Privacy

Privacy policy

This policy covers the website uptova.com and the application app.uptova.com. It describes which data we process, why, for how long, who receives it and which rights you have.

Last updated: 15 September 2026

1. Controller

Hachim Benddane, trading as Uptova, Lewishamstraße 7, 10629 Berlin, Germany. E-mail: contact@uptova.com (subject "Privacy").

2. Website visitors

  • Server logs: when you open a page, our hosting provider (Vercel) processes your IP address, browser type, requested URL and time for security and error diagnosis, for up to 30 days. Legal basis: our legitimate interest in a secure website (Art. 6(1)(f) GDPR).
  • Web analytics: we use Vercel Web Analytics, which counts page views and anonymous interaction events (for example which button was used) without cookies, without cross-site tracking and without storing your IP address. Legal basis: Art. 6(1)(f) GDPR.
  • Language preference: a cookie named uptova-language and a local-storage entry remember the language you chose. They contain no personal data and are strictly necessary for the language you selected (§ 25(2) no. 2 TDDDG). We set no advertising cookies and therefore show no consent banner.
  • Agency enquiry form: if you request managed PPC, we store name, e-mail, brand, website, target regions, revenue band, advertising budget band, goal, the language you used and the campaign parameters of the link you arrived from, in order to answer your enquiry (Art. 6(1)(b) GDPR, pre-contractual steps). Enquiries are stored in a dedicated database project separate from the application. Appointment booking loads Calendly only after you submit the form and choose to book; Calendly processes the data you enter there under its own privacy policy and may set its own cookies.
  • E-mails you send us are received through Cloudflare Email Routing and stored in our mailbox for as long as needed to handle your request. Legal basis: Art. 6(1)(b) GDPR for requests relating to a contract, otherwise Art. 6(1)(f) GDPR.

3. Application accounts

  • To create an account we process your e-mail address, a password (stored only as a salted hash by our authentication provider), your name, your language and workspace settings and the roles you assign to team members. Your Amazon password is never requested or stored. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Your e-mail address and a password are required to open an account; all other details are optional.
  • The sign-in form is protected by Cloudflare Turnstile, which processes your IP address and browser signals to detect bots (Art. 6(1)(f) GDPR).
  • Activity log: for signed-in users we record session metadata, page paths, sign-ins and selected administrative actions with IP address and user agent to detect abuse and to audit administrative actions. IP addresses are removed after 7 days, events after 30 days and session metadata after 12 months. No keystrokes, form contents or mouse movements are recorded. You can inspect, export and delete your own activity data in the application (Settings › My data).
  • Optional connections (for example Google Sheets export) are established only when you activate them and can be revoked in the application at any time.

4. Amazon information

When you authorise Uptova through Login with Amazon or the Selling Partner API authorisation flow, Amazon issues Uptova an access token for your account. Using it, Uptova retrieves:

  • advertising data from the Amazon Ads API: campaigns, ad groups, keywords and targets, search-term reports, bids, budgets, performance metrics and, where Amazon enables it, Amazon Marketing Stream signals;
  • selling partner data from the Selling Partner API: orders without any buyer personal data, catalogue attributes of your products, inventory, prices, fees, refunds and promotions, sales and traffic per product, and the Brand Analytics reports described on our Amazon data and analytics page where your brand is enrolled in Brand Registry.
  • Purpose: to provide the service you subscribed to — dashboards, profitability and rank analyses, recommendations, and the changes you approve. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
  • We request no restricted Selling Partner API roles and receive no buyer personal data (no names, addresses, e-mail addresses, phone numbers or payment data).
  • Uptova writes to your accounts solely for changes you approve — individually, or through automation rules and listing tests you start within the limits you set: advertising changes through the Amazon Ads API, and listing content updates through the Selling Partner API Listings Items API (Product Listing role). Everything else is read.
  • Amazon information is processed only within the account of the selling partner who authorised Uptova. We do not aggregate it across selling partners' businesses or customers, do not sell it, pass it only to the processors listed in section 6 and never to other selling partners, and do not publish or share insights about Amazon's business. Our use follows Amazon's Acceptable Use Policy and Data Protection Policy.
  • Amazon authorisations are stored server-side. During the account-connection step they pass through your browser only as an encrypted, time-limited blob that your browser cannot read. Disconnecting Amazon in the application deletes the stored authorisation.

5. AI-assisted features

If you use an AI feature (AI Cockpit answers, listing text suggestions, search-term briefings, product image editing), the text you enter, the product data and the account metrics selected for that request are transmitted to the model provider that answers the request: Magica (an API relay to Anthropic Claude and Google Gemini models), Google (Gemini API) or xAI (Grok API). Product image editing uses 1min.ai, Google (Gemini API) or OpenAI, or Higgsfield if you connect your own Higgsfield account. No buyer data and no raw Amazon reports are transmitted; only the fields needed for the request. AI outputs are labelled as suggestions and never change your Amazon account without your approval. Legal basis: Art. 6(1)(b) GDPR.

6. Recipients and processors

We use the following providers under data processing agreements: Supabase (database, authentication, server functions — application project in the EU, Frankfurt region; a separate project for agency enquiries); Vercel (web hosting and web analytics — EU and US); Cloudflare (DNS, e-mail routing, bot protection — global network); Resend (transactional e-mails such as sign-in links and reports); Sentry (error monitoring of the application); the AI model providers named in section 5 (only when you use an AI feature); Calendly (only if you book a call); our mailbox provider (Google). Optional connections you activate yourself with your own account (for example Google Sheets or Slack) are governed by those providers’ terms and their data is stored separately from Selling Partner API data. Active Uptova Amazon workflows use only official Amazon sources; external services that vend information retrieved from Amazon websites are disabled. Amazon receives the API requests made on your behalf. We do not sell personal data or Amazon information. A data processing agreement for customers is available on request.

7. International transfers

Where a provider processes data outside the European Economic Area (Vercel, Cloudflare, Google, OpenAI, xAI, Magica, 1min.ai, Higgsfield, Resend, Sentry and Calendly), transfers rely on the EU Standard Contractual Clauses or an adequacy decision (EU-US Data Privacy Framework where the provider is certified). A copy of the clauses is available on request at contact@uptova.com.

8. Retention and deletion

  • When you disconnect Amazon in the application, the stored authorisation is deleted immediately and every sync for that account stops. Amazon information and everything derived from it is deleted no later than 30 days after you close your account or ask us to delete it at contact@uptova.com, subject "Privacy".
  • Account data is deleted when you close your account, unless statutory retention applies (invoices and accounting records: 8 years under § 147 AO and § 14b UStG).
  • Enquiry data is deleted 12 months after the last contact. Server logs are deleted after 30 days at the latest.

9. Security

Transport encryption (TLS) everywhere; per-account isolation enforced by row-level security in the database; encryption at rest by our infrastructure providers; least-privilege access; secrets kept out of source control and checked by automated scans; a written incident response plan with named roles, reviewed twice a year. A security incident affecting Amazon information is reported to Amazon within 24 hours of detection, and affected customers are informed without undue delay. Security contact: contact@uptova.com, subject "Security".

10. Your rights

You have the right to access, rectify, erase and export your personal data, to restrict its processing and to withdraw consent at any time with effect for the future. Write to contact@uptova.com, subject "Privacy". You may also lodge a complaint with a supervisory authority; the authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.

11. Right to object (Art. 21 GDPR)

You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms.

12. Minors and changes

Uptova is a business service and is not directed at persons under 18. We update this policy when our services or the law change; the date above shows the current version.