Amazon SP-API OAuth
What is Amazon SP-API OAuth?
Amazon's Selling Partner API (SP-API) uses OAuth 2.0 to securely authorize third-party applications to access seller data. When you connect your Amazon account to Pilot Partners S.L., you go through a secure authorization flow managed by Amazon.
How it works:
1. You click "Connect Amazon Account" on our platform.
2. You are redirected to Amazon's login page (you never share your password with us).
3. Amazon shows you the permissions we are requesting.
4. You approve or deny the request.
5. If approved, Amazon sends us a secure token that allows limited access to your data.
6. We never see or store your Amazon password.
Permissions We Request
We request only the minimum permissions needed to deliver our services. Each permission (role) is listed below with its purpose:
| Permission | What it accesses | Why we need it |
|---|---|---|
| Inventory and Order Tracking | Orders, history and stock levels | Analyse sales performance, prevent stock-outs and support inventory management |
| Product Listing | Product listings, catalogue and A+ Content | Optimise titles, bullets, keywords and A+ Content with our Listing Builder |
| Pricing | Own and competitor pricing | Pricing strategy, Buy Box tracking and deviation detection |
| Amazon Fulfillment | FBA inventory, shipments and replenishment | Replenishment forecasting and FBA stock-out prevention |
| Buyer Solicitation | Amazon official review request | Send Amazon’s official review request after order delivery |
| Selling Partner Insights | Account health and performance | Proactive compliance alerts and account health monitoring |
| Finance and Accounting | Transactions, fees and settlements | Build the real P&L of the channel |
| Brand Analytics | Search Query Performance and market data | Competitive position analytics, estimated share and repeat purchase behaviour |
| Buyer Communication | Buyer messaging | Manage post-purchase communication and buyer support on behalf of the selling partner |
| Direct-to-Consumer Shipping (restricted) | Order shipping address | Generate labels and manage FBM order shipping on behalf of the selling partner |
| Tax Invoicing (restricted) | Buyer tax data | Connect the selling partner’s invoicing system with Amazon to issue and upload compliant invoices |
Three of these permissions (Buyer Communication, Direct-to-Consumer Shipping and Tax Invoicing) involve access to buyer personal data. We request only those matching functionality we actually deliver, we access such data through short-lived Restricted Data Tokens, we process it solely on behalf of the selling partner, and we delete it within a maximum of 30 days from order delivery. We never use it for our own purposes nor share it with unauthorised third parties.
What We Do With Your Data
Listing optimization: We analyze your product data and generate optimized listing content using AI.
Image generation: We use your product information to create professional product images.
Analytics: We aggregate your sales, advertising, and inventory data to provide actionable insights.
AI Processing: Some product data (titles, descriptions, images) is processed by our AI providers (OpenAI, fal.ai) to generate content. We only send the minimum data required and never share personally identifiable or financial information with AI providers.
We do not use your data for any purpose other than providing our services to you.
Your Control
You have full control over your Amazon connection at all times:
Revoke access: Go to Amazon Seller Central > Apps & Services > Manage Your Apps. Find "Pilot Partners S.L." and click "Revoke".
What happens when you revoke: We immediately invalidate your tokens. All Amazon SP-API data is deleted from our systems within 30 days. Your Pilot Partners S.L. account and contact information remain unless you request deletion.
Request data deletion: Email hello@pilot-partners.com with subject "Data Deletion Request". We process all deletion requests within 30 days.
Security Measures
We take the security of your Amazon data seriously:
- Token encryption: All OAuth tokens (access and refresh) are encrypted at rest using AES-256.
- TLS encryption: All data in transit uses TLS 1.2 or higher.
- Access controls: Only authorized personnel can access token storage, with role-based access control (RBAC).
- Audit logging: All access to SP-API data is logged for security review.
- Token rotation: Access tokens are automatically refreshed per Amazon's guidelines; we never store expired tokens.
- Secure infrastructure: Our backend runs on SOC 2 certified infrastructure providers (Google Cloud Platform and Vercel). Pilot Partners S.L. does not hold its own SOC 2 certification.