Data security
This page explains how sellerfox protects credentials, where its product infrastructure is hosted, when data is sent to external services, and what happens when a workspace is deleted.
Technical description
This page describes how the product behaves. Legal bases, privacy rights, and statutory retention periods are defined in the privacy policy.
Encryption and credentials
| Data | Protection |
|---|---|
| sellerfox password | Stored as a hash rather than in plaintext |
| Amazon connection tokens | Encrypted before storage and decrypted only for access through the relevant connection |
| Saved webhook credentials | Encrypted before storage |
| Amazon password and 2FA code | You enter both only on Amazon's consent pages; sellerfox does not receive these credentials |
The table covers credentials only. What the Amazon connection is allowed to read is listed under Connect Amazon accounts → What you grant sellerfox.
Storage location and access
sellerfox hosts its product infrastructure in Germany. Every provider operating this infrastructure is ISO/IEC 27001 certified or has a SOC 2 Type II report.
The next section explains what data sellerfox sends to external services for specific features.
For signed-in members, the workspace role determines which data and features they can access. Membership applies only to that workspace. See the permissions matrix for details by feature.
MCP access is available only when the workspace has MCP enabled, you have authorized a valid connection, the workspace is approved for that connection, and you are an active Owner or Admin there. Revoking the connection or losing the required role also ends access through MCP. See MCP server → Requirements for each data request for the five security checks.
Where data leaves sellerfox
| Activity | Data sent | Trigger |
|---|---|---|
| Email and PDF report delivery | Recipient address, notification content, and report attachment | Workspace configuration or a product notification |
| Payments | Billing contact, company and address details, VAT ID, and workspace reference | The Workspace Owner starts or manages a subscription |
| Error and performance monitoring | Error details, technical request and performance data, and limited browser context | Product operation |
| External market-data retrieval | Tracked keywords and product and marketplace identifiers for Product Boost | Owner or Admin product configuration |
| Webhooks | Selected workspace KPI data and the configured authentication | An Owner or Admin creates a webhook |
| MCP | Data returned for an approved workspace | A user authorizes a client and calls a tool |
sellerfox minimizes monitoring data before it is sent. Payment form input is not collected by monitoring; passwords and tokens are removed from monitoring data.
Retention and deletion
sellerfox stores MCP call logs for up to 180 days. MCP server → Call logs describes their contents and availability.
Workspace product data remains available while the workspace is active. After a trial ends without a subscription or the final paid period of a canceled subscription ends, sellerfox removes the product data about 17 days later. Billing → When access ends describes the warning, access, and reactivation process.
After a manual workspace deletion, sellerfox removes the product data about 48 hours later. Removed product data cannot be restored in the dashboard.
sellerfox deletes all of the workspace's product data. This includes the following groups, among others:
- Analytics data: metrics, products, keywords and rankings, orders and fees, SQPR records, and generated PDF reports.
- Workspace configuration: alerts, events, filters, KPI sets, product lists, settings, and memberships.
- Integrations and files: webhook configuration and delivery history, report files, workspace logos, imported COGS files, and the workspace's inclusion in user-authorized MCP connections.
- Profit data: COGS, income and expenses, and FBM cost settings.
Individual audit records, such as a log of the workspace deletion, remain. These records cannot be used to restore the workspace or the product data.
sellerfox also keeps invoices and contract records. See the privacy policy for the legal basis and retention periods. Deleting your personal account is a separate support request and is not triggered by deleting a workspace.
Who operates sellerfox
sellerfox is operated by MATO Solutions GmbH in Vienna, Austria. Company details are in the imprint.
Related
- Permissions — current workspace access by role.
- How sellerfox works — data sources, refreshes, and outputs.
- Workspaces, teams & roles — deletion prerequisites and confirmation.
- Subscription, billing & credits — access after cancellation.