Trust & Security

Data Protection & Security

Last updated: 25 July 2026

Hoseh Seller is a seller-side profit-analytics tool. We connect to a seller's own marketplace shops with their permission, read a limited set of their own data, and use it only to show that seller their analytics. This page explains exactly what we access, why, and how we protect it.

In one line: Read-only access via official OAuth, used solely to give the authorising seller their own profit analytics — never sold, never shared, never used for any other seller, and deleted within 14 days of disconnecting.

1. Read-only access via official OAuth

A seller connects each shop through the marketplace's own official OAuth authorisation flow (Shopee Open Platform, Lazada Open Platform, TikTok Shop Open Platform). We request read-only scopes only. Hoseh Seller cannot create, edit, cancel, or delete anything in your store, change prices, message buyers, or take any action on your behalf.

The seller authorises the connection and can revoke it at any time — from the marketplace's Seller Centre / app-authorisation settings, or by asking us. Revoking immediately stops any further data sync.

2. Purpose limitation

We use connected-shop data for one purpose only: to compute and display analytics back to the seller who authorised the connection. Specifically, we do not:

3. What data we access, and why

We request only the minimum read-only data needed to compute profit. Hoseh Seller does not need or use buyer personal information (such as names, addresses, or phone numbers) to provide its analytics, and does not display buyer PII.

DataWhy we read itAccess
OrdersCompute revenue, profit, and order summariesRead-only
Products / ItemsMap SKUs and attribute costs and feesRead-only
Finance / PaymentUse actual platform fee and payout breakdownsRead-only
Logistics (where available)Attribute shipping and fulfilment costsRead-only

Product costs (COGS) and similar inputs are provided by the seller themselves so we can calculate true profit. Account information (name, email) is collected when you register or contact us.

4. AI-assisted features

Two features use a third-party AI provider (Google, via the Gemini API) to turn figures we have already calculated into plain language: the insight summaries and the in-app assistant. The AI does not calculate your numbers and does not make decisions — the figures in the app are the source of truth, and AI-generated text is labelled as such in the app.

5. Security

6. Data retention & deletion

To request deletion or ask a data question, email hello@hoseh.app.

7. Sub-processors

We use a small number of trusted providers to host and operate Hoseh Seller on our behalf. Each is engaged under data-protection terms at least as protective as our own, processes your data only on our instructions and never for its own purposes, and we remain responsible for them.

Type of providerWhat it does for us
Database & hostingStores your account and analytics data; runs our server functions
AI text generation
Google (Gemini API)
Turns figures we have already calculated into plain language — see section 4. We name this one specifically because it is the provider that receives your figures to generate text
Error monitoringHelps us detect and fix faults
Transactional emailSends account and team-invitation emails
Website hostingServes this public website

The current list of named providers, and each one's processing location, is available to sellers on request: email hello@hoseh.app. We give notice of any intended addition or replacement of a sub-processor so you can object on reasonable data-protection grounds.

8. International transfers

Hoseh Seller currently serves sellers in Malaysia; we expect to support additional Southeast-Asian markets over time and will update this page accordingly. Where data is processed or stored outside your country (for example, by a cloud region operated by a sub-processor), we take steps to ensure it remains protected to a standard consistent with Malaysia's PDPA 2010, including contractual data-protection terms with our providers.

9. Data-flow summary

1. Seller authorises (official OAuth, read-only)  →  2. Hoseh Seller syncs the seller's own order / product / fee data  →  3. Stored securely, isolated per seller, encrypted  →  4. Seller views their own analytics in-app  →  5. Deleted within 14 days of disconnect or request.

10. Questions or requests

For any data-protection question, access or deletion request, contact hello@hoseh.app. For a security disclosure, contact security@hoseh.app. See also our Privacy Policy and Terms of Service.