Spartin Global LLC ("Spartin," "we," "us") provides Amazon marketplace management services to consumer product brands. This policy explains what information we handle, why, and how we protect it.
Who we serve
Our services are provided to businesses. The dashboard is available only to brands that have a services agreement with us and to our own staff. There is no public sign-up, and we do not offer services to consumers.
Information we handle
Account information. For each person we give dashboard access, we hold a name, a business email address, and authentication records (sign-in times, and whether multi-factor authentication is enabled). Passwords are set by the user and are never visible to us.
Amazon business data. Where a brand authorizes our application to access its Amazon selling account, we retrieve business performance data belonging to that brand: orders and units by product, product identifiers (SKU and ASIN), product titles, inventory quantities, fulfilment status, and advertising performance.
We do not request, retrieve, or store personal information about Amazon shoppers. We deliberately use the non-personal variant of Amazon's order reports, and we have not requested any Amazon API permission that would give us buyer names, addresses, or contact details.
Website visitors. Our public website collects only what is necessary to operate and secure it.
How we use it
We use Amazon business data for one purpose: to report a brand's own performance back to that brand, and to inform the marketplace management work that brand has engaged us to perform.
We do not sell, rent, or license data. We do not use one client's data to benefit another client. We do not use client data for advertising. We do not use client data to train machine learning or AI models.
Who we share it with
A brand's data is visible to that brand's own authorized users, and to the limited number of named Spartin personnel who manage that account.
No brand can access another brand's data. Every record is tagged to a single brand, and the system determines which brand a signed-in user belongs to from their authenticated session rather than from anything the user's browser can change.
We use two service providers that process data on our behalf:
| Provider | Role | Location |
|---|---|---|
| Render | Application hosting, background processing, and database | United States |
| Clerk | User authentication and access management | United States |
Each is bound by its own contractual security obligations and is reached only over encrypted connections. We do not transfer data to any other third party except where required by law.
How we protect it
- Data is encrypted in transit and at rest.
- Access is restricted by role. Brand users can read only their own organization's data; staff access is limited to named individuals and requires multi-factor authentication.
- API credentials and access tokens are held in a managed secrets store, encrypted with a managed key, and are never placed in source code or source control.
- All retrieval of Amazon data happens on our servers. No Amazon credential or token is ever exposed to a browser.
- We maintain a written incident response plan, reviewed at least every six months.
How long we keep it
We retain a brand's data for as long as our services agreement is in effect.
If a brand revokes our application's authorization, or the engagement ends, we stop retrieving new data immediately and delete the brand's stored data within 30 days, except where we are required to retain records by law. A brand may request deletion at any time by writing to the address below.
Your choices
A brand may revoke our application's access to its Amazon selling account at any time, directly in Amazon Seller Central, without contacting us.
Brands and their authorized users may request access to, correction of, or deletion of information we hold about them. Where a brand's own customers or personnel have rights under applicable law, we will support that brand in responding to such requests.
Security incidents
If we become aware of an incident affecting a brand's data, we will notify that brand promptly, and will notify Amazon within 24 hours of detection where Amazon data is involved.
Changes
We will update this page if our practices change and will revise the effective date above. Material changes affecting existing clients will be communicated directly.