CommerceOS · Privacy Notice

Fretron CommerceOS Privacy Notice

Last updated: 22 July 2026

This notice covers the Fretron CommerceOS application. It explains what data CommerceOS holds, why, how it is secured, how long it is kept, and how to have it deleted. It is specific to CommerceOS and takes precedence over the general Fretron website privacy policy for anything processed inside the application.

Section 1

Who We Are

Fretron CommerceOS is published and operated by Fretron Private Limited, a company incorporated in India under CIN U60100HR2020PTC085857, with its registered office at 4th Floor, Plot No. 55, Sector 44, Gurugram, Haryana 122003, India.

For anything in this notice, contact privacy@fretron.com, or reach support at support@fretron.com and +91 9711799111, Monday to Saturday 09:30–18:30 IST. The full escalation path is on the CommerceOS support page.

Where a seller uses CommerceOS to fulfil their own orders, the seller is the controller of the personal data in those orders and Fretron acts as a processor on the seller’s instructions.

Section 2

Seller Authorization

CommerceOS accesses a seller’s marketplace account only after that seller explicitly authorizes it, through the marketplace’s own consent flow.

  • The seller signs in on the marketplace’s own authorization page. Fretron never asks for, receives, or stores a seller’s marketplace username or password.
  • The marketplace returns an authorization code, which Fretron exchanges for a refresh token. That token is encrypted before storage and is scoped to that seller’s tenant only.
  • Fretron requests only the access needed to operate the functions described on the CommerceOS product page.
  • The seller can revoke the authorization at any time from their own marketplace seller account, or ask us to disconnect the channel. Either stops all further data retrieval.

Section 3

What We Collect, and Why

3.1 Information obtained from a marketplace under seller authorization

Where the seller connects Amazon, this is Amazon Information as defined in Amazon’s Data Protection Policy. CommerceOS retrieves:

DataPurpose it is used for
Listings and catalog data — seller SKU, marketplace product identifier, title, product type, images Building the seller’s channel catalog and mapping channel SKUs to internal item records.
Orders and order line items — order identifiers, items, quantities, prices, status, fulfilment node, cancellations Creating the internal sales order, allocating stock, routing to a warehouse, and driving pick, pack and dispatch.
Inventory quantities and acknowledgements Keeping one available-to-sell number consistent between the CommerceOS ledger and the channel.
Shipment, label, packing slip and invoice documents Producing the paperwork that physically ships the order, and retaining proof of dispatch.
Return events Matching a return to its order and putting sellable stock back on the ledger.
Settlement reports and finance transactions Reconciling marketplace payouts against orders and flagging short payments, fee, commission or tax mismatches.
Buyer shipping address (restricted) Producing a shipping label or handing off to a carrier for a self-ship order. Nothing else.

3.2 How buyer personal information is handled

  • Recipient names, shipping addresses and buyer contact details are restricted data. They are retrieved only through the marketplace’s restricted-data-token flow, only for an active self-ship account with restricted access explicitly enabled, only for a shipping-label or carrier-handoff purpose, and only for a user holding the relevant permission. They are not copied into the sales order or retained as a reusable buyer profile. An audit record is written showing who accessed what, when, for which order and for what purpose — without the restricted values.
  • Buyer email is not used as the customer identifier. CommerceOS maps an Amazon order to the seller’s configured channel customer and does not copy buyer email into sales-order master data. Where restricted contact data is required to fulfil an order, it is obtained through the same purpose-bound flow described above.
  • Buyer personal information is never used to contact buyers for marketing, never used to build profiles, and never disclosed to anyone outside the flow described in section 5.

3.3 Seller account and usage data

  • User names, work email addresses, phone numbers, and roles for the seller’s CommerceOS users.
  • Company details, warehouse and location records, and channel configuration.
  • Application and audit logs — who did what and when — used for security, troubleshooting and support.

Section 4

What We Never Do

These are absolute. They apply to Amazon Information and to information from every other connected marketplace.

We never sell it

No marketplace information, and no buyer personal information, is ever sold, licensed, rented, or traded to anyone, for any amount, under any circumstances.

We never use it for advertising

It is not used for advertising, marketing, remarketing, audience building, lookalike modelling, or lead generation — for Fretron or for anyone else.

We never use it to train models

It is not used to train, fine-tune, or improve any machine-learning model, ours or a third party’s.

We never pool it across sellers

Each seller’s data is scoped to that seller’s own tenant. It is not aggregated with other sellers’ data to produce benchmarks, market intelligence, or any other derived product.

We never share it for anyone else’s purposes

The only disclosures are those in section 5.

Section 5

When Information Is Shared

Marketplace information is disclosed only in these situations, and never for any purpose of our own:

  • To operational providers the seller has configured. Carriers, warehouse operators, and fulfilment partners that the seller has set up in their own account, and only the minimum needed to execute that seller’s shipment — for example, a delivery address handed to the carrier the seller selected for that order.
  • To the subprocessors listed in section 8. They operate the platform on our behalf under contract, may use the data only to provide their service to us, and may not use it for their own purposes. Amazon buyer PII is excluded from optional AI inference services.
  • Back to the marketplace itself, where an operation requires it — for example confirming a shipment or publishing an inventory quantity.
  • Where the law requires it — a binding order from a court or a competent authority. Where we are lawfully permitted to do so, we notify the affected seller first.

There is no other sharing. We do not disclose marketplace information to advertisers, data brokers, analytics vendors, or any other third party.

