Amazon Seller Data Security & Compliance
SellerVault is built with enterprise-grade security from the ground up. Here's how we protect your Amazon seller data.
Security Architecture
Encryption at Rest & In Transit
All data is encrypted using TLS 1.3 in transit and AES-256 at rest. Amazon API credentials are encrypted with per-tenant keys before storage.
Authentication & Access Control
JWT-based authentication with short-lived access tokens (15 min) and secure refresh tokens (7 days). Role-based permissions (admin, member, viewer) with 10-attempt lockout protection.
Minimal Data Access
We only access inventory, orders, sales, and fee data via Amazon SP-API. We never access your account settings, payment information, or listing content.
Infrastructure Security
Hosted on dedicated VPS with SSH key-only access. Database connections restricted to localhost. Nginx reverse proxy with SSL termination and rate limiting.
Token Management
Amazon OAuth tokens are stored encrypted and rotated automatically. You can revoke access anytime from Amazon Seller Central without contacting us.
Data Retention & Deletion
12-month operational-data retention policy with automated archival. Full data export is available on request. Account deletion removes personal, seller, and Amazon data; limited Stripe customer, subscription, and Checkout identifiers plus reconciled SaaS payment-retry, scanner-overage invoice, and reimbursement commission invoice evidence may be retained for up to seven years where required for tax, accounting, and legal obligations.
Compliance
Amazon Developer Policy (DPP)
CompliantSellerVault adheres to Amazon's Data Protection Policy including Section 1.4 (authentication controls), Section 3 (data encryption), and Section 5 (data retention). No PII is shared with third parties.
Amazon SP-API Terms of Use
CompliantRegistered Amazon SP-API developer with approved application. All API calls respect rate limits and use official SDK methods.
GDPR
ReadyData processing agreements available on request. Users can export or delete their data at any time. No personal data is processed without consent.
CCPA
ReadyCalifornia residents can request data disclosure, deletion, or opt-out of data sale (we don't sell data). Contact [email protected] for requests.
What We Access
Data We Access
- Product catalog (ASIN, SKU, title, price)
- Inventory levels and FBA stock
- Order history and sales data
- Amazon fees (referral, FBA, storage)
- Inbound shipment records
- Customer return records (for reimbursement auditing)
Data We Never Access
- Your Amazon password or login credentials
- Payment or banking information
- Account settings or seller profile
- Listing content or product descriptions
- Customer personal information (names, addresses)
- Advertising bid strategies or budgets (unless Ads API connected)
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly. We take all reports seriously and will respond within 48 hours.
Contact: [email protected]