Last updated: July 2, 2026
This Privacy Policy describes how Xiamen Yunzhongcheng Technology Co., Ltd. ("we", "us", or "our") collects, uses, stores, and protects data when you use Notice123 (the "Service"). The Service is a SaaS application that helps Amazon sellers manage inventory and track order events through the Amazon Selling Partner API (SP-API).
By using the Service, you agree to the practices described in this Privacy Policy. This policy is designed to comply with the Amazon Acceptable Use Policy (AUP), Data Protection Policy (DPP), and applicable regional privacy regulations including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
Summary: We only access data from your authorized Amazon seller account through the SP-API. We do not access buyer PII, do not aggregate data across sellers, and do not sell or share your Amazon data with any third party. All data is encrypted in transit and at rest.
We access data from your Amazon seller account exclusively through the Amazon Selling Partner API, and only after you have explicitly authorized our application via Amazon's OAuth workflow. The data we access includes:
We explicitly do not access or process:
When you request access to Notice123, we collect your email address, name, and company information for onboarding and communication purposes only. This data is used to process your access request and manage your subscription.
We use the data accessed through the SP-API solely for the following purposes:
We do NOT use Amazon data for: marketing, advertising, buyer targeting, review fabrication, cross-seller aggregation, insights about Amazon's business, or any purpose other than providing the inventory and order management features described above.
All Amazon Information is retrieved exclusively through the Amazon Selling Partner API. We do not retrieve Amazon Information from any external or non-Amazon sources. We do not use any external data services that vend Amazon Information.
We do not share, sell, rent, lease, or otherwise distribute Amazon Information to any third party. Amazon Information accessed through the SP-API is processed solely within our application infrastructure to provide the Service to the authorized seller.
We do not aggregate data across different sellers' businesses or Amazon customers. Each seller's data is processed independently within a multi-tenant isolated architecture.
All data transmitted between our systems and Amazon SP-API, and between our systems and your browser, is encrypted using TLS 1.2 or higher. Insecure communication channels are disabled. All internal and external endpoints enforce encryption in transit.
All Amazon Information stored in our systems is encrypted at rest using AES-256 encryption. Encryption keys are managed through a dedicated Key Management System (KMS) and are accessible only to authorized application processes. SP-API credentials and secret keys are encrypted and never stored in plain text, in public repositories, or hard-coded into applications.
Access to Amazon Information is governed by the following controls:
We implement firewalls, Access Control Lists (ACLs) to deny unauthorized IP access, intrusion detection and prevention systems (IDS/IPS), anti-virus and anti-malware protection on all endpoints, and network segmentation to isolate Amazon Information processing systems. Controls are in place to prevent the disabling of anti-virus and anti-malware software.
We maintain a vulnerability management program that includes:
We retain data only for as long as necessary to provide the Service:
Upon receiving a deletion request from Amazon, we will permanently and securely delete or return all Amazon Information within 72 hours of notification. All online and network-accessible instances of Amazon Information will be deleted within 90 days. Upon request, we will provide written certification that all Amazon Information has been securely destroyed.
When a seller revokes authorization or terminates their subscription, we will cease accessing their Amazon data immediately and delete all associated Amazon data within 30 days, as described in our Terms of Service.
Data destruction follows NIST SP 800-88 standards, including:
All active data stores and all backups/copies are destroyed. Data anonymization (e.g., hashing of PII) is not considered an acceptable deletion method. When using cloud services, we use supported deletion mechanisms (such as delete APIs or TTL policies); simply removing object pointers or orphaning data is not accepted.
We maintain an incident response plan that is:
We have designated an Incident Management Point of Contact (IMPOC) who is available at all times, has the authority to coordinate incident response activities, and can be reached quickly in the event of a data breach or security incident. The IMPOC's contact information (name, email, phone) is provided to Amazon and kept up to date.
Any security incident involving Amazon Information will be reported to security@amazon.com within 24 hours of detection. We will investigate each security incident and document the incident description, remediation actions, and corrective processes or system controls implemented to prevent recurrence. All incident documentation will be provided to Amazon upon request.
We maintain procedures for notifying government agencies as required by applicable law. We will notify Amazon within 24 hours if Amazon Information is requested through legal process. During a security incident, we will not communicate on behalf of Amazon to regulators or customers unless Amazon provides written authorization.
As an authorized seller, you have the following rights under applicable data protection regulations, including the GDPR (for EU/EEA residents) and CCPA/CPRA (for California residents):
To exercise any of these rights, contact us at contact@yzccn.com. We will respond to your request within 30 days. If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
Our application complies with the following Amazon policies:
We use cloud infrastructure providers to host and run the Service. These providers act as data processors and are bound by confidentiality agreements. They do not have access to Amazon Information beyond what is necessary for infrastructure maintenance. All third-party subcontractors are subject to third-party risk assessments before engagement.
We do not use any external (non-Amazon) data services that vend Amazon Information.
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the Service at least 30 days before the changes take effect. The updated policy will be effective immediately upon posting after the notice period.
If you have any questions about this Privacy Policy or our data practices, please contact us: