1. Controller and contact
The production legal entity, registered address and privacy contact must be confirmed before public launch. Until then, this page is a release-candidate draft and must not be represented as final legal approval.
2. Data we process
Account data may include email address and verification state, limited-account entitlement, authentication records, workspace role, subscription state, a 16+ age self-attestation with policy version and timestamp, and redacted fixed-code security events. Where a separately disclosed age, identity, or legal-capacity assurance applies, we may record its decision or level, provider name, and a one-way provider reference. Seller data may include official Wildberries API tokens, products, orders, sales, finance rows, advertising statistics, inventory, feedback and analytics outputs.
Wildberries tokens are encrypted server-side and are never included in browser workspace responses. New passwords use salted, memory-hard Argon2id hashes, session tokens are stored only as hashes, TOTP secrets are encrypted, recovery codes are stored as hashes, and passkey records hold public-key and protected credential security data. Device biometrics remain on the device; we do not receive biometric templates.
The eligibility and audit state does not retain date of birth, raw identity documents, image or video evidence, biometric templates, raw provider assertions or responses, email body content, or raw email tokens.
3. Why we process data
Data is used to connect seller accounts, calculate product profit, identify profit leaks, produce read-only recommendations, secure the service, provide support and comply with lawful data-rights requests.
4. Official API and automation boundary
The service uses official Wildberries APIs only. The release candidate does not automatically change prices, advertising bids, product cards, stock or supply plans. Recommendations require seller review.
5. Retention and deletion
Redacted email-delivery state and authentication-security events currently use a 90-day retention policy; they use fixed status or reason categories and hashes rather than message bodies or tokens. Other retention periods must be configured according to the final legal basis, accounting duties and active contracts. Account deletion can be initiated in the application or through the public deletion page. Identity verification is required before irreversible deletion.
6. Sharing and processors
Production hosting, database, monitoring, email and payment processors must be listed before launch. Data is not sold to advertisers. Access is limited by workspace role and operational need.
7. Security
Controls include encryption in transit, encryption of sensitive tokens and deletion-request identifiers at rest, Argon2id password hashing, encrypted TOTP secrets, hashed recovery codes and sessions, CSRF protection, rate limits, audit logs, backups and least-privilege access. A completed authenticator, recovery-code, or passkey factor change revokes all active sessions.
8. Your rights
Depending on applicable law, users may request access, correction, export, restriction or deletion. Requests are tracked and verified before irreversible action. Contact details and jurisdiction-specific rights require legal confirmation before launch.
TONOYAN AI