Privacy Policy
Last updated: September 13, 2026
Wholesale AI is a Chrome extension for Amazon wholesale sellers. Its single purpose is to provide local Amazon wholesale research guidance, a local saved-brand workspace, and paid membership access for those features. Its public marketing pages may use the limited Reddit landing-page measurement described below; that measurement is separate from the extension's local research data.
Wholesale AI provides research guidance only. It does not guarantee brand approval or claim to know private wholesale policy, actual MOQ, distributor availability, profitability, or approval likelihood.
Data stored locally in Chrome
The extension stores onboarding answers; an unfinished onboarding or Business Profile edit draft containing normalized answers, create-or-edit mode, update time, and an optional locally saved website URL so the same local flow can resume after a refresh or reopen; a local Business Profile containing business readiness, experience, wholesale-account status, an approximate monthly Amazon revenue band, category focus, opening-order comfort, supplier-document readiness, business website or email-domain readiness, and an optional website URL; an optional resale-certificate document selected by the user, including its filename, type, size, upload time, and local file data; Important Notice consent, acceptance time, and accepted version; one-time Amazon handoff status and update time; display settings; the local ten-analysis allowance, including granted ASINs, short-lived in-progress reservations, and bounded recent finalization receipts; a local license device identifier; pending Stripe Checkout details; the versioned optional subscription-measurement decision and an immutable copy bound to a pending Checkout attempt; a signed membership token; a separately signed, non-entitling billing-ownership proof when one is issued; Saved Brands created by the user, including the result and plain-language main reason shown at save time; a short-lived saved-product restore record created when the user reopens a saved product; local counts of unique Amazon products reviewed; and a versioned, bounded local product-milestone ledger.
The local product-milestone ledger keeps one control-only experiment assignment plus first and last timestamps, bounded counts, and no more than 24 recent occurrence keys per milestone for onboarding completion, finalized signals, first saves, saved-brand rechecks, paywall exposure, and checkout requests. It does not store ASINs, Amazon URLs, brand names, Business Profile answers, Saved Research content, billing email, license or device identifiers, or Stripe Checkout Session IDs. The optional website is normalized and saved locally; Wholesale AI does not visit, crawl, authenticate, or verify it. The optional resale-certificate completed state is Saved locally — not verified. The document stays only in Chrome extension storage on that device and is not uploaded to Wholesale AI or any server, parsed, authenticated, validated, or used by the recommendation engine. The handoff stores no Amazon search query or search-result data. The restore record expires after five minutes and is removed after the matching ASIN consumes it. In-progress analysis reservations and bounded finalization receipts also expire. Local profile, certificate, handoff, free-analysis grant, saved-brand, restore, product-milestone, Amazon-page, and recommendation data are not sent to the billing service or transferred to another Chrome profile.
The free-analysis allowance is local rather than account-based. Clearing extension storage or uninstalling and reinstalling the extension may remove that record and reset the allowance.
Data read from Amazon
On supported Amazon.com product pages, the extension may read the visible ASIN, product title, brand, category, seller and offer details, fulfillment details, visible price spread, purchase activity, rating, review count, Best Sellers Rank, availability, and brand-store links. This information is evaluated locally in the browser and is not sent to the fulfillment service. Wholesale AI does not add recommendation markers to Amazon search, category, deal, or recommendation grids. An eligible user with no completed recommendation may see one dismissible instruction on a visible Amazon home or search page; its action focuses Amazon's search field, and it does not read, analyze, store, transmit, or mark search results.
Reddit landing-page measurement
The public Wholesale AI homepage and /desktop landing page may load Reddit Pixel a2_jobha39bdfvu when the page URL contains only permitted campaign values and the browser does not report Global Privacy Control or Do Not Track. The integration sends one PageVisit event and sends a custom ChromeWebStoreClick event only when the visitor activates the actual Wholesale AI Chrome Web Store link. That Store click is not labeled as an extension install, account creation, checkout, or purchase. The email and signed-handoff /install page and the Chrome extension do not load the Reddit Pixel.
