Back to home

Privacy Policy

How commercemon collects, uses, protects, and deletes account and authorized marketplace data.

Last updated: 2026-08-14

1. Scope

This Privacy Policy explains how the operator of commercemon ("commercemon", "we", "us", or "our") handles personal information and seller-authorized marketplace data when you use our website, dashboard, reports, exports, support, and platform connections.

commercemon is an independent software service. It is not Shopee, Lazada, Shopify, TikTok, or any of their affiliates.

2. Information We Collect

Account and workspace information

  • Name, email address, authentication records, language preference, and workspace membership.
  • Support requests, configuration choices, and activity needed to operate and secure the service.
  • Subscription and billing status. Full payment-card details are processed by the selected payment provider and are not stored by commercemon.

Seller-authorized marketplace data

We access marketplace data only after a seller completes the applicable platform authorization process. Depending on the platform, market, seller type, and scopes approved for our application, this may include:

  • Store identifiers, store name, region, status, and authorization metadata.
  • Orders, order lines, timestamps, statuses, prices, discounts, taxes, shipping amounts, cancellations, and refunds.
  • Products, variants, Seller SKUs, prices, stock levels, warehouse or fulfillment status.
  • Returns, reverse-logistics records, settlement statements, transactions, and platform fees when the applicable scope is available.
  • Analytics metrics such as clicks or conversion rate only when the marketplace expressly provides and authorizes those metrics.

Buyer or recipient details may be included by a platform where required for an authorized business purpose. Such fields may be masked, restricted by time, or unavailable under platform policy. We do not attempt to bypass platform masking or access controls.

Connection credentials

We process access tokens, refresh tokens, shop identifiers, regional identifiers, authorization scopes, and token-expiration information needed to maintain a connection. Credentials are encrypted at rest or stored through a protected secret reference and are never included in report exports.

Technical information

We may collect IP address, browser and device information, essential cookies, request logs, error records, and security events needed for authentication, abuse prevention, reliability, and troubleshooting.

3. How We Use Information

We use information to:

  • Authenticate users and operate tenant-isolated workspaces.
  • Retrieve data requested by an authorized seller and keep it synchronized.
  • Normalize marketplace records and produce daily operational views, including documented GMV calculations.
  • Provide filters and exports for a store, date range, or authorized portfolio.
  • Refresh or revoke connection credentials and notify users about connection errors.
  • Provide support, process subscriptions, secure the service, and comply with law and marketplace developer terms.

We do not sell marketplace data or personal information. We do not use seller-authorized data to build advertising audiences or to train general-purpose AI models.

4. Data Sources and Authorization

Marketplace data comes from official developer interfaces after seller authorization. A connection does not grant access beyond the scopes approved by the marketplace and the seller. Available fields can differ by country, account type, fulfillment model, and platform policy.

You may disconnect a store in commercemon and may also revoke access through the relevant marketplace account or Seller Center. Revocation stops future collection after the platform notifies us or our next authorization check detects it.

5. Sharing and Service Providers

We disclose information only as needed to operate the service, including to:

  • The marketplace whose API you direct us to use, for authorization, token refresh, and requested API calls.
  • Cloud hosting, database, storage, security, monitoring, and transactional-email providers acting on our instructions.
  • Payment processors for subscriptions purchased outside the marketplace, where permitted.
  • Professional advisers, regulators, courts, or authorities when required by law or necessary to protect users and the service.

Service providers receive only the information reasonably required for their function and are expected to protect it under contractual and legal obligations.

6. Retention and Deletion

We retain account and marketplace data while the account or connection remains active and for only as long as reasonably needed to provide reports, resolve synchronization issues, meet contractual or legal duties, and protect the service.

When a store is disconnected, we stop future synchronization. You may request deletion of stored marketplace data and your account through the in-product support channel. We may retain limited billing, security, audit, or legal records where required, and residual copies may remain temporarily in encrypted backups until their normal rotation completes.

7. Security

We use HTTPS, encrypted connector credentials, tenant-level authorization checks, least-privilege access, input validation, and operational logging. No system can guarantee absolute security. Users are responsible for protecting their account credentials and promptly reporting suspected unauthorized access.

8. International Processing

commercemon may process information in countries other than your own through our infrastructure and service providers. Where required, we use appropriate contractual, organizational, and technical safeguards for cross-border processing.

9. Your Choices and Rights

Subject to applicable law, you may request access, correction, export, restriction, objection, or deletion of your personal information. You can also revoke a marketplace connection at any time. Submit requests through the signed-in support channel so we can verify the requester and affected workspace.

10. Children

The service is intended for businesses and authorized adult users. It is not directed to children.

11. Changes

We may update this Policy as the service, marketplace requirements, or laws change. We will update the date above and provide additional notice when a material change requires it.

12. Contact

For privacy questions, data-access requests, or deletion requests, use the support function available in the commercemon dashboard. The operator's legal entity name, registered address, and privacy contact email will also be published here before public commercial launch.