Legal

Privacy Policy

Last Updated: September 3, 2026

1. Introduction

1.1

This Privacy Policy describes how VNash Digital Pvt Ltd (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information in connection with the Sapyon AI web application and related services (the “Service”), currently offered at https://app.sapyon.com.

1.2

Sapyon AI is a business software application for managing retail advertising and related retail operations. It allows authorized users to connect advertising and retail platform accounts, view and act on campaign and performance data, configure automations and schedules, and use an in-product chat assistant.

1.3

By accessing or using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.

2. Who We Are

2.1

The Service is operated by:

VNash Digital Pvt Ltd
Bangalore, India
Privacy inquiries: [email protected]
General contact: [email protected]

2.2

The product name displayed in the Service is Sapyon AI. The product tagline displayed in the Service is Retail Ops. The production hostname referenced in the application documentation is app.sapyon.com.

2.3

Dual role. We act in two capacities:

  • (a) Controller of Personal Data relating to accounts used to sign in to Sapyon AI (for example, email address, authentication credentials or Google account identifiers, role and permission assignments, and Service usage associated with that account).
  • (b) Processor of Personal Data and other data that a Customer (the business that uses the Service) causes to be processed through connected advertising and retail platforms and through features the Customer configures (for example, Amazon Advertising profiles, campaign and keyword data, reports, automations, chat threads about those accounts, and Seller/Vendor retail data). That processing is described further in our Data Processing Agreement (“DPA”).

2.4

If you use the Service on behalf of a business, that business is typically the Customer. Your administrator may grant or revoke your access to specific advertising profiles.

3. Scope

3.1

This Policy applies to Personal Data processed through the Service, including:

  • (a) the sign-in and account management surfaces (/login, /signup, /settings, /login/oauth/callback);
  • (b) Connections, Accounts, Dashboard, Workspace, campaign management, budget rules, automations, recommendations, daily spend, dayparting (stream insights), Chat, Audience (Amazon Marketing Cloud), and Retail features;
  • (c) administrator surfaces (/admin/users, /admin/account-metrics, /admin/report-coverage, /admin/stream-subscriptions, /admin/settings, /admin/retail/:credentialId), where a user has the required role or permission.

3.2

This Policy does not apply to:

  • (a) Amazon, Google, Flipkart, or other third-party platforms that you connect or use to sign in, which have their own privacy policies;
  • (b) websites or services that we do not operate, even if linked from the Service;
  • (c) employment or vendor contracting processes that are not part of the Sapyon AI application.

3.3

The Service is a business (B2B) application. It is not directed to consumers acting in a purely personal capacity, except to the extent an individual creates an app account.

4. Information We Collect

4.1 Information You Provide

We collect information you submit in the Service, including:

  • (a) Sign-up and sign-in. Email address and password (password must be at least eight (8) characters). Alternatively, you may choose “Continue with Google,” in which case we receive an authorization code that our backend exchanges for a session.
  • (b) Password changes. Current password and new password, submitted to POST /api/v1/auth/change-password. Demo accounts cannot change passwords in Settings.
  • (c) Chat. Message content you send in Chat threads, optional thread titles, and your browser timezone sent with messages. Chat may produce assistant replies and action proposals (for example, proposed bid, budget, status, or negative-keyword changes) that you can confirm, reject, edit, or undo where the Service permits.
  • (d) Automation and dayparting configuration. Rule names, entity types, conditions, schedules, timezones, frequencies, execution hours, weekly days, start/end dates, campaign or portfolio scope, term-list names and entries (blacklist or whitelist terms), and hourly-budget / dayparting schedules (including time windows, multipliers, and IST-based schedule configuration as presented in the Service).
  • (e) Audience (AMC). Audience name, description, SQL query text (including templates such as cart-adders or search-term queries, or custom SQL), advertiser type, time windows, lookback days, and refresh-rate settings.
  • (f) Bid snapshots. Optional snapshot name and note.
  • (g) Campaign creation and edits. Campaign, ad group, product, keyword, targeting, negative targeting, bidding, budget, and related fields you enter when creating or editing Sponsored Products (SP), Sponsored Brands (SB), or Sponsored Display (SD) entities.
  • (h) Daily spend. A daily budget value you save for a profile.
  • (i) Administrator actions. When a super admin or a user with admin.users.read (and related write APIs) creates or updates users: email, password, global role (super_admin or account_owner), profile grants, and active/deactivated status.
  • (j) Seller/Vendor self-authorization. Super admins may paste a Vendor self-authorized refresh token and related fields (region, marketplace id, selling partner id, display name) into Admin settings. That token is transmitted to our backend and is not intended to remain in the browser after submission.
  • (k) Support and other communications you send to [email protected].