The integration may make bounded utm_source, utm_medium, utm_campaign, utm_content, utm_term, and Reddit click-ID values in the landing-page URL available to Reddit. Invalid, duplicate, unsupported, or out-of-bounds campaign values disable Reddit measurement for that visit. Wholesale AI does not supply Reddit with an email address, phone number, payment detail, Amazon activity or page content, ASIN, recommendation result, Business Profile answer, Saved Brand, resale certificate, extension identifier, or license-device identifier through this landing-page integration. Automatic email and phone matching are disabled in the configured Reddit Pixel. The Store link remains usable when measurement is unavailable or blocked.
Billing and membership data
Stripe-hosted Checkout collects payment details directly. Wholesale AI does not receive or store card numbers. The extension sends the local license device identifier, Checkout Session ID, signed membership token, separately signed billing-ownership proof, or versioned optional subscription-measurement decision to the fulfillment service only for checkout, access refresh, plan verification, resubscription, billing-portal, or consented measurement requests. The billing-ownership proof cannot authorize Amazon analysis.
If the user explicitly chooses Verify plan ownership, the billing email is sent to the fulfillment service to locate one unambiguous Wholesale AI billing relationship and send a one-time verification code. Stripe Customer metadata may store the exact Wholesale AI source subscription and license identifiers, owner-device hash, ownership-revocation identifier, recovery challenge hash, recovery request and consumption identifiers and times, and resubscription Checkout linkage. Active subscription metadata continues to store the active license-device binding. Fully canceled subscriptions remain read-only. Verification codes expire after 30 minutes and may be retried only by the same winning device after consumption.
Optional subscription lifecycle measurement
Payment buttons open Stripe directly without an optional measurement screen. New Checkout attempts default to all optional measurement choices denied; an already-bound Checkout decision is preserved when resuming that attempt. Missing, invalid, or outdated measurement consent is treated as denied. Existing subscribers can withdraw optional measurement from the extension without affecting paid access.
The current consent version covers the server-verified offer ID, monthly or annual billing interval, commercial cohort, and successful-refund measurement. Legacy version 1 and version 2 choices remain readable only within their original scope and do not authorize those new fields or refund events.
The decision version, decision time, Google analytics choice, Google advertising-conversion-matching choice, independent OpenAI Ads paid-subscription-measurement choice, and always-denied Google advertising-personalization setting are sent to the fulfillment service and retained in Stripe Checkout Session and Subscription metadata. For a validated explicit decision, the Checkout Session also stores Stripe's server-side Session creation time as the receipt time. Legacy Google-only decisions never authorize OpenAI Ads measurement. Clearing or uninstalling the extension does not remove this Stripe consent record.
If subscription analytics is granted, the signed Stripe webhook service may send limited subscription_start, positive-value purchase, successful refund, subscription_payment_failed, subscription_cancel_scheduled, and subscription_ended events to the owned Google Analytics 4 property with Measurement ID G-R1H2BGF9Q0. Current-version events include the verified offer ID, monthly or annual billing interval, and commercial cohort, plus time, currency, the amount actually paid, due, or refunded when applicable, Stripe billing or cancellation reason, and server-derived pseudonymous identifiers. Refund creation and update notifications are deduplicated by Stripe refund ID and do not change entitlement. subscription_start is emitted only for the first successful positive-value invoice of a new subscription and is the only event that may be imported to Google Ads as a Primary conversion, counted Every with actual value and currency. purchase records initial and renewal invoice revenue in Google Analytics only and is not imported to Google Ads. refund records a successful revenue reversal in Google Analytics only and is not imported to Google Ads. Failure, cancellation, and end events are diagnostic and never positive advertising conversions.
Advertising conversion matching is a separate optional choice. If it is denied, ad_user_data=DENIED and no billing-email hash is sent. If it is granted, the service may normalize the Stripe billing email and generate a one-way SHA-256 hash in server memory only to help Google match the imported subscription_start conversion. Only that hash, never the raw billing email, may be sent to the owned Google Analytics property; neither raw nor hashed billing email is stored in the delivery outbox or withdrawal record. Every Google Analytics lifecycle-measurement payload sends ad_personalization=DENIED; that per-event setting is independent of, and is not overridden by, the linked account's global personalization setting.
