亚马逊 SP-API 应用服务声明
尊敬的亚马逊卖家,本声明旨在阐述我们作为亚马逊公共开发者,所提供的 SP-API 应用服务,并特别强调我们的费用政策、核心功能以及严格的数据安全与隐私保障。
开发者应用与服务介绍
我司开发的创新型亚马逊销售管理平台,深度集成亚马逊 Selling Partner API
(SP-API),旨在为亚马逊销售伙伴提供一站式、智能化运营解决方案。我们致力于利用大数据分析与人工智能技术,帮助单个卖家提升运营效率、优化销售业绩、降低成本,并实现业务的持续增长。
我们的核心功能涵盖以下方面:
1. 智能订单管理与履行 (Smart Order Management & Fulfillment)
a. 深度集成订单 API:我们高效获取并处理亚马逊订单详情(包括买家 PII,如买家姓名、收货地址、联系电话等)。这些 PII
将严格遵循亚马逊数据保护政策,加密处理后,用于准确的订单记录、生成货件、打印标签、全面的订单追踪、以及为授权用户提供客户服务支持。
b. 统一订单管理:无论是亚马逊 FBA 订单、卖家自发货订单,还是多渠道配送订单,平台都能实时同步与集中管理您(指单个卖家)的订单数据,确保其完整与准确。
c. AI 辅助的订单处理优化:
i. 异常订单识别:运用 AI 模型分析您(卖家)的订单数据,自动识别潜在的异常订单(如地址错误、高风险欺诈),及时预警,减少履约风险。
ii. 最优履约路径推荐:结合库存、物流成本和配送时效,为卖家自发货订单智能推荐最优发货方案,甚至自动化创建符合要求的货件。
d. 核心价值:极大提升订单处理效率,减少人工错误,确保订单履约的准确性和时效性,优化客户购物体验。
2. 全链路商品管理与智能刊登 (Comprehensive Product & Smart Listing Management)
a. 高效商品信息管理:支持批量创建、编辑和更新亚马逊商品列表 (Listing),包括价格、库存、商品描述、图片、关键词、实体信息等核心属性。
b. 商品类型定义 (PTD) 应用:我们利用 Product Type Definitions API 获取最新的商品类型定义(JSON
Schema),确保卖家刊登的产品属性符合亚马逊要求,大幅提升刊登成功率和准确性。
c. AI 辅助的刊登优化:
i. 智能文案生成与优化:基于大数据和 AI,辅助卖家生成吸引人的商品标题、五点描述和产品详情,优化关键词布局,提高搜索排名和转化率。
ii. 竞品分析与定价策略:通过分析公开市场上的同类商品数据,提供智能定价建议,帮助卖家制定更具竞争力的价格策略。
iii. 违规风险预警:自动识别刊登内容中可能存在的违规风险词汇或图片,提前预警并提供修改建议,降低 Listing 被移除或禁售的风险。
d. 核心价值:缩短商品上架周期,提升 Listing 质量和曝光度,增强商品竞争力。
数据管理与政策承诺
我司在此郑重承诺,我们严格遵守亚马逊的所有政策和规定,确保在使用亚马逊 Selling Partner API (SP-API)
时合法合规。我们深知保护数据安全和用户隐私的重要性,并且全面遵循亚马逊可接受使用政策(AUP)、数据保护政策(DPP)以及其他所有相关政策中的多项条款:
- 关于透明度(AUP 第 2.2 和 2.4
条):我们始终对授权用户保持透明,清晰准确地告知所访问亚马逊数据的类型、内容及具体用途。若涉及使用人工智能等模型进行数据分析、预测或辅助决策(例如,库存预测、销售趋势分析),我们会明确说明模型的使用目的、主要数据来源、核心计算方式和数据的效性,确保用户对我们提供的服务有清晰了解,实现数据使用方式的完全透明化。
- 关于法律法规遵守(AUP 第 2.5 条):我们承诺遵守所有适用的法律法规和行业标准,包括但不限于数据隐私和保护法规(如欧盟的《通用数据保护条例》
GDPR、中国的《网络安全法》等),在数据处理的各个环节严格遵循法律要求,充分保护用户的个人信息和业务数据安全。
- 关于数据收集最小化(AUP 第 3.8 条):我们仅收集通过亚马逊 SP-API
获得的、实现本应用功能和为授权用户提供服务所必需的数据。我们绝不会请求或获取任何超出此范围的信息,确保数据收集和使用的最小化原则,最大限度减少对用户隐私的影响。
- 关于数据聚合与共享限制(AUP 第 4.4 条):我们充分认识到保护亚马逊销售伙伴数据的重要性。我们郑重承诺,绝不会将通过亚马逊 SP-API
获取的数据进行跨授权用户业务或者客户范围的聚合,也不会将这些数据提供、销售或以任何形式分享给任何第三方,包括与本应用或授权用户存在竞争关系的实体。我们采取严格的技术和管理措施,确保数据使用范围严格限定在为授权用户自身业务服务的边界内,防止数据被不当利用或泄露,保障数据主体的合法权益和商业机密。
- 关于亚马逊业务见解保密(AUP 第 4.5 条):我们深刻理解亚马逊业务见解的敏感性和价值。我们承诺,不会推广、发布或分享任何从 SP-API
