Data controls
Disconnect and delete data
An authorized seller organization may revoke Amazon access and request deletion of its service data at any time.
Effective August 26, 2026
Disconnect Amazon access
- Use the internal account-connections screen to disconnect the applicable advertiser or seller account, or email the request to amazon-api@munchellollc.com.
- Identify the legal organization and the Amazon account or profile to disconnect. Do not send passwords, OAuth tokens, or client secrets.
- We verify that the requester is authorized, revoke the stored grant, and stop future synchronization.
Request deletion
Send an email with the subject “Data deletion request” and identify the organization and connected account. We may request additional non-secret information to verify authority. We will confirm the scope and completion status to the verified requester.
Deletion timetable
- Authorization and synchronization stop after verified disconnection.
- Encrypted refresh tokens are removed from active systems within 7 days.
- Raw reports and other active tenant data are removed within 30 days unless the organization requests a narrower scope.
- Encrypted backup copies expire within 35 additional days.
- Limited audit or security records may be retained for up to 24 months when needed to prevent fraud, investigate incidents, establish authorization, or meet legal obligations.
Revoke directly through Amazon
An organization may also revoke an application's authorization through its Amazon account. Revoking at Amazon prevents future token use, but the organization should still submit a deletion request if it wants historical service data removed before the normal retention period.