Last updated July 25, 2026
Privacy Policy
Sailwyn (the "Service") is operated by OneCommerce Inc., a New York corporation ("OneCommerce", "we", "us"). The Service provides advertising analytics, seller-authorized Brand Analytics, sales and traffic reporting, inventory and profitability reporting, AI-assisted analysis and recommendations, review-request tools, and campaign optimization software for Amazon sellers. This policy explains what information we collect, how we use and protect it, and how sellers can request changes or deletion.
Information we collect
Account information. Name, business name, email address, and login credentials that users provide when creating an Sailwyn account.
Amazon authorization data. When a seller connects an Amazon account, we receive OAuth authorization tokens, selling partner identifiers, advertising profile identifiers, and marketplace identifiers. We never receive or ask for Amazon passwords.
Amazon business and Brand Analytics data (Selling Partner API). As authorized by the seller, we access non-PII sales, traffic, settlement, listing, inventory, catalog, pricing, order-related, Search Query Performance, Search Catalog Performance, Amazon Search Terms, and Market Basket reports available to that seller account. Brand Analytics reports are accessed only for eligible sellers and their authorized brands, ASINs, and marketplaces.
Amazon advertising data (Amazon Ads API). As authorized by the seller, we access advertising campaigns, ad groups, keywords, targeting, budgets, bids, and advertising performance reports.
Usage and log data. Application logs, sync status, and records of actions taken in the Service, kept for security, support, and auditability.
No buyer personal information. The Service is designed to operate without buyer personally identifiable information. We do not request API permissions for, and do not intentionally collect, buyer names, delivery addresses, phone numbers, shipping labels, or tax invoice documents.
How we use information
We use information to authenticate users, provide account-specific reporting and automation, monitor account and synchronization health, maintain security and audit logs, and respond to support requests.
Amazon data use limitation. Data obtained through Amazon APIs is used solely to provide the Service to the seller account that authorized access. We do not aggregate or combine Amazon data across authorized sellers to provide or sell data, benchmarks, comparisons, or insights to any party, including other sellers. We do not sell Amazon data, use it for third-party advertising, publish or share insights about Amazon's business, or use Amazon-derived insights for OneCommerce's own business purposes.
Write actions. Where the Service performs write actions on a seller's behalf, those actions fall into two categories, both limited to the authorizing seller's own account: (1) advertising optimization through the Amazon Ads API — adjusting campaign budgets and bids, optimizing keyword and auto-targeting bids, adjusting placement bids, creating exact-match keywords from harvested search terms, and creating negative keywords and negative product targets; and (2) sending Amazon's standard "Request a Review" solicitation for eligible orders through Amazon's Solicitations API. Review solicitations are delivered by Amazon using Amazon's own template; we never see or store buyer contact details. All write actions run only with the seller's explicit approval in the Action Center and are fully audit-logged. The Service does not create campaigns or ad groups, add positive product or category targets, or create, update, or delete listings, orders, or any other seller account data.
AI and machine learning processing. The Service uses machine learning models and large language models to analyze a seller's own connected advertising, sales, inventory, catalog, and returns data, and to generate performance diagnosis, wasted-spend findings, product issue signals, and bid and budget recommendations for that seller. This processing runs on infrastructure operated by OneCommerce within our own Amazon Web Services environment, using Amazon Bedrock. We do not send Amazon data to third-party generative AI or large language model providers. We do not use seller data or Amazon data to train, fine-tune, or improve any general-purpose or shared model, and models are not trained on one seller's data to serve another seller. AI output is advisory: recommendations are presented for the seller to review, and no AI-generated change is applied to a seller's Amazon account without the seller's explicit approval in the Action Center. AI-generated analysis may contain errors, and sellers remain responsible for reviewing recommendations before approving them.
Data sharing
We do not sell seller business data. We share information only with infrastructure service providers needed to operate the Service (such as hosting providers) under confidentiality obligations, when required to comply with law or a valid legal process, to protect the security and integrity of the Service, or to fulfill a request made by the seller.
Data security
We protect information with controls that include: encryption of data in transit (TLS) and encryption of Amazon authorization tokens at rest; least-privilege access controls so that personnel access is limited to what their role requires; separation of each customer's data within the Service; and logging and monitoring of access to systems that store Amazon data.
Security incidents. If we become aware of a security incident affecting Amazon data or seller data, we will investigate promptly and notify affected sellers and Amazon as required. To report a suspected security issue, email chris.c@sailwyn.com with the subject line "Security".
Data retention and deletion
Amazon API data is retained for no more than 12 months, except where a longer period is required by applicable law. Data outside the 12-month reporting window is deleted. Sellers may request deletion of their account data at any time as described on our Data Deletion page. Verified deletion requests are completed within 30 days, and residual copies in backups expire within 90 days, subject to legal and security retention requirements. Revoking Amazon authorization stops all future data synchronization for that account.
Cookies
The Service uses only cookies that are necessary for authentication and session management. We do not use third-party advertising cookies.
Changes to this policy
If we make material changes to this policy, we will update this page and revise the date above. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact
For privacy questions or requests, contact OneCommerce Inc. at chris.c@sailwyn.com, or by mail at OneCommerce Inc., 540 W 28th St, Apt 3J, New York, NY 10001, United States.