Skip to main content

Security and Compliance

Effective 2 September 2026. Last reviewed 2 September 2026.

About this page

Datarova is built and operated by Advanced Seller Pty Ltd (ABN 95 628 246 355) and its related entity Datarova LLC. This page explains what Amazon data we access, why we access it, how we protect it, and how we meet the policies Amazon sets for solution providers that use the Selling Partner API (SP-API) and the Amazon Ads API. It sits alongside our Privacy Policy and Terms & Conditions.

What Datarova does

Datarova is an Amazon product research and rank tracking platform. Most of what you see in Datarova comes from public marketplace information and our own models. When you connect your Amazon seller account, we use the Selling Partner API to keep the ASINs you track in Projects current, for example when prices change or variations are added or removed. Our Amazon Ads integration, currently in beta for a limited group of customers, reads advertising performance data through the Amazon Ads API under the same rules described on this page.

How we get access to your Amazon account

  • You authorise us. We access an Amazon account only after its owner authorises Datarova through Amazon's own authorisation flow for SP-API and for Amazon Ads. We never ask for your Seller Central login, your Amazon Ads login, or your own API keys, and we will not accept them if offered.
  • We ask for the minimum. We request only the API roles and scopes our features need. We do not request roles we do not use.
  • You can revoke at any time. Remove Datarova from Seller Central under Apps & Services, or from your Amazon Ads account. We stop pulling new data immediately, and revocation starts the deletion timeline described below.
  • We protect the credentials. Refresh tokens and application credentials are encrypted at rest and readable only by the services that need them. Access tokens expire one hour after issue. We rotate our application client secrets every 180 days, as Amazon requires, and immediately on any suspected compromise. Refresh tokens are revoked the moment you disconnect Datarova.

Data we do not access

Datarova does not request or store Amazon customer personal information. We do not use Restricted Data Tokens and we do not retrieve buyer names, shipping addresses, phone numbers, email addresses, or payment details. Datarova is not a shipping, tax, or fulfilment tool, so it has no need for this data.

How we use your Amazon data, and how we don't

We use your Amazon data to provide the Datarova features you use and, as our Terms & Conditions allow, to operate, support, and improve Datarova.

We do not:
  • combine one seller's API data with another's, or provide or sell aggregated API data to anyone;
  • sell, rent, license, or share your Amazon data with anyone, other than the infrastructure providers named on this page that store or carry it for us, and the legal, regulatory, and business-transfer disclosures described in our Privacy Policy;
  • use Amazon data to market to Amazon customers, to solicit or alter reviews, or to profile, surveil, or discriminate against anyone;
  • use, offer, or promote any external data service that resells data retrieved from Amazon;
  • publish or use insights about Amazon's own business;
  • combine Amazon Ads data with third-party data sources without Amazon's written approval;
  • use Amazon data or API materials to train or improve large language models or other machine learning models.

Every record we hold from Amazon's APIs carries the account it came from, so its origin is always attributable, and authorisation checks at the application and database layer keep each account's data separate from every other account's.

If we learn that a customer is using Datarova to breach their agreement with Amazon, we suspend their access and report it to Amazon.

Being clear about what you see

Figures such as search volume, sales estimates, and rank trends are produced by Datarova's own models from public marketplace data. They are estimates, not values reported by Amazon. Data we read from your Amazon account is shown as Amazon provides it, and we never alter it.

Security controls

Encryption

All connections use TLS 1.2 or higher. Databases, object storage, backups, and secrets are encrypted at rest with AES-256. Keys are held in AWS Key Management Service, restricted to our own services, and rotated at least once a year.

Infrastructure and network

Datarova runs on Amazon Web Services, with Cloudflare in front of every public hostname. Security groups, network access control lists, and network segmentation separate internet-facing services from databases and internal systems, and the database accepts connections only from our application servers. A web application firewall with managed rule sets and rate limiting sits in front of every internet-facing endpoint, and our servers accept traffic only through Cloudflare. Threat detection runs continuously across the AWS account. We keep network architecture diagrams and evidence of these controls for review.

Identity and access

Every person has a unique account. There are no shared, generic, or default accounts, and every service account has a named owner. Multi-factor authentication is required on every account with access to production systems or Amazon data. Access is denied by default and granted on a need-to-know basis, at the minimum level needed for the role. Accounts lock after ten failed login attempts. Passwords are at least 12 characters, mixed case with numbers and symbols, cannot reuse the last ten, and expire within 365 days. We review who has access at least quarterly, and remove access within 24 hours of a role change or departure.

