Privacy Policy
Last updated: August 26, 2026
1. Introduction
The OptimalCentral platform is owned and operated by Optimal Inc. ("Optimal," "we," "us," or "our"), a service that helps Amazon sellers audit and optimize their listings and store operations. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at optimalcentral.com or use our services.
By using OptimalCentral, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the service.
2. Information We Collect
Account information. When you create an account, we collect your name, email address, sign-in identifiers, and payment information (processed securely by Stripe — we do not store full card numbers). Throughout this policy, "account information" means this information about you as the account holder — it is distinct from the Amazon business data described below.
Amazon seller data. To provide our service, you may authorize us — through Login with Amazon and the Amazon Selling Partner API — to access data associated with your Amazon Seller account, including product listing content, ASINs and catalog information, pricing data, inventory levels, order data, financial and sales reports, traffic and conversion metrics, and account-level details about the seller account itself — the marketplaces it is registered in and its performance status — which we use to validate the connection and to label your reports with the right marketplace. We do not access or store buyer names, email addresses, or other buyer contact information, and we do not contact your buyers. We access only the data necessary to provide the features you use, such as listing audits, operations dashboards, and performance reporting. Some of this data can also reach us as push notifications: on plans that include alerting, we subscribe to Amazon's notification service so that a change in your account — for example an offer change, a change in your account’s status, or a change in FBA inventory availability — is delivered to us as an event; these subscriptions deliver data about your account and change nothing in it; when you disconnect, we stop processing pushed events about your account, and the underlying subscription is deleted once no connected account uses it. Two features write back, and both require your approval before anything is submitted: if you approve a listing fix field by field, we submit the text you approved to that listing through the Selling Partner API; and if you approve a price change in the Repricer, we submit that one price for that one SKU. In both cases we keep the previous values with the change so you can restore them in one action, and neither runs on its own — a price is only ever submitted after you approve that specific price, one SKU at a time. Prices stay in that marketplace’s own currency; we never convert between marketplaces. We make no other change to your Seller Central account — not to your inventory, and not to your orders.
Messages to your buyers. Two tools in our product — Auto Review Request and Buyer Messages — are built to send Amazon's own review request, and a warranty document you upload, through Amazon's own messaging templates. Neither is active: Amazon has granted our application the authorizations they require, but both tools remain switched off while we complete our own pre-launch checks, so no message can be sent on your behalf today, and the statement above holds. We will update this policy in the same release that switches the tools on. Even then, both tools stay off until you enable them and authorize the exact configuration yourself, and neither exposes buyer names or contact details to us — Amazon addresses and delivers the message. A full list of the Amazon authorizations our application holds is on our Amazon API use page.
Amazon advertising data. If you connect your Amazon Ads account, you authorize us — through the Amazon Ads API — to access your advertising profiles and campaign data, such as campaigns, ad groups, targets, budgets, and performance reports, so that we can provide advertising audit, monitoring, and optimization features. This is a separate authorization from the Selling Partner API connection described above, granted through a different Amazon sign-in and revocable on its own: our Selling Partner API access is used to read your seller data and, where you approve a listing change field by field or approve a price change in the Repricer for a single SKU, to submit that change back to your listing; no advertising feature writes anything through it. That advertising authorization also lets us submit changes back to your advertising account — for example bid or budget adjustments, negative keywords, or pausing a campaign. We do this only under the approval rules described in the "Automated Changes to Your Amazon Advertising Account" section of our Terms of Service. Authorization tokens are stored encrypted, and you can disconnect at any time from within the service; disconnecting stops all automation immediately.
Amazon Marketing Cloud data. If your Amazon account has an Amazon Marketing Cloud (AMC) instance and your plan includes AMC Insights, you authorize us to run a fixed set of pre-written analytical queries against your own AMC instance and to store their results — for example new-to-brand share, ad product overlap, impression frequency, and search terms that received impressions but no conversions. AMC returns aggregated, privacy-protected outputs; we do not receive or store records about individual shoppers.
Usage data. We automatically collect information about how you interact with the service, including pages visited, features used, browser type, IP address, and timestamps. If you reach the site through a tagged marketing link — for example an app store listing or an advertisement — we also record which link it was, so we can tell which channels bring sellers to us. This data is used to improve the product and diagnose issues.
Communications. If you contact us via email or our support form, we retain those communications to help us respond and improve our service.
3. How We Use Your Information
- To provide, operate, and maintain the OptimalCentral service
- To generate your listing audits, scores, and optimization recommendations
- To process payments and manage your subscription
- To send transactional emails (receipts, trial reminders, service updates)
- To respond to support requests and communications
- To monitor and analyze usage trends to improve the service
- To detect, prevent, and address fraud or technical issues
We do not sell your personal information to third parties.
