Legal

Data Protection Policy

Last updated: September 8, 2026  ·  Version 1.0

This Data Protection Policy describes how ChainPilot handles, stores, protects and processes data accessed through Amazon's Selling Partner API (SP-API) and other third-party platform integrations. This document is intended for Amazon's review as part of our SP-API developer application.

1. Company overview

ChainPilot is a supply chain management platform for Amazon FBA and Shopify sellers doing $500k–$10M in annual revenue. Our platform provides:

2. Amazon SP-API data we access

We request access to the following SP-API data types, each with a specific justified purpose:

Data type API endpoint Purpose Retention
Sales reports Reports API — Detail Page Sales and Traffic Calculate sales velocity (7/30/90 day) per ASIN to generate inventory forecasts and reorder recommendations 90 days rolling
FBA inventory levels FBA Inventory API Display current stock levels and calculate days of cover per product Current snapshot only — refreshed every 6 hours
Inbound shipments Fulfillment Inbound API Track inbound FBA shipments and display status to sellers Active shipments only — archived after delivery confirmed

We do not request access to and will never access:

3. How we collect data

Data is collected exclusively through the following authorized mechanism:

4. Data storage and infrastructure

Status note. The Amazon Selling Partner API integration described in this document is not yet live, and ChainPilot does not currently ingest Amazon SP-API data. The controls below describe our infrastructure as it stands today. Section 4.4 lists the additional controls that will be in place before any Amazon data is processed.

4.1 Infrastructure

4.2 Encryption and credentials

4.3 Access controls

4.4 Controls required before Amazon data is processed

We will not enable the SP-API integration until the following are in place:

5. Data usage restrictions

We strictly adhere to the following restrictions on Amazon SP-API data:

6. Data retention and deletion

Data type Retention period Deletion trigger
Amazon sales reports 90 days rolling window Automatic — older data purged weekly
Inventory snapshots Current + 7 days history Automatic — older snapshots deleted daily
Shipment records Until delivery + 30 days Automatic after confirmed delivery
All Amazon data Until access revocation All data deleted within 30 days of revocation or account closure
API credentials Until access revocation Immediately deleted upon revocation

7. Incident response

In the event of a data breach or security incident:

8. Third-party subprocessors

Amazon SP-API data is processed only within our own infrastructure. We do not pass Amazon data to any subprocessors. The only third-party services we use are:

9. Compliance

10. Contact for data protection inquiries

For any questions about this Data Protection Policy or our data handling practices:

C Holding Group, LLC (trading as ChainPilot)
440 N Barranca Ave #2697
Covina, CA 91723
United States
Email: privacy@chainpilot.app
Response time: within 2 business days

Related documents: Terms of Service  ·  Privacy Policy  ·  Data Protection Policy