Firesell
FeaturesSecurityPrivacyContact

Privacy policy

How Maikhana LLC collects, uses, stores, protects, shares and deletes information in Firesell.

Effective 17 September 2026Applies to firesell.app and the Firesell application

Controller
Maikhana LLC, Texas, United States
Where data is held
The United States, by the five providers listed in section 7
Buyer personal information
Not requested and not retrieved — see section 3
Sale of data
None, to anyone, ever — see section 5

Contents

  1. Who we are
  2. Scope
  3. What we collect
  4. How we use information
  5. What we never do
  6. How we store and protect information
  7. Who we share information with
  8. How long we keep it, and how it is deleted
  9. Your rights
  10. Children
  11. Changes
  12. Contact

Who we are#

Firesell is operated by Maikhana LLC, a limited liability company formed in Texas, United States. We are the controller of the information described here. For any question about this policy, write to privacy@firesell.app and a person will answer.

Scope#

This policy covers the Firesell website and application. It covers two kinds of information: information about you as our customer, and information about your Amazon selling account that you authorize us to retrieve on your behalf. We call the second kind Amazon Information, and we handle it under the Amazon Services API Data Protection Policy as well as this one.

What we collect#

Account information

  • Your name, email address and sign-in credentials, which are held by our identity provider. We never see your password.
  • Your organization name, team members and their roles.
  • Billing contact details and subscription records.
  • Messages you send to support.

Amazon Information

When you connect an Amazon selling account, we retrieve only what the roles you granted allow, which may include:

  • Your seller account and marketplace participation details.
  • Listings, product attributes, images, and listing issues Amazon reports.
  • Inventory quantities and fulfillment records, including FBA inventory.
  • Prices and fees for your offers, and the competitive pricing summaries Amazon returns for the products you sell.
  • Order records and their fulfillment status.
  • Financial events, settlement reports and related accounting data.
  • Sales and traffic performance data for your own catalogue.

We do not request roles that grant buyer personally identifiable information, and we do not retrieve buyer names, shipping addresses, phone numbers or email addresses. If a future feature requires them, we will request the appropriate Amazon role, update this policy, and tell you before that feature is enabled.

Technical records

  • Sign-in events, IP address, browser type and timestamps.
  • Application logs recording which operations ran and whether they succeeded.

Credential material is excluded from logs, traces, error reports and background job records by a redaction layer that we test.

Cookies

We set cookies that keep you signed in and remember your workspace. We use no advertising cookies, and we do not track you across other websites.

How we use information#

  • To operate Firesell and carry out the actions you ask it to perform.
  • To show you your catalogue, inventory, orders and financial results.
  • To provide support, and to investigate errors you report.
  • To protect the service against abuse, fraud and unauthorized access.
  • To bill you, and to meet our tax and legal obligations.

What we never do#

  • We do not sell, rent or license your information to anyone.
  • We do not share Amazon Information with advertisers or data brokers.
  • We do not pool one customer’s Amazon Information with another customer’s, and we do not use it to produce aggregated market data.
  • We do not use any customer’s Amazon Information to inform the Amazon selling business operated by Maikhana LLC.
  • We do not use your data to train machine learning models.
  • We do not use browser automation against Seller Central, and we do not scrape Amazon. All access is through registered Selling Partner API applications.

How we store and protect information#

Each protection below carries its grade. Architecture means it cannot happen because of how the system is built; verified by test means a test fails if it stops being true; policy means a decision a person could reverse. Every one also states what would have to become true for it to fail.

  • Policy

    Data is encrypted in transit with TLS 1.2 or higher. Data is encrypted at rest with AES-256.

    Fails if a store were provisioned without encryption at rest.

  • Architecture

    Your Amazon authorization is sealed with envelope encryption using a customer-managed key in AWS Key Management Service, bound cryptographically to your organization and connection. A ciphertext moved between accounts cannot be decrypted.

    Fails if the encryption context stopped binding the ciphertext to your organization and connection, which would take a deliberate change to both the key usage and the storage code.

  • Architecture

    Our web tier can seal a credential but holds no permission to decrypt one. Only background workers decrypt, at the moment of an Amazon call, and every decryption is logged.

    Fails if the decryption permission were added to the web tier’s access policy. A test asserts that the attempt is refused.

  • Architecture

    No interface displays a stored credential to anyone, including our own staff. Credentials are replaced, never revealed.

