Legal version v1 · Last updated: July 13, 2026
Privacy Policy
This Privacy Policy describes how AtlasCore Marketplace Hub collects, uses, stores, and protects information when you use our multi-marketplace seller dashboard across Etsy, Amazon, Shopify, eBay, Walmart, TikTok Shop, Instagram Shopping, Pinterest Shopping, Faire, WooCommerce, Squarespace Commerce, BigCommerce, Temu, Wayfair, SHEIN, Wish, Newegg, Magento / Adobe Commerce, Oracle NetSuite Commerce, custom and third-party marketplace integrations.
1. Our Commitment
User data is encrypted in transit and at rest where supported. We do not sell your personal information or seller data to data brokers, advertisers, or unrelated third parties.
2. Etsy Data Handling & Privacy Notice
The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.
DISCLAIMER: THIS APPLICATION IS SOLELY PROVIDED BY ATLASCORE ("APPLICATION DEVELOPER"). YOU ACKNOWLEDGE THAT ETSY, INC. AND ITS AFFILIATES ARE NOT THE APPLICATION DEVELOPER, DO NOT PROVIDE THE APPLICATION SERVICE, AND MAKE NO WARRANTIES OF ANY KIND WITH RESPECT TO THE APPLICATION OR DATA ACCESSED THROUGH IT.
This section describes how AtlasCore processes Etsy seller data when you connect an Etsy shop. AtlasCore is an independent application and is not endorsed or certified by Etsy, Inc.
a) Data collected
- Shop information: shop name, shop ID, and connection status retrieved via OAuth
shops_r - Listings: listing titles, SKUs, prices, quantities, and catalog snapshots via
listings_r - Order receipts: receipt and transaction metadata when expanded OAuth scopes (e.g.
transactions_r) are granted after Etsy commercial approval — not collected in default personal read-only mode - OAuth credentials: encrypted access and refresh tokens required to maintain your authorized connection
b) Purpose of processing
- Personal mode: shop identity and read-only listing snapshots refreshed to stay inside Etsy's 6-hour display cache
- Commercial mode (after Etsy scope approval): order fulfillment workflows, shipping tracking, and seller dashboard analytics you enable
- Secure token refresh and webhook-driven cache updates for connected shops
c) Retention & security
- Etsy OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest and are never sold or shared with unrelated third parties
- Encrypted buyer name and shipping/contact fields on cached receipts are redacted 30 days after fulfillment (
fulfilled_at) or 90 days after create if the receipt stays unfulfilled - Seller-facing order GETs are cache-only. Unmasked buyer PII requires
include_pii=trueand a platform administrator orfulfillment_managerrole (audit-logged) - Etsy webhook event payloads are retained for up to 90 days, then purged by a daily background retention job. Replay identifiers survive seller disconnect; ciphertext is scrubbed when the shop is unlinked
- Synced listing and shop snapshots follow the retention schedules in our Data & Retention Policy
d) Seller control
- Revoke OAuth: disconnect Etsy in the AtlasCore dashboard or revoke AtlasCore in Etsy's Apps & websites settings (see Disconnect Marketplace)
- Complete deletion: delete your AtlasCore account to queue permanent erasure of stored Etsy tokens, cached listings, orders, and connection metadata (see Delete Account or self-service deletion)
e) Local title and tag builder
Privacy Notice: Title and tag templates run locally in your browser. No listing data or shop metadata is transmitted to external machine learning models or third-party AI training endpoints per Etsy API Terms §5.
f) Security incidents & breach notification
AtlasCore maintains a Security Incident & Data Breach Protocol (docs/INCIDENT_RESPONSE_RUNBOOK.md) aligned with Etsy API Terms §7. For security events affecting Etsy shop or buyer data, we commit to:
- Notify Etsy's Data Protection Officer at dpo@etsy.com within 24 hours of confirmation
- Include the nature of the breach, affected endpoint(s), scope of PII impacted, and immediate remediation or containment steps taken
- Notify affected shop owners via support@atlascore-market.com within 24 hours of confirmation
3. Amazon Selling Partner Data Protection & Privacy Policy
This section describes how AtlasCore processes Amazon Selling Partner API (SP-API) data when you connect an Amazon seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Amazon.com, Inc.
a) Encryption at rest (AES-256-GCM)
- Amazon Login with Amazon (LWA) OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format — plaintext tokens are refused at decrypt time - Order buyer PII retrieved via Restricted Data Token (RDT) — including buyer names, shipping addresses, and phone numbers — is encrypted at rest in dedicated database columns (
buyer_name_enc,shipping_address_enc,phone_enc,raw_payload_enc) using the same AES-256-GCM standard
b) 30-day post-fulfillment PII purge (Amazon DPP)
AtlasCore operates an automated daily background retention job that redacts Amazon order buyer PII after 30 days post-fulfillment, consistent with Amazon's Data Protection Policy requirements for fulfilled orders:
- Eligible orders: status
Shipped,Delivered, orPartiallyShippedwith a recorded fulfillment date - Redaction overwrites encrypted PII columns with a secure redaction marker; purge events are recorded in the enterprise audit log
- Disconnecting Amazon or deleting your AtlasCore account permanently removes stored Amazon orders and encrypted credentials from your tenant workspace
c) Tenant isolation & Amazon AUP Sections 4.4 and 4.5
AtlasCore strictly adheres to Sections 4.4 and 4.5 of Amazon's Acceptable Use Policy:
- Amazon SP-API data is isolated per seller workspace — one Amazon account per AtlasCore tenant; all catalog and order queries are scoped to the authenticated seller
- Amazon seller data, ASIN performance records, and customer order details are processed exclusively for the private, authorized internal operational use of the seller account holder who connected the account
- AtlasCore never aggregates Amazon data across multiple sellers for comparative insights, pricing benchmarks, or public display
- AtlasCore never re-identifies, publishes, or sells Amazon seller data or buyer PII to any third party
d) Role-gated PII access
Unmasked Amazon buyer and shipping details in the dashboard require explicit authorization (platform administrator or fulfillment_manager role). Authorized PII access events are recorded in the audit log. By default, order responses return masked buyer information.
