Privacy policy
Last updated 30 July 2026
Scanvio is operated by TSN Tech & Strategy Network. This policy describes what we collect, why, how it is protected, and when it is deleted. It is written to be specific: where a limit applies, the actual number is given.
What we collect
Your account. Email address and a password, stored only as a bcrypt hash. We can never read your password.
Your Amazon connection. When you connect your Amazon Seller account, we store the refresh token Amazon issues, encrypted. We do not receive or store your Amazon password.
Your scanning and listing activity. Books you scan, the verdicts produced, prices observed on Amazon, listings you create, shipments you build, and repricing decisions made on your behalf.
Your business details. The ship-from address you enter for FBA shipments, and billing details held by Stripe.
Security records. Sign-in attempts (email, IP address, success or failure) and a log of every request we make to Amazon on your behalf.
What we do not collect
We never receive Amazon customer or buyer data.Scanvio does not call Amazon's Orders, Reports or Finances APIs, and does not request Restricted Data Tokens. No names, addresses or contact details of Amazon buyers reach us at any point.
We never see your card number. Payments go directly to Stripe; card details do not touch our servers.
How we use it
To run the product you signed up for: judging whether a book is worth buying, listing it on Amazon, keeping it priced against competing offers, and building FBA shipments. Amazon data is used only to provide those features to you, the seller it belongs to.
We do not sell your data, and we do not use one seller's data to advantage another. Book catalogue details and sales-rank history — facts about products, not about people — are shared across accounts so that a book someone has already scanned loads faster for everyone. Your own scan history, the prices you recorded, your listings and your shipments are yours alone and are never visible to another seller.
How it is protected
Amazon refresh tokens are encrypted at rest with AES-256-GCM. API tokens are stored as SHA-256 hashes and shown to you exactly once. Passwords are bcrypt-hashed. Everything else sits in a managed PostgreSQL database encrypted at rest.
All traffic uses HTTPS. Accounts lock for 15 minutes after ten failed sign-in attempts. Access to production systems is limited to the operator named below, over accounts protected by multi-factor authentication.
Who it is shared with
We use a small number of processors, each for one job:
- Amazon (SP-API) — to read prices and manage your listings and shipments
- Vercel — hosting
- Supabase — the database
- Stripe — subscriptions and marketplace payouts
- Inngest — background jobs
- Amazon Web Services (SQS) — receiving price-change notifications
- Shippo — shipping labels for the Scanvio storefront
We disclose data otherwise only where the law requires it. We do not share it with advertisers.
How long it is kept
- Storefront buyer shipping addresses — erased 30 days after delivery is confirmed
- Sign-in records and Amazon request logs — 13 months, then deleted
- Observed prices and sales-rank history — 18 months
- Your Amazon refresh token — until you disconnect Amazon or close your account, whichever comes first
These limits are enforced by an automated daily job, not by anyone remembering to run something.
Your choices
You can disconnect Amazon at any time in Settings, which revokes our access. You can delete your listings and shipments yourself. To request a copy of your data or deletion of your account, email us — we will act within 30 days.
Deleting your account removes your personal data. Anonymous product facts — that a particular book had a particular price on a particular day — are retained, as they identify no one.
Children
Scanvio is a business tool and is not directed at anyone under 18.
Changes
If this policy changes materially we will email account holders before it takes effect. The date at the top always reflects the current version.
Contact
Questions about privacy, data access or deletion: info@scanv.io
TSN Tech & Strategy Network — the same address is the security contact for reporting a vulnerability or suspected incident.