Language / 언어

Amazon SP-API Data Protection and Handling Policy

Organization: Evenus  |  Website: goldenrod.co.kr  |  Last updated: 2026-04-28

This policy describes how Evenus collects, processes, stores, uses, shares, protects, and disposes of Amazon Information obtained through Amazon Selling Partner API (“SP-API”). Evenus uses Amazon Information only for its own seller operations, order fulfillment, Korean export declarations, K-Packet shipping, and legal or tax compliance. Amazon Information is not used for marketing, advertising, profiling, resale, unrelated analytics, or any purpose unrelated to fulfillment and statutory compliance.

1. Scope and Purpose

Evenus operates a private, in-house fulfillment automation system for its own Amazon seller account. The system uses SP-API data only to process customer orders, generate required Korean export declaration data, create Korea Post K-Packet shipping labels, update shipment status, and maintain legally required non-PII business records.

The application is not offered to other sellers, and Amazon Information is not sold, rented, disclosed for marketing, used for customer profiling, or used to train AI or machine learning models.

2. Amazon Information Collected

Evenus collects only the minimum Amazon Information required for fulfillment and compliance. Depending on the order and marketplace requirements, this may include:

  • Amazon order identifier, marketplace, SKU, quantity, and order status.
  • Recipient name, shipping address, and phone number when provided and required for delivery.
  • Shipping service requirements, tracking number, and shipment confirmation data.
  • Information required to prepare Korean export declarations and shipping labels.

Recipient name, shipping address, phone number, and any files containing those values are classified as restricted Amazon PII.

3. Collection Source

Amazon Information is collected only from official Amazon systems authorized for Evenus’s seller account, including SP-API and Seller Central where applicable. Evenus does not retrieve, purchase, scrape, or receive Amazon Information from non-Amazon data brokers, aggregators, unauthorized third parties, or external sources.

4. System Architecture and Data Flow

Evenus uses a Cloudflare and Google Cloud based architecture designed to separate public access controls, application processing, encryption, storage, logging, and operational workflow management.

Identity and Access

  • Google Workspace is used for the named administrator account.
  • Security-key MFA is enforced.
  • Cloudflare Access is connected to Google Workspace as the identity provider.
  • Only the named administrator account and enrolled company Windows device are allowed.

Endpoint Protection

  • Microsoft Intune manages the company Windows endpoint.
  • Microsoft Defender for Endpoint provides EDR and device control.
  • Microsoft Purview Endpoint DLP blocks unauthorized local export, copy/paste, USB storage, and personal cloud upload.

Edge and API Protection

  • Cloudflare WAF, API Shield, Access, Gateway, Rate Limiting, and Bot/DDoS protection restrict public access.
  • mTLS and Cloudflare service tokens are used to protect backend routes.
  • Cloudflare Workers perform edge validation, request routing, and PII-redacted logging.

Application and Storage

  • Google Cloud Run operates the SP-API middleware and fulfillment automation backend.
  • Google Cloud KMS manages encryption keys.
  • Google Secret Manager stores API credentials and secrets.
  • Google Firestore stores Amazon PII only as ciphertext.
  • Google Cloud Storage stores encrypted files, backups, and log archives.
  • Airtable stores only non-PII workflow status and operational metadata.

5. Processing Activities

When an Amazon order is ready for fulfillment, the backend retrieves the minimum order data required from SP-API. Amazon PII is immediately separated from non-PII operational data, classified as restricted data, and encrypted before storage.

PII is decrypted only in memory by the authorized Google Cloud Run runtime process for the limited purpose of preparing and transmitting export declaration data to uTradeHub/KTNET and shipping data to Korea Post K-Packet over encrypted connections.

Plaintext PII is not made available in Airtable or general workflow tools. In rare fulfillment exception cases, the named administrator may access only the minimum necessary PII through a Cloudflare Access-protected internal console from the enrolled company Windows device. Such access is time-limited, logged, reviewed, and used only to complete shipment or export compliance.