    Fails if such an interface were built. It cannot be built in the web application, because that tier has no key to decrypt with.

  • Architecture

    Access to the systems that hold your data is split by identity rather than granted by job title: the web tier can encrypt and not decrypt, background workers connect with a restricted database role rather than a blanket service key, and whoever administers the encryption key has no permission to use it on data.

    Fails if a component were granted a permission outside its tier — the blanket database key to a worker, or the decryption permission to the web tier.

  • Policy

    Application secrets are held in the encrypted configuration stores of our hosting providers, never in source code or a repository.

    Fails if a secret were committed to the repository by mistake.

  • Architecture

    Tenant separation is enforced in the database, not only in application code.

    Fails if row-level security were dropped from a tenant table, or a composite foreign key were replaced with a plain one.

What this section does not claim

Firesell holds no SOC 2 report, ISO 27001 certification, third-party penetration test or audit, and we do not operate a security team, an access-review programme, a background-check process or a published password or multi-factor authentication policy. The protections above are properties of how the system is built rather than procedures a team carries out, and we would rather say so than describe an organization we do not have. Our security page sets out the full model, including its limits and the checks that have to pass before we accept a live seller credential.

Who we share information with#

We share information only with infrastructure providers that process it on our instructions under contract:

Infrastructure providers. All store data in the United States.
ProviderPurposeInformation
Vercel Inc.Application hosting and content delivery for the Firesell web application.Application traffic; no seller credentials are readable by this tier.
Supabase, Inc.Managed PostgreSQL database, hosted on Amazon Web Services.Seller account records, catalogue, inventory, pricing and order data, and encrypted credential ciphertext.
Amazon Web Services, Inc.Key management, background processing, object storage and message queues.Encryption keys, queued work, and bulk data files.
Temporal Technologies, Inc. (Temporal Cloud)Durable orchestration of background operations such as imports and updates.Operation metadata and identifiers. Credential material is excluded by a redaction layer.
Clerk, Inc.User authentication, organizations and team membership.Your name, email address and organization membership. No Amazon Information.

All of these providers store data in the United States. We may also disclose information when the law requires it, or to Amazon where an Amazon policy requires us to report an incident. If our business is ever sold or merged, your information would transfer with it, and we would tell you first.

How long we keep it, and how it is deleted#

  • We keep Amazon Information while your account is active and you need it.
  • When you disconnect an Amazon account, the stored authorization is disabled immediately and deleted.
  • When you close your account, we delete Amazon Information within 30 days. Copies held in encrypted backups are removed as those backups expire on their retention cycle.
  • If we ever hold personally identifiable information from Amazon, it is deleted within 30 days of delivery, as the Amazon Data Protection Policy requires.
  • We keep billing and tax records for as long as the law requires, and security logs for up to 12 months.
  • You can ask for an export of your data before you close your account.

Your rights#

You may ask us to give you a copy of the information we hold about you, to correct it, to delete it, or to export it. Write to privacy@firesell.app and we will respond within 30 days. We will verify your identity before acting.

If you are a California resident, you have the rights given by the California Consumer Privacy Act, including the right to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined there, and we do not discriminate against anyone who exercises a right. If you are in the United Kingdom, the European Economic Area or Switzerland, you have the rights given by the UK GDPR or the GDPR, including the right to complain to your supervisory authority.

Children#

Firesell is a business tool. It is not directed to children, and we do not knowingly collect information from anyone under 18.

Changes#

If we change this policy we will post the new version here with a new effective date. If a change materially affects how we handle Amazon Information, we will email the account administrator at least 30 days before it takes effect.

Contact#

Maikhana LLC, Texas, United States.

Privacy
privacy@firesell.app
Security
security@firesell.app
Support
support@firesell.app

Related documents: security · terms of service.

Firesell

  • Features
  • Security

Legal

  • Privacy policy
  • Terms of service

Contact

  • support@firesell.app
  • privacy@firesell.app
  • security@firesell.app

Company

  • Maikhana LLC
  • Texas, United States

Questions about Firesell, or want it tried against your own catalogue? Email support@firesell.app — every message reaches a person, and we answer each one.

Firesell is a product of Maikhana LLC. Amazon and the Amazon Selling Partner API are trademarks of Amazon.com, Inc. or its affiliates. Firesell is an independent application and is not affiliated with, sponsored by, or endorsed by Amazon.com, Inc.