If you sell on Amazon and you connect a third-party tool, buyer-level personal information moves from Amazon's servers to that tool. Names, ship-to addresses, phone numbers on some orders. Amazon writes a Data Protection Policy that says what third parties are and are not allowed to do with any of that, and the policy is not vague. This is a short account of how OttoCentral fits inside it.
What SP-API sends us.
For every order we sync, Amazon's Selling Partner API returns the order-level record: order id, items, quantities, amounts, fees, marketplace, buyer name, ship-to address, and a phone number on marketplaces that expose one. That is the shape of an order, and Amazon's data-flow rules apply to every field in it.
We do not receive credit card numbers, buyer login credentials, or Amazon-account-level information. Those never leave Amazon in the first place. What we receive is what a fulfilment centre would receive if the seller shipped every order themselves: enough to pick, pack, and ship. Nothing more.
Who sees it inside OttoCentral.
- The seller who owns the Amazon account that the order came from. That is the person who logged into OttoCentral, clicked Connect on Seller Central, and authorised the SP-API grant.
- Team members that seller invited into their OttoCentral workspace, subject to whatever role that seller assigned to them.
- The optional warehouse integration the seller enabled, if they enabled one. Today that is Skuload; if the seller has not enabled it, the data flows nowhere else.
Nobody else, and no aggregation across sellers. Buyer PII from your orders does not appear in another seller's OttoCentral, not even in anonymised form, not for benchmarks, not for product analytics.
Retention: the clocks we run.
Amazon's rule is that buyer data must be deleted within 30 days of the order date, unless a specific legal, tax, or dispute reason keeps it longer. We run that clock. Once an order crosses 30 days from its date, its buyer-level fields (name, address, phone) are removed from the active systems that display them. The order record itself stays for the seller's accounting; the buyer PII columns become empty.
If a seller revokes the SP-API connection before the 30 days are up, the same removal happens immediately for every order from that connection. If a seller closes their OttoCentral account, every buyer field is removed within 30 days of that closure.
Backups: another clock.
Database backups exist so that a catastrophic failure does not delete a seller's history. That means a backup taken today will contain buyer PII that was legitimately present today. Backups are retained on a 90-day rolling window. When a backup rolls out of the window, the buyer fields inside it roll out with it. Between deletion in active systems and expiration of the newest backup, there is a bounded period during which buyer PII exists only as an offline copy that nobody in the product can query.
What we deliberately do not do.
- No marketing to buyers. The email address on an order does not go into any list, ours or a partner's. Amazon forbids it, and we have no product reason to do it.
- No selling of buyer data. Never to advertisers, never to data brokers, never to analytics vendors.
- No cross-seller aggregation. We do not build a "who buys what" dataset across the sellers we serve. We are a tool for each seller's own orders, not a data business.
How to check us.
The mechanism side of this lives in one place: our Privacy Policy section 4, on Amazon Buyer Data. The mechanism itself is that SP-API is the only way this data enters the system, each seller controls the OAuth grant that keeps it flowing, and Amazon Seller Central's Manage Your Apps panel is where the seller cuts it off. There is no other side channel.