Skip to main content

Privacy policy

Last updated: July 16, 2026

This privacy policy describes how Alejandro Grau Perez, operating under the commercial brand B2M ("we"), collects, uses, stores, protects, shares and deletes data in connection with the B2M - MCP software service and this website. It is written to comply with the EU General Data Protection Regulation (GDPR) and with the Amazon Data Protection Policy that governs applications built on the Amazon Selling Partner API.

1. Data we collect

When a brand authorizes B2M - MCP from its Amazon Seller Central account, we receive access to the business data covered by that authorization through the Amazon Selling Partner API: catalog and listing content, order data at business level (identifiers, statuses, quantities and channels), inventory levels, pricing information, financial events and settlement data, account health information and shipment statuses.

We do not collect buyer personal data. B2M - MCP does not request, access or store personal information of Amazon buyers, such as names, delivery addresses, phone numbers or email addresses. The application operates exclusively on seller business data.

Separately, we collect the contact data our customers give us directly: name, company, email address and phone number, together with the correspondence we exchange. The contact form on this website collects the name, company, email address and message that you submit.

2. How we use the data

We use the authorized Amazon account data solely to provide the B2M - MCP service to the customer that owns that data: audits, reports, management tools and analytics about that customer’s own business. We use customer contact data to communicate about the service, answer requests and manage the commercial relationship.

We do not sell data. We do not share data with third parties for commercial or analytical purposes. We do not aggregate data across customers, and we do not use one customer’s data to build products or insights for anyone else.

3. Where and how the data is stored

Service data is stored in a controlled environment with encryption and access restricted to authorized personnel. Google Workspace (Google Drive for Business) acts solely as a storage infrastructure provider, under our own access controls and retention policies. Our hosting provider stores the data processed by this website’s infrastructure.

4. How we protect the data

Data is encrypted in transit. Access to data is restricted according to job function, protected by strong passwords and multi-factor authentication. Credentials and access tokens for the Amazon Selling Partner API are stored securely and rotated periodically. The security page of this website describes our controls in more detail.

5. Who we share data with

We do not share data with anyone for commercial or analytical purposes. Data is processed on our behalf solely by our infrastructure providers, engaged as processors under data processing agreements:

  • Google Workspace (Google LLC) — storage infrastructure
  • Hostinger — website and application hosting

6. How long we keep the data, and how we delete it

Amazon account data is kept while the customer’s authorization is active, because it is what the service operates on. When the authorization is revoked or the contract ends, we delete the customer’s Amazon account data within 30 days, except where a specific legal obligation requires keeping specific records for longer.

Customer contact data is kept for the duration of the commercial relationship and up to the legal limitation periods applicable to contractual obligations in Portugal. Deletion is performed by removing the data from active systems and from managed storage, following a documented procedure. You can request deletion earlier at any time (see section 7).

7. Your rights under the GDPR

If you are a natural person whose personal data we process (for example, as a contact person of a customer), you have the right to access your data, to have it rectified, to have it deleted, to receive it in a portable format, to restrict or object to its processing, and to withdraw consent where processing is based on consent.

To exercise any of these rights, write to hello@b2mktplace.com. We answer within one month. You also have the right to lodge a complaint with a supervisory authority; in Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD).

The data controller is Alejandro Grau Perez, Portugal. Contact: hello@b2mktplace.com, +351 928 123 239.

8. Revoking the Amazon authorization

You can revoke the authorization of B2M - MCP at any time from your Amazon Seller Central account, in the section where Amazon lists your authorized applications. Revocation is immediate: the application loses access to your account data from that moment.

After revocation, the data already processed for your workspace follows the deletion process described in section 6: it is deleted within 30 days, or earlier if you request it.

9. Changes to this policy

When we change this policy, we update its text on this page and revise the date shown at the top. If a change materially affects how we process customer data, we notify our customers directly by email before it takes effect.