Skip to content

How we protect your data

The security controls behind every SellerGoat engagement. SellerGoat operates under Amazon's Data Protection Policy and Acceptable Use Policy; the controls on this page are the same ones attested in our Solution Provider Profile.

We treat Amazon data with the seriousness it deserves: your seller account, your customers, your numbers.

Security controls

Encryption in transit

All Amazon data is encrypted end-to-end when retrieved via the Selling Partner API.

Access control

Access to Amazon data is restricted by role and job duty. Only authorized SellerGoat personnel working on a client's account can view that client's data.

Strong authentication

Every account requires a 12-character password minimum with special characters, multi-factor authentication (MFA), and an annual credential-rotation review. Password expiration is enforced every 365 days.

Network security

Firewalls, intrusion detection and prevention, anti-malware, and network segmentation across our environment.

Credential handling

Credentials are never stored in public repositories, hard-coded into applications, or shared between users.

Incident response

We maintain a documented incident response plan with defined roles, 6-month reviews, and 24-hour notification procedures. Any security incident involving Amazon Information is reported to security@amazon.com within 24 hours of detection.

Third-party data handling

SellerGoat does not sell, license, or disclose Amazon Information to unrelated third parties. Amazon data retrieved via the Selling Partner API is processed internally by SellerGoat and delivered only to the authorized client whose data it is.

We use Google LLC (Gmail and Google Drive) as a sub-processor, solely to deliver reports to authorized client recipients under Google's standard data protection terms. No other sub-processors are used to handle Amazon Information.

Where your data comes from

All Amazon Information is obtained directly from Amazon through the Selling Partner API and other Amazon-provided APIs, for seller accounts that have explicitly authorized SellerGoat access. We do not retrieve Amazon Information from any external (non-Amazon) sources.

You can revoke SellerGoat's access at any time in Seller Central under Apps & Services → Manage Your Apps.

Questions about how we handle data?

Tell us about your brand. We reply within 1 business day with a scoped quote. No spam, no obligation.