Amazon Data Protection & Acceptable Use
Mavenic is a seller-facing analytics application built on the Amazon Selling Partner API (SP-API). This page describes — precisely — what Amazon data Mavenic accesses, why, how it is protected, and when it is deleted. It reflects our obligations under Amazon's Acceptable Use Policy (AUP) and Data Protection Policy (DPP), and we treat it as binding on everyone at Wicom.
1. What we access, and why
Mavenic requests the minimum set of SP-API roles required to render the dashboards a seller sees in the product — nothing more:
| Data | Source | Purpose in Mavenic |
|---|---|---|
| Order data (non-PII) | Orders API | Order feed with statuses (pending, shipped, delivered, refunded), order totals, and SKU-level line items for the order dashboard and sales metrics. |
| Inventory levels | FBA Inventory API | Available and inbound FBA stock per SKU, powering stock dashboards, days-of-cover forecasts, and restock alerts. |
| Sales & traffic reports | Reports API | Aggregated sales and traffic figures used to compute total sales and the organic vs ad-attributed split. |
| Catalog details | Catalog Items API | Product titles and images, used only to label the seller's own products in the interface. |
2. What we deliberately do not access
- No buyer personal information. We do not request buyer names, shipping addresses, email addresses, or phone numbers, and we do not use Amazon's Restricted Data Token mechanism. Mavenic's analytics are computed entirely from non-PII data.
- No buyer-seller messaging content or contact tools.
- No payment or financial instruments belonging to buyers.
- No write access to listings, prices, or fulfillment — Mavenic reads, it does not change your account.
3. Our commitments under Amazon's policies
- Purpose limitation. Amazon data is used solely to provide the Mavenic dashboard and alerts to the authorized seller who connected the account — never for any other purpose.
- No customer targeting. We never use data obtained through Amazon APIs to market to Amazon customers, to solicit, purchase, or manipulate reviews, or to contact buyers off-platform.
- No data brokering. We do not sell, rent, license, or otherwise disclose Amazon data to third parties, and we do not use or promote services that do.
- No cross-account aggregation. Data from one seller's account is never combined with another's — not for benchmarks, not for "market insights," not for internal research. Each workspace is logically isolated.
- Confidentiality of business insights. Insights derived from a seller's Amazon business remain that seller's. They are never used to advantage any other business, including Wicom's own retail brands, which run in fully separate workspaces under the same rules as any customer.
- No model training. Amazon data is not used to train machine-learning models or any generalized product feature.
4. Security controls
- Encryption in transit: all connections — browser to Mavenic, Mavenic to Amazon — use TLS 1.2 or higher.
- Encryption at rest: databases and backups are encrypted with AES-256.
- Credential protection: Login with Amazon (LWA) tokens and API credentials are stored encrypted, rotated per Amazon's token lifecycle, and never written to logs.
- Least privilege: production access is restricted to named engineers with a need, protected by multi-factor authentication, logged, and reviewed quarterly.
- Environment separation: development and testing environments never contain production Amazon data.
- Monitoring: API activity and administrative access are logged and retained for audit.
5. Retention & deletion
- Synced Amazon data is retained only while the seller's connection is active, to power historical dashboards the seller sees.
- When a seller disconnects Mavenic (from the product or from Seller Central → Manage Your Apps) or closes their account, synced Amazon data is purged within 30 days, including from backups on their rotation cycle.
- Sellers may request immediate deletion at any time by emailing privacy@mavenic.co — we confirm completion in writing.
6. Incident response
If we confirm a security incident affecting Amazon Information, we will notify Amazon at security@amazon.com within 24 hours of confirmation, notify affected sellers without undue delay, and cooperate fully with Amazon's investigation — including remediation steps and a root-cause report.
7. Subprocessors
Mavenic runs on reputable cloud infrastructure providers under data processing agreements. Subprocessors host and process data on our instruction only; they receive no rights to use Amazon data for their own purposes. A current list is available on request.
8. Questions
Security or compliance questions — including from Amazon — are welcome at security@mavenic.co or contact@wicom.asia.
Wicom Joint Stock Company
101 Lang Ha Street, Dong Da, Ha Noi, Vietnam