← Back to keel

Keel — Privacy Policy

Provider: The Smart Fellows (“TSF,” “we,” “us,” “our”)  ·  Applies to: the Keel application and the Keel marketing site (together, the “Service”)  ·  Effective date: August 9, 2026  ·  Last updated: August 9, 2026

1. Overview & our role

This Policy explains what information we handle and how. Keel is a business-to-business tool for Amazon and Walmart sellers: compliance orientation, landed-cost math, FBA reimbursement preparation, listing monitoring, and review intelligence. For the business data a customer brings into its Keel workspace (“Customer Data”), the customer is the controller and TSF is the processor — we handle it on the customer’s behalf under our Terms of Service. For our own site visitors and for the account data of a customer’s users, TSF is the controller and this Policy describes our own practices. Keel is not designed to collect or process end-consumer personal information.

2. Information we handle

a) Account data (personal). Email address and authentication data for the people a customer authorizes to use Keel, plus workspace role and optional name. Used to sign users in, enforce their role, and support them.

b) Customer business data (not consumer PII). Products, SKUs, costs and pricing, compliance answers and generated labels, certificates and documents the customer stores in its document vault, marketplace listing data, and reimbursement-claim worksheets the customer builds.

c) Marketplace connection data. When a customer connects a marketplace account (for example, Amazon through Amazon’s Selling Partner API), we store the read-only connection credentials server-side and use them only to retrieve that customer’s own marketplace data at its direction. We never use a connection to edit listings, change prices, submit claims, or take any other action on a customer’s account.

d) Usage & technical data. Operational server and request logs — IP address, browser/device type, timestamps, error events — used for security, troubleshooting, and reliability. This is not third-party analytics or ad-tracking (see §6).

e) Marketing-site & contact data. If you submit the email form on the marketing site, we collect the email address you provide, which free tool you used, and a snapshot of the figures you entered into that tool (for the landed-cost calculator this includes the costs, prices and margins you typed). We also record a salted hash of your IP address — never the raw address — and your browser type, to rate-limit abuse. Our team is notified of each submission so we can follow up. If you email us, we receive what you send.

f) Billing data. Billing contact details, plan, and payment records. Card payments are processed by our payment processor — we never receive or store full card numbers. Invoices paid by ACH or wire transfer are handled through our bank; we see the payment reference and remittance details, not your online banking credentials.

Categories of personal information (CCPA/CPRA notice at collection).

Statutory categoryCollected?ExamplesPurposeRetention
IdentifiersYesWork email, user ID, IPAuthenticate users; operate/secure the Service; respond to inquiriesAccount: subscription life + wind-down (§8); marketing contacts: 24 months
Commercial informationYesPlan, billing contact, payment recordsProvide and bill the ServiceSubscription life + legal/tax retention
Internet/network activityYesLog and error eventsSecurity, reliability, troubleshootingRolling operational basis (§8)
Sensitive PI — account log-in credentialsYesKeel auth credentials; marketplace connection tokensOnly to sign in / operate the account and retrieve data at the customer’s directionLife of the account/connection
Geolocation (precise), biometric, health, protected-class dataNoWe do not collect these

Sensitive personal information (SPI). The only SPI we handle is account and marketplace-connection credentials. We use SPI solely to provide the Service and do not use it to infer characteristics; we therefore do not use or disclose SPI for any purpose that would trigger a “Limit the Use of My Sensitive Personal Information” right.

3. How we use information

We do not sell personal information, do not “share” it for cross-context behavioral advertising, and do not use Customer Data to train AI models.

4. Legal bases for processing (EEA/UK)

ProcessingLegal basis (UK/EU GDPR Art. 6)
Providing the Service to a customer and its authorized users; billingContract — necessary to perform our agreement with you
Security, abuse prevention, rate limiting, reliability, service improvementLegitimate interests — running a secure, working service, balanced against your rights
Marketing emails to people who submitted the marketing-site formConsent — given at the form, withdrawable at any time (§10)
Keeping financial, tax and legal recordsLegal obligation

Where we act as a processor for Customer Data, we process it on the customer’s documented instructions under our Terms of Service and our Data Processing Addendum, which is available to customers on request at info@thesmartfellows.us.

5. Marketplace & public listing data

Keel’s operating tools work on the customer’s own marketplace data, retrieved read-only and at the customer’s direction.

