AMAZON SP-API ACCESS + SECURITY

How EzSeller handles Amazon seller data.

EzSeller is built as a public Amazon seller-operations application. Sellers authorize their own account through Amazon OAuth. EzSeller does not ask sellers to paste Amazon passwords, refresh tokens, or developer credentials.

Launch access scope

EzSeller's launch product is designed around non-restricted seller operations: Product Listing, Inventory and Order Tracking, Amazon Fulfillment, Finance and Accounting, Pricing, Brand Analytics, and Selling Partner Insights as required by the enabled workflows. EzSeller does not require restricted buyer PII roles for its launch workflows and does not need buyer names, shipping addresses, buyer messages, tax-remittance PII, or Direct-to-Consumer Shipping PII.

Requested Amazon roles are kept to the minimum needed by the enabled product surface. Adding a materially different Amazon workflow requires a separate role and data-use review before it is exposed to customers.

Authorization and isolation

Each seller authorizes EzSeller through Amazon's OAuth flow. The resulting authorization is bound to one EzSeller workspace and the participating Amazon marketplaces returned for that seller. Tenant and marketplace checks are enforced on requests so one seller's authorization cannot silently fall back to another seller or marketplace.

Credentials and encryption

Amazon application secrets and seller authorization material remain server-side. Credentials are encrypted at rest, are never intentionally returned in MCP responses, and are excluded from support and acquisition telemetry. External endpoints require HTTPS; internal application controls apply least privilege to seller and workspace authority.

Data minimization and retention

EzSeller stores only the seller data and operational evidence needed to provide the requested workflows, support security, and preserve bounded provenance. Amazon-sourced information is deleted when it is no longer required for the authorized purpose and, after seller revocation or termination of access, within 30 days unless a specific legal, tax, or regulatory obligation requires retention. Any legally retained copy remains protected and is not reused for a new purpose.

EzSeller's launch scope does not require restricted buyer PII. If a future product feature would require restricted data, it will not be enabled until the corresponding Amazon role, architecture, privacy, security, and retention requirements have been separately approved.

Monitoring, vulnerabilities and incident response

Release gates include automated tests, source/security checks, dependency and workflow checks, and exact-deployed-version verification. Security-relevant events are recorded without intentionally storing seller credentials in logs. Critical security incidents involving Amazon information are escalated through the documented incident-response process, including Amazon notification within the policy-required window. Critical and high-risk vulnerabilities are tracked to the remediation timelines required by Amazon policy.

Service providers and seller control

EzSeller currently uses Cloudflare for the application runtime, Neon for application data storage, Stripe for billing, and Resend for account email. Connected AI clients receive only the MCP results authorized for the workspace and operate under their own terms. Sellers can revoke Amazon authorization and can request deletion through EzSeller Support.

Company and support

EzSeller is operated by SMAT Designs. For security, privacy, account, or Amazon-connection questions, use the support page or email onboarding@smatdesigns.com. Do not send Amazon passwords, access tokens, refresh tokens, or card information.

EzSeller is an independent software product. References to Amazon, Seller Central, FBA, and SP-API describe compatibility and supported workflows; they do not imply endorsement or partnership by Amazon.