Data security & Amazon data policy
Last updated 17 September 2026 · WeSpark
This policy describes how WeSpark protects client data, including information obtained from Amazon Seller Central, the Amazon Advertising console and the Amazon Selling Partner API (SP-API). It is written to meet Amazon's Acceptable Use Policy and Data Protection Policy and applies to every team member, contractor and system that touches client data.
1. How we connect to your Amazon account
Access is granted only through Amazon's own permission systems: a Seller Central user invitation with limited permissions, Advertising console access, or an SP-API authorisation that you approve in Seller Central and can revoke at any time. We never ask for, receive or store your Amazon password, and we never share logins.
2. What we use the Selling Partner API for
We request only unrestricted SP-API roles needed to run advertising, listing and catalogue work: Product Listing, Pricing, Inventory and Order Tracking, Amazon Fulfillment, Brand Analytics, Selling Partner Insights, and Finance and Accounting. We do not request roles that expose buyer personally identifiable information (Direct-to-Consumer Shipping, Buyer Communication, Tax Invoicing). The data is used to audit accounts, build and optimise listings and campaigns, plan inventory, and produce the weekly, monthly and quarterly reports described in this playbook — for that client only.
3. Use limitation
Amazon information is used solely to provide the contracted services to the client it belongs to. It is never sold, rented, shared with other clients, used for our own marketing or product development, combined across clients, or used to build models or benchmarks that identify a seller. We do not use Amazon information to contact buyers.
4. Personally identifiable information
Our services do not require buyer PII (names, addresses, phone numbers, email addresses). We do not request API roles that return it. If PII appears incidentally in a report, we do not download, retain, or process it, and any such record is deleted within 30 days of the order being fulfilled unless a legal obligation requires otherwise. PII is never written to logs, spreadsheets, tickets or chat tools.
5. Where data lives and how it is protected
Client data is stored only in access-controlled cloud services (Google Workspace and our reporting tools) hosted by providers that maintain SOC 2 / ISO 27001 certified environments. Data is encrypted in transit with TLS 1.2 or higher and encrypted at rest with AES-256 or stronger. API credentials and refresh tokens are stored in a secrets manager, never in code, documents or email, and are rotated on staff changes. No client data is stored on personal devices or removable media.
6. Who can access it
Every team member has an individual named account protected by multi-factor authentication; shared accounts are prohibited. Access follows least privilege: each person can see only the client accounts they work on, and access is reviewed quarterly and removed within 24 hours when someone leaves or changes role. Company devices use full-disk encryption, automatic screen lock, managed updates and endpoint protection.
7. Monitoring and logging
Access to client data and API calls is logged with who, what and when. Logs are retained for at least 90 days, are protected from tampering, and never contain PII or credentials. Anomalies such as unusual download volumes or logins from new locations are reviewed.
8. Retention and deletion
Client data is kept only for as long as the engagement requires. When an engagement ends, or when you revoke access, we delete the client's Amazon information from our systems within 30 days — immediately on request — and confirm deletion in writing. Encrypted backups expire within a further 30 days. Records we must keep by law (invoices, contracts) are kept without Amazon account data.
9. Security incidents
We maintain a written incident-response plan. If we detect or suspect a security incident affecting Amazon information, we notify Amazon at security@amazon.com within 24 hours of detection, notify the affected client without undue delay, contain the incident, and preserve evidence. Where personal data of EU/UK or California residents is involved, we also notify the relevant authorities within the legally required windows.
10. Secure development and vulnerability management
Any software we run against Amazon data follows Amazon's SP-API guidance: least-privilege scopes, no credentials in source code, dependency updates, and review before release. Critical security patches are applied within 72 hours of release; other patches within 30 days. We do not expose Amazon information through public endpoints.
11. Sub-processors
Google Workspace (documents, spreadsheets, email), our cloud hosting and reporting providers, and Stripe (payments — card numbers never reach us). Each is bound by data-processing terms and does not receive buyer PII. We will inform clients before adding a sub-processor that would process their Amazon information.
12. Audits and requests
We cooperate with Amazon's audit and certification requests under the Data Protection Policy, and we provide clients with a written summary of the controls above on request. Security questions or deletion requests: operations@wespark.co.
WeSpark
Office 1: 6340 N Eldridge Pkwy Ste N117, Houston, TX 77041, US
+1 (917) 939-5151 · operations@wespark.co
