Skip to content

Data security

This page explains how sellerfox protects credentials, where its product infrastructure is hosted, when data is sent to external services, and what happens when a workspace is deleted.

Technical description

This page describes how the product behaves. Legal bases, privacy rights, and statutory retention periods are defined in the privacy policy.

Encryption and credentials

DataProtection
sellerfox passwordStored as a hash rather than in plaintext
Amazon connection tokensEncrypted before storage and decrypted only for access through the relevant connection
Saved webhook credentialsEncrypted before storage
Amazon password and 2FA codeYou enter both only on Amazon's consent pages; sellerfox does not receive these credentials

The table covers credentials only. What the Amazon connection is allowed to read is listed under Connect Amazon accounts → What you grant sellerfox.

Storage location and access

sellerfox hosts its product infrastructure in Germany. Every provider operating this infrastructure is ISO/IEC 27001 certified or has a SOC 2 Type II report.

The next section explains what data sellerfox sends to external services for specific features.

For signed-in members, the workspace role determines which data and features they can access. Membership applies only to that workspace. See the permissions matrix for details by feature.

MCP access is available only when the workspace has MCP enabled, you have authorized a valid connection, the workspace is approved for that connection, and you are an active Owner or Admin there. Revoking the connection or losing the required role also ends access through MCP. See MCP server → Requirements for each data request for the five security checks.

Where data leaves sellerfox

ActivityData sentTrigger
Email and PDF report deliveryRecipient address, notification content, and report attachmentWorkspace configuration or a product notification
PaymentsBilling contact, company and address details, VAT ID, and workspace referenceThe Workspace Owner starts or manages a subscription
Error and performance monitoringError details, technical request and performance data, and limited browser contextProduct operation
External market-data retrievalTracked keywords and product and marketplace identifiers for Product BoostOwner or Admin product configuration
WebhooksSelected workspace KPI data and the configured authenticationAn Owner or Admin creates a webhook
MCPData returned for an approved workspaceA user authorizes a client and calls a tool

sellerfox minimizes monitoring data before it is sent. Payment form input is not collected by monitoring; passwords and tokens are removed from monitoring data.

Retention and deletion

sellerfox stores MCP call logs for up to 180 days. MCP server → Call logs describes their contents and availability.

Workspace product data remains available while the workspace is active. After a trial ends without a subscription or the final paid period of a canceled subscription ends, sellerfox removes the product data about 17 days later. Billing → When access ends describes the warning, access, and reactivation process.

After a manual workspace deletion, sellerfox removes the product data about 48 hours later. Removed product data cannot be restored in the dashboard.

sellerfox deletes all of the workspace's product data. This includes the following groups, among others:

  • Analytics data: metrics, products, keywords and rankings, orders and fees, SQPR records, and generated PDF reports.
  • Workspace configuration: alerts, events, filters, KPI sets, product lists, settings, and memberships.
  • Integrations and files: webhook configuration and delivery history, report files, workspace logos, imported COGS files, and the workspace's inclusion in user-authorized MCP connections.
  • Profit data: COGS, income and expenses, and FBM cost settings.

Individual audit records, such as a log of the workspace deletion, remain. These records cannot be used to restore the workspace or the product data.

sellerfox also keeps invoices and contract records. See the privacy policy for the legal basis and retention periods. Deleting your personal account is a separate support request and is not triggered by deleting a workspace.

Who operates sellerfox

sellerfox is operated by MATO Solutions GmbH in Vienna, Austria. Company details are in the imprint.