Keel — Privacy Policy
1. Overview & our role
This Policy explains what information we handle and how. Keel is a business-to-business tool for Amazon and Walmart sellers: compliance orientation, landed-cost math, FBA reimbursement preparation, listing monitoring, and review intelligence. For the business data a customer brings into its Keel workspace (“Customer Data”), the customer is the controller and TSF is the processor — we handle it on the customer’s behalf under our Terms of Service. For our own site visitors and for the account data of a customer’s users, TSF is the controller and this Policy describes our own practices. Keel is not designed to collect or process end-consumer personal information.
2. Information we handle
a) Account data (personal). Email address and authentication data for the people a customer authorizes to use Keel, plus workspace role and optional name. Used to sign users in, enforce their role, and support them.
b) Customer business data (not consumer PII). Products, SKUs, costs and pricing, compliance answers and generated labels, certificates and documents the customer stores in its document vault, marketplace listing data, and reimbursement-claim worksheets the customer builds.
c) Marketplace connection data. When a customer connects a marketplace account (for example, Amazon through Amazon’s Selling Partner API), we store the read-only connection credentials server-side and use them only to retrieve that customer’s own marketplace data at its direction. We never use a connection to edit listings, change prices, submit claims, or take any other action on a customer’s account.
d) Usage & technical data. Operational server and request logs — IP address, browser/device type, timestamps, error events — used for security, troubleshooting, and reliability. This is not third-party analytics or ad-tracking (see §6).
e) Marketing-site & contact data. If you submit the email form on the marketing site, we collect the email address you provide, which free tool you used, and a snapshot of the figures you entered into that tool (for the landed-cost calculator this includes the costs, prices and margins you typed). We also record a salted hash of your IP address — never the raw address — and your browser type, to rate-limit abuse. Our team is notified of each submission so we can follow up. If you email us, we receive what you send.
f) Billing data. Billing contact details, plan, and payment records. Card payments are processed by our payment processor — we never receive or store full card numbers. Invoices paid by ACH or wire transfer are handled through our bank; we see the payment reference and remittance details, not your online banking credentials.
Categories of personal information (CCPA/CPRA notice at collection).
| Statutory category | Collected? | Examples | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Yes | Work email, user ID, IP | Authenticate users; operate/secure the Service; respond to inquiries | Account: subscription life + wind-down (§8); marketing contacts: 24 months |
| Commercial information | Yes | Plan, billing contact, payment records | Provide and bill the Service | Subscription life + legal/tax retention |
| Internet/network activity | Yes | Log and error events | Security, reliability, troubleshooting | Rolling operational basis (§8) |
| Sensitive PI — account log-in credentials | Yes | Keel auth credentials; marketplace connection tokens | Only to sign in / operate the account and retrieve data at the customer’s direction | Life of the account/connection |
| Geolocation (precise), biometric, health, protected-class data | No | — | We do not collect these | — |
Sensitive personal information (SPI). The only SPI we handle is account and marketplace-connection credentials. We use SPI solely to provide the Service and do not use it to infer characteristics; we therefore do not use or disclose SPI for any purpose that would trigger a “Limit the Use of My Sensitive Personal Information” right.
3. How we use information
- Provide, secure, support, maintain, and improve the Service.
- Authenticate users and enforce roles, plans, and tenant isolation.
- Retrieve and analyze a customer’s own marketplace data at its direction.
- Bill for the Service and keep the records tax and accounting rules require.
- Respond to inquiries and, where you have asked us to, send occasional Keel updates.
- Detect, prevent, and address security incidents, fraud, and abuse.
- Comply with law and enforce our agreements.
We do not sell personal information, do not “share” it for cross-context behavioral advertising, and do not use Customer Data to train AI models.
4. Legal bases for processing (EEA/UK)
| Processing | Legal basis (UK/EU GDPR Art. 6) |
|---|---|
| Providing the Service to a customer and its authorized users; billing | Contract — necessary to perform our agreement with you |
| Security, abuse prevention, rate limiting, reliability, service improvement | Legitimate interests — running a secure, working service, balanced against your rights |
| Marketing emails to people who submitted the marketing-site form | Consent — given at the form, withdrawable at any time (§10) |
| Keeping financial, tax and legal records | Legal obligation |
Where we act as a processor for Customer Data, we process it on the customer’s documented instructions under our Terms of Service and our Data Processing Addendum, which is available to customers on request at info@thesmartfellows.us.
5. Marketplace & public listing data
Keel’s operating tools work on the customer’s own marketplace data, retrieved read-only and at the customer’s direction.
Separately, where the listing-research lookup is enabled for a customer, that customer can ask Keel to read one specific public product page. Any such request is user-directed and one page at a time: we do not crawl, we do not build or keep a catalogue of scraped pages, and nothing from the lookup is retained beyond the customer’s own session. We carry out the retrieval through commercial services — Rainforest API and BlueCart API, which return structured listing data, and ScraperAPI, which returns the page content itself. Before anything is shown or stored, our normalizer strips reviewer names and other end-consumer personal information. Keel does not build profiles of consumers, does not store reviewer identities, and never posts, replies, or acts on a marketplace on a customer’s behalf.