6. Encryption and Key Management

Amazon PII is encrypted before storage using field-level AES-256-GCM encryption. Encryption keys are managed in Google Cloud KMS. Key access is limited to authorized service accounts, and key usage is logged and reviewed. Keys are inventoried, access is restricted by least privilege, and keys are rotated at least annually or immediately upon suspected exposure.

Plaintext encryption keys, SP-API credentials, refresh tokens, uTradeHub credentials, and K-Packet credentials are never stored in source code, Airtable, logs, local files, or unmanaged spreadsheets. Application secrets are stored in Google Secret Manager and accessed only by approved runtime service accounts.

Amazon SP-API credentials, including LWA client secrets and related application credentials, are inventoried and rotated at least annually or immediately upon suspected exposure, personnel change, or abnormal access.

7. Storage and Data Segregation

Google Firestore is the primary operational storage for Amazon PII ciphertext. Firestore access is restricted by Google Cloud IAM to approved Cloud Run service accounts. Firestore is not publicly exposed.

Google Cloud Storage is used for encrypted shipping labels, export declaration files, backups, and log archives. Buckets are private, public access is disabled, and access is limited by IAM.

Airtable is not used as an Amazon PII database. Airtable stores only non-PII workflow status such as internal order key, masked or hashed order reference, production stage, export declaration status, K-Packet status, tracking registration status, error code, retry count, and processing timestamp.

8. Use of Amazon Information

Amazon Information is used only for:

  • Order fulfillment for Evenus’s own Amazon seller account.
  • Preparation and submission of Korean export declarations through uTradeHub/KTNET.
  • Creation of Korea Post K-Packet shipping labels and tracking information.
  • Shipment confirmation and tracking update to Amazon.
  • Legal, tax, audit, and regulatory compliance where required.

Amazon Information is not used for marketing, advertising, unrelated analytics, customer profiling, resale, or any purpose unrelated to fulfillment and compliance.

9. Sharing and Approved Subprocessors

Evenus shares Amazon Information only with parties required to host, secure, process, and fulfill orders. Data is shared only over encrypted connections, using TLS 1.2 or higher where applicable, and only the minimum fields required for each purpose are transmitted.

  • Cloudflare: edge security, WAF, Access, Gateway, Workers, WARP, routing, and log delivery.
  • Google Workspace: administrator identity, account management, and MFA.
  • Google Cloud: Cloud Run, Cloud KMS, Secret Manager, Firestore, Cloud Storage, BigQuery, Cloud Logging, and Security Operations.
  • Microsoft Endpoint Security: Intune, Defender for Endpoint, and Purview Endpoint DLP for endpoint security, USB control, EDR, and DLP.
  • Airtable: non-PII workflow status, masked or hashed order references, production status, export status, K-Packet status, retry count, and operational metadata only. Airtable is not used to store plaintext Amazon PII.
  • Korea Post K-Packet: generation of international shipping labels and tracking.
  • uTradeHub/KTNET and Korean customs-related systems: preparation and submission of required export declaration data.

Evenus does not share Amazon Information with marketing agencies, advertising platforms, analytics resellers, data brokers, or unauthorized third parties.

10. Access Control and Need-to-Know

Amazon Information access is limited to one named administrator using a unique, non-shared Google Workspace account with security-key MFA. Cloudflare Access allows access only from the approved account and enrolled company Windows device.

Access is granted on a least-privilege and need-to-know basis, approved by the Incident Management Point of Contact (“IMPOC”), reviewed quarterly, centrally logged, and removed within 24 hours when no longer required. Service accounts are separate from human accounts, scoped to specific functions, inventoried, and rotated.

