Security & Marketplace Compliance
Last Updated: September 2026
At getsellerfeedback (operated by GetSeller Suite Limited), security, data protection, and platform compliance are built into every layer of our infrastructure. We maintain strict technical and organizational safeguards to ensure compliance with the Amazon Selling Partner API (SP-API) Data Protection Policy (DPP), eBay REST API Developer Standards, and international privacy frameworks (UK/EU GDPR & US CCPA).
1100% Marketplace Policy Compliance
- Official API Integration: All review requests are dispatched strictly through official, sanctioned platform endpoints (such as the Amazon SP-API ‘solicitReview’ endpoint and eBay messaging APIs). We never use unofficial scrapers or risky automation workarounds.
- Strict Prohibited Practices Enforcement: We strictly prohibit sentiment gating, positive review filtering, incentivized ratings, or promotional upsells inside automated messages. All suppression rules are built purely on objective operational metrics (e.g., order age, delivery status, refund state).
2Data Encryption & Key Management
- Encryption in Transit: All traffic between clients, our servers, and marketplace endpoints is encrypted using TLS 1.2 / TLS 1.3 protocols with modern cryptographic cipher suites.
- Encryption at Rest: Sensitive credentials, database records, and OAuth access/refresh tokens are encrypted using AES-256 encryption before storage.
- Key Management: Encryption keys are stored separately from encrypted payloads using dedicated hardware security modules (HSM) and managed key service infrastructure with strict key rotation policies.
3Network Security & Access Control
- Least Privilege Principle: Production system access is strictly restricted to authorized engineering personnel using role-based access control (RBAC) and hardware-backed multi-factor authentication (MFA).
- Network Isolation: Database instances and internal application servers run within isolated Virtual Private Clouds (VPC) protected by firewall rules and zero-trust ingress policies.
- Session Security: Administrative access logs and system activities are continuously logged, monitored, and audited for anomalous behavior.
4Amazon SP-API PII Handling & Automated Purging
- Data Minimization: We only fetch buyer and order metadata strictly necessary to execute compliant post-purchase review requests.
- Automated PII Sanitization: Customer Personally Identifiable Information (PII) fetched via marketplace APIs is retained only for the window required to perform compliance verification and trigger review requests, after which PII fields are automatically purged in full alignment with Amazon SP-API Data Protection Policies.
5Infrastructure Reliability & Monitoring
- High Availability: Hosted on enterprise-grade cloud infrastructure providing global redundancy, continuous uptime monitoring, and automated failover capabilities.
- Rate Limit Protection: Automated queue management prevents API throttling, ensuring smooth and compliant dispatch volumes that respect marketplace rate limits.
6Incident Response & Responsible Disclosure
- Incident Management: In the event of a confirmed security incident impacting user credentials or data, GetSeller Suite Limited maintains a formal incident response plan to notify affected users and regulatory bodies within statutory timeframes (e.g., within 72 hours under UK/EU GDPR).
- Vulnerability Reporting: Security researchers and customers can report potential security concerns or disclosures directly to our team at: support@getsellersuite.com.