LEGAL
Privacy Policy
Last updated · 18 September 2026 · Beta
This policy covers the MerchPPC Chrome extension and the merchppc.com website. It is written to be read, and the shortest true summary is this: your Merch and Amazon Ads data is read into a database inside your own browser, stays there, and is never uploaded to us. This website holds your account, your installations, your plan, and the operational records needed to run the service — and the table below is the whole of it, not a summary.
1 · Who operates this site
MerchPPC.com is operated by Marco Sousa. This policy covers the website: accounts, beta access, extension installations, entitlements, billing, assistant integrations, support correspondence, and service operations. It also explains what the MerchPPC Chrome extension does not send here.
2 · What the extension processes, and where it stays
The extension reads your Merch and Amazon Ads data through the Amazon session already signed in to your browser, and writes it into a database on your own machine. It never asks for your Amazon password.
Your listings, designs, sales, royalties, campaigns, ad groups, targets, search terms and report rows are not uploaded. There is no copy of them on this website and no row anywhere for a product, a sale, a campaign or an amount of money. Neither are your Amazon cookies or credentials. What that buys and costs you is a page of its own.
3 · What merchppc.com stores
Using the dashboards needs no website account. An account exists for the things that involve our servers, and this is all of it — grouped by why it exists. Where a record is removed on a schedule, the schedule is stated; where it is not, it says so rather than implying one.
| What | Why | How long |
|---|---|---|
| Your account Email address, role, timestamps |
To sign you in and to attach everything else to somebody | While the account exists |
|
Sign-in links and codes
The address the link was sent to, and a hash of the code — never the code itself |
Passwordless sign-in; there is no password to store | A code stops working after 15 minutes and a session token after 14 days. The record of the request is kept. No fixed schedule |
|
Linked installations
An identifier the extension mints itself, a label you choose, the browser name and extension version, link state, whether it is primary, whether it may accept assistant calls, two token hashes, and five timestamps. Also one short line saying what that computer can read designs with: whether reading is switched on, whether the word reader is ready, and whether Chrome's built-in AI is ready, downloadable, unavailable or too slow there. It is sent each time the browser connects and says nothing about any design |
To know which browsers are yours, to route an assistant to one, and to show you what is linked. The design-reading line is only ever counted, to decide which readers are worth building | Until you revoke the installation or delete the account |
|
Merch account pin
A one-way hash of your Amazon Merch on Demand account id — never the id itself — with the identifier of the browser that reported it and two timestamps |
To keep one Merch account to one email, so one seller cannot hold two accounts. It is compared for equality and never displayed or listed | Until you delete the account, which releases it |
|
Plan and capabilities
Which capabilities are granted, where the grant came from, and its dates |
To decide what the extension may do | While the account exists |
|
Billing
Processor customer and subscription identifiers, product, interval, amount, currency, status and entitlement dates |
To grant or remove paid access, and for accounting | As long as tax and accounting obligations require. Raw webhook payloads are erased after 30 days |
|
Assistant integrations
Your consent per provider, OAuth client and scope metadata, the selected installation, quota counters, and per-call metadata: tool name, outcome, duration, byte counts, correlation identifier |
To honour your consent, enforce quotas, and diagnose failures | Per-call metadata after 90 days |
|
Security events
Sign-in attempts and revocations, the request id, and a one-way hash of the address the attempt came from |
To detect and investigate unauthorised access | 365 days |
|
Where a signup came from
Campaign tag, medium, source, content and term from the link you arrived on; the referring site's hostname; the path you landed on; and when |
To know which channels bring people who stay | While the account exists. No fixed schedule |
|
Which places accounts come from
A country or a continent, and a number. Nothing else |
To know where the product is being used, and where it is not | Indefinitely — it is a counter, about 195 rows at most, and no row points at anybody |
|
Messages you send us
Your name, email, topic and message, plus whether delivery succeeded and whether it has been answered |
To answer you — and so a mail outage cannot lose your message, it is written down before delivery is attempted | Until answered and no longer needed. No fixed schedule |
|
Administrator actions
What was done, to which record, the outcome, and a whitelisted summary of the change |
So that an operator changing your entitlements or access leaves a trace, including when the action was refused | Kept. No fixed schedule |
|
Server errors
The exception type, where it came from, how many times, and its message truncated to 500 characters |
So that a fault is noticed rather than going to a log nobody reads | Until resolved and cleared. No fixed schedule |
|
