Amazon SP-API Security & Data Protection

Learn how EliteSecom handles and protects data received through Amazon Selling Partner API (SP-API), with a focus on security, privacy, access control, retention, and responsible data handling.

Amazon SP-API Security Overview

EliteSecom uses Amazon Selling Partner API (SP-API) to provide authorized ecommerce and order management functionality. We handle Amazon data only for legitimate service purposes.

Data Flow Architecture

Amazon Seller

Amazon SP-API

EliteSecom

Authorized Seller Workflow

Seller Authorization

  • OAuth 2.0-based authorization with explicit seller consent
  • Token-based authentication with secure token storage
  • Scoped permissions based on seller-approved operations

Amazon Data Accessed

  • Order information for order management
  • Inventory data for inventory synchronization
  • Settlement reports for payment reconciliation

Access Control

  • Role-based access to Amazon data within EliteSecom
  • Audit logging of all Amazon API access and data usage
  • Regular access reviews and permission audits

Data Protection

  • Encryption of Amazon data in transit and at rest
  • Secure API communication with Amazon SP-API endpoints
  • Data isolation per seller account

Amazon Data & PII Handling

Description of the Amazon-related data actually processed by EliteSecom.

EliteSecom may access customer information (such as names and shipping addresses) necessary for order fulfillment, shipping label generation, and customer service operations. This data is accessed only when authorized by the seller through the Amazon SP-API authorization process.

This information is required to fulfill orders, generate shipping labels, provide customer support, and reconcile payments — all core functions of the order management system.

Order processing, shipping label generation, customer communication, and payment reconciliation functionality may require access to this data.

Access is restricted to authorized EliteSecom personnel and automated systems based on role-based access controls. All access is logged and audited.

Data is protected through encryption, access controls, audit logging, and security monitoring. Protection measures align with our SOC 2 Type II and ISO/IEC 27001:2022 controls.

Access Control

Access to Amazon-related data is restricted to authorized systems and personnel based on operational requirements.

Role-Based Access

Access controls based on user roles and responsibilities.

Principle of Least Privilege

Users have only the access necessary for their specific roles.

Audit Logging

Comprehensive logging of all Amazon data access and usage.

Regular Access Reviews

Periodic review and revocation of unnecessary access permissions.

Amazon SP-API Compliance

EliteSecom's commitment to responsible handling of Amazon SP-API data and applicable requirements.

Amazon data is accessed only with explicit seller authorization through the Amazon SP-API OAuth 2.0 process

Data processing is limited to the specific scope authorized by the seller and necessary for service delivery

Security controls align with SOC 2 Type II and ISO/IEC 27001:2022 certifications

Regular security assessments including VAPT to identify and remediate vulnerabilities

Amazon data is not used for advertising purposes or sold to third parties

Amazon SP-API Security Inquiries

For questions about EliteSecom's Amazon SP-API security and data handling practices, please contact:

security@elitesecom.ai