Last updated: 2026-05-23 · Amazon DPP Compliance · v2 (clarifies PII boundary)
Data Protection (Data Protection Statement)
This document describes how Shenzhen Renli Technology Co., Ltd. handles data obtained via Amazon SP-API in emit-erp, to comply with Amazon Data Protection Policy (DPP) and applicable laws. emit-erp currently does not request any PII-restricted role and does not receive any buyer personal information; this document also pre-describes the handling mechanism if a PII role is added later for business need.
0. PII Boundary (Current State)
emit-erp currently does not request any PII-restricted role in its Amazon SP-API application:
- Not requested: Direct-to-Consumer Shipping, Tax Invoicing, Tax Remittance, Professional Services;
- Therefore, Orders and other SP-API endpoints under our scope do not return buyer name, shipping address, phone or email (governed by Amazon's RDT — Restricted Data Token mechanism);
- Buyer messaging is routed through Amazon's official anonymized email channel via the Messaging API; emit-erp never sees the buyer's real email;
- For MFN orders, shipping labels are generated as PDF by Amazon's official API; emit-erp only handles file transfer and print scheduling, and does not parse plaintext addresses;
- If a PII-restricted role is added later for business need, all PII protection mechanisms described in sections 3-7 below will take effect immediately.
1. Data Classification
| Category | Typical Fields | PII? | Retention |
| Buyer info | Name, shipping address, email, phone | Not received (no PII role requested) | — (if added later: ≤ 30 days) |
| Order business data | Order ID, SKU, amount, status | No | Service period |
| Inventory & FBA Data | SKU, stock level, inbound ID | No | Service period |
| Ads & Reports | Campaigns, keywords, reports | No | Service period |
2. Data Collection
All data is obtained only after you actively complete OAuth in Amazon Seller Central. emit-erp, acting as a Selling Partner App, calls SP-API endpoints on demand (Orders v0, FBA Inventory v1, Reports 2021-06-30, Advertising API, Catalog Items, Listings Items, Product Pricing, AWD, Brand Analytics, etc.). We do not store your Amazon password, and never access data outside the authorized scope. The current authorized scope does not include any buyer PII.
3. Data Transmission & Storage
- Hosting: emit-erp is self-hosted and operated by Shenzhen Renli Technology Co., Ltd. on its own servers; no third-party SaaS platforms are involved in the data path.
- Encryption in transit: Client ↔ emit-erp uses TLS 1.2+; emit-erp ↔ Amazon SP-API uses HTTPS + AWS SigV4 signing.
- Encryption at rest: Databases and object storage use AES-256; keys are independently managed with periodic rotation.
- Regional isolation: Data is stored in separate, region-aligned databases (North America / Europe / Far East) per the seller's marketplace, with no cross-region replication.
- Backups: Daily encrypted snapshots; backup media also encrypted; backups auto-destroyed after 30 days.
4. Access Control
- Principle of least privilege;
- R&D, operations, and customer service belong to separate IAM groups by role;
- Two-factor authentication (2FA) required for all production system access;
- All access and export operations on production systems are fully logged; logs retained for 1 year (currently no PII; if a PII role is added later, PII decryption events are separately audited with 90-day event-log retention).
5. Data Retention & Deletion
- Currently no buyer PII is received; if a PII role is added later for business need, buyer PII is retained up to 30 days from acquisition and auto-purged from production and backups on expiry;
- Billing and tax records: retained 7 years per law, but only de-identified -de-identified statistical fields are kept;
- Authorization revocation: sync stops within 72 hours; all business data deleted within 90 days (if PII has been received, it is separately purged within 30 days);
- On-demand deletion: request immediate deletion via Contact Us; tickets closed within 7 business days.
6. incident response
In the event of a data security incident:
- Initiate the incident response process and isolate impact within 24 hours;
- Notify Amazon and submit an incident report within 72 hours (per DPP § 9.1);
- Notify affected users and take remediation actions per applicable laws including GDPR, CCPA, PIPL.
7. security assessment
- Annual independent third-party penetration testing and security assessments;
- Quarterly internal vulnerability scans and code audits;
- SDLC integrated with SAST / DAST / SCA tooling.
8. Data Protection Officer (DPO)
- Company: Shenzhen Renli Technology Co., Ltd.
- Email: emit-erp@hotmail.com(please include "DPO" in subject)
- Phone: (+86)18098973306
- Address: Building A, A328, Fuhai Tech Industrial Park, Bao'an District, Shenzhen (Qianhai Cooperation Zone)