Legal

Privacy Policy

How Inwizards handles Amazon Selling Partner API (SP-API) data. Amazon AUP & DPP compliant data handling.

Effective date: July 16, 2026  |  Last updated: July 16, 2026

Data controller / provider: Inwizards Software Technology Private Limited — info@inwizards.com

This Privacy Policy explains how Inwizards Software Technology Private Limited ("Inwizards", "we", "us") handles data obtained through the Amazon Selling Partner API (SP-API) in connection with the Amazon Connector for Odoo application. It applies to all Amazon Information the application accesses on behalf of an authorizing Amazon Selling Partner ("seller"). We comply with the Amazon Acceptable Use Policy (AUP) and the Amazon Data Protection Policy (DPP).

1. What data we collect

With the seller's authorization, the application may access the following categories of Amazon Information to deliver its features:

  • Order information — order IDs, items, quantities, prices, order and fulfillment status.
  • Buyer information (PII) — buyer name, shipping address, and, where provided by Amazon, contact details, used strictly for order fulfillment, shipping, invoicing, and permitted buyer communication.
  • Inventory & catalog data — product listings, SKUs, quantities, and pricing.
  • Fulfillment & shipping data — FBA/FBM shipment, tracking, returns, and removal data.
  • Financial & tax data — settlements, fees, and tax amounts for reconciliation and invoicing.

2. How we collect it

Amazon Information is collected only through authorized SP-API endpoints, after the seller grants explicit consent via Amazon's official authorization (Login with Amazon / OAuth) flow. We do not scrape Amazon, and we do not obtain Amazon Information from any external, third-party, or unauthorized source.

3. How we process and store it

The application runs in an Odoo environment — either the seller's own Odoo installation, or an Odoo environment operated by Inwizards on the seller's behalf as a hosted service. Where Inwizards operates the environment, it runs on a dedicated virtual private server under our sole control, with the database on a private network that is not reachable from the internet; the controls described in section 7 apply to that environment.

Amazon Information is processed to synchronize orders, inventory, listings, fulfillment, shipping, and tax records between Amazon and Odoo. Data is protected with TLS 1.2+ encryption in transit and encryption at rest. SP-API credentials (client secrets and refresh tokens) are encrypted with AES-256 at the application layer before being written to the database, are never displayed in the user interface, and are never hard-coded or stored in plaintext or public repositories. Encryption keys are held outside the database under restricted access, are never committed to source control, and are rotated at least annually.

4. How we use it

Amazon Information is used solely to provide the integration features the seller has enabled. We do not use Amazon Information for advertising, marketing, resale, model training, independent analytics, or any purpose other than the seller-authorized operation of the application.

Artificial intelligence and machine learning. Inwizards offers AI-based products under separate business lines. The Amazon Connector for Odoo is not one of them. The application uses no AI/ML systems — no in-house models, no third-party AI services, and no large language or generative AI models — to process, ingest, or interact with Amazon Information; all processing is deterministic, rule-based application logic. Amazon Information is never sent to any AI/ML service or model provider, and is never used to train, fine-tune, retrain, or otherwise improve any AI/ML model, by Inwizards or by any third party, nor pooled across customers for model improvement.

5. How we share it

We do not sell or share Amazon Information with third parties for their own use. Limited disclosure occurs only as strictly necessary to complete the seller's own operations — for example, providing a shipping address to the carrier selected to deliver that order. Any such processing is limited to what is required to fulfill the order and is subject to this policy. Our hosting provider and our edge security provider supply the underlying server and inbound traffic protection respectively; neither is granted access to Amazon Information for its own use, and both act solely as infrastructure service providers under contract. Amazon Information is never used by Inwizards for any independent purpose of its own.

6. Retention & disposal

Personally identifiable information (PII) is retained only as long as needed to provide the service, and no longer than 30 days after order delivery, except where a longer period is required by law and solely to comply with that legal obligation. When no longer required, PII is securely deleted using industry-standard secure-deletion procedures.

7. Security controls

  • Access control: role-based access control (RBAC) and least-privilege; access to Amazon Information limited to authorized personnel and logged.
  • Authentication: multi-factor authentication (MFA) enforced for privileged access; strong password requirements (minimum 12 characters, complexity, expiration, and account lockout).
  • Encryption: TLS 1.2+ in transit; AES-256 encryption of SP-API credentials at the application layer before storage, with keys held outside the database under restricted access; encryption at rest for stored data and for backups.
  • Network protection: a Web Application Firewall with OWASP protections, rate limiting, bot and brute-force protection, and DDoS mitigation in front of all public endpoints, covering both HTTPS and WebSocket traffic. The origin server accepts inbound web traffic only from our edge provider's address ranges, so these protections cannot be bypassed. The database is on a private network with no public port. Administrative access is by SSH key only from approved addresses. Endpoint protection with full-disk encryption is used on development and support systems.
  • Monitoring & logging: SP-API activity logged with timestamps and user identifiers, retained at least 12 months, with automated alerts for suspicious activity. No customer PII is stored in logs.
  • Secure development: code scanned before every release; vulnerability scans every 30 days; annual penetration testing; separate production and test environments; no real PII used in testing.

8. Seller & data-subject rights

Sellers may revoke the application's SP-API authorization at any time through Amazon Seller Central, which stops further data access. Sellers or their buyers may request access, correction, or deletion of personal data handled by the application by contacting us at info@inwizards.com. We honor deletion requests in accordance with Amazon's DPP and applicable law.

9. Security incidents

We maintain a documented incident response plan covering detection, containment, assessment, notification, remediation, and post-incident review. In the event of a confirmed security incident involving Amazon Information, we notify Amazon at security@amazon.com and affected sellers within 24 hours of detection.

10. Contact

Inwizards Software Technology Private Limited
Email: info@inwizards.com
Incident Management Point of Contact: Anuj Singh — anuj@inwizards.com. Reachable for any security incident such as data leakage or breach; incidents are acknowledged within 4 hours and Amazon is notified within 24 hours of any confirmed incident involving Amazon Information.

This policy is specific to Amazon SP-API data handling. It may be updated from time to time; the "Last updated" date above reflects the current version.

Contact

Questions about this policy?

Write to us — a real person answers, and we're happy to walk through how your data is handled.

Emailinfo@inwizards.com Incident contact — Anuj Singh · anuj@inwizards.com

Talk to us first

Questions about data handling, retention or your rights under this policy? Email us and we'll respond quickly.

Email Us

Incidents acknowledged within 4 hours