/
← Back to VendorCore

Privacy Policy

Last updated: 12 May 2026

This Privacy Policy describes how Margau Trading OÜ ("we", "us", "VendorCore") collects, uses, and protects information when you use the VendorCore service (the "Service").

Controller

Margau Trading OÜ
Registry code: 14866499
VAT identification number: EE102748875
Address: Männimäe/1, Pudisoo küla, 74626 Kuusalu vald, Harju maakond, Estonia
Email: [email protected]

Data we collect

Information you provide

When you contact us or request access to the Service, we collect the information you submit, including your name, work email address, company name, and any free-text content you provide.

Amazon Vendor data (Selling Partner API)

If you authorize VendorCore via Amazon's Selling Partner API OAuth flow, we retrieve data from your Vendor Central account on your behalf, including but not limited to:

  • Vendor Retail Analytics reports (Sales, Traffic, Inventory, Forecasting, Net Pure Product Margin)
  • Brand Analytics reports (Search Terms, Market Basket Analysis, Repeat Purchase Behavior) for ASINs associated with your brand
  • Purchase Orders, Advanced Ship Notices, Invoices, and Settlement data
  • Catalog data for ASINs in your portfolio

We access this data exclusively under the scope of the roles you grant during the OAuth authorization process. VendorCore does not access personally identifiable information about end customers of Amazon.

Usage data

We collect basic usage information (pages viewed, features used, browser type, IP address in truncated form) for product improvement and security purposes.

How we use data

We process your data exclusively for the following purposes:

  • Providing the Service (analytics dashboards, AVN preparation materials, reports) to the authorizing vendor
  • Responding to support inquiries
  • Improving and maintaining the Service
  • Complying with legal obligations

We do not sell your data, share it with third parties for marketing purposes, or aggregate vendor data across customers.

Legal basis (GDPR)

We process personal data under the following legal bases of the EU General Data Protection Regulation (GDPR):

  • Contract performance (Art. 6(1)(b) GDPR): to provide the Service to you under our agreement.
  • Legitimate interests (Art. 6(1)(f) GDPR): to operate, secure, and improve the Service.
  • Consent (Art. 6(1)(a) GDPR): where you have explicitly opted in.
  • Legal obligation (Art. 6(1)(c) GDPR): to comply with applicable law.

Data storage and security

Vendor data is stored in encrypted form (AES-256 at rest, TLS 1.2 or higher in transit) on infrastructure located within the European Union. Access is restricted to authenticated users explicitly authorized by the vendor account owner and to a limited number of VendorCore engineers on a strict need-to-know basis. We maintain access logs and security monitoring in accordance with Amazon's Data Protection Policy.

Data retention

We retain vendor data for as long as your authorization is active. If you revoke authorization or terminate your use of the Service, we delete or anonymize associated vendor data within 30 days, subject to any legal retention obligations.

Sub-processors

We may use carefully selected sub-processors to operate the Service, including cloud infrastructure providers within the EU. All sub-processors are bound by data processing agreements requiring equivalent levels of data protection. A current list of sub-processors is available upon request.

Your rights

Under the GDPR, you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at [email protected].

Cookies

This website uses only essential cookies required for its functionality. We do not use tracking cookies or third-party analytics services that profile visitors.

International transfers

Where data is transferred outside the European Economic Area (for example, in communication with Amazon's Selling Partner API), such transfers occur under appropriate safeguards including Standard Contractual Clauses.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email.

Contact

For any questions or concerns about this Privacy Policy, contact us at [email protected].