We do not collect a legal name, phone number, or billing address as account fields. Connection “display names” and advertising account names typically come from connected platforms.

4.2 Account Information

For each app user, the Service stores and retrieves an account record that includes:

  • (a) user id;
  • (b) email address;
  • (c) whether the account is a demo account (is_demo);
  • (d) whether the account is active (is_active);
  • (e) global roles (including super_admin);
  • (f) permission codes (including, as used in the application, admin.users.read, profiles.write, automation.write, and automation.execute);
  • (g) accessible advertising profile ids (accessible_profile_ids);
  • (h) authentication secrets handled by the backend (password credentials for email/password users; Google subject identifier google_sub for Google sign-in users). Passwords are not stored in the browser except while you type them into a form.

Session tokens: after sign-in, the browser stores in localStorage under the key amz_app_session an access token, an optional refresh token, and a copy of the user object. API requests send Authorization: Bearer <access_token>. Signing out removes this item from localStorage on the device.

4.3 Business Information

When you or your administrator connect platforms and use advertising or retail features, we process business and advertising data associated with those connections. This is primarily Customer Data processed on the Customer’s behalf. It includes:

  • (a) Amazon Advertising (Login with Amazon / LWA). Connection identifiers, manager account ids, display names, OAuth scopes, consent and expiry timestamps, health/status, linked advertising profile ids, and related alerts.
  • (b) Advertising profiles and catalog. Profile ids, account names, manager account names, country codes, marketplace identifiers, enablement/setup status, sync status, last sync times, and last errors.
  • (c) Campaigns and entities. Portfolios, campaigns, ad groups, product ads, keywords, product targets, negative keywords, negative targets, brands, ASINs/SKUs, eligibility and product metadata, budgets, states (enabled/paused/archived), bids, placement adjustments, and related Amazon entity identifiers.
  • (d) Reports and performance metrics. Report rows and summaries for campaigns, keywords, targets, search terms, placements, match types, targeting types, daily spend, budget usage, and date-range comparisons, including metrics such as spend, sales, impressions, clicks, and related derived metrics displayed in Dashboard, Workspace, Reports, Compare, and Recommendations.
  • (e) Amazon Ads streams / dayparting. Stream health, summary and row data, heatmaps (including timezone), budget-usage stream data, and stream subscription identifiers, dataset ids, destination ARNs, queue URLs, client request tokens, notes, realm, and AWS region fields used by administrators to manage stream subscriptions.
  • (f) Amazon Marketing Cloud (AMC). Instance ids and names, advertiser ids, marketplace ids, audience definitions and execution ids, query text, and audience status.
  • (g) Selling Partner API (SP-API) Seller and Vendor. Selling partner ids, regions, marketplace ids, connection type (seller or vendor), discovered store/account names, country and currency codes, sales summaries, ASIN/catalog and inventory-related fields displayed in Retail, traffic (glance views), purchase orders, Brand Analytics catalog and search-term rows, geo sellout (including ship-to country/state or province), review/sentiment topic rows, and organic/inorganic sales breakdowns. Super admins may link advertising profiles to vendor credentials (ads-vendor links).
  • (h) Flipkart. OAuth connections including seller id, display name, scopes, consent and expiry, status/health, and verification results. We also support Flipkart Ads OAuth connections where enabled.
  • (i) Customer-configured Service data. Automation rules and execution/pending logs, term lists, hourly-budget groups and run logs, budget rules and campaign associations, bid snapshots and apply-job results, chat threads/messages/proposals, recommendation dismissals stored locally, and CSV exports generated in the browser from on-screen data.

