Privacy Policy — Amazon SP-API Data

Effective date: May 28, 2026
Last update: May 28, 2026
Data controller: Raven Industries (sole proprietorship), France

1. Scope of this policy

This privacy notice describes how Raven Industries collects, processes, stores, shares and disposes of personal data obtained via the Amazon Selling Partner API (SP-API), including order data covered by the Direct-to-Consumer Shipping and Tax Invoicing roles.

2. Data we collect from Amazon SP-API

For each Amazon order routed through our fulfillment workflow, we receive and process:

  • Customer name (buyer name)
  • Postal shipping address (street, postal code, city, country)
  • Customer email address
  • Phone number (when provided by the buyer)
  • Order line items, quantities, totals
  • Billing address (for invoicing)
  • Order identifiers (Amazon order ID, marketplace ID, ASIN, SKU)

3. Lawful basis for processing

  • Contract performance (GDPR Art. 6.1.b): delivery of purchased goods.
  • Legal obligation (Art. 6.1.c): invoicing and accounting records (French CGI Art. 289 — mandatory 10-year retention for invoices only).

4. Purpose of processing

PII is used exclusively for:

  • Generating shipping labels with our carrier (Colissimo / La Poste).
  • Routing orders to the correct dispatch zone and carrier service tier.
  • Sending shipment tracking notifications to the buyer.
  • Generating compliant tax invoices.
  • Processing returns and refunds.

PII is never used for marketing, analytics, profiling, or shared with third parties beyond what is described in §6.

5. Storage and security

  • Encryption at rest: sensitive PII fields (name, address, email, phone) are encrypted at the application layer using AES-256-GCM (libsodium, authenticated encryption with AAD context binding) before being written to MySQL.
  • Key management: encryption keys stored in SOPS-encrypted configuration files using age (X25519 + ChaCha20-Poly1305), with the master key held offline and rotated annually.
  • Encryption in transit: TLS 1.3 for all transport.
  • Access control: single-operator access via 2FA (Authelia TOTP + WebAuthn). Database access restricted to localhost and the internal Docker network.
  • Backups: restic-encrypted (AES-256), local + offsite (Backblaze B2 EU datacenter).
  • Hosting location: dedicated server in France.

6. Sharing

PII is shared only with:

  • Colissimo (La Poste) — for shipping label generation. Strictly limited to data needed for delivery.
  • French tax authorities — only invoice data, when legally required.

No data is shared with marketing networks, analytics providers, AI services, or any third-party processor.

7. Retention

  • Order PII: automatically purged 30 days after order completion.
  • Invoice records: retained 10 years (mandatory French law — CGI Art. L102B).
  • Audit logs of API access: 18 months.
  • Sentry exception data: 90 days, PII redacted before storage.

A monthly automated purge script removes expired records.

8. Data subject rights (GDPR Chapter III)

Data subjects can exercise the following rights by emailing security@ravenindustries.fr:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Portability (Art. 20)
  • Objection (Art. 21)

Response within 30 days. Free of charge unless manifestly unfounded.

Right to lodge a complaint with the CNIL (French Data Protection Authority) — https://www.cnil.fr/en/plaintes

9. Incident notification

In case of personal data breach:

  • Amazon: security@amazon.com within 24 hours.
  • CNIL: within 72 hours (GDPR Art. 33).
  • Affected data subjects: without undue delay when high risk to rights/freedoms is identified (GDPR Art. 34).

10. Contact

Incident Management Point of Contact (IMPOC):
HASNA GATOUFI
security@ravenindustries.fr
+33 7 68 88 52 93 (available 24/7 for security incidents)

Data controller:
Raven Industries
Email: contact@ravenindustries.fr


Une version française de cette politique est disponible ici.