Privacy policy
Agent ChaChing is a mobile app for Amazon sellers made by 52commerce. This policy explains what we process when you use the app and this website, why, how long we keep it, and what you can do about it.
In short
- We read order data from your own Amazon seller account, and nothing about your buyers.
- We use it for one purpose: your sale alerts and the order count in the app. Nothing is aggregated across sellers, sold, or used to train models.
- Everything lives on servers in the European Union, encrypted.
- Raw orders are kept 90 days by default (you can choose 30 to 365 days). Everything is deleted within 30 days after you disconnect Amazon or delete your account, backups included.
- No advertising, no tracking across apps or websites.
1. Who is responsible
52commerce, Kronenburgsingel 525, unit 3.05, 6831 GM Arnhem, the Netherlands. Chamber of Commerce (KvK) number: 83007229. Email: [email protected].
52commerce is the controller for your account data, the website and our own logs. For the Amazon order data of your seller account we act on your instructions and for your purpose only; see section 10.
2. What this policy covers
The Agent ChaChing app for iOS and Android, the website agentchaching.com including the partner form, and email contact with us. Amazon, Apple and Google have their own privacy policies for their services; we link to them where relevant.
3. What we process, why, and on what basis
3.1 Account data
Your email address; the sign-in method you chose (email link, Sign in with Apple, or Google); the push tokens of your devices; your subscription status and plan as reported by the app store (we never see card numbers); and your settings, such as chosen sounds, marketplaces, quiet hours and whether the amount is shown in alerts.
Purpose: to provide the service, deliver alerts, bill you and support you. Legal basis: performance of a contract (article 6(1)(b) GDPR). Retention: as long as your account exists, then deleted within 30 days.
3.2 Amazon order data from your seller account
When you connect Amazon, we read order data through Amazon's Selling Partner API with a single read-only permission, "Inventory and Order Tracking". We store exactly these fields:
- marketplace (for example amazon.de);
- purchase date and time;
- order status (for example Pending, Unshipped, Shipped, Canceled);
- order total and currency;
- number of items, and per item: quantity, seller SKU, ASIN and product title;
- fulfilment channel (FBA or FBM);
- a keyed hash (HMAC) of the Amazon order number, used only to recognise the same order twice, plus the last four characters of the order number for the alert text.
From these records we compute daily totals per marketplace: number of orders, units and revenue.
What we never request, store, display or share: buyer names, shipping or billing addresses, buyer email addresses, phone numbers, postal codes, payment details, tax information or gift messages. We do not call the Amazon endpoints that return buyer information and we never use a Restricted Data Token. Some Amazon order notifications include a destination postal code; we discard it the moment the notification arrives and never write it to disk.
Purpose: to send you a sale alert and show today's order count in the app. Legal basis: performance of a contract; for this data we process on your instructions (section 10). Retention: raw order records 90 days by default, adjustable between 30 and 365 days in the app; daily totals for as long as your account exists.
Your Amazon password never touches our systems. The authorisation token Amazon issues is stored encrypted (section 7). You can revoke the authorisation at any time in the app or in Seller Central under Apps and Services, Manage Your Apps.
3.3 Technical logs
Request timestamps, endpoints, response codes, app version, device model and operating system version, error reports, and, for a short time, your IP address for abuse prevention. Logs contain no Amazon order content, no buyer data and no tokens.
Purpose: to keep the service reliable and secure and to detect abuse. Legal basis: legitimate interest (article 6(1)(f) GDPR). Retention: 90 days. Audit logs of access to seller data (who, what, when, result; identified by a user id only) are kept 12 months.
3.4 Product usage
Anonymised events such as "screen opened", "test alert sent" and "alert delivered, in N seconds", processed with an EU-hosted analytics provider. No advertising identifiers, no tracking across apps or websites.
Purpose: to improve the app. Legal basis: legitimate interest; you can turn this off in Settings. Retention: raw events 12 months.
3.5 Website
- Partner application: name, email, channel and audience size, to assess and set up your partnership. Legal basis: steps prior to a contract. Deleted 12 months after a declined application, otherwise kept for the duration of the partnership.
- Email contact: the content of your message, kept as long as needed to handle it and up to 24 months.
This website sets no cookies and uses no analytics. Fonts are loaded from Google Fonts, which means your browser requests the font files from Google's servers and Google receives your IP address for that request. The partner form opens your own email app; nothing is sent to a form provider.
4. Where your data is stored
In the European Union. Our servers, database and backups run with Hetzner in Germany and Finland. The message queue that receives Amazon's order notifications and the key management service that protects your Amazon token run with Amazon Web Services in Stockholm, Sweden (region eu-north-1). Backups stay in the EU.
