← Back to Circes

Privacy Policy

Last updated: June 24, 2026

Who We Are

Circes ("we", "our", "us") is a managed Amazon brand-management service. Sellers engage Circes to manage their Amazon advertising, inventory, pricing, and listings on their behalf — Circes is not a self-serve software product. This Privacy Policy explains what information we collect, how we use it, and how we protect it.

Information We Collect

Prospect and contact information, provided through our website forms: name, email, brand name, company website, revenue range, ad spend range, and current tools.

Amazon account data, accessed under OAuth authorization granted by the seller through Amazon Seller Central: catalog and listing data, inventory and fulfillment data, sales and order data, advertising performance and search-term data, and Amazon Brand Analytics data including Search Query Performance (SQP).

Website usage data: standard analytics (pages visited, referrer, device type). We do not engage in cross-site tracking and do not sell visitor data.

How We Use Your Information

Prospect and contact information is used to qualify prospective engagements and communicate with prospects and clients.

Amazon account data is used solely to manage the authenticated seller's Amazon operations under their engagement with Circes — for example, optimizing campaigns, reviewing inventory, recommending listing changes, and producing the weekly performance report. We do not use seller data for marketing, lead generation, advertising, or any purpose outside the seller's engagement.

We measure the internal performance of our own system (e.g., which recommendation types succeed across applied actions) to improve operator decisions. Internal performance measurement never exposes one seller's data, account, brand, or queries to another.

Amazon Brand Analytics & Selling Partner API Data

Circes accesses Amazon Brand Analytics and Selling Partner API (SP-API) data only under explicit OAuth authorization granted by the seller through Amazon Seller Central.

Data we access

Data we do NOT access

Circes does not request or process customer-identifying data from SP-API. We do not access buyer names, buyer email addresses, buyer phone numbers, buyer shipping addresses, buyer order details, customer reviews tied to individual reviewers, or any other field that could identify an individual Amazon customer.

Our SP-API OAuth scope is limited to operational metrics, catalog data, advertising data, and aggregate marketplace data. We do not request the Buyer Information role or any other SP-API scope that exposes customer personally identifiable information (PII).

Scope of use. We use this data solely to manage the authenticated seller's Amazon operations under their service agreement with Circes. We do not share Brand Analytics or SP-API data with any party other than the sub-processors listed below, do not aggregate or anonymize it across sellers, do not resell it, and do not use one seller's data to inform another seller's account.

Compliance. Our use of Amazon data complies with the Amazon Marketplace Web Service Acceptable Use Policy, including the data-handling, customer-protection, and permitted-use requirements in sections 4.4 and 4.5.

Sub-processors

We use the following sub-processors, each bound by contractual confidentiality and data-protection obligations:

No raw Brand Analytics or SP-API data is shared with any party not listed above.

Data Security & Access Controls

API credentials are encrypted at rest using AES-256-GCM. All data is encrypted in transit using TLS 1.2 or higher. Access to seller data is restricted to the Circes operators assigned to that seller's account and to the internal analytics systems that surface recommendations for those operators. Every action applied to a seller's Amazon account is recorded in an audit log with before/after values and the responsible operator.

Data Retention & Deletion

A seller may revoke Circes's access at any time through Amazon Seller Central, which immediately terminates our API access.

Circes deletes the seller's stored SP-API and Brand Analytics data within thirty (30) days of any of: (a) the seller revoking OAuth access, (b) the end of the engagement, or (c) a written deletion request sent to hello@circes.ai. We may retain limited records — such as invoicing data and audit-log summaries — where required by law or for legitimate accounting purposes.

Your Rights

You may request access to, correction of, or deletion of personal information held by Circes by emailing hello@circes.ai. We respond within thirty (30) days.

Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated to active clients by email before taking effect.

Contact

For privacy or data inquiries: hello@circes.ai