e) Seller control
- Disconnect Amazon: revokes stored LWA tokens, purges local encrypted order cache, and removes synced catalog rows (see Disconnect Marketplace)
- Account deletion: permanent erasure of Amazon credentials, orders, and catalog snapshots via GDPR marketplace purge (see Delete Account)
4. eBay Marketplace Data Protection & Privacy Policy
This section describes how AtlasCore processes eBay REST API data when you connect an eBay seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by eBay Inc.
a) Encryption at rest (AES-256-GCM)
- eBay OAuth access and refresh tokens and PKCE state verifiers are stored using AES-256-GCM encryption at rest with the
enc:v1:format — plaintext tokens are refused at decrypt time - Order buyer PII — including buyer usernames, registration names, and shipping addresses — is encrypted at rest in dedicated database columns before persistence using the same AES-256-GCM standard
b) 30-day post-fulfillment PII purge (eBay DPP)
AtlasCore operates an automated daily background retention job that redacts eBay order buyer and shipping PII after 30 days post-fulfillment:
- Eligible orders:
FULFILLEDstatus with a recorded fulfillment timestamp - Redaction overwrites encrypted PII columns with a secure redaction marker; the public orders cache API excludes buyer data by design
- Disconnecting eBay or deleting your AtlasCore account permanently removes stored eBay orders and encrypted credentials from your tenant workspace
c) Marketplace Account Deletion webhooks
AtlasCore registers for eBay Commerce Notifications including MARKETPLACE_ACCOUNT_DELETION. Verified notifications trigger automated purge of encrypted OAuth tokens, cached orders, and webhook ledger rows for the affected seller account.
d) Tenant isolation
- eBay seller data is isolated per enterprise workspace — one eBay account per AtlasCore tenant; catalog and order queries are scoped to the authenticated seller and tenant context
- Unmasked buyer details in fulfillment views require explicit authorization (fulfillment-manager or platform-admin roles)
e) Seller control
- Disconnect eBay: revokes stored OAuth tokens and purges local encrypted order cache (see Disconnect Marketplace)
- Account deletion: permanent erasure of eBay credentials, orders, and catalog snapshots via GDPR marketplace purge (see Delete Account)
- See also eBay DPP Compliance
5. Shopify Marketplace Data Protection & Privacy Policy
This section describes how AtlasCore processes Shopify Admin API data when you connect a Shopify store. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Shopify Inc.
a) Encryption at rest (AES-256-GCM)
- Shopify OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Webhook payloads and unified channel order snapshots are encrypted before persistence using the same standard
b) Mandatory GDPR webhooks & HMAC verification
AtlasCore registers for Shopify mandatory compliance webhooks including customers/data_request, customers/redact, and shop/redact. Inbound deliveries require valid HMAC-SHA256 signatures and are deduplicated using X-Shopify-Webhook-Id.
c) 30-day PII retention
AtlasCore operates automated retention that redacts Shopify order customer PII after 30 days post-fulfillment. The public orders cache API excludes customer names, emails, and addresses by design.
d) Tenant isolation
- Shopify store data is isolated per enterprise workspace — one Shopify account per AtlasCore tenant; catalog and order queries are scoped to the authenticated merchant and tenant context
e) Merchant control
- Disconnect Shopify: revokes stored OAuth tokens and purges local encrypted order cache (see Disconnect Marketplace)
- See also Shopify DPP Compliance
6. TikTok Shop Data Security & Privacy Policy (DSPR Compliance)
This section describes how AtlasCore processes TikTok Shop Open API data when you connect a TikTok seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by TikTok Inc. or its affiliates.