获取的关于亚马逊业务的见解、数据分析报告或其他内部信息,亦不将这些见解或数据用于本应用自身的业务运营、市场研究或任何非授权决策中,坚决维护亚马逊数据的保密性和完整性。
数据安全管理措施
在数据安全管理方面,我们采取多层级、全方位的技术与管理措施,确保数据的完整性、保密性和可用性,严格遵循亚马逊《漏洞管理》、《网络保护指南》、《关键安全控制指南》、《日志和监控》、《数据加密和恢复》、《事件响应》以及《敏感凭证保护》等所有相关安全政策和最佳实践:
- 严格的数据访问控制机制:我们建立了严格的数据访问控制机制,实施唯一身份识别、多因素认证(MFA),并遵循最小权限原则(Principle of Least
Privilege),确保只有经过授权且基于"需要知道"原则的人员才能访问相关数据,且每个员工只能访问履行职责所必需的最少数据。所有访问行为均被详细记录和审计,定期进行访问权限审查。
- 数据存储与加密:在数据存储方面,采用行业标准的强加密技术(例如
AES-256),确保数据在静态存储和动态传输过程中的安全性,防止未经授权的访问。所有数据存储于符合高安全标准的云服务环境中,具备强大的物理和网络安全防护。我们实施密钥管理策略,确保加密密钥的安全生成、存储、轮换和销毁。
- 数据分类和分级管理:我们对数据进行分类和分级管理,根据不同数据的重要性和敏感程度采取差异化的保护措施,同时定期对数据进行审查和清理,确保数据的准确性、完整性,并按政策进行及时删除。
- 数据备份与恢复:我们对亚马逊信息进行定期自动化备份或存档,并安全存储于加密的冷存储服务中,以防数据丢失或损坏。所有备份数据也采用 AES-256
加密。我们定期测试数据恢复流程,以确保在发生数据丢失事件时能够迅速、完整地恢复数据。
- 完善的数据安全事件应急响应计划:我们制定了完善的数据安全事件应急响应计划,拥有漏洞管理、渗透测试、代码安全审查、实时监控、异常行为检测及自动化威胁防护机制(如
WAF、IDS/IPS),以预防、识别并应对潜在安全威胁。一旦发生任何数据安全事件(如数据库入侵、未经授权访问、数据泄露),将立即启动应急响应流程,采取遏制、根除和恢复措施,并在 24
小时内立即按照亚马逊要求向其进行通报(通知至 sp-api-security@amazon.com),最大限度降低影响。我们定期进行安全演练和员工安全培训,提高全体人员的安全意识和响应能力。
- 网络保护措施:我们的应用部署在受保护的网络环境中,实施防火墙、入侵检测/防御系统(IDS/IPS),并采用网络分段来隔离不同安全级别的数据。所有与亚马逊 SP-API
的通信均通过加密的 TLS 1.2 或更高版本通道进行,确保数据传输的机密性和完整性。
- 敏感凭证保护:我们严格遵循亚马逊关于敏感凭证保护的指导方针。所有 API
凭证、密钥和其他敏感信息均采用强加密技术存储在安全的环境中,并实施严格的访问控制。我们禁止在代码库、配置文件或公开可访问的位置硬编码凭证。凭证的轮换和管理流程自动化且受严格审计。
个人识别信息(PII)保留与删除政策
PII 数据仅为实现订单履约目的而收集和保留。根据亚马逊的数据保护政策,在订单发货并交付成功后,我们将在不超过 30 天内安全地删除所有 PII
数据。若因法律法规强制要求需延长数据保留期,我们将对其进行加密并存储于安全合规的冷存储服务中,且仅在法律允许的范围内进行访问和使用。我们建立了严格的数据删除流程,确保 PII 数据被彻底、不可逆地销毁。
外部方共享亚马逊信息声明
我司不与任何外部方共享从亚马逊获取的个人识别信息(PII)数据。
对于我们的智慧物流追踪服务,我们可能会与选定的第三方物流追踪服务提供商共享非 PII 的订单信息(例如订单
ID、追踪号和承运商名称)。此共享通过安全的加密通道进行,且仅用于向授权用户提供实时的货代状态更新。所有此类数据共享均严格遵循最小权限原则,并仅限于实现应用功能所需,完全符合亚马逊的数据保护政策。我们与所有第三方服务提供商签订了严格的数据保护协议,确保他们同样遵守高标准的数据安全和隐私保护要求。
联系我们
如果您对我们的业务有任何疑问,欢迎随时通过官网联系方式与我们联系。我们期待为亚马逊卖家社区贡献力量,助力卖家在亚马逊平台上取得更大成功。
Amazon SP-API Application Service Statement
Dear Amazon Sellers, this statement outlines the SP-API application services we provide as an Amazon
Public Developer, with a particular emphasis on our pricing policy, core functionalities, and stringent
data security and privacy safeguards.
Application Pricing (Fees) Plan: Transparent, Flexible, with a 30-Day Free Trial