Rate-limit counters
A one-way hash of the address or email a request came from, and a count |
So that one source cannot exhaust sign-in, the API or the assistant relay for everybody else | Deleted when the window closes — minutes to a day |
|
Email preferences
Which kinds of email you agreed to, and where that agreement came from |
So that consent is a record rather than a memory | While the account exists |
|
Beta invitations
That an invitation was issued to you, by which operator, and a hash of its token |
So an invitation can be accepted once and traced afterwards | While the account exists |
|
Feedback you send us
Your own words — a summary, the detail you wrote, and which screen it came from |
So a report about a wrong number can be answered | Kept. No fixed schedule |
|
Bug reports from the extension
Your own words, plus what the extension can say about itself: its version and build, your operating system as one word, your Chrome version, which screen you were on, whether your browser is connected, whether its sync is current, and any error it recorded. Never a product, a sale, a campaign or an amount of money. If you are not signed in you can add an email address so we can reply |
So something broken can be found and fixed | 180 days, then your words are deleted and the record kept |
|
Files you attach to a bug report
Screenshots or logs you choose and attach yourself. Nothing is ever captured from your screen — the extension cannot take a screenshot and asks for no permission that would let it |
So a problem you can see can be seen by us | 30 days after the report is answered or closed, 180 days at the outside |
|
Billing reconciliation
A nightly check that the plan on your account matches the processor's, and what it found |
So a subscription that stopped paying, or one that paid and was not credited, is noticed rather than discovered by you | Kept. No fixed schedule |
|
Operational switches
That an operator paused part of the service, which one, and the reason they gave |
Because the reason is shown to you when something is switched off, and it should be attributable | Kept. No fixed schedule |
4 · Three things worth saying plainly
An error message can contain a value. Server errors are grouped by a hash of the fault's type and origin, never of its text — but the message itself is stored so it can be read, and an exception message sometimes carries an interpolated value such as a record identifier. It is truncated at 500 characters. This is the one place where something unpredictable can end up in a record, and saying otherwise would be more comfortable than true.
An administrator's audit trail deliberately drops things. The summary of a change is built from a whitelist, and any field whose name contains amazon, token, secret or password is discarded before the record is written.
Your address is looked at once and never written down. The first time an account signs in, the request's headers are read to work out a country — or, where nothing in front of this site can tell us one, the continent of the datacentre that answered. That place is added to a counter. The address itself is not stored, not raw and not hashed, and the counter has no column that could point back at you: it holds a place and a number, so nobody with the database can tell which account is the one in Portugal.
Reading this site quietly gives you nothing to carry. A visitor who arrives with no campaign tag and no external referrer is given no session and no cookie at all. A session is created only when there is something to remember — arriving on a tagged link, or signing in.
5 · The assistant relay
Connecting Claude or ChatGPT requires your own account with that provider, and they process your conversation under their own terms. MerchPPC passes the result of one specific tool request between your assistant and your own extension. It does not give either provider access to your computer, your browser, your Amazon cookies or your credentials.
Each assistant is a separate grant — consenting to one never grants the other — revocable at Account → Assistants, and rate-limited to 30 calls a minute and 300 a day, shared across assistants.
Relayed payloads are never stored here — not the prompt, not the tool arguments, not the result, not the Amazon data that answered it. Only the metadata in the table above is kept.
If you separately authorise proposals, a tool may ask your extension to write an advertising change into the Publish queue inside your own browser. That row is stored by your extension, not by us, and it reaches Amazon only after you approve it.
If you authorise the batch permission, a tool may ask your extension for a small preview of a design you have not published yet — a few hundred pixels, never the print file — with a few colour measurements taken from it. For an assistant that cannot receive pictures from an app, ChatGPT among them, the same design also goes as a smaller picture, at most 256 pixels, written out as text for it to decode and look at. If you also switch on reading on this computer in the batch panel, your extension reads each of those designs in your own browser, with a small text reader downloaded once from merchppc.com and, where you agree to it, the AI model built into Chrome; no picture is sent anywhere to be read. A tool may then receive a short text description of each design: the words printed on it and a sentence about what it shows. These pass through the relay like any other result and are not stored here, and your extension's privacy mode withholds all of them.
