Amazon Privacy Policy
Privacy and Data Handling Policy — Amazon SP-API Integration
Last Updated: July 2026 Company: Ugurlar Grup
This Privacy and Data Handling Policy describes how Ugurlar Grup ("we", "us", "our") collects, processes, stores, uses, shares, and disposes of Amazon Information, including Personally Identifiable Information (PII), obtained through the Amazon Selling Partner API (SP-API).
1. Data Collection We collect Amazon order data including buyer name, shipping address, phone number, and order details exclusively through the SP-API. Data is collected only when an order is placed and retrieved by our internal ERP system.
2. Data Processing Collected data is processed within our private, self-hosted Odoo ERP system for the sole purposes of: generating shipping labels, fulfilling orders via local carriers, and generating legally required tax invoices (e-Fatura).
3. Data Storage All Amazon Information is stored in an encrypted PostgreSQL database using AES-256 encryption at rest. The database resides in a private, non-public subnet with restricted firewall access.
4. Data Usage PII is used exclusively for order fulfillment and tax invoicing. It is never used for marketing, advertising, profiling, or any purpose beyond the original fulfillment scope.
5. Data Sharing We do NOT share, sell, rent, or disclose Amazon Information to any third parties, marketing agencies, or external organizations. All data remains strictly within our closed-loop ERP system.
6. Data Retention and Disposal PII is retained for no longer than 30 days after order shipment. After this period, all PII is permanently and irreversibly deleted from our primary databases and encrypted backups using cryptographic erasure methods.
7. Incident Response In the event of a data breach, we will isolate affected systems, revoke compromised credentials, and notify Amazon at security@amazon.com within 24 hours of detection.
8. Contact Incident Management Point of Contact (IMPOC): eticarettr@ugurlargrup.com