AMAZON SP-API COMPLIANCE

Amazon data, handled with purpose and care.

How Magallane accesses, protects and uses Amazon seller information to deliver authorized marketplace workflows.

ENCRYPTEDACCESS CONTROLLEDCLEAR TERMS

Amazon Selling Partner API use

Magallane uses Amazon SP-API only to provide seller-authorized features such as order synchronization, inventory management, listing workflows, pricing, catalog lookup and FBA operations.

  • Orders and fulfillment workflows
  • FBA and FBM inventory
  • Listings, catalog and pricing
  • Seller-requested analytics

Data minimization and purpose limitation

We request and process only the information required to deliver the feature selected by the seller. Amazon information is not sold, used for advertising profiles or disclosed for unrelated purposes.

Protection of Amazon information

Marketplace credentials and sensitive configuration are protected using AES-256-GCM encryption. Connections use encrypted transport, access is restricted by user and tenant, and application activity is logged for accountability.

  • Encrypted in transit and at rest
  • Tenant-level data isolation
  • Role and session-based access controls
  • No credential display in the user interface

Retention and deletion

Amazon information is retained only while required to provide authorized functionality, satisfy legal obligations or resolve operational records. Sellers may disconnect their Amazon account and request deletion of eligible data.

Incident response

Magallane maintains procedures to identify, contain, investigate and remediate suspected security events. Affected parties and Amazon are notified when required by applicable policy or law.

Seller control

The seller remains in control of marketplace authorization. Access can be revoked through Magallane or Amazon Seller Central, after which new API retrieval stops.