Security & Data Protection
Last updated: July 28, 2026
Jam Group 18 LLC maintains physical, administrative, and technical safeguards designed to protect the information we access, store, use, and transmit. Our program is built to meet the requirements of Amazon's Data Protection Policy (DPP) and Acceptable Use Policy (AUP), and to protect Amazon sellers and their customers' information.
We do not process Amazon customer PII for our services. Our platform provides analytics, reporting, and advertising optimization using performance, catalog, inventory, advertising, and store-analytics data. We do not require, use, or retain personally identifiable information about Amazon customers for marketing or any other non-permitted purpose, and we never target Amazon customers using data obtained through Amazon's APIs.
1. Authorized access only
- We access a seller's Amazon data only after the seller grants explicit third-party authorization through Amazon's official Login with Amazon (OAuth) flow.
- We never request, accept, or store Amazon usernames, passwords, or another provider's access keys.
- Sellers may revoke access at any time through their Amazon account.
- We request only the data and roles necessary for the application's functionality, on a need-to-know basis.
2. Identity and access management
- Each person with access to information is assigned a unique ID; we do not use shared, generic, or default accounts.
- Access follows the principle of least privilege and is granted strictly on a need-to-know basis.
- Multi-factor authentication (MFA) is required for accounts with access to information.
- Password policy: minimum 12 characters with mixed character types, enforced expiration and history, and account lockout after repeated failed attempts.
- Access is reviewed on a regular basis, and access for departing personnel is removed promptly.
3. Encryption
- In transit: all information is encrypted using TLS 1.2+ (and equivalent secure protocols) across internal and external endpoints.
- At rest: information is encrypted at rest using industry-standard strong encryption (AES-256) on reputable cloud infrastructure, with managed key handling.
- Encryption keys are restricted to our authorized processes and services.
4. Network protection
- Network firewalls and access-control lists restrict access to authorized sources only.
- Data stores are not publicly accessible; access is mediated through controlled application layers.
- We use monitoring and intrusion-detection practices, and keep anti-malware protections current.
5. Data minimization, attribution, and segregation
- We collect only the information required to deliver the service and retrieve nothing beyond what is necessary.
- Information is attributed to its source so that each seller's data can be identified and isolated.
- We do not aggregate data across sellers to provide to, or sell to, any third party, including competing sellers.
6. Retention and deletion
- We retain information only as long as needed to provide the service and to meet legal obligations.
- Upon Amazon's or a seller's request to delete, we securely delete the relevant information within the timeframes required by Amazon's policies, using industry-standard sanitization methods.
- Non-PII data is not retained beyond the periods permitted by policy and applicable law.
7. Logging and monitoring
- We log security-relevant events — access attempts, data changes, and system errors — across the channels that provide access to information.
- Logs are access-controlled to prevent unauthorized access and tampering, retained for reference in the event of an incident, and do not contain customer PII.
- We monitor activity to detect anomalous access patterns and trigger investigation.
8. Vulnerability and asset management
- We maintain baseline configurations and apply patches, updates, and fixes on a regular basis.
- We perform vulnerability scanning on a recurring schedule and remediate findings according to risk severity.
- We maintain an inventory of systems and assets with access to information and a change-management process for production systems.
- We do not hardcode secrets or credentials in code or expose them in public repositories, and we maintain separate test and production environments.
9. Incident response
- We maintain a documented incident-response plan defining roles, incident types, response procedures, and escalation paths.
- We designate an Incident Management Point of Contact and review the plan periodically and after major system changes.
- In the event of a security incident affecting Amazon information, we notify Amazon promptly and within the timeframe required by the DPP, investigate, remediate, and document corrective actions.
10. Personnel and third parties
- Personnel with access to information complete data-protection and security-awareness training and are bound by confidentiality obligations.
- We restrict storage of information on personal or removable devices.
- We assess the security practices of vendors and subprocessors before granting access, and only share data with parties whose standards are at least as strict as ours and only as necessary to provide the service.
11. Compliance and audit
- We maintain the books and records reasonably required to verify compliance with Amazon's Acceptable Use Policy, Data Protection Policy, and the Amazon Services API Developer Agreement.
- We will certify compliance in writing and cooperate with audits or assessments upon Amazon's reasonable request.
Contact
Security questions or to report a concern: jamgroup18llc@gmail.com