Legal

Privacy Policy

Last updated: September 25, 2025

Wilen Consulting respects your privacy. This document explains data collection, usage, storage, protection, sharing, and deletion practices, including Amazon Selling Partner API data, across our services, applications, and websites.

1. Information We Collect

  • Amazon Information: Orders, listings, inventory, pricing, fulfillment, and restricted personal details permitted by Amazon roles (shipping labels, tax information).
  • Business/Account Data: Client contact information, billing details, and configuration settings.
  • Website Data: Form submissions and support inquiries.
  • Technical/Log Data: IP addresses, device information, user agents, audit logs, and event records.

2. How We Use Information

  • Deliver integrations, automations, reporting, and analytics for authorized sellers.
  • Process Amazon data exclusively for seller-authorized purposes aligned with Amazon's Data Protection Policy.
  • Enable security, auditing, abuse detection, and regulatory compliance.
  • We do not sell or use Amazon Information for advertising or marketing.

3. Sharing of Information (AUP 4.6)

  • Amazon data transfers only to systems authorized by the Selling Partner (ERPs, WMS platforms like NetSuite, Extensiv, SellerCloud).
  • Secure sub-processors support service delivery (AWS hosting, monitoring, email systems); all undergo compliance vetting.
  • We never disclose Amazon Information to unrelated third parties.

4. Storage & Protection

  • Encryption in transit using TLS 1.2+ and at rest using AES-256.
  • Segmented networks, firewalls, intrusion detection/prevention systems, endpoint protection, and multi-factor authentication.
  • No hardcoded secrets; keys stored securely.
  • Fully isolated test and production environments.

5. Access Management & Least Privilege

  • Unique employee/contractor accounts; shared credentials prohibited.
  • Role-based access control ensures minimum necessary permissions.
  • Quarterly access reviews; removal within 24 hours of departure.
  • Access tied to HR records for individual employee identification.
  • Amazon data cannot reside on personal devices.

6. Credential Management

  • Minimum 12-character passwords requiring uppercase, lowercase, numbers, and special characters.
  • Password reuse prevented; rotation required every 90 days minimum.
  • Multi-factor authentication mandatory for administrative accounts.
  • API keys encrypted at rest; never stored in code or public repositories.

7. Logging & Monitoring

  • Centralized, tamper-evident logs record authentication events, access attempts, data modifications, and errors.
  • Retention minimum 90 days; daily review with real-time alerts for anomalies (unusual request rates, canary record access).

8. Vulnerability Management

  • Secure configuration standards and routine patching protocols.
  • Static code analysis before release; vulnerability scanning at minimum 180-day intervals.
  • High-severity issues remediated within 30 days.
  • All issues tracked to resolution.

9. Incident Response & Risk Management

  • Documented response plans covering detection, containment, eradication, recovery, and root-cause analysis.
  • Amazon notification at [email protected] occurs within 24 hours of security incidents involving Amazon data.
  • Client notification follows legal or contractual requirements.
  • Plans reviewed every 6 months and after significant changes.

10. Data Retention & Deletion

  • Amazon personal information retained maximum 30 days post-delivery unless legally required (tax compliance).
  • Deletion follows NIST 800-88 standards.
  • Data removal within 30 days of Amazon request; production instances cleared within 90 days with deletion certification available.

11. Your Rights

  • You may request access, correction, or deletion of your data as required by law. Contact [email protected] or visit our contact page.