Back to Support
DragonBotHelp

Security & privacy

Data protection

All data is encrypted in transit (TLS) and at rest. We store only secure OAuth tokens — never your passwords or raw credentials. Each workspace is fully isolated — your data is never shared or mixed with other users.

Amazon TOS compliance

DragonBot connects through the official Amazon SP-API. No scraping, no browser automation, no gray-area workarounds. We are fully compliant with Amazon's Terms of Service, Data Protection Policy, and Acceptable Use Policy.

Permission controls

You choose how DragonBot operates:

  • Read-only (default): DragonBot can only pull data and generate reports
  • Supervised: DragonBot asks before taking any action on your accounts
  • Autonomous: DragonBot handles routine tasks, escalating edge cases

Data retention

  • Amazon Customer PII: Retained max 30 days after order delivery, for fulfillment and tax compliance only
  • Amazon non-PII data: Deleted within 18 months
  • Account data: Retained while your account is active, deleted on closure
  • Security logs: Retained 12 months minimum for incident response

Audit trail

Every action DragonBot takes is logged — what it did, when, and why. You can review the full audit trail at any time. Nothing happens without a record.

Your rights

You can access, correct, delete, or export your data at any time. You can also revoke DragonBot's access to any connected service instantly. See our full Privacy & Data Protection Policy for details.

We don't train on your data

Your data is used solely to provide services to you. We do not use your data to train AI models. We do not sell your data. Period.

Still need help?

info@getdragonbot.com

© 2026 Chacha Advisory LLC. All rights reserved.

30 N Gould St Ste R, Sheridan, WY 82801, USA