Notice123
  • Features
  • How It Works
  • Data Boundaries
  • Security
  • Pricing
  • FAQ
  • Privacy
  • Terms
  • Support
Request Access

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy describes how Xiamen Yunzhongcheng Technology Co., Ltd. ("we", "us", or "our") collects, uses, stores, and protects data when you use Notice123 (the "Service"). The Service is a SaaS application that helps Amazon sellers manage inventory and track order events through the Amazon Selling Partner API (SP-API).

By using the Service, you agree to the practices described in this Privacy Policy. This policy is designed to comply with the Amazon Acceptable Use Policy (AUP), Data Protection Policy (DPP), and applicable regional privacy regulations including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Summary: We only access data from your authorized Amazon seller account through the SP-API. We do not access buyer PII, do not aggregate data across sellers, and do not sell or share your Amazon data with any third party. All data is encrypted in transit and at rest.

1. Data We Access

1.1 Amazon Seller Data

We access data from your Amazon seller account exclusively through the Amazon Selling Partner API, and only after you have explicitly authorized our application via Amazon's OAuth workflow. The data we access includes:

  • Inventory data: FBA inventory levels, SKU quantities, and inventory status information
  • Order status data: Order identifiers, order status (Pending, Shipped, Delivered), and order item quantities
  • Listing data: SKU identifiers and listing status for inventory management purposes

1.2 Data We Do NOT Access

We explicitly do not access or process:

  • Personally Identifiable Information (PII) about Amazon customers, including names, addresses, email addresses, phone numbers, or payment details
  • Buyer communication messages or buyer feedback
  • Financial or banking information
  • Data from Amazon's public-facing websites
  • Data from external (non-Amazon) sources about Amazon Information

1.3 Contact and Onboarding Data

When you request access to Notice123, we collect your email address, name, and company information for onboarding and communication purposes only. This data is used to process your access request and manage your subscription.

2. How We Use Data

We use the data accessed through the SP-API solely for the following purposes:

  • Inventory management: Displaying your Amazon inventory levels and calculating stock consumption
  • Inventory risk alerts: Monitoring inventory against your configured thresholds and sending alerts when stock is low
  • Order notifications: Detecting order status changes and notifying you in real time
  • Cancellation alerts: Detecting buyer-initiated cancellation requests and alerting you promptly
  • Order-triggered workflows: Recalculating inventory consumption when order events are received

We do NOT use Amazon data for: marketing, advertising, buyer targeting, review fabrication, cross-seller aggregation, insights about Amazon's business, or any purpose other than providing the inventory and order management features described above.

3. Data Sources

All Amazon Information is retrieved exclusively through the Amazon Selling Partner API. We do not retrieve Amazon Information from any external or non-Amazon sources. We do not use any external data services that vend Amazon Information.

4. Data Sharing

We do not share, sell, rent, lease, or otherwise distribute Amazon Information to any third party. Amazon Information accessed through the SP-API is processed solely within our application infrastructure to provide the Service to the authorized seller.

We do not aggregate data across different sellers' businesses or Amazon customers. Each seller's data is processed independently within a multi-tenant isolated architecture.

5. Data Security

5.1 Encryption in Transit

All data transmitted between our systems and Amazon SP-API, and between our systems and your browser, is encrypted using TLS 1.2 or higher. Insecure communication channels are disabled. All internal and external endpoints enforce encryption in transit.

5.2 Encryption at Rest

All Amazon Information stored in our systems is encrypted at rest using AES-256 encryption. Encryption keys are managed through a dedicated Key Management System (KMS) and are accessible only to authorized application processes. SP-API credentials and secret keys are encrypted and never stored in plain text, in public repositories, or hard-coded into applications.

5.3 Access Controls

Access to Amazon Information is governed by the following controls:

  • Unique user IDs: Every individual accessing Amazon Information is assigned a unique identifier. Generic, shared, or default login credentials are prohibited.
  • Role-based access control: Access is granted based on job duties and business functions following the principle of least privilege (need-to-know basis).
  • Quarterly access reviews: Personnel and service access lists are reviewed at least every 90 days. Accounts no longer requiring access are promptly removed.
  • Multi-Factor Authentication (MFA): MFA is enforced for all internal systems that may come into contact with Amazon Information.
  • Account lockout: Accounts are automatically locked after 10 unsuccessful login attempts.
  • Password policy: Passwords must be at least 12 characters with a mix of uppercase, lowercase, numbers, and special characters. Password history of the last 10 passwords is maintained to prevent reuse. Passwords are rotated at least annually.
  • API key rotation: SP-API keys and application credentials are rotated periodically per our key management policy.
  • No personal device storage: Employees and contractors are prohibited from storing Amazon Information on personal devices.

5.4 Network Security

We implement firewalls, Access Control Lists (ACLs) to deny unauthorized IP access, intrusion detection and prevention systems (IDS/IPS), anti-virus and anti-malware protection on all endpoints, and network segmentation to isolate Amazon Information processing systems. Controls are in place to prevent the disabling of anti-virus and anti-malware software.