6 · Email
Signing in is transactional and does not opt you into anything. Product updates and marketing are a separate preference you can change without losing access to your account. Sign-in emails contain a private link and may contain a six-digit code — do not forward either.
7 · Cookies
The site uses session cookies for authentication, security and CSRF protection, and for the attribution case described above. Some interface preferences are kept in your browser's local storage. None of it is used to build a profile or sold to anybody.
There is no analytics provider on this site. No third-party analytics script, no tag manager, no advertising pixel. If one is ever added, this page is updated before it ships.
8 · Who we share data with
Hosting, the database, and transactional email are run by service providers on our behalf. Nothing is charged today and no payment details are collected. When paid plans arrive, checkout, card details, invoices and receipts will be handled by a dedicated payment processor — MerchPPC never sees a full card number — and this page names it before the first charge.
Links to Facebook and Amazon lead to services with their own policies. We do not control how those platforms process what you do there. And we would disclose account records if the law genuinely required it.
9 · What we do not do
We do not sell your data. We do not use it to make automated decisions about you. We do not ask for your Amazon password anywhere on this website. And we cannot look at your sales, royalties or campaigns — not as a policy but as a fact of where they are stored.
10 · Deleting things
You can ask for a copy of what is connected to your account, correction of anything inaccurate, or deletion. Depending on where you live you may also have rights to restrict, port, or object to processing. Requests go to privacy@merchppc.com.
Some records may survive a deletion request where they are needed for security, dispute handling, tax, accounting or legal reasons — billing records are the usual case.
The database in your browser is yours to delete without asking. Uninstall the extension, or clear its storage, and it is gone. Nothing of it exists anywhere else; a re-install syncs it again from Amazon.
What deletion actually does, exactly. Asking us to erase your account starts a seven-day countdown, and nothing is destroyed until it runs out. It can be cancelled at any point before then, and cancelling leaves nothing behind. When it runs, every record that is attached to your account is deleted — the account itself, your installations, your plan and grants, your assistant grants and their call history, your security events, your email preferences, your beta invitation, your feedback and your bug reports.
Some things do not go, and it is fairer to name them than to let you assume otherwise. Every one of them is here because it is not attached to your account in the first place, or because removing it would destroy a record about somebody else.
- The record of what an operator did keeps its rows and loses its link to you: a log saying somebody erased an account, which vanishes when they erase the account, is not a record of anything.
- The count of accounts per country stays as it is, because it holds only a place and a number — there is no row in it that is yours, which is the same property that stops anybody here working out which account is the one in Portugal.
- A message you sent us through the old contact form is not attached to an account and is not removed by deleting one. It carries the name, address and text you typed. Ask and it goes.
- The record that a sign-in code was requested for an address outlives the account, because it is keyed by the address rather than by the account — the same reason it works before an account exists. It holds the address and a hash, not a working code.
The first two cannot be used to identify you. The last two can, which is why they are named rather than counted, and why the address given above reaches somebody who can remove them by hand.
11 · Security
HTTPS in production, secure session cookies, access controls, CSRF protection, hashed sign-in codes and hashed installation tokens. No internet service can promise absolute security, and this one does not.
12 · Children
MerchPPC is for adults running or learning about Amazon Merch on Demand and Amazon Ads. It is not directed to children.
13 · Amazon
MerchPPC is not affiliated with, endorsed by, or connected to Amazon. "Amazon", "Merch on Demand" and related marks belong to Amazon.com, Inc. The extension acts as your browser, under your session, at your direction — it reads the same pages and reports your session could already open, at a rate-limited pace with backoff.
We never ask for your Amazon password. The extension has no way to accept one and nowhere to put it. If anything ever asks you for it, it is not us.
14 · Changes to this policy
Signed-in users are told before a change takes effect, and the date at the top of this page is when it last changed. Where a change affects what is collected or who processes it, this page is updated before the change takes effect.
15 · Reaching us
Questions about privacy go to privacy@merchppc.com.