1. Scope and roles
This notice applies to munchellollc.com and Munchello Commerce Control, an invitation-only service operated by Munchello LLC. For website administration, security, and direct business communications, Munchello acts as a data controller. When an authorized business connects its Amazon account, that business controls its account data and Munchello processes that data only to provide the authorized service.
The platform does not sell personal information or Amazon data, expose one customer’s data to another, use connected-account data for behavioral advertising, generalized benchmarking, cross-tenant product improvement, or training any Munchello or third-party AI model.
2. Information we may process
Website and account information
Business and administrator name, work email, role, support communications, authorization status, IP address, device/browser information, and security or audit events.
Amazon Ads data
Authorized advertiser profiles, portfolios, campaigns, ad groups, ads, targeting, keywords, search terms, placements, budgets, bids, creative metadata, impressions, clicks, spend, attributed orders, attributed sales, and related reporting.
Seller and economics data
If separately authorized through Amazon Selling Partner API, the non-restricted analytics service may process catalog/listing metadata, inventory and fulfillment status, non-PII order metrics, returns/refunds, fees, settlements, and owner-supplied costs or expenses. Munchello does not request restricted SP-API roles, buyer contact details, or other restricted buyer PII.
Credentials
Amazon access and refresh tokens are credentials used to maintain an authorized connection. Production tokens are encrypted and isolated from analysis agents; passwords are never requested or stored by Munchello.
3. Sources and purposes
We receive data from the authorized business, Amazon APIs after owner consent, and the operation of our website and service. We use connected-account data only to authenticate users; connect and synchronize the authorized account; display its performance and profitability; detect data-quality, waste, and opportunity signals; prepare that account owner’s reviewable recommendations; enforce that owner’s budgets and policies; keep required audit records; provide authorized support; and meet legal obligations. Reliability improvements use technical telemetry and synthetic or mock data—not one tenant’s Amazon data for another tenant’s benefit.
4. Service providers and AI
We disclose only the information reasonably needed to infrastructure and communications providers listed on our Subprocessors page, or to Amazon to operate the authorized integration. Human access is limited to authorized support or security personnel with a documented need. We may also disclose information when legally required or in a corporate transaction subject to appropriate protections.
No external AI system receives connected Amazon data by default. Before enabling an AI provider for live account analysis, Munchello will verify contractual confidentiality, no-training, retention, and security terms; minimize the fields sent; update the subprocessor list; and obtain the connected business’s written authorization.
5. Isolation and security
Munchello’s production architecture is designed to separate each legal entity’s Amazon authorizations, data stores, encryption boundary, rules, and audit history. Analysis agents are intended to receive limited read/propose access only; they do not receive Amazon secrets or unilateral approval/execution permissions. Production account access will not be activated until the applicable security controls and review gates are implemented. See our Security page.
6. Retention and deletion
The service enforces a documented schedule. Short-lived OAuth state is kept only long enough to complete authorization; access tokens expire according to Amazon’s schedule; refresh credentials are destroyed promptly after verified revocation; raw reporting data is kept for no more than 90 days while an account is active; and normalized business metrics remain only while needed for the authorized service. After a verified deletion request, primary-store connected-account data is deleted within 14 days and remaining backup copies expire within 30 days of the request.
De-linked security evidence without Amazon payloads or reversible account identifiers may be kept up to 12 months to demonstrate access revocation and protect the service. An authorized owner may request disconnection and deletion as described on our Data Deletion page. Narrowly limited legal-hold records may be preserved only where law requires it.
7. Cookies and website analytics
This public information website currently uses only technical features required to deliver the pages securely. It does not use advertising cookies or cross-site behavioral tracking. If analytics or additional cookies are added, this notice and any required consent controls will be updated before use.
8. Choices and rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, or a copy of personal information. An Amazon account owner can revoke the application’s authorization in Amazon at any time. Submit requests to amazon-api@munchellollc.com. We will verify the requester’s authority before acting on connected-account data.
9. International processing and safeguards
Munchello is a United States operator. Providers may process technical or service data in the United States and other countries where they operate. Before a production Amazon connection is activated, the required data-processing agreement will identify the applicable primary storage region, providers, transfer safeguards, and authorized account scope.
10. Changes and contact
We may update this notice as the private beta, data scope, or legal requirements change. The date at the top identifies the current version. Material changes affecting connected-account data will be communicated to authorized administrators.
Privacy contact: Munchello LLC, amazon-api@munchellollc.com.