This policy describes how Plug Seller protects information obtained through the Amazon Selling Partner API and Walmart APIs, in alignment with Amazon’s Acceptable Use Policy and Data Protection Policy and Walmart’s developer requirements.
Scope of data
“Marketplace Information” means any data we retrieve on your behalf from Amazon or Walmart, including product, pricing, listing, inventory, and order information, and any personally identifiable information (PII) contained in it.
Use limitation
- We use Marketplace Information solely to provide the Service to the seller it belongs to.
- We never sell Marketplace Information, and we never share it for advertising or any purpose unrelated to the Service.
- We retrieve only the data needed for the feature you are using.
- We do not request or access Amazon buyer personally identifiable information, and our integration does not use restricted roles.
Encryption
- In transit: all data is transmitted over TLS 1.2+.
- At rest: stored data is encrypted using industry-standard encryption (AES-256 or equivalent).
- API credentials and tokens are stored encrypted and never exposed to clients.
Access controls
- Access to Marketplace Information is restricted to authorized personnel on a least-privilege, need-to-know basis.
- Access is authenticated and logged; credentials are rotated and revoked when no longer needed.
Retention & deletion
We retain Marketplace Information only as long as needed to provide the Service and to meet legal obligations, and we delete PII within 30 days of a deletion request or when it is no longer required. See Data Deletion.
Incident response
We maintain an incident-response plan. In the event of a security incident affecting Marketplace Information, we will investigate and remediate promptly and notify affected parties and the relevant marketplace as required. For incidents involving Amazon Information, we will notify Amazon at security@amazon.com within 24 hours of detection.
Governance
We review access, logs, and security controls regularly and require all personnel to follow these practices.
Contact
Security or data-protection questions? Email support@plugakademi.org.
