Privacy Policy

Last Updated: August 2026

Limonene, a service operated by Zed Axis ("we", "our", "us"), respects your privacy and is committed to protecting your personal data. This policy explains, in plain language, what data we collect when you visit our website or connect your Amazon seller account, why we collect it, who we share it with, and how to have it deleted.

1. Who We Are

We are the data controller responsible for your personal data. Limonene is operated by Zed Axis, based in Egypt. For any privacy question or request, contact us at [email protected].

2. Compliance with Amazon Data Protection Policy (DPP)

Our services integrate with the Amazon Selling Partner API (SP-API). We strictly adhere to Amazon's Data Protection Policy (DPP) and Acceptable Use Policy (AUP). Our full security posture is mapped to the DPP and AUP section-by-section in an internal POLICIES document, available to Amazon's vetting team or to a security researcher on written request to [email protected].

We do not collect or store buyer Personally Identifiable Information (PII) at rest. Buyer name and city are read from SP-API on demand at the moment a tax invoice is rendered, then discarded as soon as the request returns.

3. The Data We Collect About You

We collect, use, store and transfer the following kinds of data about you:

  • Account Data — your email address (used to sign in via a magic link or Google), and an optional phone number you can add for WhatsApp contact. If you sign in with Google, we receive your basic Google profile: name, email address, and profile picture. We never see or store any password.
  • Identity Data — first name, last name, business name, tax ID (when you use the tax invoicing features).
  • Contact Data — email address, telephone number, optional Telegram chat ID for notifications.
  • Amazon Selling Partner Data — seller IDs, SP-API refresh tokens (AES-256-GCM encrypted at rest with a per-token random IV), inventory summaries, listings and pricing data, FBA shipment and financial events (including refund and adjustment events used for reimbursement detection), inbound shipment plans, and catalog item metadata. All retrieved only with the SP-API roles you explicitly authorize.
  • Order Data — order IDs, purchase dates, ship dates, and item lists, used to compute review eligibility windows and to render tax invoices on demand. Buyer name and city appear transiently in rendered invoice PDFs; they are not written to any database collection.
  • Buyer Message Metadata — read-only display of buyer-seller message threads. Message bodies are fetched fresh on each request and not persisted.
  • Tax Filing Data — if you enable e-invoicing, your credentials for the Egyptian Tax Authority (ETA) or Saudi ZATCA, stored AES-256-GCM encrypted, plus the receipts and invoices we file for you (see section 7).
  • AI Chat Data — the messages you send to the built-in assistant and its replies, kept as your conversation history (see section 5).
  • Usage Data — analytics about how the website and app are used (see section 8).

4. How We Use Your Data

We will only use your data when you authorize it. Specifically:

  • To create and secure your account and sign you in (email magic links or Google sign-in).
  • To compute and display insights (out-of-stock, reimbursements owed, slow movers, Buy Box status) from your SP-API data.
  • To execute the one-click actions you authorize (price changes, removal orders) and to draft the ready-to-paste reimbursement claim messages you file yourself in Seller Central.
  • To notify you (the seller, not your buyers) about your store — see section 6 for channels and opt-out.
  • To occasionally re-engage you by email or WhatsApp if you stop using the service (for example, a reminder of what changed in your store). You can opt out of these messages any time by contacting support.
  • To run a per-seller repricer on listings you have configured rules for, capped at Amazon's 20% per-cycle AI Agent Policy.
  • We never share, sell, or expose your data to other sellers, advertisers, or third parties.

5. AI Processing (the Assistant)

Limonene includes an AI assistant that answers questions about your store. When you chat with it, your messages plus the minimum excerpts of your own store data needed to answer (for example inventory levels, sales figures, prices) are sent to an AI model provider acting as our subprocessor. No buyer personal information is ever sent to AI providers — we do not store any to begin with.

The model providers we use:

  • Anthropic (Claude) — per its commercial API terms, Anthropic does not train its models on API inputs or outputs.
  • Google (Gemini) — we use the paid Gemini API tier, which per Google's terms does not use submitted data to train its models.
  • DeepSeek — DeepSeek's platform terms permit it to use API data to improve its services. For this reason we send DeepSeek only what is strictly needed to answer the question at hand, and you can choose a different model for your chats at any time from the model picker.

Your conversation history is stored on our servers so you can pick up where you left off; delete it by deleting a conversation or requesting account deletion.

6. Notifications

If you connect Telegram, we store your Telegram chat ID and send you messages that contain your own store metrics (for example stock alerts or daily summaries). Email and WhatsApp notifications work the same way when you provide those contact details. All notification channels can be turned off in Settings at any time, and notifications go only to you — never to your buyers.

7. Tax Filing Data (ETA / ZATCA)

If you enable e-invoicing, we store your Egyptian Tax Authority (ETA) or Saudi ZATCA credentials encrypted at rest with AES-256-GCM — the same protection as your Amazon tokens. They are used solely to file the documents you initiate or enable; we never file anything you did not ask for. Copies of filed receipts and invoices are retained so you have a record of what was submitted. Your tax data is transmitted to the relevant government authority only at your instruction.

8. Analytics

We use Google Analytics 4 and our own first-party event tracking to understand how the website and app are used (pages visited, features clicked). This helps us improve the product. We do not sell analytics data or any other data, and we do not use it for third-party advertising.

8a. Your Master Kill Switch

The Settings page includes a one-click "Pause everything" button that immediately halts every background worker touching Amazon on your behalf. We honor it within one worker cycle (≤30 minutes).

9. Data Deletion and Retention

If you terminate your account or revoke SP-API access, we permanently delete all Amazon-sourced data from live systems within 30 days, using deletion methods aligned with NIST SP 800-88. Backups containing your data are purged within 90 days. Non-PII analytics data is retained for up to 18 months. To delete your account data (email, phone, chat history, tax credentials) or request immediate deletion of anything else, contact support at [email protected].

10. Subprocessors

The third parties involved in operating Limonene are:

  • DigitalOcean — droplet hosting and the underlying MongoDB instance.
  • Let's Encrypt — TLS certificate issuance.
  • Telegram Bot API — only used to deliver operator-configured alerts to the seller's own Telegram. No Amazon-sourced data is sent except the seller's own alert text.
  • Anthropic, Google (Gemini), DeepSeek — AI model providers for the assistant, as described in section 5.
  • Google (sign-in & Analytics) — optional Google sign-in and Google Analytics 4 as described in sections 3 and 8.
  • Zoho Mail — transactional email delivery (sign-in links and service notifications).

The Egyptian Tax Authority and Saudi ZATCA are government bodies, not subprocessors — your tax documents are transmitted to them only at your instruction (section 7). No other party receives Amazon-sourced data. We do not sell, share, or aggregate data across sellers. We do not target Amazon customers for marketing and do not fabricate or modify reviews.

11. Security and Incident Response

Our Incident Management Point of Contact is the founder, Mohamed Abouzid ([email protected]). Security incidents affecting Amazon-sourced data are reported to [email protected] within 24 hours of detection. Every write action that crosses the SP-API boundary on your behalf is recorded in an internal audit log retained for at least 12 months.