Some of our services help sellers analyse and optimise their Amazon business. Where you connect your Amazon account, we access data through the Amazon Selling Partner API ("SP-API") strictly in accordance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy ("DPP").
What we access and why
With your authorisation, we access your SP-API access credentials together with advertising, order and seller information, solely to provide analytics, reporting and advertising optimisation to you. We use Amazon-derived data only for these purposes.
Purpose restriction and no sale of data
We do not sell or rent Amazon-derived data, and we never use it for advertising or for any purpose not expressly permitted by Amazon. Any interaction with Amazon (for example, account verification) is handled in compliance with the DPP.
Retention and deletion
We delete personally identifiable information originating from SP-API (for example, customer address information) within 30 days after an order is fulfilled, unless a longer retention period is required by law. When you disconnect your Amazon account, the related credentials and data are revoked and deleted.
Encryption and access control
Amazon data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-128 or AES-256), with encryption keys held in a key management system. Access is restricted to authorised personnel who require it to perform their role.
Incident response
If a security incident involving Amazon data occurs, we notify Amazon within 24 hours and inform affected individuals where applicable. We designate an Incident Management Point of Contact (IMPOC), reachable at [email protected], who is available to coordinate the response to any data leakage or security breach.
Audit cooperation
We cooperate fully with Amazon in the event of any audit or assessment of our data protection practices relating to SP-API data.