OpenAI Ads paid-subscription measurement is a third, independent optional choice. If it is granted, the signed Stripe webhook service may send exactly one subscription_created event after Stripe confirms the first successful positive-value invoice for a new public subscription. The event may include its time, amount and currency, an internal plan ID derived from the verified Stripe offer and billing interval, an approved source URL only when the configured action source is web, and a pseudonymous event ID used to prevent duplicates. The event is sent with opt_out=true. No raw or hashed billing email is sent to OpenAI under this version. Renewals, refunds, failed payments, scheduled cancellations, ended subscriptions, legacy Google-only choices, and Chrome Web Store reviewer access do not create positive OpenAI Ads conversions.
To deliver consented lifecycle events reliably, Google Cloud Firestore temporarily stores separate Google and OpenAI Ads pseudonymous delivery outboxes and withdrawal-control records containing delivery and subscription identifiers, lifecycle type and time, consent flags, permitted invoice or refund values, verified offer dimensions when authorized, and retry state. The OpenAI Ads outbox contains only the exact conversion payload plus delivery-control fields; it does not store the API key, raw or hashed billing email, Chrome device or license identifiers, or a full Stripe object. Neither raw nor hashed billing email is stored in the outbox or control record. When Google advertising conversion matching is granted, the one-way email hash is created in memory only immediately before delivery, and that delivery is only to Google. Outbox and withdrawal-control records have a purgeAt time 45 days after persistence; Firestore TTL deletion is asynchronous and may occur later. Nonsecret Google authentication-smoke proofs have a purgeAt time 24 hours after verification.
Google Cloud Tasks carries only a minimal pseudonymous delivery envelope—the delivery ID, generation number, and schema version—to retry delivery to the exact service revision. It carries neither raw nor hashed billing email.
Optional measurement never includes card numbers, raw billing email, names, phone numbers, ChatGPT conversation text, Chrome device or license identifiers, Amazon activity or page content, ASINs, recommendation results, Business Profile answers, Saved Brands, research activity, resale certificates, or locally stored websites. Wholesale AI does not send these fields to Google Analytics, Google Ads, or OpenAI Ads. Because ads link directly to the Chrome Web Store, Store-to-Stripe conversion matching remains best-effort and is not a deterministic person-level or click-level connection.
Third parties
- Stripe provides hosted checkout, immediate new-public subscriptions, legacy and reviewer trial billing, invoices, payment handling, and the customer billing portal.
- Google Cloud Run and Firestore provide the minimal checkout, membership, recovery, billing-portal, optional lifecycle-measurement, durable delivery, and measurement-withdrawal service.
- Google Cloud Tasks schedules bounded retries using only the minimal pseudonymous delivery envelope described above.
- Resend sends recovery codes and, only for eligible legacy or reviewer trials, trial-ending reminders to the Stripe billing email.
- Google Search opens only when the user clicks Search wholesale options; Wholesale AI does not fetch or store search results.
- Google Forms hosts the optional anonymous feedback survey that Chrome may open after the extension has been uninstalled.
- Google Analytics 4 receives limited subscription-lifecycle and paid-invoice measurement only when subscription analytics is granted. Chrome Web Store-managed Analytics separately provides aggregate listing and install reporting controlled by Google.
- Google Ads may receive only an imported first-positive-invoice
subscription_startconversion and consented hashed billing-email matching when advertising conversion matching is separately granted.purchaseandrefundremain Google Analytics revenue events and are not imported; cancellation, end, and payment-failure events are not positive conversions, and every Google Analytics lifecycle-measurement payload sendsad_personalization=DENIEDregardless of the linked account's global personalization setting. - OpenAI Ads may receive one
subscription_createdevent for the first successful positive-value invoice of a new public subscription only when OpenAI Ads measurement is independently granted. The event uses a pseudonymous duplicate-prevention ID, contains no raw or hashed billing email under this version, and is not created for renewals, refunds, failures, scheduled cancellations, ended subscriptions, legacy Google-only consent, or reviewer access. - Reddit may receive the limited landing-page
PageVisitandChromeWebStoreClickmeasurement described above. This integration does not report an install, checkout, or purchase.
