Privacy policy

Crazy Vendor LTD (“Crazy Vendor,” “we,” “us,” or “our”) respects the privacy and security of our customers, users, marketplace sellers, and individuals whose information may be processed through our services.

This Privacy Policy explains how Crazy Vendor collects, accesses, uses, processes, stores, shares, protects, and deletes information through our websites, mobile applications, software platform, APIs, integrations, extensions, and related services collectively referred to as the “Services.”

Crazy Vendor provides business software primarily to eCommerce sellers, brands, retailers, and other commercial organizations.

By using the Services, you acknowledge the practices described in this Privacy Policy.

1. Scope

This Privacy Policy applies to information processed through Crazy Vendor, including information received directly from users and information received through authorized third-party integrations.

These integrations may include marketplaces, eCommerce platforms, payment providers, shipping carriers, fulfillment providers, communication providers, and other services connected by a customer.

Depending on the relationship and applicable law, Crazy Vendor may act as a data controller, business, service provider, or data processor.

Where Crazy Vendor processes information on behalf of a business customer, the customer generally determines the purposes for which the information is processed.

2. Information We Process

The information processed depends on the Services and integrations you use.

Account and Business Information

We may process:

  • Name
  • Business or company name
  • Email address
  • Telephone number
  • User account information
  • User roles and permissions
  • Subscription and billing status
  • Business preferences
  • Support communications

Marketplace and eCommerce Information

When you authorize an integration, Crazy Vendor may receive information made available through the relevant platform.

This may include:

  • Marketplace or store identifiers
  • Product information
  • Listings
  • SKUs
  • Inventory
  • Orders
  • Fulfillment information
  • Sales information
  • Returns and refunds
  • Marketplace fees
  • Settlement and financial information
  • Reimbursement information
  • Performance metrics
  • Customer communications
  • Information necessary to perform authorized marketplace operations

Supported integrations may include services provided by Amazon, Walmart, eBay, Etsy, Shopify, WooCommerce, Google, shipping carriers, fulfillment providers, and other platforms.

Order and Recipient Information

For order management, merchant-fulfilled shipping, tax, legal, fulfillment, or other authorized purposes, Crazy Vendor may process:

  • Recipient name
  • Shipping address
  • Email address
  • Telephone number
  • Order information
  • Product information
  • Shipment information
  • Tracking information
  • Customs information
  • Tax information where applicable

Access to this information is restricted to the purposes for which it was authorized.

Shipping and Fulfillment Information

Crazy Vendor may process:

  • Sender and recipient details
  • Shipment weight and dimensions
  • Product descriptions
  • Declared values
  • Customs documentation
  • HS or tariff classifications
  • Carrier information
  • Tracking numbers
  • Shipping labels
  • Duties and taxes
  • Carrier charges and adjustments
  • Warehouse and fulfillment information

Financial and Business Analytics Information

Crazy Vendor may process business information necessary to provide reporting and analytics features, including:

  • Revenue
  • Sales
  • Fees
  • Refunds
  • Shipping costs
  • Cost of goods
  • Reimbursements
  • Settlements
  • Profitability information
  • Inventory values
  • Operational metrics

Payment Information

Payments may be processed through third-party payment providers.

Crazy Vendor does not need to store complete payment card information when that information is collected directly by an authorized payment processor.

We may process transaction identifiers, invoices, subscription status, billing history, credits, and payment status.

Device, Security, and Technical Information

When users access Crazy Vendor, we may process information necessary for security, authentication, reliability, and system operation, including:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Application version
  • Login events
  • Authentication events
  • Session information
  • Error information
  • Diagnostic information
  • Security events
  • Feature usage and system performance information

We apply data minimization principles and do not intentionally collect device information that is unrelated to the functionality, security, or operation of the Services.

