Privacy policy
This policy explains what information iCommerceteam collects, why we collect it, how we look after it, who we share it with, and how long we keep it. It covers visitors to this website and the clients we work with.
For the specific handling of Amazon selling partner data, see our data protection page.
Who we are
iCommerceteam provides Amazon marketplace services to businesses. For the purposes of data protection law we act as a data controller for information about our own website visitors and client contacts, and as a data processor for the account data our clients authorise us to access on their behalf.
You can reach us about anything in this policy by booking a call, which is the contact route for this site.
What we collect
Information you give us
- Details you provide when booking a call: your name, email address, and anything you write when scheduling. Bookings are handled by Calendly, which processes that information on our behalf and under its own privacy policy.
- Information about your Amazon business that you share with us during scoping, such as approximate catalogue size and the marketplaces you sell in.
- Correspondence between us, including email and meeting notes, kept for the duration of our working relationship.
Information we access on a client’s behalf
- Amazon account data that a client authorises us to access, either through delegated Seller Central or Vendor Central permissions or through the Selling Partner API. This may include catalogue, inventory, order, advertising and performance data.
- This data belongs to the client. We access it to deliver the services they have engaged us for, under the authorisation they grant, and for no other purpose.
Information collected automatically
- Standard server logs for this website, including IP address, browser type and pages requested. These are used to keep the site running and secure.
- This site does not use advertising cookies, and does not track visitors across other websites.
How we use it
- To hold the call you booked and prepare a quote afterwards.
- To deliver the services a client has engaged us for, including reporting and analysis.
- To administer our contract with a client, including invoicing.
- To keep this website secure and to diagnose technical problems.
- To meet legal and accounting obligations that apply to us.
We do not sell personal information. We do not use client account data to build products or benchmarks offered to anyone else, and we do not combine one client’s data with another’s.
Our legal basis
- Legitimate interests. Responding to an enquiry you sent us, and keeping our website secure.
- Performance of a contract. Delivering the services a client has engaged us for.
- Legal obligation. Retaining records we are required to keep.
- Consent. Where you have given it, and which you can withdraw at any time.
How we store and protect it
- Data is encrypted in transit and at rest.
- Credentials and access tokens are stored separately from the data they unlock, with access limited to the systems that need them.
- Access is restricted to personnel working on the relevant engagement, is reviewed periodically, and is removed when someone leaves the engagement or the business.
- Systems holding client data require multi-factor authentication.
- We keep records of who has access to what, so that access can be audited and withdrawn.
Who we share it with
We share personal information only where it is necessary, and only with:
- Service providers who host our systems or handle our scheduling, currently Railway for hosting and Calendly for bookings. They work under contracts that limit them to processing data on our instructions.
- Professional advisers such as accountants and lawyers, where required.
- Authorities, where we are legally required to disclose information.
We do not share client account data with other clients, and we do not pass it to third parties for their own purposes.
International transfers
Where information is transferred outside the region it was collected in, we use providers who offer appropriate safeguards for that transfer, and we limit transfers to what the service requires.
How long we keep it
- Bookings and enquiries that do not become engagements. Kept for up to 12 months, then deleted.
- Client account data. Kept for the duration of the engagement and for up to 90 days afterwards, so reporting can be handed over, then deleted.
- Contractual and financial records. Kept for the period our legal and accounting obligations require.
- Website logs. Kept for up to 90 days.
A client can ask us to delete their data sooner, and we will do so except where we are legally required to retain it.
How we delete it
When a retention period ends, or when deletion is requested, data is removed from our active systems and from backups on the backup rotation cycle. Access tokens are revoked immediately on request or when an engagement ends. We confirm in writing once deletion is complete.
Your rights
Depending on where you are, you may have the right to ask us for a copy of your information, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. You can also withdraw consent where our use relies on it, and complain to your local data protection authority.
To exercise any of these, book a call and raise it there, or state the request when booking. We respond within one month.
Changes to this policy
If we change this policy we will update this page. Where the change is significant, we will tell affected clients directly.
Contact
iCommerceteam
Book a call