Purpose
This policy defines how our organization collects, processes, stores, uses, shares, retains, and disposes of Amazon Selling Partner API (SP-API) information. Amazon information is handled solely for the purpose of providing authorized business services to our customers and in accordance with Amazon’s SP-API Data Protection Policy.
Data Collection
We collect only the minimum Amazon information required to perform the requested business functions. Data is obtained exclusively through authenticated Amazon SP-API requests after the selling partner has explicitly authorized our application. No Amazon information is collected from unauthorized sources.
Depending on the permissions granted by the seller, collected data may include order information, shipping addresses, buyer information, inventory, products, pricing, shipment details, and other SP-API resources necessary for order processing and fulfillment.
Data Processing
Amazon information is processed only to provide requested services, including:
- Importing and managing customer orders.
- Generating shipping labels.
- Communicating with shipping carriers to obtain tracking numbers.
- Updating shipment status, inventory levels, and order fulfillment.
- Synchronizing marketplace data with our centralized fulfillment system.
Processing is automated wherever possible and limited to authorized business operations.
Data Storage
Amazon information is stored only in secured production systems.
Security controls include:
- Encrypted connections (TLS 1.2 or higher) for data in transit.
- Encryption of sensitive data at rest using industry-standard encryption.
- Databases hosted in private network segments that are not publicly accessible.
- Role-based access control (RBAC) with least-privilege permissions.
- Multi-factor authentication (MFA) for administrative access.
- Logging and monitoring of administrative access and security events.
- Regular security updates and vulnerability remediation.
Amazon information is retained only as long as necessary to perform authorized business functions or to satisfy legal, accounting, or contractual obligations.
Use of Amazon Information
Amazon information is used exclusively to:
- Process and fulfill customer orders.
- Generate shipping labels.
- Obtain carrier tracking numbers.
- Update shipment and fulfillment status.
- Synchronize inventory and marketplace information.
- Meet legal and regulatory requirements.
Amazon information is never used for advertising, profiling, analytics unrelated to the authorized service, or any purpose prohibited by Amazon’s SP-API policies.
Data Sharing
Amazon information is not sold, rented, or disclosed to third parties except when required to perform the authorized service.
Where necessary, limited information (such as recipient name, address, and contact details) is shared only with shipping carriers and logistics providers for shipment creation and delivery.
Third-party service providers receive only the minimum information required to perform their function and are contractually required to protect the data using appropriate security controls.
Employee Access
Access to Amazon information is restricted on a need-to-know basis.
Each employee has:
- A unique user account.
- Individual authentication credentials.
- Role-based permissions.
- Least-privilege access.
- MFA for privileged accounts.
Access rights are reviewed periodically and immediately revoked when no longer required or upon termination of employment.
Data Retention
Amazon personal data, including customer names, addresses, and contact information, is retained only for the minimum period required to complete the requested business process. Personal data used for order fulfillment and shipping purposes is securely deleted within 30 days after the fulfillment process is completed.
Data Disposal
When Amazon information reaches the end of its retention period, it is securely disposed of by:
- Permanently deleting database records.
- Removing associated files from storage.
- Deleting backups in accordance with backup retention schedules.
- Ensuring disposed data cannot be recovered through any means.
Security Monitoring
Systems are continuously monitored for unauthorized access attempts, privilege changes, authentication failures, and other security events. Security logs are retained for audit purposes and reviewed regularly. Suspected security incidents are investigated promptly, and corrective actions are taken as necessary.
Incident Response
If unauthorized access, disclosure, or misuse of Amazon information is detected, access is immediately restricted, the incident is investigated, affected credentials are revoked or rotated as appropriate, and remediation measures are implemented. Where required by Amazon policies or applicable law, notifications are made within the required timeframes.
Policy Review
This policy is reviewed periodically and updated whenever significant changes occur to our infrastructure, security controls, or Amazon SP-API integration.





