Legal
Privacy Policy
Last updated: August 6, 2026
Metrique (“Metrique”, “we”, “us”, “our”) provides operations, inventory, finance, and advertising analytics software for e-commerce sellers, delivered through our web dashboard, mobile application, and API integrations (the “Service”). This Privacy Policy explains what information we collect, why we collect it, how it is stored and protected — including how we handle access to your connected Amazon Seller and Advertising accounts — and the choices and rights available to you.
By creating a Metrique account, connecting an Amazon account, or otherwise using the Service, you agree to the collection and use of information as described in this policy.
1.Scope & who this policy covers
This policy applies to organizations and individual users (“you”, “your”) who use Metrique to manage e-commerce operations — including business owners, employees, and staff invited to a Metrique organization workspace — and to the data we process on their behalf as a result. It covers our web application, mobile application, backend services, and any integrations we offer with third-party platforms such as Amazon.
Metrique is a business-to-business tool. We are not a consumer marketplace, and we do not knowingly collect data directly from your end customers (the shoppers who buy from your Amazon store) — see Section 5 for exactly what order-related data we do and do not store.
2.Who we are
Metrique is operated by Clinch Studio, registered at Mayuri Nagar, Miyapur, Hyderabad, India (“Metrique”, “we”, “us”). For the purposes of applicable data protection law, Metrique acts as the data controller for account and organization data described in Section 3.1, and as a data processor acting on your instructions for the Amazon seller data described in Sections 3.2 and 4, which you control as the Amazon seller of record.
3.Information we collect
3.1 Account & organization information
To create and operate a Metrique account for you and your team, we collect:
- Name, email address, and phone number of each individual user invited to your organization
- Organization details (business name, GSTIN where provided, business locations)
- Role and permission assignments within your organization’s workspace
- Authentication data (hashed passwords, session tokens) — we never store passwords in plain text
This is the only category of personally identifiable information we hold about individuals, and it belongs to your own team members who use the Service — not to your end customers. See Section 5 for what we explicitly exclude.
3.2 Amazon seller data (via API integrations)
When you connect an Amazon Selling Partner or Amazon Advertising account, we ingest and store the business data made available through Amazon’s APIs so we can power your dashboards. This includes:
- Orders & returns — order IDs, order item IDs, SKUs, ASINs, quantities, order status, dates, return reasons and disposition codes
- Financial data — settlements, fees, reimbursements, tax reports (MTR/GST filings), deferrals, and payouts
- Inventory data — FBA stock levels, fulfillment center IDs, batch and expiry metadata you record
- Advertising data — campaign, ad group, keyword, and search-term performance metrics
- Catalogue & listing data — product titles, images, ASIN-to-SKU mappings, and Brand Analytics reporting
This data is operational and financial in nature — it is scoped to your business, not to individual shoppers. See Section 4 for exactly how this access works.
3.3 Technical & usage data
Like most web and mobile applications, our servers automatically log technical information needed for security, debugging, and reliability: IP address, device and browser type, operating system, timestamps, and the API endpoints or screens accessed. We use this data to keep the Service secure and functioning — not for advertising or profiling.
4.Amazon account access
Because Metrique is built to work directly against your Amazon Seller Central data, how we access and handle your Amazon account is one of the most important parts of this policy. We take it seriously.
4.1 How authorization works
We never ask for or store your Amazon Seller Central username or password. Instead, you authorize Metrique through Amazon’s own secure authorization flow — Login with Amazon (LWA) for the Selling Partner API, and Amazon’s standard OAuth flow for the Advertising API. Amazon issues Metrique a scoped refresh token tied to your seller account, which we use to request short-lived access tokens on your behalf. At no point does this flow expose your Amazon login credentials to us.
4.2 Scope of access
We request only the Amazon API “roles” (permission scopes) required for the specific features you use — for example, Orders, Finance, Inventory and Fulfillment, Amazon Advertising, and Brand Analytics. Where a feature requires an additional role we don’t already have (for example, listing images or carrier pickup scheduling), we ask for that specific role only when you enable that feature — we do not request broad, unused access “just in case.”
4.3 What we do with this access
We do
- Read order, financial, inventory, and advertising data to build your reports
- Perform an action on Amazon only when you explicitly trigger it in the app (e.g. rescheduling a carrier pickup)
- Store the minimum data needed to power your dashboards
- Use Amazon data solely to provide the Service to your organization
We don’t
- Create, cancel, or modify orders on your behalf
- Take automated or independent actions on your Amazon account without your direct action
- Sell, rent, or share your Amazon account data with advertisers or data brokers
- Use your Amazon data to train general-purpose or third-party machine learning models
4.4 Credential security
Refresh tokens and API client secrets are encrypted at rest (AES-256-GCM) in our database and are never displayed back to any user, including your own team, once submitted. Access to decrypt and use these credentials is restricted to the backend services that need them to sync your data, and every sync operation is scoped to your organization.
4.5 Revoking access
You can revoke Metrique’s access to your Amazon account at any time — either from within Metrique (organization settings) or directly from Amazon Seller Central / Advertising Console under your connected third-party apps. Once revoked, we can no longer pull new data from Amazon on your behalf, and previously issued tokens are deleted.