a) Encryption at rest (AES-256-GCM)
- TikTok Shop OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format — plaintext tokens are refused at decrypt time - Order buyer PII retrieved from TikTok Shop APIs — including buyer names, shipping addresses, and phone numbers — is encrypted at rest in dedicated database columns before persistence using the same AES-256-GCM standard
b) TikTok-owned 30-day / 90-day PII retention (DSPR)
A TikTok-owned retention worker redacts cached TikTok Shop buyer and shipping fields on two clocks, consistent with TikTok Partner Center Data Security and Privacy Requirements:
- 30-day post-delivery: terminal statuses
DELIVERED,COMPLETED, orCANCELLEDwith afulfilled_attimestamp. The clock may first stamp Partnershipped_time, then upgrades to the genuinedelivery_timewhen the order transitions toDELIVEREDorCOMPLETED - 90-day open ceiling: unfulfilled, shipped, or in-transit orders (
AWAITING_SHIPMENT,AWAITING_COLLECTION,IN_TRANSIT,SHIPPED), andCANCELLEDorders that have nofulfilled_at - Redaction overwrites encrypted PII columns with a secure redaction marker; purge events are recorded in the enterprise audit log
- Disconnecting TikTok Shop or deleting your AtlasCore account permanently removes stored TikTok orders and encrypted credentials for the signed-in seller (and workspace overlay, when present)
c) Tenant isolation & data use restrictions
AtlasCore adheres to TikTok Partner Center acceptable use and data security requirements:
- TikTok Shop data uses a B2C base scope — credentials, catalog, and orders belong to the signed-in seller (
user_id). An optional workspace overlay viaX-Tenantfurther partitions rows when a workspace is bound; personal connections remain seller-scoped when no tenant header is present - TikTok seller data and customer order details are processed exclusively for the private, authorized internal operational use of the seller account holder who connected the account
- AtlasCore never aggregates TikTok data across multiple sellers for comparative insights, pricing benchmarks, or public display
- AtlasCore never re-identifies, publishes, or sells TikTok seller data or buyer PII to any third party
d) Webhook security
Inbound TikTok Shop webhook notifications at POST /api/v1/tiktok/webhooks are verified using HMAC-SHA256 signatures against the raw request body before any order sync is queued. Requests outside a 300-second replay window (validated via webhook timestamp headers) are rejected before processing.
When TikTok sends a seller deauthorization or authorization revocation event, AtlasCore automatically revokes stored OAuth tokens and executes a tenant-scoped data purge for the affected shop — removing local encrypted orders, catalog rows, and webhook ledger entries for that workspace only.
e) Seller control
- Disconnect TikTok Shop: revokes stored OAuth tokens, purges local encrypted order cache, and removes synced catalog rows (see Disconnect Marketplace)
- Account deletion: permanent erasure of TikTok credentials, orders, and catalog snapshots via GDPR marketplace purge (see Delete Account)
- See also TikTok Shop Data Handling & DSPR Compliance
7. Instagram Shopping & Meta Platform Data Protection
This section describes how AtlasCore processes Instagram Shopping and Meta Commerce data when you connect a Facebook Page or Instagram Commerce account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Meta Platforms, Inc.
a) Encryption at rest (AES-256-GCM)
- Meta OAuth long-lived access tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Cached Instagram order rows store an allowlisted operational dictionary (order id, status, date, item counts, operational totals) encrypted at rest — not buyer or shipping fields
b) Instagram-owned 30-day / 90-day PII purge
AtlasCore operates an Instagram-owned retention worker that redacts Instagram Shopping / Meta Commerce operational order blobs on Instagram-specific clocks:
- 30-day post-delivery / terminal clock:
DELIVERED,COMPLETED, orCANCELLEDorders are redacted 30 days afterorder_date - 90-day open-order ceiling:
SHIPPED,IN_PROGRESS, and other unfulfilled statuses are redacted 90 days after first persist (created_at) - Redaction overwrites the encrypted Instagram payload with a secure marker. Later Instagram syncs and webhooks do not rehydrate a redacted row. Purge events are recorded in the enterprise audit log
- Disconnecting Instagram Shopping, Meta deauthorize callbacks, or deleting your AtlasCore account permanently removes stored orders and encrypted credentials for each matching Instagram account
c) Tenant isolation & data use restrictions
- Instagram Shopping is a B2C seller connection. The base binding is the signed-in seller; an enterprise workspace is optional and, when present, is scoped via the
X-Tenantheader - Meta Commerce data is processed exclusively for the authorized internal operational use of the seller who connected the account
- AtlasCore never aggregates Instagram or Meta Commerce data across sellers for comparative insights or public display
- AtlasCore strictly prohibits re-identification, sale, or unauthorized secondary use of Meta user and buyer data
- AtlasCore never re-identifies, publishes, or sells Instagram or Meta Commerce seller data or buyer PII to any third party
d) Webhook & compliance ingress
Inbound Meta webhook notifications at POST /api/v1/instagram/webhooks are verified using HMAC-SHA256 (X-Hub-Signature-256) against the raw request body. Meta data-deletion and deauthorize callbacks remain mounted for Platform Terms compliance regardless of feature flags.
When Meta sends a deauthorize or data-deletion request, AtlasCore persists an Instagram compliance receipt, then revokes stored tokens and executes a per-account tenant-scoped purge for every matching Page or Meta user binding.
e) Seller control
- Disconnect Instagram Shopping: purges encrypted tokens and cached order metadata for the active workspace (see Disconnect Marketplace)
- Meta data deletion: status updates are available at Instagram Data Deletion Status
- See also Instagram Shopping Data Handling and Instagram Shopping DPP Compliance
8. Pinterest Shopping Data Protection & Privacy Policy
This section describes how AtlasCore processes Pinterest Shopping and Pinterest API v5 data when you connect a merchant account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Pinterest, Inc.
a) Encryption at rest (AES-256-GCM)
- Pinterest OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Cached catalog product metadata stores only an operational allowlist (item id, title, description, price, availability, link). Encrypted webhook ledger rows store an operational envelope only. Sensitive order payloads use AES-256-GCM where retained
b) Pinterest-owned 30/90-day retention
AtlasCore runs a Pinterest-owned retention worker that redacts inactive or delisted catalog JSON and linked channel-order buyer PII on Pinterest clocks:
- 30 days after a terminal delivery or completion status for orders, and after inactive / deleted / delisted catalog items age past 30 days. Active in-stock catalog items are not redacted for age alone
- 90 days for open (non-terminal) Pinterest channel orders, measured from the cache pull timestamp
- Redaction overwrites catalog JSON with a secure marker and refuses later rehydration; purge events are recorded in the enterprise audit log
- Disconnecting Pinterest Shopping, merchant deauthorization webhooks, or deleting your AtlasCore account permanently removes stored catalog cache and encrypted credentials for that seller connection
c) Tenant isolation & data use restrictions
- Pinterest Shopping data is stored on a B2C seller base (the signed-in user), with optional workspace scoping when an enterprise tenant slug is bound. Personal-mode connections may have a null workspace.
