Bonsai - Marketplace Management | Software for Amazon, Temu, TikTok ShopBonsai - Gestione Marketplace | Software per Amazon, Temu, ManoMano, TikTok Shop
Skip to main content
Bonsai
  • Pricing
  • Modules
    Listing & Catalogue ManagementA single catalogue for every marketplace. Publish, update and optimise product listings in bulk, with automatic SKU/ASIN mapping.
    Inventory, Stock & PricingA single, real-time view of your warehouse with automated pricing rules for every sales channel.
    Administration & AccountingAutomated marketplace settlement reconciliation, per-channel P&L and EU multi-country VAT management.
    Product & Competitor TrackingMonitor competitor prices, Buy Box, stock and receive AI-powered SmartPrice suggestions.
    Smart LogisticsAutomatic courier selection, 1-click label generation and unified tracking across all marketplaces.
    Business Intelligence & AnalyticsA single dashboard for every marketplace, with real-time KPIs and AI-powered forecasting.
    Marketing & AdvertisingPREVIEWAmazon Ads, Amazon DSP and marketplace campaigns managed with AI. Cross-channel attribution, ROAS optimisation and automatic budget allocation.
    Campaign ManagerPREVIEWCreate, plan and monitor all ad campaigns from one dashboard. Budget, keywords, ad copy, targeting and consolidated reporting.
    See all modulesBSpanel modules overview and comparison
  • Onboarding
  • Amazon DSPNEW
  • Integrations
    MarketplaceAmazon, eBay, Temu, TikTok Shop, ManoMano
    E-commerceShopify, WooCommerce, PrestaShop, Magento
    CorrieriBRT, DHL, TNT, Poste Italiane, Mail Boxes Etc.
    Gestionali ERPSAP, Zucchetti, Sistemi, TeamSystem, Dynamics 365
    FatturazioneFatture in Cloud, TeamSystem, SDI XML, IVA OSS
    FornitoriCollega i tuoi fornitori tramite API o file Excel / CSV
    AI MCPClaude, ChatGPT, Copilot, Gemini — chiedi in chat i dati del tuo gestionale
    LogisticaAmazon FBA, Huboo, Hyve, 3PL, magazzino interno
    Scopri tutte le integrazioniMarketplace, corrieri, ERP, e-commerce e altro
  • Resources
    Discover
    BlogInsights and updates.
    Documentation & IntegrationsTechnical docs and API guides.
    Help CenterSupport and documentation.
    Partners
    Become a partnerJoin our partner network.
    Customers
    Case studiesRead our customers’ success stories.
    ClientiCase study e recensioni verificate
    News
    Latest newsStay up to date — subscribe to the newsletter.
Try Bonsai
  1. Home
  2. MCP Connector
  3. Privacy
ITEN

Privacy Policy — Bonsai MCP Connector

Scope: This policy covers the Bonsai MCP Connector when used with supported AI clients and services, including ChatGPT, Codex, Claude, OpenAI, and Anthropic. The MCP endpoint and processing are the same regardless of the selected AI provider; the provider processes information under its own terms.

Last updated: 16 September 2026
Controller: Bonsai Srls, Via Francesco Ferrucci 100, 59100 Prato (PO), Italy — VAT IT02533060972
Website: https://www.bonsaigrowth.it
Contact: info@bonsaigrowth.it

1. Data controller

The data controller is Bonsai Srls, Via Francesco Ferrucci 100, 59100 Prato (PO), Italy (VAT IT02533060972). For privacy requests (access, deletion, objection, or connector disconnection support), email info@bonsaigrowth.it.

2. Scope

This notice covers the Bonsai MCP Connector when used with compatible artificial intelligence services, including Anthropic's Claude and OpenAI's ChatGPT or Codex: a remote MCP server over HTTPS, authenticated with OAuth 2.0. It does not replace Bonsai's general product privacy notices. It applies when you connect the connector from the selected AI service, complete OAuth ("I am a company" or "I am an agency"), and invoke connector tools already available in the authorized Bonsai workspace. This is a B2B service, not directed at children under 18.

3. Data we collect

We process only what is needed to authenticate you, run tools, and keep the service secure and auditable. We do not collect complete chat transcripts, AI-service memory, conversation history, files you upload to the AI service, or any conversation data beyond what a tool needs to run.

