Privacy Policy
Last updated: 11 June 2026
1. Who We Are
Opexcel ("we", "our", "us") operates opexcel.app, a business analytics platform for Amazon sellers. The service connects to your Amazon Selling Partner account, with your authorisation, and turns your order, fee and inventory data into dashboards, profitability analytics and pricing tools.
For the personal data described in this policy, Opexcel is the data controller. You can reach us at contact@opexcel.app or via our contact page.
2. Information You Provide
- Account data — your name, email address and profile picture from your Google account when you sign in with Google.
- Configuration data — information you enter or upload to use the service, such as cost-of-goods figures, pricing rules, tracked products and notification settings (including any Discord webhook URL you choose to connect).
3. Data We Ingest from Amazon on Your Behalf
When you connect your Amazon seller account, we retrieve and store data through the Amazon Selling Partner API (SP-API) so the dashboard can work:
- Order data — order IDs, statuses, purchase dates, items, quantities and prices.
- Financial data — fees, fee estimates, settlement events and proceeds for your seller account.
- Inventory and shipment data — stock levels, inbound shipments and listing prices.
- Catalog data — product titles, categories, dimensions and images.
- Seller account identifiers — your Selling Partner ID (merchant token).
Buyer order data. The raw order records Amazon returns can include buyer-related fields, such as the buyer's order email address (typically an anonymised Amazon alias) and delivery address details for each order. We store these raw records as supplied so your order history can be synced, audited and re-processed accurately. From the delivery address we also derive the destination town and the outward half of the postcode (for example "LS1"), which power aggregate order-destination analytics shown only to you. We are actively reducing the buyer-identifying fields we keep in long-term storage (see Data Retention below).
4. How We Use Data
We use the data described above solely to provide the service to you:
- Displaying your orders, sales history and financial performance.
- Calculating profitability metrics (fees, VAT estimates, margins, ROI) for your products.
- Running features you configure, such as repricing rules, deal monitoring and alerts.
- Producing aggregate analytics for your account, such as the order-destination map.
- Operating, securing and troubleshooting the platform.
We do not sell personal data, use it for advertising, or contact your buyers. Each user's data is kept isolated to their own account.
5. Lawful Basis
We process personal data under UK GDPR on the basis of contract performance (Article 6(1)(b) — providing the service you signed up for) and legitimate interests (Article 6(1)(f) — operating, securing and improving the platform, including aggregate analytics for your account).
6. Infrastructure and Third Parties
We do not sell or rent your data. We share data only with the service providers needed to run the platform:
- Vercel — application hosting.
- Neon — the Postgres database where synced data is stored.
- OpenStreetMap Nominatim — postcode-to-coordinates geocoding for map features. Only postcodes are sent — never names, emails or street addresses. Route lines on shipment maps are drawn using the public OSRM routing service, which receives map coordinates only.
- Amazon SP-API and Keepa — the data sources we query on your behalf to populate the dashboard.
- Discord — if you connect a Discord webhook, the alerts you configure are sent to the webhook URL you provide.
- Google — sign-in is handled by Google as your identity provider.
7. Data Retention
Synced order and financial data is retained for as long as your account is active, because historical data is what powers your long-term analytics (profit trends, learned fee rates, FIFO cost accounting). Buyer-identifying fields contained in raw order records (such as buyer email and full delivery address) are being phased out of long-term storage as part of ongoing data-minimisation work — aggregate analytics only need the derived town and outward postcode. You may request deletion of your data at any time (see Your Rights below).
8. Data Security
Your Amazon credentials (the LWA refresh token that authorises SP-API access) are encrypted at rest using AES-256-GCM before being stored. Access tokens are short-lived and never stored persistently. All data is transmitted over HTTPS/TLS, and every query that touches user data is scoped to the owning account.
9. Amazon SP-API Compliance
This application uses the Amazon Selling Partner API in accordance with Amazon's Acceptable Use Policy and Data Protection Policy. Data retrieved via the SP-API is used solely to provide the services described in this policy to the authorising seller.
10. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted.
- Receive an export of your data in a portable format.
- Restrict or object to certain processing.
To exercise any of these rights, contact us at contact@opexcel.app. We honour requests without undue delay and within statutory timescales. You can also revoke this application's access to your Amazon account at any time via Seller Central → Apps & Services → Manage Your Apps. If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk).
11. Cookies
We use strictly necessary cookies only — the session cookies required to keep you signed in. We do not use analytics, advertising or cross-site tracking cookies.
12. Changes to This Policy
We may update this policy as the service evolves. The updated version will be posted on this page with a revised "Last updated" date.
13. Contact
For privacy questions or to exercise your rights: contact@opexcel.app. See also our Terms of Service.