Security & Compliance
SellerFeeInspector adopts technical and organizational measures to protect Amazon sellers' data, in compliance with the Amazon Data Protection Policy and the GDPR.
Data Security
Technical protection
- Communications protected by an encrypted HTTPS connection (TLS 1.3).
- SP-API tokens are encrypted at rest with
Fernet (AES-128 CBC + HMAC). - Data is stored on private OVH VPS servers located in the EU, with periodic backups and regular updates.
- Data access restricted exclusively to the company's internal technical staff.
- Secure login with brute-force protection (rate limiting, logging of failed attempts).
- Application audit logs to monitor access and relevant operations.
- Restrictive CSP policy to limit content from unauthorized external sources.
Organization & Policies
- Compliance with the Amazon Selling Partner API Data Protection Policies.
- Full compliance with the GDPR for all personal data processing.
- Limited retention: Amazon reports are deleted automatically after processing, unless the user explicitly needs them.
- Incident management: in case of a personal data breach, an internal procedure is triggered with notification to the Data Protection Authority and to users within 72h.
- Refresh tokens and sensitive data are accessible only through server-side authentication and internal logging.
- User data is not shared with external third parties for commercial purposes.
More details on the processing of personal data are available in our Privacy Policy.
SellerFeeInspector is an independent application and is not affiliated with Amazon. Amazon is a registered trademark of Amazon.com, Inc. and its affiliates.