Data Handling & Privacy Policy — SP-API Application

Data Handling & Privacy Policy — Ayurveda Hub SP-API Application

Owner: Elofyn Solutions Private Limited
Application: Ayurveda Hub SP-API (private / self-use)
Seller Account: Ayurveda Hub Official, Merchant ID AUSSTZ8JH5A5T, Amazon.in marketplace.
Last updated: 22 May 2026

1. Scope

This policy describes how the application collects, processes, stores, uses, shares, and disposes of Amazon Information, including any Personally Identifiable Information (PII) of Amazon buyers obtained through the Selling Partner API (SP-API).

2. Information Collected

The application retrieves the following data via the Selling Partner API:

  • Order metadata (Amazon Order ID, OrderStatus, ShipServiceLevel, EasyShipShipmentStatus, FulfillmentChannel, IsPrime, item information, pricing).
  • Easy Ship handover slot data and scheduled package status.
  • Tax invoice and shipping label PDFs generated by Amazon, which contain buyer name, shipping address, and phone number.

The application does not collect or persist payment instrument data, government identity numbers, or any data outside of what Amazon includes in the standard SP-API responses.

3. Processing

Data is processed strictly for the operational purposes stated in the application's role request:

  • Identifying unshipped Easy Ship orders.
  • Scheduling Easy Ship pickup slots via createScheduledPackage.
  • Retrieving and printing the shipping label and tax invoice for handover to the Amazon Easy Ship courier.
  • Generating GST-compliant tax invoices as required under CGST Rule 46.

No analytics, profiling, machine-learning training, or third-party enrichment of buyer data is performed.

4. Storage

  • Application configuration (LWA Client ID, Secret, Refresh Token) is stored in a .env file on a single Google Cloud Platform Compute Engine VM, with file permissions 600, encrypted at rest by GCP's default AES-256-XTS disk encryption with Google-managed keys.
  • Label and invoice PDFs are written to a server-side directory on the same VM, served only over TLS via Nginx behind an access-code-gated landing page.
  • Buyer PII is not persisted in any database. Order data is fetched on demand from the SP-API and discarded once the label has been generated.
  • All in-transit traffic to the SP-API uses TLS 1.2 or higher.

5. Use

Data is used only by the developer-owned application running on the production VM, for the purposes described in Section 3. No other applications, microservices, partners, or contractors have access.

6. Sharing

Amazon Information is not shared with any third party. The only outbound flow of buyer PII is the printing of the shipping label and tax invoice that is physically handed to the Amazon Easy Ship courier at pickup, as required by the Easy Ship workflow itself.

7. Retention and Disposal

  • Label and invoice PDFs are automatically purged from the VM 48 hours after generation.
  • Order PII pulled into memory for label generation is discarded as soon as the response is rendered (no on-disk caching).
  • Tax invoice archival required by CGST Rule 36(1) is handled separately as an encrypted archive outside the application's working storage.
  • LWA refresh tokens are rotated on developer change of role, suspected compromise, or at minimum every 365 days.

8. Buyer Rights

Buyer access, correction, and deletion requests are handled by Amazon at the marketplace level; the application does not maintain an independent buyer record outside the working storage described above.

9. Breach Notification

In the event of an incident involving buyer PII, the developer will: (1) immediately rotate the LWA refresh token, (2) take a forensic snapshot of the affected VM, (3) notify Amazon within the timeframe required by the Selling Partner API Acceptable Use Policy, and (4) notify the Indian CERT-In as required under the Information Technology Act, 2000.

10. Contact

Privacy queries: support@ayurvedahub.in