Data protection

This page sets out how iCommerceteam handles data belonging to Amazon selling partners. It supplements our privacy policy, which covers personal information more generally.

Whose data it is

Data we access from a client’s Amazon account belongs to that client. We access it as a processor acting on their instructions, under an authorisation they grant and can withdraw. We do not acquire any rights over it by processing it.

How access is granted

  • Access is granted by the selling partner, either through delegated permissions in Seller Central or Vendor Central, or by authorising our application through the Selling Partner API.
  • We request the minimum permission level the work requires. Where a task needs read access, we do not request write access.
  • The selling partner can withdraw authorisation at any time through Amazon. Collection stops immediately when they do.

Roles we use and what each is for

Across our services and applications, we request the following Selling Partner API roles. Each is used only for the purpose stated.

RolePurpose
Amazon FulfillmentTo track inbound shipments and FBA inventory state as part of replenishment oversight and capacity planning.
Brand AnalyticsTo retrieve search query performance, market basket, item comparison and repeat purchase data for the authorising selling partner's own brand. This data is the basis of the search performance, competitive position and repeat purchase reporting described above.
Inventory and Order TrackingTo retrieve inventory position so reporting reflects stock availability during the period being analysed.
Product ListingTo create and update product listings, attributes and variation relationships on the client's behalf.
Selling Partner InsightsTo retrieve sales and traffic data used in the consolidated performance view alongside Brand Analytics data.

What we do with it

  • We process selling partner data to deliver the services that partner has engaged us for: reporting, analysis, catalogue work, advertising management and account operation.
  • We use it for that purpose and no other.

What we do not do with it

  • We do not combine one selling partner’s data with another’s.
  • We do not use it to produce benchmarks, market reports, or datasets made available to other clients or to anyone else.
  • We do not sell it, licence it, or trade it.
  • We do not use it to compete with the selling partner, or to inform our own retail activity.
  • We do not transfer it to third parties except the service providers needed to operate our systems, who process it on our instructions only.

How it is secured

  • Data is encrypted in transit and at rest.
  • Credentials and access tokens are stored separately from the data they unlock, with access limited to the systems that require them.
  • Access is limited to personnel working on that client’s engagement. Access is logged, reviewed periodically, and removed when someone leaves the engagement or the business.
  • Systems holding selling partner data require multi-factor authentication.
  • Data is segregated per client so that one client’s data cannot be reached from another’s reporting.

Retention and deletion

  • Selling partner data is retained for the duration of the engagement and for up to 90 days afterwards, so reporting can be handed over.
  • After that period it is deleted from active systems, and from backups on the backup rotation cycle.
  • A selling partner can request deletion at any time. Access tokens are revoked immediately, and we confirm in writing once deletion is complete.

Incidents

If we become aware of a security incident affecting selling partner data, we investigate immediately, contain it, and notify the affected client and any authority we are required to notify, within the timeframe that applies.

Questions

Book a call with any question about how your data is handled, or to request its deletion. Selling partners can also withdraw our access at any time directly through Amazon, which stops collection immediately.