Privacy Policy
Overview
Rufusly is an AI-powered content and intelligence platform for Amazon and Shopify sellers (“Rufusly”, “we”, “us”, “our”). This Privacy Policy explains how we collect, use, store, and protect information when you use our platform at rufusly.ai.
We are committed to handling your data responsibly. We collect only what is necessary to provide our service, we never sell your personal data, and we never use your Amazon seller data to compete with you or share it with other sellers.
Key point on Amazon data: When you connect your Amazon account, we access your selling data solely to generate AI-optimised content and business intelligence for your own use. We request the minimum permissions required, and you can revoke our access at any time from your Amazon Seller Central account.
Data we collect
Account and profile data
When you create a Rufusly account we collect:
- Name and email address
- Password (hashed, never stored in plain text)
- Business name and type (optional, used to personalise outputs)
- Billing address (collected by Stripe, not stored on our servers)
Usage data
When you use the platform we collect:
- Features used, pages visited, and actions taken within the product
- Listing rewrites, image generations, and other job outputs you create
- Credit usage and subscription activity
- Error logs and performance data for debugging
Brand profile data
Brand profiles you create in Rufusly (brand name, product name, accent colours, key claims, target customer, certifications) are stored to personalise your AI-generated content. You can delete brand profiles at any time from your account settings.
Technical data
We collect standard web server logs including IP addresses, browser type, and device type. This data is used for security, fraud prevention, and aggregate analytics only.
Amazon account data
Rufusly offers a direct Amazon Selling Partner API (SP-API) connection. This access begins only after you complete a separate, explicit consent step (Amazon's own authorisation flow), not automatically from having a Rufusly account. If you never connect your Amazon account, Rufusly works from the product photos and information you upload directly and does not pull data from your Seller Central account.
Connecting your Amazon account via SP-API works as follows:
What access we request
| API scope | What we access | Why we need it |
|---|---|---|
| Product Listing | Your existing listing content (title, bullets, description), product type attribute schema | To generate AI-optimised rewrites and identify missing required attributes |
| Inventory and Order Management | Active SKUs, FBA stock levels, order counts, sales velocity | To power the bulk attribute editor, inventory risk alerts, and sales trend analysis |
| Brand Analytics / Selling Partner Insights | Search query performance, customer feedback topic summaries, Selling Partner ID and marketplace IDs | To provide keyword intelligence, surface review themes, and identify your account and marketplace |
| Finance and Accounting | Settlement data, fee summaries, reimbursement reports | To calculate profitability and surface unclaimed FBA reimbursements |
| Buyer Solicitation | Order IDs eligible for a review request (no buyer name, email, or contact details) | To submit Amazon-templated review request emails on your behalf, entirely through Amazon's own Solicitations API |
| Buyer Communication, Pricing | Messaging and pricing data tied to your listings | Reserved for related features; not yet active in the product |
Amazon Advertising (when released). If you connect your Amazon advertising account to our advertising manager once it is released, we will store the authorisation token Amazon issues for it (valid for up to a year from the date you consent), your advertising profile identifiers, and reports on the campaigns, targets, spend and sales of your own account, including campaigns Rufusly sets up on your behalf for products you chose. We will also store the plan you set (the products you chose to advertise, the starting daily budget you confirmed for each, the cost of sale you aim for, your daily spending ceiling if you set one, and how much Rufusly may do) and a log of every change proposed or applied. This is a separate authorisation from SP-API and is not covered by the roles in the table above. You can withdraw it at any time from the Login with Amazon settings on your Amazon account, from within Rufusly, or by contacting us, and the token is deleted when you disconnect or delete your account.
How we will handle Amazon data
- Writes only with your approval. We read your Amazon data automatically to power the dashboard, keyword intelligence, and reimbursement alerts. We only ever write back to your Amazon account (publishing a listing change, or submitting review request emails) when you explicitly review and approve that specific action. We do not place orders or take any action you have not specifically requested. When our advertising manager is released, Rufusly will set up and run Sponsored Products advertising, and add or archive keywords, only inside a plan you set for products you chose, as described under Advertising plans in our Terms, and every change will be recorded.
- No buyer contact data passes through us. Review request emails are submitted directly through Amazon's own Solicitations API using only the order ID. Rufusly never sees, stores, or processes the buyer's name, email address, or other contact details.
- No data sharing with other sellers. Your Amazon selling data is never shared with, sold to, or made accessible to other Rufusly users or third parties.
- No competitive use. We do not use your Amazon data to inform product decisions for competing sellers, or to build competitive intelligence products.
- Data minimisation. We sync only the data required to provide the specific features you use.
- Revoke at any time. You can revoke Rufusly's access through Amazon Seller Central → Apps & Services → Manage Your Apps, or by contacting us directly.