We offer a simple and transparent subscription model to help you manage your Amazon business efficiently
and worry-free.
Developer Application and Service Introduction
Our company has developed an innovative Amazon sales management platform, deeply integrated with the
Amazon Selling Partner API (SP-API), designed to provide Amazon selling partners with a one-stop,
intelligent operational solution. We are committed to leveraging big data analytics and artificial
intelligence technologies to help individual sellers improve operational efficiency,
optimize sales performance, reduce costs, and achieve continuous business growth.
Our core functionalities cover the following aspects:
1. Smart Order Management & Fulfillment
a. Deep Integration with Order APIs: We efficiently retrieve and process Amazon order
details (including buyer PII, such as buyer name, shipping address, and contact phone number). This PII
will be strictly handled in compliance with Amazon's Data Protection Policy, encrypted, and used for
accurate order records, shipment generation, label printing, comprehensive order tracking, and providing
customer service support to authorized users.
b. Unified Order Management: Whether it's Amazon FBA orders, seller-fulfilled orders, or
multi-channel fulfillment orders, the platform can synchronize and centrally manage your
(referring to a single seller's) order data, ensuring its completeness and accuracy.
c. AI-Assisted Order Processing Optimization:
i. Abnormal Order Identification: Utilizes AI models to analyze your (seller's)
order data, automatically identify potential abnormal orders (e.g., incorrect addresses,
high-risk fraud), provide timely warnings, and reduce fulfillment risks.
ii. Optimal Fulfillment Path Recommendation: Combines inventory, logistics costs, and
delivery timeliness to intelligently recommend the optimal shipping solution for seller-fulfilled
orders, even automating the creation of compliant shipments.
d. Core Value: Significantly improves order processing efficiency, reduces manual
errors, ensures the accuracy and timeliness of order fulfillment, and optimizes the customer shopping
experience.