11. Personal Device, USB, and Data Loss Prevention Controls

Amazon Information may be accessed only from the enrolled company Windows endpoint. Cloudflare WARP device posture checks block unmanaged devices and cellphones. Microsoft Intune, Microsoft Defender Device Control, and Microsoft Purview Endpoint DLP block USB mass storage, unauthorized local export, copy/paste to unmanaged applications, and personal cloud uploads.

Security events such as USB insertion, file-copy attempts, export attempts, unauthorized device access, unauthorized IP access, failed login attempts, and abnormal data access are logged and alert the IMPOC for investigation.

12. Logging, Monitoring, and Alerting

Security and operational logs are centralized, PII-redacted where possible, and retained for at least 12 months. Cloudflare Logpush sends WAF, Access, Gateway, Workers, and WARP logs to Google Cloud Storage for retention and to BigQuery or Google Security Operations for search, dashboards, alerting, and incident investigation.

Google Cloud Logging and Audit Logs record Cloud Run activity, KMS key usage, Secret Manager access, Firestore read/write activity, Cloud Storage access, and IAM administrative activity. Logs are reviewed at least bi-weekly and alerts are configured for suspicious activity.

Logs must not contain recipient names, full addresses, phone numbers, email addresses, SP-API tokens, refresh tokens, KMS key material, shipping label contents, or export declaration contents.

13. Backups and Recovery

Backups containing Amazon Information are encrypted, access-controlled, and stored in Google Cloud Storage with restricted IAM permissions. Backups follow the same retention and deletion rules as production data. Restore procedures are documented, and recovery testing is performed at least quarterly.

Long-term records are limited to anonymized, masked, or legally required non-PII business records. Amazon PII is not retained in long-term archives except where legally required and only for the legally required purpose.

14. Retention and Disposal

Amazon PII is retained only as long as necessary for order fulfillment, export declaration, shipping label generation, shipment confirmation, and legally required compliance activities. Unless a longer period is legally required, Amazon PII is deleted from production systems and backups no later than 30 days after delivery.

A scheduled deletion job reviews records with expired retention dates and removes Amazon PII ciphertext from Firestore, PII-containing files from Cloud Storage, object versions, backup snapshots, and temporary processing files. Airtable retains only non-PII operational status and masked or hashed references.

Non-PII Amazon Information, including masked or hashed order references and workflow metadata derived from Amazon orders, is retained only as needed for operational, accounting, audit, and compliance purposes and is not retained longer than 18 months unless a longer retention period is legally required.

15. Vulnerability and Change Management

Evenus maintains a vulnerability management process covering source code, dependencies, cloud configuration, and externally exposed endpoints. Evenus uses Snyk, GitHub Advanced Security, and Dependabot to perform dependency, secret, and code vulnerability scans before release. External vulnerability scans are performed at least monthly, and penetration testing is performed at least annually.

Findings are tracked to closure. Critical findings are remediated within 7 days, high-risk findings within 30 days, and lower-risk findings according to documented risk-based timelines. Changes are tested before deployment and approved before production release.

16. Incident Response

Evenus maintains an incident response plan for unauthorized access, database compromise, credential exposure, data leakage, and other incidents involving Amazon Information. The plan includes detection, triage, containment, credential and key rotation, impact analysis, remediation, recovery, and post-incident review.

If an incident involving Amazon Information is detected, the IMPOC investigates the incident and coordinates containment. Amazon will be notified within 24 hours of detection where Amazon Information is involved, in accordance with applicable Amazon SP-API requirements.

17. Contact

For questions about this policy or Amazon Information handling, please contact:

Evenus
Email: support@goldenrod.co.kr
Website: https://www.goldenrod.co.kr


SUPPORT센터

1555-2935

월-금 오전 10시 00분・오후 7시 00분 (점심 오후 1시・오후 2시)

boring card that's normal and used every time

Have you ever expected a new design of your own design?

The novelty of everyday objects will change your day.

Copyright ⓒ 2025 Evenus. All rights reserved.

카카오톡 채널 채팅하기 버튼