X-Tenantis not the only isolation key - Pinterest merchant and catalog data is processed exclusively for the authorized internal operational use of the seller who connected the account
- AtlasCore never aggregates Pinterest merchant data across sellers for comparative insights or public display
- AtlasCore strictly prohibits re-identification, sale, or unauthorized secondary use of Pinterest merchant or buyer data
- AtlasCore never re-identifies, publishes, or sells Pinterest seller data or buyer PII to any third party
d) Webhook & compliance ingress
Inbound Pinterest merchant notifications at POST /api/v1/pinterest/webhooks are verified using HMAC-SHA256 (X-Pinterest-SHA256-Signature) against the raw request body within a 300-second replay window. Merchant deauthorization events trigger tenant-scoped token revocation and channel purge.
e) Seller control
- Disconnect Pinterest Shopping: purges encrypted tokens and cached catalog metadata for the active workspace (see Disconnect Marketplace)
- Pinterest merchant deauthorization: status and data wipe confirmation are available at Pinterest Data Deletion Status
- See also Pinterest Shopping Data Handling and Pinterest Shopping DPP Compliance
9. Faire Wholesale Data Protection & Privacy Policy
This section describes how AtlasCore processes Faire Wholesale and Faire External API v2 data when you connect a brand account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Faire Wholesale, Inc.
a) Encryption at rest (AES-256-GCM)
- Faire OAuth merchant access tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format. Platform Faire app credentials stay in the server environment and are not written on merchant account rows. - Cached wholesale order metadata is stored in tenant-scoped tables and redacted per retention policy using the same encryption standard where payloads contain sensitive fields
b) 30-day order PII retention
AtlasCore operates an automated Faire-owned retention job that redacts Faire cached order JSON and linked channel order payloads 30 days after fulfillment — DELIVERED, COMPLETED, FULFILLED, CLOSED, CANCELED, or CANCELLED — clocked from fulfilled_at. In-transit orders such as SHIPPED remain on the 90-day open ceiling until one of those terminal states is reached. Never-fulfilled and in-transit orders are redacted 90 days after order date:
- Redaction overwrites order JSON with a secure redaction marker; purge events are recorded in the enterprise audit log
- Cancellations start the 30-day post-terminal clock from
fulfilled_at; they are not held on the 90-day open ceiling - Disconnecting Faire Wholesale, brand deauthorization webhooks, or deleting your AtlasCore account permanently removes stored order cache and encrypted credentials from your tenant workspace
c) Tenant isolation & data use restrictions
- Faire Wholesale data is isolated per enterprise workspace — each connected brand account is bound to an AtlasCore tenant via the
X-Tenantheader - Faire brand and order data is processed exclusively for the authorized internal operational use of the seller who connected the account
- AtlasCore never aggregates Faire brand data across sellers for comparative insights or public display
- AtlasCore strictly prohibits re-identification, sale, or unauthorized secondary use of Faire brand or retailer data
- AtlasCore never re-identifies, publishes, or sells Faire seller data or retailer PII to any third party
d) Webhook security
Inbound Faire wholesale notifications at POST /api/v1/faire/webhooks are verified using HMAC-SHA256 (X-Faire-Signature) against the raw request body before JSON parsing. Valid signed webhooks for unlinked brand IDs are acknowledged with HTTP 200 and persisted with an unlinked account reference so the same event_id cannot process after a later reconnect.
e) Disconnect & deletion
- Disconnect Faire Wholesale: Disconnect purges encrypted merchant credentials and cached operational orders. Webhook replay ledger identifiers and inventory claims are unlinked (account disassociated) and retained so replay cannot wipe a reconnected brand or double-decrement stock.
- Faire brand deauthorization: status and purge confirmation at Faire Data Deletion Status
See also Faire Wholesale Data Handling
10. WooCommerce Data Protection & Privacy Policy
This section describes how AtlasCore processes WooCommerce REST API and webhook data when you connect a store. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Automattic Inc. or WooCommerce.
a) Encryption at rest (AES-256-GCM)
- WooCommerce REST API consumer keys and secrets are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Optional per-store webhook signing secrets use the same encryption standard
- Cached order JSON stores an allowlisted operational subset only (order id, status, totals, currency, dates, line SKU/quantity) — not billing/shipping name, address, email, or phone
b) 30-day / 90-day order PII retention
AtlasCore operates an automated daily multi-channel retention job that redacts WooCommerce cached order JSON and linked channel order payloads after 30 days post-fulfillment or 90 days unfulfilled:
- The 30-day post-fulfillment clock applies only to exact statuses
completed,refunded,cancelled,canceled,failed,trash, andfulfilled processing,on-hold, andpendingremain on the 90-day open-order ceiling- Redaction overwrites order JSON with a secure redaction marker; purge events are recorded in the enterprise audit log
- Disconnecting WooCommerce or deleting your AtlasCore account permanently removes stored order/product cache and encrypted credentials from your tenant workspace
c) Tenant isolation & data use restrictions
- WooCommerce store data is isolated per seller and optional workspace —
X-Tenantis used when present; personal mode uses no tenant. One active store URL is allowed platform-wide. - WooCommerce catalog and order data is processed exclusively for the authorized internal operational use of the seller who connected the store
- AtlasCore never aggregates WooCommerce store data across sellers for comparative insights or public display
d) Webhook security
Inbound WooCommerce notifications at POST /api/v1/woocommerce/webhooks/ are verified using Base64 HMAC-SHA256 (X-WC-Webhook-Signature) over the raw request body for linked stores. A timestamp header is not required. Initial ping deliveries receive an unsigned 200 handshake and are not persisted; unknown store URLs with a valid global webhook secret are acknowledged to prevent WooCommerce from auto-disabling webhook subscriptions.
