Datenschutzerklärung

Privacy Policy

In dieser Datenschutzerklärung erläutern wir, wie wir personenbezogene Daten verarbeiten, wenn Sie unsere Website besuchen oder unsere Dienste nutzen. Sie können Ihre Datenschutzeinstellungen jederzeit anpassen oder widerrufen. Bei Fragen wenden Sie sich gerne an uns.

Verantwortlicher

Ewald-Moser – Sellerfun GbR
Langestr. 10
D-34590 Wabern
Deutschland

Geschäftsführer: Kristian Ewald
E‑Mail: info [at] sellerfun [dot] de
Telefon: +49 7672-341099

Amazon Selling Partner Data Processing

This section is provided in English to comply with the Amazon Selling Partner API Data Protection Policy.

1. Data Collection

Sellerfun collects data from sellers who use our e-commerce management software through the Amazon Selling Partner API (SP-API). The types of data we collect include:

  • Order Information: Order IDs, order status, order items, quantities, prices, shipping details, and buyer shipping addresses (solely for fulfillment purposes).
  • Product & Inventory Data: ASINs, SKUs, product titles, descriptions, pricing information, stock levels, and product condition.
  • Financial Data: Settlement reports, fee breakdowns, refund information, and transaction details necessary for accounting and invoicing.
  • Seller Account Information: Marketplace IDs, seller IDs, and account-level settings required for API connectivity.
  • Shipping Data: Carrier names, tracking numbers, shipping labels, and delivery status for integrated shipping solutions.
  • Reporting Data: Sales reports, inventory reports, and performance metrics for analytics and business optimization.

We only collect data that is necessary to provide our services and that the seller has explicitly authorized through the Amazon OAuth authorization flow. We do not collect data beyond what is required for the functionality the seller has subscribed to.

2. Data Usage

Data obtained through the Amazon SP-API is used exclusively for the following purposes:

  • Order Management: Processing, tracking, and fulfilling orders placed on Amazon marketplaces.
  • Inventory Management: Synchronizing stock levels across multiple sales channels to prevent overselling.
  • Pricing & Repricing: Adjusting product prices based on market conditions, competition, and seller-defined rules to optimize sales and BuyBox performance.
  • Invoicing & Accounting: Generating legally compliant invoices (including ZUGFeRD e-invoices) and providing financial reporting.
  • Shipping & Logistics: Creating shipping labels, transmitting tracking information, and automating fulfillment workflows.
  • Analytics & Reporting: Providing sellers with performance dashboards, sales analytics, and business insights.
  • Customer Communication: Facilitating buyer-seller communication exclusively through Amazon's approved messaging channels.

We do not use Amazon data for advertising, marketing, or any purpose unrelated to providing our services to the seller. Personally Identifiable Information (PII) of Amazon buyers is used solely for order fulfillment and is never used for direct marketing, resold, or shared outside of the fulfillment process.

3. Data Storage

Amazon Selling Partner data is stored securely with the following measures:

  • Location: All data is stored on servers located within the European Union (Germany), ensuring compliance with EU data protection regulations (GDPR/DSGVO).
  • Database Security: Data is stored in encrypted databases with restricted access. We use industry-standard databases with encrypted connections (TLS/SSL).
  • Access Control: Database access is limited to authorized personnel only, using role-based access control (RBAC) and individual authentication credentials.
  • Backup & Recovery: Regular encrypted backups are maintained to ensure data integrity and availability. Backup data is subject to the same access controls and security measures as production data.
  • Separation of Data: Each seller's data is logically separated and isolated to prevent unauthorized cross-account access.

4. Data Protection

We implement comprehensive security measures to protect Amazon Selling Partner data:

  • Encryption in Transit: All data transmitted between our systems, the Amazon SP-API, and the seller's browser is encrypted using TLS 1.2 or higher.
  • Encryption at Rest: Stored data is encrypted using AES-256 encryption standards.
  • Authentication & Authorization: We use OAuth 2.0 for Amazon SP-API access, with tokens securely stored and regularly rotated. Multi-factor authentication is enforced for administrative access.
  • Network Security: Our infrastructure is protected by firewalls, intrusion detection systems, and DDoS protection. All administrative access requires secure connectivity.
  • Security Headers: Our web application enforces strict HTTP security headers, including HSTS, Content Security Policy (CSP), and X-Content-Type-Options.
  • Monitoring & Logging: We maintain audit logs for data access and system changes. Anomalous activity is monitored and alerted in real time.
  • Employee Training: All employees with access to seller data receive regular training on data protection and security best practices.
  • Incident Response: We maintain a documented incident response plan. In the event of a data breach, affected sellers and Amazon will be notified within 72 hours in accordance with GDPR requirements.

5. Data Sharing

We are committed to protecting the confidentiality of Amazon Selling Partner data:

  • No Sale of Data: We never sell, rent, or trade Amazon Selling Partner data to any third party.
  • No Unauthorized Sharing: Amazon data is never shared with third parties for marketing, advertising, or any purpose unrelated to the services we provide.
  • Service Providers: We may share limited data with essential service providers (e.g., shipping carriers for label generation) only to the extent necessary to fulfill the seller's instructions. All service providers are contractually bound to equivalent data protection standards.
  • Legal Requirements: We may disclose data if required by applicable law, regulation, or valid legal process. In such cases, we will notify the affected seller to the extent legally permitted.
  • Amazon Compliance: We share data with Amazon only as required by the SP-API terms of service and the Selling Partner API Data Protection Policy.

We do not aggregate, anonymize, or de-identify Amazon Selling Partner data for independent use or redistribution.

