AMAZON DATA HANDLING & SP-API DISCLOSURE

This document describes how Jerseytech LLC ("oneshipbox") collects, uses, stores, and protects data obtained through Amazon Selling Partner API (SP-API) and related Amazon integrations.

This disclosure supplements our Privacy Notice and Terms of Use. oneshipbox is an independent software provider and is not Amazon. Unless separately stated in writing, we are not an official Amazon partner.

We maintain this disclosure in alignment with Amazon's Data Protection Policy (DPP) and Acceptable Use Policy (AUP) for Solution Providers.

1. Scope

This policy applies to Amazon seller data accessed after You authorize oneshipbox through Login with Amazon (LWA) and grant the permissions required for our Services.

It covers all systems that store, process, or otherwise handle Information retrieved from the Amazon Services API.

2. SP-API Use Cases

We access Amazon data solely to provide features You enable, including:

  • Order synchronization and fulfillment workflow management;
  • Inventory and listing updates (SKU, quantity, pricing);
  • Shipment tracking and carrier label integration;
  • Performance analytics and operational reporting;
  • Account health monitoring tools (informational only — not a guarantee of account status);
  • Buyer-seller messaging and solicitations where You enable those features;
  • Merchant fulfillment and shipping rate services where You enable those features.

3. Data Categories

Non-PII Amazon Data

Product identifiers (ASIN, SKU), order IDs, inventory levels, pricing, fees, and shipment status.

Limited Buyer PII

Name, shipping address, and phone number when required to fulfill orders through integrated workflows. We access only the minimum PII necessary for the authorized purpose.

Authentication Tokens

LWA refresh tokens and SP-API credentials stored securely and used only for authorized API calls on Your behalf.

4. Data Use Restrictions

  • We do not sell Amazon customer data;
  • We do not use Amazon data for advertising unrelated to Your authorized use;
  • We do not aggregate Amazon data across sellers for competitive intelligence or to provide insights to competing sellers;
  • We do not promote, publish, or share insights about Amazon's business for our own or others' business purposes;
  • We do not use, offer, or promote external data services that vend information retrieved from Amazon;
  • We do not share Amazon PII with third parties except as needed to provide Services You request (e.g., carriers, warehouse partners You configure) or as required by law;
  • We comply with Amazon's Data Protection Policy (DPP), Acceptable Use Policy (AUP), and applicable SP-API terms.

5. PII Use Purposes

Permitted Purposes

Buyer PII obtained through Amazon is used only for merchant fulfilled shipping and related operational purposes, including:

  • Fulfilling orders You authorize through the Services;
  • Calculating and remitting taxes;
  • Producing tax invoices and other legally required documents;
  • Meeting legal, tax, or regulatory requirements.

Prohibited Uses

We do not use Amazon buyer PII for product marketing, review fabrication or modification, or any purpose unrelated to Your authorized fulfillment operations.

6. Data Retention

Buyer PII

Buyer PII is retained no longer than thirty (30) days after order delivery, and only for as long as necessary to (i) fulfill orders, (ii) calculate and remit taxes, (iii) produce tax invoices and other legally required documents, and (iv) meet legal, tax, or regulatory requirements.

PII may be retained beyond thirty (30) days after order delivery only if required by applicable law and only for the purpose of complying with that law.

Non-PII Amazon Data

Non-PII Amazon data (e.g., product identifiers, order IDs, inventory levels, pricing, fees, shipment status) is retained while Your account is active and as needed to provide the Services.

Non-PII data is deleted within eighteen (18) months unless a longer retention period is required by applicable law or regulation.

7. Security Measures

We maintain physical, administrative, and technical safeguards consistent with industry-leading security and Amazon's DPP requirements, including:

7.1 Network and Infrastructure Protection

  • Network firewalls and access control lists to deny unauthorized access;
  • Network segmentation and intrusion detection/prevention mechanisms;
  • Anti-virus and anti-malware tools updated at least monthly, with controls preventing employees from disabling protection;
  • Secure coding practices and annual data protection and IT security awareness training for approved personnel.

7.2 Access Management and Least Privilege

  • Unique user IDs assigned to each person with access to Information — no generic, shared, or default accounts;
  • Access granted on a need-to-know basis following the principle of least privilege;
  • Quarterly review of persons and services with access to Information;
  • Access disabled within twenty-four (24) hours for terminated employees or contractors;
  • Account lockout after ten (10) or fewer unsuccessful login attempts;
  • Prohibition on storing Information on personal devices.

7.3 Credential Management

  • Minimum twelve (12) character passwords with complexity requirements (uppercase, lowercase, numbers, special characters);
  • Multi-Factor Authentication (MFA) required for all user accounts;
  • Amazon API keys encrypted at rest; access limited to required personnel;
  • API keys and associated credentials rotated at least once every twelve (12) months.