See also WooCommerce Data Handling and WooCommerce Data Deletion Status.
11. Squarespace Commerce Data Protection & Privacy Policy
This section describes how AtlasCore processes Squarespace Commerce API and webhook data when you connect a site. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Squarespace, Inc.
a) Encryption at rest (AES-256-GCM)
- Squarespace Commerce API keys and OAuth access/refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Optional per-store webhook signing secrets use the same encryption standard
- Cached order JSON stores an allowlisted operational subset only (order id, status, totals, currency, dates, line SKU/quantity) — not billing/shipping name, address, email, or phone
b) 30-day / 90-day order PII retention
A Squarespace-owned retention worker redacts Squarespace cached order JSON and linked channel order payloads after 30 days post-fulfillment or 90 days unfulfilled. The 30-day clock applies only to the exact terminal set FULFILLED, CANCELED, CANCELLED, SHIPPED, DELIVERED, COMPLETED, CLOSEDand measures from native fulfilledOn (falling back to the earliest recorded terminal-state timestamp when fulfilledOn is omitted). PENDING (and other non-terminal statuses, including PAID) remain under the 90-day open ceiling measured from native createdOn.
c) Tenant isolation & data use restrictions
- Squarespace store data is isolated per seller and optional workspace —
X-Tenantis used when present; personal mode uses no tenant. One active site is allowed platform-wide. - AtlasCore never aggregates Squarespace store data across sellers for comparative insights or public display
d) Webhook security
Inbound Squarespace notifications at POST /api/v1/squarespace/webhooks/ are verified using hex HMAC-SHA256 (Squarespace-Signature, with X-Squarespace-Signature as an alias) over the raw request body. A timestamp header is not required. Unknown site identifiers with a valid HMAC are acknowledged with 200 to prevent platform retry storms. Webhook ledgers store identifiers only.
See also Squarespace Data Handling and Squarespace Data Deletion Status.
12. BigCommerce Data Protection & Privacy Policy
This section describes how AtlasCore processes BigCommerce API and webhook data when you connect a store. AtlasCore is an independent application and is not endorsed, certified, or sponsored by BigCommerce Pty. Ltd.
a) Encryption at rest (AES-256-GCM)
- BigCommerce OAuth access tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format - Cached order metadata stores an allowlisted operational subset only (no billing, shipping, email, or phone) and is redacted after 30 days post-fulfillment or 90 days unfulfilled
b) 30-day / 90-day order PII retention
A BigCommerce-owned retention worker redacts BigCommerce cached order JSON and linked channel order payloads after 30 days post-fulfillment or 90 days unfulfilled. The 30-day clock applies only to canonical status IDs 2 (Shipped), 4 (Refunded), 5 (Cancelled), 6 (Declined), 10 (Completed) and the matching exact names, using date_shipped (or first terminal time). Status IDs 3 (Partially Shipped) and 7 (Awaiting Payment), plus Awaiting Fulfillment / Awaiting Shipment, remain under the 90-day open ceiling from native date_created.
Requested OAuth scopes are read-only store_v2_orders_read_only store_v2_products_read_only unless BIGCOMMERCE_WRITE_APPROVED is true, in which case AtlasCore requests store_products store_orders store_inventory. Catalog and order reads run when the integration is enabled. Seller writes (product create, stock/price updates, order status) run only when that write flag is also true.
c) Tenant isolation & data use restrictions
- BigCommerce accounts, settings, and product mappings are isolated per enterprise workspace via the
X-Tenantheader. UnifiedChannelOrdersnapshots are seller-scoped (user_id+ channel + external order id), not tenant-partitioned - AtlasCore never aggregates BigCommerce store data across sellers for comparative insights or public display
d) Webhook & Single-Click App security
Inbound BigCommerce notifications at POST /api/v1/bigcommerce/webhooks/ are verified using hex HMAC-SHA256 (X-BC-Signature) over the raw request body. Unknown store hashes are acknowledged with 200 to prevent platform retry storms. Single-Click App lifecycle callbacks (/auth, /load, /uninstall) verify signed_payload HMAC before processing.
See also BigCommerce Data Handling and BigCommerce Data Deletion Status.
