Data Deletion Policy
Last updated: August 2026
At MaruTally, we respect your data ownership rights. This Data Deletion Policy explains what data we actually hold, how account/data removal requests are handled today, and what to expect from that process.
1. We Do Not Store Your Amazon Order or Financial Data
MaruTally's Amazon integration operates as a relay: order, settlement, and financial event data retrieved via the Amazon Selling Partner API is passed directly through to your own TallyPrime installation and is not stored on our servers at all. There is no order/settlement database on our side to purge — it was never retained in the first place. Only account/authorization metadata (described below) is stored.
2. What We Do Store, and How Long
- Account information (email, encrypted password) and encrypted Amazon authorization credentials are retained for as long as your account remains active, so the service can continue to operate.
- API keys are stored as a one-way hash — never in a form we could read back.
- Security/audit records (e.g. login activity, administrative actions) are retained on a defined schedule appropriate to their security and legal purpose.
3. How to Request Account & Data Deletion
To request deletion of your account and associated data, email privacy@marutally.com from the address associated with your MaruTally account, with the subject line "Data Deletion Request", including your registered business name.
This is currently a manually reviewed, verified process — not an instant, fully automated self-service action. We will confirm your identity, review the request, and act on it as our operational capabilities allow. We will keep you informed of progress and tell you clearly what has and hasn't been affected once the request is completed.
4. What a Deletion Request Actually Does Today
- Account disable (blocking login/API access) and local deauthorization (MaruTally stops using a connected Amazon authorization for relay) are real, available actions we can take on request.
- Local deauthorization does not revoke access on Amazon's own systems — Amazon currently provides no way for us to do that programmatically on your behalf. If you also want to revoke access on Amazon's side, please do so directly in Amazon Seller/Vendor Central under Third-Party Developer and Apps (see Section 5).
- Full account/personal-data deletion is handled through our controlled internal review process described in Section 3. We do not currently offer instant, automated, self-service permanent deletion of an account.
5. Amazon Seller/Vendor Central Revocation
In addition to requesting deletion from MaruTally, we recommend you also navigate to your Amazon Seller/Vendor Central account and revoke MaruTally's access under the Third-Party Developer and Apps section. This ensures Amazon stops issuing active tokens for your account independent of anything we do on our side.
6. Records We May Need to Retain
Even after acting on a deletion request, certain records may need to be retained for legitimate security, legal, or compliance purposes — for example, billing/invoice records required by tax authorities, or security audit logs required for fraud/abuse investigation. We will tell you specifically what is and isn't retained as part of completing your request.
We also maintain backups of our systems for disaster recovery. Because backups exist to allow recovery of the whole system, individual account data cannot be selectively and instantly purged from every historical backup snapshot — backups age out and are replaced on their own retention schedule.
7. Contact Us
If you have any questions about data deletion, please contact us at privacy@marutally.com.
