Data Protection & Security
Last updated: 25 July 2026
Hoseh Seller is a seller-side profit-analytics tool. We connect to a seller's own marketplace shops with their permission, read a limited set of their own data, and use it only to show that seller their analytics. This page explains exactly what we access, why, and how we protect it.
In one line: Read-only access via official OAuth, used solely to give the authorising seller their own profit analytics — never sold, never shared, never used for any other seller, and deleted within 14 days of disconnecting.
1. Read-only access via official OAuth
A seller connects each shop through the marketplace's own official OAuth authorisation flow (Shopee Open Platform, Lazada Open Platform, TikTok Shop Open Platform). We request read-only scopes only. Hoseh Seller cannot create, edit, cancel, or delete anything in your store, change prices, message buyers, or take any action on your behalf.
The seller authorises the connection and can revoke it at any time — from the marketplace's Seller Centre / app-authorisation settings, or by asking us. Revoking immediately stops any further data sync.
2. Purpose limitation
We use connected-shop data for one purpose only: to compute and display analytics back to the seller who authorised the connection. Specifically, we do not:
- Sell, rent, share, or otherwise monetise seller or buyer data.
- Use one seller's data to serve, benchmark, or inform any other seller.
- Build cross-seller datasets, market databases, or category/industry benchmarks from marketplace data.
- Track, monitor, or compare competitor prices or competitor performance.
- Scrape or data-mine the marketplaces, or build any product that competes with them.
3. What data we access, and why
We request only the minimum read-only data needed to compute profit. Hoseh Seller does not need or use buyer personal information (such as names, addresses, or phone numbers) to provide its analytics, and does not display buyer PII.
| Data | Why we read it | Access |
|---|---|---|
| Orders | Compute revenue, profit, and order summaries | Read-only |
| Products / Items | Map SKUs and attribute costs and fees | Read-only |
| Finance / Payment | Use actual platform fee and payout breakdowns | Read-only |
| Logistics (where available) | Attribute shipping and fulfilment costs | Read-only |
Product costs (COGS) and similar inputs are provided by the seller themselves so we can calculate true profit. Account information (name, email) is collected when you register or contact us.
4. AI-assisted features
Two features use a third-party AI provider (Google, via the Gemini API) to turn figures we have already calculated into plain language: the insight summaries and the in-app assistant. The AI does not calculate your numbers and does not make decisions — the figures in the app are the source of truth, and AI-generated text is labelled as such in the app.
- What is sent: your own summary figures (revenue, profit, margin, fee and cost breakdowns, return and stock counts), and — for the assistant — the names of your own products where the question relates to them.
- What is never sent: buyer names, contact details or addresses, order IDs, SKU codes, or raw order records. An automated allowlist check runs before every request and blocks it entirely if personal data is detected.
- Free-text questions you type in the assistant are sent to the provider so they can be answered. The app displays a reminder above the box not to include personal or customer data; questions containing an email address are refused and never sent.
- Usage is rate-limited per seller, and the API key is held server-side only.
5. Security
- Encryption in transit: all traffic is encrypted with TLS 1.2 or higher.
- Encryption at rest: stored data is encrypted at rest by our hosting infrastructure.
- Secrets stay server-side: API keys, OAuth tokens, and client secrets are stored only on our servers and are never exposed to the browser or to other users.
- Per-seller isolation: each seller's data is access-isolated so it can only be used to serve that seller.
- Access controls & logging: internal access is restricted on a least-privilege basis, under individual named accounts, and access is logged.
- Written security program: we maintain a written information-security program with a designated Security Officer. Security issues can be reported to security@hoseh.app.
- Incident response: we maintain an incident-response process and will notify affected users, the relevant marketplaces, and — where the law requires it — the relevant data-protection authority (in Malaysia, the Personal Data Protection Commissioner) of any data breach within the time our obligations require.
6. Data retention & deletion
- Buyer personal data is not retained. Buyer details (names, addresses, phone numbers, messages) are removed before anything is written to our database — we don't need them to calculate your profit.
- Raw marketplace data is deleted after 90 days. The full payload we receive from a marketplace is purged automatically by a nightly job once it is 90 days old.
- What remains is your own calculated figures — revenue, costs, fees, and profit per order — kept for as long as your shop stays connected and your account is active, so we can show you both current and longer-term analytics. Subject to each marketplace's developer terms and applicable law.
- Tax-turnover records are monthly totals for your business with no buyer or order-level detail. We keep these until you delete your account, so your rolling 12-month threshold tracking stays accurate.
- When you disconnect a shop or request deletion, all synced marketplace data for that shop is deleted immediately, and in any event within 14 days. You can also delete your account at any time, which erases all of your data.
To request deletion or ask a data question, email hello@hoseh.app.
7. Sub-processors
We use a small number of trusted providers to host and operate Hoseh Seller on our behalf. Each is engaged under data-protection terms at least as protective as our own, processes your data only on our instructions and never for its own purposes, and we remain responsible for them.
| Type of provider | What it does for us |
|---|---|
| Database & hosting | Stores your account and analytics data; runs our server functions |
| AI text generation Google (Gemini API) | Turns figures we have already calculated into plain language — see section 4. We name this one specifically because it is the provider that receives your figures to generate text |
| Error monitoring | Helps us detect and fix faults |
| Transactional email | Sends account and team-invitation emails |
| Website hosting | Serves this public website |
The current list of named providers, and each one's processing location, is available to sellers on request: email hello@hoseh.app. We give notice of any intended addition or replacement of a sub-processor so you can object on reasonable data-protection grounds.
8. International transfers
Hoseh Seller currently serves sellers in Malaysia; we expect to support additional Southeast-Asian markets over time and will update this page accordingly. Where data is processed or stored outside your country (for example, by a cloud region operated by a sub-processor), we take steps to ensure it remains protected to a standard consistent with Malaysia's PDPA 2010, including contractual data-protection terms with our providers.
9. Data-flow summary
10. Questions or requests
For any data-protection question, access or deletion request, contact hello@hoseh.app. For a security disclosure, contact security@hoseh.app. See also our Privacy Policy and Terms of Service.