3.1 Identity and authentication

  • MCP user identifier (OAuth "TOKEN A" subject);
  • Email / login on the Bonsai workspace or Hub-Agency — during broker login only; passwords are not stored on the MCP server;
  • Subject type (company / agency / platform staff);
  • Hub-Agency organization and allowed tenants (agency path);
  • Active tenant code / id;
  • OAuth access and refresh tokens — stored in a protected secret store, never written to audit logs.

The MCP server does not store workspace passwords. The MCP server does not connect directly to tenant databases: authorized business data is retrieved through authenticated Bonsai Core APIs.

3.2 Tool arguments and results

When the selected AI service calls a tool, we process: tool name, arguments (filters such as dates, marketplace, pagination, and platform tenant identifiers), outcome (success / error), non-secret error code and message, duration, correlation id, and results returned to the AI service (KPIs, time series, product/SKU tables and metadata already stored in your Bonsai tenant).

Results come from the Bonsai product. The connector does not call Amazon SP-API and is not a third-party Amazon API wrapper. The only write tool sets the active tenant on the agency path (switch_tenant). It does not write Vendor, Ads, or Seller data.

3.3 Technical data

Infrastructure and authentication may process IP address, user-agent, timestamps, URL, HTTP status, and request identifiers for security and diagnostics. Infrastructure technical logs are retained only for as long as necessary for security, abuse prevention, diagnostics, and compliance with applicable legal obligations, according to the retention settings of the relevant infrastructure providers. They are not used for commercial profiling.

3.4 What we do not process through the connector

  • passwords after login (not persisted on MCP);
  • access tokens, refresh tokens, Authorization headers, cookies, or secrets in audit logs;
  • complete chat transcripts, memory, or conversation summaries from the selected AI service, and files uploaded by the user to the AI service;
  • personal health data, money transfers, or sponsored/promotional content (this does not refer to your Amazon Ads KPIs, which are exposed through the dedicated analytics tools).

4. Purposes and legal bases (GDPR)

  • Performance of a contract (Art. 6(1)(b)): connecting the selected AI service to Bonsai, authenticating you (OAuth), and running the tools you request;
  • Legitimate interests (Art. 6(1)(f)): tool-invocation audit, security, abuse prevention, support;
  • Legal obligation (Art. 6(1)(c)).

The connector accesses workspace data only after you authorize OAuth in the AI service and complete Bonsai login. We do not carry out automated decision-making with legal or similarly significant effects (Art. 22 GDPR).

5. Use and storage

We use the data to authenticate the AI client to the MCP server and maintain the OAuth session, resolve tenant context and permissions, call Bonsai first-party APIs, return only the tool output to the AI service, and keep an audit trail (who called which tool, on which tenant, with which filters, with which result).

Where data lives: mcp-bonsai (central MCP server); customer Core (workspace — business data stays in the tenant); Hub-Agency (agency path only).

Bonsai does not sell this data and does not use connector data to train foundation models.

6. Third parties and sharing

  • Selected AI service (e.g. Anthropic / Claude or OpenAI / ChatGPT / Codex): the MCP client you chose. Processing is governed by the terms and privacy policy of the selected AI provider. Bonsai does not control the AI service.
  • Customer Bonsai Core: source of KPIs and tables.
  • Hub-Agency (only if you choose "I am an agency").
  • Hosting / infrastructure providers: as processors under contract.
  • Hub-Dev (Bonsai ops): not on the chat path; limited ops access under internal policy.

We do not share connector data with Amazon for MCP operation.

7. Retention

  • OAuth tokens and MCP session context → until disconnect, expiry, rotation, or revocation.
  • Tool-invocation audit logs (mcp_tool_audit_logs) → 90 days, then automatic deletion.
  • Hub-Agency proxy audit logs (proxy_audit_logs) → 90 days.
  • Infrastructure technical logs → retained only for as long as necessary for security, abuse prevention, diagnostics, and compliance with applicable legal obligations, according to the retention settings of the relevant infrastructure providers.
  • Business data in the customer Core → follows the workspace contract.

8. International transfers

The MCP server and Bonsai systems are operated by Bonsai and its infrastructure providers. When the connector is used, tool arguments and results are transmitted to the selected AI service. Depending on the service used, data may be processed by OpenAI or Anthropic, including outside the European Economic Area, under their respective privacy policies and applicable terms (OpenAI · Anthropic).

