Trust & legal
Privacy Policy
This policy describes how Xylem handles information when you use our marketplace operations service.
Last updated August 6, 2026Version 1.0.0
Overview
Xylem Strategic, LLC (“Xylem,” “we,” “us”) provides a software platform that helps brands manage marketplace catalog, listings, performance, inventory, and related workflows (“Service”).
This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices available to you. It is designed around how Xylem works today — including authentication, workspaces, marketplace account connections, uploaded reports, and future AI-assisted features.
Xylem is not affiliated with, endorsed by, or an official partner of Amazon or any other marketplace unless we expressly say so in writing.
Information we collect
Account and authentication. When you create an account we process email address, password (stored as a secure hash by our authentication provider), and optional display name. Session cookies are used to keep you signed in.
Workspace and organization. We store workspace names, membership roles, invitations, brand records, and activity needed to operate multi-user access.
Marketplace connection information. When you connect or register a marketplace account we store identifiers you provide (such as seller or marketplace account labels, marketplace region, and connection status). When OAuth or Selling Partner API authorization is enabled, authorization tokens and association metadata are stored on our servers — never exposed to browser clients.
Marketplace and operational data. Depending on the features you use, this may include catalog and product attributes, listing content, advertising or performance metrics, inventory and pricing data, publishing status, and related operational records obtained from uploads or marketplace APIs.
Uploaded files and assets. Files you upload (for example performance reports or product assets) are stored to provide the Service. We do not strip available provenance metadata from assets without a product reason.
Usage and diagnostics. We may process basic application logs and diagnostic information needed to operate, secure, and troubleshoot the Service (such as timestamps, error events, and request metadata). We do not currently use a third-party advertising or product-analytics cookie toolkit on the public site.
Support communications. If you contact us, we process the content of your message and related account context needed to respond.
Cookies. Essential cookies are used for authentication and security. We do not presently set non-essential tracking cookies for advertising. If that changes, we will update this policy and introduce appropriate preferences controls.
How we use information
- Provide, operate, and maintain the Service
- Authenticate users and enforce workspace access controls
- Connect and sync supported marketplace accounts
- Analyze performance data you upload or authorize
- Improve product quality and reliability
- Detect, prevent, and investigate fraud, abuse, and security issues
- Provide customer support
- Power AI-assisted features when you use them, subject to this policy and our AI at Xylem page
- Comply with legal obligations and enforce our terms
AI processing
Some Xylem features may use automated or AI-assisted processing to generate drafts, summaries, insights, or recommendations. When those features require a third-party model provider, relevant content may be sent to that provider solely to perform the requested function.
AI-assisted output can be incomplete or incorrect. You remain responsible for reviewing material before publishing or acting on it. See AI at Xylem for our transparency principles.
Retention, disconnection, and deletion
We retain information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type.
You may disconnect marketplace accounts from Settings when you have permission to manage brand channels. Disconnecting stops further synchronization for that connection; some historical records may remain until deleted or purged according to workspace policy.
You may request account deletion through Data requests or Settings → Privacy & Data. Deletion may be processed as a verified request while automated cascading deletion continues to mature.
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. Use Data requests or contact privacy support to exercise these rights. We may need to verify your identity before fulfilling a request.
International processing: Xylem is initially U.S.-focused. Information may be processed in the United States and other countries where our providers operate. If we offer the Service in additional regions, we will update this policy accordingly.
Security and children
We apply administrative and technical safeguards appropriate to our stage, including encrypted transport (HTTPS), authentication, workspace isolation via database access policies, and server-side handling of secrets. Details are summarized on our Security page. No method of transmission or storage is perfectly secure.
The Service is not directed to children under 16, and we do not knowingly collect personal information from children.
Policy updates
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be indicated by updating that date and, where appropriate, additional notice in the product.
Contact
Privacy questions and data requests: visit Data requests or use Support.
Operating entity: Xylem Strategic, LLC. A business mailing address will be published here once finalized; until then, contact Support for written correspondence.