Integration

Amazon Selling Partner Integration

SDKECOMSOLUTION allows authorized sellers to connect applicable Amazon seller operations using the Amazon Selling Partner API (SP-API).

SDKECOMSOLUTION integrates with Amazon through SP-API. HAFA LTD does not claim Amazon endorsement, certification, or partnership unless separately authorized.

How the connection works

When a seller chooses to connect their Amazon account, SDKECOMSOLUTION uses Amazon’s authorization flow to obtain an access token for the seller’s account. SDKECOMSOLUTION then calls SP-API endpoints that the seller has authorized so it can support inventory, order, fulfilment, and shipping workflows in a centralized interface.

  • Seller initiates connection from within SDKECOMSOLUTION
  • Seller authorizes permissions for applicable SP-API scopes
  • Access tokens are stored and used to call SP-API on the seller’s behalf
  • Seller can revoke authorization, which stops API access

Authorization (OAuth) summary

Authorization is performed through an Amazon-provided OAuth/consent flow. SDKECOMSOLUTION only accesses SP-API data for accounts that have explicitly authorized the application.

We do not request or store seller login passwords. Authentication is handled by Amazon’s authorization mechanisms.


Data categories processed via SP-API

Depending on enabled features and authorized scopes, SDKECOMSOLUTION may process the following categories of data obtained from Amazon SP-API for the purpose of providing the service:

📦 Inventory Data

What's collected: SKUs, quantities on hand, availability status, listing attributes and product details.

Why: To centralize inventory visibility and synchronize stock levels to reduce overselling.

📋 Order Data

What's collected: Order identifiers, order status, line items, pricing/amounts, order timestamps.

Why: To import and manage Amazon orders from a centralized dashboard.

👤 Customer & Shipping Information

What's collected: Shipping recipient names, addresses, and other order fields needed for fulfillment and shipping.

Why: To support fulfillment and shipping operations for Amazon orders.

📬 Shipment & Tracking

What's collected: Shipment identifiers, carrier information, tracking numbers, dispatch confirmations.

Why: To manage shipments and keep Amazon updated with shipping status and tracking info.

🔑 Account Identifiers

What's collected: Seller account IDs and marketplace context.

Why: To call the correct SP-API endpoints for your Amazon account.


Data Flow: How Your Amazon Data Flows Through SDKECOMSOLUTION

  1. You authorize: You initiate Amazon connection from SDKECOMSOLUTION and grant permissions via Amazon's OAuth screen.
  2. We receive: Amazon provides an access token that we securely store.
  3. We fetch: SDKECOMSOLUTION calls Amazon SP-API endpoints to fetch inventory, orders, shipment data, etc.
  4. We store: Data is stored in encrypted form in production systems with restricted access.
  5. We display: You see your Amazon data in SDKECOMSOLUTION's dashboard alongside other channel data.
  6. We sync updates: When you make changes in SDKECOMSOLUTION (like shipment confirmations), we send updates back to Amazon.
  7. You can revoke: At any time, you can disconnect your Amazon account or revoke access, stopping all future data collection.

Why SDKECOMSOLUTION processes Amazon data

Amazon SP-API data is used to provide core functionality requested by the seller, including:

  • Importing orders for centralized processing and operational visibility
  • Supporting fulfilment and shipping workflows, including shipment and tracking updates
  • Synchronizing inventory availability to reduce inconsistent stock across channels
  • Generating operational reporting related to orders, inventory, fulfilment, and shipping

Access controls and security

Access to SP-API data is restricted to authorized accounts and governed by application-level access controls. Data is protected with encryption in transit and encryption at rest in production storage systems, and access is limited to personnel with a legitimate business need.

For a broader overview of controls, see Security & Data Protection.


Revoking Authorization

You have full control over your Amazon data access. You can revoke SDKECOMSOLUTION's authorization at any time by:

  • Disconnecting your Amazon account from SDKECOMSOLUTION settings (if available)
  • Using Amazon's authorization management tools to revoke access
  • Contacting us for assistance with revocation

Once revoked: SDKECOMSOLUTION stops calling SP-API immediately and cannot access your Amazon data.

Data Retention & Deletion

How long we keep your Amazon data: We retain Amazon-derived data only as long as needed for operational use (e.g., order history, inventory records), dispute resolution, and compliance obligations.

30-day deletion rule: For applicable Amazon SP-API data categories, we delete your Amazon-derived data within 30 days of authorization revocation or a valid deletion request, in compliance with Amazon's policies.

How to request deletion:

  • Email info@hafaa.co.uk with your account details
  • Specify which data you want deleted (or request full Amazon data deletion)
  • We'll confirm receipt and process within 30 days (or per required timeframe)
Read full Privacy Policy with Amazon data handling details

Need help with SP-API connection setup?

Contact HAFA LTD for guidance on prerequisites, authorization scopes, and integration configuration for your Amazon seller account.

Contact Us