Scope and information
We process account and business contact information, usage and security logs, seller authorization information and necessary technical credentials, and explicitly authorized Amazon order data. Order data may include identifiers, product and customization options, status, buyer names, delivery addresses and contact details needed for order processing. The public portal does not store ERP order content or login credentials.
Purpose and minimization
We use information to maintain accounts, deliver and support XERP, process authorized orders, prepare production materials, support shipping, maintain security, resolve support requests and meet legal or contractual obligations. We request only the permissions needed for the relevant function. We do not sell customer data or use it for unrelated advertising.
Amazon SP-API and personal information
We access Amazon data within the seller’s authorization and approved SP-API scope. Personal information is used only for the corresponding seller’s orders, necessary production or delivery materials, order checks and support. Server-side authorization and least-privilege controls restrict access; data is not accessed or disclosed for another seller without authorization.
Security, access and retention
Measures include HTTPS/TLS, access control, server authentication, encrypted storage of sensitive credentials, logs and maintenance. Full recipient details, telephone numbers, labels and logistics proofs are restricted to explicitly authorized shipping personnel and systems, not general order, artwork-review or sales-analysis responses. Recipient information is retained only as needed for delivery, after-sales and legal duties; synchronized and final shipping addresses are normally retained no longer than 30 calendar days after delivery. Database address records are then removed; private stored files follow applicable lifecycle rules. A separate retention basis is used only where legally or contractually necessary.
Sharing and cross-border processing
Necessary information may be disclosed to constrained infrastructure, storage, messaging, payment or technical support providers, or when required by law, authorized, or needed to protect rights and security. Processing locations may depend on the seller’s marketplace, chosen providers and infrastructure. We take reasonable measures to protect that processing.
Your choices and security incidents
Sellers can revoke authorization through Amazon; we then stop obtaining new SP-API data under that authorization. Contact us to request access, correction, deletion or other applicable rights; identity and authority may need verification. We investigate and address security incidents and notify affected parties and authorities when required by law, contract or Amazon policy.
Updates and contact
This policy may change with the service, law or security practices. Effective and updated: September 28, 2026. Contact support@ionmm.com or +86 198 7678 7974 for questions.