Privacy Policy
This policy describes what data Helm accesses when a seller connects their Amazon Selling Partner account or Amazon Advertising account, how that data is stored and protected, who can see it, and how a seller can end access at any time.
What data Helm accesses
Depending on which Amazon APIs a seller authorizes, Helm may access:
- Sales, traffic, and Search Query Performance reports (Selling Partner API)
- Order, inventory, and FBA shipment/reimbursement data (Selling Partner API)
- Product listing content — titles, bullet points, descriptions, images, and structured attributes (Selling Partner API Catalog Items / Listings Items)
- Financial event data — fees, refunds, and settlements (Selling Partner API Finances)
- Advertising campaign, targeting, and search-term performance (Amazon Ads API)
Helm requests only Amazon's standard API roles for these purposes. Helm does not request, and does not use, any Amazon role that exposes end-customer personal information (buyer names, addresses, or contact details). Order and sales data used by Helm is aggregate/product-level, not buyer-identifiable.
A seller who connects a Google Workspace or Shopify account for cross-channel reporting separately controls what that connection shares, and can revoke it independently through that provider's own account settings.
How data is stored and protected
- Amazon API credentials (refresh tokens, client secrets) are encrypted at rest with AES-256-GCM before they are ever written to Helm's database. They are never stored or logged in plaintext.
- Every seller's data is isolated by tenant at the database layer — one seller's account can never read another seller's data through Helm, including through the AI-assistant tools.
- Reporting data (sales, ads, inventory, listing content, etc.) is retained for as long as an account is active, so that trend and historical reporting remain useful. A seller can request deletion of their account's stored data at any time (see Contact, below); Helm will delete it, other than records Helm is required to retain for legal, tax, or fraud-prevention purposes.
- Access to Helm's dashboard is authenticated per user; every read of a seller's data and every write action (such as a bulk listing update) is logged with the acting user, timestamp, and action taken.
Who can see the data
Data is visible only to: (1) the seller's own authorized users, and (2) TapeGeeks Inc. staff operating Helm on the seller's behalf, where the seller has engaged TapeGeeks Inc. for that service. Helm does not sell seller data, and does not share it with third parties for advertising or marketing purposes. Helm's infrastructure runs on standard cloud hosting and database providers (for hosting and storage only); those providers do not have a business right to use the data themselves.
Bulk changes to Amazon listings
Where a seller opts into Helm's listing-attribute update feature, any proposed change is first validated against Amazon's own preview endpoint (which does not modify the live listing), shown to the seller for review, and only submitted to Amazon after the seller explicitly approves that specific batch. This feature is disabled by default and must be separately enabled per account.
Revoking access
A seller can revoke Helm's access to their Amazon account at any time from Seller Central (Apps & Services → Manage Your Apps) or their Amazon Advertising console, independently of Helm. Revoking access stops all further data collection immediately; previously collected data is handled as described above.
Amazon Data Protection Policy compliance
Helm's handling of Amazon Selling Partner and Advertising data is designed to comply with Amazon's Acceptable Use Policy and Data Protection Policy, including the encryption, access-control, retention, and scope-of-access practices described above.
Contact
Questions about this policy, or requests to access or delete your data, can be sent to greg@tapegeeks.com or 905-334-9282.