Amazon Legal addendum · Legal version v1 · Last updated: July 13, 2026
Amazon SP-API Data Protection Policy Disclosure
Last updated: August 23, 2026
This addendum describes how AtlasCore Marketplace Hub handles Amazon Selling Partner API (SP-API) data in alignment with the Amazon Data Protection Policy (DPP) and Acceptable Use Policy.
Independent application status
AtlasCore is an independent software application. Amazon, Selling Partner API, and related marks are trademarks of Amazon.com, Inc. or its affiliates. AtlasCore is not sponsored, endorsed, or affiliated with Amazon.
Data we access
When you connect Amazon Seller Central, AtlasCore may access:
- Catalog and listing metadata for workspace synchronization
- Order headers and line items for operational dashboards
- Buyer and shipping personally identifiable information (PII) only through Restricted Data Token (RDT) flows when explicitly authorized
Cached order blobs store an allowlisted operational snapshot (order identifiers, status, totals, fulfillment channel, and actual ship/delivery timestamps). Buyer name, phone, and shipping address are stored in separate encrypted columns — not as unrestricted Orders API dumps.
Controls at rest and in transit
- Encryption: LWA refresh/access tokens and cached order PII are encrypted at rest using AES-256-GCM (`enc:v1:` prefix).
- Transport: All production API traffic uses TLS 1.2+ (HTTPS).
- Access control: Unmasking buyer/shipping PII requires authenticated sessions and fulfillment-manager or platform-admin roles.
- Retention: Buyer/shipping PII is automatically purged 30 days after fulfillment when an explicit Amazon ship or delivery timestamp is present (`ShipmentDate`, `ShipDate`, `DeliveryDate`, `ActualDeliveryDate`, or `DeliveredDate` on `Shipped` / `Delivered` orders). If a terminal order has no explicit fulfillment timestamp, AtlasCore does not invent one — `fulfilled_at` stays empty and the 90-day unfulfilled clock from `purchase_date` applies. Promised ship dates and generic last-update timestamps do not start the 30-day clock. After purge, later order syncs update operational status and totals only and do not rehydrate buyer PII. Cached webhook envelopes store only operational identifiers (notification type, seller id, event id, order id).
Seller controls
- Disconnect Amazon in AtlasCore to stop sync and destroy locally stored LWA credentials and cached Amazon data. Disconnect does not call a remote Amazon token-revoke API. Revoke AtlasCore in Seller Central → Apps & Services to invalidate tokens at the source.
- Request account deletion at Delete Account or contact privacy@atlascore-market.com.
See also our global Privacy Policy and Data & Retention policies.