Security & Data Handling Policy
Last Updated: June 14, 2026
At ECOMZIER LLC, security and responsible data handling are core parts of how we design, operate, and maintain our website, agency services, Shopify applications, Amazon integration services, and related software products.
This Security & Data Handling Policy explains the administrative, technical, and operational safeguards we use to protect merchant data, customer data, Amazon Information, Shopify data, marketplace data, and other information processed through our Services.
1. Purpose of This Policy
The purpose of this policy is to describe how Ecomzier protects data throughout its lifecycle, including collection, processing, storage, access, transmission, retention, deletion, monitoring, and incident response.
This policy applies to Ecomzier's website, Shopify applications, Amazon Shopify Connector, marketplace integrations, internal systems, support operations, and related services.
2. Data We Protect
Depending on the Services used by a merchant, Ecomzier may process different types of data, including:
-
Merchant account information
-
Store name and store domain
-
Product, listing, SKU, inventory, price, and catalog data
-
Order, fulfillment, shipping, and tracking data
-
App configuration and synchronization settings
-
Support communications and diagnostic logs
-
Shopify data authorized by the merchant
-
Amazon Information authorized through Amazon Selling Partner API (SP-API)
-
Amazon buyer Personally Identifiable Information (PII), where required for authorized order fulfillment and Direct to Consumer Shipping functionality
Amazon buyer PII may include:
-
Buyer name
-
Shipping address
-
Phone number (where provided)
-
Order details
-
Shipment details
-
Related fulfillment information
3. Data Processing Purpose
Ecomzier processes merchant and platform data only for legitimate business and service-related purposes, including:
-
Operating and maintaining our Services
-
Synchronizing products, listings, inventory, orders, fulfillment, shipment, and tracking data
-
Creating Shopify orders from authorized marketplace orders
-
Supporting merchant-authorized order management
-
Troubleshooting synchronization or app issues
-
Providing customer support
-
Maintaining security and preventing unauthorized access
-
Complying with applicable laws, platform policies, and contractual obligations
Amazon buyer PII is used only for:
-
Legitimate order fulfillment
-
Shipping
-
Merchant-authorized order management
-
Customer support
-
Compliance with Amazon policies and applicable law
Amazon buyer PII is not used for advertising, marketing, profiling, resale, unrelated analytics, or any unrelated commercial purpose.
4. Infrastructure Security
Ecomzier uses secure cloud infrastructure and controlled technical environments to operate its Services.
Infrastructure safeguards may include:
-
Secure cloud hosting environments
-
Private and restricted network configurations
-
Firewall and network access controls
-
Encrypted storage systems
-
Secure API communication
-
Controlled administrative access
-
System monitoring and security alerting
-
Backup and recovery procedures
Where Amazon Information or sensitive merchant data is processed, Ecomzier applies additional safeguards to reduce the risk of unauthorized access, disclosure, alteration, or destruction.
5. Encryption and Credential Security
Ecomzier uses encryption and secure credential handling practices to protect sensitive data.
Security safeguards may include:
-
Encryption in transit using TLS 1.2 and TLS 1.3
-
AES-256 encryption for sensitive data at rest, including databases storing Amazon buyer PII
-
Encryption keys managed through AWS Key Management Service (KMS)
-
API credentials and secrets stored securely using AWS Secrets Manager
-
Restricted access to API credentials and tokens
-
Credential rotation where required by policy, platform requirements, or security procedures
Amazon SP-API credentials, Restricted Data Tokens (RDT), and related access credentials are handled with additional care and are never publicly exposed.
6. Access Control
Access to merchant data, customer data, Amazon Information, Shopify data, marketplace data, and internal systems is restricted to authorized personnel who require access for legitimate business purposes and follows the principle of least privilege.
Ecomzier applies:
-
Role-Based Access Control (RBAC)
-
Multi-Factor Authentication (MFA) for administrative access
-
Need-to-know access restrictions
-
Unique user credentials for authorized personnel
-
Restricted access to production systems
-
Periodic review of access permissions
-
Removal or restriction of access when no longer required
Employees and contractors with access to sensitive systems are expected to follow confidentiality, security, and data handling requirements.
7. Amazon SP-API and Amazon Information Security
For merchants who authorize Ecomzier to connect with Amazon Seller Central through Amazon Selling Partner API (SP-API), Ecomzier processes Amazon Information only within the scope of permissions granted by the merchant and required to provide the authorized service.
Where required for Direct-to-Consumer Shipping and merchant-fulfilled order processing, Ecomzier accesses Amazon buyer PII using Restricted Data Tokens (RDT).
