FREE SHIPPING WITHIN THE USA
30-Day Easy Returns 30-Day Easy Returns
Secure Checkout Guaranteed Secure Checkout Guaranteed
Free Shipping in USA Free Shipping in USA

Your Cart 0 Items

Shipping: Free
Sub Total: $0.00

Amazon Data Policy

Vilros Amazon Data Handling and Privacy Policy

Effective date: May 11, 2026 Owner: Vilros LLC Contact: privacy@vilros.com

This policy describes how Vilros LLC ("Vilros," "we," "our") collects, processes, stores, uses, shares, and disposes of information obtained from Amazon Selling Partner API ("SP-API") and the Amazon Seller Central account we operate as an Amazon Marketplace seller. This policy applies to all Amazon Information — including but not limited to order data, buyer Personally Identifiable Information (PII), product, inventory, financial, and performance data — that we receive from Amazon in connection with our seller account.

1. Scope and Purpose

Vilros is a private Amazon Marketplace seller. The data and integrations described in this policy support our own internal seller operations only. Vilros is not a software vendor, does not resell software or services, and does not provide an Amazon-connected application to any third party.

Amazon Information is used solely to:

  • Receive, manage, fulfill, ship, and support Amazon orders.
  • Maintain our Amazon product listings, pricing, and inventory.
  • Generate tax-compliant invoices where required by law or buyer request.
  • Communicate with Amazon buyers about their orders through Amazon's permitted channels.
  • Solicit buyer reviews through Amazon's official Request a Review mechanism, where eligible and within Amazon's permitted window.
  • Produce internal financial, merchandising, and inventory-forecasting reports for our own decision-making.
  • Comply with Amazon's seller policies and applicable law.

We do not use Amazon Information for any purpose unrelated to fulfilling the specific order or business obligation it pertains to.

2. Information We Collect

From Amazon SP-API and Seller Central we receive:

  • Order data: order ID, line items, SKUs, quantities, prices, taxes, fees, shipping method, order status, and timestamps.
  • Buyer PII (for orders we fulfill ourselves or invoice ourselves): buyer name, shipping address, billing address, email address (via Amazon's permitted messaging channels only), phone number where provided by Amazon, and tax identification number where the buyer supplies one for invoicing.
  • Product and listing data: our own listings, including titles, descriptions, attributes, images, pricing, inventory levels, and listing health status.
  • Inventory data: FBA inventory levels, inbound shipment status, and reserved/available counts per fulfillment center.
  • Financial data: settlement reports, fees, refunds, and order financial events.
  • Performance data: account health metrics, performance notifications, and policy compliance status.
  • Brand Analytics data: for products under our brand registration, search query performance, item comparison, demographics, repeat-purchase behavior, and market basket reports.

3. How Information Is Collected

Amazon Information is collected through:

  • Authenticated, encrypted (HTTPS / TLS 1.2 or higher) calls to Amazon's Selling Partner API.
  • Scheduled background jobs operated by Vilros that pull orders, listings, inventory, and reports at defined intervals.
  • Webhook and notification endpoints that receive Amazon-initiated updates, with payload signatures verified before processing.

No Amazon Information is collected through unofficial scraping, screen capture, or any method outside Amazon's published APIs and Seller Central interfaces.

4. How Information Is Processed

Amazon Information is processed within Vilros's private internal operations portal. Processing includes:

  • Routing orders to our warehouses for fulfillment based on internal allocation rules.
  • Generating pick lists, packing slips, shipping labels, and tax invoices.
  • Synchronizing inventory levels between warehouses and Amazon listings.
  • Computing per-product and per-channel profit and loss for internal reporting.
  • Forecasting demand and producing replenishment suggestions.
  • Routing buyer messages into our internal customer-service ticketing module for staff to respond through Amazon's messaging channels.

All processing occurs on servers operated by our infrastructure providers (Supabase and Vercel) on our behalf. We do not transmit Amazon Information to any analytics, advertising, profiling, or marketing platform.

5. How Information Is Stored

  • Database: Amazon Information is stored in a private PostgreSQL database hosted on Supabase. The database is encrypted at rest using AES-256 with keys managed by AWS Key Management Service (KMS).
  • File storage: documents generated from Amazon Information (PDF packing slips, shipping labels, tax invoices) are stored in private Supabase Storage buckets, encrypted at rest with AES-256 and access-controlled via row-level security.
  • In transit: all data movement uses TLS 1.2 or higher.
  • Logical separation: PII fields are isolated to specific tables and screens; staff access is gated by role-based access control and PostgreSQL Row-Level Security policies.
  • Backups: managed encrypted backups are maintained by our infrastructure providers per their standard policies.

