1. Who we are
ROSETIQ INC. is a corporation incorporated in the Province of Ontario, Canada (Ontario Corporation Number
1001717717). We are the organisation responsible for the data described in this policy. Contact details are at
the end of this page.
2. The service in one paragraph
Rosetiq is an analytics service for sellers on Amazon. A seller authorises Rosetiq to read data from the
seller's own marketplace and advertising accounts, through the interfaces those platforms provide for that purpose. Rosetiq stores that data, computes profit,
inventory, advertising and customer figures from it, and shows those figures to the seller's authorised users.
Access is read-only: Rosetiq does not change anything in the seller's accounts.
3. Data obtained from a seller's connected accounts
When a seller connects an account, Rosetiq retrieves and stores the following categories of records, and
keeps them current through scheduled synchronisation and event notifications:
- Orders and order items — order identifiers, dates, amounts, quantities, SKUs and product
identifiers, fulfilment channel, order status, and the destination country and region of each order. Street
addresses, cities and postal codes are not retrieved.
- Shipments — shipment dates, SKUs and quantities. Repeat-purchase figures are computed
from the seller's own order records with a pseudonymous key; no buyer identity is stored.
- Returns — return dates, SKUs and return reasons. Free-text comments written by buyers are
not stored.
- Financial events — settlement records: charges, fees, promotions, refunds, reimbursements
and adjustments, with their amounts and dates.
- Listings and catalog — SKUs, product identifiers, titles, images, dimensions, prices,
offers and listing status.
- Inventory and inbound — stock levels by location and state, inventory ledger movements,
inbound shipment plans and receipts, and warehousing records.
- Traffic and search — sessions, page views, conversion and search performance by listing
and day, as reported by the marketplace.
- Advertising — campaigns, ad groups, keywords and targets with spend, impressions, clicks
and attributed sales.
- Subscriptions — subscribe-and-save enrolment and delivery counts by SKU.
Rosetiq requests only the standard, non-restricted access needed to produce the figures described on the
product page. It does not request, receive or store personally identifiable information about the seller's
buyers — no names, contact details, addresses, payment details or tax identifiers. The records above are the
seller's own business records, processed only to produce figures for that seller.
4. Data the seller's users enter
- Cost of goods, supplier details, purchase orders, production and shipping lead times.
- Notes, labels, saved views and preferences.
5. Data about users of the service
- Account — name, e-mail address, organisation, role and page permissions, and a password
stored only as a salted hash. Passwords are never stored or logged in clear text.
- Session — a single session cookie set on sign-in, valid for 24 hours. There are no
advertising or analytics cookies and no third-party trackers on any Rosetiq page.
- Activity — sign-in events with their time and originating IP address, and an audit log of
significant actions within the service (for example changes to cost of goods), kept so that an organisation's
administrator can see who changed what.
- Correspondence — messages you send us by e-mail or through the contact page.
6. Why we process data
We process the data above for one purpose: to provide the Rosetiq service to the seller whose accounts the
data came from. In particular:
- to compute and display the figures the service exists to show;
- to keep those figures current and to detect when a data source has fallen behind;
- to authenticate users and enforce each organisation's access permissions;
- to support the seller when a figure is questioned;
- to operate, secure and maintain the service, including backups.
We do not sell data, share it with other sellers, aggregate it across sellers to produce
benchmarks, use it for advertising, or use it to train models.
7. Where data is stored, and who processes it
Rosetiq runs on servers operated by Hetzner Online GmbH in Germany. Data is transmitted to and from the
service over encrypted connections. Backups are taken regularly and kept within the same hosting environment.
We use a small number of service providers, each for a specific function:
| Provider | Function | Data involved |
Hetzner Online GmbH Germany | Hosting of the application and database | All data in this policy, at rest |
Resend, Inc. United States | Transactional e-mail — invitations, notifications, delivery status | Recipient address and message content |
GitHub, Inc. United States | Source code hosting and deployment | Code only, no seller data |
Because our servers are in Germany and our company is in Canada, seller data may be transferred across
borders in the course of providing the service. Marketplace and advertising platform data is handled in
accordance with the data-protection terms of the platforms it comes from, which are incorporated into our
obligations to those platforms.
