Trust & Security

Security

Last updated: August 14, 2026

Security is an important part of how we design and operate SellerRoot. We use technical and organizational measures designed to protect customer information and the systems that process it.

Data We Process

Depending on the Services you use, we may process:

  • Amazon advertising data, including campaigns, targets, search terms, spend, sales, orders, placements, and performance metrics
  • Account information such as business name, email address, billing information, and marketplace identifiers
  • Operational information such as system events, analysis activity, and administrative activity

We do not request or store your Amazon account password.

Amazon Account Access

SellerRoot connects to Amazon Advertising through Login with Amazon (LWA) and the Amazon Ads API.

When you connect your Amazon account, Amazon handles the authorization process and you grant SellerRoot the permissions required to provide the Services.

SellerRoot does not receive or store your Amazon account password.

Access is provided through Amazon’s authorized authentication and authorization framework. The permissions available to SellerRoot are determined by the authorization you grant to the application.

You can review or revoke application access through your Amazon account settings.

Encryption

We use encryption to protect information in transit and at rest.

  • In transit: Connections between your browser, our services, and supported third-party services use TLS encryption.
  • At rest: Production databases and storage use encryption provided by our infrastructure providers.
  • Sensitive credentials: API tokens and other sensitive credentials are stored using protected mechanisms and are not stored in source code.

Authentication and Access Control

Access to SellerRoot is protected through authentication and session security controls.

Access to customer information is based on user roles and workspace permissions.

Users can access only the information available to their authorized workspace and role.

Access to production systems and customer information is restricted to personnel who require it for their responsibilities.

Administrative activities are monitored and logged where appropriate.

Infrastructure

SellerRoot uses established cloud infrastructure providers for application hosting, databases, storage, and related services.

Our infrastructure includes:

  • Managed application and database infrastructure
  • Encrypted production environments
  • Restricted access to production systems
  • Automated database backups
  • Monitoring and operational controls

Third-Party Providers

We use selected third-party providers to operate the Services. These may include providers for:

  • Cloud hosting and databases
  • Application infrastructure
  • AI-assisted analysis
  • Transactional communications
  • Authentication and security services

Where a provider processes customer information on our behalf, we take reasonable steps to ensure appropriate contractual and security protections are in place.

AI-Assisted Features

Some SellerRoot features may use AI-assisted technologies for analysis and recommendations.

Only information necessary for the applicable feature is processed for this purpose.

Amazon passwords, authentication credentials, and access tokens are not provided to AI providers.

AI-assisted outputs may require review before being used for business decisions.

Data Retention and Deletion

We retain information for as long as reasonably necessary to provide the Services, maintain security, meet contractual or legal obligations, resolve disputes, and support legitimate business purposes.

When information is no longer required, it is deleted or securely disposed of in accordance with applicable requirements.

Amazon data is handled in accordance with applicable Amazon requirements and our agreements with customers.

Security Incidents

We maintain procedures for identifying, investigating, responding to, and addressing security incidents.

Where notification is required under applicable law or contractual obligations, we will notify affected customers in accordance with those requirements.

Vulnerability Reporting

If you believe you have identified a security vulnerability, please contact:

SellerRoot Private Limited

Email: contact@sellerroot.com

Please provide sufficient information for us to understand and investigate the issue.

Security Questions

For security, privacy, or compliance questions:

SellerRoot Private Limited

Email: contact@sellerroot.com