Privacy Policy

Last updated: 2026-04-19

This Privacy Policy describes how YoiYee (operated by Shenzhenshi Canhuan Xinxijishu Youxiangongsi, hereafter “we”, “us”, “our”) collects, processes, stores, uses, shares, and disposes of data obtained through the Amazon Selling Partner API (“SP-API”).

1. Who We Are

YoiYee is a UK-focused Amazon brand owner operating as a sole proprietor. This Privacy Policy applies to data accessed via SP-API for the purpose of managing our own Amazon seller operations. YoiYee is an internal-use tool; we do not offer services to other Amazon sellers and have no public API or multi-tenant architecture.

2. Information We Collect

Through SP-API, we retrieve the following categories of information:

  • Product and listing data: SKUs, ASINs, titles, prices, images, inventory levels
  • Order data: Order IDs, order status, shipping service level, marketplace, item-level details, tracking numbers, IOSS numbers, tax registration details (where provided)
  • Financial data: Amazon settlement reports, referral fees, FBA fulfilment fees
  • Advertising data: Campaign performance, keyword performance, ACOS, spend, sales
  • Buyer Personally Identifiable Information (PII): buyer name, shipping address, contact phone number — obtained via Amazon’s Restricted Data Token (RDT) flow only when required for order fulfilment (shipping label generation or shipping CSV export to contracted logistics carriers)

3. How We Use This Information

  • Internal operations: inventory management, pricing optimisation, sales analysis, advertising optimisation
  • Order fulfilment: generating shipping labels and dispatching orders through contracted logistics carriers
  • Compliance: tax-related record keeping

4. Data Storage and Retention

  • Persisted data: Non-PII data (SKUs, ASINs, order IDs, order status, financial and advertising metrics) is stored in a SQLite database on an AWS Lightsail instance. The underlying storage volume uses AWS platform-level AES-256 encryption.
  • Buyer PII: Buyer PII (name, address, phone) is never persisted to our database. It is retrieved via SP-API RDT only at the moment of use, held in process memory during the shipping label or CSV export flow, and cleared from session state upon flow completion.
  • Backups: Non-PII backups are encrypted (GPG + AES-256) and stored off-site at Cloudflare R2 with 30-day retention. Backups contain no buyer PII.

5. Third-Party Sharing

We share Amazon buyer shipping information with the following contracted logistics carriers solely for the purpose of order fulfilment:

  • 4PX Express (www.4px.com) — buyer name, full shipping address, contact phone, order ID; used to generate shipping labels and deliver orders.
  • SF Express (www.sf-express.com) — same data fields and purpose as above.

Where Amazon’s Buy Shipping API is available, we route shipments through Amazon directly, keeping buyer PII within the Amazon environment. CSV export to external carriers is used only where Buy Shipping does not cover the required route.

We do not share Amazon Information with advertising networks, analytics providers, AI providers (our internal rules specifically exclude buyer PII from any AI prompt), or any other third party.

6. Security

  • In transit: TLS 1.3 for all data transmission
  • At rest: AES-256 storage volume encryption; AES-256-GCM field-level encryption available for sensitive fields
  • Key management: GPG-backed pass key store; RSA-4096 master key; 20-character passphrase held offline in a secure physical location
  • Access control: Single-operator access enforced via SSH Ed25519 key-only, Nginx HTTP Basic Auth (bcrypt), Streamlit loopback-only binding (127.0.0.1)
  • Monitoring: PII access audit logging, daily PII regression canaries, weekly Trivy vulnerability scans, fail2ban SSH brute-force protection

7. Your Rights

You may request access to, correction of, or deletion of any personal data concerning you by contacting us at the address below. We aim to respond within 30 days in accordance with GDPR Article 12. Where the data in question is buyer PII obtained via Amazon SP-API, please note that we do not persist such data, so deletion is automatic.

8. Incident Response

In the event of a data breach affecting Amazon Information, we commit to notifying Amazon Developer Support (security@amazon.com) within 24 hours of confirmed detection, in accordance with the Amazon Data Protection Policy. Affected buyers and regulatory authorities will be notified per GDPR Article 33 (within 72 hours) where applicable.

9. Changes to This Policy

This Privacy Policy may be updated when our data handling practices change. The “Last updated” date at the top of this document reflects the most recent revision. Material changes will be communicated via an updated policy version on this page.

10. Contact

For privacy-related inquiries:

  • Email: amazon@yoiyee.com
  • Organisation: Shenzhenshi Canhuan Xinxijishu Youxiangongsi
  • Country: China