Amazon buyer PII is protected through:
-
Restricted access controls
-
Encryption
-
Security monitoring
-
Secure storage
-
Defined retention limits
Amazon buyer PII is not sold, rented, traded, disclosed to advertisers, or used for unrelated commercial purposes.
8. Data Retention and Deletion
Ecomzier retains data only as long as necessary to:
-
Provide the authorized service
-
Maintain merchant account functionality
-
Troubleshoot issues
-
Meet security requirements
-
Comply with platform policies
-
Satisfy legal obligations
Amazon Buyer PII
All Amazon buyer Personally Identifiable Information (PII) is permanently and automatically deleted within 30 days of confirmed order delivery.
This deletion is irreversible once the retention period expires and is performed in compliance with Amazon's Data Protection Policy.
Amazon Non-PII Data
Amazon non-PII data, including order, product, and account information that does not identify buyers, is retained only as necessary to provide services and maintain functionality.
Unless a longer retention period is required by law, Amazon non-PII data is retained for no longer than 18 months.
When data is no longer required, Ecomzier deletes, anonymizes, or renders the information unavailable for identification.
9. Monitoring and Audit Logging
Ecomzier maintains monitoring and audit logging practices designed to detect:
-
Suspicious activity
-
Unauthorized access
-
System errors
-
Potential security incidents
Access to Amazon Information is logged and monitored through security audit logs.
Logs are protected against unauthorized access or modification and are configured to avoid storing Amazon buyer PII unless required for security, legal, compliance, or incident investigation purposes.
10. Vulnerability Management
Ecomzier works continuously to identify, assess, and remediate security vulnerabilities.
Practices include:
-
Security monitoring
-
Dependency and software updates
-
Patch management
-
Infrastructure and application risk reviews
-
Investigation of reported vulnerabilities
-
Remediation of critical and high-risk issues
-
Security reviews before major application or infrastructure changes
11. Device and Personnel Security
Ecomzier restricts access to sensitive data and production systems to authorized personnel and approved working environments.
Safeguards include:
-
Access only through secured accounts
-
MFA for administrative tools
-
Restricted access to sensitive systems
-
Prohibition on storing Amazon buyer PII on unauthorized personal devices, removable media, or unsecured public storage
-
Access removal when personnel no longer require access
-
Confidentiality obligations for employees and contractors
12. Third-Party Service Providers
Ecomzier may use trusted third-party service providers to operate, host, secure, maintain, monitor, and support our Services.
These providers may include:
-
Cloud infrastructure providers
-
Database providers
-
Payment processors
-
Communication tools
-
Support platforms
-
Analytics providers
-
Monitoring solutions
-
Security service providers
Third-party providers may process data only for authorized purposes and are expected to maintain appropriate contractual, technical, and organizational safeguards.
Amazon buyer PII is never shared with advertising or marketing providers and is disclosed only when necessary to:
-
Provide authorized services
-
Fulfill merchant instructions
-
Support shipping or fulfillment
-
Comply with legal obligations
-
Meet Amazon policy requirements
13. Incident Response
Ecomzier maintains an incident response process to identify, investigate, contain, mitigate, and remediate potential security incidents.
In the event of a confirmed security incident involving Amazon Information, Ecomzier will notify Amazon, affected merchants, and other affected parties as required by applicable Amazon policies and law.
Ecomzier also reviews incidents to:
-
Prevent recurrence
-
Improve security controls
-
Strengthen operational safeguards
14. Backup and Recovery
Ecomzier maintains backup and recovery procedures to support:
-
Service continuity
-
Data integrity
-
Recovery from operational incidents
Backup access is restricted to authorized personnel and protected through appropriate technical and organizational safeguards.
Where backup data includes sensitive information, retention and deletion procedures are designed to align with legal, platform, and security requirements.
15. Merchant Responsibilities
Merchants are responsible for maintaining the security of their own accounts, stores, passwords, devices, staff permissions, and third-party platform access.
Merchants should:
-
Use strong passwords and MFA wherever available
-
Limit staff access to authorized personnel
-
Review app permissions before authorization
-
Remove access for staff who no longer require it
-
Keep Shopify, Amazon, and marketplace account information accurate
-
Notify Ecomzier promptly if unauthorized access or misuse is suspected
16. Relationship With Privacy Policy
This Security & Data Handling Policy should be read together with our Privacy Policy and Terms of Service.
-
The Privacy Policy explains how personal information and platform data are collected, used, stored, shared, and deleted.
-
The Terms of Service explain the rules governing the use of our website, applications, agency services, and integration services.
17. Contact Information
For questions regarding this Security & Data Handling Policy, privacy practices, or Amazon Information handling, please contact:
ECOMZIER LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States
Email: info@ecomzier.com
Phone: +1 437-873-8057
Registration Number (USA): 806210478