Amazon relationship disclaimer: Rufusly is an independent service provider. We are not affiliated with, endorsed by, or sponsored by Amazon.com, Inc. or its affiliates. Amazon is not responsible for Rufusly's services.
How we use your data
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing and operating the Rufusly service | Contractual necessity |
| Generating AI listing rewrites and product images | Contractual necessity |
| Processing subscription payments via Stripe | Contractual necessity |
| Sending transactional emails (receipts, alerts) | Contractual necessity |
| Improving product features (we do not train AI models on your content) | Legitimate interests |
| Product analytics, heatmaps and session replay | Consent |
| Measuring which websites, searches and campaigns send visitors to us | Consent |
| Fraud prevention and security | Legitimate interests |
| Sending product update emails (opt-out available) | Legitimate interests / consent |
| Complying with legal obligations | Legal obligation |
We do not sell your personal data. We do not use your data for advertising targeting on other platforms. If you submit your email address on our lifetime deal page, we use it only to send you updates about that deal, on the basis of your consent, until you unsubscribe. We also store how you reached the page (a referral code or campaign tag, if any), and we keep unsubscribed addresses only so that we do not email you again.
Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, file storage | User accounts, job outputs, brand profiles |
| Vercel | Application hosting and serverless functions | Request logs, environment variables (no user PII) |
| Vercel AI Gateway | Routes AI requests to model providers with observability | Prompts and product data passed through to the selected model |
| Anthropic (Claude) | AI listing generation and text analysis | Product data and prompts submitted for rewriting, no buyer PII. Not used to train Anthropic's models |
| OpenAI (GPT Image) | AI product image generation | Image prompts and brand profile fields |
| Google (Gemini) | AI listing analysis and content structuring | Product data and prompts submitted for processing |
| fal.ai | AI product image generation and editing | Image prompts and brand profile fields |
| Stripe | Payment processing | Name, email, billing address, payment method tokens |
| Resend | Transactional email delivery and the lifetime deal emails you have asked for | Name, email address, and email content (receipts, alerts, account notices) |
| Canva | Design editing you initiate through the optional Canva connection | Images and design content you choose to send to Canva, and the Canva account token you authorise. Only used when you connect Canva and press an edit or send action |
| PostHog | Product analytics and session replay for the logged-in app, only after you allow analytics | Page views, plan name, a pseudonymous account identifier, which steps of a feature you reached, your IP address and browser and device type, and session recordings with all on-screen text and every image hidden |
| Google Analytics | Which website or campaign sent a visitor to our public website, only after you allow analytics. It does not run inside the logged-in app | Pages viewed on the public website, the link or campaign you arrived from, browser and device type, an approximate location, and a random identifier that lets Google count a returning visitor once rather than twice |
| Microsoft Clarity | Heatmaps and session replay for the website and the logged-in app, only after you allow it | Pages viewed, clicks and scrolling, and session recordings with typed input masked |
If you install the optional CaseFlow AI browser extension, it sends data you can already see in your own Amazon Seller Central session (such as a processing summary or a case form you ask it to fill) to Rufusly, at your request. The extension has its own privacy policy at /privacy/extension.
Where we have enabled PostHog (PostHog Inc., data hosted in the EU) on the logged-in app, it records page views, your plan name, and which steps of a feature you reached, for example that a listing rewrite was started or that you ran out of credits. These are linked to a pseudonymous identifier for your account rather than to your name or email address. It also records session replays, with all on-screen text masked and every image, video and canvas hidden before anything leaves your browser, so a replay shows the shape of the page and what you clicked rather than the words or the pictures on it. Your product photographs are not sent. None of this happens until you allow analytics, and you can withdraw that at any time by emailing hello@rufusly.ai.
Google Analytics (Google Ireland Limited) tells us which website, search or campaign link sent someone to our public website, so we can see which places are worth our effort. It records the pages viewed there, the link or campaign followed, browser and device type, an approximate location, and a random identifier that lets Google count a returning visitor once rather than twice. Google uses your IP address to work out roughly where you are, such as your country and city. Google states that for Google Analytics it does not log or store the IP address itself, and it is never made available to us.
Google Analytics does not run inside the logged-in app. That is deliberate rather than incidental: addresses inside the app can contain a product identifier or a sharing link, and none of that is any of Google’s business. It runs on the public pages only, where the single question it answers is which campaign or community sent a visitor. We do not use it for advertising, and we have not connected it to any advertising account. The script is not added to the page at all until you allow analytics, and withdrawing your permission turns it off and deletes its cookies from that browser.
Microsoft Clarity (Microsoft Corporation) is used on the same basis, across both the website and the logged-in app, to produce heatmaps and session replays of pages viewed, clicks and scrolling, with typed input masked. It only starts once you allow it on the same card, and it stops when you withdraw that permission.
We do not share your data with any third parties beyond those listed above, except where required by law or with your explicit consent.
