Privacy & Data Handling Policy
TUNNING GROUP LLC · Last updated: July 25, 2026
This policy describes how TUNNING GROUP LLC ("we", "our") collects, processes, stores, uses, shares, and disposes of data — including data obtained through the Amazon Selling Partner API ("Amazon Information") — in MarkHub.
MarkHub is a software service offered to Amazon selling partners. Each customer connects their own Amazon seller account by authorizing MarkHub through Amazon's OAuth flow, and each customer's data is held in a separate workspace. We act as a processor of each selling partner's Amazon Information, on their instruction and for their own operations only. We never combine, compare, or share one selling partner's data with another.
1. What data we collect
Through the Amazon Selling Partner API, and only for the seller account each customer connects, we access: order IDs, order status, purchase dates, product identifiers (SKU, ASIN), quantities, item prices, shipping amounts, listing and pricing data. We also store supplier cost data the customer enters manually for profit calculation. We store the customer's Amazon refresh token, encrypted with AES-256-GCM using a key held outside the database. We never see or store the customer's Amazon password.
2. How we use it
Amazon Information is used exclusively to provide the service to the selling partner it belongs to: calculating per-order profit and cost of goods, monitoring account health, managing inventory, listings and pricing. We do not use Amazon Information for advertising, profiling, model training, resale, or any purpose other than operating the service for that selling partner.
3. How we store, isolate and protect it
Data is stored in a managed PostgreSQL database (Supabase) encrypted at rest with AES-256, with keys managed by the provider's Key Management System. The application runs on Vercel serverless infrastructure. Data is encrypted in transit (TLS).
Tenant isolation. Every record is bound to a workspace, and each workspace belongs to exactly one account owner. Isolation is enforced in two independent layers: PostgreSQL Row Level Security policies scoped to the authenticated user, and an explicit workspace filter in the application query layer.
API credentials and secrets are stored as encrypted environment variables, never hard-coded and never committed to source control. Administrative access is limited to the business owner on a need-to-know basis.
4. How we share it
We do not sell, rent, or share Amazon Information with any third party, and we never disclose one selling partner's data to another. Our subprocessors are: Supabase (database hosting), Vercel (application hosting), Clerk (authentication) and Stripe (payment processing — Stripe receives billing details only, never Amazon Information). Each processes data solely on our instruction under its own security and confidentiality terms.
5. Buyer personal information
MarkHub is designed to hold the minimum buyer data needed to show a seller where their own sales are going, and nothing more.
What we never request, store, or display: buyer name, street address, phone number, email address, or any payment instrument detail. These fields are discarded at ingestion and are never written to our database.
What we do store: the city, state or region, and postal code of the shipping destination, attached to the order. This is used for a single purpose — showing the seller the geographic distribution of their own orders — and is visible only to the selling partner who owns that order. It is never aggregated across selling partners, never used for advertising, and never disclosed to anyone.
Retention: 30 days. Location data is automatically erased 30 days after the order date, in line with the Amazon Data Protection Policy. After that the order remains in the account for financial reporting with the location field emptied. All other order fields — SKU, quantity, price, fees and cost — contain no buyer information and are retained as described below.
6. Data retention & disposal
Buyer location data is erased after 30 days, as described in section 5. Order, listing, pricing and cost data — none of which identifies a buyer — is retained for as long as the account is active, so the customer can run historical reporting.
On account closure or on request, the customer's workspace and all data in it are deleted, and the stored Amazon refresh token is revoked. A customer may disconnect their Amazon account at any time from Settings, which revokes our access immediately.
7. Incident response
In the event of a data incident we revoke and rotate affected credentials, isolate affected systems, review logs to determine scope, notify affected customers, and — where Amazon Information is involved — report to security@amazon.com within 24 hours of detection, then remediate the root cause.
8. Your rights
Customers may request access to, correction of, export of, or deletion of their data at any time by contacting us at the address below. We respond within 30 days.
9. Contact
For privacy questions or to report a security incident, contact:
TUNNING GROUP LLC — support@usemarkhub.com