5.5 Vulnerability Management

We maintain a vulnerability management program that includes:

  • Vulnerability scanning: Conducted at least every 180 days across all systems processing Amazon Information
  • Penetration testing: Conducted at least every 365 days by qualified security professionals
  • Pre-release code scanning: Automated vulnerability scans are run before every production release
  • Remediation timelines: Critical vulnerabilities are remediated within 7 days; high-severity vulnerabilities within 30 days
  • Geo-distributed backups: Encrypted backups are maintained in geographically distributed locations

6. Data Retention

We retain data only for as long as necessary to provide the Service:

  • Amazon PII data: If any PII is inadvertently received, it is deleted within 30 days of order delivery. PII is not stored beyond this period except where required by applicable law, in which case it is stored as an encrypted offline backup in a physically secure facility.
  • Non-PII Amazon Information: Retained for a maximum of 18 months from the date of collection, unless a longer retention period is required by applicable law.
  • System logs: Security and access logs are retained for a minimum of 12 months to support audit and incident investigation requirements.
  • Contact and onboarding data: Your contact information (email, name, company) is retained for the duration of your active subscription and deleted within 30 days of subscription termination.

7. Data Deletion and Destruction

7.1 Deletion Upon Amazon Request

Upon receiving a deletion request from Amazon, we will permanently and securely delete or return all Amazon Information within 72 hours of notification. All online and network-accessible instances of Amazon Information will be deleted within 90 days. Upon request, we will provide written certification that all Amazon Information has been securely destroyed.

7.2 Deletion Upon Seller Revocation

When a seller revokes authorization or terminates their subscription, we will cease accessing their Amazon data immediately and delete all associated Amazon data within 30 days, as described in our Terms of Service.

7.3 Destruction Standards

Data destruction follows NIST SP 800-88 standards, including:

  • Clear: Overwriting data with zeros or random patterns
  • Purge: Firmware-level erasure or cryptographic key destruction
  • Physical destruction: Shredding, crushing, or incineration of physical media when applicable

All active data stores and all backups/copies are destroyed. Data anonymization (e.g., hashing of PII) is not considered an acceptable deletion method. When using cloud services, we use supported deletion mechanisms (such as delete APIs or TTL policies); simply removing object pointers or orphaning data is not accepted.

8. Incident Response

8.1 Incident Response Plan

We maintain an incident response plan that is:

  • Approved by senior management and reviewed at least every 6 months
  • Updated after significant infrastructure or system changes, and after lessons learned from any incident
  • Covers all standard phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned

8.2 Incident Management Point of Contact (IMPOC)

We have designated an Incident Management Point of Contact (IMPOC) who is available at all times, has the authority to coordinate incident response activities, and can be reached quickly in the event of a data breach or security incident. The IMPOC's contact information (name, email, phone) is provided to Amazon and kept up to date.

8.3 24-Hour Notification

Any security incident involving Amazon Information will be reported to security@amazon.com within 24 hours of detection. We will investigate each security incident and document the incident description, remediation actions, and corrective processes or system controls implemented to prevent recurrence. All incident documentation will be provided to Amazon upon request.

8.4 Legal and Regulatory Notifications

We maintain procedures for notifying government agencies as required by applicable law. We will notify Amazon within 24 hours if Amazon Information is requested through legal process. During a security incident, we will not communicate on behalf of Amazon to regulators or customers unless Amazon provides written authorization.

9. Your Rights — GDPR, CCPA, and Regional Privacy Laws

As an authorized seller, you have the following rights under applicable data protection regulations, including the GDPR (for EU/EEA residents) and CCPA/CPRA (for California residents):

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete personal data
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data from our systems
  • Right to restrict processing: Request that we limit the processing of your personal data
  • Right to object: Object to the processing of your personal data for certain purposes
  • Right to data portability: Receive your personal data in a structured, machine-readable format
  • Right to revoke authorization: Disconnect Notice123 from your Amazon account at any time through Amazon Seller Central

To exercise any of these rights, contact us at contact@yzccn.com. We will respond to your request within 30 days. If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.

10. Compliance with Amazon Policies

Our application complies with the following Amazon policies:

  • Acceptable Use Policy (AUP): We use SP-API data only for acceptable Amazon seller activities and only for sellers who have authorized us
  • Data Protection Policy (DPP): We follow specific requirements for the receipt, storage, usage, transfer, and disposition of data accessed through the SP-API, including encryption, access controls, data retention, deletion, and incident response
  • Solution Provider Agreement: We adhere to the terms of the Amazon Services API Solution Provider Agreement

11. Third-Party Services

We use cloud infrastructure providers to host and run the Service. These providers act as data processors and are bound by confidentiality agreements. They do not have access to Amazon Information beyond what is necessary for infrastructure maintenance. All third-party subcontractors are subject to third-party risk assessments before engagement.

We do not use any external (non-Amazon) data services that vend Amazon Information.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the Service at least 30 days before the changes take effect. The updated policy will be effective immediately upon posting after the notice period.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • General inquiries: contact@yzccn.com
  • Security incidents: security@yzccn.com
  • Phone: +86 186-0591-8653
  • Address: Xiamen Yunzhongcheng Technology Co., Ltd., Xiamen, Fujian, China
Notice123

Real-time inventory and order event management SaaS for Amazon sellers. Built with the Amazon Selling Partner API.

A product of Xiamen Yunzhongcheng Technology Co., Ltd.

Product

  • Features
  • How It Works
  • Pricing
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Support

Contact

contact@yzccn.com security@yzccn.com +86 186-0591-8653 Xiamen, Fujian, China
© 2025-2026 Xiamen Yunzhongcheng Technology Co., Ltd. All rights reserved.
Notice123 is an independent application and is not affiliated with or endorsed by Amazon. "Amazon" and related marks are trademarks of Amazon.com, Inc. or its affiliates.