Storage and security
Your account and job data is stored in the European Union on Supabase infrastructure. All data is encrypted at rest and in transit using TLS 1.2+ encryption.
Some of our third-party processors, including Anthropic, OpenAI, Google, fal.ai, Stripe, Microsoft, Vercel, Resend, and PostHog (whose data we have hosted in the EU, though the company is based in the United States), are based in or transfer data to the United States, and Canva is based in Australia. Where this involves an international transfer of personal data outside the UK, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent recognised safeguard with that processor. For Google Analytics we contract with Google Ireland Limited, which acts as our processor for the measurement itself and, for some limited data, as a controller in its own right under Google’s own measurement terms. For that transfer we rely on Google’s certification under the UK Extension to the EU-US Data Privacy Framework and, where that does not apply, the IDTA in Google’s terms.
- Row-Level Security (RLS) on all database tables, every query is scoped to the authenticated user
- All API keys stored in server-side environment variables, never exposed to the browser
- Product data sent to AI models (Anthropic Claude, OpenAI, Google Gemini, fal.ai) never includes buyer names, emails, or other buyer contact details, and all AI processing happens server-side, never in your browser
- OAuth 2.0 for Amazon account connections, we never store your Amazon password
- Amazon SP-API tokens stored encrypted in our database
- Automatic session expiry and token rotation for Amazon OAuth connections
If you become aware of any security vulnerability, please contact us immediately at security@rufusly.ai.
Incident response
In the event of a data security incident involving your personal data or Amazon account data, we will:
- Investigate and work to contain the incident as promptly as possible, aiming to contain within 4 hours of detection
- Aim to notify affected users by email within 24 hours of confirming a breach
- Where required, notify the ICO within 72 hours of becoming aware of the breach, in line with our obligations under UK GDPR
- Aim to report any incident involving Amazon Selling Partner data to security@amazon.com within 24 hours of detection
- Provide a written summary of the incident, affected data, and remediation steps to affected users
Our incident response plan, including defined roles and responsibilities, is reviewed every six months.
Data retention
We retain your data for as long as your account is active. An account whose free trial has ended is not deleted and has no fixed end date, so to avoid holding data indefinitely on an account nobody is using: if a free account has not been signed in to for 24 months, we will email you at least 30 days before deleting the account and its associated data. Paid accounts are retained for as long as the subscription is active.
When you delete your account:
- Your profile, brand profiles, and listing history are deleted within 30 days
- Amazon SP-API and Amazon Advertising tokens are revoked and deleted immediately
- Generated images and CSV exports are deleted from storage within 30 days
- Billing records are retained for 7 years as required by UK law
- Anonymised, aggregated analytics data may be retained indefinitely. This does not cover analytics events or session replays, which are linked to your account. Those are held by PostHog and Microsoft Clarity for those services’ standard retention periods, and are deleted at the end of that period or when you ask us to delete them, whichever comes first. Google Analytics data is not linked to your account, and Google deletes the underlying event records automatically at the end of the retention period set on our property; the cookies on your device expire after two years, or sooner if you withdraw your permission
You can request immediate deletion of all personal data by emailing hello@rufusly.ai.
Your rights
Under UK GDPR, you have the following rights:
- Right to access: Request a copy of all personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw any consent given at any time
To exercise any of these rights, email hello@rufusly.ai. You also have the right to lodge a complaint with the ICO at ico.org.uk.
Cookies
Rufusly uses these essential cookies, which cannot be turned off:
- Authentication cookie: Keeps you logged in during your session (essential, cannot be disabled)
- Preference cookie: Stores UI preferences such as theme and view settings
We do not use advertising or retargeting cookies, and no advertising pixel runs on this site. Where PostHog analytics is enabled in the logged-in app it stores an identifier in your browser’s local storage rather than a cookie. Nothing is stored there until you allow analytics, and withdrawing your permission clears it. Google Analytics, once you allow analytics, sets two cookies on this site (_ga and _ga_Q4S9F9RNQ2), which distinguish one visitor from another and hold the current visit. Both expire after two years. Withdrawing your permission deletes them from that browser. Microsoft Clarity is different: once you allow analytics, it sets two of its own cookies (_clck and _clsk) to recognise a returning visitor and to group a session together. Nothing is set before you allow it, and withdrawing your permission erases them. See section 5.
Children's privacy
Rufusly is a business tool intended for adults aged 18 and over. We do not knowingly collect personal data from children under 18.
Policy changes
When we make material changes, we will notify you by email and update the “Last updated” date at the top of this page. Continued use of Rufusly after the effective date constitutes acceptance of the updated policy.
Contact us
Rufusly
LUMINOUS EMPORIUM LTD (company number 16201976), 124-128 City Road, London, EC1V 2NX, United Kingdom
Email: hello@rufusly.ai
Security: security@rufusly.ai