Security & Data Handling Policy

Last Updated: June 14, 2026

At ECOMZIER LLC, security and responsible data handling are core parts of how we design, operate, and maintain our website, agency services, Shopify applications, Amazon integration services, and related software products.

This Security & Data Handling Policy explains the administrative, technical, and operational safeguards we use to protect merchant data, customer data, Amazon Information, Shopify data, marketplace data, and other information processed through our Services.

1. Purpose of This Policy

The purpose of this policy is to describe how Ecomzier protects data throughout its lifecycle, including collection, processing, storage, access, transmission, retention, deletion, monitoring, and incident response.

This policy applies to Ecomzier's website, Shopify applications, Amazon Shopify Connector, marketplace integrations, internal systems, support operations, and related services.

2. Data We Protect

Depending on the Services used by a merchant, Ecomzier may process different types of data, including:

  • Merchant account information

  • Store name and store domain

  • Product, listing, SKU, inventory, price, and catalog data

  • Order, fulfillment, shipping, and tracking data

  • App configuration and synchronization settings

  • Support communications and diagnostic logs

  • Shopify data authorized by the merchant

  • Amazon Information authorized through Amazon Selling Partner API (SP-API)

  • Amazon buyer Personally Identifiable Information (PII), where required for authorized order fulfillment and Direct to Consumer Shipping functionality

Amazon buyer PII may include:

  • Buyer name

  • Shipping address

  • Phone number (where provided)

  • Order details

  • Shipment details

  • Related fulfillment information

3. Data Processing Purpose

Ecomzier processes merchant and platform data only for legitimate business and service-related purposes, including:

  • Operating and maintaining our Services

  • Synchronizing products, listings, inventory, orders, fulfillment, shipment, and tracking data

  • Creating Shopify orders from authorized marketplace orders

  • Supporting merchant-authorized order management

  • Troubleshooting synchronization or app issues

  • Providing customer support

  • Maintaining security and preventing unauthorized access

  • Complying with applicable laws, platform policies, and contractual obligations

Amazon buyer PII is used only for:

  • Legitimate order fulfillment

  • Shipping

  • Merchant-authorized order management

  • Customer support

  • Compliance with Amazon policies and applicable law

Amazon buyer PII is not used for advertising, marketing, profiling, resale, unrelated analytics, or any unrelated commercial purpose.

4. Infrastructure Security

Ecomzier uses secure cloud infrastructure and controlled technical environments to operate its Services.

Infrastructure safeguards may include:

  • Secure cloud hosting environments

  • Private and restricted network configurations

  • Firewall and network access controls

  • Encrypted storage systems

  • Secure API communication

  • Controlled administrative access

  • System monitoring and security alerting

  • Backup and recovery procedures

Where Amazon Information or sensitive merchant data is processed, Ecomzier applies additional safeguards to reduce the risk of unauthorized access, disclosure, alteration, or destruction.

5. Encryption and Credential Security

Ecomzier uses encryption and secure credential handling practices to protect sensitive data.

Security safeguards may include:

  • Encryption in transit using TLS 1.2 and TLS 1.3

  • AES-256 encryption for sensitive data at rest, including databases storing Amazon buyer PII

  • Encryption keys managed through AWS Key Management Service (KMS)

  • API credentials and secrets stored securely using AWS Secrets Manager

  • Restricted access to API credentials and tokens

  • Credential rotation where required by policy, platform requirements, or security procedures

Amazon SP-API credentials, Restricted Data Tokens (RDT), and related access credentials are handled with additional care and are never publicly exposed.

6. Access Control

Access to merchant data, customer data, Amazon Information, Shopify data, marketplace data, and internal systems is restricted to authorized personnel who require access for legitimate business purposes and follows the principle of least privilege.

Ecomzier applies:

  • Role-Based Access Control (RBAC)

  • Multi-Factor Authentication (MFA) for administrative access

  • Need-to-know access restrictions

  • Unique user credentials for authorized personnel

  • Restricted access to production systems

  • Periodic review of access permissions

  • Removal or restriction of access when no longer required

Employees and contractors with access to sensitive systems are expected to follow confidentiality, security, and data handling requirements.

7. Amazon SP-API and Amazon Information Security

For merchants who authorize Ecomzier to connect with Amazon Seller Central through Amazon Selling Partner API (SP-API), Ecomzier processes Amazon Information only within the scope of permissions granted by the merchant and required to provide the authorized service.

Where required for Direct-to-Consumer Shipping and merchant-fulfilled order processing, Ecomzier accesses Amazon buyer PII using Restricted Data Tokens (RDT).

