Privacy policy
Last updated: August 19, 2026
This policy explains what SellerRestart (“we”) collects, why, how long we keep it, and how to get it deleted. The operator of this service is [legal entity name], [address], contactable at [support@yourdomain.com].
We never ask for your Amazon credentials
We do not request, collect, or store your Amazon username, password, one-time codes, or any other Amazon credential, and we never log in to your Seller Central account. You submit your appeal yourself. If any message claiming to come from us asks for your Amazon login, it did not come from us.
What we store
- The notice you paste or upload, including any screenshot or PDF, and the text extracted from it.
- Your answers to the intake questionnaire and any documents you upload (invoices, authorisations, compliance records, and so on).
- Your email address, which Stripe collects at checkout and passes to us so we can deliver your Plan of Action.
- The generated diagnosis and Plans of Action, including revisions.
- A one-way hash of your IP address and a daily counter, used only to enforce the limit of three free analyses per visitor per day. We do not store raw IP addresses.
- Attribution data — UTM parameters and the referring page from your first visit — so we know which channels bring sellers here.
- Stripe payment metadata (a session identifier and payment status). Card details are handled entirely by Stripe and never reach our servers.
What we do with it
We use it to produce your diagnosis and your Plan of Action, to deliver them to you, to provide the two included revisions, to prevent abuse of the free tier, and to keep the records we need for accounting and support. The lawful basis, where the GDPR applies, is performance of a contract with you, and our legitimate interest in preventing abuse and understanding which marketing channels work.
Who else sees it
We use a small number of processors, and nobody else:
- Anthropic (Claude API) — your notice and intake answers are sent to the model that writes the diagnosis and the Plan of Action.
- Supabase — database and private file storage.
- Vercel — hosting and server logs.
- Stripe — payment processing and your email address at checkout.
- Resend — sending the delivery and access emails.
- Optionally, privacy-friendly analytics and advertising pixels, where the operator has enabled them. These see page views, not your case content.
We do not sell your data, we do not share it with data brokers, and we do not use your notice or your documents to train any model.
Retention
- Uploaded files are kept alongside the case record they belong to. We do not delete them on a schedule, and we will not claim to: they are removed when you ask us to delete your case, and at the same time as the rest of that case’s data. If you would rather not rely on us holding them, download your documents and keep your own copy.
- Case records (notice text, answers, deliverables) are kept while your case is open and for [24] months afterwards, so that a returning seller can still reach a plan they paid for.
- Rate-limit hashes are kept for [30] days.
- Payment records are kept as long as tax and accounting law requires (typically [7] years).
Deletion and your rights
You can ask us to delete your case data at any time by writing to [support@yourdomain.com] from the address you used at checkout. We delete the case, its files and its deliverables within [30] days, keeping only what payment records law requires. Depending on where you live you may also have the right to access, correct, port, or restrict processing of your data, and to complain to your data protection authority. California residents have the rights described in the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information as those terms are defined there.
Access links
Case pages are reached through a private link containing a random token rather than a password. Anyone holding that link can open the case, so treat it like a password and do not forward it.
Cookies
We use a first-party cookie only for the operator’s admin session. Attribution data is kept in your browser’s local storage, not in a cookie. Any analytics or advertising pixels the operator enables set their own cookies under their own policies.
Children
This service is for businesses and is not directed to anyone under 18.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects an open case, tell you by email.