Amazon SP-API Data Handling Policy
Amazon Selling Partner API – Data Handling & Privacy Policy
Effective date: August 11, 2026
Organization: 9365893 CANADA INC, operating as Artorang (“we,” “us,” or “our”)
Website: https://artorang.com
Contact: artorang.com@gmail.com
This page describes how 9365893 CANADA INC (Artorang) collects, processes, stores, uses, shares, and disposes of Amazon information obtained through the Amazon Selling Partner API (SP-API) in connection with operating our own Amazon selling account(s). This policy is provided for Amazon Solution Provider / SP-API compliance and transparency. It applies to Amazon order and related data accessed via SP-API; it is separate from any general website privacy notice that may apply to visitors of our Shopify storefront.
1. Scope
This policy covers Amazon Information, including Personally Identifiable Information (PII) such as buyer shipping name, shipping address, and phone number, retrieved through SP-API for seller-fulfilled order processing. Our SP-API application is an internal operations tool used only by Artorang to manage our own Amazon store(s). It is not offered as a public multi-seller SaaS product to other Amazon sellers.
2. Roles and purpose
We use SP-API solely to support our own Amazon business operations, including product/listing workflows and order fulfillment. Restricted shipping PII is requested only where required to fulfill seller-fulfilled (merchant-fulfilled) orders—specifically to obtain shipping details needed to process orders and provide them to our shipping partner so orders can be delivered to customers.
We do not use Amazon customer PII for marketing to Amazon buyers, advertising, resale of data, or unrelated analytics.
3. What Amazon data we collect
Depending on the API operation and approved roles, we may process:
- Order identifiers and non-PII order metadata (for example Amazon order ID, SKUs, quantities, prices, order status, timestamps)
- Shipping PII (buyer shipping name, street address, city, state/region, postal code, country, and phone), retrieved only when needed to fulfill an order
- Authentication credentials for SP-API access (for example client credentials and refresh tokens), which are organizational secrets and not customer PII
We request Restricted Data Token access only for the shipping-address data elements required for fulfillment. We do not collect Amazon buyer payment card data through SP-API.
4. How data is collected
Amazon Information is collected exclusively through Amazon’s official SP-API endpoints (including the Orders API and Tokens API where Restricted Data Tokens are required). Data is retrieved over encrypted HTTPS (TLS 1.2 or higher) using approved application credentials associated with our Amazon selling / developer account.
5. How data is processed and used
Amazon Information is processed to:
- Identify open / unshipped seller-fulfilled orders
- Prefill shipping details for fulfillment
- Provide shipping details to our shipping partner so the order can be delivered
- Support shipping and order-status operations for our own Amazon orders
Access to systems that can retrieve or display Amazon PII is limited to authorized administrative users within Artorang on a need-to-know basis for fulfillment and support of those orders.
6. Storage
Shipping PII: Buyer shipping name, address, and phone are retrieved for fulfillment processing and are not retained in our primary business database as long-term customer records. Where temporary processing copies exist (for example in an authenticated admin session or application memory during order creation), they are used only to complete the fulfillment workflow.
Non-PII order records: We may store Amazon order identifiers and related sales/operations metadata (for example order ID, SKU, quantity, price, status) in our internal systems for business operations, reporting, and reconciliation.
Credentials: SP-API credentials are stored in secured server-side configuration / secret storage with access restricted to authorized administrators. Credentials are not placed in public source repositories.
Amazon Information at rest is protected using industry-standard encryption controls (minimum AES-128; AES-256 preferred) for secrets and any stored sensitive materials, with key access restricted and keys rotated at least annually or upon suspected compromise.
7. Sharing
We do not sell Amazon customer PII. We share Amazon shipping information only as needed to fulfill and deliver orders:
- Shipping partner: Shipping name, address, phone, and related shipment details required to ship the order to the customer
- Amazon: As required for SP-API operation, account compliance, and incident notification obligations
- Service providers / hosting: Infrastructure providers that host our application or backups, under contractual/security controls, without authorizing them to use Amazon PII for their own purposes
- Legal / regulatory: When required by applicable law, regulation, legal process, or to protect rights and safety
We do not share Amazon PII with unrelated third parties for advertising or list brokerage.
8. Retention and disposal
- PII: Retained no longer than 30 days after order delivery, unless a longer period is required by applicable law, tax, or regulatory obligations
- Non-PII Amazon data: Retained up to a maximum of 18 months, unless a longer period is required by applicable law
- Security logs: Retained for at least 12 months
When retention ends, Amazon Information is securely deleted or sanitized using industry-standard deletion practices. Upon Amazon’s deletion notice or request, we permanently delete applicable Information within 30 days unless retention is legally required.
9. Security controls (summary)
We maintain administrative, technical, and organizational safeguards aligned with Amazon’s Data Protection Policy expectations for SP-API integrations, including:
- Network restrictions so databases and administrative endpoints are not publicly exposed beyond required HTTPS application access
- Encryption in transit (TLS 1.2+) and encryption at rest for credentials and sensitive stored materials
- Access limited to authorized users; unique accounts; strong password requirements; multi-factor authentication where supported for administrative and Amazon-related accounts
- Prohibition on storing Amazon PII on personal devices, USB media, or unsecured personal cloud shares
- Logging and monitoring of authentication and administrative activity, with investigation of suspicious events
- Vulnerability management with timely remediation of critical and high findings
- Documented incident response, including notification to Amazon at security@amazon.com within 24 hours of a confirmed security incident involving Amazon Information
10. Personal devices and removable media
Approved users are prohibited from copying Amazon PII to personal phones, personal computers, USB flash drives, or unsecured consumer cloud storage. Amazon Information may be accessed only through approved systems. Suspected policy violations or unauthorized access trigger credential revocation/rotation and incident investigation.
11. International transfers
Our shipping partner and hosting providers may process data in the United States or other jurisdictions where they operate. Where such processing occurs, we take steps appropriate to the service relationship to protect Amazon Information in line with this policy and Amazon’s requirements.
12. Subprocessors / subcontractors
Our shipping partner receives Amazon order shipping data only as needed to deliver seller-fulfilled orders. Hosting and infrastructure providers that support our internal application may process encrypted backups or system data. We review such providers for security suitability before granting access to systems that can handle Amazon Information.
13. Children’s data
Our SP-API workflows are not directed at children and are not intended to collect children’s data. Amazon order PII is processed only as provided by Amazon for order fulfillment.
14. Changes to this policy
We may update this policy to reflect operational, legal, or Amazon policy changes. The effective date at the top of this page will be revised when material changes are made. Continued use of our SP-API integration after an update constitutes operation under the revised policy.
15. Contact / Incident Management Point of Contact (IMPOC)
For questions about this Amazon data handling policy, or to report a security concern related to our SP-API integration:
- Name: Amin Shokouhi
- Role: Owner / Developer / Incident Management Point of Contact
- Email: artorang.com@gmail.com
- Business: 9365893 CANADA INC (Artorang)
This page is intended to satisfy Amazon SP-API Data Governance documentation requirements regarding how 9365893 CANADA INC (Artorang) handles Amazon Information. It does not replace Amazon’s own privacy notices to Amazon customers, and it does not change Amazon’s role as the platform where those customers placed their orders.