Legal

Privacy policy

How Mabi Labs collects, uses, stores, protects, shares and deletes data in Mabi Data Intelligence, including data received from Amazon's Selling Partner API and the other platforms our customers connect.

Effective 21 August 2026 · Version 1.0

1. Who we are and what this policy covers

Mabi Data Intelligence (the "application") is a commerce analytics service operated by BIUK Brands Ltd, a company registered in England and Wales (company number 15048258, registered office Unit C1A, Poole Hall Road Industrial Estate, Ellesmere Port, CH66 1ST, United Kingdom), trading as Mabi Labs ("Mabi Labs", "we", "us"). This policy covers this website (mabilabs.io), the application, and the data we receive from platforms that our customers authorise us to read: Amazon Seller Central and Amazon Ads, Shopify, eBay, Meta, Google, Xero, Brevo, PayPal and Clearpay.

For data held in a customer's workspace, the customer (the business that connected the platforms) is the data controller and Mabi Labs is the data processor acting on its instructions. For account data of the people who log in, and for this website, Mabi Labs is the controller. We comply with the UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR.

2. In short

  • We process platform data only to provide analytics to the business that authorised the connection.
  • We do not sell data, use it for advertising, pool it across customers, or use one customer's data to benefit another.
  • We do not request or hold Amazon buyer personal information. Amazon data in the application is order, financial, inventory, catalogue, advertising and aggregated Brand Analytics data.
  • Everything is hosted in the EU (Frankfurt), encrypted in transit and at rest, and deleted when a connection is removed or a subscription ends.

3. Data we process

3.1 Account data

Name, work email address, hashed password, workspace membership and role, invitation and login events, and an audit log of administrative actions. Provided by the person creating the account or by the workspace owner who invites them.

3.2 Connected platform data

Read from each platform after the customer authorises the connection through that platform's own consent flow. We request the minimum permissions needed for the features described on this site.

PlatformData readPersonal data?
Amazon Seller Central (Selling Partner API)Orders and order items (order identifiers, dates, amounts, status, fulfilment channel, marketplace), financial events and settlements (fees, refunds, reimbursements, chargebacks), inventory and listings, catalogue attributes, business and Brand Analytics reports (Sales & Traffic, Repeat Purchase, aggregated by day or month and by ASIN), Subscribe & Save metrics from the Replenishment API.No. We do not hold the roles that return buyer names, addresses, email addresses or phone numbers and we do not request them.
Amazon AdsCampaign, ad group, keyword and search-term performance; budgets; listing status for advertised products.No.
ShopifyOrders and line items, including the customer identifier, email address and the shipping region as supplied by Shopify; products and variants; payouts, transactions and fees; inventory levels.Yes: customer identifier, email and shipping region of the customer's shoppers, used only to distinguish new from returning customers and to match payments to orders.
eBay, PayPal, ClearpayTransaction and settlement statements uploaded as CSV by the customer.May include buyer names or identifiers if present in the file. We use only the order reference and the amounts.
Meta Ads, Google AdsCampaign, ad-set and ad performance metrics; campaign dimensions; product catalogue mapping.No.
Google Analytics 4Aggregated sessions, source and medium, conversions.No.
XeroInvoices, bills, bank transactions, account codes and contacts needed for reconciliation.May include names of suppliers and contacts as recorded by the customer in Xero.
BrevoCampaign and automation statistics and attributed revenue.No. We do not read subscriber lists.
Customer uploadsProduct cost (COGS) files, fixed-cost schedules and similar business data the customer chooses to import.Not normally.

3.3 Technical data

Server and security logs (IP address, user agent, timestamps, request path), error reports and sync-job records. Logs do not contain platform tokens or report contents.

4. Why we use it and on what legal basis

  • To provide the service (performance of a contract): syncing, storing and presenting the customer's data in dashboards, reports, alerts and exports.
  • To run the application securely (legitimate interests): authentication, access control, audit logging, rate limiting, fraud and abuse prevention, backups.
  • To support customers (contract and legitimate interests): answering questions about a figure, tracing a number to its source.
  • To meet legal obligations: tax, accounting and regulatory record-keeping, responding to lawful requests.

We do not use customer data to train machine-learning models, to build benchmarks across customers, to profile individuals, or for marketing to anyone other than the customer's own designated contacts about the service itself.