Separately, where the listing-research lookup is enabled for a customer, that customer can ask Keel to read one specific public product page. Any such request is user-directed and one page at a time: we do not crawl, we do not build or keep a catalogue of scraped pages, and nothing from the lookup is retained beyond the customer’s own session. We carry out the retrieval through commercial services — Rainforest API and BlueCart API, which return structured listing data, and ScraperAPI, which returns the page content itself. Before anything is shown or stored, our normalizer strips reviewer names and other end-consumer personal information. Keel does not build profiles of consumers, does not store reviewer identities, and never posts, replies, or acts on a marketplace on a customer’s behalf.

6. Cookies & similar technologies

7. How we share information — service providers

We do not sell your data. We share it only with service providers (sub-processors) that help us run the Service, each bound by contract to protect it and use it only to provide the Service:

Service providerPurposeData involved
Supabase — cloud hosting, database, authentication, storageRuns the app, database, sign-in, and document vaultAll Service data; hosted in the United States (us-east-1); request logs
Netlify — site deliveryHosts and delivers the site and appVisitor request logs (IP, user agent)
Slack — internal notificationsNotifies our team when someone submits the marketing form or requests a plan changeThe submitted email address and the request details
Stripe — payment processingProcesses card payments and issues invoicesBilling contact and payment details; card data goes to Stripe, never to us
PNC Bank — bankingReceives ACH and wire payments on invoicesPayment and remittance records
Marketplaces you connect (Amazon Selling Partner API, Walmart)Retrieve your own marketplace data, read-only, at your directionYour marketplace data, only for the marketplace you connect
Listing-research services — Rainforest API and BlueCart API (structured listing data); ScraperAPI (page retrieval)Retrieve the one public product page you ask Keel to readThe product URL or identifier you submit; no account data; reviewer personal data stripped before storage; nothing retained after your session

We may also disclose information to comply with law or valid legal process, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice as required). We will keep this list current and notify customers of material changes to our sub-processors.

8. Data retention

9. Security

Customer workspaces are isolated at the database layer with row-level security — every query is scoped to the customer’s own workspace, and paid-module access is enforced in the database, not just in the interface. Data is encrypted in transit and at rest by our hosting provider. Documents live in a private storage bucket reachable only through short-lived signed links. Only a publishable, non-privileged API key is ever sent to the browser; privileged keys and provider secrets stay server-side. No method of transmission or storage is completely secure, but we work to protect your information appropriately for a business tool of this kind, and we will notify affected customers without undue delay — and no later than 72 hours — after confirming a breach affecting their data.

10. Your rights

Everyone

You may ask us to access, correct, or delete your personal information, or to provide a copy of it. To exercise any right — including unsubscribing from Keel updates — email info@thesmartfellows.us. We will verify your request and respond within the time the applicable law allows. If you are an employee of a Keel customer and your request concerns that customer’s workspace data, we may refer the request to that customer, who controls it. We will not discriminate against you for exercising your rights.

EEA and UK residents (GDPR)

You have the right to access your personal data; to rectification; to erasure; to restriction of processing; to data portability; to object to processing carried out on the basis of our legitimate interests; and to withdraw consent at any time (withdrawal does not affect processing already carried out). You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office.

International transfers. We are based in the United States and our infrastructure is hosted in the United States. When personal data is transferred out of the EEA or UK to us or our sub-processors, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with the technical measures described in §9 — and, where a provider participates in it, the EU–US Data Privacy Framework. You may request a copy of the relevant transfer safeguards at the address above.

California residents (CCPA/CPRA)

We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. The categories we collect, our purposes, and our retention periods are set out in §2 and §8. You may exercise your rights to know, delete, and correct at the address above, and you may use an authorized agent.

11. Children

The Service is a business tool, is not directed to children, and we do not knowingly collect personal information from anyone under 16. (Keel’s compliance tooling helps sellers assess regulations that apply to children’s products — that involves product data, not children’s personal information.)

12. Changes to this Policy

We may update this Policy. For material changes we will post the updated Policy here, update the “Last updated” date, and notify account holders. Continued use of the Service after the effective date constitutes acceptance.

13. Contact

The Smart Fellows
794 Lost Creek Lane
Northfield, OH 44067
United States
info@thesmartfellows.us