Privacy Policy & Architecture Statement
1. Information We Store Exclusively on Your Local Device
The vast majority of data processed by MerchOS never leaves your physical workstation. The desktop client stores the following information locally inside your user data directory in an encrypted SQLite database file (merch.db):
- Product & Design Catalogs: ASINs, titles, brand names, bullet points, marketplace IDs, product mockups, and local artwork file paths.
- Sales & Financial History: Daily units sold, royalties earned, cancellations, returns, and calculated net margins.
- Amazon Advertising Telemetry: Campaign IDs, daily budgets, bids, search term reports, and negative keyword lists.
- Amazon API Credentials: Your client IDs, client secrets, and refresh tokens are stored locally and encrypted at rest using AES-256-GCM authenticated encryption tied to your local device.
- Niche Research & BSR Curves: Live BSR snapshots, competition radar logs, and bookmarked keywords.
2. Direct Amazon Communications (No Intermediary Relays)
When MerchOS synchronizes your catalog or executes self-driving Amazon Ads rules (such as the Negative Keyword Harvester or Smart Bids Auto-Pilot):
- All API network requests are dispatched directly from your computer’s local IP address to Amazon’s official endpoints (e.g.,
advertising.amazon.comandsellingpartnerapi-na.amazon.com). - MerchOS maintains no cloud proxy servers, relays, or intermediary mirrors. We cannot see, intercept, or log your API traffic.
- The MIO Chrome / Brave Companion extension interacts directly with your authenticated browser session to streamline design uploads without transmitting session credentials to external servers.
3. Information Processed by External Services
To maintain software licensing, process payments, and provide optional AI capabilities, the following minimal data is shared with trusted external service providers:
A. Billing & Subscriptions (Paddle.com)
Our order process is conducted by our Merchant of Record, Paddle.com (Paddle Payments Ltd / Paddle.com Inc). Paddle acts as the data controller for payment processing, fraud detection, and sales tax/VAT compliance. When you subscribe, Paddle collects:
- Your email address, billing name, country, and billing address.
- Payment card details or PayPal credentials (processed under PCI-DSS Level 1 compliance; MerchOS never touches or stores credit card numbers).
- You can review Paddle’s privacy policy at paddle.com/legal/privacy.
B. Software Licensing Verification
To validate that your software installation is authorized, MerchOS communicates with our licensing API (api.merchos.shop). The licensing server receives only:
- Your License Key string (e.g.,
MIO-ENT-XXXX-XXXX). - An irreversible cryptographic SHA-256 hash of your machine hardware identifier to enforce the 1-account-per-device limit.
- Application version and operating system platform (macOS or Windows).
- What is NEVER sent: ASINs, design files, sales units, royalties, Amazon tokens, or catalog metrics.
C. Optional AI Listing Assistant (Groq & Google Gemini)
If you elect to use the AI Listing Assistant in the SEO view or Create Page Companion:
- Only the artwork image concept and selected prompt keywords are transmitted via TLS to the inference provider (Groq or Google Gemini).
- No financial data, sales numbers, or account details are ever included in AI prompts.
- You can configure your own private API keys in MerchOS Settings at any time to route prompts directly under your personal provider account.
4. Zero Telemetry & No Third-Party Tracking
We do not sell, rent, or monetize seller data. Furthermore:
- MerchOS includes zero behavioral analytics trackers (no Google Analytics, no Mixpanel, no Facebook pixels, no Segment).
- Diagnostic sync logs are written locally to your
merch_sync_logsSQLite table for your personal inspection and troubleshooting.
5. Data Retention, Backups & Deletion Rights
Because all business data resides on your machine:
- Full Data Portability: You can export your entire database snapshot to CSV or raw SQLite with one click in the Settings panel.
- Instant Deletion: Deleting the
merch.dbfile from your computer immediately and permanently purges all stored catalog records and credentials.
6. Contact & Inquiries
For privacy-related inquiries, data requests, or architecture verification, contact our team:
Email: [email protected]
Support: merchos.shop/contact
Billing Management: paddle.net