eBusiness Services LLC is a registered service provider in Amazon's Solution Provider Portal. This page summarizes how we protect the information we access on behalf of clients. It is a public summary of three internal documents: our SP-API Data Protection Policy, Credential Management Policy and Incident Response Plan (each version [2.0], effective [date], owner [name, title]), which are available to clients and to Amazon on request.
How we access client accounts
- Access is granted by the seller through Amazon's Solution Provider Portal and limited to the roles the seller confirms in Seller Central.
- Each staff member uses their own identity-verified Amazon login. We do not request, store or use seller passwords, shared logins or two-step verification codes.
- Our SPP administrator assigns each staff member only the client accounts and functions their job requires, and removes access within one business day of a role change or departure.
- Access logs are reviewed weekly.
What we protect
Everything Amazon defines as Amazon Information: seller account data, orders, buyer information, inventory, pricing, financial and performance data, and any personally identifiable information (PII) about Amazon customers.
Access control
- Role-based access control across all systems that hold Amazon Information
- Multi-factor authentication mandatory for every user
- Passwords of at least 12 characters with upper and lower case letters, numbers and special characters, unique per system, rotated on a schedule, never reused
- Least-privilege by default; access reviewed quarterly
Systems and network protection
Amazon Information is handled in Microsoft 365 (email and files), Microsoft Dynamics 365 (client records) and [secrets manager]. Public-facing services sit behind Cloudflare. Firewalls restrict traffic to approved services and ports. Endpoint protection is installed on every workstation. Vulnerability scans run every 30 days and penetration testing annually.
Encryption and storage
Data in transit is encrypted with TLS 1.2 or higher; data at rest with AES-256. Amazon Information is never stored on personal devices, in unmanaged cloud storage, in email attachments, or in chat tools. Backups are encrypted.
Retention and deletion
Personally identifiable information is deleted no later than 30 days after order delivery, and sooner once the operational need ends, except where law requires a longer period (for example tax invoices). Non-PII operational data is retained only for the duration of the client engagement and deleted within 30 days of its end. Deletion uses secure, unrecoverable methods.
Credential management
Any credentials used for client work (SPP logins, tool logins, API tokens where a client authorizes a tool) are stored in an encrypted secrets manager, never in documents, code, email or chat. Credentials are rotated on a schedule and immediately if compromise is suspected. Credentials are never shared between staff or with third parties.
Incident response
Our Incident Response Plan covers detection, containment, investigation, eradication, recovery, notification, prevention, documentation and review. Security incidents involving Amazon Information are reported to Amazon at security@amazon.com within 24 hours of detection, and affected clients are informed promptly. Every incident is documented and reviewed to strengthen controls.
Third parties
We do not share Amazon Information with other clients, partners or outside organizations. Service providers that process our data (listed in the Privacy Policy) are bound by contract and security review.
Training and review
All staff complete data protection and incident response training at hiring and annually. These policies are reviewed every six months, after any incident, and whenever Amazon updates its Data Protection Policy.
Organizational changes
We notify Amazon of material organizational changes (ownership, legal name, address, key personnel responsible for security) within 30 days.
Questions about this page: security@elitebusinessllc.org.
