1. Who we are and what this covers
CBT Labs, Inc., a Delaware corporation, is the controller of the personal data described here. This policy covers the cbtlabs.co website and the application at app.cbtlabs.co.
It does not cover Mercado Libre, Amazon, Google or any other platform you connect: each of them processes data under its own policy.
2. Information we collect
We collect only what the Service needs in order to work:
- Account data: name, email address, company, profile picture if you sign in with Google, and the sign-in method you used.
- Authentication data: encrypted password, session history, active sessions with their approximate date, browser and operating system.
- Marketplace connection: your Mercado Libre seller identifier, the access and refresh tokens of the connection, and β if you use your own application β its DevCenter credentials. Tokens and credentials are stored encrypted.
- Catalog data: products, ASINs, titles, descriptions, images, source prices, stock, brand and category blacklists.
- Configuration: margins per country, taxes, logistics costs, publishing rules, synchronization frequency and notification preferences.
- Sales data: orders, listings sold, amounts, currencies, marketplace fees, shipping costs, withholdings and the costs you enter to calculate profitability.
- Billing data: plan, credits, invoices and payment status. The card is processed by Stripe; we do not receive or store the full number.
- Technical data: IP address, browser, device, timestamps and error logs generated when you use the app.
3. How we use your information
We use the data to:
- Create and maintain your account and keep your session secure.
- Publish, update, pause and synchronize your listings on the marketplaces you connect.
- Generate titles, descriptions and translations adapted to each country.
- Calculate suggested prices, margins and profitability of your sales.
- Process payments, credits and subscriptions.
- Send you operational notifications you configured: publishing errors, low credits, daily summaries.
- Detect abuse, diagnose failures and improve the Service.
- Comply with legal obligations that apply to us.
4. Legal bases for processing
Where the GDPR or equivalent rules apply, we process data on these bases: performance of the contract, for everything required to deliver the Service you contracted; legitimate interest, for security, fraud prevention and product improvement; consent, for optional communications, which you can withdraw at any time; and legal obligation, for accounting and tax records.
5. Mercado Libre data and access tokens
When you connect your seller account, Mercado Libre issues us tokens that let us act on your behalf. We store them encrypted and use them exclusively to run the features you use: publishing, synchronization, reading orders and reading shipping costs.
We do not use your marketplace data to sell to your customers, we do not share it with other sellers on the platform, and we do not use it to build audience or contact lists.
You may revoke the connection at any time, from the Service or from your Mercado Libre account. Once revoked, the tokens stop working and we delete them.
6. AI processing
To generate titles, descriptions and translations, we send product data β title, description, attributes, category β to language model providers acting as processors on our behalf, under contracts that forbid using that content to train general models.
We do not send account data, passwords, payment data or customer data to those providers.
8. International transfers
The Service runs on infrastructure located in the United States. If you use it from Latin America or the European Union, your data will be transferred to and processed in that country, with the contractual safeguards required by the applicable rules.
10. How long we keep data
We keep account and catalog data for as long as your account is active. When you delete it, we remove your personal data and revoke your marketplace tokens.
Billing and invoicing records are kept for the period tax law requires. Aggregate data that no longer identifies anyone may be kept without a time limit.
11. Security
Traffic travels over TLS, passwords are stored hashed, marketplace tokens and credentials are encrypted, and access to production is limited to the people who need it.
No system is perfectly secure. If a breach occurs that affects your data, we will notify you and the authority in charge within the time frames the law requires.
12. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, request a portable copy, object to certain processing or withdraw a consent you gave.
Much of this you can do yourself: edit your profile, review and close sessions, disconnect your marketplace account, and delete your account from the profile screen. For anything else, write to [CONTACT EMAIL] and we will answer within the legal time frame.
If you are in the European Union or the United Kingdom, you may also lodge a complaint with your data protection authority.
13. Children
The Service is aimed at businesses and is not directed to minors. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
14. Changes to this policy
We will update this page when the Service changes. If a change materially affects how we handle your data, we will notify you by email or inside the app before it takes effect.
15. Contact
CBT Labs, Inc. β [MAILING ADDRESS], Delaware, United States.
Privacy questions or requests about your data: [CONTACT EMAIL].