Amazon Data Handling Policy

Data we collect from Amazon

Through the Amazon Selling Partner API, we collect: order details (items, quantities, prices), and — for orders we fulfill ourselves — the buyer's name and shipping address, retrieved via a Restricted Data Token scoped to that specific order.

How we process and use this data

Order and address data is used solely to (1) create a corresponding order in our order-management system (Shopify), and (2) generate a shipping label and fulfill the order through our warehouse partner. It is not used for marketing, profiling, or any purpose unrelated to fulfilling that order.

Where and how this data is stored

Our integration application does not persist buyer PII in its own storage. The name and address obtained from Amazon exist only in memory for the single request used to create the corresponding Shopify order — nothing is written to disk in any system we directly control beyond that point.

The Shopify order created from that data is retained as a standard business transaction record, consistent with our normal recordkeeping practices and applicable tax/accounting retention requirements. Order records within Shopify are protected by Shopify's own security and encryption practices as our e-commerce platform.

Who we share this data with

  • Shopify, our e-commerce platform, as the system of record for order processing.
  • Our fulfillment partner, limited to the name and shipping address needed to pack and ship a specific order.
  • Railway, our hosting provider, as part of running our integration application (this application's own storage does not contain buyer PII — see above).

We do not sell, rent, or share this data with any advertiser, data broker, or unrelated third party.

Retention and disposal

Because this application does not store buyer PII outside the single request needed to create the matching Shopify order, there is no separate retention period for our own systems to manage. The resulting Shopify order is retained as a standard business record, consistent with normal e-commerce recordkeeping and applicable tax/accounting retention requirements — not deleted on a fixed short timeline, since doing so would conflict with those requirements.

If our access to the Selling Partner API is ever revoked, this application's own state (which never contained buyer PII to begin with) is deleted within 30 days, consistent with Amazon's Data Protection Policy.

Contact

Questions about this policy can be directed to onesupplierllc@gmail.com.

Last updated: September 1, 2026