Legal

Privacy Policy

Last updated: 12 September 2026

Amazon connection status: Amazon has approved CEILR's requested Product Listing and Brand Analytics SP-API scope. Approval alone does not connect a seller account. CEILR will treat Amazon-originated seller data as live only after the seller explicitly authorizes CEILR and the connection is successfully configured and verified.

Who operates CEILR

CEILR is operated by Arc Techno Pty Ltd. Questions about privacy can be sent to support@ceilr.com.

Information we may collect

  • Account details, including your name, email address and authentication information.
  • Workspace data you enter or upload, such as product economics, ASINs, keywords and seller reports.
  • Subscription and entitlement information. Payment-card details are handled by the payment provider and are not stored directly by CEILR.
  • Technical and security information, including timestamps, service logs, browser data and error information.
  • Support communications and product feedback.
  • Onboarding/contact request information, including your marketplace, approximate ASIN count and the workflow problem you describe.
  • Optional marketing measurement information when you choose to allow it, such as page views, traffic source, device/browser context, interactions with CEILR marketing-site calls to action and advertising-attribution identifiers.

Optional website and advertising measurement

CEILR uses a separate Google Tag Manager container, Google Analytics 4 property and CEILR-specific Google Ads tag for ceilr.com. These marketing tags are not loaded until a visitor chooses Allow analytics. If measurement is declined, the CEILR marketing site does not intentionally load those tags for that browser choice. A visitor can reopen the choice from the site's Privacy choices control.

Marketing measurement is intended to understand public-site traffic, interactions such as page visits and links that open CEILR, and CEILR advertising attribution. Enhanced conversions are not enabled. CEILR does not intentionally send Amazon seller data, buyer PII, payment-card data or authenticated CEILR workspace content through the public marketing-site tags.

Amazon seller data and SP-API scope

Amazon has approved CEILR's standard SP-API scope for the Product Listing and Brand Analytics roles. Direct Amazon seller data remains unavailable for a seller until that seller explicitly authorizes CEILR through Amazon's applicable authorization workflow and CEILR successfully configures the connection.

CEILR intends to use Product Listing access only to read permitted catalog/listing context, listing attributes, status/issues and product-type requirements for listing/search analysis and seller decision support. CEILR intends to use Brand Analytics only to read permitted seller-authorized analytics reports and datasets for eligible sellers and brands. CEILR does not create, update, patch, merge or delete Amazon listings, prices or inventory through SP-API.

CEILR's current Amazon scope does not request restricted SP-API roles, buyer personally identifiable information (PII) or Restricted Data Tokens (RDTs). CEILR does not use Amazon access to send buyer communications or review requests, and it does not sell Amazon-originated seller data to advertisers or other sellers.

Amazon Ads data

Status: CEILR's direct Amazon Ads API integration is built but is not active. It stays disabled until Amazon approves CEILR's Amazon Ads API access and issues the required credentials. CEILR therefore does not currently receive seller advertising data directly through the Amazon Advertising API. Sellers may separately upload advertising reports to CEILR as workspace evidence; those seller-provided uploads are not direct Amazon Ads API access. The Amazon Advertising API is a separate Amazon approval from the SP-API roles described above; approval of one is not approval of the other.

When the integration is enabled and a seller explicitly authorizes it, CEILR will access only the following through the Amazon Advertising API, and only for that seller:

  • Advertising profiles the seller authorizes, so the seller can choose which advertising account a report belongs to.
  • Aggregate Sponsored Products advertised-product reports, limited to impressions, clicks, cost, advertised ASIN, advertised SKU, 14-day purchases, 14-day sales and the reporting date range.

These are aggregate performance figures for the seller's own advertised products. They contain no buyer identity, no buyer personally identifiable information, no search-term-level buyer data and no order-level customer information.

CEILR uses this data for one purpose: to show the seller their own advertising performance alongside their product economics, so they can judge profitability and decide what to do next. CEILR does not sell Amazon Ads data, does not share it with other sellers or advertisers, and does not use one seller's data to inform another seller's results.

CEILR makes no advertising changes. It reads reporting only. CEILR does not create, pause or edit campaigns, ad groups, targets or keywords, and does not change bids, budgets or negative targeting. Those endpoints are not implemented. Every advertising decision stays with the seller, in their own Amazon account.

A seller can disconnect Amazon Ads from CEILR at any time, which deletes CEILR's stored authorization credential. Revoking CEILR's access on the Amazon side is done by the seller in their own Amazon account.

How information is used

We use information to respond to onboarding/contact requests, provide and secure the service, isolate customer workspaces, process subscriptions, support users, prevent abuse, improve reliability, understand public marketing-site performance and CEILR advertising attribution when measurement is allowed, and meet legal obligations.

Service providers and sharing

CEILR may use contracted providers for hosting, authentication, transactional email, billing, monitoring, optional website and advertising measurement and permitted licensed market-data services. Providers receive only the information needed to perform their contracted role. CEILR does not sell personal information or Amazon-originated seller data, and it does not share one seller's workspace or Amazon-originated data with another seller.

Storage and protection

CEILR uses HTTPS/TLS for data in transit and contracted cloud platforms for application hosting, authentication and storage. Amazon credentials and authorization tokens are handled server-side and are not intentionally exposed in public website code. Customer workspaces are protected by authenticated, tenant-isolated application boundaries and least-privilege service access. No online service can guarantee absolute security.

Retention and deletion

Ordinary account, billing and support records are retained only for as long as reasonably necessary for the service, security, dispute resolution and applicable legal obligations. Amazon-originated non-PII data will be retained for no longer than 18 months and may be deleted sooner when no longer needed for the disclosed purpose or when Amazon policy or applicable law requires earlier deletion. Security logs are retained for at least 12 months in line with current Amazon SP-API security guidance and are designed not to contain Amazon credentials or buyer PII.

If a seller revokes CEILR's Amazon authorization, CEILR will stop making new SP-API calls for that authorization. Amazon-originated information will be deleted or de-identified when it is no longer permitted or required, subject to applicable legal obligations and Amazon's Data Protection Policy. Eligible deletion requests may be sent to support@ceilr.com.

Your choices

You may request access to, correction of, or deletion of eligible personal information by contacting support. Public-site visitors can choose whether to allow optional marketing measurement and can reopen that choice using the site's Privacy choices control. If you authorize CEILR's Amazon connectivity, you may revoke CEILR's Amazon authorization through the applicable Amazon account controls. Some billing, security or legal records may need to be retained where required by law.

International processing

Some providers may process information outside Australia. We take reasonable steps to use reputable providers and appropriate contractual and security controls.

Changes

We may update this policy as the service, providers or legal requirements change. The current version will be published on this page.