Amazon Information is used only to provide authorized store operations and fulfillment services. We do not sell Amazon Information or use restricted information for advertising profiles or purposes unrelated to the authorized service.
1. Scope
This policy applies to information processed by Adtron through the Amazon Selling Partner API, Amazon Ads API, and information voluntarily provided by authorized brand sellers in connection with order, inventory, finance, advertising analysis, and fulfillment collaboration services.
2. Information collection and use
After a seller expressly authorizes Adtron through OAuth, we may process store identifiers, product and SKU information, inventory, orders, financial information, advertising information, and shipping information within the authorized scope. For seller-fulfilled orders, this may include the recipient's name, delivery address, and necessary contact information when required to complete delivery.
We use this information only to:
- display and manage authorized store orders, inventory, and operating information;
- prepare or verify shipping labels, arrange delivery, and update tracking;
- handle delivery exceptions and necessary customer support;
- support financial reconciliation, advertising analysis, and operations collaboration;
- secure the service, audit access, and investigate anomalous activity; and
- comply with applicable legal and Amazon policy obligations.
3. Information sharing
Each client may access only information from its own authorized stores. When a seller instructs us to complete seller-fulfilled delivery, we may provide a carrier with the minimum information required to complete that delivery. We do not disclose Amazon Information to unrelated third parties except when required by law, directed by the seller, or necessary to provide the agreed service.
We do not sell Amazon Information or share it with advertisers, data brokers, or other unrelated third parties.
4. Security and access controls
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including:
- TLS protection for information in transit and encryption or controlled protection for sensitive information at rest;
- least-privilege access based on job responsibility and business need;
- separation of client, store, environment, and functional access;
- logging of authentication, authorization, administrative actions, and restricted information access;
- controlled credential management, system patching, network restrictions, monitoring, and periodic access review;
- separation of development and production environments, with synthetic or de-identified test data preferred; and
- security awareness and confidentiality obligations for personnel with authorized access.
5. Retention and deletion
We retain information only for the time needed to provide the authorized service and satisfy applicable legal obligations. Recipient personally identifiable information used for seller-fulfilled orders is generally deleted or de-identified within 30 days after shipment. If law requires longer retention, its use and access are restricted to that obligation.
When a seller revokes authorization or the service ends, we stop new access and delete or de-identify related information according to the applicable retention schedule, unless retention is legally required. Backups age out according to controlled backup retention schedules and are not restored for ordinary business use after a deletion request.
6. Seller rights and choices
Authorized sellers may revoke the Adtron application through their Amazon account. Sellers may also contact us to request access to, correction of, or deletion of information processed for their stores. We verify the requester's relationship to the relevant seller account before fulfilling a request.
7. Security incident response
If an incident may involve Amazon Information, we initiate our incident response process, isolate affected systems or credentials, preserve relevant logs, assess impact, remediate the issue, and implement measures to reduce recurrence. Incidents involving Amazon Information are reported through Amazon's designated security channel in accordance with Amazon's Data Protection Policy, including applicable reporting time requirements.
8. Policy changes
We may update this policy to reflect changes in our services, legal requirements, or Amazon policies. Material changes will be published on this page and the “Last updated” date will be revised.
9. Contact
Data controller and service provider: Hefei Xitu Technology Development Co., Ltd. (合肥希图科技发展有限公司)
Application: Adtron
Email: wz@doitio.com
Website: https://www.doitio.com/