3. How We Use Information

Crazy Vendor uses information only for legitimate and authorized purposes, including:

  • Providing the Crazy Vendor Services
  • Creating and maintaining user accounts
  • Authenticating users
  • Connecting authorized third-party accounts
  • Synchronizing marketplace information
  • Managing inventory
  • Managing orders
  • Managing listings
  • Processing shipments
  • Providing warehouse and fulfillment tools
  • Providing financial and profitability reporting
  • Supporting reimbursement workflows
  • Providing customer service functionality
  • Providing operational analytics
  • Generating authorized business insights
  • Detecting and preventing security incidents
  • Preventing fraud or misuse
  • Maintaining system reliability
  • Troubleshooting technical problems
  • Processing subscriptions and payments
  • Providing customer support
  • Complying with legal and regulatory requirements
  • Complying with applicable marketplace, API, and platform requirements
  • Enforcing our Terms and protecting our Services

We do not use personal information for purposes that are materially incompatible with the purposes for which it was collected without providing appropriate notice or obtaining consent where required.

4. Data Minimization and Access

Crazy Vendor requests and processes only information reasonably necessary to provide the features authorized by the customer.

Access to information within Crazy Vendor is governed by role-based access, least-privilege principles, and business need.

Users should authorize only integrations and permissions necessary for the features they intend to use.

5. Amazon Information and SP-API Data

Crazy Vendor may receive information through Amazon Services APIs after an Authorized User grants Crazy Vendor permission to access that information.

Crazy Vendor uses Amazon Information only to perform authorized activities for the Amazon Authorized User who provided authorization.

Crazy Vendor does not use Amazon Information to perform activities for another seller or customer unless separately and lawfully authorized.

Amazon Customer PII

Personally Identifiable Information received through restricted Amazon API operations is used only for purposes permitted by Amazon, including merchant-fulfilled shipping and applicable legal, tax, or regulatory requirements.

Crazy Vendor does not use Amazon Customer PII for:

  • Marketing to Amazon customers
  • Advertising
  • Creating customer marketing databases
  • Soliciting reviews
  • Creating or modifying reviews
  • Unrelated analytics
  • Cross-customer profiling
  • Generalized AI model training

Amazon Customer PII is retained for no longer than 30 days after order delivery unless retention beyond that period is specifically required by applicable legal, tax, or regulatory obligations.

Amazon Data Separation and Aggregation

Crazy Vendor maintains mechanisms to identify the source and ownership of Amazon Information.

Crazy Vendor does not aggregate information obtained through Amazon Services APIs across different Authorized Users for the purpose of providing, selling, publishing, or distributing that combined information or derived insights to other customers or third parties.

Amazon Information belonging to one Authorized User is not made available to another Authorized User.

Amazon Data Retention and Deletion

Crazy Vendor retains Amazon Information only for the period necessary and permitted for the authorized purpose.

Amazon PII is subject to the specific retention requirements described above.

Where applicable, non-PII Amazon Information is retained within Amazon’s applicable retention limits and generally no longer than 18 months unless longer retention is legally required or otherwise expressly permitted.

Crazy Vendor permanently and securely deletes Amazon Information from live systems within 30 days of the earliest applicable event, including:

  • A deletion request or notice from Amazon
  • Revocation or termination of authorization by the applicable customer
  • Crazy Vendor no longer being authorized or entitled to process the information
  • Termination or expiration of applicable Amazon API participation

Legally required information may be retained only for the applicable legal, tax, or regulatory purpose and only for the required period.

Amazon Security Incidents

Security incidents affecting Amazon Information are handled under Crazy Vendor’s incident response procedures and applicable Amazon notification requirements.

Crazy Vendor maintains an Incident Management Point of Contact and follows applicable notification and remediation obligations.

6. Google User Data

Where a user connects a Google account or Google service, Crazy Vendor accesses Google user data only after authorization and only for the features that the user has chosen to enable.

Crazy Vendor requests only the Google API permissions necessary to provide the applicable user-facing features.

Crazy Vendor’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including applicable Limited Use requirements.

Google user data is used only to provide or improve prominent user-facing features authorized by the user.

Crazy Vendor does not sell Google user data.

Crazy Vendor does not use Google user data for:

  • Advertising
  • Retargeting
  • Personalized advertising
  • Data brokerage
  • Creditworthiness determination
  • Unrelated marketing
  • Unrelated generalized AI model training

Google user data is not transferred to third parties except where permitted under applicable Google requirements and necessary to provide authorized functionality, maintain security, comply with applicable law, or complete another permitted activity.

