Legal
Privacy policy.
What we collect, how we use it, and the specific commitments around SP-API, Keepa, tenant isolation, and deletion on cancel.
Effective: June 8, 2026 · Last updated: June 8, 2026
Who we are
Adept Acquisitions LLC (“Adept,” “we,” or “us”), a Texas limited liability company, operates adeptseller.com and the Adept sourcing application (the “Service”). This Privacy Policy explains what data we collect, how we use it, and the choices you have.
What data we collect
We collect the following categories of data:
- Account information— your name, email address, hashed password, and multi-factor authentication settings.
- Authentication data— session and access tokens used to keep you signed in securely.
- SP-API connection metadata— your seller ID, marketplace, read-only authorization tokens, and connection status. We do not collect your customers' personal information or order details.
- Workspace data you create— storefront lists, ASINs, scores, queue decisions, notes, and hold rules.
- Market data cache— Keepa-derived product data (price history, sales rank, fees), which is product data, not personal data.
- Usage analytics— feature events and aggregate activity, scoped to your tenant.
- Billing data— handled by Stripe. We store a customer reference and plan status; we do not store full payment-card numbers.
- Technical data— IP address, browser and device information, and server logs, used for security and reliability.
How we use your data
We use your data to:
- Operate the sourcing pipeline — discovery, scoring, and your ranked queue.
- Authenticate you and keep your account and tenant secure.
- Process subscriptions and billing through Stripe.
- Provide support and respond to your requests.
- Maintain, debug, and improve the Service, using aggregated or anonymized data where possible.
- Send you transactional and service messages, such as billing receipts and security alerts.
- Comply with our legal obligations.
We do not sell your personal data, and we do not use it for third-party advertising.
SP-API access scope
When you authorize Amazon Selling Partner API (SP-API) access, Adept receives read-only permission scoped to your seller account. We use this access exclusively to read product eligibility, restriction state, and catalog metadata so we can upgrade the verdicts shown in your queue to match your actual gating.
Adept never lists products, edits listings, changes prices, manages inventory, fulfills orders, or takes any write action on your seller account. The scopes we request are documented at /docs#restrictions.
You can revoke Adept's SP-API authorization at any time from Amazon Seller Central. Revocation immediately stops further reads; cached data is handled per the “Data retention and deletion” section below.
Keepa data usage
Adept uses Keepa as a third-party source of historical Amazon market data (price history, sales rank, offer history, fee estimates). For each ASIN you encounter in the Service, we may pull and cache Keepa data for up to 24 hours so we can score and re-score products without burning your token budget on every page load.
We do not resell Keepa data, expose Keepa API tokens to other tenants, or aggregate raw Keepa datasets for any purpose other than rendering the Service to you. Keepa's own terms of service apply to the underlying data.
Tenant isolation
Every database query, queue operation, and API call in the Service is scoped to your tenant identifier. Row-level security rules in our PostgreSQL database enforce this at the storage layer — application-level bugs cannot expose another tenant's data without simultaneously bypassing database-enforced policies.
Workspace seats inside your tenant share data scoped to that tenant; we do not commingle data across tenants for analytics, machine-learning training, or any other use.
Security and breach notification
We protect your data with encryption in transit (TLS) and encryption at rest, including encrypting SP-API refresh tokens before they reach the database, as described in our Amazon data disclosure.
If we become aware of a confirmed security incident affecting your personal data, we will notify affected users without undue delay. Where the incident involves Amazon Selling Partner API (SP-API) data, we will notify Amazon within 24 hours of confirming the incident, in accordance with Amazon's Data Protection Policy (DPP).
Third-party services
We rely on a small set of trusted subprocessors to run the Service. Each processes data only as needed to provide its function, under its own terms and security commitments:
- Supabase — managed PostgreSQL database, authentication, and storage.
- Stripe — subscription billing and payment processing.
- Resend — transactional and service email delivery.
- Keepa — third-party Amazon market data.
- Fly.io — application and worker hosting.
- Cloudflare — DNS and content delivery / edge network.
We update this list as our infrastructure changes. If you need a current subprocessor list for a vendor review, email us.
Data retention and deletion
When you cancel your Adept subscription, your tenant's personal data (account info, workspace data, decision history) is hard-deleted from production within 30 days. Backups containing your data roll off our retention window within 90 days.
We retain a limited set of anonymized, internal usage metrics (such as counts of ASINs scored and tenant tier distribution) solely to operate and improve the Service. These metrics contain no Amazon-derived product or account data, and we never aggregate them across sellers or publish them as market, performance, or competitive insights. Billing records required for tax and audit compliance are retained for the period required by applicable law, even after account deletion.
To request immediate deletion ahead of the 30-day window, email [email protected].
Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. You can exercise these rights by emailing [email protected]; we may need to verify your identity first.
U.S. (CCPA/CPRA).California residents have the right to know what personal information we collect, to request deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information, and we will not discriminate against you for exercising your rights. We honor opt-out preference signals, including the Global Privacy Control (GPC), and we provide a notice at collection when you sign up.
EU/UK (GDPR). We process personal data under the legal bases of contract, legitimate interests, consent, and legal obligation, and you have the right to lodge a complaint with your local supervisory authority.
Texas (TDPSA). Adept Acquisitions LLC is a Texas limited liability company, and we do not sell or share your personal data. Under the Texas Data Privacy and Security Act, Texas residents may exercise the rights to access, correct, delete, and obtain a portable copy of their personal data using the same contact email above.
Children's data
The Service is intended for business users aged 18 and over. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. If you believe a minor has provided us data, please contact us.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and notify active users by email or in the app. Your continued use of the Service after a change becomes effective means you accept the updated policy.
Contact
Questions about this policy? Email [email protected].