This Data Protection Policy describes how ChainPilot handles, stores, protects and processes data accessed through Amazon's Selling Partner API (SP-API) and other third-party platform integrations. This document is intended for Amazon's review as part of our SP-API developer application.
1. Company overview
ChainPilot is a supply chain management platform for Amazon FBA and Shopify sellers doing $500k–$10M in annual revenue. Our platform provides:
- AI-powered inventory forecasting and days of cover calculations
- Automated reorder alerts and purchase order management
- Freight tracking and shipment status monitoring
- Cash flow forecasting and P&L reporting
- Supplier communication and payment workflow management
2. Amazon SP-API data we access
We request access to the following SP-API data types, each with a specific justified purpose:
| Data type |
API endpoint |
Purpose |
Retention |
| Sales reports |
Reports API — Detail Page Sales and Traffic |
Calculate sales velocity (7/30/90 day) per ASIN to generate inventory forecasts and reorder recommendations |
90 days rolling |
| FBA inventory levels |
FBA Inventory API |
Display current stock levels and calculate days of cover per product |
Current snapshot only — refreshed every 6 hours |
| Inbound shipments |
Fulfillment Inbound API |
Track inbound FBA shipments and display status to sellers |
Active shipments only — archived after delivery confirmed |
We do not request access to and will never access:
- Customer personal data (names, addresses, contact information)
- Customer payment information or financial data
- Product pricing management or listing modification capabilities
- Order management or fulfillment capabilities
- Any data beyond what is listed above
3. How we collect data
Data is collected exclusively through the following authorized mechanism:
- Sellers explicitly authorize our application through Amazon's standard OAuth 2.0 flow in Seller Central
- Authorization is granted per seller account — we never access data without explicit per-account authorization
- Sellers can revoke access at any time through Seller Central → Apps & Services → Manage Your Apps
- Where refresh tokens are used to maintain authorized access, they are held server-side only and are never exposed to the browser, to other accounts or to any third party
4. Data storage and infrastructure
Status note. The Amazon Selling Partner API integration described in this
document is not yet live, and ChainPilot does not currently ingest Amazon SP-API data. The
controls below describe our infrastructure as it stands today. Section 4.4 lists the additional
controls that will be in place before any Amazon data is processed.
4.1 Infrastructure
- All data is stored on DigitalOcean cloud servers located in Frankfurt, Germany (EU)
- Servers run Ubuntu LTS with security patches applied
- Production servers are dedicated — no shared hosting
- Account data is held in per-account server-side stores, each isolated to a single customer account
4.2 Encryption and credentials
- All data in transit is encrypted using TLS 1.2 minimum (TLS 1.3 preferred), with HTTPS enforced across the application
- Account passwords are never stored in readable form — they are hashed with PBKDF2-SHA256 at 600,000 iterations with a per-password salt
- Session cookies are signed, HTTP-only and same-site restricted
- API credentials and secrets are held in a configuration file outside the application source, with filesystem permissions restricted to the service owner — never in source code or version control
4.3 Access controls
- Production server access is restricted to the application owner only
- SSH access requires key-based authentication
- Each customer can only access their own data — every request is resolved to a single account and reads and writes are confined to that account's own data store
- Two-factor authentication (TOTP, RFC 6238) is available on ChainPilot accounts
4.4 Controls required before Amazon data is processed
We will not enable the SP-API integration until the following are in place:
- Encryption at rest (AES-256) for all stored Amazon data, including Personally Identifiable Information
- Encrypted, access-controlled backups held separately from the production server
- Mandatory multi-factor authentication for all administrative access
- Retention and deletion controls meeting Amazon's Data Protection Policy requirements, including deletion of PII within 30 days of order completion unless a legal obligation requires otherwise
5. Data usage restrictions
We strictly adhere to the following restrictions on Amazon SP-API data:
- Purpose limitation: Amazon data is used exclusively to provide inventory management and supply chain services to the authorizing seller. It is never used for any other purpose.
- No data selling: We do not sell, rent, trade or otherwise transfer Amazon data to any third party under any circumstances.
- No advertising use: Amazon data is never used for advertising targeting, marketing profiling or any commercial purpose beyond the core service.
- No aggregation for resale: We do not aggregate seller data to create benchmarks, market intelligence reports or any product sold to third parties.
- No unauthorized sharing: Amazon data is never shared with third parties except where strictly necessary to provide the service (e.g. displaying data in the seller's own dashboard).
- Minimum necessary access: We request only the data types required to provide the service — no speculative data collection.
6. Data retention and deletion
| Data type |
Retention period |
Deletion trigger |
| Amazon sales reports |
90 days rolling window |
Automatic — older data purged weekly |
| Inventory snapshots |
Current + 7 days history |
Automatic — older snapshots deleted daily |
| Shipment records |
Until delivery + 30 days |
Automatic after confirmed delivery |
| All Amazon data |
Until access revocation |
All data deleted within 30 days of revocation or account closure |
| API credentials |
Until access revocation |
Immediately deleted upon revocation |
7. Incident response
In the event of a data breach or security incident:
- We will notify affected sellers within 72 hours of becoming aware of a breach
- We will notify Amazon in accordance with SP-API terms within the required timeframe
- We maintain an incident response procedure that includes immediate access revocation, investigation, remediation and disclosure
- Security incidents are logged and reviewed to prevent recurrence
8. Third-party subprocessors
Amazon SP-API data is processed only within our own infrastructure. We do not pass Amazon data to any subprocessors. The only third-party services we use are:
- DigitalOcean — infrastructure hosting only. DigitalOcean does not have access to application data.
- Gmail / Google Workspace — used to send transactional notification emails to sellers. Email content contains only summary information (e.g. "Your reorder alert is ready") — raw Amazon data is never included in emails.
9. Compliance
- We comply with Amazon's Acceptable Use Policy and Developer Agreement
- We comply with GDPR for EU-based users
- We comply with applicable data protection laws in the jurisdictions where we operate
- This policy is reviewed and updated at least annually or upon any material change to our data practices
10. Contact for data protection inquiries
For any questions about this Data Protection Policy or our data handling practices:
C Holding Group, LLC (trading as ChainPilot)
440 N Barranca Ave #2697
Covina, CA 91723
United States
Email: privacy@chainpilot.app
Response time: within 2 business days