JDTC's commitment to protecting Amazon seller data in compliance with Amazon's Data Protection Policy and international data protection standards.
Last updated: March 31, 2026
Six core principles guide how we handle all data accessed through Amazon's SP-API.
We only collect and process data that is strictly necessary for providing the requested services. No excess data collection.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Regular security audits ensure ongoing protection.
Strict role-based access controls ensure only authorized personnel can access sensitive data, with full audit logging.
PII is deleted within 30 days of order completion. All data is permanently deleted upon contract termination.
We maintain a comprehensive incident response plan and will notify Amazon and affected parties within 24 hours of any breach.
Full compliance with Amazon's Data Protection Policy, Acceptable Use Policy, and applicable data protection regulations.
This Data Protection Policy applies to all data accessed, processed, or stored by JDTC Co., Ltd. in connection with our Amazon Selling Partner API (SP-API) services. It supplements our Privacy Policy and is specifically designed to address the requirements of Amazon's Data Protection Policy.
| Data Type | Purpose | Retention Period |
|---|---|---|
| Order PII (names, addresses) | Order fulfillment only | 30 days post-delivery |
| Product & inventory data | Store management | Duration of contract |
| Sales analytics data | Performance reporting | Duration of contract + 1 year |
| Advertising data | Campaign management | Duration of contract |
| Account credentials | System access | Deleted upon termination |
JDTC implements the following technical measures to protect Amazon seller data:
JDTC strictly adheres to Amazon's Data Protection Policy requirements:
In the event of a data security incident, JDTC will:
When we engage third-party service providers who may process Amazon seller data, we:
Data Protection Contact