SourceDock Privacy Policy
SourceDock is a product of Odyne LLC. This policy describes how we collect, use, store, protect, share, and delete information for the web application and the optional Chrome extension, including Amazon Selling Partner API information, in line with Amazon’s Data Protection Policy.
Who is responsible
Odyne LLC operates SourceDock. We are the controller of account data you give us and the processor of Amazon Information we retrieve only after you authorize SourceDock in Amazon’s official Login with Amazon flow.
Web application and Amazon SP-API data
When you create an account we collect your email address, password hash or identity-provider identifiers, subscription and billing metadata from Stripe, and the workspace data you enter (ASINs, costs, notes, purchases). We also keep: your profile photo if you upload one; the days you used the app and the badges that earns; when you were last active; a log of security-relevant actions on your account (sign-ins, plan changes, connections); your ASIN search history; and your two-factor secret, encrypted.
If you connect an Amazon selling account, Amazon issues OAuth tokens. We store the refresh token encrypted at rest (AES-256-GCM). We never collect your Amazon password, Seller Central cookies, or two-factor codes. We use those tokens only to call SP-API for the authorizing selling partner, and only for features that selling partner uses:
- Restrictions and catalog data for ASINs they research
- Pricing and fee estimates for those ASINs
- On the Flagship plan, finances and settlement data for fee and reimbursement recovery
We do not sell Amazon Information. We do not aggregate SP-API data across selling partners to provide or sell to any party (Acceptable Use Policy 4.4). We do not publish insights about Amazon’s business (Acceptable Use Policy 4.5). Each selling partner sees only their authorized account plus public catalog data and their own inputs.
Keepa is used for public price-history and sales-estimate data. Stripe processes card payments; we do not store full card numbers.
What the extension does
The extension connects to your account and helps you check brand approval status on Amazon Seller Central (United States). When you start a check, it opens the Seller Central page for that product and reads the approval status Amazon already displays. It does not click, type, submit forms, or apply for approval. It runs only on sellercentral.amazon.com and the SourceDock web app.
Extension data we collect (only after you consent)
- ASINs, marketplace, and approval outcomes you check
- Amazon seller ID, to attach outcomes to the right account
- SourceDock authentication tokens (never Amazon credentials)
- Extension version and Chrome major version
- Selector-failure telemetry (which lookup failed and the page URL; no page HTML)
- Local consent choice and cached selectors on your device
Data the extension does not collect
- Page HTML or DOM snapshots
- Browsing history outside the two sites above
- Name, email, or demographics through the extension
- Credit-card or bank numbers through the extension
- Amazon passwords, session tokens, or login cookies
- Amazon buyer / customer PII or their orders
- Cookies from other websites, keystrokes, or form inputs
Settlement and fee figures used by Capital Recovery come from the web application via SP-API after you authorize it, not from the extension.
How we use, share, and delete data
- Use: provide the product you subscribed to, secure the account, and bill the subscription.
- Share: only with the providers that run the service, listed below. No sale of personal or Amazon Information.
- Protect: HTTPS in transit; Amazon refresh tokens encrypted at rest; access limited to operating the service.
- Retention: check results and price history 90 days; inactive session data 30 days; workspace data (Vault, purchases, recovery) for as long as your account exists. Anonymous, per-ASIN market history with no link to any account is kept indefinitely.
- Deletion: from Account > Danger you can delete your account yourself. Your plan is cancelled at once so nothing more is charged, and after a 30-day grace period the account and everything in it (including your Amazon tokens) is permanently erased. You may also email support@sourcedock.io. Amazon tokens are erased the moment you disconnect Amazon.
Who we send data to
We use these companies to run the service. Each receives only what its job needs:
- Amazon (SP-API and Login with Amazon): the calls you authorized for your seller account.
- Stripe: payments and subscriptions. We never see your full card number.
- Keepa: the ASINs you research, to fetch public price history and sales estimates.
- Resend: transactional email (verification, receipts, billing notices).
- Google: only if you sign in with Google.
- DigitalOcean, Neon, and Cloudflare: hosting, the database, and the network edge that serves the site.
- GitHub: hosts the extension and desktop installer files you download.
We use no advertising or analytics trackers on the website or in the app.
Your rights (GDPR and CCPA)
You may request access, correction, deletion, restriction, portability, or to object. California residents may request to know or delete personal information. We do not sell personal information. Email support@sourcedock.io with the subject “Privacy Request.”
Chrome Web Store Limited Use
The extension only accesses Seller Central pages to read approval outcomes of checks you start. We do not use that data for advertising, lending, or creditworthiness, and we do not transfer it except to provide the core service.
Trademark
Amazon, Amazon.com, Seller Central, and Amazon Services API are trademarks of Amazon.com, Inc. or its affiliates. SourceDock is a product of Odyne LLC. SourceDock is not affiliated with, endorsed by, or sponsored by Amazon.
Changes
We will update the date above when this policy changes. Continued use after a change means you accept the updated policy.
Contact
Odyne LLC, SourceDock. support@sourcedock.io