This business information may include Personal Data (for example, user emails of app users, identifiers contained in advertising search terms, ship-to geography, or Amazon audience user_id values referenced in AMC SQL). We do not require you to submit special-category data, and the Service is not designed to collect it.

4.4 Usage Information

We process information generated by your use of the Service, including:

  • (a) API requests your session makes to our backend (/api/v1/...), with the Bearer token attached for authenticated routes;
  • (b) feature use implied by those requests (for example, opening Workspace, confirming a chat proposal, creating an automation, triggering catalog or report sync);
  • (c) administrator metrics views (account-level cost and sales aggregations) and report-coverage tooling;
  • (d) chat action history (proposal status, timestamps, undo eligibility);
  • (e) automation execution status, error messages, and dry-run flags;
  • (f) OAuth connection health and last API success times.

The Service does not include third-party product-analytics SDKs (for example, Google Analytics, Mixpanel, Segment, Amplitude, PostHog, Hotjar, or Sentry). Our backend infrastructure maintains standard server-side logs and monitoring necessary to operate and secure the Service.

4.5 Device and Technical Information

When you use the Service, our web servers, hosting provider, and any reverse proxy typically receive standard technical data such as IP address, date and time, request URL, user agent, and similar HTTP metadata, which may be retained for security and operational purposes.

The browser also holds:

  • (a) localStorage: session (amz_app_session) and dismissed recommendation ids per profile;
  • (b) sessionStorage: selected app date range (amz.appDateRange.v1), last selected advertising profile, and Workspace entity cross-filter state per profile.

The Service does not set first-party tracking cookies. See Section 8.

4.6 Cookies and Similar Technologies

See Section 8.

4.7 Information From Third Parties

We receive information from:

  • (a) Google, if you use Continue with Google: authorization and account linking based on a verified email; Google-only users have no password in the Service.
  • (b) Amazon Advertising APIs, after you authorize Login with Amazon: advertising profiles, campaigns, reports, recommendations, AMC context, streams, and related advertising data.
  • (c) Amazon Selling Partner API, after Seller Central or Vendor Central authorization (or super-admin self-authorized token): retail sales, catalog, traffic, orders, Brand Analytics, geo sellout, reviews, and related retail data.
  • (d) Flipkart, after you authorize Flipkart OAuth: connection and seller-related data returned by that integration.
  • (e) Administrators of the Customer, who create users, assign profile access, deactivate users, and trigger syncs.
  • (f) Infrastructure providers that host or proxy the Service (see Section 7.1).

We do not independently verify all third-party data. Accuracy depends on those platforms and on the permissions you grant.

5. How We Use Information

We use information to:

5.1

Provide, operate, and maintain the Service, including authentication, session management, role-based access to advertising profiles, and administrator controls.

5.2

Connect to third-party APIs using tokens and credentials you authorize, and to refresh or prompt re-authorization when Amazon LWA or other connections require it (amazon_lwa_reauth_required).

5.3

Sync, store, and display advertising catalogs, reports, stream/dayparting data, and retail data, including scheduled or on-demand sync and report ingest (including ingest from object storage as described by the application’s report-sync APIs).

5.4

Enable campaign management: create and update SP, SB, and SD campaigns and related entities; change budgets, bids, states, negatives, and placements; apply recommendation packs; and run bulk Workspace jobs (keyword bids, search-term negation, campaign placement jobs).

5.5

Run Customer-configured automations and dayparting/hourly-budget schedules, including pending-action queues and execution logs.

5.6

Provide Chat: send your prompts and relevant account context to the backend, generate replies and action proposals, and execute confirmed actions against connected advertising accounts. Chat message records may store model and provider identifiers returned by the backend.

5.7

Provide AMC audience creation, listing, and deletion where AMC is available for the connected account.

5.8

Provide bid snapshots: capture, list, apply, retry, export apply results, and delete snapshots.

5.9

Support administrators: user provisioning, profile grants, deactivation, account metrics, report coverage (including S3 vs database coverage states), and Amazon Ads stream subscriptions (including SQS queue configuration).

