CloudrayAI

Built on the Amazon Selling Partner API

Clear profit and inventory analytics for your Amazon business.

CloudrayAI is operated by Cloudray (HK) Limited. We build reporting and reconciliation software for Amazon sellers: once you authorize your selling account, we turn the order, fee, settlement and inventory data Amazon exposes into profit, settlement and stock-reconciliation reports. We serve sellers who use Fulfillment by Amazon and operate across more than one marketplace, and we do not access buyer personal information.

About us

Who we are

CloudrayAI is operated by Cloudray (HK) Limited (鐳雲(香港)有限公司), a company incorporated in Hong Kong in 2021 (Business Registration No. 72775485). Our registered office is in Kowloon Bay, Hong Kong, and our product and engineering team is based in Nanjing, Jiangsu, China. We work with Amazon sellers operating across the North America, Europe and Far East regions.

Day to day, we connect to each customer's authorized Amazon selling account through the Selling Partner API, retrieve the financial, order and inventory records our services depend on, reconcile them against the customer's own cost and inventory inputs, and deliver seller-specific reports. Access is by invitation.

We are paid quotation-based service fees. Before any paid service begins we agree a written Order stating scope, price, currency and term. No fee arises from visiting this website, receiving an invitation or authorizing your Amazon account. See Pricing and section 8 of our Terms of Service.

For Amazon sellers

What we do for sellers

Once you authorize your Amazon selling account, this is what our application does on your behalf.

1

Profit & fee analytics

We reconstruct your Amazon fees and settlements to the line item and report profit by SKU, order and marketplace.

2

FBA inventory reconciliation

We track FBA stock and inbound shipments and reconcile them against your own records to surface discrepancies.

3

Order & settlement reporting

We consolidate your orders and settlement deposits into reports you can export and audit.

Full detail, including the SP-API data each service uses, is on the Services page.

How it works

Connecting your Amazon account

We access your Amazon selling account only through Amazon's official authorization flow. You stay in control and can revoke access from Seller Central at any time.

  1. 1

    Start the authorization

    You begin the connection from your account on this site.

  2. 2

    Sign in to Seller Central

    Amazon asks you to review the access being requested and confirm consent.

  3. 3

    Amazon returns to us

    Amazon redirects back to our registered callback with a one-time authorization code.

  4. 4

    Access is established

    We exchange that code for a long-lived credential, stored encrypted, and used only for the services you signed up for.

We request seven Selling Partner API roles — Finance and Accounting, Amazon Fulfillment, Inventory and Order Tracking, Selling Partner Insights, and (for planned features) Product Listing, Pricing and Brand Analytics. We use the four current roles to produce financial and inventory analytics on your behalf; the planned roles are not used until the corresponding features are available. We do not request any Restricted Role and do not access buyer personally identifiable information. The Services page lists the data each role uses and why.

Security & compliance

How we protect seller data

Amazon's Data Protection Policy sets binding requirements for anyone handling Selling Partner data. The first group below are technical controls implemented on this site. The second group restates commitments made in sections 5 to 7 of our Privacy Policy.

These statements describe particular controls and commitments. They are not a certification, and they do not represent that every business record is encrypted at rest.

Implemented on this site

Encryption in transit

The entire site, including both OAuth endpoints, is served over HTTPS.

Credentials at rest

Amazon refresh tokens are encrypted with Fernet authenticated encryption before they are written to our database.

Secrets and keys

Application secrets are read from server environment variables rather than embedded in the source repository, and the production service refuses to start if a required key is absent.

Sign-in without passwords

Accounts are invitation-only and use one-time login links. We store a SHA-256 digest of each login token, never the token itself.

Authorization-flow integrity

Every Amazon authorization uses a one-time, server-stored state value, and mismatches are rejected. Database queries are parameterized.

Logging

Application logs exclude access tokens, refresh tokens, authorization codes and application secrets.

Availability monitoring

Availability monitoring can attempt recovery and issue alerts.

Log retention

Application and request logs are written to durable storage and kept for 90 days, within the limit stated in section 6 of the Privacy Policy. Credentials are removed before a log line is written.

Backups

The authorization database is backed up daily. Each backup is verified by opening it and reading its contents, and backups are kept for 30 days, matching the deletion deadline in section 6 of the Privacy Policy.

Sign-in attempt limits

Sign-in link checks are limited by source address: ten consecutive failures block further attempts from that address for fifteen minutes.

Commitments in our Privacy Policy

Incident notification

If we detect an actual or suspected security incident involving Amazon Information, we will notify Amazon within 24 hours of detection and, where we process affected personal data for a customer, notify that customer without undue delay (Privacy Policy, section 5).

Retention and deletion

We retain Selling Partner Data only while strictly necessary and will permanently delete it within 30 days of the earliest deletion trigger set out in section 6 of the Privacy Policy, keeping only what a legal requirement obliges us to keep.

Personnel and providers

Access by personnel must be limited to the work necessary to serve the relevant customer, under confidentiality obligations and approved access arrangements. Service providers are identified in a Service Provider and Processing Location Schedule that we provide before enabling a customer's connection (Privacy Policy, sections 5 and 7).

Get in touch

Questions about our services, our use of Amazon Selling Partner data, or working with us? We're happy to talk.

Contact us