This statement describes the technical and organizational measures Shenzhen Yipin Mingxuan Technology Co., Ltd. ("PPC Opt", "we") applies to protect customer data — including Amazon data accessed through the Amazon Advertising API and Amazon Selling Partner API (SP-API). Our controls are designed to align with Amazon's Data Protection Policy for API developers.
0. Data Scope and Role-Based Minimization
- We request only non-PII API roles. Depending on each seller's authorization, the data we handle is limited to: advertising campaign and performance data; business reports (store-level sessions, orders, sales, Buy Box percentage); catalog attributes and listing status; offer pricing and Buy Box status; FBA inventory levels; and settlement-level fee data (referral and FBA fees).
- We do not request, and our systems are not provisioned to receive, buyer PII or order-level buyer details. We do not hold roles that involve PII (such as order shipping or buyer communication roles).
- Each API data class is consumed only by the feature it supports (e.g., inventory data drives campaign pacing; settlement fees drive margin guardrails), and is never repurposed.
1. Encryption
- In transit: All connections to the Service, and all connections between the Service and Amazon APIs, use TLS 1.2 or higher. Unencrypted HTTP is redirected or refused.
- At rest: Databases, caches, backups, and object storage are encrypted with AES-256 (via AWS-managed encryption).
2. Credential and Token Handling
- Amazon authorization uses OAuth 2.0 (Login with Amazon). We never see, request, or store your Amazon account password.
- Refresh tokens and API credentials are stored encrypted at rest, access-restricted to the synchronization services that need them, and are never written to application logs, error reports, or client-side code.
- User login passwords are stored only as salted, one-way hashes using a modern password-hashing algorithm.
- When you revoke Amazon authorization, tokens for that profile are invalidated and deleted; API access stops immediately.
3. Access Control
- Tenant isolation: Each customer's data is logically isolated; all data access paths enforce tenant scoping so no user can reach another tenant's data.
- Least privilege: Staff access to production systems is limited to a small number of engineers who need it for operations, granted per-task and logged.
- Administrative access to production infrastructure requires multi-factor authentication.
- Role-based access control governs what users can do inside the platform (e.g., view-only vs. approve/execute optimization actions).
4. Network and Infrastructure
- The Service runs on Amazon Web Services in isolated network segments; databases and caches are not publicly reachable from the internet.
- Traffic enters through managed load balancing and content delivery layers with TLS termination; security groups restrict inbound access to required ports only.
- Production and development environments are separated; customer data is not used in development or testing.
5. Logging and Monitoring
- Application and infrastructure logs are monitored continuously for errors, anomalous access, and resource health, with automated alerting to on-call engineers.
- Logs are designed to exclude advertising data payloads and credentials; access to logs is restricted to operations staff.
- Every change made to an advertising account through the Service (automated or manual) is written to a tamper-evident audit trail visible to the account owner.
6. Availability and Backups
- Databases are backed up automatically with point-in-time recovery; backups are encrypted and access-restricted.
- The platform is deployed with redundant capacity and health-checked endpoints; failed components are replaced automatically.
7. Incident Response
- We maintain an incident response process covering detection, containment, eradication, recovery, and post-incident review.
- If a security incident results in unauthorized access to your data, we will notify affected customers without undue delay and no later than 72 hours after confirmation, describing the nature of the incident, the data affected, and remediation steps.
- Where an incident involves Amazon data, we will also notify Amazon without undue delay, and in any event within 24 hours of confirmation, as required by Amazon's policies.
8. Data Deletion
- Upon your request, account closure, or revocation of Amazon authorization, the associated data is deleted from production systems within 30 days;
- Encrypted backups containing deleted data age out within the following backup rotation cycle and are not restored except for disaster recovery;
- To request deletion, email vip@ppcopt.com from your registered address.
9. Organizational Measures
- Engineering staff receive security and data-handling onboarding, including rules for Amazon data;
- Changes to production code go through review and staged deployment with health gates;
- Third-party subprocessors (cloud hosting, transactional email) are bound by confidentiality and security obligations and are listed in our Privacy Policy.
10. Reporting a Security Issue
If you believe you have found a vulnerability or a security issue affecting the Service, please report it to vip@ppcopt.com. We investigate all reports and respond promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to address it.
11. Contact
Security and data-protection questions:
Shenzhen Yipin Mingxuan Technology Co., Ltd.
Address: 6th Floor, Mingzhu Building, Bantian Street, Longgang District, Shenzhen 518129, Guangdong Province, China
Email: vip@ppcopt.com · Phone: +86 131 6873 3147