7.4 Encryption in Transit and at Rest

  • TLS 1.2+ (or SFTP/SSH-2) for all Information in transit on internal and external endpoints;
  • Message-level encryption where channel encryption terminates in untrusted multi-tenant hardware;
  • PII encrypted at rest using at least AES-128 or RSA with 2048-bit keys or higher;
  • Key Management System (KMS) covering key generation, secure storage, rotation, and revocation.

7.5 Secure Development

  • No hardcoded sensitive credentials (encryption keys, secret access keys, passwords) in code;
  • Sensitive credentials not exposed in public code repositories;
  • Separate test and production environments.

7.6 Logging and Monitoring

  • Security-related event logging across service APIs, storage layers, and administrative dashboards;
  • Log review in real-time or at least bi-weekly;
  • Logs retained for at least twelve (12) months unless otherwise required by law;
  • Logs do not contain PII unless necessary to meet legal, tax, or regulatory requirements;
  • Monitoring alarms for suspicious activity (unauthorized calls, unexpected request rates, anomalous data retrieval).

7.7 Vulnerability Management

  • Vulnerability scanning at least every thirty (30) days;
  • Penetration testing at least every three hundred sixty-five (365) days;
  • Code scanned for vulnerabilities prior to each release;
  • Critical vulnerabilities remediated within seven (7) days; high-risk vulnerabilities within thirty (30) days;
  • Geographically separated backup site to ensure timely restoration of PII access and availability.

7.8 Asset Management and Data Loss Prevention

  • Quarterly inventory of software and physical assets with access to PII;
  • Regular patching, updates, and change management with segregation of duties;
  • PII not stored on removable media, personal devices, or unsecured public cloud applications unless encrypted (AES-128 or RSA-2048 minimum);
  • Data loss prevention (DLP) controls to monitor and detect unauthorized data movement;
  • Secure disposal of printed documents containing PII.

7.9 Data Attribution

Amazon Information is stored in separate databases or tagged to identify its origin, ensuring Amazon data can be distinguished from other data sources.

8. Incident Response

We maintain a documented incident response plan reviewed at least every six (6) months and after major infrastructure or system changes.

Our Incident Management Point of Contact (IMPOC) is reachable at [email protected].

Upon detecting a Security Incident (any actual or suspected unauthorized access, collection, use, transmission, disclosure, corruption, or loss of Information), we will:

  1. Notify Amazon at [email protected] within twenty-four (24) hours of detection;
  2. Investigate the incident and document description, remediation actions, and corrective controls;
  3. Maintain chain of custody for evidence and make documentation available to Amazon upon request;
  4. Not represent or speak on behalf of Amazon to any regulatory authority or customers unless Amazon specifically requests in writing.

9. Data Deletion

Amazon-Requested Deletion

Upon Amazon's notice requiring deletion, we permanently and securely delete Information within thirty (30) days unless retention is necessary to meet legal, tax, or regulatory requirements.

All live (online or network accessible) instances of Information are permanently and securely deleted within ninety (90) days after Amazon's notice.

Secure deletion follows industry-standard sanitization processes such as NIST 800-88.

If requested by Amazon, we will certify in writing that all Information has been securely destroyed.

User-Requested Deletion

When You disconnect Amazon or close Your account, we delete or anonymize Amazon data within a reasonable period, subject to legal retention requirements.

To request deletion, email [email protected] with Your account email and seller ID. We will confirm completion within thirty (30) days.

10. Subprocessors

We use vetted cloud infrastructure providers to host the Services. Subprocessors are bound by confidentiality and data protection obligations at least as strict as our own.

We conduct annual third-party risk assessments of vendors or subcontractors before granting them access to Amazon data.

11. Audit and Compliance

  • We maintain records reasonably required to verify compliance with Amazon's AUP, DPP, and SP-API Developer Agreement during the agreement period and for twelve (12) months thereafter;
  • Upon Amazon's written request, we will certify in writing that we are in compliance with these policies;
  • We will cooperate with Amazon audits, assessments, and inspections of systems involved in retrieving, storing, or processing Information;
  • If an audit reveals deficiencies, we will remediate them at our cost within an agreed-upon timeframe and provide evidence as requested by Amazon.

12. Organizational Change Notification

We maintain a written policy to inform Amazon SP-API Solution Provider Support (https://developer.amazonservices.com/support) within thirty (30) days of organizational changes or events that materially change our need for or use of Information, including mergers, acquisitions, transfers of business ownership, or material changes in product or service offerings.

We disclose affiliated entities involved in our Application or service when requesting additional API roles.

13. Your Responsibilities

You must comply with Amazon's Acceptable Use Policy, Data Protection Policy, and marketplace rules.

You are the seller of record and remain responsible for order fulfillment, customer communications, returns, and account health.

Do not use oneshipbox to circumvent Amazon policies or to misrepresent Your relationship with Amazon.

Do not share Your Amazon access keys, portal passwords, or SP-API credentials with us or any third party outside authorized OAuth/LWA flows.

14. Updates and Contact

We may update this disclosure to reflect changes in Amazon requirements or our practices.

Questions: [email protected]