Draft — legal review requiredLast updated 27 September 2026

Privacy Policy

What LazyOne collects, why it is collected, who processes it, how long it is kept, and how to get it deleted.

Warning

This document has not been legally reviewed

It is a working draft written to describe how the platform actually behaves. It has not been reviewed against the operating entity, jurisdiction, tax and consumer requirements, subscription terms, intellectual-property terms or grievance-contact obligations that apply. Do not rely on it as a binding agreement. Questions: brandbucksconsulting@gmail.com.

1. Scope

This policy covers the LazyOne website and workspace. It describes the platform as it is actually built. Where a protection is not yet implemented, this document says so rather than implying otherwise.

2. What we collect

Account information

Mobile number, email address, display name and account role, and which sign-in methods you use. Your PIN and your security-question answer are stored only as one-way hashes, never in a form that can be read back. Email passwords are held, hashed, by our authentication service; LazyOne does not store them itself.

Content you create

Brand profiles, discovery briefs, product records, campaign briefs, generated outputs, your edits, approvals, and files you upload such as logos, product images and video clips.

Operational records

Generation job status, attempt counts, safe error codes, request identifiers, timestamps and audit events for security-relevant actions such as role changes and administrative edits.

Technical data

Standard request metadata needed to serve pages and apply rate limits. Where we use a network address for abuse prevention it is hashed on receipt, so the raw address is not retained.

What we do not collect

We do not ask for payment card details, because there is no billing in this version. We do not use advertising trackers or third-party analytics profiling on the public site. We do not want passwords, API keys or client confidential documents sent through the contact form.

2a. Connected social and advertising accounts

If you connect a Facebook Page, an Instagram professional account, a Meta advertising account or a LinkedIn profile, we additionally store an access token issued by that platform, encrypted with AES-256-GCM; the connected account’s own identifier and name at that platform; the permissions that were granted; and, for Meta and LinkedIn, the app-scoped user identifier the platform gives us for you within our app alone.

The app-scoped identifier is stored for one reason: so that a deletion request originating at the platform can find everything you authorised. No administrator can read a stored token — there is deliberately no database permission that would allow it.

Removing an app in your Facebook settings sends us a signed deletion request. We verify it, delete every Facebook, Instagram and Meta advertising connection you authorised along with the encrypted tokens, cancel anything scheduled to post through them, and return a confirmation code and a link where you can check the result. What survives is a receipt — a status, a date and three counts, keyed by a one-way hash of the app-scoped identifier rather than by the identifier — and an audit entry recording that the deletion ran. Neither can re-identify you at the platform. Full details, including how to make the same request yourself, are on the data deletion page.

2b. Connected marketplace seller accounts

If you connect an Amazon Seller Central account or a Flipkart seller account, you authorise LazyOne through the marketplace’s own sign-in, and we store the refresh and access tokens it issues, encrypted with AES-256-GCM, together with your seller account identifier and the marketplaces you sell in. We read your seller data only through the marketplace’s official seller APIs — never by scraping, browser automation or uploaded reports.

What we read: your listings (SKU, ASIN or FSN, title, bullet points, description, images as links to the marketplace’s copies, attributes, variations, status, price, MRP or list price, available stock); your orders and order items (order and item identifiers, dates, SKU, quantity, price, tax, discount and status); refunds and returns where the marketplace reports them; sales figures per SKU; and, for Amazon sellers with Brand Analytics access, sessions and page views per SKU. We use it to show your listings and sales analytics, to run the pricing optimizer if you turn it on, and to make the changes described below.

What we change, and only on your instruction: on Amazon, listing text you approve (title, bullet points, description and search terms) and prices — either a price you approve, or a price set by a pricing optimizer that you activate, which works only within the minimum and maximum prices you set and which you can pause at any time. LazyOne does not change your stock on Amazon. On Flipkart, prices and stock you approve.

What we do not read or keep: your buyers’ names, email addresses, phone numbers or delivery addresses, or any other buyer personal data. We do not request the marketplace permissions that would provide it.

Your marketplace data is never sold or shared for advertising, and it is never sent to an AI provider: no listing, order, sale, return, stock figure or account detail read from a marketplace is used as input to AI generation, whichever provider key you have connected. Marketplace listings are edited by hand in LazyOne; AI features elsewhere in LazyOne work only with content you give them. The only services that process marketplace data on our behalf are our hosting and database providers, Render and Supabase (section 5). We keep marketplace data while the marketplace is connected, because the features you use read it. Disconnecting Amazon removes the stored Amazon credentials and the Amazon marketplace data associated with that connection, including the Amazon content of your change history; content-free security and audit records (that a change was made, when, and whether it succeeded) may be kept. Disconnecting Flipkart removes its tokens and the data read through it; the record of changes you approved and sent there stays in your change history until you close your LazyOne account. Closing your account deletes all of it. You can also withdraw LazyOne’s access in the marketplace’s own seller settings.

Who at LazyOne can access your marketplace data

Access to data read from a marketplace seller account, including Amazon, is restricted to authorised personnel with a business need. LazyOne is currently operated by its owner, who is the only person with administrative access to it, for support, security and maintenance. If employees, contractors or agents are ever given such access, LazyOne will first apply the required authorisation, verification, least-privilege and disclosure controls, and will update this policy.

