How Inwizards handles Amazon Selling Partner API (SP-API) data
This Privacy Policy explains how Inwizards Software Technology Private Limited ("Inwizards", "we", "us") handles data obtained through the Amazon Selling Partner API (SP-API) in connection with the Amazon Connector for Odoo application. It applies to all Amazon Information the application accesses on behalf of an authorizing Amazon Selling Partner ("seller"). We comply with the Amazon Acceptable Use Policy (AUP) and the Amazon Data Protection Policy (DPP).
With the seller's authorization, the application may access the following categories of Amazon Information to deliver its features:
Amazon Information is collected only through authorized SP-API endpoints, after the seller grants explicit consent via Amazon's official authorization (Login with Amazon / OAuth) flow. We do not scrape Amazon, and we do not obtain Amazon Information from any external, third-party, or unauthorized source.
The application runs in an Odoo environment — either the seller's own Odoo installation, or an Odoo environment operated by Inwizards on the seller's behalf as a hosted service. Where Inwizards operates the environment, it runs on a dedicated virtual private server under our sole control, with the database on a private network that is not reachable from the internet; the controls described in section 7 apply to that environment.
Amazon Information is processed to synchronize orders, inventory, listings, fulfillment, shipping, and tax records between Amazon and Odoo. Data is protected with TLS 1.2+ encryption in transit and encryption at rest. SP-API credentials (client secrets and refresh tokens) are encrypted with AES-256 at the application layer before being written to the database, are never displayed in the user interface, and are never hard-coded or stored in plaintext or public repositories. Encryption keys are held outside the database under restricted access, are never committed to source control, and are rotated at least annually.
Amazon Information is used solely to provide the integration features the seller has enabled. We do not use Amazon Information for advertising, marketing, resale, model training, independent analytics, or any purpose other than the seller-authorized operation of the application.
Artificial intelligence and machine learning. Inwizards offers AI-based products under separate business lines. The Amazon Connector for Odoo is not one of them. The application uses no AI/ML systems — no in-house models, no third-party AI services, and no large language or generative AI models — to process, ingest, or interact with Amazon Information; all processing is deterministic, rule-based application logic. Amazon Information is never sent to any AI/ML service or model provider, and is never used to train, fine-tune, retrain, or otherwise improve any AI/ML model, by Inwizards or by any third party, nor pooled across customers for model improvement.
We do not sell or share Amazon Information with third parties for their own use. Limited disclosure occurs only as strictly necessary to complete the seller's own operations — for example, providing a shipping address to the carrier selected to deliver that order. Any such processing is limited to what is required to fulfill the order and is subject to this policy. Our hosting provider and our edge security provider supply the underlying server and inbound traffic protection respectively; neither is granted access to Amazon Information for its own use, and both act solely as infrastructure service providers under contract. Amazon Information is never used by Inwizards for any independent purpose of its own.
Personally identifiable information (PII) is retained only as long as needed to provide the service, and no longer than 30 days after order delivery, except where a longer period is required by law and solely to comply with that legal obligation. When no longer required, PII is securely deleted using industry-standard secure-deletion procedures.
Sellers may revoke the application's SP-API authorization at any time through Amazon Seller Central, which stops further data access. Sellers or their buyers may request access, correction, or deletion of personal data handled by the application by contacting us at info@inwizards.com. We honor deletion requests in accordance with Amazon's DPP and applicable law.
We maintain a documented incident response plan covering detection, containment, assessment, notification, remediation, and post-incident review. In the event of a confirmed security incident involving Amazon Information, we notify Amazon at security@amazon.com and affected sellers within 24 hours of detection.
Inwizards Software Technology Private Limited
Email: info@inwizards.com
Incident Management Point of Contact: Anuj Singh — anuj@inwizards.com. Reachable for any security incident such as data leakage or breach; incidents are acknowledged within 4 hours and Amazon is notified within 24 hours of any confirmed incident involving Amazon Information.