Authorized seller data,
used within defined boundaries.

SellerOS processes data needed for enabled features and protects it through isolation, least privilege, encryption, audit, and lifecycle controls.

01 / DATA SOURCES

Authorized APIs and information a seller chooses to provide

SellerOS does not collect operating data through unrelated methods or provide one seller's data to competing sellers.

Amazon SP-API

Authorized products, orders, inventory, FBA, fees, cases, and related operating data.

Amazon Ads API

Authorized campaigns, ad groups, targeting, budgets, bids, spend, traffic, and attribution.

Brand Analytics

Search, traffic, keyword, and brand analytics when the seller account has the required access.

Seller-provided data

Costs, supply-chain facts, product assets, brand information, files, and other data users choose to provide.

1AuthorizationStore, API, and permission scope
2Necessary syncFields required by enabled features
3IsolationSeller, store, and user boundaries
4Limited useDisplay, analysis, and approved actions
5LifecycleDelete, de-identify, or restrict

02 / COMPLIANCE

Access, purpose, and retention have clear limits

SellerOS applies relevant Amazon data-protection and acceptable-use policies, developer agreements, contracts, and applicable law to authorized data. Amazon policies and agreements
01

Minimum necessary access

We request roles, APIs, and data needed for the features a user enables.

02

Purpose limitation

Data supports user-requested operations, analysis, security, and support. It is not sold or used for unrelated advertising profiles.

03

PII and restricted data

Routine analytics does not depend on buyer PII. Restricted data is accessed only for authorized, necessary workflows.

04

Lifecycle management

Retention follows business need, platform policy, contracts, and law, followed by deletion, de-identification, or restricted access.

03 / SECURITY

Controls reduce unnecessary exposure

Protection covers identities, permissions, environments, transport, secrets, logs, backups, and incident response.

Identity and least privilege

Unique identities and access scoped by organization, store, role, function, data, and action.

Seller and environment isolation

Optional store environments use operating-system or virtual-machine boundaries; accounts, files, tools, and sessions are not reused across environments.

Encryption and secret protection

Encrypted transport, password hashing, and protected credentials that stay out of ordinary logs.

Audit and incident response

Relevant access, permission, synchronization, and action events support review and investigation.

AI receives only the context needed for the current task

SellerOS prioritizes aggregated, statistical, and de-identified data. Buyer PII, API secrets, refresh tokens, database passwords, and system credentials are not ordinary AI analysis inputs.

Managed actions run only after an authorized user enables the relevant plan and remain constrained by object, budget, inventory, profit, risk, and permission controls.

Read the Data and AI Security Statement

04 / ISOLATED STORE OPERATING ENVIRONMENTS

U.S. operating environments support authorized store operations, not regional bypass

Enterprise customers may choose an isolated U.S. operating environment and U.S. business Internet connection for their own authorized Amazon store operations.
01

Operating-system boundary

Optional store environments run within separate operating-system or virtual-machine boundaries. Store accounts, files, tools, and sessions are not reused across environments; browser-profile separation is only one control inside that boundary.

02

Defined operating purpose

The environment supports a customer's own Amazon operations, stable account context, team collaboration, and auditability. SellerOS does not offer a public shared proxy or VPN service.

03

Platform rules still apply

Platform availability, account eligibility, and publishing restrictions remain controlling. SellerOS does not use these environments to bypass TikTok or any other platform's geographic restrictions.

04

Controlled and auditable

Authorized users initiate access under session, permission, and logging controls. Suspected misuse may be suspended and investigated.