Este documento está disponible en inglés y en polaco.
Privacy policy
1. Data controller
The controller of personal data processed in BidBeacon (beacon.lalill.eu) is LALILL GROUP sp. z o.o., ul. Krzywa 4, 64-920 Piła, Poland, entered in the Polish National Court Register (KRS) under no. 0000928824, VAT ID PL7642706604, REGON 520268540.
Contact for data protection matters: ue.nocaebdib@olleh, phone 777 797 497 84+.
2. What data we process
- Account data: email address, full name, company name, VAT number, a hash of your password (the password itself is never stored), app settings and your chosen language.
- Billing data: your plan, orders, payment status and invoicing details (company name, address, VAT number). We never see or store payment card details – they are processed by Stripe.
- Files and analysis results: the reports you upload (Amazon Ads, sales, product costs, orders, transactions) and the reports and recommendations generated from them.
- Technical data: IP address and browser information in the server logs, session identifier.
- Correspondence: data you provide by email or phone, including before you create an account.
The Seller Central orders report may contain data about your customers (e.g. shipping city and postcode). We do not need or use this data for the analysis – we process it only as part of the file you upload, on your behalf (see section 6).
3. Purposes and legal bases
- Creating and running your account, performing analyses and providing the service – Art. 6(1)(b) GDPR (contract).
- Invoicing and accounting – Art. 6(1)(c) GDPR (legal obligation).
- Security of the service, preventing abuse, establishing and defending legal claims – Art. 6(1)(f) GDPR (legitimate interest).
- Account-related emails (e.g. password reset) – Art. 6(1)(b) GDPR.
- A few tips emails during the trial (getting started, analysis results, end of trial) – Art. 6(1)(f) GDPR (our legitimate interest in helping you use the service). You can unsubscribe with one click in the footer of each email.
- Referral programme – we record who referred an account in order to grant the reward – Art. 6(1)(b) GDPR.
- Answering enquiries before an account is created or a contract is concluded – Art. 6(1)(b) GDPR (steps prior to entering into a contract), otherwise Art. 6(1)(f) GDPR (legitimate interest in handling correspondence).
We do not send newsletters or advertising and we do not profile users.
4. Amazon Ads connection
Instead of uploading reports, you can connect your Amazon Ads account using Login with Amazon. The connection is only possible after you explicitly authorise it with Amazon – we never learn your password.
- What we retrieve: the list of your advertising profiles (marketplace, currency, account name) and the Sponsored Products reports needed for the analysis: campaigns, ad groups, keywords and targets, search terms, advertised products (ASINs), impressions, clicks, costs, sales and orders.
- Purpose: solely to perform analyses and recommendations for you. We do not share this data with third parties, do not sell it and do not combine it with other customers' data.
- Protection: access tokens are stored encrypted, and the encryption key is kept outside the database. Retrieved reports are accessible only to your account.
- Retention: tokens – until you disconnect; retrieved reports – like other analysis files (section 7).
- Disconnecting: at any time under "Amazon Ads" in the app – we then delete the tokens and stop retrieving data. You can also revoke access in your Amazon account settings.
You always approve changes to your campaigns.
Sales connection (Selling Partner API). On the same terms you can connect a Vendor Central or Seller Central account – you grant consent with Amazon and never give us your password or keys. We only retrieve the reports the analysis needs for the period you choose: for Vendor – sales per ASIN (units, revenue, cost of goods, returns); for Seller – the order report in the version without buyers' personal data (order ID, date, product, quantity, price, tax, and shipping city, postcode and country – see the terms, §7). Tokens are stored encrypted; you can disconnect under "Amazon sales" in the app or in Amazon ("Manage Your Apps").
5. Recipients
- Hosting and email provider: ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Niemcy / Germany – servers in the European Union.
- Payment provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland – for card payments. Stripe processes payment data as an independent controller and may transfer it to Stripe entities in the USA under GDPR transfer mechanisms (including the EU-U.S. Data Privacy Framework and standard contractual clauses). Details: stripe.com/privacy.
- Our accountants, the Polish National e-Invoicing System (KSeF) and public authorities – to the extent required by law.
Apart from the Stripe case described above, we do not transfer data outside the European Economic Area. If you connect your Amazon Ads account (section 4), the service retrieves campaign data from Amazon's infrastructure; on Amazon's side that data is processed under your agreement with Amazon and its privacy notice. The website does not use third-party fonts, analytics tools or advertising scripts. Exchange rates are retrieved from the European Central Bank and the National Bank of Poland without sending any user data.
6. Your customers' data in uploaded files
For personal data contained in files you upload (e.g. the orders report), you are the controller and we process that data on your behalf solely to perform the analysis. The terms of this processing are set out in § 7 of the Terms of Service.
7. How long we keep data
- Files uploaded for an analysis or downloaded from Amazon (advertising reports, sales, price lists used in the analysis) – 90 days after the analysis, then deleted automatically.
- Reports generated by BidBeacon (Excel, upload file) – 365 days after the analysis.
- Account data and analysis results stored in the app (figures, recommendations, history) – until your account is deleted. You can ask us to delete individual analyses earlier.
- Billing data – for the period required by tax law (generally 5 years from the end of the tax year).
- Server logs (including IP addresses) – up to 30 days, then deleted.
- Bot protection on forms (sign-up, login, password reset) – instead of a third-party CAPTCHA, your browser solves a short computational task; for attempt limits we store a one-way hash of the IP address (not the address itself) for 24 hours – Art. 6(1)(f) GDPR (security of the service).
- Correspondence – up to 12 months after the matter is closed, or for the duration of the contract if one is concluded.
8. Cookies
We only use cookies that are strictly necessary for the service to work, so we do not ask for consent:
bbsess– login session, deleted when you close the browser;bb_lang– your chosen language, kept for one year.
9. Security
Connections to the service are encrypted (HTTPS), passwords are stored only as hashes, customer files are not accessible from the internet and every user can access only their own data.
10. Your rights
You can exercise most rights yourself under "Account" in the app: change your data, download all your data (export) and delete your account. After deletion we keep only the payment history to the extent required by tax and accounting law (Art. 6(1)(c) GDPR).
You have the right to access, rectify and erase your data, to restrict its processing, to data portability and to object to processing based on legitimate interest. To exercise these rights or delete your account, email ue.nocaebdib@olleh. You can also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw), or with the authority in your country.
Providing data is voluntary, but you cannot create an account without an email address and password.
11. Changes
We will inform you of material changes to this policy by email or in the app. The current version is always available on this page.