Security
How data gets in, and what we never ask for
Last updated: 5 October 2026
This page is the detailed version of what the homepage already says under "How data arrives." It exists so anyone evaluating AMZN Agent — a buyer, their IT team, or a security reviewer — can see exactly what the browser extension does, what each workspace can see, and where the data is hosted, without digging through a sales page.
The browser extension, permission by permission
The extension runs in the background while you are signed into your own seller and business accounts. It does not have its own login and does not intercept or store the password you use for those sites.
| What it can do | Why, in plain terms |
|---|---|
| Read pages on your seller and business domains | It needs to see the order, inventory and shipment pages you already have open or scheduled to load, to copy the rows into your workspace. It does not read pages outside those domains. |
| Run on a schedule in a background tab | Customer orders, FBA inventory and shipments are collected automatically every few hours so nobody has to remember to open a tab (see the exact times below). |
| Send the rows it reads to your workspace | Each row is sent to the AMZN Agent account you signed the extension into, over an encrypted connection, and stored against that account only. |
| Show a badge when a run is paused | If a page asks for a manual security check, the extension stops and waits rather than guessing, and shows that in the toolbar icon. |
What it does not do: it never asks you to type or paste a marketplace password into AMZN Agent, never stores one if typed elsewhere in the browser, and never acts on your account beyond reading the pages above — it does not place orders, send messages or change settings on your seller account.
Collection schedule
The same four schedules shown on the homepage, stated here without rounding: customer orders every 6 hours; FBA inventory at 04:00 in each marketplace's own time zone; FBA shipments at 05:00 local; business purchase orders once a day. A run that is interrupted — by a browser restart or a security check — resumes from the last page it finished, instead of starting over or skipping ahead.
Workspace separation
Every row is tagged with the AMZN Agent account that collected it. There is no cross-account query path in the product — a workspace cannot read another workspace's rows, by design, not just by permission check.
The website, the app, the warehouse panel and the API all run as Cloudflare Workers with Cloudflare-managed storage. We do not run our own servers for this product.
A delivered order never slips back to pending and a cancelled shipment stays cancelled — status changes are validated going one direction, which keeps a bad read from quietly corrupting history.
A linked prep warehouse gets a separate sign-in at warehouse.amznagent.com that only sees the stores and countries you explicitly connect it to.
Reporting a concern
If you believe you have found a security issue, write to us at the address on the contact section of the homepage with what you found and how to reproduce it. We will acknowledge it and let you know once it is addressed.
Related pages
Privacy notice covers what the website itself collects. Website terms cover use of this site. Both are separate from the agreement that governs the application itself.