Privacy Policy
Last updated: 7 August 2026
This policy explains what personal data we collect when you use TrueMargin, why we collect it, who we share it with, how long we keep it, how we protect it and what rights you have. TrueMargin is a profit-analytics service for Amazon sellers, so most of the information we handle is your own business data rather than data about consumers. It is written to be read together with the Turkish clarification notice published at https://truemargin.com.tr/kvkk and alongside the Terms of Service at https://truemargin.com.tr/terms.
1. Who we are and how to contact us
TrueMargin is operated by Tars LLC, a limited liability company organized under the laws of the State of Wyoming, United States, with Wyoming Secretary of State filing number 2026-002000733 and its registered office at 30 N Gould St # 21464, Sheridan, WY 82801, United States (referred to in this policy as “we” or “us”). We are the controller of the personal data described here. You can contact us about any privacy matter, including a request to exercise your rights, by email at contact@tarslimited.com.
This policy covers the marketing website at https://truemargin.com.tr, the application at https://app.truemargin.com.tr and the TrueMargin browser extension.
Tars LLC is an independent solution provider. It is a separate legal entity from Amazon and from the Amazon selling partners who use the service: we are not Amazon, and we are not affiliated with, endorsed by or acting on behalf of Amazon. Our access to Amazon data exists only because an individual seller has authorized our application, and it exists only for as long as that authorization does.
2. Data we collect
We collect only the data we need in order to run your account, produce your analytics and keep the service secure. In detail:
- Account data: your first and last name, your email address, your telephone number (required when you create an account; you can clear it later from your profile), your password (kept only as a bcrypt hash and never in readable form), your chosen avatar, your interface preferences such as language, theme, time zone, date format and reporting currency, and the date on which you accepted our notices when you signed up.
- Amazon business data that you connect or import: your orders and order lines, your products, your FBA inventory levels and the related fee and cost figures, together with your Amazon seller identifier, the marketplaces you sell in and the Amazon region you select. This data reaches us either through the Selling Partner API after you authorize us, or from a CSV file that you upload yourself.
- Tax and invoicing data: your country of establishment, whether you sell as a company or as an individual, your VAT or GST registration status and registration numbers for each marketplace, and, if you buy a paid plan, your company name, tax number, tax office and invoicing address.
- Billing and subscription data: the identifiers of your Stripe customer record, subscription and invoices, invoice amounts and links, and the brand, last four digits and expiry date of your payment card. The full card number and the security code never reach our servers at all.
- Technical and security data: your IP address and browser user-agent string, your session and trusted-device records, an audit record of security-relevant events such as sign-in, password change, session revocation and account deletion, and a log of the service emails we send you.
- Content you create in the service: products you save from the browser extension, including the ASIN, marketplace, title, image, category and sales rank, the address of the Amazon page you saved it from, your own notes and your cost figures; your cost entries and alert thresholds; and the file name of the CSV files you import together with the row numbers and error messages of any rows that could not be imported.
- Invitation data: if you invite a colleague to your workspace, we store the email address and the optional name you enter for that person so that we can deliver the invitation.
3. Amazon information
TrueMargin connects to Amazon only after you authorize it yourself. You start the connection inside TrueMargin, Amazon shows you its own consent page in Seller Central, and Amazon then returns an authorization to us. We never ask you for your Amazon password or your Seller Central sign-in details and we never accept them; the connection is made only through Amazon's own authorization flow. So that we can match the returned authorization to the right account, a signed parameter passes through Amazon's consent page containing your TrueMargin user identifier and the details of the connection you started — the name you gave the store, the region and the marketplaces you selected. It is signed so that it cannot be tampered with, and it contains no other personal data.
Through that authorization we retrieve a deliberately narrow set of commercial data:
- Order-level data: the Amazon order number, the purchase and update dates, the order status, the marketplace, the fulfilment channel, the sales channel, the currency and the order totals.
- Order line data: the seller SKU, the ASIN, the product title, the quantity and the price, tax, shipping, gift-wrap and promotion amounts.
- Fee data from the Finances API: the referral fee, the FBA fees and other fee components belonging to your own orders.
- FBA inventory data: your own inventory quantities per SKU.
We do not collect Amazon buyer personal information. TrueMargin never requests buyer names, buyer email addresses, telephone numbers or shipping addresses; no order or order-item record we store has a column for any of them; and the application never obtains a Restricted Data Token, which is the mechanism Amazon requires before it will release information of that kind. If you upload an Amazon report that happens to contain buyer columns, those columns are ignored and never stored. Amazon data therefore reaches us as commercial and financial figures about your business, not as information about your customers.
Amazon information is used for one purpose only: to produce profit, margin, fee, cost and inventory analytics inside the account of the seller who authorized it. In particular:
- We do not sell Amazon information, and we do not share it with anyone for advertising or marketing purposes.