Section 6

Retention and Deletion

  • Amazon buyer PII, including recipient name, shipping address, phone or contact details, and PII-bearing shipping documents, is retained only as necessary to fulfil the order and is deleted from active systems no later than 30 days after order shipment. It is not retained as a reusable buyer profile.
  • Non-PII order, inventory, catalog, document metadata and settlement records may be retained for as long as the seller’s account is active because the seller needs them to run and reconcile their own operation. This longer period does not apply to the Amazon buyer PII described above.
  • On account closure or channel disconnection, records for that account or channel are deleted within 30 days of the closure or of a verified deletion request.
  • Authorization credentials are revoked and deleted when a channel is disconnected or the account is closed.
  • Backups are encrypted and lifecycle-bounded. Amazon buyer PII expires from backup copies under the same maximum 30-day lifecycle. A deletion covers live data stores and additional copies; removing an application pointer alone is not treated as deletion.
  • Statutory exception. Where Indian tax or company law requires a transaction record to be kept — GST invoice records, for example — we keep only the record the law requires, for only as long as it requires, and nothing else. We tell you in writing what was kept and why.
  • No indefinite archives. We do not hold marketplace information in archives beyond the periods stated here.

How to request deletion

Email privacy@fretron.com from the address registered on the account with DATA DELETION REQUEST in the subject line, naming the account and the channels concerned. We acknowledge within two business days, verify that the request comes from an authorized user, complete it within 30 days, and confirm in writing what was deleted. The full procedure, including data export requests, is on the CommerceOS support page.

Section 7

Security

Where the data lives

Fretron CommerceOS runs on Google Cloud Platform in the asia-south1 (Mumbai), India region, on a managed Kubernetes cluster in a namespace dedicated to CommerceOS. Application records are held in a MongoDB database inside that cluster; documents and files are held in Google Cloud Storage. Data at rest is encrypted at the storage layer by the cloud provider.

Encryption

  • In transit: all traffic between a seller’s browser and CommerceOS, and between CommerceOS and every marketplace or third-party API, is encrypted with TLS.
  • Amazon buyer PII and marketplace credentials at rest: retained sensitive payloads and authorization credentials, including refresh tokens, are encrypted before persistence using AES-256-GCM with a per-record random initialization vector and authentication tag. Per-record data-encryption keys are protected with envelope encryption under Google Cloud KMS. Key use is restricted by IAM to designated GKE application service accounts, recorded in Cloud KMS audit logs, and rotated on a defined schedule. Plaintext keys are never stored in application records, logs, source code or repositories.

Access control

  • Every record is scoped to a single seller tenant. A request that carries one tenant's identity cannot read another tenant’s data.
  • Inside a seller’s account, actions are gated by role-based permissions — managing channel integrations, and accessing restricted buyer data, are each separate permissions that an administrator grants explicitly.
  • Fretron personnel access production data only where required to provide support or resolve an incident, under the same tenant-scoped controls.
  • Access to restricted buyer data is audit-logged with the acting user, the order, the purpose, and the time.
  • Authorization codes and credentials are redacted from error messages and logs.

Reporting a security issue

Email support@fretron.com with SECURITY in the subject line, or call +91 9711799111. Security reports go straight to the engineering on-call.

Section 8

Subprocessors

These are the third parties that process CommerceOS data on our behalf. Each is bound by contract to use it only to provide their service to us.

Subprocessor Purpose Location Data involved
Google Cloud Platform (Google Cloud India / Google LLC) Application hosting, managed Kubernetes, file/document object storage, and Cloud KMS key protection. asia-south1 (Mumbai), India All CommerceOS application data, including Amazon Information, at rest and in processing.
Anthropic PBC Provides Claude models for the optional CommerceOS assistant through the Anthropic API. Only invoked when a user of the seller’s account uses the assistant. The CommerceOS API account is configured for zero data retention: prompts and outputs are not retained by Anthropic and are not used for model training. United States Only the minimum operational order, inventory or catalog data the user’s assistant query concerns. Amazon buyer personal information is excluded: restricted buyer data is not stored on the operational records the assistant reads.
xAI Corp. Provides Grok models for intent recognition in the optional warehouse operator voice interface through the xAI API. The CommerceOS API account is configured for zero data retention: API requests and outputs are not retained by xAI and are not used for model training. United States Spoken operator commands and the minimum operational identifiers required to execute them. Warehouse voice flows do not involve Amazon buyer personal information.
GST Suvidha Providers (Clear/ClearTax, MasterGST, Whitebooks) Generation of GST e-invoices and e-way bills where the seller enables Indian GST compliance. Invoked only on documents the seller chooses to file. India Invoice-level tax data required by law for e-invoicing, which may include the ship-to address on the invoice.

Carriers, warehouse operators and fulfilment partners are configured by the seller in their own account and act on the seller’s instructions, not ours. They are not Fretron subprocessors; they receive only what that seller’s shipment requires.

Section 9

Your Rights

A seller may ask us to give them a copy of the data held for their account, correct it, restrict how it is processed, or delete it. Where a buyer wishes to exercise a right over their own personal data, that request goes to the seller they bought from, who is the controller of it; we support the seller in acting on it.

Requests go to privacy@fretron.com and are handled on the timelines in section 6.

Section 10

Changes to This Notice

We update this notice when what we do changes. The date at the top always reflects the current version. Where a change materially affects how marketplace information is handled, we notify affected sellers directly rather than relying on this page alone.

Questions About This Notice

Email privacy@fretron.com or call +91 9711799111, Monday to Saturday 09:30–18:30 IST.

CommerceOS product page · Pricing · Website privacy policy

Review build