Draft skeleton — not yet a published policy
This page lays out the required structure only. Every section below is intentionally empty: privacy policy text is a binding legal statement and must be written and reviewed by the business and its counsel. Do not submit this site for Amazon review until every section is filled in and this notice is removed.
1.Introduction and scope
This section must cover:
- Which legal entity publishes this policy, and how to identify it
- Which websites, applications, and services the policy covers
- Who the policy applies to (visitors, customers, authorized Amazon sellers)
- Effective date and how changes are communicated
TODO · 待填
Legal copy for “Introduction and scope”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
2.Information we collect
This section must cover:
- Information you provide directly (account registration, billing, support enquiries)
- Information collected automatically (log data, IP address, device and browser data, cookies)
- Information received from Amazon after you authorize the application
- Whether any Personally Identifiable Information is collected, and if so which fields
TODO · 待填
Legal copy for “Information we collect”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
3.Amazon Selling Partner data
This section must cover:
- Exactly which categories of Selling Partner data are retrieved via the SP-API
- The specific business purpose for each category
- Confirmation that data is used only to provide services to the seller it belongs to
- That data is never sold, and never used to compete with the seller
- How authorization is granted and how a seller revokes it in Seller Central
- Commitments made under the Amazon Data Protection Policy and Acceptable Use Policy
TODO · 待填
Legal copy for “Amazon Selling Partner data”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
4.How we use information
This section must cover:
- Each processing purpose, stated separately
- The legal basis for each purpose where GDPR or a comparable regime applies
- Whether data is used for analytics, product improvement, or model training — and if so, how it is de-identified
- Marketing communications and how to opt out
TODO · 待填
Legal copy for “How we use information”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
5.How we store and protect data
This section must cover:
- Where data is hosted (provider, country or region)
- Encryption in transit and at rest, including the encryption applied to Amazon credentials
- Access control, least-privilege, and authentication requirements for staff
- Logging, monitoring, and vulnerability management
- Incident response process and the breach notification timeline
TODO · 待填
Legal copy for “How we store and protect data”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
6.Data retention and deletion
This section must cover:
- Retention period for each category of data, including Amazon Selling Partner data
- What is deleted when a seller revokes authorization, and how quickly
- What is deleted when an account is closed, and how quickly
- How a customer requests deletion, and how the request is verified
- Any data retained for legal or accounting obligations, and the basis for retaining it
TODO · 待填
Legal copy for “Data retention and deletion”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
7.Sharing with third parties
This section must cover:
- Every subprocessor and service provider, with the purpose of each
- That Selling Partner data is not sold or shared for advertising
- Disclosures required by law, and disclosures in a merger or acquisition
- The safeguards imposed on subprocessors by contract
TODO · 待填
Legal copy for “Sharing with third parties”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
8.International data transfers
This section must cover:
- Which countries data is transferred to or stored in
- The transfer mechanism relied on (e.g. Standard Contractual Clauses)
- Safeguards applied to cross-border transfers
TODO · 待填
Legal copy for “International data transfers”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
9.Cookies and similar technologies
This section must cover:
- Which cookies are set, by whom, and for what purpose
- The distinction between strictly necessary cookies and optional ones
- How a visitor manages or withdraws consent
TODO · 待填
Legal copy for “Cookies and similar technologies”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
10.Your rights and choices
This section must cover:
- Rights of access, rectification, erasure, restriction, portability, and objection
- Rights specific to applicable regimes (GDPR, UK GDPR, CCPA/CPRA, PIPL as relevant)
- How to exercise a right, and the response timeline
- The right to lodge a complaint with a supervisory authority
TODO · 待填
Legal copy for “Your rights and choices”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
11.Children's privacy
This section must cover:
- That the service is not directed to children
- The minimum age for using the service
- What happens if data from a minor is discovered
TODO · 待填
Legal copy for “Children's privacy”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
12.Changes to this policy
This section must cover:
- How material changes are announced and how much notice is given
- Where the version history or effective date is shown
TODO · 待填
Legal copy for “Changes to this policy”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md
13.Contact us
This section must cover:
- Privacy enquiry email address
- Postal address of the legal entity
- Data protection officer or EU/UK representative, if one is appointed
- A dedicated security contact for reporting suspected data incidents
TODO · 待填
Legal copy for “Contact us”. To be drafted / reviewed by counsel.
Fill in before submitting for review — see docs/registration-checklist.md