13. Temu Open Platform Data Protection & Privacy Policy
This section describes how AtlasCore processes Temu Open Platform API and webhook data when you connect a seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by PDD Holdings Inc. / Whaleco Inc. or Temu.
a) Request signing & encryption at rest
- Outbound Temu Open Platform API calls use MD5 request signing per Partner Platform requirements
- OAuth access and refresh tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format
b) 30-day / 90-day order PII retention
A Temu-owned retention worker redacts Temu cached order JSON and linked channel order payloads after 30 days post-fulfillment or 90 days unfulfilled. The 30-day clock applies only to exact terminal names (Shipped, Delivered, Fulfilled, Completed, Closed, Cancelled, Refunded), using shipTime / deliveryTime (or first terminal time). Awaiting, unshipped, and partial statuses remain under the 90-day open ceiling from native orderTime / createdAt.
c) Tenant isolation & data use restrictions
- Temu accounts, settings, and product mappings are isolated per enterprise workspace via the
X-Tenantheader. UnifiedChannelOrdersnapshots are seller-scoped (user_id+ channel + external order id), not tenant-partitioned - AtlasCore never aggregates Temu seller data across accounts for comparative insights or public display
d) Webhook security
Inbound Temu notifications at POST /api/v1/temu/webhooks/ are verified using HMAC-SHA256 (X-Temu-Signature) over the raw request body. Unknown seller identifiers are acknowledged with 200 to prevent platform retry storms.
See also Temu Data Handling and Temu Data Deletion Status.
14. Wayfair Partner Home Data Protection & Privacy Policy
This section describes how AtlasCore processes Wayfair Partner Home API and webhook data when you connect a supplier account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Wayfair Inc. or its affiliates.
a) Client credentials OAuth & encryption at rest
- Wayfair Partner Home integration uses OAuth 2.0 client credentials against
https://auth.wayfair.com - Merchant client secrets and access tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format.client_idandsupplier_idare stored as operational identifiers
b) Order cache & retention
Cached Wayfair purchase orders store an allowlisted operational subset only. Buyer, ship-to, and warehouse address blocks are not persisted. Seller dashboard reads remain cache-only. Live server-side GraphQL reads run for background scheduled syncs, health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment (SHIPPED / DELIVERED / CANCELLED / CANCELED / FULFILLED / COMPLETED / CLOSED) or 90 days unfulfilled from native poDate. Fulfillment clocks are not reset on later syncs. Inventory and ASN writes require operator write approval.
c) Tenant isolation & data use restrictions
- Wayfair supplier data is isolated by authenticated
user_idand tenant/account-bound operational models, together with theX-Tenantworkspace header - AtlasCore never aggregates Wayfair supplier data across accounts for comparative insights or public display
d) Webhook security
Inbound Wayfair notifications at POST /api/v1/wayfair/webhooks/ are verified using HMAC-SHA256 (X-Wayfair-Signature) over the raw request body before timestamp checks and JSON parsing. Unknown supplier identifiers are acknowledged with 200 to prevent platform retry storms.
Disconnect purges encrypted credentials and cached operational orders. Unlinked retention applies strictly to replay defense identifiers in wayfair_processed_webhook_events so a later reconnect cannot ingest the same notification twice.
See also Wayfair Data Handling and Wayfair Data Deletion Status.
15. SHEIN Open Platform Data Protection & Privacy Policy
This section describes how AtlasCore processes SHEIN Open Platform API and webhook data when you connect a seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by SHEIN Distribution Corporation or its affiliates.
a) Request signing & encryption at rest
- Outbound SHEIN Open Platform API calls use HMAC-SHA256 request signing per developer documentation
- Merchant App Secret, open_key, and access tokens are stored using AES-256-GCM encryption at rest with the
enc:v1:format.app_keyandopen_idare stored as operational identifiers
b) 30-day order PII retention
Cached SHEIN orders store an allowlisted operational subset only. Buyer names, phones, emails, and shipping/receiver addresses are not persisted. Seller dashboard reads remain cache-only. Live server-side reads run for background scheduled syncs, health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment (SHIPPED / DELIVERED / CANCELLED / CANCELED / FULFILLED / COMPLETED / CLOSED / REFUNDED) or 90 days unfulfilled. Fulfillment clocks are not reset on later syncs. Inventory and delivery writes require operator write approval.
c) Tenant isolation & data use restrictions
- SHEIN seller data is isolated per enterprise workspace — authenticated user scope plus connected accounts and settings — via the
X-Tenantheader - AtlasCore never aggregates SHEIN seller data across accounts for comparative insights or public display
d) Webhook security
Inbound SHEIN notifications at POST /api/v1/shein/webhooks/ are verified using HMAC-SHA256 (X-SHEIN-Signature) over the raw request body before timestamp checks and a bounded payload parse. HMAC is then strictly verified before any data persistence or dispatch. After disconnect, unlinked retention applies strictly to shein_processed_webhook_events replay identifiers — not to an inventory adjustment ledger. Unknown seller Open IDs are acknowledged with 200 to prevent platform retry storms.
See also SHEIN Data Handling and SHEIN Data Deletion Status.