Human access to Google user data is restricted and permitted only where the user has provided appropriate authorization, where necessary for security or support under applicable requirements, or where required by law.

Users may disconnect Google integrations and revoke Crazy Vendor’s access through Crazy Vendor or their Google account permissions.

7. Artificial Intelligence and Automated Features

Crazy Vendor may provide AI-assisted analytics, recommendations, classifications, summaries, alerts, or business insights.

When AI or automated processing is used, Crazy Vendor aims to make the nature and purpose of the feature clear to the user.

AI-generated information may be based on marketplace information, user-provided data, historical business information, and other authorized information available to the customer’s account.

AI-generated outputs may be incomplete, delayed, or inaccurate and should be reviewed before being used for material business decisions.

Crazy Vendor applies data integrity and validation controls appropriate to automated processing that may materially affect customer business operations.

Amazon Information and AI

Crazy Vendor does not combine Amazon Information from multiple Authorized Users to generate cross-seller insights for other customers.

Crazy Vendor does not use Amazon Customer PII to train generalized AI models.

Amazon Information is used with AI functionality only where that use supports an authorized customer-facing Crazy Vendor feature and complies with Amazon requirements.

Third-Party AI Providers

If a Crazy Vendor feature requires personal information to be transmitted to a third-party AI provider, Crazy Vendor will provide appropriate disclosure regarding the provider, information involved, and purpose before such transfer and will obtain explicit user permission where required.

Crazy Vendor does not provide personal information to third-party AI providers for their independent advertising or unrelated commercial purposes.

8. Mobile Application Permissions

The Crazy Vendor mobile application requests access only to device capabilities reasonably necessary for user-requested functionality.

Where mobile operating systems require permission to access protected information or device functionality, Crazy Vendor will provide an appropriate explanation and request permission before accessing that information.

Declining an optional permission will not prevent access to unrelated application functionality.

9. How We Share Information

Crazy Vendor does not sell personal information for monetary consideration.

Information may be shared only where reasonably necessary with:

Connected Platforms

Information may be transmitted to marketplaces, eCommerce platforms, carriers, fulfillment providers, or other services when the customer requests Crazy Vendor to perform an action through that service.

Service Providers

Crazy Vendor may use third-party service providers for functions such as:

  • Cloud infrastructure
  • Data storage
  • Cybersecurity
  • Communications
  • Payment processing
  • Monitoring
  • Error reporting
  • Customer support
  • Software infrastructure

Service providers receive only information reasonably necessary to perform their authorized function.

Where third parties process Amazon Information, Crazy Vendor performs applicable vendor due diligence and requires appropriate information security and confidentiality protections.

Legal Requirements

Information may be disclosed where reasonably necessary to comply with law, regulation, valid legal process, or enforceable governmental request, or to protect Crazy Vendor, its customers, users, or others against fraud, abuse, or security threats.

Corporate Transactions

Information may be transferred in connection with a merger, acquisition, restructuring, financing, or sale of business assets, subject to applicable contractual, privacy, platform, and legal requirements.

Where information subject to special platform restrictions is involved, Crazy Vendor follows those applicable restrictions.

10. Data Security

Crazy Vendor maintains an information security program designed to protect information against unauthorized access, loss, alteration, disclosure, or misuse.

Security controls may include, as applicable:

  • Encryption in transit
  • Encryption at rest
  • Access controls
  • Multi-factor authentication
  • Credential protection
  • Network security controls
  • Application security controls
  • Endpoint security
  • Logging and monitoring
  • Vulnerability management
  • Secure software development practices
  • Change management
  • Backup and recovery procedures
  • Incident response procedures
  • Employee security training
  • Third-party risk management

Security controls are reviewed and updated based on risk, contractual requirements, platform requirements, and changes to our systems.

No electronic system can provide absolute security.

11. Data Retention

Retention periods depend on the type, source, purpose, and legal status of the information.

