Last Updated: August 10, 2026
Revised August 10, 2026 — added the AI-use disclosure, the storage map, and the named service-provider list.
1. Scope and contact
This policy explains how BFarm collects, uses, stores, protects, shares, and deletes data for bfarm.top, service enquiries, and seller-authorized Amazon managed services. BFarm is a trading name of Maksym Lazuto, Individual Entrepreneur (ФОП) registered in Ukraine. Privacy requests can be sent to max@bfarm.top; security incidents can be reported to security@bfarm.top.
2. Website visitors and service enquiries
BFarm may collect the following information when you use this website:
- Contact and enquiry data: name, email, telephone number, ASIN, service interest, and the message you choose to submit.
- Technical delivery data: IP address, browser and device information, request time, and security logs needed to deliver and protect the website.
- Optional analytics data: page views, interactions, campaign attribution, and performance diagnostics only after you select Accept.
Contact, audit, and issue-resolution forms are service requests and do not subscribe you to marketing. The Academy newsletter uses a separate explicit checkbox and confirmation email. BFarm does not sell personal data.
3. Cookies and optional telemetry
Optional analytics and advertising technologies are disabled unless you select Accept. Rejecting them does not affect the website or forms. You can change the choice using Cookie settings in the footer. With consent, BFarm may use Google Tag Manager, Google Analytics, Google Ads/DoubleClick, Ahrefs Web Analytics, Vercel Analytics, Vercel Speed Insights, and Sentry diagnostics. Sentry session replay and form-email identity stitching are disabled.
Withdrawal stops future optional telemetry after the page reloads and removes analytics cookies and local-storage values accessible on the BFarm domain. Cookies placed on a third-party domain may also be controlled through that provider or your browser settings.
4. Current Amazon managed services
For Account Management and Advertising Optimization, a seller invites BFarm through Seller Central Authorized Partners and chooses the permissions needed for the written service scope. The seller retains Admin ownership and can change or revoke access through Amazon.
Depending on the engagement, BFarm may use non-PII Amazon Information concerning:
- account health, policy notifications, listing and catalog issues, and Amazon support cases;
- Sponsored Products, Sponsored Brands, and Sponsored Display campaigns and reports;
- inventory, FBA, account-performance, and seller reporting needed for the agreed work;
- aggregate customer-feedback and performance signals that do not identify or contact a buyer.
BFarm does not request or use buyer names, addresses, telephone numbers, email addresses, communications, restricted tax data, or direct-to-consumer shipping data. Clients must not grant permissions for those data categories. BFarm also does not request Seller Central passwords, client-created private applications, Client IDs, Client Secrets, refresh tokens, or other client API credentials.
5. Personnel and access
Access to a client's Amazon account is held by the founder, Maksym Lazuto. One assigned BFarm contractor holds a separate, individually verified account and is added as a user on a specific client account only when an assignment requires it; that access is least-privilege, limited to the assigned catalog and non-PII work, and removed when it is no longer needed.
Every person BFarm permits to access or process client data — employee, agent, or contractor — signs written confidentiality and data-handling terms before any access is granted. Those terms require individual, attributable accounts with multi-factor authentication; forbid using one client's information to serve another; forbid subcontracting or sharing access; forbid placing Amazon personal data on personal devices or in unapproved AI tools; require a suspected incident to be reported no later than 24 hours after becoming aware of it; and require the return or deletion of every copy within seven days of the engagement ending. Access is client-specific and need-to-know.
6. Where Amazon Information is held
Amazon Information used for managed services is held in the following places, each for a stated purpose:
- Managed work device — day-to-day work by assigned personnel on client-scoped files;
- Google Workspace — managed-service files and client communication;
- Managed application server at a cloud hosting provider — runs the BFarm reporting database, which holds records derived from Amazon reports and from exports the client supplies: advertising performance metrics, keyword position history, and uploaded report files;
- Encrypted off-site backups in Google Drive — the reporting database is copied daily. Backups are encrypted before they leave the server and remain encrypted in storage; the encryption key is held by BFarm and is not shared with the storage provider.
BFarm does not publish host names, addresses, regions, or the specific security tooling used at any of these locations.
7. Service providers
BFarm uses the service providers below. Each receives only the minimum required to perform its function for a specific client engagement, and no provider receives client information for its own purposes.