Optional uninstall feedback
After Wholesale AI has been uninstalled, Chrome may open the Wholesale AI feedback form. Completing it is optional. The form asks for the main reason for uninstalling, how far the user got, and an optional suggestion for what would make the product worth reinstalling.
The form is configured not to collect email addresses and does not require Google sign-in. Wholesale AI does not add an ASIN, Amazon page, device identifier, license identifier, billing email, Business Profile answer, or other extension data to the survey URL. Responses are used only to improve Wholesale AI. Users are asked not to include passwords, payment details, resale certificates, Amazon account information, or other sensitive information.
Uninstalling the extension does not cancel a paid subscription. A subscriber must manage or cancel billing through Stripe or contact info@thewholesalecove.com.
Data not collected
Wholesale AI does not collect browsing history outside supported Amazon.com pages; backend recommendation data; outreach history; CRM notes; Amazon purchase, sales, profit, or outreach outcomes; or remotely transmitted recommendation, Amazon-page, Business Profile, Saved Brands, certificate, research-activity, or extension-usage telemetry. Remote measurement is limited to the Reddit landing-page events described above, optional Stripe billing-lifecycle measurement after separate consent, and aggregate Chrome Web Store reporting controlled by Google. Wholesale AI does not sell data or transfer data to data brokers.
Chrome Web Store Limited Use
Wholesale AI's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Chrome API data is used only for the disclosed research and paid-access purpose; it is not used for advertising, sold, or transferred to data brokers. Optional Google conversion matching uses only a separately consented server-generated SHA-256 hash of the Stripe billing email, does not use information received from Chrome APIs, and sends ad_personalization=DENIED on every Google Analytics lifecycle-measurement payload regardless of the linked account's global personalization setting.
Retention, control, and security
Most local extension data remains until the user removes it, clears extension storage, or uninstalls the extension. An unfinished onboarding or Business Profile edit draft is removed after the matching Business Profile saves successfully; otherwise it remains locally so the user can resume. Saved-product restore records expire after five minutes, in-progress analysis reservations expire after a short window, and bounded finalization receipts expire. Local recommendation counts, reviewed-product state, free-analysis grants, versioned notice consent, the bounded product-milestone ledger, and the completed or dismissed first-use handoff state remain in extension storage until it is cleared, subject to Chrome's local storage limits. Users can replace or remove the optional resale-certificate document in the Business Profile editor, remove individual Saved Brands, and manage or cancel billing through Stripe. Billing records are retained by Stripe as needed for subscription, payment, fraud prevention, accounting, legal, and support purposes.
The optional measurement decision remains in local extension storage until replaced, cleared, or the extension is uninstalled; the Checkout-bound consent record described above remains in Stripe metadata under Stripe's applicable retention obligations. Reddit, Google, and OpenAI retain measurement data under their applicable account settings and legal requirements. Global Privacy Control or Do Not Track prevents the Reddit Pixel from loading on a future landing-page visit. Withdrawing subscription-measurement consent stops future Google and OpenAI optional subscription measurement after the billing service confirms the change; it does not change an unfinished Checkout choice, delete data already processed by Google or OpenAI, cancel the subscription, or affect product access. Use Wholesale AI's self-service optional-measurement control to withdraw from future subscription measurement, or contact info@thewholesalecove.com for support.
Optional uninstall survey responses remain in Google Forms only while they are needed for product-improvement analysis and are deleted when they are no longer needed. The form is configured not to collect an email address or require sign-in, and the survey URL contains no extension or account identifier.
The extension verifies signed membership tokens locally. Stripe secrets, webhook secrets, and private signing keys are never stored in the extension. Billing and membership requests use HTTPS.
Contact
For billing, privacy, or support questions, email info@thewholesalecove.com.
Read the Terms of Service or visit Wholesale AI Support.