Legal

Privacy policy

Last updated June 8, 2026

ASIN Metrics (“we”, “us”) is a sourcing tool for Amazon resellers, delivered as a website at asinmetrics.com and a companion Chrome extension. This policy explains what data we collect, how we use it, who we share it with, and how you can remove it. If something here is unclear, please contact us or email info@asinmetrics.com.

1. What we collect

  • Account data. When you sign up we store your email address and a hashed password (or, if you sign in with Google, the email address and a Google account identifier). We do not see or store your Google password.
  • Sourcing data you create. Lists, list items (ASIN + marketplace), notes, tags, costs, lookup history, and saved settings. This data is bound to your account.
  • Product metadata we fetch on your behalf. When you look up an ASIN, we query third-party data providers for price history, sales rank, fees, and offer information, and cache the result against your account so repeat lookups are fast.
  • Operational data. Server logs (IP address, user-agent, request paths, timestamps) needed to run, secure, and debug the service. Logs are retained for a limited period and are not used to build advertising profiles.
  • Optional integrations. If you connect Amazon Selling Partner API or Google (see section 3), we store the refresh tokens we need to call those APIs on your behalf. Refresh tokens are encrypted at rest.

We do not collect biometric data, government IDs, financial-card numbers (Stripe handles billing, not us), or location beyond the coarse signal in an IP address.

2. How we use it

  • To provide the product — let you sign in, run lookups, save lists, and view your dashboard.
  • To call third-party APIs (data providers, Google Sheets, Amazon SP-API) only for the actions you initiate.
  • To respond to your support requests.
  • To detect and prevent abuse (rate-limiting, fraud, account takeover).
  • To communicate service-critical updates (security notices, billing changes). We don't send marketing email without explicit opt-in.

We do not sell your data, rent it, or share it with advertisers. We do not train machine-learning models on your saved lists or notes.

3. Google account data & the Sheets sync

Connecting your Google account is optional. The integration exists so your saved lists can mirror to a Google Sheet you control. When you connect, you grant the following OAuth scopes:

  • userinfo.email & openid — so we know which Google account is connected.
  • spreadsheets — to create tabs and write your lists into the spreadsheet you pick.

We use these scopes only to read your email for the connection record and to write list data to the sheet you select. We do not read your Drive files, your other spreadsheets, your contacts, or your mail. The sync is one-way (app → sheet) — we never read sheet contents back into your account.

ASIN Metrics' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access at any time from your Google account permissions page or via the Disconnect button on the in-app integrations screen.

4. Amazon Selling Partner API data

Connecting your Amazon seller account is optionaland powers the Seller Central analytics and gating features. When you connect, you authorize ASIN Metrics — through Amazon’s official Selling Partner API and Login with Amazon — to access the following on a read-only basis, only while your account is connected:

  • Orders & sales. Order and sales records used to calculate your revenue, profit, and sell-through analytics. We request these through non-restricted roles only and do not access or store buyer personally identifiable information such as buyer names or shipping addresses.
  • Fees & financials. Referral and fulfilment fees, for accurate profit math.
  • Business & performance reports. To surface trends across your own catalog.
  • Listing restrictions (gating). To tell you whether you are eligible to sell a given ASIN.

How we use Amazon information. We use Amazon information solely to provide the features you have enabled, to you, the connected selling partner. Specifically:

  • We do not aggregate data across Authorized Users’ businesses or customers obtained through the Amazon Services API to provide or sell to any party, including competing sellers (Amazon Acceptable Use Policy §4.4).
  • We do not promote, publish, or share insights about Amazon’s business, and we do not use such insights for our own business purposes (Amazon Acceptable Use Policy §4.5).
  • We do not sell, rent, or share your Amazon data with advertisers, and we do not use it to train machine-learning models.

Security, retention & deletion. Selling Partner API refresh tokens are encrypted at rest with AES-256-GCM; all data is encrypted in transit (TLS). Access to Amazon information is least-privilege and audited. We retain Amazon information only as long as necessary to provide the features you use. We do notrequest or store buyer personally identifiable information (such as buyer names or shipping addresses). Disconnecting your Amazon account on the in-app integrations screen — or revoking access in Seller Central — immediately stops further access, and we delete retained Amazon information within 30 days. This is consistent with Amazon’s Acceptable Use Policy and Data Protection Policy.

5. Where data lives & who processes it

We use a small number of vetted sub-processors to run the service:

  • Supabase — Postgres database, authentication, and file storage.
  • Vercel — application hosting and edge delivery.
  • Product data provider — Amazon product, pricing, and rank data.
  • Google — only when you explicitly connect a Google account for the Sheets sync.
  • Stripe — payment processing for paid plans (if applicable).

6. Cookies

We use only strictly necessary cookies — there are no advertising, analytics, or cross-site tracking cookies, so no consent banner is required. They are: a session cookie that keeps you signed in, short-lived state cookies used during Google and Amazon sign-in to prevent request forgery, and a brief checkout cookie that remembers which plan you picked while you create your account. These are essential to operate the service; we do not use cookies to profile you or build advertising audiences.

7. Security

Data in transit is encrypted with TLS. Data at rest is stored in managed Postgres with encryption enabled. OAuth refresh tokens are additionally application-level encrypted before they hit the database. Access to production systems is restricted and audited.

No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you without undue delay.

8. Your choices

  • Access & export. The dashboard and the in-app export give you your account data — lists, notes, settings, costs, and lookup history; the Google Sheets sync is a continuous export too. If you need anything we hold that isn't covered there, email us and we'll provide it.
  • Correct. You can edit lists, notes, and settings directly in the app at any time.
  • Delete. You can delete individual records, disconnect integrations, or close your account entirely. Closing the account removes your records from our active systems within 30 days; encrypted backups roll off on their normal schedule.
  • Disconnect Google. Use the “Disconnect” button on the integrations page, or revoke at myaccount.google.com/permissions. Disconnecting stops new syncs immediately.

9. Children

ASIN Metrics is a business tool. It is not directed at children under 16, and we do not knowingly collect data from them.

10. Storefront & competitor-seller data

Some features let you research public Amazon storefronts and sellers you choose to track. To provide them, we fetch and cache publicly available business informationabout those sellers — such as a public store or business name, location, rating, recent public feedback, and estimated sales metrics — through our data provider, and associate it with the tracking entry you created. We process this under our and our users’ legitimate interest in market and competitor research, limited to public business information; we do not collect private contact details of third-party sellers, and we do not use this data for advertising.

Are you a seller who wants your store removed from our cache? Email info@asinmetrics.com and we will remove it promptly.

11. Changes to this policy

When we make material changes we will update the “Last updated” date and, for significant changes, notify you in-app or by email before they take effect.

12. Contact

Privacy questions, deletion requests, or concerns about a Google integration can go through our contact form or email info@asinmetrics.com and we will reply within one business day.