Privacy policy
Data Security and Privacy Policy
Publication Date: February 6, 2025
Effective Date: February 10, 2025
Scope: This policy applies to the system [Application Name] ,including its related services. It covers Amazon Selling Partner API (SP-API) data access and management.
1. How We Collect and Use Data
We strictly comply with Amazon’s Data Protection Policy (DPP) and Acceptable Use Policy (AUP) to ensure all data processing activities adhere to Amazon's security and privacy standards.
We access the following data through Amazon Selling Partner API (SP-API):
-
Order Data: Includes order numbers, order status, order amounts, etc., used solely for order management functions.
-
Inventory Data: Includes product inventory information, SKU, ASIN, used for inventory synchronization and management.
-
Financial Data: Used for sales reports and profit analysis (if applicable).
-
Advertising Data: Used to optimize ad placements (if applicable).
1.1 Purpose of Data Usage
We use Amazon API data strictly for the following legitimate purposes:
-
Order Management: Synchronizing order information to help sellers track order status.
-
Inventory Synchronization: Automatically updating inventory levels to prevent overselling or stockouts.
-
Sales Analysis: Providing data insights to help sellers optimize their operational strategies.
-
Ad Optimization: Using authorized advertising data to enhance ad placement strategies.
We do not store, share, sell, or misuse any Amazon API data. All data is used strictly within the authorized scope of the seller's account.
2. Data Storage and Security
We implement industry-standard security measures to protect Amazon API data from unauthorized access, tampering, or disclosure.
2.1 Data Encryption
-
Transmission Encryption (TLS 1.2 or higher): All API requests and data transmissions are encrypted using HTTPS to prevent interception or tampering.
-
Storage Encryption (AES-256): All stored data (such as order records) is protected using AES-256 encryption to ensure security.
2.2 Access Control
-
Principle of Least Privilege (PoLP): Only authorized internal employees and systems can access API data, with strict restrictions in place.
-
Multi-Factor Authentication (MFA): Our internal management system enforces multi-factor authentication to enhance account security.
-
Regular Security Audits: We conduct periodic internal and external security audits to ensure API access compliance with Amazon’s requirements.
2.3 Data Retention and Deletion
-
Data Minimization Principle: We store only the necessary API data and regularly delete outdated historical data.
-
Automated Deletion Policy:
-
Order and financial data will be automatically deleted within 7 days.
-
Inventory data will be updated and removed after 1 day.
-
-
Data Deletion upon Account Termination: If a seller terminates cooperation with us, we will permanently delete all related data within 15 days.
3. Data Sharing and Third-Party Access
-
No Unauthorized Data Sharing: We do not share, sell, or exchange Amazon API data with any unauthorized third parties.
-
Third-Party Service Providers: If cloud storage, hosting servers, or other third-party services (e.g., AWS, Azure) are used, we ensure that all vendors comply with industry standards such as GDPR, CCPA, ISO 27001, and sign Data Protection Agreements (DPA) with them.
4. User Data Rights
Under the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), seller users have the following rights regarding their data:
-
Right to Access: Users can request to view API data stored by us.
-
Right to Deletion: Users can request the deletion of all data associated with their accounts.
-
Right to Restrict Processing: Users can restrict how we process their data.
To exercise any of these rights, please contact us via email.
5. Security Incident Response
We have established a data breach response mechanism to handle security incidents:
-
Assess the impact within 24 hours of detection.
-
Notify affected users within 72 hours (if applicable).
-
Report the incident to Amazon and take appropriate measures as per Amazon’s requirements.
6. Compliance and Policy Updates
We regularly review and update this Data Security and Privacy Policy to ensure compliance with Amazon SP-API’s latest requirements. If significant changes occur, we will notify users via email or announcements.
Last Updated: February 10, 2025
7. Contact Us
If you have any questions about this policy or wish to request data access/deletion, please contact us:
Company Name: Ningbo Ruisi Jichuang Technology Co., Ltd.
Phone Number: +86 18086623415
Email: reylida@163.com