- Hosting and infrastructure — DigitalOcean, Vercel;
- Network and DNS — Cloudflare;
- Storage and workspace — Google;
- Error monitoring — Sentry;
- Language-model processing — Anthropic;
- Orchestration — LangChain, used as a framework rather than an independent data recipient.
Website-only providers, which do not receive Amazon Information: Mailchimp for service-lead records and confirmed newsletter subscriptions, Calendly when a visitor chooses to schedule a call, and Google and Ahrefs for optional website telemetry after consent.
This list is kept current. When a provider is added or removed, or its function changes, this page is updated. This list does not assert provider-specific training, security, accuracy, or retention guarantees.
8. Use of AI, calculations, accuracy, and freshness
BFarm uses language models as a working tool inside its own process. Models assist with reviewing and summarising the seller-authorised Amazon reports and the client-supplied material BFarm already holds for the engagement, with preparing listing content — titles, bullet points, product descriptions, and backend keyword candidates — and with drafting the written deliverables in which findings and recommendations are presented.
A model is not a source of Amazon data and is not a source of facts about a product or an account. Every input comes from the material a client supplies or from the Amazon reports that seller has authorised BFarm to use. No model is given Amazon Information to hold, and no model output is treated as a fact about an account.
No model has access to a seller account and no model takes an action. A model cannot place or change a bid, budget, price, or listing, and cannot act inside Seller Central. Model output is never applied or published automatically: the operator reviews every output, and the seller approves a change before it is applied to a listing or included in a deliverable. Where a model is used, its input is limited to what the assigned task requires, it is processed on BFarm's instruction for that client only, and it is not made available to another client's work.
BFarm's provider terms and account settings are configured to exclude client material from model training.
Model output can be incomplete or wrong and carries no accuracy guarantee; the operator's review and the seller's approval are the controls BFarm relies on, not the model. Advertising calculations such as break-even ACoS depend on costs and other source data supplied by the seller. A deliverable identifies the material formula, assumptions, source period, and as-of date. Every recommendation reflects the reporting period and the as-of date of the Amazon report it was derived from, not the current state of the account; costs, fees, campaigns, listings, and competitors change after a report is pulled, so a recommendation can be stale by the time it is read. Any figure, estimate, or projection shown in a deliverable is an estimate derived from stated assumptions, not a promised result. BFarm does not guarantee an ACoS, TACoS, sales, ranking, or timeline outcome.
9. Protection, retention, and deletion
BFarm uses individual accounts, multi-factor authentication where available, access controls, managed devices and servers, confidentiality duties, and least-privilege review. Amazon Information is used only for the authorizing seller's documented service purpose and is not sold, pooled between sellers, or used for BFarm advertising.
Where a client uses a third-party seller-analytics service, the subscription is the client's, BFarm works inside the client's own account by invitation as a named user, and any export used comes from the client and is used only for that client. BFarm does not scrape Amazon, does not resell access to Amazon data, and holds no dataset pooled across sellers. Seller-authorized Amazon access and permitted Amazon reports for the specific client remain separate from any non-Amazon brand materials.
- Non-PII Amazon Information is retained only while it is needed for the agreed service and for the reporting history that service depends on. An automatic upper limit is specified and scheduled but is not yet enforced; until it is, records are removed on request rather than on a schedule.
- An Amazon deletion request is actioned within 30 days; applicable live copies are removed within 90 days after notice.
- When access is revoked or a service ends, BFarm removes information no longer required for the engagement or legal records.
- A suspected incident involving Amazon Information is escalated to Amazon no later than 24 hours after discovery and handled under the current Amazon policy.
10. Client-provided exports and planned SP-API status
Available today through Amazon analytics exports supplied directly by the managed-service client, with client-scoped storage and read-only reporting. BFarm currently has no approved or active SP-API application or production OAuth integration. The only planned SP-API scope is the non-restricted Brand Analytics role for read-only Search Query Performance and Sales and Traffic reports. No seller is connected through a BFarm OAuth flow, and no production authorization code or token is processed. Planned only after the required Amazon approval, production implementation, security verification, and seller authorization. Amazon Ads API remains a separate future authorization path.
11. Your rights and international processing
Depending on your jurisdiction, you may request access, correction, deletion, portability, restriction, or objection. BFarm will support a seller client with valid requests concerning data processed on that seller's behalf. Providers may process data in the jurisdictions where they operate, subject to the applicable contract and law.
12. Policy changes
Material updates will appear on this page with a revised Last Updated date and will be communicated separately when required by law.