8. How long we keep data
Records obtained from connected accounts are kept only as long as strictly necessary to provide the service.
Order, financial, inventory, traffic and advertising records — which carry no buyer identifiers — are retained
for the life of the subscription, because year-over-year comparison and repeat-purchase analysis depend on
history. When a subscription ends, or the seller withdraws authorisation, seller data is deleted as
described in section 9.
User account data is kept while the account exists. Sign-in and audit records are kept for as long as the
organisation they belong to is a customer. Operational logs are kept for a limited period for security and
troubleshooting and then discarded.
9. Deletion, access and correction
To have a seller's data deleted, the organisation's administrator writes to
support@rosetiq.com from the e-mail address registered on the account. We
confirm the request with the administrator, then delete all records belonging to that seller — orders,
shipments, financial events, listings, inventory, advertising, traffic, entered data and derived figures —
and confirm in writing when it is done. Deletion is completed within 30 days of the confirmed request. Backups are retained for no longer than thirty days
and are never restored to reinstate deleted records, so no copy survives beyond thirty days of the request.
Withdrawing Rosetiq's authorisation in the seller's own marketplace or advertising account settings stops
all further retrieval immediately, and we treat it as an instruction to delete: all records obtained from that
account are deleted within 30 days of the withdrawal, unless we are required by law to keep specific records.
The same applies when a subscription ends. Where a platform whose data we hold requires that data to be deleted or
returned, we complete the deletion within 72 hours of the request, remove all live instances within 90 days, and
certify completion in writing if asked.
To have a user account deleted, or to access or correct the data we hold about you as a
user, write to the same address. Organisation administrators can also remove users directly within the
service.
10. Security, and how to report a problem
What is in place. Rosetiq's integration issues read requests only — nothing in a seller's
account can be changed through it. Sellers grant access through the platform's own authorisation flow and can
withdraw it at any time; no platform password is ever shared with us. All connections use TLS, and plain HTTP
is redirected. Every record carries its seller's identifier, and the database enforces row-level security on
top of the application's own filtering. Passwords are stored as salted bcrypt hashes; sessions use HttpOnly,
Secure cookies valid for 24 hours; access within an organisation is controlled per page, and sign-ins are
logged. The credentials the service uses are held in server configuration, not in the application code. The database is backed up on a
schedule within the hosting environment in Germany. Access to stored data within Rosetiq is limited to the
engineer who operates the service.
Reporting. Write to support@rosetiq.com
with the subject Security report — for a security vulnerability, a privacy concern, or any
suspected misuse of data obtained from a connected marketplace or advertising account, whether you are a
researcher, a seller, a buyer or a third party. Include what you saw and how to reproduce it. A
machine-readable pointer to this section is published at /.well-known/security.txt.
What we commit to. An acknowledgement within three business days; an assessment and an
intended fix date within ten business days, with updates until the fix is deployed. We maintain a written
incident-response plan, review it every six months, and name a single person responsible for handling an
incident. Where an incident affects data obtained from a connected marketplace or advertising account, we
notify that platform within 24 hours of detecting it, in the manner its terms require, and the seller without
undue delay. When data must be destroyed, we clear or purge it — records, backups and exports alike — and can
produce written certification that it was done. Good-faith research within
scope — rosetiq.com, app.rosetiq.com and the e-mail we send — is authorised: we will not pursue legal action and
will not characterise it as malicious. Where a platform's terms require us to notify it of any access to data,
we do so and state that the access was authorised research. Out of scope: the platforms whose data we read,
our hosting and e-mail providers, denial of service and social engineering.
11. Applicable law
We handle personal information in accordance with the Personal Information Protection and Electronic
Documents Act (Canada) and, where it applies to a seller's or user's data, the General Data Protection
Regulation, and the California Consumer Privacy Act as amended, where it applies. We do not sell or share personal
information as those terms are defined in that Act. You may complain to the Office of the Privacy Commissioner of
Canada or to your local supervisory authority. We would prefer to hear from you first.
12. Changes
When this policy changes, the new version is published here with a new effective date. Changes that
materially reduce protections are notified to organisation administrators by e-mail before they take effect.
13. Contact
ROSETIQ INC.
160 Densmore Road, Unit 38, Cobourg, Ontario K9A 0X8, Canada
support@rosetiq.com