SP-API Statement

SP-API Compliance & Data Security Statement

(Amazon Selling Partner API — Compliance & Data Security Statement)
Declarant Entity: anjishanghedianzishangwuyouxiangongsi
Effective Date: August 1, 2026

This Statement is established to comply with the Amazon Developer Services Agreement, the Amazon Data Protection Policy (DPP) (Revised November 2025), the Amazon Acceptable Use Policy (AUP), and all applicable data protection laws and regulations (including but not limited to GDPR, CCPA, etc.).

I. Entity Information

Company / Developer Name: anjishanghedianzishangwuyouxiangongsi
Country of Registration: China
Official Website: https://melokea.com/
SP-API Integration Contact: LINGLING SHANG
Contact Phone: +86 17055060013
Contact Email: admin@melokea.com
Business License No.: 91330523MA2D5DQ6X6

II. Compliance Commitment

We hereby declare that we have read, understood, and committed to strictly complying with all provisions of the following agreements and policies:

Amazon Developer Services Agreement;
Amazon Data Protection Policy (DPP);
Amazon Acceptable Use Policy (AUP);
All applicable privacy and data protection laws in the jurisdictions where end users are located.

III. Data Collection & Use

This application integrates with the Amazon Selling Partner API (SP-API) to collect the following categories of personal data (PII), solely for the purposes of order processing, customer service, and legitimate business operations:

Data Type Purpose of Collection User Authorization Method
Buyer name, shipping address, phone number Order fulfillment and logistics tracking Explicitly agreed upon by the user when placing an order on the Amazon platform
Order item details, transaction amount Order synchronization and financial reconciliation Same as above
Seller identifier (Seller ID), authorization token API authentication and access control Explicitly agreed by the seller during the authorization flow
Important Statement: We do NOT collect or request access to buyers’ microphone, camera, location data, SMS/call logs, device usage data, or any information unrelated to the functionality of this application.

IV. Data Sharing & Third-Party Disclosure

No Sharing with Third-Party Advertising Networks: We solemnly commit that, without the explicit and separate consent of the end user, we shall never transfer, sell, or share any personal data with any third-party advertising networks, data brokers, or marketing platforms.
Limited Sharing with Essential Service Providers: We may share the minimum necessary data with the following categories of service providers, all of whom are bound by equivalent confidentiality and data protection obligations:
Logistics carriers (e.g., SF Express, JD Logistics): buyer name, address, and phone number shared solely for package delivery purposes.
Cloud service providers (e.g., AWS / Tencent Cloud): data hosted within the People’s Republic of China (or as otherwise specified), with no cross-border transfer without user consent.
Data analytics service providers: only de-identified and aggregated data is used; no PII is shared for analytics purposes.

V. Data Security Controls (Key Review Area for SP-API)

We have deployed and continuously maintain the following technical and administrative measures to ensure the security of PII:

Control Area Specific Requirement Our Implementation Status
Transmission Encryption TLS 1.2 or higher ✓ TLS 1.3 Enabled
Encryption at Rest PII storage encrypted with AES-256 or RSA 2048-bit or higher ✓ AES-256 Enabled
Access Control Account locked after 10 failed login attempts; password history retains the last 10 passwords; API keys rotated every 90 days ✓ Configured
Incident Management Designate a dedicated Incident Management Point of Contact (IMPOC) ✓ IMPOC: Kenny; Email: impoc@melokea.com
Vulnerability Management Critical vulnerabilities remediated within 7 days; high-risk vulnerabilities within 30 days ✓ SLA Established
Log Retention Security logs retained for at least 12 months ✓ Configured
Data Retention Non-PII data retained no longer than 18 months; PII deleted within 30 days after order delivery ✓ Automated Cleanup Policy Set
Data Deletion Upon receiving Amazon’s written deletion notice, secure deletion completed within 30 days; all online instances and backups purged within 90 days ✓ Emergency Procedure Established

VI. Permission Usage Statement

This application requests only the minimum permissions necessary for its intended functionality. In runtime environments of Android N / Fire OS 6 and above, permissions are requested dynamically in context (“while-in-use”), and we never pre-authorize or abuse permissions to collect irrelevant data.

VII. User Rights & Remedies

End users have the right to exercise the following rights with respect to their personal data: access, rectification, deletion, restriction of processing, data portability, and withdrawal of consent. Users may contact us through the following channels to exercise these rights:

Privacy Contact Email: privacy@melokea.com
Response Timeframe: We will respond to all legitimate requests within 15 business days of receipt.

VIII. Contact Information & Signatures

The following table sets forth the designated personnel responsible for data protection, privacy compliance, and security incident response:

Role Name Email Phone
Primary Contact (Legal Representative) LINGLING SHANG admin@melokea.com +86 17055060013
SP-API Integration Contact LINGLING SHANG admin@melokea.com +86 17055060013
IMPOC Kenny impoc@melokea.com
Privacy Officer Lisa privacy@melokea.com
Data Protection Officer (DPO) Lisa privacy@melokea.com

Declaration

We hereby declare that all information provided above is true, accurate, and complete. We further commit to promptly updating this Statement and notifying Amazon of any material changes to the information set forth herein.

Legal Representative / Developer Signature: __________________
Printed Name: LINGLING SHANG
Title: Legal Representative
Date: _2026_ Year _08_ Month __01_ Day
Sortieren nach:
Es wurden keine Produkte gefunden, die Ihrer Auswahl entsprechen.