Data Access & Restriction Policy
How ReddStudio accesses, processes, and protects Amazon Selling Partner data. Aligned with the Amazon Marketplace Developer Agreement and Acceptable Use Policy (sections 4.4 and 4.5).
Last updated: February 18, 2026
1. Data We Access
ReddStudio requests access to the following Amazon SP-API resources, limited to the minimum necessary for our service:
Catalog Items API
Product title, bullet points, features, and category data. Used to auto-fill the product brief when sellers import an ASIN.
Listings Items API
Listing image submission. Used to push generated listing images directly to a seller's Amazon listing after approval.
Brand Analytics
Search term reports including search frequency rank, click share, and purchase share. Used to identify high-converting keywords that inform AI-generated listing visuals and A+ Content.
Data We Do NOT Access
- Order data or fulfillment information
- Financial reports, settlements, or revenue data
- Customer personally identifiable information (PII)
- Inventory or supply chain data
- Advertising or sponsored product data
- Buyer messaging or communication data
2. Access Restrictions
Access to Amazon Selling Partner information is restricted based on role and business function:
Sellers (End Users)
Each seller can only access data from their own authenticated Amazon Seller Central account. There is no cross-account data access. A seller cannot view, modify, or access any other seller's data through our platform.
Developers (Engineering Team)
Developer access to raw Amazon API responses is limited to the engineering team and restricted to debugging and incident resolution. All developer access is logged with timestamps and purpose. Developers do not have standing access to production API data.
AI Models
Amazon data (product information, keyword reports) is provided to AI models only during active generation sessions. Data is session-scoped and not retained by the AI model after the session completes. No Amazon data is used to train or fine-tune AI models.
No Third-Party Sharing
Amazon Selling Partner data is never sold, shared with, disclosed to, or made accessible to any third party. This includes analytics providers, advertising networks, data brokers, and any other external entity.
3. Data Retention & Deletion
OAuth Tokens
SP-API refresh tokens are encrypted at rest using Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256). Tokens are stored only for the duration of the seller's active connection and are permanently deleted when the seller disconnects their Amazon account.
Brand Analytics Data
Search term reports and keyword performance data are session-scoped. Data is fetched on-demand when a seller initiates a generation workflow and is not stored permanently. Generated outputs (listing images, A+ modules) are retained as user content; the underlying Amazon analytics data used to inform generation is not.
User-Initiated Deletion
Sellers can disconnect their Amazon Seller Central account at any time from the Settings page. Disconnecting immediately deletes the stored refresh token and any cached API data. Users can also delete their entire ReddStudio account, which removes all associated data including generated outputs and project history.
4. Security Measures
Transport Security
All communication with Amazon SP-API and between our services uses TLS 1.2 or higher. No Amazon data is transmitted over unencrypted channels.
API Authentication
SP-API requests are signed using AWS Signature Version 4. OAuth tokens are managed through Amazon's Login with Amazon (LWA) authorization flow.
Encryption at Rest
Sensitive credentials (SP-API refresh tokens) are encrypted using Fernet (AES-128-CBC). The encryption key is stored as an environment variable, separate from the database.
Infrastructure Isolation
Application infrastructure runs on Railway with environment-level isolation between staging and production. Database access is restricted to application services only.
5. User Consent & Control
Explicit Authorization
Sellers must explicitly connect their Amazon Seller Central account through the OAuth authorization flow. ReddStudio does not access any Amazon data until the seller completes this authorization. The OAuth consent screen clearly describes the data scopes being requested.
Disconnect at Any Time
Sellers can disconnect their Amazon account from the Settings page at any time. Disconnecting immediately revokes our access and deletes all stored tokens. No background data access occurs after disconnection.
No Background Access
ReddStudio only accesses Amazon data when the seller actively initiates an action (importing an ASIN, pulling keyword data, pushing images to a listing). There are no scheduled background jobs, automated data pulls, or passive data collection.
6. Contact
For questions about this policy, data access practices, or to request data deletion, contact us at:
support@reddstudio.ai