Trust & Compliance

Security & Data Protection

How we handle seller data.

Account Access & Authentication

Leviathan Recon works from reports you export yourself. There is no API connection to your account and no credential of yours for Recon to hold. You upload the files, and Recon rebuilds your unit ledger from them. Recon reads the files you upload. It cannot place orders, change listings, move funds, or act in your account.

The done-for-you work runs on those same uploads: the audit, the manufacturing-cost documentation and the claim filing are all prepared from the files you export and upload. Anything beyond that is agreed with you in writing first.

Inside Recon, each user account your admin creates carries one of three roles, Admin, Vendor or Viewer, with role-specific permissions applied per user across eight permission modules, and every change is written to an audit log.

The platform contains no SP-API client, no MWS client, no OAuth flow, no credential field, and no token store.

Data Isolation & Multi-Tenancy

Each client gets a separate PostgreSQL database — not a shared table with a tenant column. Your data is isolated from every other client's at the database level. The workspace your team sees carries your company's own display name and logo, configurable by your own admin in settings.

Encryption

All data is encrypted in transit (via TLS 1.2 or higher). Sensitive data at rest is encrypted using industry-standard encryption protocols.

Data Retention & Deletion

After a trial ends, your data is retained for 30 days. You can request deletion at any time, and it is performed immediately. During an active engagement, your data is retained for the duration of our contract and for seven calendar years after termination, as required for tax and business record compliance.

Sub-Processors

We use trusted service providers to run this platform:

  • Cloud hosting: AWS
  • Email & communications: Resend, Twilio
  • Rate limiting & data stores: Upstash
  • Analytics: Google Analytics 4

Each processor handles only the data necessary for their specific service.

GDPR & Data Protection Regulations

For the purposes of the EU and UK General Data Protection Regulation (GDPR), Leviathan Sellers is the data controller for personal information collected through this website and during account setup. We are committed to processing personal data transparently and lawfully, in accordance with GDPR and India's Digital Personal Data Protection Act (DPDP).

You have the right to access, correct, or request deletion of your personal data at any time. See our Privacy Policy for detailed information about your rights and how to exercise them.

Questions About Security

If you have questions about how we handle data or our security practices, contact us at service@leviathansellers.com.