Apollo by eBrands — Privacy Policy
Last updated: July 2026
1. Who we are
Apollo is the technology platform behind the eBrands operating system for global commerce, operated by eBrands Holdings Oy ("eBrands", "we", "us"). Its Amazon Selling Partner API integration at oauth.ebrands.com is the authorization entry point that enables Apollo to access Amazon Seller Central data through Amazon's Selling Partner API (SP-API). It covers the Amazon seller accounts that eBrands owns and operates; the integration is not offered to other sellers.
2. What this policy covers
This policy describes how Apollo collects, processes, stores, retains, and deletes Amazon-derived data accessed via the SP-API under the authorization granted on those accounts. A role-by-role statement of what we access and why is published separately on our data access & purpose page. This policy is designed to comply with Amazon's Acceptable Use Policy (AUP) and Data Protection Policy (DPP).
3. What data we access
Apollo reads only the SP-API data needed to run the operations, finance, tax, and inventory processes it supports:
- Orders: order IDs, line items, quantities, status, marketplace, and fulfillment timestamps.
- Inventory: FBA and seller-fulfilled stock levels per warehouse and per ASIN.
- Financials & settlements: settlement reports, fees, refunds, reserves, and payout estimates.
- Catalog & listings: ASINs, SKUs, titles, prices, and listing status.
- Tax:Amazon's VAT Transactions Report (report type GET_VAT_TRANSACTION_DATA) for the EU marketplaces where eBrands is registered for VAT, used for internal EU VAT reconciliation and month-end reporting.
- Reports: standard SP-API reports required for the modules above.
Apollo accesses Personally Identifiable Information (PII) — such as buyer name and shipping address — for fulfillment-related purposes, and handles it under the stricter rules described in section 6. Coarse location data derived from the delivery address is also used for internal operational purposes, including an internal view of order activity by area rather than by individual address. The purpose of each restricted SP-API role we hold is set out on our data access & purpose page.
4. How we use the data
Amazon-derived data is used solely to:
- Run the operations dashboard, deferred order estimates, and inventory planning features.
- Fulfill our own Merchant-Fulfilled orders and confirm shipment back to Amazon.
- Reconcile EU VAT and produce our own month-end financial reporting.
- Aggregate our own brand performance across the marketplaces we sell on.
We do not, and will not:
- Use Amazon data to market to Amazon customers or solicit reviews.
- Aggregate or sell competitive insights across other sellers' data.
- Share Amazon data with advertising networks.
5. Legal basis
Where the GDPR or equivalent regimes apply, our legal basis for processing Amazon-derived data is the performance of the sales contract with the buyer, our legal obligations in tax and accounting, and our legitimate interest in operating and securing the Apollo platform. eBrands Holdings Oy is the controller for the Amazon seller accounts it owns and operates.
6. Encryption and security
We apply technical and organisational measures appropriate to the risk to protect Amazon data, including encryption, access controls, and logging of the systems that handle it. Amazon data is transmitted in transit to and from Amazon using TLS 1.2 or higher. PII is encrypted at rest using AES-256, and non-PII Amazon data is stored on encrypted volumes.
7. Retention
- PII (e.g. buyer name, shipping address): retained for no more than 30 days after order delivery, except where a longer period is required by tax, legal, or accounting obligations.
- Non-PII Amazon data (orders, inventory, settlements, catalog): retained as long as necessary to operate the platform and to meet our legal obligations.
8. Deletion and data removal
If authorization for an account is ended in Seller Central, or on written request to apollo@ebrandsglobal.com, we stop accessing that account's Amazon data and delete or de-identify the Amazon data we hold for it, subject to the retention periods required by tax, accounting, and other legal obligations. Backup copies are purged on their normal rotation schedule.
9. Sub-processors
Apollo runs on Amazon Web Services (AWS) infrastructure inside the European Union. Amazon-derived data may also be handled by the business systems and service providers we operate on — such as our enterprise resource planning, logistics, and operational support services. We review sub-processors handling Amazon data at least annually and require equivalent protections where we contract with them directly. A current and complete list of sub-processors is available on request.
10. International transfers
Amazon data is processed primarily inside the EEA. Where a transfer outside the EEA is necessary, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
11. Incident response
In the event of a confirmed data incident affecting Amazon data, eBrands will notify Amazon within 24 hours of confirmation, and affected individuals or supervisory authorities as required by applicable law and the SP-API Data Protection Policy.
12. Your rights
Authorization for a connected account can be revoked at any time from Seller Central → Apps & Services → Manage Your Apps. If you are an Amazon buyer and want to exercise your rights of access, correction, deletion, or portability over data we hold about your order, contact apollo@ebrandsglobal.com. We respond within 30 days.
13. Contact
eBrands Holdings Oy
Email: apollo@ebrandsglobal.com
Website: ebrands.com
14. Changes
We may update this policy as the Apollo platform evolves or as Amazon's policies change. When a change affects the Amazon data our integration accesses or the purpose it is used for, we update this policy, our data access & purpose page, and our Amazon Appstore listing before the change ships.