Privacy policy

Last updated 30 August 2026

This policy covers two things: the CosmOS product, which connects to your marketplace accounts, and this website.

We have tried to write it so you can check it rather than trust it. Where a claim can be verified inside the product, it is described in enough detail to be checked.

The short version

CosmOS reads your selling and settlement data from the marketplaces you connect, so it can keep your books. It does not read your buyers' personal details, and every permission it asks for is read-only.

Your data is stored separately from every other customer's. The keys that let us read your marketplace are encrypted before they are stored.

You can disconnect a marketplace at any time, and you can ask us to delete your data.

Who this is from

CosmOS is a product of ArivLabs. ArivLabs is the entity accountable for the data described here.

Requests about your data go through the contact form.

What the product reads from your marketplace

When you connect a marketplace, you approve a set of read permissions on that marketplace's own site. It shows you the exact list before you confirm. What we ask for is:

WhatWhy it is needed
SettlementsThe payouts you receive. This is the money side of your books
OrdersWhat sold, so revenue is recognised against the payout
Returns and refundsReversals against the original sale
Fees and adjustmentsCommission, shipping, storage and advertising costs
ProductsNames and SKUs, so a line reads as a product rather than a code
Stock movementsInventory value, where your plan includes it

What it does not read

We do not read your buyers' personal details. Names, delivery addresses and contact details are not needed to keep books, so we do not request the marketplace permissions that grant them.

We do not have permission to change anything on your marketplace account. Every permission is read-only: CosmOS cannot alter a listing, change a price, cancel an order or move your stock. The only thing it writes is your ledger, inside CosmOS.

Your marketplace credentials

You never give CosmOS your marketplace password. You sign in on the marketplace's own site, it asks you to approve CosmOS, and it then tells us directly that you did.

What we receive and store is a token that lets us read the data listed above. It is encrypted before it is stored, it is never written to a log, and it is never shown on screen.

Support will never ask you for your marketplace password or your API keys.

Marketplaces expire these approvals. Amazon expires one after 365 days and emails you before it lapses. When it does, syncing stops until you reconnect.

Where your data is stored, and who can see it

Your data is held in a database in the Asia Pacific (Mumbai) region and is separated per account at the database level, so one account's queries cannot reach another's.

Access to your books inside CosmOS is controlled by the roles you give people in your own account.

A small number of CosmOS staff can administer accounts: creating them, resetting a demonstration account, and managing which features are switched on. That administrative surface does not read your books.

This website

This site is separate from the product. You do not need an account to read it, and it holds none of your marketplace data.

If you fill in a form

The demo and contact forms collect what you type: your name, your work email, your company, and your message. That is sent to our forms provider and reaches us as a notification. We use it to reply to you.

Cookies and analytics

Analytics do not run until you accept them. When you first arrive, the choice defaults to off, and nothing analytical loads unless you choose otherwise. You can change it at any time through Cookie settings in the footer.

If you do accept analytics, we use Google Analytics and PostHog to understand which pages people read and where they get stuck. PostHog processes this in the United States. That involves a transfer of your usage data outside India.

PostHog can also record a session, which is a replay of how a page was used. Every form input is masked in those recordings: what a form looks like is captured, what you type into it is not.

Necessary cookies keep the site working and your cookie choice remembered. Those cannot be turned off, because without them we cannot remember that you declined.

How long we keep things

Your accounting records stay for as long as your account is open. They are accounting records, so disconnecting a marketplace does not delete them.

If you ask us to delete your data, we delete it.

Your choices

Disconnect a marketplace. From Channels, at any time. Syncing stops immediately and we stop reading.

Turn off analytics on this site. Cookie settings, in the footer.

Ask for your data, or its deletion. Through the contact form. Tell us which account you mean and what you want, and we will confirm when it is done.

Changes

If this policy changes in a way that affects what we read or who we share it with, we will say so rather than quietly reposting the page. The date at the top is when it last changed.

We use cookies to improve your experience, analyze site traffic, and personalize content. You can manage your preferences at any time.