2. Comprehensive Product & Smart Listing Management
a. Efficient Product Information Management: Supports bulk creation, editing, and
updating of Amazon product listings (Listing), including core attributes such as price, inventory,
product descriptions, images, keywords, and variation information.
b. Product Type Definition (PTD) Application: We leverage the Product Type Definitions
API to obtain the latest product type definitions (JSON Schema), ensuring that sellers' listed product
attributes comply with Amazon's requirements, thereby significantly improving listing success rates and
accuracy.
c. AI-Assisted Listing Optimization:
i. Intelligent Copywriting Generation & Optimization: Based on big data and AI, assists
sellers in generating engaging product titles, bullet points, and product details, optimizing keyword
placement to improve search rankings and conversion rates.
ii. Competitor Analysis & Pricing Strategy: By analyzing publicly available data
on similar products in the market, provides intelligent pricing suggestions to help sellers
formulate more competitive pricing strategies.
iii. Compliance Risk Warning: Automatically identifies potential compliance risk words
or images in listing content, provides early warnings, and offers modification suggestions to reduce the
risk of listings being removed or suppressed.
d. Core Value: Shortens product launch cycles, improves listing quality and visibility,
and enhances product competitiveness.
Data Management and Policy Commitment
We hereby solemnly commit that we strictly adhere to all Amazon policies and regulations, ensuring full
compliance when using the Amazon Selling Partner API (SP-API). We deeply understand the importance of
protecting data security and user privacy and fully comply with multiple clauses in Amazon's Acceptable
Use Policy (AUP), Data Protection Policy (DPP), and all other relevant policies:
- Regarding Transparency (AUP Sections 2.2 and 2.4): We always maintain transparency
with authorized users, clearly and accurately informing them about the type, content, and specific
use of the Amazon data accessed. If using AI or other models for data analysis, prediction, or
decision support (e.g., inventory forecasting, sales trend analysis), we will clearly explain the
model's purpose, main data sources, core calculation methods, and data recency, ensuring users have
a clear understanding of the services we provide and achieving full transparency in data usage.
- Regarding Legal and Regulatory Compliance (AUP Section 2.5): We commit to complying
with all applicable laws, regulations, and industry standards, including but not limited to data
privacy and protection regulations (such as the GDPR in the EU, the Cybersecurity Law in China,
etc.), strictly adhering to legal requirements at every stage of data processing to fully protect
users' personal information and business data security.
- Regarding Data Collection Minimization (AUP Section 3.8): We only collect data
obtained through the Amazon SP-API that is necessary to implement the functionalities of this
application and provide services to authorized users. We will never request or obtain any
information beyond this scope, ensuring the principle of data collection and use minimization to
maximally reduce the impact on user privacy.
- Regarding Data Aggregation and Sharing Restrictions (AUP Section 4.4): We fully
recognize the importance of protecting Amazon selling partner data. We solemnly commit that we will
never aggregate data obtained through the Amazon SP-API across authorized user businesses or
customer scopes, nor will we provide, sell, or share this data in any form with any
third party, including entities that compete with this application or authorized users. We adopt
strict technical and management measures to ensure that data usage is strictly limited to serving
the authorized user's own business, preventing improper use or leakage of data, and safeguarding the
legitimate rights and commercial secrets of data subjects.
- Regarding Amazon Business Insights Confidentiality (AUP Section 4.5): We deeply
understand the sensitivity and value of Amazon business insights. We commit that we will not
promote, publish, or share any insights, data analysis reports, or other internal information
obtained from the SP-API about Amazon's business, nor to use these insights or data for
our own application's business operations, market research, or any unauthorized decision-making,
resolutely maintaining the confidentiality and integrity of Amazon data.
Data Security Management Measures
In terms of data security management, we adopt multi-layered, comprehensive technical and management
measures to ensure the integrity, confidentiality, and availability of data, strictly adhering to
Amazon's policies and best practices regarding Vulnerability Management, Network Protection Guidance,
Key Security Controls Guidance, Logging and Monitoring, Data Encryption and Recovery, Incident Response,
and Safeguarding Sensitive Credentials:
- Strict Data Access Control Mechanisms: We have established strict data access
control mechanisms, implementing unique identification, multi-factor authentication (MFA), and
adhering to the Principle of Least Privilege, ensuring that only authorized personnel with a
"need-to-know" basis can access relevant data, and each employee can only access the minimum data
necessary to perform their duties. All access activities are meticulously logged and audited, with
regular reviews of access permissions.
