SP-API Privacy & Data Use Policy

12:39

Altura Group – Amazon SP-API Privacy & Data Use Policy

Last updated: 14 November 2025

Altura Group Ltd (“Altura Group”, “we”, “our”, “us”) provides Amazon consulting services supported by an internal analytics tool built using the Amazon Selling Partner API (“SP-API”). This policy outlines how we access, process, store, share, and protect Amazon Information in compliance with:

  • Amazon’s Acceptable Use Policy (AUP)
  • Amazon’s Data Protection Policy (DPP)
  • Amazon Services API Developer Agreement
  • GDPR and other applicable data protection laws

1. Information We Access

With explicit authorisation from the Selling Partner, we may retrieve the following categories of data depending on the roles granted:

  • Sales, advertising, business reports
  • Finance, settlements, reconciliations
  • Inventory and catalogue data
  • Order and fulfilment data (non-PII except where legally required)
  • Brand analytics and insights
  • Buyer-seller messaging data (if applicable)

We do not access or store information beyond what is required to provide agreed services.


2. Purpose of Use

Amazon Information is used solely to:

  • Deliver analytics insights to authorised Selling Partners
  • Improve operational efficiency and reporting
  • Help Selling Partners manage their Amazon accounts
  • Fulfil legally required business functions (e.g., VAT reporting, accounting)

We do not:

  • Sell data
  • Aggregate data across different clients
  • Use data for marketing
  • Provide data to competitors or external parties
  • Publish insights about Amazon’s business

This fully aligns with AUP sections 4.2–4.5.


3. Data Sharing

We only share Amazon Information with:

  • Authorised Users (the brand owner granting access)
  • Internal Altura Group personnel who require access to perform their job

Third-party infrastructure includes:

  • Cloudflare (network security/CDN)
  • Neon (via AWS) (database storage)
  • Vercel (hosting platform where transit may occur)

No other external parties receive Amazon Information.

All third parties meet or exceed our security standards in accordance with AUP 4.7.


4. Security Controls

We maintain industry-standard security measures:

  • Role-based access restrictions
  • Credential security (no hardcoding, no sharing)
  • Encrypted communication (TLS)
  • Secure password policies
  • Monitoring, detection, and incident response
  • Required reporting to security@amazon.com for security incidents

We never request Amazon portal usernames, passwords, or access keys directly from clients.


5. Data Retention & Deletion

We retain Amazon Information only for as long as necessary to deliver contracted services or meet legal obligations.

Upon termination of services or upon request, all stored Amazon Information is securely deleted in compliance with the DPP.


6. Authorized Users Rights

Selling Partners may request:

  • Access to stored Amazon Information
  • Correction of data
  • Deletion of data
  • Revocation of SP-API authorisations at any time via Seller Central or Vendor Central

7. Contact Information

Altura Group Ltd

United Kingdom

Email: amazon@alturagroup.co.uk