- We do not combine or aggregate one seller's Amazon data with another's in order to create benchmarks, market reports or any other product or service.
- We do not use Amazon information to train machine-learning or artificial-intelligence models, whether for ourselves or for any third party.
- We do not use Amazon information to compete with you or to make decisions about your Amazon business.
- Access is limited to the authorized personnel of Tars LLC, and to any contractors acting on our behalf under written confidentiality and data-protection obligations, who operate, secure and support the service, and only where such access is necessary for those purposes.
You can withdraw the authorization at any time and you do not need our permission to do so. You revoke it in Amazon Seller Central, on the page where you manage the applications you have authorized.
Once you revoke the authorization in Seller Central we can no longer retrieve data with it, and the next time a synchronisation runs the connection is marked as disconnected in TrueMargin. Revoking the authorization does not by itself erase what has already been imported. The stored authorization record, which is held in encrypted form, together with the imported order, product and inventory data, is deleted when you remove the connected Amazon store inside TrueMargin, when you delete your TrueMargin account, or when you ask us to delete it at contact@tarslimited.com — in which case we do so within 30 days of your request.
4. How we use your data
- To provide the service: calculating profit, margin, fees, taxes and costs, and producing the dashboards, tables, reports and alerts you use.
- To operate your account: authenticating you, sending two-factor codes, managing sessions, trusted devices and workspace members.
- To handle billing: creating and managing subscriptions, issuing invoices and tracking the provider credits your queries consume.
- To keep the service secure: recording security events, limiting repeated attempts against sign-in and password endpoints, and warning you by email when a sign-in occurs from a new device.
- To communicate with you about the service: email address verification, security notices, invoices, workspace invitations and the alerts you have chosen to receive. These messages are service messages, not advertising.
- To comply with legal obligations, including accounting and tax requirements, and to establish, exercise or protect a legal right.
- To keep the service working: diagnosing faults that are reported to us and maintaining our servers.
We do not use your data for advertising profiles, and we do not carry out automated decision-making that produces legal effects for you.
5. Legal bases and the Turkish KVKK notice
Where data protection law requires us to identify a legal basis for processing, we rely on the following:
- Performance of a contract: creating and running your account, providing the analytics you subscribe to, and handling billing and support.
- Legitimate interests: keeping the service and your account secure, preventing abuse of our sign-in and sign-up endpoints, keeping records of security-relevant events, and establishing, exercising or protecting a legal right.
- Legal obligation: keeping accounting and tax records and responding to lawful requests from competent authorities.
- Explicit consent: the notices you accept when you sign up. You can withdraw your consent at any time by writing to contact@tarslimited.com or by deleting your account; withdrawal does not affect processing already carried out.
If you are in Türkiye, the Turkish-language clarification notice published at https://truemargin.com.tr/kvkk is our statutory notice under Law No. 6698 on the Protection of Personal Data. It is written to meet the disclosure requirements of that law and is shorter than this document. This policy is the complete description of the personal data we process and of what we do with it, for readers in Türkiye and elsewhere alike, and it is the description we apply wherever the statutory notice is briefer. Neither text replaces or narrows the other. If you believe the two are inconsistent, write to contact@tarslimited.com and we will correct it.
6. The browser extension
The TrueMargin browser extension displays profit calculations on Amazon product pages. It is optional: it works only if you install it and pair it with your account.
- It stores its access key, the address of our API and your theme and language choice in the browser's synchronised storage, and a randomly generated per-installation device identifier in the browser's local storage. Please note that Chrome synchronises the first of these through your Google account, so a copy of the key can exist on the other browsers where you are signed in; the device identifier is never synchronised.
- It requests only the storage and active-tab permissions, and it runs only on five Amazon marketplace sites and on our own addresses.
- On the Amazon product page you are viewing, it reads what that page makes available in your browser: the title, image, price, brand, seller, rating, availability, category breadcrumb, the listed dimensions and weight, and the page’s own view of the other offers for the same product. All of that stays inside the Amazon tab you have open and inside your own visit to Amazon — the panel uses it to draw a calculation on your screen, and none of it is sent to us.
- The data it collects is sent only to our own API, and it reaches us at four moments. When the panel opens it asks our servers for your saved settings, the day’s exchange rates and our product record for the ASIN you are looking at, so the ASIN and the marketplace reach us then. When you press refresh, it asks our servers to fetch that product’s data again, sending the ASIN, the marketplace and which additional figures you want included. When you ask the panel for the list of competing offers, the ASIN and the marketplace are sent to us and our servers fetch the list from a licensed product-data provider, not from your browser. When you press save on a product, it sends us the ASIN, the marketplace, the title, the image, the category, the address of the Amazon page you are on, your notes and your cost figures.