4.6 Compliance with Amazon’s requirements
Our use of information received from Amazon’s APIs complies with the Amazon Data Protection Policy and the applicable Acceptable Use Policy for the Selling Partner API and Advertising API. We do not use Amazon Information to market to end customers, and we do not combine Amazon Information with data from other sources to build profiles of individual shoppers.
5.What we do not collect or store
We do not store your end customers’ personal information in our database. Order and return data synced from Amazon is limited to operational identifiers — order ID, SKU, ASIN, quantities, amounts, dates, fulfillment center, and return/reason codes. We do not ingest or persist buyer names, email addresses, phone numbers, or shipping addresses.
Specifically, Metrique does not collect, process, or retain:
- The names, email addresses, or phone numbers of your customers who purchase through Amazon
- Shipping or billing addresses of your customers
- Payment card or other financial instrument details belonging to your customers
- Any Amazon “PII” fields beyond aggregate, order-level identifiers necessary for reconciliation and reporting
Where a compliance report from Amazon (such as a GST/tax report) includes jurisdiction-level fields (e.g. the buyer’s state, for tax purposes), this is retained only where it is not personally identifying and only to the extent required for the reporting feature it supports.
We also do not use cookies for third-party advertising, do not run ad-tracking pixels, and do not sell any data — yours or your customers’ — to data brokers, advertisers, or any third party.
6.How we use information
We use the information described above solely to:
- Operate, maintain, and improve the Metrique Service for your organization
- Build the reporting, analytics, and alerting features you access within your dashboards
- Authenticate users and enforce your organization’s role-based access controls
- Provide customer support and respond to your requests
- Detect, prevent, and investigate security incidents, fraud, or abuse
- Comply with legal and regulatory obligations (e.g. audit trails, tax reporting)
We do not use your data to build advertising profiles, and we do not sell your data or your customers’ data to any third party for advertising or marketing purposes.
7.Legal basis for processing
Depending on your location and applicable law, our basis for processing personal information includes:
- Performance of a contract — processing your organization’s account data is necessary to provide the Service you signed up for
- Legitimate interests — for security monitoring, fraud prevention, and service improvement
- Consent — where you explicitly authorize an Amazon account connection or opt in to a specific feature
- Legal obligation — where retention or disclosure is required by law (e.g. tax records)
For users in India, we process personal data in accordance with the applicable provisions of the Digital Personal Data Protection Act, 2023 and related rules.
9.Sub-processors & third-party services
We rely on a small number of vetted infrastructure providers to operate the Service:
- Amazon Web Services (AWS) — application hosting and database infrastructure (RDS, EC2)
- Amazon Selling Partner API & Advertising API — the source of the seller data described in Sections 3.2 and 4
- Transactional email provider — for account activation, invites, and operational notifications
Each sub-processor is contractually bound to use data only to provide services to Metrique and to apply security measures at least as protective as those described in this policy.
10.Storage, security & access control
- Data is stored in a private, access-controlled database that is not publicly reachable
- Amazon API credentials (client secrets, refresh tokens) are encrypted at rest using AES-256-GCM and are never displayed back to any user once submitted
- Access to your organization’s data is restricted to authenticated users within your organization, enforced through role-based access control (RBAC)
- All data in transit between your device, our servers, and Amazon’s APIs is encrypted using TLS
- Internal access to production systems is limited to personnel who need it to operate and support the Service
No method of transmission or storage is 100% secure. We continually work to protect your information, but we cannot guarantee absolute security.
11.Data retention
We retain synced Amazon data and account information for as long as your Metrique account remains active, so that historical reporting and trend analysis stay available to you. If you disconnect an Amazon account, the associated credentials are deleted immediately and we stop syncing new data; previously synced operational data is retained unless you request its deletion.
If you close your Metrique account, you may request deletion of your organization’s data by contacting us at the address in Section 17. We may retain limited data where required by law (e.g. financial records for statutory retention periods) or to resolve disputes and enforce our agreements.
12.Your rights & how to exercise them
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data, subject to legal retention requirements
- Withdraw consent for a connected Amazon account at any time
- Object to or restrict certain processing of your data
- Request a copy of your data in a portable format
To exercise any of these rights, contact us using the details in Section 17. We will respond within a reasonable timeframe and in accordance with applicable law.
Grievance Officer: in accordance with the Digital Personal Data Protection Act, 2023, you may direct grievances relating to your personal data to our Grievance Officer at info@clinchstudio.com.
14.Children's privacy
The Service is intended for business use by adults operating or working for an e-commerce seller. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of 18.
15.International data transfers
Our infrastructure is hosted with cloud providers that may process data in regions outside your own country. Where data is transferred internationally, we take reasonable steps to ensure it receives a comparable level of protection to that described in this policy, including through contractual safeguards with our infrastructure providers.
16.Changes to this policy
We may update this policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. Material changes will be reflected by an updated “Last updated” date above, and where changes are significant, we will provide additional notice (such as an in-app or email notification).
17.Contact us
If you have questions about this policy, your data, or how we handle your connected Amazon account, contact us at:
- Email: info@clinchstudio.com
- Grievance Officer: info@clinchstudio.com
- Registered address: Clinch Studio, Mayuri Nagar, Miyapur, Hyderabad, India