6. Data Retention & Deletion

We retain Amazon Selling Partner data only for as long as necessary:

  • Active Accounts: Data is retained for the duration of the active service agreement between Sellerfun and the seller.
  • After Account Termination: Upon termination of a seller's account or service agreement, all Amazon SP-API data (including order data, product data, and financial reports) is permanently deleted within 30 days, unless longer retention is required by law (e.g., German tax law requires retention of invoicing data for up to 10 years).
  • PII Minimization: Personally Identifiable Information (PII) of Amazon buyers (such as shipping addresses and buyer names) is automatically purged from our systems within 30 days after the respective order has been fulfilled and the return window has closed, unless retention is legally required.
  • On-Demand Deletion: Sellers may request immediate deletion of their data at any time by contacting us at info [at] sellerfun [dot] de. We will process deletion requests within 10 business days and provide written confirmation.
  • Token Revocation: Upon account termination, all Amazon API access tokens and refresh tokens are immediately and permanently deleted.
  • Backup Deletion: Data in encrypted backups is purged according to the backup retention cycle (maximum 90 days after the primary data is deleted).

7. Contact for Data Protection Inquiries

For any questions, concerns, or requests related to your Amazon Selling Partner data, including data access, correction, or deletion requests, please contact us:

Ewald-Moser – Sellerfun GbR
Attn: Data Protection
Langestr. 10
D-34590 Wabern, Germany
E-Mail: info [at] sellerfun [dot] de
Phone: +49 7672-341099

We will respond to all data protection inquiries within 30 days.

Allgemeine Datenschutzerklärung (DSGVO)

Die folgenden Abschnitte betreffen die allgemeine Nutzung unserer Website gemäß der Datenschutz-Grundverordnung (DSGVO).

Hosting

Unsere Website wird von der ispOne business GmbH in Deutschland gehostet. Der Hoster verarbeitet Verbindungsdaten, um die technische Funktion zu gewährleisten und die Betriebssicherheit zu erhöhen. Rechtsgrundlage ist unser berechtigtes Interesse an einer sicheren und effizienten Bereitstellung unseres Angebots gemäß Art. 6 Abs. 1 lit. f DSGVO.

Server Log Files

Beim Aufruf unserer Website werden bestimmte Daten wie IP‑Adresse, Zeitpunkt des Zugriffs, aufgerufene Ressource, Referrer und Browser‑Informationen erfasst und in Server‑Logfiles gespeichert. Diese Daten dienen der Fehleranalyse und Sicherheit, werden nicht personenbezogen ausgewertet und nach 30 Tagen gelöscht. Rechtsgrundlage ist das berechtigte Interesse an der Funktionsfähigkeit der Website.

Kontaktformular

Wenn Sie unser Kontaktformular nutzen, verarbeiten wir die von Ihnen eingegebenen Daten (z. B. Name, E‑Mail‑Adresse, Nachricht) ausschließlich zur Bearbeitung Ihrer Anfrage. Die Verarbeitung erfolgt mit Ihrer Einwilligung (Art. 6 Abs. 1 lit. a DSGVO) und kann von Ihnen jederzeit widerrufen werden. Ohne Angabe Ihrer Daten können wir Ihre Anfrage nicht beantworten.

Registrierung / Testzugang

Sofern Sie sich für einen Testzugang registrieren oder einen Vertrag mit uns abschließen möchten, verarbeiten wir die hierfür erforderlichen Daten (z. B. Name, Kontaktdaten, Firmeninformationen). Die Verarbeitung dient der Anbahnung oder Erfüllung eines Vertragsverhältnisses gemäß Art. 6 Abs. 1 lit. b DSGVO.

Cookies und Tools

Unsere Website setzt technisch erforderliche Cookies ein, um grundlegende Funktionen wie die Navigation zu gewährleisten. Darüber hinaus nutzen wir optionale Tools (z. B. Analyse‑ oder Marketing‑Cookies) nur mit Ihrer ausdrücklichen Einwilligung. Rechtsgrundlage hierfür ist Art. 6 Abs. 1 lit. a DSGVO in Verbindung mit § 25 TTDSG. Sie können Ihre Auswahl jederzeit anpassen.

Sicherheitsdienste (Cloudflare Turnstile)

Zur Vermeidung von Spam und automatisierten Eingaben setzen wir Cloudflare Turnstile ein. Hierbei können Cookies gesetzt und Verbindungsdaten erhoben werden. Daten können auf Servern von Cloudflare verarbeitet werden. Rechtsgrundlage ist Ihre Einwilligung; ohne diese Einwilligung können manche Formulare nicht genutzt werden.

Widerspruchsrecht

Wenn wir Ihre Daten auf Grundlage unseres berechtigten Interesses verarbeiten, haben Sie das Recht, dieser Verarbeitung zu widersprechen. Bei begründetem Widerspruch stellen wir die Verarbeitung ein. Sie können auch der Verarbeitung Ihrer Daten für Zwecke der Direktwerbung jederzeit widersprechen; in diesem Fall werden Ihre Daten nicht mehr zu diesem Zweck verwendet.

Widerrufsrecht

Sie haben das Recht, eine bereits erteilte Einwilligung jederzeit mit Wirkung für die Zukunft zu widerrufen. Nach dem Widerruf werden Ihre Daten nicht mehr auf Grundlage dieser Einwilligung verarbeitet, sofern keine andere Rechtsgrundlage besteht.

Rechte der betroffenen Personen

Sie haben das Recht auf Auskunft über Ihre bei uns gespeicherten personenbezogenen Daten, das Recht auf Berichtigung, Löschung oder Einschränkung der Verarbeitung sowie auf Datenübertragbarkeit. Zudem können Sie sich bei der zuständigen Aufsichtsbehörde beschweren, wenn Sie der Ansicht sind, dass die Verarbeitung Ihrer Daten nicht rechtmäßig erfolgt.