- The addresses it is permitted to talk to are fixed in its code, so a tampered configuration cannot send your key anywhere else. Each request to us carries your personal extension key and the per-installation device identifier.
You can revoke the extension's key at any time from your account settings, and changing your password revokes it automatically.
7. Cookies
We use three cookies. None of them is used for advertising or tracking.
- tm_session keeps you signed in. It is HttpOnly and SameSite=Lax, it is transmitted over HTTPS in production, and it lasts 30 days if you choose to be remembered and 24 hours if you do not.
- tm_trusted is set only if you tick the trust-this-device option during two-factor authentication, so that you are not asked for an emailed code on that browser for 30 days. We store only a hash of its value.
- tm-locale remembers whether you want the interface in Turkish or English. It lasts one year and is shared between the marketing site and the application so that your language choice follows you.
The first two cookies are strictly necessary for authentication and the third stores a preference. We do not use Google Analytics, Google Tag Manager, advertising pixels, session-replay tools, A/B-testing tools or any third-party analytics or error-reporting service: no such code exists in the website, the application or the browser extension. Web fonts are served from our own servers rather than being fetched from a font provider while you browse.
8. Service providers and international transfers
We do not sell personal data. We share it only with the service providers we need in order to run TrueMargin, and only to the extent each of them needs:
- Amazon (Selling Partner API and Login with Amazon): the source of the seller data you authorize. We send your authorization token and query parameters such as marketplace identifiers and date ranges. We do not send Amazon any personal data about you beyond the signed connection parameter described in the Amazon information section.
- Stripe: payments and subscription management. Stripe receives your email address, your name and our internal user identifier. Card details are entered on Stripe's own pages, not on ours.
- Resend: delivery of service emails. Resend receives the recipient address, the subject and the message body. Security emails about a sign-in from a new device contain the IP address and browser user-agent of that sign-in.
- EasyParser: Amazon product data lookups. It receives our own API key and the query itself, such as an ASIN, a search term or an Amazon seller identifier. It receives no identity data about you.
- Keepa: product and price history. It receives our own API key and the ASIN. It receives no identity data about you.
- Frankfurter: daily European Central Bank exchange rates. The request contains no user data at all.
- Google, in one limited case: our HTML emails reference a font stylesheet hosted by Google. If your email program loads remote content, Google can see your IP address and email-client details at that moment. The website and the application make no such request.
- Third-party image hosts, if you choose one: if you set your avatar to an image hosted elsewhere, the browser of anyone who views it will request the image from that host, and that host will see their IP address.
These providers operate internationally, and the Amazon endpoint we call depends on the region you select for your seller account, which may be North America, Europe or the Far East. Your data may therefore be processed outside Türkiye. Where we transfer personal data abroad we do so because it is necessary in order to perform our contract with you and to provide the features you have asked for. Apart from the providers listed above, we disclose personal data only where the law obliges us to do so.
9. Where your data is stored
TrueMargin does not run on a third-party cloud database. All account and business data is stored in a PostgreSQL database that we host ourselves on our own server, and it can be reached only through the application; the database is not exposed to the public internet. Traffic between your browser and the service is encrypted with TLS, terminated by our own reverse proxy using certificates issued by Let's Encrypt.
We take a daily backup of the database and keep fourteen days of backups. Because of this, data that has been deleted from the live database can still exist inside a backup file for up to fourteen days before that file is rotated out.
10. Retention and deletion
We keep personal data for as long as your account is active, and after that only for as long as we are required to keep it in order to meet legal or accounting obligations or to establish, exercise or protect a legal right. Where our systems apply a fixed period, it is one of the following:
- Security audit records: 365 days.
- Service email records, including the recipient address, subject and delivery status: 365 days.
- Price-history provider fetch logs: 180 days. Note that the credit-usage ledger, which records which operation you ran and which ASIN you looked up, is separate from these logs and is kept for as long as your account exists — see the paragraph below.
- Expired sessions, used or expired one-time codes and verification tokens, and revoked or expired trusted devices: removed by a housekeeping job that runs daily.
- Time-limited items expire on their own: sign-in sessions after 30 days if you chose to be remembered and otherwise after 24 hours, trusted devices after 30 days, emailed one-time codes after 10 minutes, password-reset links after 1 hour, email verification links after 24 hours and workspace invitations after 7 days.
Your orders, products, inventory records, saved products and credit-usage records are the working data of your account. They are kept while the account is active, so that the analytics keep the history they are built on, and they are not retained beyond the life of the account: Amazon information is never kept for its own sake, and it is never kept after you remove the store it belongs to. You stay in control of it — removing a connected Amazon store deletes that store and the Amazon data synced into it, including its orders, products and inventory, and deleting your TrueMargin account deletes everything, including your saved products and your credit-usage records.
