Amazon Information from one authorized seller is used only to provide services to that seller. We do not combine Amazon business data across sellers for benchmarking, resale, marketing, public reporting, or our own business purposes, and we do not publish or share insights derived from Amazon business data.
1. Scope
This policy applies to information processed by Adtron through the Amazon Selling Partner API and information voluntarily provided by authorized sellers for non-PII order and inventory synchronization and Sales and Traffic business reporting. The current SP-API request is limited to Inventory and Order Tracking, Amazon Fulfillment, and Brand Analytics. Separately authorized Amazon Ads API data is governed by its own enabled scope and does not expand SP-API access.
2. Information collection and use
After a seller expressly authorizes Adtron through OAuth, the current service may process store identifiers, product and SKU information, non-PII order-tracking fields, FBM and FBA inventory, and Sales and Traffic report metrics within the authorized scope. The current request does not include buyer names, addresses, contact details, restricted shipping data, financial settlement data, or write access to listings, prices, inventory, or fulfillment.
We use this information only to:
- synchronize authorized store order status, SKU, quantity, dates, and fulfillment channel without customer-identifying information;
- synchronize authorized FBM listing availability and FBA inventory quantities;
- produce store-specific Sales and Traffic business reports for the authorizing seller;
- secure the service, audit access, and investigate anomalous activity; and
- comply with applicable legal and Amazon policy obligations.
3. Information sharing
Each client may access only information from its own authorized stores. Amazon Information is not shared with external parties for the current order, inventory, and business-reporting use case, except when required by law or expressly directed by the authorizing seller.
We do not aggregate Amazon business data from multiple authorized sellers for benchmarking, comparison, resale, marketing, public reports, model training, or any Adtron business purpose. We do not publish or share insights derived from Amazon business data. We do not sell Amazon Information or share it with advertisers, data brokers, or other unrelated third parties.
4. Security and access controls
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including:
- TLS protection for information in transit and encryption or controlled protection for sensitive information at rest;
- least-privilege access based on job responsibility and business need;
- separation of client, store, environment, and functional access;
- logging of authentication, authorization, administrative actions, and restricted information access;
- controlled credential management, system patching, network restrictions, monitoring, and periodic access review;
- separation of development and production environments, with synthetic or de-identified test data preferred; and
- security awareness and confidentiality obligations for personnel with authorized access.
5. Retention and deletion
We retain information only for the time needed to provide the authorized service and satisfy applicable legal obligations. The current request does not include recipient personally identifiable information or restricted shipping data.
When a seller revokes authorization or the service ends, we stop new access and delete or de-identify related information according to the applicable retention schedule, unless retention is legally required. Backups age out according to controlled backup retention schedules and are not restored for ordinary business use after a deletion request.
6. Seller rights and choices
Authorized sellers may revoke the Adtron application through their Amazon account. Sellers may also contact us to request access to, correction of, or deletion of information processed for their stores. We verify the requester's relationship to the relevant seller account before fulfilling a request.
7. Security incident response
If an incident may involve Amazon Information, we initiate our incident response process, isolate affected systems or credentials, preserve relevant logs, assess impact, remediate the issue, and implement measures to reduce recurrence. Incidents involving Amazon Information are reported through Amazon's designated security channel in accordance with Amazon's Data Protection Policy, including applicable reporting time requirements.
8. Policy changes
We may update this policy to reflect changes in our services, legal requirements, or Amazon policies. Material changes will be published on this page and the “Last updated” date will be revised.
9. Contact
Data controller and service provider: Hefei Xitu Technology Development Co., Ltd. (合肥希图科技发展有限公司)
Application: Adtron
Email: wz@doitio.com
Website: https://www.doitio.com/