6. How Information Is Used

Internally, Amazon Information is used only by authenticated Vilros employees acting in defined operational roles:

  • Owner / Admin: full access for account configuration, audit, and oversight.
  • Manager: access to orders, inventory, listings, financials, and analytics for operational decision-making.
  • Customer Service: access limited to orders relevant to active support cases, for the purpose of responding to buyer inquiries.
  • Shipper / Fulfillment: access limited to orders in the active fulfillment workflow, restricted to the fields needed to pick, pack, label, and ship the shipment.

All access to PII-bearing screens is logged in an append-only audit table.

Amazon Information is never used for:

  • Marketing, advertising, retargeting, or analytics outside of our internal Amazon performance review.
  • Profiling, scoring, or modeling buyer behavior beyond the aggregated reports Amazon provides through Brand Analytics.
  • Training third-party machine-learning models.
  • Sale, lease, or transfer to any third party.

7. How Information Is Shared

We share Amazon Information only with the following parties, only to the minimum extent necessary, and only for the specific purpose stated:

  • Supabase — managed database and storage infrastructure. Subprocessor. Encrypted at rest and in transit. No independent access to or use of the data.
  • Vercel — managed application hosting. Subprocessor. Amazon Information transits through Vercel during request handling but is not persisted on Vercel infrastructure.
  • Shipping carriers and rate-shopping aggregator (EasyPost or Shippo, with UPS, FedEx, USPS, DHL) — receive only the buyer name, shipping address, weight, and dimensions strictly required to generate a shipping label and tracking record for the specific shipment.
  • Vilros employees — authenticated, role-gated access through the internal portal, bound by our confidentiality and acceptable-use policy.

We do not share Amazon Information with:

  • Marketing, advertising, retargeting, or analytics platforms.
  • Data brokers, data resellers, or audience-building services.
  • Other ecommerce sellers, competitors, or marketplaces.
  • Public or social media platforms.
  • Any third party for any purpose unrelated to fulfilling, supporting, accounting for, or invoicing the specific Amazon order the information pertains to.

All subprocessors are contractually bound to data-protection terms requiring confidentiality, security, and purpose limitation equivalent to those applied in this policy.

8. How Information Is Disposed

  • Buyer PII is retained only as long as required to fulfill the order, support post-sale activity (returns, refunds, disputes), satisfy Amazon's record-keeping requirements, and meet applicable tax and accounting retention obligations. After the longest applicable retention period has elapsed, buyer PII is purged or irreversibly anonymized by automated jobs.
  • Order, financial, and inventory records are retained for the period required by applicable tax, accounting, and corporate-record law (generally seven years in the United States), after which they are purged or archived in anonymized form.
  • Document artifacts (shipping labels, packing slips, invoices) are retained per the same schedule and then deleted from storage.
  • Audit logs are retained for a minimum of one year and are append-only; they are not editable or selectively deletable.
  • Departing employees lose access to all Amazon Information the same day they leave the company. Their historical actions remain in the audit log.

9. Security Controls

  • Encryption at rest (AES-256, AWS KMS-managed keys) and in transit (TLS 1.2+).
  • PostgreSQL Row-Level Security enforced at the database layer in addition to UI-level role gating.
  • Multi-factor authentication required on all administrative consoles (Supabase, Vercel, GitHub, Amazon Seller Central) and on portal accounts with PII access.
  • Secrets stored in encrypted environment-variable stores; never in code, configuration files, or version control.
  • HMAC signature verification on all inbound webhooks.
  • Append-only audit logging of all PII access and all state-changing actions.
  • Anomaly alerts (failed authentication bursts, signature failures, abnormal access patterns) routed to a monitored internal channel.
  • Annual review of access lists, role assignments, and subprocessor relationships.

10. Incident Response

If we detect or are notified of a suspected security incident affecting Amazon Information:

  1. The implicated account or system is isolated immediately.
  2. The Owner conducts a scope assessment using audit logs.
  3. Affected parties are notified, and Amazon is notified through the channels and timelines required by Amazon's Data Protection Policy.
  4. Authorities are notified as required by applicable law.
  5. A written post-incident review is performed and remediation tracked to closure.

11. Employee Obligations

Every Vilros employee with access to Amazon Information has signed an acceptable-use and confidentiality policy that prohibits accessing Amazon Information from personal devices, copying it to removable media, photographing screens, forwarding it to personal accounts, or sharing it outside the company. Violation is grounds for termination.

12. Policy Updates

This policy is reviewed and updated at least annually and whenever a material change is made to how Amazon Information is collected, processed, stored, used, shared, or disposed. The effective date at the top of this document reflects the most recent update.

13. Contact

Questions about this policy or requests related to Amazon Information held by Vilros may be directed to:

Vilros LLC Email: privacy@vilros.com Website: https://vilros.com