- Data Storage and Encryption: For data storage, we employ industry-standard strong
encryption technologies (e.g., AES-256), ensuring the security of data during storage (at rest) and
transmission (in transit), preventing unauthorized access. All data is stored in cloud service
environments that meet high security standards, possessing robust physical and network security
protection. We implement a key management strategy to ensure the secure generation, storage,
rotation, and destruction of encryption keys.
- Data Classification and Tiered Management: We perform data classification and
tiered management, adopting differentiated protection measures based on the importance and
sensitivity of various data types. Concurrently, we regularly review and cleanse data to ensure its
accuracy, completeness, and timely deletion in accordance with policies.
- Data Backup and Recovery: We conduct regular automated backups or archiving of
Amazon information, securely storing it in encrypted cold storage services to prevent data loss or
corruption. All backup data is also encrypted with AES-256. We regularly test data recovery
processes to ensure prompt and complete data recovery in the event of data loss.
- Comprehensive Data Security Incident Response Plan: We have developed a
comprehensive data security incident response plan, incorporating vulnerability management,
penetration testing, code security reviews, real-time monitoring, anomaly detection, and automated
threat protection mechanisms (such as WAF, IDS/IPS) to prevent, identify, and respond to potential
security threats. In the event of any data security incident (e.g., database intrusion, unauthorized
access, data breach), we will immediately activate the incident response process, taking
containment, eradication, and recovery measures, and will immediately notify Amazon within 24 hours
as required (notification to sp-api-security@amazon.com), minimizing the impact. We regularly
conduct security drills and employee security training to enhance overall security awareness and
response capabilities.
- Network Protection Measures: Our application is deployed in a protected network
environment, implementing firewalls, intrusion detection/prevention systems (IDS/IPS), and utilizing
network segmentation to isolate data of different security levels. All communication with the Amazon
SP-API is conducted through encrypted TLS 1.2 or higher channels, ensuring the confidentiality and
integrity of data transmission.
- Safeguarding Sensitive Credentials: We strictly adhere to Amazon's guidelines for
safeguarding sensitive credentials. All API credentials, keys, and other sensitive information are
stored using strong encryption technologies in a secure environment, and strict access controls are
implemented. We prohibit hardcoding credentials in codebases, configuration files, or publicly
accessible locations. Credential rotation and management processes are automated and subject to
strict auditing.
Personally Identifiable Information (PII) Retention and Deletion Policy
PII data is collected and retained solely for the purpose of order fulfillment. In accordance with
Amazon's Data Protection Policy, all PII data will be securely deleted within 30 days after the order
has been shipped and successfully delivered. If extended data retention is mandated by legal or
regulatory requirements, the data will be encrypted and stored in a secure and compliant cold storage
service, accessed and used only within the bounds permitted by law. We have established strict data
deletion processes to ensure PII data is thoroughly and irreversibly destroyed.
Statement on Sharing Amazon Information with External Parties
Our company does not share Personally Identifiable Information (PII) obtained from Amazon with any
external parties.
For our smart logistics tracking service, we may share non-PII order information (e.g.,
order ID, tracking number, and carrier name) with selected third-party logistics tracking service
providers. This sharing occurs via secure encrypted channels and is solely for the purpose of providing
real-time shipment status updates to authorized users. All such data sharing strictly adheres to the
Principle of Least Privilege and is limited to what is necessary for the application's functionality,
fully complying with Amazon's Data Protection Policy. We have signed strict data protection agreements
with all third-party service providers to ensure they also adhere to high standards of data security and
privacy protection.
Contact Us
Should you have any questions about our business, please feel free to contact us via the contact
information on our official website. We look forward to contributing to the Amazon seller community and
helping sellers achieve greater success.