← Trust Center & Legal
API & Integrations

Marketplace Developer Data Protection Statement

How Ecom10x meets Amazon's Data Protection Policy and Flipkart's API licence obligations as a registered developer.

Company: EcomSarthi Business Solutions LLP ("EcomSarthi", "we", "us", "our")
Product: Ecom10x — One Dashboard. Every Marketplace. (the "Platform" or "Service")
Effective Date: 31 August 2026 · Version: 1.0 · Next Review: 28 February 2027

1. Purpose and Scope

This Statement describes how EcomSarthi Business Solutions LLP, as the developer of Ecom10x, handles information obtained through marketplace developer programmes — the Amazon Selling Partner API (SP-API) and the Flipkart Seller API. It is written for marketplace review teams and supplements our [Privacy Policy](/legal/privacy-policy), [Security Policy](/legal/security-policy) and [API Terms of Use](/legal/api-terms-of-use).

Ecom10x is a seller-facing analytics and operations tool. We access a marketplace only on the instruction of the seller who owns that account, and only for the features that seller has enabled.

2. What we actually collect

We deliberately keep the smallest footprint that still produces a correct profit and loss statement:

CategoryCollectedNotes
Order and shipment recordsYesOrder reference, date, status, SKU, quantity, price, delivery state, courier
Settlement, fee and tax recordsYesCommission, shipping, reverse shipping, GST, TCS, TDS, payouts
Listing, price and inventoryYesSKU, listing identifier, price, stock
Returns recordsYesReturn type, reason, associated order
Advertising performanceYesCampaign, targeting, spend, sales
Buyer nameOnly from seller-uploaded filesNever requested from an API; the API sync stores an empty buyer record
Buyer email, phone, full addressNoNot requested, not parsed, not stored
Payment instrumentsNoNever collected in any form

Because we do not collect buyer contact details or addresses, the personally identifiable information reaching our systems is limited to a buyer name present in files the seller chooses to upload. Delivery state is retained for tax and logistics analysis; it is not combined with a name to identify an individual.

3. Retention and deletion

  • Personally identifiable information is retained only as long as needed for the seller-requested purpose, and no longer than the period permitted by the relevant marketplace programme, except where Indian tax or accounting law requires a longer period. Where law requires retention, the record is kept for that legal purpose alone.
  • Marketplace OAuth, access and refresh tokens are deleted within 24 hours of a seller disconnecting an account.
  • A seller may delete an imported file, an account, or their entire workspace at any time; deletion removes the derived records with it. See the [Data Deletion Policy](/legal/data-deletion-policy).
  • Backups are encrypted and rotate on a defined schedule; deletions propagate as backups age out.

4. Encryption

  • In transit: TLS 1.2 or higher for all connections, including every call to marketplace APIs.
  • At rest: databases and backups are encrypted at rest. Marketplace credentials, OAuth tokens and provider secrets are additionally encrypted at the application layer with AES-256-GCM before they are written, so they are unreadable in a database dump.
  • Secrets are never rendered back in full in the interface, never written to logs, and never included in exports.

5. Access control

  • Role-based access with five roles and per-client scoping; every query is scoped to the requesting organisation, so cross-tenant access is denied by design.
  • Least privilege for staff and service components; production data access is restricted, logged and reviewed.
  • Multi-factor authentication (TOTP, RFC 6238, with single-use backup codes) is available on every account and enforced as a step-up challenge at sign-in, including for federated sign-in. Accounts that can reach production or customer data are expected to keep it enabled.
  • Passwords are a minimum of 12 characters and must include upper and lower case letters, a number and a special character. They expire after 365 days and must be rotated, and are stored only as salted adaptive hashes (bcrypt). Repeated failed sign-ins are throttled per account and per source.
  • Access for departing personnel is revoked within 24 hours of termination or role change.

6. Logging, monitoring and incident response

  • Security-relevant and destructive actions are written to an audit log retained for at least 12 months, separately from business data.
  • Suspected incidents follow our [Incident Response Policy](/legal/incident-response-policy).
  • Marketplace notification: where an incident involves information obtained through a marketplace API, we notify that marketplace's security contact within 24 hours of detection — for Amazon, security@amazon.com — in addition to notifying affected customers and any regulator required under Indian law.

7. Vulnerability management and key rotation

  • Dependencies are monitored and updated; critical-risk vulnerabilities are remediated within 7 days and high-risk within 30 days of discovery.
  • Application credentials and encryption keys are rotated at least annually, and immediately on suspected or confirmed compromise.
  • Security reports are welcome under our [Vulnerability Disclosure Policy](/legal/vulnerability-disclosure-policy).

8. Permitted use and restrictions

Information obtained through a marketplace API is used only to provide the requesting seller with the features they enabled — reconciliation, profit and loss, inventory, returns, tax packs and advertising analysis.

We do not:

  • sell, rent, licence or otherwise disclose marketplace information to any third party for that party's own purposes;
  • combine one seller's data with another's, or expose one seller's data to another, in any feature, benchmark or report;
  • use marketplace information to compete with the marketplace or with the seller;
  • retain information after the seller disconnects, beyond what law requires;
  • transfer information to a subprocessor outside the list published in our [Subprocessor Policy](/legal/subprocessor-policy).

9. Artificial intelligence

Where a seller uses our AI assistant, the request sent to the model provider is scoped to that seller's own workspace and is scrubbed of identifiers before it leaves our systems. Model providers are engaged as subprocessors under terms that prohibit training on our customers' data. See the [AI Usage Policy](/legal/ai-usage-policy).

10. Marketplace relationship

Ecom10x is an independent product of EcomSarthi Business Solutions LLP. Amazon, Flipkart, Meesho and other marketplace names are trademarks of their respective owners. We are not affiliated with, endorsed by, or acting as an agent of any marketplace. Each marketplace's own terms continue to govern the seller's relationship with that marketplace.

Governing Law & Dispute Resolution

This document is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, without regard to conflict-of-law principles.

Any dispute arising out of or in connection with this document shall first be attempted to be resolved amicably through good-faith negotiation within thirty (30) days of written notice. Failing amicable resolution, the dispute shall be referred to arbitration by a sole arbitrator appointed in accordance with the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be [JURISDICTION_CITY — e.g., New Delhi], India, and proceedings shall be conducted in English. Subject to the foregoing, the courts at [JURISDICTION_CITY — e.g., New Delhi], India shall have exclusive jurisdiction.

Contact

EcomSarthi Business Solutions LLP
[REGISTERED_OFFICE_ADDRESS OF ECOMSARTHI BUSINESS SOLUTIONS LLP]
Support: support@ecom10x.com · Legal: legal@ecom10x.com · Phone: [SUPPORT_PHONE_NUMBER]