Privacy Policy
Last Updated: September 29, 2026
Revised September 29, 2026: clarified current data sources, service providers, historical AI use and technical review; kept the planned Insights API scope separate and aligned deletion requirements with the current Amazon policy.
1. Scope and contact
This policy explains how BFarm collects, uses, stores, protects, shares, and deletes data for bfarm.top, service enquiries, BFarm Insights reporting, and seller-authorized Amazon managed services. BFarm is a trading name of Maksym Lazuto, Individual Entrepreneur (ФОП) registered in Ukraine. Privacy requests can be sent to max@bfarm.top; security incidents can be reported to security@bfarm.top.
2. Website visitors and service enquiries
BFarm may collect the following information when you use this website:
- Contact and enquiry data: name, email, telephone number, ASIN, service interest, and the message you choose to submit.
- Technical delivery data: IP address, browser and device information, request time, and security logs needed to deliver and protect the website.
- Optional analytics data: page views, interactions, campaign attribution, and performance diagnostics only after you select Accept.
Contact, audit, and issue-resolution forms are service requests and do not subscribe you to marketing. The Academy newsletter uses a separate explicit checkbox and confirmation email. BFarm does not sell personal data.
3. Cookies and optional telemetry
Optional analytics and advertising technologies are disabled unless you select Accept. Rejecting them does not affect the website or forms. You can change the choice using Cookie settings in the footer. With consent, BFarm may use Google Tag Manager, Google Analytics, Google Ads/DoubleClick, Ahrefs Web Analytics, Vercel Analytics, Vercel Speed Insights, and Sentry diagnostics. Sentry session replay and form-email identity stitching are disabled.
Withdrawal stops future optional telemetry after the page reloads and removes analytics cookies and local-storage values accessible on the BFarm domain. Cookies placed on a third-party domain may also be controlled through that provider or your browser settings.
4. Current Amazon managed services
For Account Management and Advertising Optimization, a seller invites BFarm through Seller Central Authorized Partners and chooses the permissions needed for the written service scope. The seller retains Admin ownership and can change or revoke access through Amazon.
Depending on the engagement, BFarm may use non-PII Amazon Information concerning:
- account health, policy notifications, listing and catalog issues, and Amazon support cases;
- Sponsored Products, Sponsored Brands, and Sponsored Display campaigns and reports;
- inventory, FBA, account-performance, and seller reporting needed for the agreed work;
- aggregate customer-feedback and performance signals that do not identify or contact a buyer.
BFarm does not request or use buyer names, addresses, telephone numbers, email addresses, communications, restricted tax data, or direct-to-consumer shipping data. Clients must not grant permissions for those data categories. BFarm also does not request Seller Central passwords, client-created private applications, Client IDs, Client Secrets, refresh tokens, or other client API credentials.
5. Personnel and access
Access to a client's Amazon account is held by the founder, Maksym Lazuto. One assigned BFarm contractor holds a separate, individually verified account and is added as a user on a specific client account only when an assignment requires it. That access is least-privilege and limited to non-PII work; it is granted per client account only for the assigned work, is bounded by the permissions the seller grants and by the written assignment rather than by additional segmentation on BFarm's side, and is removed when it is no longer needed. Access is client-specific.
Every person BFarm permits to access or process client data — employee, agent, or contractor — signs written confidentiality and data-handling terms before any access is granted. Those terms require individual, attributable accounts with multi-factor authentication; forbid using one client's information to serve another; forbid subcontracting or sharing access; forbid placing Amazon personal data on personal devices or in unapproved AI tools; require a suspected incident to be reported no later than 24 hours after becoming aware of it; and require the return or deletion of every copy within seven days of the engagement ending.
6. Where Amazon Information is held
The main storage locations used for managed services are listed below. Development and processing services are described in section 7.
- Managed work device — day-to-day work by assigned personnel on client-scoped files;
- Google Workspace — managed-service files and client communication;
- Managed application server at a cloud hosting provider — runs the BFarm reporting database, which holds records derived from Amazon reports and from exports the client supplies: advertising performance metrics, keyword position history, and uploaded report files;
- Encrypted off-site backups in Google Drive — the reporting database is copied daily. Backups are encrypted before they leave the server and remain encrypted in storage; the encryption key is held by BFarm and is not shared with the storage provider.
BFarm does not publish host names, addresses, regions, or the specific security tooling used at any of these locations.
7. Service providers
BFarm uses external providers for hosting, storage, development and review. The purposes below distinguish confirmed use from integrations whose current use has not been verified.
- DigitalOcean and Vercel — DigitalOcean hosts the reporting application; Vercel hosts the public website.
- Google Workspace and Google Drive — managed-service files and report workbooks, client communication and encrypted off-site backups.
- GitHub — the development repository contains client-related files. The types of data in those files are still being reviewed.
- OpenAI / Codex — development and technical review have included metrics and metadata derived from Amazon reports.
