Privacy Policy

1. Scope and Compliance

This Privacy Policy describes how Shopping Sutra LLC ("Company", "we", "us") manages data through the EcomDataIQ platform. We strictly adhere to the Amazon Data Protection Policy (DPP) and Acceptable Use Policy (AUP). Our infrastructure is designed by enterprise architects to ensure that data integrity and brand sovereignty remain our highest priorities.

2. Data Minimization & PII Exclusion

In alignment with Amazon's security requirements, EcomDataIQ is architected to be "PII-Blind." We do not request, ingest, or store Personally Identifiable Information (PII) such as customer names, shipping addresses, or phone numbers. Our API requests are limited to anonymized catalog performance, inventory counts, and advertising attribution metrics. Any customer-identifiable metadata inadvertently received is automatically purged at the ingress point before reaching persistent storage.

3. Isolated Architecture & Storage

We utilize a "Siloed Ingress" methodology within our Google BigQuery data warehouse. Every unique brand or Selling Partner account is provisioned with a physically isolated dataset. This ensures that data from one entity can never be co-mingled or accessed by another, providing a level of security synonymous with institutional financial exchanges.

  • Encryption in Transit: All data moving from Amazon APIs to our environment is protected via TLS 1.3 encryption.
  • Encryption at Rest: All stored data is protected by AES-256 Google-managed encryption keys.
  • Access Control: Administrative access is restricted to Shopping Sutra LLC executives via Multi-Factor Authentication (MFA).

4. Incident Response Plan (SIRP)

Shopping Sutra LLC maintains a documented Security Incident Response Plan. In the event of a suspected security anomaly or unauthorized access, our protocol dictates the immediate rotation of all API Client Secrets, isolation of affected BigQuery datasets, and mandatory notification to Amazon Developer Support within 24 hours.