16. Wish Merchant API Data Protection & Privacy Policy
This section describes how AtlasCore processes Wish Merchant API and webhook data when you connect a merchant account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by ContextLogic Inc. or its affiliates.
a) Encryption at rest
- Merchant OAuth access tokens, refresh tokens, and optional webhook secrets are stored using AES-256-GCM encryption at rest with the
enc:v1:format.merchant_idis stored as an operational identifier
b) 30-day order PII retention
Cached Wish orders store an allowlisted operational subset only. Buyer names, phones, emails, and shipping addresses are not persisted. Seller dashboard reads remain cache-only. Live server-side reads run strictly for seller-initiated sync (POST /sync/), health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment (SHIPPED / DELIVERED / CANCELLED / CANCELED / REFUNDED / FULFILLED / COMPLETED / COMPLETE / CLOSED) or 90 days unfulfilled. Fulfillment clocks are not reset on later syncs. Inventory writes require operator write approval.
c) Tenant isolation & data use restrictions
- Wish merchant data is isolated per authenticated user and enterprise workspace (accounts and settings) via the
X-Tenantheader. Unlinked retention after disconnect applies strictly towish_processed_webhook_eventsreplay identifiers — not an inventory adjustment ledger - AtlasCore never aggregates Wish merchant data across accounts for comparative insights or public display
d) Webhook security
Inbound Wish notifications at POST /api/v1/wish/webhooks/ are verified using HMAC-SHA256 (X-Wish-Signature) over the raw request body before timestamp freshness is accepted. After HMAC verification, a bounded payload parse extracts merchant_id for account binding. HMAC is authenticity proof; dispatch and deauth bind only when the verified merchant ID matches an active account whose stored secret matched (or the unique active merchant under the platform secret). HMAC is strictly verified before any data persistence or dispatch. Unknown or ambiguous merchant IDs are acknowledged with 200 to prevent platform retry storms.
See also Wish Data Handling and Wish Data Deletion Status.
17. Newegg Marketplace API Data Protection & Privacy Policy
This section describes how AtlasCore processes Newegg Marketplace API and webhook data when you connect a seller account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Newegg Inc. or its affiliates.
a) Encryption at rest
- Authorization Keys, Secret Keys, and optional webhook secrets are stored using AES-256-GCM encryption at rest with the
enc:v1:format.seller_idis stored as an operational identifier
b) 30-day order PII retention
Cached Newegg orders store an allowlisted operational subset only. Customer names, phones, emails, and ship-to/bill-to addresses are not persisted. Seller dashboard reads remain cache-only. Live server-side reads run strictly for seller-initiated sync (POST /sync/), health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment (SHIPPED / INVOICED / VOIDED / CANCELLED / CANCELED / CLOSED / COMPLETE / COMPLETED / DELIVERED / FULFILLED) or 90 days unfulfilled from native OrderDate. Fulfillment clocks are not reset on later syncs. GetInventoryRequest is used for read-only catalog and stock inquiries when item lookups are performed. UpdateInventoryRequest writes remain gated by NEWEGG_WRITE_APPROVED.
c) Tenant isolation & data use restrictions
- Newegg seller data is isolated per authenticated user — including connected accounts and settings. The
X-Tenantheader provides workspace partition when present - AtlasCore never aggregates Newegg seller data across accounts for comparative insights or public display
d) Webhook security
Inbound Newegg notifications at POST /api/v1/newegg/webhooks/ are verified using HMAC-SHA256 (X-Newegg-Signature) over the raw request body first. After HMAC verification, AtlasCore performs a bounded payload parse of seller_id for post-HMAC merchant binding. HMAC is strictly verified before any data persistence or dispatch. Unlinked replay-defense rows are retained only in newegg_processed_webhook_events. Unknown seller IDs are acknowledged with 200 to prevent platform retry storms.
See also Newegg Data Handling and Newegg Data Deletion Status.
18. Magento / Adobe Commerce API Data Protection & Privacy Policy
This section describes how AtlasCore processes Magento REST API and webhook data when you connect a store. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Adobe Inc. or its affiliates.
a) Encryption at rest
- Integration tokens, store URLs, and optional webhook secrets are stored using AES-256-GCM encryption at rest with the
enc:v1:format.store_hashis stored as an operational identifier. Integration Bearer tokens are the standard authentication mechanism. Optional admin credential exchange generates a session-scoped Magento admin token; AtlasCore stores only the resulting Bearer token and does not retain the admin username or password
b) 30-day order PII retention
Cached Magento orders store an allowlisted operational subset only. Customer names, emails, telephone numbers, and billing/shipping addresses are not persisted. Seller dashboard reads remain cache-only. Live server-side reads run strictly for seller-initiated sync (POST /sync/), health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment for case-insensitive terminal states COMPLETE, CLOSED, CANCELED, and CANCELLED (complete / closed / canceled). Magento holded orders remain on the 90-day unfulfilled clock, anchored to native Magento order created_at. Fulfillment clocks are not reset on later syncs. Inventory writes require operator write approval. Unlinked retention after disconnect applies strictly to magento_processed_webhook_events— there is no inventory adjustment ledger.
c) Tenant isolation & data use restrictions
- Magento store data is isolated per enterprise workspace via the
X-Tenantheader - AtlasCore never aggregates Magento store data across accounts for comparative insights or public display
d) Webhook security
Inbound Magento notifications at POST /api/v1/magento/webhooks/ are verified using the AtlasCore HMAC-SHA256 header standard (X-Magento-Signature) over the raw request body before timestamp freshness is evaluated. Merchant webhook secrets are authenticity checks over those same raw bytes; dispatch and deauthorization bind only to the verified MagentoAccount whose store ID matches the verified payload. A bounded payload is parsed only after HMAC authenticity succeeds. X-Tenant is ignored on webhook ingress. Unknown store URLs are acknowledged with 200 to prevent platform retry storms.
See also Magento Data Handling and Magento Data Deletion Status.
