Privacy policy
Last updated September 24, 2026
This policy explains what Mizan, operated by Authect, collects, why, who else processes it and the choices you have. Contact us at privacy@xolt.io.
What we collect
Account data: your name, email address, a hash of your password, two-step verification settings, and your organizations, workspaces and roles.
Seller business data, only after you authorize it through Amazon: sales, traffic, fees, settlements, inventory, returns and listings for the accounts you connect. We do not request buyer names, addresses, emails or phone numbers. If a report contains such columns we drop them before storing anything, and we keep order IDs only as keyed hashes.
Data you enter: product costs, fixed costs and targets.
If you connect Google for Sheets export: an authorization limited to the spreadsheets Mizan creates in your Drive.
Technical data: IP addresses for rate limiting and security, and error reports with personal data removed.
How we use it
To provide the service: sync your Amazon data, calculate profit and inventory metrics, write your monthly action plan, build exports and send the emails you ask for (sign-in, verification, re-authorization reminders and monthly reports).
To keep the service secure and working. We do not sell your data, use it for advertising, or use it to train AI models.
AI processing
The monthly action plan is written by Anthropic's API from aggregated findings only (product identifiers, titles and the related numbers). Raw reports, order data and buyer data are never sent.
Who processes data for us
We use a small set of sub-processors for hosting, the database, background jobs, encryption and storage, AI, email and error monitoring. The current list, with purpose and region, is on the Sub-processors page. We share data with others only if the law requires it.
How long we keep it
Seller data is kept while the Amazon connection exists. When you disconnect, sync stops at once, the authorization is wiped, and the data is deleted 30 days later unless you reconnect, or immediately if you choose.
Deleting an organization or your account removes its data at once. Sessions expire after 7 days of inactivity. Security audit records are kept for up to 2 years, and a minimal record that a deletion happened is kept to prove it.
Your rights and choices
You can access and export your organization's data, correct it, disconnect Amazon or Google, and delete your account or organization from the app. For any other request, including under the GDPR or the privacy laws of the UAE, Saudi Arabia or Egypt, write to privacy@xolt.io and we will answer within 30 days.
Where data is stored
Our database and file storage run in the European Union. Some sub-processors, such as the AI provider, may process data in the United States under appropriate safeguards.
Cookies
We use only the cookies the app needs: your sign-in session, and your language and theme preferences. We use no advertising or tracking cookies.
Security
We encrypt data in transit and at rest, encrypt authorizations with AWS KMS, isolate each customer's data in the database and require two-step verification for sensitive actions. The Security page has the details. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as the law requires.
Children
Mizan is a business service and is not meant for anyone under 18.
Changes
We will update this page and the date above when this policy changes, and tell account owners by email about material changes.