5. Amazon data: specific commitments

Where data is received through the Selling Partner API or the Amazon Ads API, we additionally commit to the following, consistent with Amazon's Acceptable Use Policy and Data Protection Policy:

  • Amazon information is used solely to provide the analytical services described on this site to the Selling Partner who authorised access, and for no other purpose.
  • It is not aggregated with other Selling Partners' data, not used to derive insights about Amazon or other sellers, not used for advertising or marketing, and not sold, rented, licensed or otherwise disclosed to third parties except the subprocessors in section 7 that host the service.
  • We do not request or retain Personally Identifiable Information about Amazon buyers. If any such information ever reached us (for example inside a customer-uploaded file), we would delete it within 30 days of receipt unless retention were required by law.
  • Access tokens are stored encrypted, are never logged or shown in the interface, and are revoked when the connection is removed. Selling Partners may also revoke access at any time from Seller Central under Apps and Services.
  • Amazon information is stored on encrypted volumes in the EU, accessible only to authorised Mabi Labs personnel over authenticated, logged connections, and is deleted within 30 days of the connection being removed or the subscription ending.
  • Security incidents involving Amazon information are reported to Amazon within 24 hours of detection, and to the affected Selling Partner without undue delay.

6. Storage and security

  • Location. Application servers run on Vercel in Frankfurt, Germany. The database is a managed PostgreSQL service (Neon) in AWS eu-central-1, Frankfurt.
  • Encryption. TLS 1.2 or higher on every connection. Data is encrypted at rest by the hosting providers. Platform credentials are additionally encrypted at the application layer and held only in the environment of the running service.
  • Access. Role-based access inside the application; every record scoped to its workspace; administrative actions logged. Production access for Mabi Labs staff is limited to named engineers, uses multi-factor authentication and is logged.
  • Resilience. Automated database backups, retained for up to 30 days, in the same region.
  • Development. Customer data is not copied to developer machines; development and testing use separate databases.

7. Sharing and subprocessors

We share data only with the providers that host and deliver the service, under contracts that bind them to process it only on our instructions:

ProviderPurposeLocation
Vercel Inc.Application hosting, scheduled jobs, logsFrankfurt, Germany (eu-central / fra1)
Neon Inc.Managed PostgreSQL databaseAWS eu-central-1, Frankfurt, Germany
Resend Inc.Transactional email (invitations, password resets)EU and US; recipient email address only
Slack TechnologiesAlert digests, only if the customer connects a Slack webhook; contains aggregated figures, no platform credentialsPer the customer's Slack workspace

The connected platforms (Amazon, Shopify, Meta, Google, Xero, Brevo and the others listed in section 3) are sources, not recipients. We do not send customer data back to them beyond the authentication exchange each platform requires. We do not use advertising networks, analytics trackers or data brokers, and we will disclose data to public authorities only when legally compelled to do so.

8. International transfers

Data is stored and processed in the EU. Some subprocessors are headquartered in the United States; where any support access or transfer outside the UK or EU occurs, it is covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, as applicable.

9. Retention and deletion

  • Platform data is kept while the connection is active. When a customer disconnects a platform or ends the subscription, that platform's data is deleted from the live database within 30 days and ages out of backups within a further 30 days.
  • Account data is kept while the account is active and for 12 months after closure, then deleted, except where we must keep records for legal or accounting reasons.
  • Logs are kept for 30 days.
  • On request, a customer can have its whole workspace deleted sooner. We confirm completion in writing.

10. Your rights

If you are a person whose data we hold, you have the right to access it, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. To exercise any of these, contact us by email with "Data request" in the subject line. We acknowledge within two working days and respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

If you are a shopper of one of our customers (for example, you bought from a store that uses the application), the retailer is the controller of your data. Please contact them; we will assist them in responding.

11. Cookies and local storage

This website sets no cookies and runs no analytics. The application sets one strictly necessary session cookie to keep you logged in, and stores your theme preference in your browser's local storage. Neither is used for tracking or advertising.

12. Children

The service is for businesses. We do not knowingly collect data from anyone under 18.

13. Changes to this policy

We will post any changes on this page with a new effective date and version number. For material changes we will notify workspace owners by email before they take effect.

14. Contact

BIUK Brands Ltd, trading as Mabi Labs · Unit C1A, Poole Hall Road Industrial Estate, Ellesmere Port, CH66 1ST, United Kingdom · Contact us by email · mabilabs.io/contact