19. Oracle NetSuite Commerce API Data Protection & Privacy Policy
This section describes how AtlasCore processes NetSuite SuiteTalk REST API and webhook data when you connect an account. AtlasCore is an independent application and is not endorsed, certified, or sponsored by Oracle Corporation or its affiliates.
a) Encryption at rest
- TBA Consumer Key/Secret, Token ID/Secret, and optional webhook secrets are stored using AES-256-GCM encryption at rest with the
enc:v1:format.account_idis stored as an operational identifier
b) 30-day order PII retention
Cached NetSuite orders store an allowlisted operational subset only. Customer names, emails, telephone numbers, and billing/shipping addresses are not persisted. Seller dashboard reads remain cache-only. Live server-side reads run strictly for seller-initiated sync (POST /sync/), health checks, and credential validation. AtlasCore redacts cached order JSON after 30 days post-fulfillment (BILLED / CLOSED / CANCELED / CANCELLED; Billed / Closed / Cancelled) or 90 days unfulfilled, anchored to the native SuiteTalk tranDate / createdDate. Fulfillment clocks are not reset on later syncs. Inventory writes require operator write approval. Persistent 401/403 responses fail closed until the merchant reconnects.
c) Tenant isolation & data use restrictions
- NetSuite account data is isolated per enterprise workspace via the
X-Tenantheader - AtlasCore never aggregates NetSuite account data across accounts for comparative insights or public display
d) Webhook security
Inbound NetSuite notifications at POST /api/v1/netsuite/webhooks/ are verified using HMAC-SHA256 (X-NetSuite-Signature) over the raw request body before timestamp freshness is evaluated. A missing or invalid signature returns HTTP 401 immediately. If the platform signing secret does not match, AtlasCore may parse a bounded payload solely to extract account_id for per-account key resolution. HMAC is then strictly verified before any data persistence or dispatch. Webhook ingress ignores X-Tenant and binds to the verified realm. Unknown account IDs are acknowledged with 200 to prevent platform retry storms. Unlinked netsuite_processed_webhook_events rows (event ids only) are retained after disconnect.
See also NetSuite Data Handling and NetSuite Data Deletion Status.
20. Information We Collect
- Account data: name, email, authentication credentials, organization and team membership
- Marketplace connection data: OAuth tokens, refresh tokens, shop identifiers, and connection status for each linked marketplace
- Seller operational data: listings, orders, inventory, analytics, and sync metadata retrieved via marketplace APIs you authorize
- Technical data: IP address, device/browser type, session logs, and error diagnostics used for security and reliability
- Billing data: subscription status and payment references processed by our payment provider (we do not store full card numbers)
21. How We Use Information
We process data to:
- Authenticate you and provide dashboard features
- Sync and display marketplace data you request
- Maintain OAuth sessions and refresh tokens securely
- Provide support, security monitoring, and service improvements
- Comply with legal obligations and enforce our Terms
22. Third-Party Marketplace APIs
AtlasCore communicates with marketplace APIs only after you initiate a connection. Each platform receives the data necessary to authenticate and fulfill API requests under its own privacy and developer policies. We are not responsible for how marketplaces process data once transmitted to their systems. Disconnecting a marketplace stops new API calls using your stored tokens (see Disconnect Marketplace).
23. OAuth Token Handling
OAuth access and refresh tokens are stored using industry-standard protection mechanisms. Tokens are used solely to perform actions you authorize in the dashboard. You may revoke access at any time by disconnecting within AtlasCore or revoking the app in the marketplace's developer or account settings.
24. Data Sharing
We share data only with:
- Infrastructure providers that host and secure the service under contract
- Marketplace APIs you explicitly connect
- Law enforcement or regulators when required by valid legal process
We do not sell personal information.
25. Your Rights
Depending on your jurisdiction, you may request access, correction, export, or deletion of your personal data. See our Data & Retention Policy and Delete Account pages for details.
25. California Consumer Privacy Rights (CCPA / CPRA)
This section applies to California residents and supplements the rights described above under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
a) No sale or cross-context sharing
AtlasCore does not sell your personal information and does not share personal information for cross-context behavioral advertising. We do not disclose seller or buyer data to data brokers, ad networks, or unrelated third parties for their independent commercial purposes.
b) Categories of personal information
In the preceding 12 months we may have collected the categories described in Section 5 (account, marketplace connection, seller operational, technical, and billing data) solely to provide and secure the AtlasCore service you authorize.
c) Your California rights
Subject to applicable law and verification, California residents may request:
- Right to Know / Access: the categories and specific pieces of personal information we hold about you, and how we use and disclose it
- Right to Delete: erasure of personal information we collected from you, subject to legal exceptions
- Right to Correct: correction of inaccurate personal information in your account profile
- Right to Non-Discrimination: we will not deny goods or services, charge different prices, or provide a different level of service because you exercised your privacy rights
d) How to exercise your rights
- Self-service deletion: use Settings → Delete Account in the dashboard, or follow the steps on our Delete Account page
- Access / export: authenticated users may request a portable JSON export via
GET /api/v1/profile/export-datawhile signed in - Other requests: email privacy@atlascore-market.com from your registered account email. We verify identity before fulfilling requests and respond within 45 days (or as required by law)
Authorized agents may submit requests on your behalf with proof of authorization as required by California law. See also our Data & Retention Policy for retention schedules that apply after a deletion request.
26. International Transfers
Data may be processed in the United States or other regions where our subprocessors operate. We apply appropriate safeguards for cross-border transfers as required by applicable law.
27. Children
AtlasCore is intended for business users aged 18 and older. We do not knowingly collect data from children.
28. Contact
Privacy inquiries: privacy@atlascore-market.com.