- Anthropic — historical records show language-model calls for listing and proposal work. Those records do not identify the exact inputs or establish current use.
- Sentry — optional website diagnostics after consent and operational error events. The components sending those events and whether they contain Amazon Information have not been established.
- LangChain — software used for orchestration; using the framework does not by itself send data to a separate provider.
Current use of LangSmith tracing and automated report exports to Google Sheets has not been verified. Cloudflare has appeared in network and DNS configuration, but its role in carrying report contents has not been confirmed.
Mailchimp processes service-enquiry records and newsletter signup and confirmation requests. Newsletter emails require a separate signup and email confirmation. Resend processes the visitor's name, email, selected service and enquiry details to send enquiry notifications to BFarm. Calendly receives booking details when a visitor schedules a call. Google and Ahrefs provide optional website telemetry after consent. PayPal and plata by mono receive payment details when a client chooses to pay an invoice through bfarm.top/pay. Enquiry and booking text may contain information the visitor includes; do not submit buyer personal data or credentials.
Naming a provider or data source does not establish permission to send it Amazon Information. Applicable terms, the service purpose and the data involved must be checked separately. This policy does not promise provider-specific training, security, accuracy or retention guarantees.
8. Use of AI, calculations, accuracy, and freshness
This section covers managed-service work and development or technical review. The planned BFarm Insights SP-API scope excludes transferring Amazon Information to language-model providers. That planned restriction does not describe every historical or current BFarm workflow, and this disclosure does not authorize a transfer.
Language models assist with drafts and review. Recorded Anthropic use includes listing and proposal work; observed OpenAI / Codex review has included Amazon report-derived metrics and metadata. This does not establish which source files were sent in each historical call or that these tools are currently connected to the production reporting application.
Inputs can come from Amazon reports, client materials or third-party seller tools, depending on the task. A model answer is not evidence that a product or account claim is true. The source and permitted use of an input require a separate check.
BFarm requires operator review of model output and client approval before account or listing changes. The operator reviews every output before including it in a client deliverable. These are service requirements, not a claim that every software integration enforces them automatically.
Provider retention and training terms depend on the product and account settings. BFarm does not make a blanket zero-retention or no-training guarantee.
Model output can be incomplete or wrong and carries no accuracy guarantee. The operator checks it against the source material. Calculations such as break-even ACoS depend on the seller's cost inputs. Deliverables state formulas, assumptions, source periods and as-of dates. Reports describe the period they cover; later changes in fees, prices, listings or campaigns may make recommendations stale. Estimates are not promised results. BFarm does not guarantee an ACoS, TACoS, sales, ranking or timeline outcome.
9. Protection, retention, and deletion
BFarm uses individual accounts, multi-factor authentication where available, access controls, managed devices and servers, confidentiality duties, and least-privilege review. Client data is not sold or combined with another client's reports into a shared dataset.
BFarm uses Helium 10 for keyword and competitor research for listings, and occasionally for rank or profit analysis. We have used sellerboard occasionally, but are not using it now. The current Insights report pages read Search Query Performance and Sales and Traffic exports, not data from those tools. BFarm does not scrape Amazon or resell access to Amazon data. Use of a seller tool does not by itself establish permission to reuse or disclose the information it provides.
- Non-PII Amazon Information is retained only while it is needed for the agreed service and for the reporting history that service depends on. An automatic upper limit is specified and scheduled but is not yet enforced; until it is, records are removed on request rather than on a schedule.
- Deletion requests can be sent to max@bfarm.top. Amazon's current Data Protection Policy requires permanent, secure deletion of all Amazon Information, including all live copies, within 30 days of the earliest applicable trigger: an Amazon deletion notice, seller revocation or termination, loss of authorization to use the information, or the end of participation in Amazon's services.
- Revocation and service termination are handled under the Amazon deletion requirement stated above.
- A suspected incident involving Amazon Information is escalated to Amazon no later than 24 hours after discovery and handled under the current Amazon policy.
10. Client-provided exports and planned SP-API status
BFarm imports client-provided Search Query Performance and Sales and Traffic exports into a reporting workspace. Reports are separated by client and marketplace, show their source period, and do not make changes in Seller Central. BFarm currently has no approved or active SP-API application or production OAuth integration. The only planned SP-API scope is the non-restricted Brand Analytics role for read-only Search Query Performance and Sales and Traffic reports. No seller is connected through a BFarm OAuth flow, and no production authorization code or token is processed. Amazon API access remains planned. Activation requires the relevant Amazon approval, seller authorization, and verification of the live connection and its security controls. Amazon Ads API remains a separate future authorization path.
11. Your rights and international processing
Depending on your jurisdiction, you may request access, correction, deletion, portability, restriction, or objection. BFarm will support a seller client with valid requests concerning data processed on that seller's behalf. Providers may process data in the jurisdictions where they operate, subject to the applicable contract and law.
12. Policy changes
Material updates will appear on this page with a revised Last Updated date and will be communicated separately when required by law.