If you ask us to delete data we hold about you, or if Amazon requires us to delete information we obtained through the Selling Partner API, we delete that data permanently and securely within 30 days of the request, except where we are legally obliged to keep it. Write to contact@tarslimited.com from the address registered to your account.
You can delete your account yourself from the Security tab of your profile settings. Deletion requires your password and a fresh one-time code sent to your email address, even if you have switched two-factor authentication off. It takes effect immediately and cannot be undone: there is no grace period and no recovery window.
Deleting your account removes your user record and everything attached to it, including your sessions, trusted devices, preferences, seller and billing profiles, saved products, extension keys, subscriptions, invoices, payment-method records and import jobs. It also deletes any connected Amazon seller account of which you were the only member, together with its orders, products, inventory and the stored Amazon authorization, and it deletes your customer record at Stripe. A seller account that you share with other members is not deleted; only your membership in it is removed.
Two categories survive account deletion for a limited period, and we prefer to state this plainly: security audit records are kept, without your user identifier, until they reach 365 days, and service email records retain the recipient address until they reach 365 days. Backup files may also contain your data for up to fourteen days, as described above.
11. How we protect your data
- Passwords are hashed with bcrypt at cost factor 12 and are never stored or logged in readable form. A new password must be at least 12 characters long and must contain at least one letter and one number.
- Two-factor authentication by emailed code is switched on by default for every new account, and switching it off also requires a code.
- Only one session can be active per account: signing in somewhere new revokes every other session. You can list and revoke your sessions and trusted devices yourself, and changing your password revokes all other sessions and all browser-extension keys.
- Session, trusted-device, verification, invitation and extension-key tokens are stored only as SHA-256 hashes, never in their original form. Emailed codes are hashed as well, expire after 10 minutes, allow at most five attempts and are compared in constant time.
- The Amazon authorization token and our provider API keys are encrypted with AES-256-GCM before they are written to the database, using a dedicated encryption key that must be configured separately in production.
- The service is served over HTTPS only, with HTTP Strict Transport Security and a content security policy. We also send security headers that prevent the page from being placed in a frame, restrict referrer information and switch off camera, microphone and location access.
- Sign-in, password, session, billing and deletion events are written to an audit record, and we email you when a sign-in happens from a device we have not seen before.
- Sign-in, sign-up, password-reset and code-entry endpoints are rate limited, and sign-in responses are deliberately timed so that they do not reveal whether an email address is registered with us.
If we become aware of a security incident affecting Amazon information, we will notify Amazon within 24 hours of detecting it, in line with the incident response plan we keep in force. Where a personal data breach meets the notification criteria of the applicable law, we will notify the competent authority and the affected individuals in accordance with the requirements and time limits of that law, and we will tell you what happened and what you should do about it.
12. Your rights and how to exercise them
Depending on where you are, you have the right to obtain a copy of the personal data we hold about you, to have inaccurate data corrected, to have your data erased, to receive it in a portable form, to object to or ask us to restrict certain processing, and to withdraw a consent you have given.
You can do much of this yourself inside the application: you can edit your profile, change your email address and your password, manage your sessions and devices, export your tables as CSV files, remove a connected Amazon store — which also deletes the orders, products and inventory imported into it — and delete your account outright. For anything else, write to contact@tarslimited.com from the address registered to your account. We will identify you, respond without undue delay and in any event within the period required by the law that applies to you, and we will not charge you for a reasonable request.
If you are in Türkiye, Article 11 of Law No. 6698 sets out your rights in respect of your personal data, including the right to learn whether your data is being processed, to request information about the processing, to request correction or erasure and to have such requests communicated to third parties to whom the data has been transferred. You may exercise those rights through contact@tarslimited.com as described in the notice at https://truemargin.com.tr/kvkk, and you have the right to complain to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu). If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local supervisory authority.
13. Children
TrueMargin is a business tool for Amazon sellers. It is not directed at children and we do not knowingly collect personal data from anyone under the age of 18. If you believe that a child has provided us with personal data, write to contact@tarslimited.com and we will delete it.
14. Changes to this policy
We may update this policy when the service changes or when the law requires it. The date shown at the top of this page always reflects when the policy was last changed.
If a change materially affects how we handle your personal data, we will tell you by email to the address registered to your account, or through a notice inside the application, before the change takes effect. If you continue to use TrueMargin after a change takes effect, the updated policy applies to your use of the service.
Contact
Questions about this document can be sent to the operator of TrueMargin:
Tars LLC
30 N Gould St # 21464, Sheridan, WY 82801, United States
Registered in: Wyoming · 2026-002000733
contact@tarslimited.com
+44 7576 034 999