3. Why we process it

  • To create and secure your account.
  • To store your brand profile and produce the output you request.
  • To keep generation history so you can see what was generated, edited and approved.
  • To provide support, and to investigate faults using request identifiers and safe error codes.
  • To protect the platform — rate limiting, abuse prevention and audit trails.
  • To meet legal obligations that apply to us.

4. AI processing — read this section

When you request generation, the relevant parts of your brief and brand profile are sent to the AI provider whose key you have connected in LazyOne, so it can produce the requested output. That means your brief content leaves our infrastructure and is processed by that provider under your agreement with them. Data read from a connected marketplace seller account is the exception: it is never sent to an AI provider (section 2b).

We cannot promise on that provider’s behalf that your content is never retained or never used for their own purposes. If your brief contains information you cannot share with a third-party processor, do not submit it for generation.

Retrieved website content and uploaded documents are treated as untrusted data rather than instructions, and we do not store more of a fetched page than the generation requires.

5. Processors we rely on

  • Render — application hosting: serves the application and runs its background work.
  • Supabase — database, authentication and file storage: stores your account, content, uploads and connected-account data.
  • AI providers you connect — process the briefs and content you submit for generation, on your own key. They never receive data read from a marketplace seller account.
  • Marketplace seller APIs — Amazon Selling Partner API and Flipkart Seller APIs, which you authorise. They are sources of your seller data; we send them only the changes you approve.
  • External workflow automation — optional. When enabled, it processes notification payloads such as a job identifier and a notification email address.

Data read from a connected marketplace seller account, including Amazon, is processed only by Render and Supabase. The locations and data-processing terms of our providers will be published here before this policy is final; that is part of the outstanding legal review.

6. Cross-border processing

Our providers may process data outside your country. The specific regions depend on the deployment configuration, and we will not assert a particular storage location until the implemented configuration has been verified.

7. Retention

  • Account records — kept while your account exists.
  • Brand profiles, projects and outputs — kept until you delete them.
  • Uploaded assets — kept until you delete them or delete the brand they belong to.
  • Operational logs — our application logs record error codes, statuses and counts, and are built not to contain passwords, tokens or marketplace content. How long our hosting provider keeps them is set by that provider’s configuration.
  • Marketplace seller data and tokens — kept while the marketplace is connected, refreshed by each sync, and deleted when you disconnect it or close your account. Content-free security and audit records may be kept. No fixed retention period applies while a marketplace stays connected.
  • Audit events — retained longer than ordinary content, because their purpose is to record who changed what.
  • Platform deletion receipts — a status, a date and three counts, kept so the confirmation link we gave you keeps working and so we can show the request was honoured. They contain no platform identifier.

Exact retention periods per category will be published here once they are set. Some items can be archived rather than deleted, and an archived item can be restored; deleting is permanent. Deleted data is removed from the live database immediately. Our database plan does not currently include backups; if that changes, we will review how long deleted data can remain in them and update this policy. We do not routinely keep manual copies of the production database; a temporary copy made for recovery or maintenance is kept secure, restricted to the owner, and deleted once that work is done.

8. Security

What is implemented:

  • Server-side authentication and authorisation for every protected action.
  • Database row-level security, so a query cannot return another user’s rows.
  • Secrets restricted to server environments and kept out of browser bundles.
  • Input validation at every trust boundary, and validation of AI output before it is stored.
  • Rate limits on authentication, generation, search, contact and uploads.
  • Restrictions on URL retrieval that block private and local network addresses.
  • Upload checks on type, extension, file signature and size.
  • Sanitisation of rich content before it is rendered.
  • Audit events for administrative and security-relevant actions.

We will not claim a specific encryption standard, certification or data-residency guarantee until the deployed configuration verifies it. No platform can promise absolute security.

9. Your rights

You can access the content in your workspace at any time, correct it directly, export generated output, and delete brands, assets and your account. To ask about data we hold, or to request deletion you cannot complete in the product, write to brandbucksconsulting@gmail.com.

To remove data from a connected Facebook, Instagram or Meta advertising account specifically, see the data deletion page. You can do it yourself, immediately, from either the platform or your LazyOne settings.

Depending on where you live, you may have additional statutory rights including objection, restriction, portability and complaint to a supervisory authority. The applicable framework and the response timelines we commit to will be stated here after legal review.

10. Deleting your account

Deleting your account removes your brand profiles, projects, generated outputs and uploaded assets, your connected accounts and their stored credentials — including Amazon and other marketplace seller connections — and all marketplace data held for you. Content-free security and audit records are kept for integrity and security; the account they point to is emptied of anything that identifies you. Deleted content is not recoverable once permanent removal has run, so export anything you want to keep first.

11. Children

LazyOne is a business tool and is not directed at children. We do not knowingly create accounts for people below the age at which they can consent in their jurisdiction.

12. Changes

When this policy changes materially we will update the date above and, for account holders, notify you through the product or by email.

13. Contact

Privacy questions and requests: brandbucksconsulting@gmail.com. The grievance-officer details required in our operating jurisdiction will be added here before this policy is treated as final.