1. Scope
This policy applies to website visitors, prospective business customers, authorized users, and sellers who may connect an Amazon account to VastSell in the future. Amazon’s own processing is governed by Amazon’s policies.
2. Information we collect
We receive business contact details and emails you send us. This public website has no account-registration or contact-form database. Authorized seller workflows may process account identifiers, listings, orders, inventory, fulfillment and advertising metrics only as required by enabled features. The initial public SP-API application excludes restricted buyer personal information and Restricted Data Tokens (RDT); buyer names, phone numbers and shipping addresses are outside this initial scope.
3. How we use information
We use information to respond to demo requests, operate and secure the service, provide seller-selected workflows, diagnose errors, meet legal obligations, and investigate security incidents. We do not sell Amazon Information or use it for unrelated advertising or profiling.
4. Authorization and access
Amazon connections require explicit seller authorization through Amazon OAuth. SP-API production access remains subject to Amazon approval and is not represented as available by this website. Ads authorization is separate from SP-API authorization. Permissions are limited to the approved, enabled workflows; account passwords must never be sent to VastSell. Users can revoke an active connection in Amazon's authorization management.
5. Storage and cross-border transfer
Our hosting provider is Alibaba Cloud in China. Information relating to users in the United States or Canada may therefore be transferred to and stored in China. The applicable hosting region, processing scope and transfer safeguards will be specified in the customer agreement before onboarding. This website does not imply approval for cross-border processing of restricted Amazon buyer information.
6. Security
The ERP implements HTTPS transport protection, encrypted integration credentials, multi-factor authentication, server-side role checks and tenant isolation. Access is limited by business need. These controls do not constitute a claim that every stored dataset or backup is encrypted, or that all future SP-API workflows have passed security validation. Storage encryption, retention, incident response and recovery controls must be verified for the relevant service before expanding its data scope.
7. Sharing
We may use infrastructure, monitoring, email, support, security, and professional service providers only as needed to operate the service. They must process information under appropriate confidentiality and security obligations. We may disclose information when legally required.
8. Retention and deletion
We retain information only as necessary for an authorized feature, contract, security need or legal obligation. After revocation or a verified deletion request, we assess and delete or irreversibly de-identify information no longer required. We explain any necessary retention and the applicable completion timeline to the requester. Backup copies expire through controlled rotation; any restored copy must remain subject to the deletion request. A feature-specific retention schedule is required before expanding production data processing.
9. Your choices
Email admin@vastsell.com to request access, correction or deletion. See our data deletion process. Sellers can revoke an active Amazon authorization through Amazon's authorization management.
10. Contact
Privacy inquiries: admin@vastsell.com · Company: 上海瀚峰准成科技有限公司 · Website: https://vastsell.com