Who can access your data

Access to Amazon data inside Datarova is limited to a single named administrator with a documented business need. That person completes data protection and security awareness training every year, is bound by confidentiality obligations, and works only from a company-managed device with full-disk encryption, endpoint protection, and automatic screen lock after 15 minutes. Amazon data is never accessed from unmanaged personal devices or stored on removable media. If the team grows, every new person goes through the same access approval, training, and device controls before they can see any Amazon data.

Secure development

Credentials never live in source code. Secrets sit in a managed secrets store. Every change is reviewed before merge, dependencies and code are scanned for vulnerabilities before each release, and test and production environments are fully separate. Changes follow a documented process with testing and approval by someone other than the author. Our integration stays within Amazon's API usage limits, and we monitor and correct errors on our side of the connection.

Logging and monitoring

We keep centralised logs of authentication, data access, data changes, and system errors, with timestamps and the identity behind each event. Logs are protected from tampering, contain no customer personal information, are reviewed through automated alerting, and are retained for at least 30 days. Alerts fire on unusual request rates, unusual data retrieval volumes, and unauthorised API calls, and every alert is investigated and documented.

Vulnerability management

Our servers and container images are scanned for vulnerabilities continuously, and code and dependencies are scanned before each release. Critical findings are fixed within 7 days and high-risk findings within 30 days.

Backups and recovery

Databases are backed up automatically every day to encrypted storage. Backup copies expire on their own fixed schedule shortly after the live data is deleted, and never more than 30 days after it, so deleted data does not linger in backups. We maintain documented recovery time and recovery point objectives and test restores on a schedule.

Risk management

We run a documented risk assessment covering threats, likelihood, impact, and remediation, reviewed by company leadership at least once a year.

Retention and deletion

We keep your Amazon data only for as long as it is needed to provide the features you use, and to meet legal, tax, or regulatory obligations. When you disconnect your Amazon account, close your Datarova account, or Amazon asks us to delete, we permanently delete your Amazon data from all live systems within 30 days. If a legal, tax, or regulatory obligation requires us to keep a specific record beyond that point, we keep only that record, only for as long as the obligation lasts, and delete it when the obligation ends. Backup copies expire on their own fixed schedule within a further 30 days at most. Deletion uses provider deletion APIs and follows industry-standard sanitisation guidance (NIST 800-88). We can provide written confirmation of deletion on request.

Where your Amazon data is processed

Your Amazon account data is stored and processed on Amazon Web Services. Cloudflare carries the encrypted traffic between your browser and our servers, and does not store your Amazon data. No other provider receives your Amazon data in the ordinary operation of Datarova. The only exceptions are the legal, regulatory, and business-transfer disclosures described in our Privacy Policy, which apply to all personal information we hold. Providers that handle your Datarova account, billing, and support details are listed in our Privacy Policy. Every provider we use is bound by written terms that include confidentiality and data protection obligations.

Incident response

We maintain a written incident response plan that defines roles, incident types, escalation paths, and evidence handling. We review it every six months and after any major change to our systems, and we have a named incident management point of contact. If we detect a security incident involving Amazon data, we notify Amazon at [email protected] within 24 hours of detection, notify affected customers without undue delay, and notify regulators where the law requires it. We investigate every incident, document the cause and the fix, and keep the evidence available for Amazon to review.

Reporting a security issue

If you believe you have found a vulnerability in Datarova, or suspect Amazon data has been misused, email [email protected] with "Security" in the subject line. We acknowledge reports within two business days, keep you informed while we investigate, and fix confirmed issues according to the severity timelines above. We will not take legal action against anyone who reports in good faith and avoids accessing other people's data.

Privacy law

We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles, and with the GDPR, UK GDPR, and applicable US state privacy laws where they apply to our customers. We keep a record of the data we process and why. To request deletion of your Amazon data or your Datarova account, email [email protected] and we will complete it within the 30-day window described above, subject to the same legal retention exception. Our Privacy Policy explains your access, correction, and complaint rights and how to exercise them.

Amazon policy compliance

Datarova is a registered Amazon Selling Partner API solution provider and an Amazon Ads API developer.

We comply with:

We review each Amazon policy update when it is announced and adjust our controls and this page. We tell Amazon within 30 days of any organisational change that affects our need for or use of Amazon data. We cooperate fully with Amazon security audits and assessments, and remediate any finding within the agreed timeframe. We keep Amazon's non-public information confidential.

Independence

Datarova is an independent product. Amazon, Amazon Ads, and all related marks are trademarks of Amazon.com, Inc. or its affiliates. Datarova is not affiliated with, sponsored by, or endorsed by Amazon.

Contact

Security, compliance, and support: [email protected]
Advanced Seller Pty Ltd (ABN 95 628 246 355)