Crazy Vendor retains personal information only for as long as reasonably necessary to provide the Services, comply with applicable obligations, maintain security, resolve disputes, and enforce agreements.

Information subject to a third-party marketplace or API retention requirement is handled according to that applicable requirement.

Amazon Information is subject to the specific rules described in Section 5.

After information is no longer required, Crazy Vendor deletes, anonymizes, or securely disposes of it in accordance with applicable requirements.

Backups may contain information for a limited additional period until they are securely overwritten under normal backup lifecycle procedures, where permitted by applicable requirements.

12. Account and Data Deletion

Users may request deletion of their Crazy Vendor account and associated personal information.

Where the mobile application supports account creation, users may initiate account deletion from within the application.

Crazy Vendor also provides a web-based account deletion request process.

Crazy Vendor may verify identity and authority before processing a deletion request.

For organization accounts, account administrators may be required to authorize deletion of organization-level data.

Individual users may request deletion of their individual Crazy Vendor user profile. Business records controlled by a customer’s organization may remain within the organization’s account where appropriate.

Information may be retained after a deletion request only where required or permitted by applicable law or binding platform requirements.

Where information is retained for legal purposes, it will not be used for unrelated purposes.

Deleting a Crazy Vendor account does not automatically delete information maintained independently by connected third-party platforms.

13. Revoking Third-Party Access

Users may disconnect marketplace and third-party integrations through the functionality provided by Crazy Vendor where available.

Users may also revoke access directly through the applicable third-party platform.

After authorization is revoked, Crazy Vendor stops retrieving new information through that authorization and handles previously received information according to applicable retention and deletion requirements.

14. User Rights

Depending on applicable law, individuals may have rights to:

  • Access personal information
  • Obtain a copy of personal information
  • Correct inaccurate personal information
  • Request deletion
  • Restrict processing
  • Object to certain processing
  • Withdraw consent
  • Request data portability
  • Stop certain sharing or processing
  • Submit a complaint to an applicable regulatory authority

Requests may be submitted to:

info@crazyvendor.io

Crazy Vendor may verify the identity and authority of the requesting person.

Where Crazy Vendor processes information solely on behalf of a business customer, Crazy Vendor may direct the request to that customer or assist that customer in responding.

15. California Privacy Rights

Where applicable California privacy law applies, eligible individuals may exercise rights provided under that law.

Crazy Vendor does not discriminate against individuals for exercising applicable privacy rights.

Crazy Vendor does not sell personal information for monetary consideration.

If Crazy Vendor engages in an activity that is legally considered a “sale” or “sharing” under applicable California law, Crazy Vendor will provide required disclosures and choices.

16. International Processing

Crazy Vendor and authorized service providers may process information in Israel, the United States, and other locations in which Crazy Vendor or its service providers operate.

Where applicable law requires safeguards for international transfers, Crazy Vendor uses appropriate contractual, technical, or organizational safeguards.

17. Cookies and Similar Technologies

Crazy Vendor websites and applications may use cookies, local storage, and similar technologies for:

  • Authentication
  • Account security
  • Session management
  • User preferences
  • Performance
  • Reliability
  • Analytics

Where required by applicable law, Crazy Vendor provides appropriate controls for non-essential technologies.

18. Children’s Privacy

Crazy Vendor is a business software service and is not intended for children.

Crazy Vendor does not knowingly offer the Services directly to children in circumstances prohibited by applicable law.

19. Third-Party Services

Third-party services connected to Crazy Vendor operate under their own terms and privacy policies.

Crazy Vendor is not responsible for independent processing performed by third parties outside Crazy Vendor’s control.

Users should review the policies of services they choose to connect.

20. Changes to This Privacy Policy

Crazy Vendor may update this Privacy Policy to reflect changes in our Services, technologies, integrations, business practices, legal requirements, or third-party platform requirements.

The date at the beginning of this Policy identifies the most recent revision.

Where required, Crazy Vendor will provide additional notice or request renewed consent before materially changing how previously collected information is used.

21. Contact

Crazy Vendor LTD

Email: info@crazyvendor.io

Website: Crazy Vendor