Skip to content

Amazon SP-API Data Handling Policy

Amazon Selling Partner API – Data Handling & Privacy Policy

Effective date: August 11, 2026
Organization: 9365893 CANADA INC, operating as Artorang (“we,” “us,” or “our”)
Website: https://artorang.com
Contact: artorang.com@gmail.com

This page describes how 9365893 CANADA INC (Artorang) collects, processes, stores, uses, shares, and disposes of Amazon information obtained through the Amazon Selling Partner API (SP-API) in connection with operating our own Amazon selling account(s). This policy is provided for Amazon Solution Provider / SP-API compliance and transparency. It applies to Amazon order and related data accessed via SP-API; it is separate from any general website privacy notice that may apply to visitors of our Shopify storefront.

1. Scope

This policy covers Amazon Information, including Personally Identifiable Information (PII) such as buyer shipping name, shipping address, and phone number, retrieved through SP-API for seller-fulfilled order processing. Our SP-API application is an internal operations tool used only by Artorang to manage our own Amazon store(s). It is not offered as a public multi-seller SaaS product to other Amazon sellers.

2. Roles and purpose

We use SP-API solely to support our own Amazon business operations, including product/listing workflows and order fulfillment. Restricted shipping PII is requested only where required to fulfill seller-fulfilled (merchant-fulfilled) orders—specifically to obtain shipping details needed to process orders and provide them to our shipping partner so orders can be delivered to customers.

We do not use Amazon customer PII for marketing to Amazon buyers, advertising, resale of data, or unrelated analytics.

3. What Amazon data we collect

Depending on the API operation and approved roles, we may process:

  • Order identifiers and non-PII order metadata (for example Amazon order ID, SKUs, quantities, prices, order status, timestamps)
  • Shipping PII (buyer shipping name, street address, city, state/region, postal code, country, and phone), retrieved only when needed to fulfill an order
  • Authentication credentials for SP-API access (for example client credentials and refresh tokens), which are organizational secrets and not customer PII

We request Restricted Data Token access only for the shipping-address data elements required for fulfillment. We do not collect Amazon buyer payment card data through SP-API.

4. How data is collected

Amazon Information is collected exclusively through Amazon’s official SP-API endpoints (including the Orders API and Tokens API where Restricted Data Tokens are required). Data is retrieved over encrypted HTTPS (TLS 1.2 or higher) using approved application credentials associated with our Amazon selling / developer account.

5. How data is processed and used

Amazon Information is processed to:

  • Identify open / unshipped seller-fulfilled orders
  • Prefill shipping details for fulfillment
  • Provide shipping details to our shipping partner so the order can be delivered
  • Support shipping and order-status operations for our own Amazon orders

Access to systems that can retrieve or display Amazon PII is limited to authorized administrative users within Artorang on a need-to-know basis for fulfillment and support of those orders.

6. Storage

Shipping PII: Buyer shipping name, address, and phone are retrieved for fulfillment processing and are not retained in our primary business database as long-term customer records. Where temporary processing copies exist (for example in an authenticated admin session or application memory during order creation), they are used only to complete the fulfillment workflow.

Non-PII order records: We may store Amazon order identifiers and related sales/operations metadata (for example order ID, SKU, quantity, price, status) in our internal systems for business operations, reporting, and reconciliation.

Credentials: SP-API credentials are stored in secured server-side configuration / secret storage with access restricted to authorized administrators. Credentials are not placed in public source repositories.

Amazon Information at rest is protected using industry-standard encryption controls (minimum AES-128; AES-256 preferred) for secrets and any stored sensitive materials, with key access restricted and keys rotated at least annually or upon suspected compromise.

7. Sharing

We do not sell Amazon customer PII. We share Amazon shipping information only as needed to fulfill and deliver orders:

  • Shipping partner: Shipping name, address, phone, and related shipment details required to ship the order to the customer
  • Amazon: As required for SP-API operation, account compliance, and incident notification obligations
  • Service providers / hosting: Infrastructure providers that host our application or backups, under contractual/security controls, without authorizing them to use Amazon PII for their own purposes
  • Legal / regulatory: When required by applicable law, regulation, legal process, or to protect rights and safety

We do not share Amazon PII with unrelated third parties for advertising or list brokerage.

8. Retention and disposal

  • PII: Retained no longer than 30 days after order delivery, unless a longer period is required by applicable law, tax, or regulatory obligations
  • Non-PII Amazon data: Retained up to a maximum of 18 months, unless a longer period is required by applicable law
  • Security logs: Retained for at least 12 months

When retention ends, Amazon Information is securely deleted or sanitized using industry-standard deletion practices. Upon Amazon’s deletion notice or request, we permanently delete applicable Information within 30 days unless retention is legally required.

9. Security controls (summary)

We maintain administrative, technical, and organizational safeguards aligned with Amazon’s Data Protection Policy expectations for SP-API integrations, including:

  • Network restrictions so databases and administrative endpoints are not publicly exposed beyond required HTTPS application access
  • Encryption in transit (TLS 1.2+) and encryption at rest for credentials and sensitive stored materials
  • Access limited to authorized users; unique accounts; strong password requirements; multi-factor authentication where supported for administrative and Amazon-related accounts
  • Prohibition on storing Amazon PII on personal devices, USB media, or unsecured personal cloud shares
  • Logging and monitoring of authentication and administrative activity, with investigation of suspicious events
  • Vulnerability management with timely remediation of critical and high findings
  • Documented incident response, including notification to Amazon at security@amazon.com within 24 hours of a confirmed security incident involving Amazon Information

10. Personal devices and removable media

Approved users are prohibited from copying Amazon PII to personal phones, personal computers, USB flash drives, or unsecured consumer cloud storage. Amazon Information may be accessed only through approved systems. Suspected policy violations or unauthorized access trigger credential revocation/rotation and incident investigation.

11. International transfers

Our shipping partner and hosting providers may process data in the United States or other jurisdictions where they operate. Where such processing occurs, we take steps appropriate to the service relationship to protect Amazon Information in line with this policy and Amazon’s requirements.

12. Subprocessors / subcontractors

Our shipping partner receives Amazon order shipping data only as needed to deliver seller-fulfilled orders. Hosting and infrastructure providers that support our internal application may process encrypted backups or system data. We review such providers for security suitability before granting access to systems that can handle Amazon Information.

13. Children’s data

Our SP-API workflows are not directed at children and are not intended to collect children’s data. Amazon order PII is processed only as provided by Amazon for order fulfillment.

14. Changes to this policy

We may update this policy to reflect operational, legal, or Amazon policy changes. The effective date at the top of this page will be revised when material changes are made. Continued use of our SP-API integration after an update constitutes operation under the revised policy.

15. Contact / Incident Management Point of Contact (IMPOC)

For questions about this Amazon data handling policy, or to report a security concern related to our SP-API integration:

  • Name: Amin Shokouhi
  • Role: Owner / Developer / Incident Management Point of Contact
  • Email: artorang.com@gmail.com
  • Business: 9365893 CANADA INC (Artorang)

This page is intended to satisfy Amazon SP-API Data Governance documentation requirements regarding how 9365893 CANADA INC (Artorang) handles Amazon Information. It does not replace Amazon’s own privacy notices to Amazon customers, and it does not change Amazon’s role as the platform where those customers placed their orders.

Search

Back to top

Shopping Cart

Your cart is currently empty

Shop now