Amazon Data Handling Policy
What we do with the Amazon order data you bring in, and every safeguard around it — written to the strictest bar we are held to.
What this page is. It describes how Arub collects, processes, stores, uses, shares and disposes of information obtained from Amazon through the Amazon Selling Partner API (SP-API), in line with the Amazon Data Protection Policy and the Acceptable Use Policy. It supplements, and does not replace, our organisation-wide Information Security Policy and our Privacy Policy. Amazon Information is kept logically separate from every other sales channel and is used for one thing only: fulfilling the order it belongs to.
1. Who we are
Arub is order, shipping and listing software operated by Arub, Inc., a Florida corporation (“Arub”, “we”, “us”). We run a multi-marketplace order-fulfilment business selling custom wood signage and related products. We access Amazon Information solely to fulfil orders placed by buyers on our Amazon storefront. Amazon Information is kept logically segregated and is never combined with, or used for the benefit of, any other sales channel.
Contact for privacy and security matters: privacy@arub.com for data and deletion requests, security@arub.com for security reports. Postal: Arub, Inc., 18741 Titus Road, Hudson, FL 34667, United States. The policy owner is Ownership / Operations, acting as Information Security Lead.
2. What Amazon data we collect and why
We collect only the minimum Amazon Information required to fulfil an order. This may include buyer name, shipping address, order and item details, and order identifiers, retrieved through authorised SP-API operations (for example, the order and order-address endpoints). We do not request or retain Amazon Information beyond what a specific order requires.
3. How the data flows
Amazon Information flows in a single, contained direction:
- Orders are retrieved from Amazon over an encrypted connection (TLS 1.2 or higher).
- Order data passes to our internal fulfilment application on a single-tenant server under our exclusive control.
- Recipient details are used to obtain shipping rates and generate carrier-compliant shipping labels.
- Tracking numbers and shipment confirmations are uploaded back to Amazon to complete the order.
No Amazon Information is processed by, or transmitted to, any system outside this fulfilment path.
4. Where it is held and how it is secured
Amazon Information containing personally identifiable information (PII) is stored on a privately hosted, single-tenant Linux server under our exclusive control. It is not stored on personal devices, external media, unsecured cloud applications, or public repositories.
- Encryption at rest. Amazon PII is encrypted at rest on servers, databases and storage.
- Encryption in transit. All transfers of Amazon Information use TLS 1.2 or higher; administrative access uses SSH-2 / SFTP.
- Access controls. The database is bound to localhost and is not remotely accessible. Access to Amazon Information is granted on a least-privilege, need-to-know basis, with unique per-user accounts and multi-factor authentication for systems handling Amazon data.
- Credential protection. SP-API credentials are stored encrypted, never in plaintext, application code or public repositories.
- Backups. Backups that contain personal or sensitive data are encrypted.
5. The only purposes we use it for
Amazon Information is used strictly and exclusively to fulfil the specific order to which it relates: retrieving eligible shipping rates, generating shipping labels with carrier-compliant recipient details, and confirming shipment with tracking. Amazon Information is never used for marketing, advertising, customer profiling, market research, resale, model training, or any purpose beyond fulfilment of the order to which it relates.
6. Who receives the data
Amazon PII is shared only with authorised logistics carriers, and only the recipient details necessary for physical delivery, for the sole purpose of delivering the order. Our carriers are USPS, UPS and FedEx. No other third parties, data processors, sub-processors, analytics providers or advertisers receive Amazon Information. Amazon Information is never sold, licensed or disclosed for any non-fulfilment purpose.
7. How and when it is deleted
We collect and retain only the Amazon PII needed to fulfil orders. In line with Amazon's requirement, order-related PII is retained no longer than 30 days after order fulfilment unless retention is required by law. When Amazon PII is no longer needed, it is securely deleted or de-identified. Amazon PII is not stored on removable media or personal / unmanaged devices, and no indefinite PII archives are maintained.
8. Security incident notification
We log and monitor system and application activity for suspicious behaviour — such as repeated failed logins, unusual access patterns or abnormal request volumes — and investigate triggered alarms under our documented incident response process. We investigate, contain and remediate incidents, revoke affected access, and preserve relevant logs.
In the event of a confirmed or suspected security incident affecting Amazon Information, we notify Amazon at 3p-security@amazon.com within 24 hours of detection, and notify affected individuals, marketplaces and authorities as required by applicable law and platform terms.
9. Changes to this policy
We review this policy at least every six months and after any major change to our systems or controls. Material changes will be reflected in the “Last updated” date at the top of this page.
Questions about how we handle Amazon data
If a reviewer or a seller needs anything this page does not answer, a person will reply — not a queue.