shipments.fyi ("we", "us") provides tools that help Amazon FBA sellers reconcile shipments, track reimbursement claim deadlines, and understand per-SKU profit. This policy explains what data we collect, why, where it lives, and your choices. Questions or requests: support@shipments.fyi.
The short version
- The free scanner and profit tools run entirely in your browser — CSV files you analyze there are never uploaded to our servers unless you are signed in and explicitly import or track something.
- We collect the minimum needed to run the service: your account email, the business data you choose to save, and payment records — plus a cookieless count of page views on our public pages, and of how often the free tools were run there. We collect no data about your buyers.
- We never sell your data, never share it with other sellers, and never aggregate it across customers for resale or published insights.
Data we collect
Account data
Sign-in is handled by Clerk (our authentication provider). We receive your email address and a unique account identifier. We do not see or store your password.
Business data you choose to save
If you are signed in and use the server-backed features, we store what you submit: imported FBA shipment CSV data (shipment IDs, SKUs, FNSKUs/ASINs, quantities, dates), tracked claim records (units short, estimated values, deadlines, case text, statuses), and per-SKU costs you enter for profit analysis. This is your operational business data; it contains no information about your buyers.
Client-side analysis
The free scanner and true-profit analyzers parse your files locally in your browser. Those files are never transmitted to us, logged by us, or stored on our servers.
So that you can try more than one file in a sitting — and so a scan is not lost if you create an account partway through — the scanner keeps the result of a scan in your own browser's local storage. That copy stays on your device and is never sent to us. It stops being usable at the end of the day it was created, and is erased the next time you open the scanner. You can remove it immediately with "Start a new scan", or by clearing site data in your browser. Nothing about a scan's contents reaches us unless you are signed in and explicitly choose to track its claims, which saves those claim records to your account. We do count that a scan ran, and whether our parser could read the file — a bare tally with nothing attached to it, described under Cookies and analytics below.
Payments
Paid subscriptions are processed by Stripe. Your card number never touches our servers — we store only a payment-method reference, your plan, amounts charged, and billing status so we can operate your subscription.
Transactional emails (claim-deadline alerts, billing notices) send through Brevo, our email provider.
We no longer operate a launch waitlist. If you joined it previously, we still hold the email address and signup source you gave us, synced to Brevo, and will use them only for the launch announcement you asked for. You can ask us to delete that record at any time using the contact details below.
Cookies and analytics
We use essential session cookies from Clerk to keep you signed in. On payment pages, Stripe.js sets its own cookies (such as __stripe_mid) for fraud prevention. We run no advertising trackers and no ad networks.
To see which pages actually help sellers find us — and whether the free tools work when they get there — we count page views on our public pages using Vercel Web Analytics, along with a short, fixed list of counters on the scanner and the profit tool: that a scan ran, that a file could not be read, that the sample was run, that an earlier scan was restored in your browser, and that a profit analysis ran. It sets no cookies and does not follow you across other sites. For each view it records the page address, the site that referred you, and coarse device information (browser, operating system, device type, approximate country). Visitors are counted using a hash Vercel derives from the request and discards daily, so views cannot be tied back to you or joined up over time.
Those counters carry a name and nothing else — no properties, no numbers, no labels of any kind — recorded against the same page address and coarse device information as a view.
Your signed-in pages are excluded outright: nothing at all is sent — not a page view, and not a counter — for anything under /dashboard, /shipments,/import, /upgrade, /account or /support. On the public pages we measure, the address is stripped of everything but campaign tags (utm_*, ref). Your file never leaves your browser and is never part of this: we never send a dollar figure, a unit count, a SKU, an ASIN, a shipment number, a file name, an error message, your email address or your account id — and we never send whether a scan found anything. Nothing you upload or type is part of this.
Our basis for this is our legitimate interest in knowing which pages are useful. Because it is cookieless, aggregated, and confined to this site, we do not gate it behind a consent banner. If you would rather not be counted, any content blocker that blocks requests to /_vercel/insights will stop it, with no effect on anything the service does for you.
Where your data lives (subprocessors)
We use a small set of infrastructure providers, each receiving only what their function requires: Vercel (application hosting, and page-view and tool-usage counting on our public pages), Neon (PostgreSQL database), Clerk (authentication), Stripe (payment processing), and Brevo (email delivery). Application data is stored in the United States; Brevo processes email and contact data in the European Union.
How we use data
Only to provide and improve the service you signed up for: running your scans and claim tracking, sending the alerts and billing emails you enabled, support, and counting page views and free-tool runs on our public pages so we know which pages are worth keeping and whether the tools work. We do not sell personal data, share it with advertisers, or combine data across customers to build or publish market insights.
Amazon data
There are two ways your Amazon numbers reach shipments.fyi, and they are not handled identically. Files you export and provide yourself are your own business records, covered by the sections above. Data we fetch directly from Amazon, if you connect your account, is additionally governed by Amazon's Data Protection Policy. Connecting is optional; every tool works without it.
If you connect your Amazon account
You authorize us through Login with Amazon, on Amazon's own site. Your Amazon password is never shown to us, sent to us, or stored by us, and we will never ask you for it. The authorization token we receive is encrypted (AES-256-GCM) before it is stored and is never written to logs.
The access is read-only, and limited to three permission categories: Amazon Fulfillment, Finance and Accounting, and Selling Partner Insights. We have not requested, and will not request, any permission that carries your buyers' personal information. We read your inbound shipment records and reimbursement-related financial events; from those we store the short-shipment findings that become your tracked claims.
You can revoke it at any time, without asking us — in Seller Central, under Apps and Services → Manage Your Apps. Revoking stops all future access immediately.
We do not combine your Amazon data with any other seller's, and we do not sell, share, or publish it.
Security
All data is encrypted in transit (TLS) and at rest. Access to production systems is limited, credentialed, and protected by multi-factor authentication. Every data query in the application is scoped to your account — with no valid session, reads return nothing.
Retention and deletion
How long we keep something depends on where it came from, and the difference is worth understanding before you choose how to get your data in.
Data you provided yourself — anything from a file you exported and uploaded, claims you tracked, unit costs you entered — is kept for as long as your account is active. There is no time limit on it, so your history stays as deep as you build it.
Data we fetched from Amazon on your behalf is deleted automatically 18 months after we receive it. That ceiling comes from Amazon's Data Protection Policy, not from us, and a scheduled job enforces it daily whether or not anyone asks. If you want an unlimited record of a period, upload the report for it — that copy is yours and is not subject to the ceiling.
Email support@shipments.fyi to request export or deletion of your account and its data at any time — we honor deletion requests within 30 days, except records we must keep for legal or tax reasons (e.g., payment ledger entries).
Your rights
You can access, correct, export, or delete your personal data by contacting us. If you unsubscribe from marketing email, we stop sending it; transactional email (billing notices, deadline alerts you enabled) continues while the feature is active.
Changes
We'll update this page when our practices change and revise the effective date above. Material changes will be announced by email to account holders.
See also our Terms of Service.