5.10

Maintain security: validate JWTs, enforce is_active, restrict demo users to granted profiles, and limit certain Seller/Vendor and retail operations to super admins.

5.11

Communicate with you about the Service, security, and (if you contact us) support.

5.12

Comply with law, enforce terms, and protect rights, safety, and integrity of the Service.

5.13

Improve the Service. We do not use Customer advertising data or chat content to train general-purpose AI models unless otherwise agreed with the Customer in writing.

We do not use the Service to process payments, subscriptions, credits, or invoices. The application has no billing module. Amazon or Flipkart ad spend is charged by those platforms, not by the Sapyon AI application.

6. Legal Bases for Processing

6.1

If the EU/UK GDPR (or equivalent) applies to our role as Controller of Account Data, we rely on:

  • (a) Contract (Art. 6(1)(b)): to create and administer your account, authenticate you, and provide the Service you request;
  • (b) Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, understand reliability of integrations, and administer role-based access control, balanced against your rights;
  • (c) Consent (Art. 6(1)(a)): where you choose Google sign-in or optional connections, to the extent consent is the appropriate basis;
  • (d) Legal obligation (Art. 6(1)(c)): where we must retain or disclose information to comply with law.

6.2

As Processor of Customer Data, we process Personal Data on the Customer’s documented instructions, as described in the DPA. The Customer is responsible for ensuring it has a lawful basis to permit that processing (including advertising, retail, and end-customer or shopper-related data obtained via Amazon or Flipkart).

6.3

Whether GDPR, UK GDPR, or other regimes apply to a given User or Customer depends on the location and role of the relevant party.

7. How We Share Information

We do not sell Personal Information in the ordinary commercial sense of selling a list of users. Statutory “sale” or “share” under California law is addressed in Section 14.

7.1 Service Providers

We use vendors to host and operate the Service, including:

  • (a) Netlify, which hosts the web application; production infrastructure uses same-origin /api/* proxying so the browser communicates over HTTPS.
  • (b) Amazon Web Services (AWS). The production API proxy target is an AWS Elastic Load Balancing hostname in us-east-1; our infrastructure uses RDS for data storage, S3 for advertising report files, SQS for Amazon Ads stream subscriptions, and ECS / Secrets Manager for backend hosting and secrets.
  • (c) Cloudflare, which provides DNS services for sapyon.com.
  • (d) Google LLC, for Google OAuth (Continue with Google) and for Google Fonts loaded from fonts.googleapis.com and fonts.gstatic.com.
  • (e) LLM / AI provider(s) used to power Chat functionality.

We may also engage additional processors for functions such as email delivery, monitoring, support tooling, and backups. A current list of sub-processors is available on request.

These providers process information only as needed to provide their services to us, subject to our contracts with them where applicable.

7.2 Third-Party Integrations

If you or the Customer connect a platform, we share data with that platform as needed to provide the integration, and we receive data back from it:

  • (a) Amazon Advertising (Login with Amazon / advertising APIs), including campaign writes you confirm (budgets, bids, states, keywords, negatives, budget rules, automations, chat-confirmed actions, hourly-budget updates).
  • (b) Amazon Selling Partner API (Seller Central and Vendor Central).
  • (c) Flipkart OAuth (and Flipkart Ads to the extent enabled).
  • (d) Google, for sign-in.

These platforms are independent controllers or processors of their own services. Their use is governed by their terms and privacy policies and by the consents you grant in their OAuth screens. Amazon advertising spend and retail transactions are not billed through Sapyon AI.

7.3 Legal Requirements

We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of the Company, Customers, Users, or the public.

7.4 Business Transfers

We may disclose information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and this Policy’s purposes.

7.5 Administrators and Other Users of the Same Customer

Users with access to the same advertising profile can see Customer Data for that profile. Super admins and users with admin permissions can see user emails, roles, profile grants, and operational metrics described in admin screens. Demo accounts are limited to granted demo profiles and do not receive a super-admin bypass.

8. Cookies and Tracking Technologies

8.1

The Sapyon AI frontend does not implement a cookie banner, does not set first-party analytics cookies, and does not load common third-party advertising or analytics pixels.

