Privacy Policy

Last updated: 14 September 2026

This policy is issued by ME ASPECT LTD (company number 14471480, registered office Unit 10 EDEAL Business Centre, Dittons Park, Dittons Road, Polegate, BN26 6HY), trading as MarginLens. We are the data controller for the personal data described here. MarginLens provides Amazon Seller Central analytics — sales, fees, inventory, advertising spend and profit reporting — for Amazon sellers who connect their own seller account to our app. This policy explains what we collect, why, where it goes, and what you can ask us to do with it. Questions to admin@marginlens.net.

What we collect

When you connect your Amazon Seller Central account through Amazon's own authorisation process, we access:

To run your account we also hold:

What we do not collect

We do not access, request or store your customers' personal data. No buyer names, delivery or billing addresses, phone numbers or email addresses reach MarginLens. We request only the non-personally-identifiable Selling Partner API roles needed for order, financial, fee, inventory and advertising data, and the code that reads orders does not read buyer or shipping fields. The one thing we hold about an order is Amazon's own order number, which identifies the order, not the person.

Why we process it, and our lawful basis

We do not sell, rent or share your data with advertisers or anyone else for marketing. We do not use it to train models.

Where it is stored, and international transfers

MarginLens runs on Google Cloud in europe-west2 (London): our application servers, our database (Google Cloud Firestore) and the store for Amazon authorisation tokens (Google Secret Manager) are all located there, so your seller data is stored in the UK. Google processes that data on our behalf under its Cloud data-processing terms, which incorporate the UK International Data Transfer Addendum to the EU standard contractual clauses for any support or maintenance access from outside the UK.

Stripe (payments) and Amazon (the source of your data) may also process data outside the UK under their own terms; where personal data leaves the UK, those transfers rely on the UK International Data Transfer Agreement or Addendum, or an adequacy decision.

Who we share it with (sub-processors)

ProviderWhat forWhat they see
Amazon Selling Partner API and Ads APIThe source of your seller data, accessed only with your authorisation, which you can revoke at any time in Seller CentralYour seller account identity and the data you authorise
Google Cloud / FirebaseHosting, sign-in, database, token storage and the servers that run the appEverything listed above, as our infrastructure provider
StripeSubscription paymentsYour email, plan and card details (the card details never pass through us)
Google FontsThe typefaces on our pagesYour IP address and browser details when a font file is fetched
Exchange-rate feed (currency-api, served via jsDelivr and Cloudflare Pages)Converting non-sterling orders to poundsNothing about you — our server fetches a public rate table

That is the whole list. We do not use analytics, session recording, error-tracking services or advertising networks.

Cookies

We use only strictly necessary storage: the session that keeps you signed in, and your own display preferences, both held in your browser. We do not use analytics or advertising cookies, and we do not track you across other sites, which is why there is no cookie banner. Stripe sets its own cookies on its checkout pages under its own policy.

How long we keep it

Security

Data is encrypted in transit (TLS) and at rest. Amazon authorisation tokens are stored in Google Secret Manager, separately from the database, and are never written to logs or shown in the app. Each seller's data is kept under its own account and every query is scoped to that account at the database layer, so one seller's data is not reachable from another's session. Access to production is limited to named staff and requires their own credentials. If a security incident affects your data we will tell you without undue delay, and the Information Commissioner's Office within 72 hours where the law requires it.

Your rights

Under UK data protection law you can ask us to:

To exercise any of these, email admin@marginlens.net from the address on your account. We reply within one month. There is no charge. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113 — though we would rather hear from you first.

Your controls in the app

Changes to this policy

If we change what we collect or who we share it with, we will update this page and the date at the top, and tell you in the app if the change matters to you.

Contact

ME ASPECT LTD, trading as MarginLens — admin@marginlens.net