Data Handling and Security
Effective date: 18 July 2026
This page explains how AIORAS TECHNOLOGY LTD ("we", "us", "our") collects, uses, stores, and protects the data from the platforms a seller connects to our e-commerce audit and operations products, with specific attention to Amazon Selling Partner API (SP-API) data and Amazon's Data Protection Policy (DPP) and Acceptable Use Policy (AUP). It sits alongside our Privacy Policy and Terms of Service.
1. Amazon Selling Partner API data
Where a seller connects their Amazon account, we access their Amazon data to reconcile it against their own bookkeeping and to surface fee, margin and inventory issues. We retrieve this data today through DataDoe, an authorised Amazon data provider that the seller separately authorises against their own Amazon account, and we are onboarding direct SP-API access under our own Amazon Solution Provider registration. Whichever path applies to a given seller, the same commitments below apply.
1.1 What we access
Access is read-only. We do not access any buyer personally identifiable information; we read only order identifiers, totals, quantities, and product and financial data.
- Orders: order identifiers, dates, totals, quantities, and fulfilment status
- Finances: fee breakdowns (referral and FBA fees), refunds, and disbursements
- FBA inventory: stock levels and inbound shipments
- Catalogue (in development): product identifiers (ASIN, SKU) to tie sales and inventory to specific products
- Pricing (in development): the seller's own pricing and offer data, to relate price to margin
Amazon advertising data, where used, is retrieved through the separate Amazon Advertising API, not the Selling Partner API, and is covered by its own authorisation.
1.2 How we use Amazon data
- Reconciling orders and fees against the seller's accounting records
- Calculating true profit and loss per brand and per product
- Detecting unbooked fees, fee creep, and margin erosion
- Projecting cash flow based on Amazon's payout timing
- Identifying inventory risks such as stockouts, overselling and reorder timing
1.3 How we do not use Amazon data
- We do not sell, rent, or share Amazon Information with any third party for their own purposes
- We do not use Amazon Information to advertise or market to third parties
- We do not aggregate Amazon Information across sellers for benchmarking or competitive intelligence
- We do not use Amazon Information to train machine-learning models
- We do not retain Amazon Information after a seller disconnects (deleted within 30 days)
1.4 Retention and deletion
- Active connection: Amazon Information is retained for the duration of the seller's active connection and subscription
- Disconnection: permanently deleted within 30 days of disconnecting the Amazon account
- Account closure: all Amazon Information permanently deleted within 30 days of closure
- On-demand deletion: a seller may request deletion at any time via privacy@aioras.ai
2. Other connected platforms
We connect to Shopify (Admin API), QuickBooks (Intuit), and Google (Ads and Analytics) through their official OAuth 2.0 APIs, and we read only the data needed to reconcile and report on the seller's business. The same security, retention, and deletion commitments apply as for Amazon data. We never store a seller's marketplace passwords.
3. Security measures
- In transit: all data is encrypted using TLS 1.2 or higher; HTTPS is enforced on every endpoint
- At rest: stored data is encrypted using AES-256-GCM
- Credentials: OAuth tokens and access keys are held in an encrypted secret store, never in application code, logs, or public repositories
- Isolation: multi-tenant logical separation; every database query is scoped to a single seller, so no seller's data is accessible to another
- Infrastructure: hosted on Cloudflare's global platform (Workers, D1, R2), with Cloudflare's DDoS protection and edge security
- Access control: internal access follows least privilege and requires multi-factor authentication
- Monitoring: automated dependency and secret scanning on our codebase
4. Incident response
We maintain a formal incident response plan with defined roles, reviewed at least every six months. In the event of a confirmed incident:
- Security incidents involving Amazon Information are reported to security@amazon.com within 24 hours of detection
- Affected sellers are notified where required, and personal-data breaches are assessed for notification to the UK Information Commissioner's Office within 72 hours under UK GDPR
- A post-incident review documents the timeline, root cause, and corrective actions
5. Our data protection role
For the platform data we access on a seller's authorisation, including Amazon Information, we act as the seller's service provider and data processor, using it only to provide the service to that seller. The seller remains the account holder and controller of their own platform data. We act as data controller for the account and contact data a customer gives us directly, as described in our Privacy Policy.
6. Your controls
- Connect and disconnect: add or remove any platform connection at any time
- Export: download reconciled data, reports, and findings
- Delete: request full deletion of your data at any time
- Revoke: revoke our access directly from Amazon Seller Central, DataDoe, Shopify, Google, or your accounting tool
7. Compliance
- UK GDPR / Data Protection Act 2018: controller for account data, processor for the platform data we access on a seller's behalf
- Amazon Data Protection Policy (DPP) and Acceptable Use Policy (AUP): we handle Amazon Information in line with these policies
- PCI DSS: payment processing is handled by Stripe (PCI DSS Level 1 certified); we do not store card details
- SOC 2: we are aware of SOC 2 requirements and are planning our controls accordingly; we are not yet SOC 2 certified
8. Contact
Questions about our data handling, security, or to exercise your data rights: privacy@aioras.ai. AIORAS TECHNOLOGY LTD, 4th Floor Office, 205 Regent Street, London, England, W1B 4HB. Company number 16037096.