Data Protection Policy
How we protect data obtained through the Amazon Selling Partner API.
This policy describes how Shenzhen Lufeizhitong Technology Co., Ltd. ("we", "us") collects, uses, stores, protects,
retains and deletes data obtained through the Amazon Selling Partner API (SP-API) in the course
of providing the Lufeizhitong ERP service, and the organizational and technical measures we
implement to safeguard data security. This policy complies with Amazon Developer data protection requirements.
1. Scope and Definitions
This policy applies to all data we access, collect or process through Amazon SP-API, including but not limited to:
- Personally Identifiable Information (PII): buyer name, shipping address, phone number, email address, gift messages, etc.;
- Order Data: order IDs, purchased items, amounts, fulfillment status, etc.;
- Inventory Data: FBA/FBM inventory quantities, storage locations, etc.;
- Financial & Settlement Data: transaction details, platform fees, settlement reports, etc.;
- Report Data: various business reports requested and downloaded via SP-API;
- Authorization Credentials: OAuth refresh tokens and other access credentials.
This policy also applies to our employees, contractors, and any personnel with access to the above data.
2. Data Collection and Minimization
- We collect only the data fields strictly necessary to deliver product functionality — no excessive collection;
- We access seller data only after explicit authorization via Amazon OAuth 2.0; sellers may revoke authorization at any time in Seller Central;
- We do not collect buyer data unrelated to core functions such as order fulfillment, inventory management, or financial accounting;
- We do not use SP-API data for any purpose unrelated to providing services to sellers, including but not limited to marketing, profiling, selling, or re-sharing.
3. Data Storage and Encryption
- Encryption in Transit: All data transmissions (including communication with Amazon APIs) use TLS 1.2 or higher;
- Encryption at Rest: Stored sensitive data (including PII) is encrypted using AES-256;
- Key Management: Encryption keys are managed by a dedicated Key Management Service (KMS), stored separately from data, and rotated periodically;
- Storage Location: Data is stored in Alibaba Cloud data centers located in South China 1 (Shenzhen), with physical security protections.
4. Access Control
- We implement Role-Based Access Control (RBAC) following the principle of least privilege — employees access only the data necessary for their work;
- Access to production data requires Multi-Factor Authentication (MFA);
- All data access operations are recorded in complete audit logs, retained for at least 180 days and reviewed periodically;
- Access permissions are immediately revoked upon employee departure or role change.
5. Data Retention and Deletion
- We retain data only for the period necessary to fulfill the service purpose;
- Upon seller authorization revocation or service termination, we delete all SP-API data and credentials within 30 days;
- Expired data is destroyed via secure deletion methods (overwrite / cryptographic erasure), ensuring irrecoverability;
- Backup data follows the same retention and deletion policies and is purged synchronously upon expiry.
6. Third Parties and Sub-processors
We engage only the following categories of sub-processors, each bound by a Data Processing Agreement (DPA):
| Category | Sub-processor | Purpose |
|---|---|---|
| Cloud Infrastructure | Alibaba Cloud | Servers, databases, object storage |
| Key Management | Alibaba Cloud KMS (Key Management Service) | Encryption key custody |
| Monitoring & Alerting | Alibaba Cloud CloudMonitor | System availability and security monitoring |
- We do not sell, rent, or otherwise share SP-API data with any unrelated third party;
- Sub-processors access data only to the extent necessary to provide their services and are contractually bound to equivalent protection obligations;
- We will notify affected sellers in advance before adding new sub-processors.
7. Data Subject Rights
- We cooperate with Amazon and buyers in exercising data access, correction, and deletion rights as required by law;
- Upon receiving a data subject request forwarded by Amazon, we will respond and process it within the statutory timeframe;
- Sellers may submit data-related rights requests via zhanglvfeiztong@outlook.com.
8. Security Incident Response
- We maintain a comprehensive security incident response plan and conduct regular drills;
- In the event of an actual or suspected data breach, we will notify Amazon and affected sellers within 72 hours;
- Notifications will include the nature of the incident, scope of impact, and remediation measures taken and planned;
- Post-incident reviews are conducted to continuously improve security mechanisms.
9. Employee Confidentiality and Training
- All personnel with access to client data sign confidentiality agreements and assume confidentiality obligations;
- New employees must complete data security and compliance training upon onboarding; existing employees undergo annual refresher training;
- Violations of data security policies are handled strictly in accordance with company policies and applicable laws.
10. Policy Updates and Contact
We may revise this policy from time to time. Material changes will be announced prominently on this page with an updated "Last Updated" date. For any questions about this policy or to exercise data-related rights, please contact us:
- Data Protection Email: zhanglvfeiztong@outlook.com
- Phone: +86-188-0341-7177
- Address: Room 301, Building A7, Second Industrial Zone, Fuwei Community, Fuyong Subdistrict, Bao'an District, Shenzhen, Guangdong, China
This policy is also available in Chinese: 数据保护政策(中文版).