9. Security

  • HTTPS and OAuth 2.0 with PKCE;
  • separate tokens (AI client→MCP vs MCP→workspace);
  • secrets and tokens excluded from audit logs;
  • no direct SQL or tenant-database connection from MCP (authorized business data is retrieved through authenticated Bonsai Core APIs);
  • domain tenant not freely chosen by the AI service (allowlist / session context);
  • analytics tools read-only, except switching the active agency tenant;
  • invocation audit for operational traceability.

Personal-data breaches are handled under GDPR Arts. 33–34.

10. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, objection, data portability, and you may disconnect the connector at any time.

  1. Disconnect the connector from the settings of the selected AI service.
  2. Revoke Bonsai access (logout, OAuth token revocation, agency membership removal).
  3. Email info@bonsaigrowth.it for access to or deletion of audit logs still within the retention window.

You may lodge a complaint with the Italian Data Protection Authority (Garante), Piazza Venezia 11, 00187 Rome, Italy — or with your local EEA supervisory authority.

11. Children

The connector is a professional service for Bonsai account holders. It is not directed at anyone under 18.

12. Changes

We may update this notice. The date at the top is the current version. For material changes we will provide reasonable notice where required.

13. Directory acknowledgements (summary)

  • Collection: OAuth identity, tenant context, tool arguments, tool results needed to fulfil the call, technical and audit logs. No harvesting of complete AI-service chat transcripts, no AI-service memory queries, no workspace passwords on MCP.
  • Use and storage: run tools, enforce tenant allowlist and permissions, audit, security. Encrypted secret store for tokens. The MCP server does not connect directly to tenant databases; authorized business data is retrieved through authenticated Bonsai Core APIs.
  • Third parties: the selected AI service (OpenAI/ChatGPT/Codex or Anthropic/Claude), customer Core, Hub-Agency (agency path), hosting processors. Not Amazon SP-API from the MCP server.
  • Retention: 90 days for MCP and Hub-Agency audit logs; tokens until disconnect/revocation/expiry.
  • Contact: info@bonsaigrowth.it.

Bonsai Srls · Via Francesco Ferrucci 100, 59100 Prato (PO), Italia · P.IVA IT02533060972 · info@bonsaigrowth.it

Contact

  • Info@bonsaigrowth.it
  • Tel: +39 328 2753183
  • Legal Office:

    Via Francesco Ferrucci 100,
    Prato, PO, 59100, Italia
  • Operational Office:

    Via Giacinto Fabbroni 11,
    Prato, PO, 59100, Italia

Follow

BLOG Of Bonsai

Discover
  • Rotazione Deal Amazon 2026: Guida Completa Venditori
  • Catalogo Multi-Marketplace 2026: Guida Completa a PIM, Amazon SP-API e Content Ops
  • Repricing Amazon e Stock Multi-Magazzino: Guida Definitiva 2026 al Real-Time Sync

Pages

  • Home
  • Pricing
  • Modules
  • Onboarding
  • Integrations
  • Clienti
  • FAQ
  • Support
  • Blog
  • Contact
  • Terms and conditions
  • Privacy Policy
  • Claude MCP Connector
  • ChatGPT MCP Connector
  • MCP Support
  • MCP Terms
  • MCP Privacy Policy
Book a call

Compliance:

Bonsai operates in compliance with Amazon SP-API Policies. Data access and use are regulated and limited to authorized purposes.

Bonsai does not store, process or transmit Amazon data outside the official SP-API connections.

Recensioni verificate

Capterra ReviewsGetApp ReviewsSoftware Advice Reviews

Partner ufficiali Amazon

Amazon Ads Verified PartnerAmazon Selling Partner Appstore — Software PartnerAvailable at Amazon Appstore

Bonsai srls

Partita IVA: 02533060972 · Codice Fiscale: 02533060972 · Vat Europeo: IT02533060972

Indirizzo: Via Francesco Ferrucci 100 — 59100 Prato (PO)

© 2026 Bonsai. All rights reserved.

This site uses cookies

We use necessary technical cookies for site functionality and analytical cookies to improve your experience. You can accept all cookies or manage your preferences.