8.2

The Service uses localStorage and sessionStorage (similar technologies) for:

  • (a) authentication session (amz_app_session);
  • (b) UI preferences such as date range, last advertising profile, Workspace filters, and dismissed recommendations.

These are required for the Service to function as implemented (session and UI state). They are stored on your device. Clearing site data signs you out and resets those preferences.

8.3

Google Fonts. The application loads fonts from Google. Google may process your IP address and request metadata. This is a third-party request, not a first-party cookie set by our application.

8.4

Third-party OAuth pop-ups (Google, Amazon, Flipkart) may set cookies on those parties’ domains according to their policies.

8.5

We will publish a dedicated cookie notice if our use of cookies changes in the future.

9. Data Retention

9.1

Account Data is retained while your account remains active and for a limited period thereafter as needed for security, dispute resolution, and legal compliance.

9.2

Customer Data (advertising, retail, automations, chat, snapshots, reports) is retained for the duration of the Customer relationship and the DPA, and until deleted or returned in accordance with the DPA and Customer instructions. The Service allows deletion or archival of certain objects, including chat thread archiving, bid snapshot deletion, automation rule deletion, AMC audience deletion, and hourly-budget group deletion. Deletion requests are processed in accordance with our data retention practices and the DPA.

9.3

Deactivated users. Administrators can set is_active to false. Deactivated users cannot use a stored session after the client revalidates with /api/v1/auth/me. Deactivation in the UI is not presented as erasure.

9.4

Browser storage remains until you clear it or sign out (session key) or until the browser session ends (sessionStorage).

9.5

Demo accounts use a shared password model as described in Settings. Demo account data is retained only as long as necessary to support demonstration use.

9.6

Specific retention periods, where applicable, are set out in the DPA.

10. Data Security

10.1

We implement technical and organizational measures appropriate to a multi-tenant B2B application, including:

  • (a) authentication required for non-public API routes when app auth is enabled;
  • (b) Bearer JWT access tokens issued by the backend;
  • (c) role-based access (super admin, account owner, profile grants, permission codes);
  • (d) demo-user profile restrictions;
  • (e) password minimum length of eight (8) characters and authenticated password change for non-demo users;
  • (f) Google OAuth as an alternative to passwords;
  • (g) HTTPS for user access to the production web application;
  • (h) user confirmation before Chat action proposals are executed against advertising accounts;
  • (i) super-admin restriction for certain SP-API connection and retail operations.

10.2

The browser stores access and refresh tokens in localStorage. This is not equivalent to httpOnly cookie storage. Users should use a private device, sign out on shared devices, and protect their password and Google account.

10.3

We continuously evaluate additional certifications and security practices as the Service matures.

10.4

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

11. International Data Transfers

11.1

The production web application is hosted on Netlify with DNS on Cloudflare. The API proxy target is an AWS load balancer in the us-east-1 region (United States). Report files and streams involve S3 and SQS. Users outside the United States should expect that Account Data and Customer Data may be processed in the United States and in other locations where our providers operate.

11.2

Where applicable, we rely on Standard Contractual Clauses or other approved transfer mechanisms, as set out in our Data Processing Agreement, to lawfully transfer Personal Data internationally.

11.3

Data residency in a single country or region is not offered.

12. Your Privacy Rights

12.1

Depending on applicable law, you may have rights to access, correct, delete, or restrict processing of Personal Data, to object to processing, to portability, and to withdraw consent.

12.2

App users can:

  • (a) view the email associated with the session in the Service;
  • (b) change password (non-demo accounts) in Settings;
  • (c) sign out (clears client session storage);
  • (d) reconnect or manage Amazon and other connections where the UI permits;
  • (e) archive chat threads and delete certain Customer-configured objects described in Section 9.2.

12.3

There is no in-app “delete my account” or “export all my data” control in the application. To exercise rights that the UI does not support, contact [email protected]. We may need to verify identity and, if you are not the Customer’s administrator, we may redirect the request to the Customer.

12.4

If we process data solely as a Processor, we will refer data-subject requests to the Customer and assist as described in the DPA, unless law requires us to act directly.