4. Sharing Your Information
We do not sell your information or disclose it to any third party for that party's own purposes. We share information only with the following service providers, solely so they can perform services on our behalf:
- Railway — cloud infrastructure; application and database hosting
- Cloudflare — network security, including web application firewall and TLS
- Anthropic — AI processing; listing content is processed transiently to generate audit results and recommendations, and is not used to train AI models
- Stripe — payment processing
- Resend — transactional email (receipts and notifications)
- Sentry — error monitoring, configured to exclude seller data from error reports
- Google — sign-in with Google (authentication only) and aggregated website usage analytics
These providers are contractually obligated to protect your information and may only use it to perform services on our behalf. We may also disclose information if required by law, court order, or to protect our rights or the safety of others.
5. Data Retention
We retain your account data for as long as your account is active or as needed to provide the service.
Deleting your account. You can delete your account yourself at any time from your account settings. Deletion is immediate and irreversible: it cancels any active subscription and removes your account together with the data keyed to it — audits, trackers, reports, stored analysis results, and any connection credentials.
If you cancel without deleting. Cancelling a subscription leaves your account and its history in place so you can come back to it. We delete or anonymize the account information in an inactive account within 90 days of cancellation, and we email you in advance so you can keep the account by signing back in. This does not apply where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements). Data obtained through Amazon's APIs is additionally subject to the limits in Section 6.
6. Amazon Selling Partner and Advertising Data
Data we retrieve through the Amazon Selling Partner API, the Amazon Ads API, or Amazon Marketing Cloud under your authorization is subject to additional safeguards:
- It is used solely to provide the features of the service to you, the authorizing seller. We do not sell it, share it with other sellers, aggregate it across accounts, or use it for advertising. The one exception is marketplace-level data that Amazon publishes in the same form to any authorized caller rather than about any one account — for example, Amazon's top-search-terms table, and Amazon's own aggregated summaries of the public customer reviews on a product or a product category. That data describes the marketplace, a catalogue listing, or a category as a whole rather than any individual seller account, and we may retrieve it under a single authorized connection and use it to provide market-context features to all customers. Data specific to your account is never handled this way.
- It is encrypted in transit and at rest, and access credentials (including authorization tokens) are stored encrypted.
- You may revoke our access at any time from your Amazon account, or by disconnecting from within OptimalCentral. Disconnecting immediately deletes the stored authorization tokens for that connection and freezes every automation that depends on it.
- Your own AI assistant (MCP). If you connect an AI assistant of your choice to your OptimalCentral account through our MCP endpoint, the data that assistant requests under your authorization — which can include data we retrieved for you through Amazon's APIs — is returned to that assistant. The assistant is chosen and operated by you, not by us; it receives only what it requests on your behalf, nothing is ever pushed to it, and you can revoke its access at any time from your account settings. What that assistant's provider does with data you send it is governed by your agreement with that provider.
- Selling Partner API data. Once you revoke authorization, close your account, or otherwise remove our access, we delete the associated Selling Partner API data within 30 days, except where retention is required by law.
- Advertising and AMC data. Reports and analysis results already produced for you stay in your account after you disconnect, so that disconnecting does not destroy your own history. They are removed when you delete your account, and we will delete them sooner on request — write to [email protected] and we will do so within 30 days.
- Our handling of this data complies with the Amazon Selling Partner API Data Protection Policy and Acceptable Use Policy, and with applicable Amazon Ads API data policies.
7. Security
We implement commercially reasonable technical and organizational measures to protect your data, including encrypted data transmission (HTTPS/TLS), encryption of stored credentials, access controls, and automatic lockout of an account after repeated failed sign-in attempts. Our software dependencies are scanned for known vulnerabilities at least every 30 days, and service credentials are rotated on a fixed schedule. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
8. Cookies
We use essential cookies to keep you logged in and to maintain session state. We may also use analytics cookies to understand how users navigate the service. You can disable cookies in your browser settings, but some features may not function correctly as a result.
9. Your Rights
Your account information is personal information (also called personal data) under privacy laws such as the GDPR and the CCPA. Depending on your location, you may have the right to:
- Access the account information we hold about you
- Request correction of inaccurate information
- Request deletion of your account information — you can also delete your account and its data yourself, at any time, from your account settings
- Ask us to restrict or stop processing your account information, or object to a particular use of it
- Withdraw an authorization you have given us, including access to your Amazon accounts
- Opt out of marketing communications at any time
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. Children's Privacy
OptimalCentral is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us personal information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
12. Browser Extension
The Optimal Chrome extension reads the Amazon product page you are currently viewing to run listing checks locally in your browser. Page content is analyzed on your device and is not transmitted to our servers. When you use a tool action, only the product identifier (ASIN) is sent to your Optimal account. The extension does not collect your browsing history and only operates on Amazon product pages.
13. Contact Us
If you have questions about this Privacy Policy, please contact us at:
[email protected]
Optimal Inc.