Amazon buyer PII is protected through:

  • Restricted access controls

  • Encryption

  • Security monitoring

  • Secure storage

  • Defined retention limits

Amazon buyer PII is not sold, rented, traded, disclosed to advertisers, or used for unrelated commercial purposes.

8. Data Retention and Deletion

Ecomzier retains data only as long as necessary to:

  • Provide the authorized service

  • Maintain merchant account functionality

  • Troubleshoot issues

  • Meet security requirements

  • Comply with platform policies

  • Satisfy legal obligations

Amazon Buyer PII

All Amazon buyer Personally Identifiable Information (PII) is permanently and automatically deleted within 30 days of confirmed order delivery.

This deletion is irreversible once the retention period expires and is performed in compliance with Amazon's Data Protection Policy.

Amazon Non-PII Data

Amazon non-PII data, including order, product, and account information that does not identify buyers, is retained only as necessary to provide services and maintain functionality.

Unless a longer retention period is required by law, Amazon non-PII data is retained for no longer than 18 months.

When data is no longer required, Ecomzier deletes, anonymizes, or renders the information unavailable for identification.

9. Monitoring and Audit Logging

Ecomzier maintains monitoring and audit logging practices designed to detect:

  • Suspicious activity

  • Unauthorized access

  • System errors

  • Potential security incidents

Access to Amazon Information is logged and monitored through security audit logs.

Logs are protected against unauthorized access or modification and are configured to avoid storing Amazon buyer PII unless required for security, legal, compliance, or incident investigation purposes.

10. Vulnerability Management

Ecomzier works continuously to identify, assess, and remediate security vulnerabilities.

Practices include:

  • Security monitoring

  • Dependency and software updates

  • Patch management

  • Infrastructure and application risk reviews

  • Investigation of reported vulnerabilities

  • Remediation of critical and high-risk issues

  • Security reviews before major application or infrastructure changes

11. Device and Personnel Security

Ecomzier restricts access to sensitive data and production systems to authorized personnel and approved working environments.

Safeguards include:

  • Access only through secured accounts

  • MFA for administrative tools

  • Restricted access to sensitive systems

  • Prohibition on storing Amazon buyer PII on unauthorized personal devices, removable media, or unsecured public storage

  • Access removal when personnel no longer require access

  • Confidentiality obligations for employees and contractors

12. Third-Party Service Providers

Ecomzier may use trusted third-party service providers to operate, host, secure, maintain, monitor, and support our Services.

These providers may include:

  • Cloud infrastructure providers

  • Database providers

  • Payment processors

  • Communication tools

  • Support platforms

  • Analytics providers

  • Monitoring solutions

  • Security service providers

Third-party providers may process data only for authorized purposes and are expected to maintain appropriate contractual, technical, and organizational safeguards.

Amazon buyer PII is never shared with advertising or marketing providers and is disclosed only when necessary to:

  • Provide authorized services

  • Fulfill merchant instructions

  • Support shipping or fulfillment

  • Comply with legal obligations

  • Meet Amazon policy requirements

13. Incident Response

Ecomzier maintains an incident response process to identify, investigate, contain, mitigate, and remediate potential security incidents.

In the event of a confirmed security incident involving Amazon Information, Ecomzier will notify Amazon, affected merchants, and other affected parties as required by applicable Amazon policies and law.

Ecomzier also reviews incidents to:

  • Prevent recurrence

  • Improve security controls

  • Strengthen operational safeguards

14. Backup and Recovery

Ecomzier maintains backup and recovery procedures to support:

  • Service continuity

  • Data integrity

  • Recovery from operational incidents

Backup access is restricted to authorized personnel and protected through appropriate technical and organizational safeguards.

Where backup data includes sensitive information, retention and deletion procedures are designed to align with legal, platform, and security requirements.

15. Merchant Responsibilities

Merchants are responsible for maintaining the security of their own accounts, stores, passwords, devices, staff permissions, and third-party platform access.

Merchants should:

  • Use strong passwords and MFA wherever available

  • Limit staff access to authorized personnel

  • Review app permissions before authorization

  • Remove access for staff who no longer require it

  • Keep Shopify, Amazon, and marketplace account information accurate

  • Notify Ecomzier promptly if unauthorized access or misuse is suspected

16. Relationship With Privacy Policy

This Security & Data Handling Policy should be read together with our Privacy Policy and Terms of Service.

  • The Privacy Policy explains how personal information and platform data are collected, used, stored, shared, and deleted.

  • The Terms of Service explain the rules governing the use of our website, applications, agency services, and integration services.

17. Contact Information

For questions regarding this Security & Data Handling Policy, privacy practices, or Amazon Information handling, please contact:

ECOMZIER LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States

Email: info@ecomzier.com
Phone: +1 437-873-8057
Registration Number (USA): 806210478