Privacy and Data Handling Policy

Inskeep Privacy Policy

Last updated: May 26, 2026. This policy covers Inskeep customer data and Amazon Selling Partner API data, including restricted buyer information used for authorized order fulfillment and shipping workflows.

Amazon Information is used only for authorized seller operations and is protected according to Amazon Services API policies, the Amazon SP-API Data Protection Policy, and applicable law.

1. Scope

This Privacy and Data Handling Policy explains how Inskeep collects, uses, stores, protects, shares, and deletes information processed through the Inskeep application, including information received from Amazon Selling Partner API (SP-API).

For Amazon integrations, we treat all information received from Amazon SP-API, Seller Central, or related Amazon services as Amazon Information. This includes seller account information, catalog and listing data, inventory, orders, order items, shipment data, financial data, and any restricted buyer personally identifiable information.

2. Information We Collect

We collect information authorized users provide directly, such as account profile details, company settings, support requests, product records, inventory records, purchase orders, and configuration data.

When an authorized seller connects a sales channel, we collect operational data needed to provide the service. For Amazon, this may include listings, pricing, inventory, orders, order items, shipment status, financial transactions, buyer shipping name, shipping address, phone number, and tracking or label details when needed for order fulfillment and Amazon Buy Shipping.

We collect application logs, authentication events, audit events, integration activity, device/browser metadata, and security-relevant telemetry needed to operate, troubleshoot, and secure the service.

3. How We Use Information

We use customer and Amazon Information only to provide and secure the Inskeep service for the seller or organization that authorized access.

Permitted uses include syncing listings, pricing, inventory, orders, order items, financial summaries, fulfillment status, shipping readiness, Amazon Buy Shipping label workflows, tracking updates, reporting, support, audit logging, fraud prevention, and incident investigation.

We do not sell Amazon Information, buyer PII, customer data, or seller data. We do not use Amazon Information for advertising, profiling unrelated to seller operations, or any purpose not authorized by the seller and Amazon policy.

4. Amazon Restricted Data and PII

Inskeep requests restricted Amazon buyer PII only when necessary for an approved operational purpose, such as fulfilling an Amazon order, obtaining eligible Amazon Buy Shipping services, purchasing a shipping label, storing tracking results, handling support for an order, or satisfying legal obligations.

Amazon buyer PII may include recipient name, shipping address, phone number, buyer email when provided by Amazon, gift or shipment-related details, and other information that can identify or contact an individual.

Access to restricted data is limited to authorized users and service components with a business need. We use role-based access controls, individual user accounts, audit logs, and least-privilege service credentials.

5. Retention and Deletion

We retain Amazon buyer PII only as long as necessary for order fulfillment, shipping, customer support, tax or legal compliance, and security/audit needs.

Amazon buyer PII is deleted or de-identified no later than 30 days after order shipment or delivery, unless a longer period is required by law for tax, regulatory, dispute, or compliance purposes.

If Amazon or an authorized customer requests deletion or return of Amazon Information, we will securely delete or return the applicable information according to Amazon policy and applicable law. Backup copies expire through normal encrypted backup rotation.

6. Security Controls

We use administrative, technical, and physical safeguards designed to protect Amazon Information and customer data from unauthorized access, disclosure, alteration, and destruction.

Controls include HTTPS/TLS encryption in transit, encrypted production databases and backups at rest, access controls based on job duties, MFA where available, secure credential storage, private repositories, environment-based secrets, audit logs, application change review, and restricted administrative access.

Production databases, file storage, and internal services are not intentionally exposed to the public internet except through authenticated application interfaces and managed service endpoints required to operate the service.

7. Credentials and Secrets

Credentials, tokens, encryption keys, and secret access keys are stored using environment variables or managed secret storage and are not intentionally hard-coded into source code.

Access to credentials is limited to authorized administrators and service processes. If a credential is suspected to be exposed, we revoke and rotate it as soon as practicable and investigate the event under our incident response process.

8. Logging, Monitoring, and Incident Response

We maintain logs for authentication, administrative actions, integration activity, order and fulfillment actions, errors, and security-relevant events. Logs are reviewed to investigate suspicious activity, operational failures, and potential security incidents.

Our incident response process includes identifying the affected systems and data, containing unauthorized access, preserving relevant logs, revoking exposed credentials, remediating root cause, restoring service from trusted systems or backups, and documenting corrective actions.

If we detect a security incident involving Amazon Information, we will notify Amazon at security@amazon.com within 24 hours when required by Amazon policy and will notify affected customers as required by law or contract.

9. Testing and Development

We use separate development and production workflows. Production PII is not used for routine testing. Test data should be synthetic, anonymized, or redacted unless limited production troubleshooting is specifically required.

Application changes are reviewed and tested before production deployment. Vulnerability findings are triaged by severity, tracked to remediation, and prioritized according to risk.

10. Sharing and Subprocessors

We do not sell or rent customer data, seller data, Amazon Information, or Amazon buyer PII.

We may share information with service providers that help us host, secure, monitor, support, or operate Inskeep, but only as needed to provide the service and subject to confidentiality and security obligations.

We may disclose information if required by law, legal process, security investigation, or to protect the rights, safety, and integrity of Inskeep, our customers, Amazon, or others.

11. Customer Controls and Requests

Authorized customers may request access, correction, export, deletion, or disconnection of their data by contacting us. We will respond according to applicable law, contractual obligations, Amazon policy, and the operational requirements of the connected seller account.

Customers can revoke channel authorization through the relevant marketplace or by contacting Inskeep support for assistance with disconnecting integrations.

12. Contact

For privacy, data handling, Amazon Information, or security questions, contact Colin Inskeep at colin@inskeep.io.

Incident Management Point of Contact: Colin Inskeep, colin@inskeep.io.

Questions

For privacy, security, or Amazon SP-API data handling requests, email colin@inskeep.io.

Contact privacy