Privacy & Data Policy
Last updated: 11 July 2026WayDigital AI ("we", "us") respects your privacy. This policy explains what information we collect, how we use it, how long we keep it, and what we do if something goes wrong. It is written to align with Amazon's Selling Partner API security control guidance for service providers, and applies to this website and to our management of client Amazon Seller Central, advertising and CRM accounts.
1. Information we collect
- Contact information — name, business name, email address and phone number, submitted through our strategy call form.
- Account access — where a client grants us role-based access to their Amazon Seller Central, Google Ads, Meta Business Manager or CRM account, limited to the scopes required for the engagement.
- Campaign & performance data — analytics, ad performance and lead data needed to plan and report on a campaign.
- Website usage data — basic, aggregated analytics (pages visited, general location, device type).
We do not collect payment card details, government ID numbers, or Seller Central login credentials directly — marketplace access is granted only through the platform's own authorised role/permission system, never by a client sharing a password with us.
2. How we use it
- To respond to your enquiry and schedule your strategy call.
- To plan, run and report on the marketing, Amazon account management or automation service you've engaged us for.
- To meet legal, accounting, or marketplace compliance requirements (e.g. Amazon Solution Provider Portal reporting).
We do not sell or rent client data to third parties, and we do not use client data to train third-party AI models.
3. Data retention
| Data type | Retention period |
|---|---|
| Strategy call form submissions (no engagement started) | 12 months, then deleted |
| Active client account access & campaign data | Duration of active engagement |
| Client PII after contract ends | Deleted within 30 days of offboarding, unless a longer period is legally required |
| Marketplace access tokens | Revoked immediately on contract end or client request |
4. Credential management
- We never ask a client to share their Seller Central, email, or ad account password directly.
- All marketplace access is granted via the platform's own role-based permission system (e.g. Seller Central User Permissions).
- Internal team access is limited to individuals actively working on that account, and reviewed/revoked when a role changes or an engagement ends.
- Where a password-based tool must be used, credentials are stored only in an encrypted password manager — never in spreadsheets or chat messages.
5. Network & access protection
- All data in transit uses encrypted (HTTPS/TLS) connections.
- Access to client dashboards is restricted to authorised team members with individual, non-shared logins.
- Multi-factor authentication (MFA) is enabled wherever the tool supports it.
6. Sharing & third parties
We share client data only with the specific third-party tools required to deliver the service (e.g. an ad platform, CRM, or analytics dashboard the client has approved). We never disclose client data to unrelated third parties.
7. Incident response
- Contain — revoke affected access/credentials within 1 hour of detection.
- Notify — inform the affected client and platform (e.g. Amazon) within 24 hours.
- Investigate — determine scope of access and root cause.
- Remediate — rotate credentials, close the gap, confirm the fix.
- Review — internal post-incident review within 5 business days.
8. Your rights
You can ask us at any time to tell you what data we hold, correct inaccurate information, delete your data once any active engagement has ended, or revoke any account access we've been granted, effective immediately.
9. Contact us
WayDigital AI, C-25, C Block, Sector 8, Noida, Uttar Pradesh, India
Email: waydigital.in@gmail.com · Phone: +91 88680 78047