete your data within [30] days, except records we must keep by law.
11 Security
- All traffic encrypted in transit; data encrypted at rest by our hosting provider.
- Marketplace tokens encrypted with a key held outside the database.
- Passwords stored as salted
scrypthashes. - Every record scoped to one account, enforced in the application layer and tested automatically.
- Least-privilege access for staff, with production access limited to [named roles].
- A global stop control that halts all repricing immediately if something looks wrong.
No service can promise perfect security. If a breach affects your data we will notify you and the relevant regulator within the time the law requires.
12 Your rights
- Access
- Get a copy of the data we hold about you.
- Correction
- Fix anything inaccurate, in the app or by asking us.
- Deletion
- Close your account and have your data erased.
- Export
- Take your product, price and decision history with you.
- Objection
- Object to processing based on legitimate interests.
- Complaint
- Raise it with your data protection authority.
California residents have the rights to know, delete, correct and opt out of sale or sharing under the CCPA. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of — but the request line is the same as everything else here.
Email info@marginfly.io and we will respond within [30] days. We never charge for a request and never treat you differently for making one.
13 International transfers and children
Marginfly is operated from the United States and our providers process data there. If you use the service from outside the US, your data is transferred to the US under [standard contractual clauses / transfer mechanism].
The service is for businesses. It is not directed at anyone under 18, and we do not knowingly collect data from children.
14 Changes to this policy
When we change something material — a new subprocessor, a new category of data, a new purpose — we will update the date at the top of this page and email account holders at least [14] days before it takes effect. Past versions stay available on request.
15 Contact
// privacy enquiries
[legal entity name]
[registered address]
We answer privacy mail ourselves — it does not go to a ticket queue.