13. GDPR Rights, Where Applicable

Where the GDPR or UK GDPR applies to our Controller processing, data subjects may have:

13.1

Right of access (Art. 15).

13.2

Right to rectification (Art. 16).

13.3

Right to erasure (Art. 17), subject to legal exceptions. Account erasure is not self-service in the application.

13.4

Right to restriction (Art. 18).

13.5

Right to data portability (Art. 20) for Account Data you provided, where technically feasible.

13.6

Right to object (Art. 21), including to processing based on legitimate interests.

13.7

Right to withdraw consent where processing is based on consent, without affecting prior lawful processing. You may stop using Google sign-in by using email/password if a password exists, or by discontinuing use.

13.8

Right to lodge a complaint with your local data protection supervisory authority.

13.9

We do not perform solely automated decision-making that produces legal or similarly significant effects about individuals as a consumer-credit or hiring system. Chat and automations can write to advertising accounts after configuration or confirmation; those are Customer-directed advertising operations, not GDPR Art. 22 consumer decisions about shoppers. AMC audience creation may affect advertising targeting on Amazon’s platform under the Customer’s instructions.

14. California Privacy Rights, Where Applicable

14.1

If you are a California resident and the California Consumer Privacy Act (as amended, including the CPRA) (“CCPA”) applies, you may have rights to know, delete, correct, and opt out of sale or sharing of Personal Information, and not to be discriminated against for exercising rights.

14.2

Categories of Personal Information we collect are described in Section 4 (identifiers such as email and user id; commercial/advertising data; internet/technical data; geolocation-related fields in retail geo sellout, if present; inference-like recommendation outputs generated from advertising performance). We collect these categories from you, from your administrators, from connected platforms, and from devices.

14.3

Business purposes are described in Section 5.

14.4

We do not sell Personal Information, nor do we share it for cross-context behavioral advertising, as those terms are defined under the CCPA.

14.5

To exercise CCPA rights, contact [email protected]. We will accept requests submitted through an authorized agent in accordance with applicable law.

14.6

Sensitive Personal Information: passwords and OAuth tokens are used only to provide the Service (authentication and connected APIs). We do not use Sensitive Personal Information for any other purpose.

15. Children’s Privacy

15.1

The Service is a business advertising-operations application. It is not directed to children.

15.2

We do not knowingly collect Personal Data from children. The Service is intended for use by individuals who are at least 18 years of age, acting on behalf of a business.

15.3

If you believe a child has provided Personal Data, contact [email protected]. We will take appropriate steps, which may include deleting the account.

16. Third-Party Services and Links

16.1

The Service depends on Amazon, Google, Flipkart, font delivery, and hosting providers. Their processing is governed by their policies.

16.2

OAuth consent screens are provided by those platforms. We receive tokens or codes needed to complete the connection or sign-in.

16.3

Super-admin paste of an SP-API refresh token is a sensitive credential transfer. The Customer is responsible for treating that token as confidential.

16.4

CSV and snapshot exports download to the user’s device. We are not responsible for the security of exported files once downloaded.

16.5

We are not responsible for third-party sites linked from the Service.

17. Changes to This Privacy Policy

17.1

We may update this Policy from time to time. The “Last Updated” date at the top of this Policy will change accordingly. Material changes will be communicated via email or an in-app notice, in addition to posting the revised Policy on this page.

17.2

Continued use after the effective date of a revised Policy constitutes acceptance where permitted by law.

18. Contact Information

Controller (Account Data): VNash Digital Pvt Ltd

Address: Bangalore, India

Privacy: [email protected]

Legal: [email protected]

General: [email protected]

For Customer Data processed on behalf of a Customer, contact the Customer (your administrator) in the first instance, and [email protected] if you need help identifying them.

19. Effective Date and Last Updated

Effective Date: June 1, 2026

Last Updated: September 3, 2026

This Policy should be read together with the Sapyon AI Terms of Service and, where we process Customer Data as a Processor, the Data Processing Agreement.

Ready to Turn Hourly Signals into Higher ROAS?

Real-time analytics, automation, and AI decisions, built specifically for Amazon advertisers. Scale with confidence.

Book a Demo