5. Who receives your data
We use the following providers (processors) to run the service. Each has signed a data processing agreement with us. Where a provider is established outside the EU, transfers rely on the European Commission's standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.
| Provider | What they do for us | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Message queue for Amazon order notifications; key management for encrypting Amazon tokens | EU (Stockholm) |
| Hetzner Online GmbH | Servers, database, backups | EU (Germany, Finland) |
| Apple Inc. | Delivery of push notifications to iOS devices (APNs); Sign in with Apple; App Store billing | USA (Data Privacy Framework, standard contractual clauses) |
| Google LLC | Delivery of push notifications to Android devices (Firebase Cloud Messaging); Google sign-in; Google Play billing; Google Fonts on the website | USA (Data Privacy Framework, standard contractual clauses) |
| RevenueCat, Inc. | Subscription status across the App Store, Google Play and web | USA (standard contractual clauses) |
| Stripe Payments Europe, Ltd. | Payments on the website; partner payouts | EU (Ireland), with Stripe, Inc. in the USA under standard contractual clauses |
| Migadu AG | Transactional email: sign-in links and receipts; our own mailbox | Switzerland (adequacy decision) |
| None at launch | Anonymised product usage (section 3.4): no provider in use yet; it will be EU-hosted and listed here before we switch it on | EU |
We share data with no one else and we never sell it. Your Amazon data is never shared with other sellers, with partners in our referral programme (they see only counts and amounts, never names or orders), or with advertisers. We may confirm to Amazon that we have deleted your data when Amazon asks, and we report security incidents involving Amazon data to Amazon as its policies require. We disclose data to authorities only when the law obliges us to.
6. Push notifications
An alert contains the marketplace ("New order on amazon.de") and, if you enable it, the amount and the product title. It never contains buyer data. Apple and Google deliver notifications to your device, so the text of an alert passes through their servers. You can turn amounts and product titles off in Settings; the alert then only says that an order came in.
7. Security
- All traffic uses TLS 1.2 or higher; our web endpoints enforce HTTPS.
- Database volumes and backups are encrypted at rest (AES-256).
- Your Amazon authorisation token is encrypted per seller with envelope encryption (AES-256-GCM) using AWS Key Management Service. Only our background workers can decrypt it; the app on your phone and our public API never can.
- Multi-factor authentication is required for every system that holds your data. Access is limited to a small number of named staff and reviewed regularly.
- Access to seller data is logged. Deletion is automated and logged.
- If a security incident affects your data, we notify you without undue delay, notify the Dutch Data Protection Authority within 72 hours where the GDPR requires it, and notify Amazon within 24 hours where Amazon data is involved.
8. How long we keep data
| Data | How long |
|---|---|
| Raw order records | 90 days by default; you can set 30 to 365 days in the app |
| Daily totals per marketplace | As long as your account exists |
| Account data and settings | As long as your account exists, then up to 30 days |
| Everything, after you disconnect Amazon, delete your account, or Amazon asks us to delete | Deleted within 30 days, including backups |
| Technical logs | 90 days |
| Audit logs (no personal data beyond a user id) | 12 months |
| Anonymised usage events | 12 months |
| Support and contact emails | Up to 24 months |
| Invoices and payment records | 7 years, as Dutch tax law requires |
9. Deleting your account and data
Three ways, your choice:
- In the app: Settings, Delete account. Your account is deactivated immediately, the Amazon authorisation is revoked, and all your data is erased within 30 days, backups included.
- By email: write to [email protected] from the address on your account. We confirm the deletion in writing.
- In Seller Central: revoke Agent ChaChing under Apps and Services, Manage Your Apps. We stop reading immediately and delete your Amazon data within 30 days.
Deleting the app from your phone does not delete your account. A paid subscription is managed by the App Store or Google Play and must be cancelled there; deleting your account does not cancel it, because the stores do not allow us to do that for you.
10. Processing on your behalf
Your Amazon order data belongs to your business. We process it only on your instructions, for your own alerts and the order count in the app, and for nothing else: no aggregation across sellers, no benchmarking, no sharing, no model training. If your business needs a data processing agreement, email us and we send you ours.
11. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent where processing is based on consent. Most of this you can do yourself in the app; for the rest, email [email protected]. We respond within one month and may ask you to confirm your identity first.
If you think we handle your data wrongly, we would like to hear it first. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority of the EU country where you live.
12. Age
Agent ChaChing is for Amazon sellers and requires an Amazon seller account. It is not intended for anyone under 18, and we do not knowingly process data of children.
13. Changes to this policy
When we change this policy, we update the date at the top. For material changes we notify you in the app or by email at least 14 days before they take effect.
14. Contact
52commerce, Kronenburgsingel 525, unit 3.05, 6831 GM Arnhem, the Netherlands. Email: [email protected].