6. Cookies & similar technologies
- Essential only. The app uses browser storage (localStorage) strictly to keep you signed in and to remember which workspace you are in. We set no advertising or tracking cookies.
- No third-party fonts or CDNs. Fonts and scripts are served from our own domain, and our content-security policy blocks third-party origins, so no font, CDN, or ad provider observes your visit.
- No analytics. As of the “Last updated” date we use no third-party analytics or advertising technology of any kind. If we add analytics, we will update this Policy, disclose it, and obtain any legally required consent before turning it on.
7. How we share information — service providers
We do not sell your data. We share it only with service providers (sub-processors) that help us run the Service, each bound by contract to protect it and use it only to provide the Service:
| Service provider | Purpose | Data involved |
|---|---|---|
| Supabase — cloud hosting, database, authentication, storage | Runs the app, database, sign-in, and document vault | All Service data; hosted in the United States (us-east-1); request logs |
| Netlify — site delivery | Hosts and delivers the site and app | Visitor request logs (IP, user agent) |
| Slack — internal notifications | Notifies our team when someone submits the marketing form or requests a plan change | The submitted email address and the request details |
| Stripe — payment processing | Processes card payments and issues invoices | Billing contact and payment details; card data goes to Stripe, never to us |
| PNC Bank — banking | Receives ACH and wire payments on invoices | Payment and remittance records |
| Marketplaces you connect (Amazon Selling Partner API, Walmart) | Retrieve your own marketplace data, read-only, at your direction | Your marketplace data, only for the marketplace you connect |
| Listing-research services — Rainforest API and BlueCart API (structured listing data); ScraperAPI (page retrieval) | Retrieve the one public product page you ask Keel to read | The product URL or identifier you submit; no account data; reviewer personal data stripped before storage; nothing retained after your session |
We may also disclose information to comply with law or valid legal process, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice as required). We will keep this list current and notify customers of material changes to our sub-processors.
8. Data retention
- Customer Data is retained for the life of the subscription. After termination you may request an export for 30 days; we then delete or de-identify Customer Data within 60 days, except for backups cycled in the ordinary course and records we must keep by law.
- Marketing contacts (emails submitted through the site) are retained for 24 months from the date you submitted them, or until you unsubscribe — whichever is sooner. If you unsubscribe we keep a minimal record of that request indefinitely, for the sole purpose of making sure we do not email you again.
- Operational logs are retained on a rolling operational basis by our hosting providers and are not kept as a permanent record.
- Billing records are retained as long as tax and accounting rules require.
9. Security
Customer workspaces are isolated at the database layer with row-level security — every query is scoped to the customer’s own workspace, and paid-module access is enforced in the database, not just in the interface. Data is encrypted in transit and at rest by our hosting provider. Documents live in a private storage bucket reachable only through short-lived signed links. Only a publishable, non-privileged API key is ever sent to the browser; privileged keys and provider secrets stay server-side. No method of transmission or storage is completely secure, but we work to protect your information appropriately for a business tool of this kind, and we will notify affected customers without undue delay — and no later than 72 hours — after confirming a breach affecting their data.
10. Your rights
Everyone
You may ask us to access, correct, or delete your personal information, or to provide a copy of it. To exercise any right — including unsubscribing from Keel updates — email info@thesmartfellows.us. We will verify your request and respond within the time the applicable law allows. If you are an employee of a Keel customer and your request concerns that customer’s workspace data, we may refer the request to that customer, who controls it. We will not discriminate against you for exercising your rights.
EEA and UK residents (GDPR)
You have the right to access your personal data; to rectification; to erasure; to restriction of processing; to data portability; to object to processing carried out on the basis of our legitimate interests; and to withdraw consent at any time (withdrawal does not affect processing already carried out). You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office.
International transfers. We are based in the United States and our infrastructure is hosted in the United States. When personal data is transferred out of the EEA or UK to us or our sub-processors, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with the technical measures described in §9 — and, where a provider participates in it, the EU–US Data Privacy Framework. You may request a copy of the relevant transfer safeguards at the address above.
California residents (CCPA/CPRA)
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. The categories we collect, our purposes, and our retention periods are set out in §2 and §8. You may exercise your rights to know, delete, and correct at the address above, and you may use an authorized agent.
11. Children
The Service is a business tool, is not directed to children, and we do not knowingly collect personal information from anyone under 16. (Keel’s compliance tooling helps sellers assess regulations that apply to children’s products — that involves product data, not children’s personal information.)
12. Changes to this Policy
We may update this Policy. For material changes we will post the updated Policy here, update the “Last updated” date, and notify account holders. Continued use of the Service after the effective date constitutes acceptance.
13. Contact
The Smart Fellows
794 Lost Creek Lane
Northfield, OH 44067
United States
info@thesmartfellows.us