Effective Date: May 13, 2026 | Last Updated: May 13, 2026
Controller: Whichita LLC DBA IQRECOVER, South Dakota LLC - integrations@IQRECOVER.com
This policy covers our use of Amazon Selling Partner API (SP-API) and Amazon Information as defined in Amazon's Data Protection Policy (DPP).
Whichita LLC DBA IQRECOVER ("we", "us", "our") is a South Dakota LLC providing IQRECOVER, a private FBA reimbursement auditing and filing service for Amazon aggregators. We comply with Amazon Services API Acceptable Use Policy (AUP), Data Protection Policy (DPP), and Developer Agreement. We only process Amazon Information to provide services you have requested and authorized via SP-API.
We access ONLY the minimum Amazon Information authorized via SP-API and required to provide reimbursement recovery services. This consists solely of non-PII operational transaction headers from disconnected Amazon ledgers. Source Layer — Secure ingestion of raw, non-PII transaction headers from disconnected Amazon ledgers.
We DO NOT request, collect, access, or store buyer PII, buyer-seller messages, restricted data, payment instruments, or tax identity information.
Amazon Information is used SOLELY to identify FBA inventory discrepancies eligible under Amazon's FBA policies, generate Amazon-ready recovery file, file reimbursement claims via SP-API or Seller Central within Amazon's filing windows, and reconcile reimbursements for billing. No other use.
Location: Private AWS infrastructure in us-east-1 only. No cross-region replication of raw Amazon Information.
Encryption at Rest: AES-256 - S3 SSE-S3 / SSE-KMS, DynamoDB encryption at rest, EBS volume encryption.
Encryption in Transit: TLS 1.2+ for all SP-API calls and client data transfers. HTTPS enforced.
Access Controls: AWS IAM with MFA required, least-privilege roles, VPC isolation with private subnets, Security Groups, AWS WAF, no public S3 buckets. Logging via CloudTrail and S3 access logs.
System Hardening: Firewalls, IDS/IPS, anti-virus/anti-malware, automated patching, network segmentation per Amazon AUP Section 5.
We do NOT sell Amazon Information. We do NOT share Amazon Information with outside parties, subcontractors, AI/ML training, or third-party services. Sharing limited to you, the authorized Selling Partner, via private pre-signed S3 URL containing limited operational data only, and to Amazon via SP-API to submit claims, or as required by law. Isolated ledger per brand, no cross-brand joins.
Raw Amazon report data: Purged within 30 days post-processing via automated lifecycle and manual confirmation. Billing reconciliation data (Settlement reference + Claim ID + amount only - no PII): Retained up to 12 months, then deleted. Upon termination or upon your request: All Amazon Information purged within 30 days. Request deletion via integrations@IQRECOVER.com
SP-API credentials stored in AWS Secrets Manager with automatic rotation, encrypted with KMS. No hard-coding, no source control, no public repositories, no email sharing. Access restricted to authorized personnel with MFA.
Documented Incident Response Plan per DPP: Defined roles, reviewed every 6 months, 24-hour internal escalation, notification to security@amazon.com and affected Selling Partner within 24 hours of detection, containment/eradication/recovery, annual tabletop exercise.
Request access, correction, deletion of business contact data and immediate purge of Amazon Information via integrations@IQRECOVER.com. Revoke SP-API authorization anytime via Seller Central > Apps and Services.
We comply with Amazon AUP, DPP, Developer Agreement, and Solution Provider Agreement.
Contact: Whichita LLC DBA IQRECOVER, South Dakota LLC - integrations@IQRECOVER.com
Security: security@amazon.com