Data & security

A defined purpose.
A clear security standard.

Our requirements for protecting seller information throughout its lifecycle.

The following security policy defines W & F TRADING LLC’s requirements for handling seller information. SP-API functionality is enabled only after Amazon approval and explicit seller authorization through Amazon OAuth.

Authorized access

Access must use individual identities, least privilege and MFA. The access policy requires quarterly reviews and revocation within 24 hours of departure. Passwords require at least 12 characters, mixed character types and an expiry no longer than 365 days.

Encryption & credentials

Seller information must use TLS 1.2 or higher in transit. Stored service data, backups and credentials require encryption, with keys held separately in managed key storage. Secrets must not be embedded in code or public repositories.

Network & vulnerability controls

Production systems require firewalls, segmentation, intrusion detection or prevention and anti-malware controls. Vulnerability scans must run monthly; critical and high-risk findings require remediation within seven and 30 days respectively.

Incident response

The incident response policy requires an assigned response owner, documented escalation procedures, review of security and access logs for suspicious activity, and a review of the response plan every six months. Incidents involving Amazon information must be reported to security@amazon.com within 24 hours of discovery, with required customer and authority notices.

Purpose & retention

Collect only information needed for the agreed workflow. The retention policy governs operational data, security records and backup deletion. Deletion must be tested and remain effective after recovery.

Provider oversight

External processors require a documented purpose, access review and contractual protections before receiving seller data. Connected-service processing locations and providers must be disclosed before onboarding.

Seller control

Authorize. Review.
Disconnect.

Each seller controls their own Amazon authorization. The service must stop account access when that authorization is revoked. Requests about data access or deletion can be sent to info@worthharvest.com.

Read the privacy policy ↗