Security & Amazon data use
ProfitFox uses a staged trust model. The Free Scan and Monitor tier are read-only. Copilot write access is enabled separately, and every proposed action shows its target, current state, proposed state, evidence, risk and rollback information before approval.
Data used for the service
ProfitFox accesses only the Amazon seller and advertising data needed for the authorized analysis. Advertising data may include profile and account identifiers, campaign structure and settings, budgets, bids, advertised products, targets, search terms, placements, impressions, clicks, spend, attributed orders and attributed sales. The purpose is limited to performance diagnosis, profit-aware recommendations and seller-authorized result measurement.
Current safeguards
- No Amazon login passwords are collected or stored.
- No buyer names, addresses, email addresses, payment details or restricted buyer data are required.
- Credentials and authorization tokens remain server-side and are excluded from source control and browser code.
- The numerical detection and impact engine is deterministic; an optional language model may explain already-computed evidence but cannot independently calculate or execute changes.
- Current execution is a dry run that creates an auditable simulation. Live Amazon Ads writes are disabled pending authorization and production validation.
Approval and future execution
ProfitFox may act only for a seller who has granted express, verifiable authorization. Real advertising or listing changes will remain disabled until the corresponding Amazon permissions, validation, access logging, approval controls and rollback behavior pass production quality assurance.
Report a security or privacy issue
Send suspected vulnerabilities, privacy issues or incidents involving ProfitFox or Amazon data to info@uberfit.eu with the subject “ProfitFox Security”. Include the affected URL or component, a description, reproduction steps where safe, potential impact and contact details. Do not include Amazon credentials or unnecessary personal data.
Reports are logged, triaged and tracked through resolution. We acknowledge actionable reports promptly, restrict access to the response team, preserve relevant evidence, contain confirmed exposure, remediate the cause and notify Amazon at security@amazon.com within 24 hours after discovering a security incident involving Amazon information.
Coordinated disclosure
Please give us a reasonable opportunity to investigate and remediate before public disclosure. This reporting channel does not create a bug-bounty program or authorize access to third-party data, service disruption, social engineering or destructive testing.