How we protect your data
The security controls behind every SellerGoat engagement. SellerGoat operates under Amazon's Data Protection Policy and Acceptable Use Policy; the controls on this page are the same ones attested in our Solution Provider Profile.
We treat Amazon data with the seriousness it deserves: your seller account, your customers, your numbers.
Security controls
Encryption in transit
All Amazon data is encrypted end-to-end when retrieved via the Selling Partner API.
Access control
Access to Amazon data is restricted by role and job duty. Only authorized SellerGoat personnel working on a client's account can view that client's data.
Strong authentication
Every account requires a 12-character password minimum with special characters, multi-factor authentication (MFA), and an annual credential-rotation review. Password expiration is enforced every 365 days.
Network security
Firewalls, intrusion detection and prevention, anti-malware, and network segmentation across our environment.
Credential handling
Credentials are never stored in public repositories, hard-coded into applications, or shared between users.
Incident response
We maintain a documented incident response plan with defined roles, 6-month reviews, and 24-hour notification procedures. Any security incident involving Amazon Information is reported to security@amazon.com within 24 hours of detection.
Third-party data handling
SellerGoat does not sell, license, or disclose Amazon Information to unrelated third parties. Amazon data retrieved via the Selling Partner API is processed internally by SellerGoat and delivered only to the authorized client whose data it is.
We use Google LLC (Gmail and Google Drive) as a sub-processor, solely to deliver reports to authorized client recipients under Google's standard data protection terms. No other sub-processors are used to handle Amazon Information.
Where your data comes from
All Amazon Information is obtained directly from Amazon through the Selling Partner API and other Amazon-provided APIs, for seller accounts that have explicitly authorized SellerGoat access. We do not retrieve Amazon Information from any external (non-Amazon) sources.
You can revoke SellerGoat's access at any time in Seller Central under Apps & Services → Manage Your Apps.
Questions about how we handle data?
Tell us about your brand. We reply within 1 business day with a scoped quote. No spam, no obligation.