Amazon data protection and handling

Tinx Amazon Connector for Microsoft Dynamics 365 Business Central

Last updated: 3 August 2026


Scope

This page describes how Tinx-IT B.V. collects, processes, stores, uses, shares and disposes of Amazon Information obtained through the Amazon Selling Partner API (SP-API) in the Tinx Amazon Connector, including personal data such as a buyer’s name, delivery address and tax registration details.

It complements our general privacy statement and our terms of service. Tinx-IT B.V. is established in the Netherlands and operates under the EU General Data Protection Regulation and the Amazon Data Protection Policy.

Our role: the data stays with the seller

The Tinx Amazon Connector is a Microsoft AppSource certified application that runs inside the selling partner’s own Business Central environment, hosted by Microsoft. Each selling partner authorises the application themselves, and the application communicates directly with the Selling Partner API from that environment.

As a result, Tinx operates no intermediate systems through which Amazon Information passes, and keeps no copy of it. Under the GDPR the selling partner is the controller for this data; Tinx acts as processor, and only where a seller grants us access to their environment.

What we collect, and for which purpose

Data is retrieved per order and used only for the purposes below. Amazon grants access to buyer data under two restricted roles, and we use each only for its stated purpose.

  • Direct-to-Consumer Shipping – for orders a seller ships themselves, the buyer’s name and delivery address are used to create the shipment and shipping label, and to report fulfilment and tracking back to Amazon.
  • Tax Invoicing – the buyer’s name, address and, for business sales, VAT identification are used to issue the statutory invoice in the seller’s own administration and to make it available to the buyer.

The legal basis is the performance of our agreement with the selling partner, together with the seller’s own legal obligation to issue and retain tax invoices. Amazon Information is never used for marketing, profiling, analytics or model training. We do not aggregate, publish or sell data obtained through the SP-API, and we do not use insights about Amazon’s business for our own purposes.

How it is stored and protected

Amazon Information resides in the selling partner’s own Business Central environment, encrypted both in transit and at rest by Microsoft, and protected by the authentication and permission settings that the seller controls. Backups of that environment are made and held by Microsoft, geographically redundant, and can be restored by an administrator to a point in the recent past.

Buyer personal data is used in that environment where the seller needs it: on the customer, the order and the shipping and invoice documents. Access to it requires a separate permission that sits outside the standard user rights and is granted explicitly by the seller, and every time buyer data is viewed or retrieved again this is recorded, including who did it, when, for which order and for what reason.

Credentials for the connection are never stored in plaintext or embedded in our code. They are held in dedicated, encrypted secret storage, rotated periodically, and handled so that they cannot appear in logs, error messages or diagnostics.

Who can see it

Tinx has no standing access to Amazon Information. Where a seller asks us to configure or support their environment, they invite the individual Tinx employee under that person’s own corporate identity, protected by multi-factor authentication, with only the permissions the task requires. Shared or generic logins are not used, so activity is attributable to a named person. The seller controls that access and can withdraw it at any time; we review our accounts periodically and revoke access promptly when an employee leaves.

Our staff work only from company-issued equipment, and no exports, backups or copies of customer data are taken onto our own systems or onto personal devices. Development and testing use Amazon’s sandbox and non-production data; where an issue can only be examined with real data, that is done inside the seller’s own environment.

Retention and disposal

The buyer’s name, address and contact details are anonymised within 30 days of the order being shipped, in line with the Amazon Data Protection Policy. This happens automatically across the customer, order and document records, so it does not depend on anyone remembering to do it. Amounts, dates, VAT and document numbers stay exactly as they were, so the seller’s audit trail remains complete – only the personal details are irreversibly removed.

Where a selling partner is legally required to retain a tax invoice, the statutory record is the invoice document archived at the time it was issued, retained for the period that the seller’s own tax law prescribes and used for no other purpose. That period follows the law applying to the seller’s accounting records, not anything set by Tinx.

If personal data is needed again later – for a return, a replacement or a credit note – it is retrieved from Amazon at that moment through the same controlled and logged route. We do not keep a private archive of buyer data to draw on.

Diagnostic logs are retained only briefly and personal data is redacted from them.

If the authorisation ends

A selling partner can withdraw the application’s authorisation in Seller Central at any time and uninstall the application. From that moment no further data is retrieved, and the stored access credentials are invalidated and removed with the application. Because Tinx keeps no copy of Amazon Information on its own systems, there is nothing on our side to delete. Archived invoice documents and the sales records remain the seller’s, subject to their statutory retention obligations.

Sharing with others

Tinx does not sell, rent or transfer Amazon Information to third parties.

Amazon Information may incidentally reach our helpdesk provider, engaged as a sub-processor under a data processing agreement concluded with the seller, if a seller attaches a log or screenshot to a support request. Such data is used only to resolve that case. Where this involves a transfer of personal data outside the European Economic Area, that transfer is covered by the safeguards in that provider’s data processing agreement. A current list of our sub-processors is available on request.

Implementation partners and other applications obtain access only where the seller grants it within their own environment; Tinx passes no Amazon Information to them.

Monitoring and incidents

We monitor our application for authentication failures, errors and unusual activity, with automated alerts to our team. Within the seller’s environment, sign-in logs and the change log record who did what.

We maintain an incident response procedure with defined roles, escalation paths and a named point of contact, reviewed regularly. On detection we contain the incident – including revoking credentials or disconnecting the integration – investigate and document it, notify Amazon within 24 hours and inform the affected seller as controller, then remediate and verify before resuming. Vulnerabilities found in our own code are tracked to closure, with critical findings prioritised, and fixes are distributed as a new application version.

Rights of buyers and other data subjects

Because the selling partner is the controller, requests for access, correction, deletion or objection should be addressed to the seller from whom the order was placed. Tinx acts only on that seller’s instructions and supports them in responding within the statutory period. If you contact us directly we will refer you to the relevant seller; we cannot identify or disclose buyer data on our own initiative.

What this means for you as a selling partner

Because the data resides in your environment, some responsibilities are yours. You decide who at Tinx may access it and with which permissions, and which of your own users receive the separate authorisation for buyer personal data. You determine the retention period for your accounting records and where invoice documents are archived. The password, device and conditional access policies of your own Microsoft tenant apply. The automatic anonymisation runs as a scheduled task in your environment, so it needs to remain active. We are glad to advise on all of this.

Reporting a vulnerability

If you believe you have found a security vulnerability in one of our applications, report it to [email protected] with enough detail to reproduce it. We will confirm receipt, keep you informed while we investigate, and ask for reasonable time to resolve the issue before public disclosure.

Contact

Incident Management Point of Contact: Kasper Dissel, [email protected]
General enquiries: [email protected]  ·  +31 850 653 138
Tinx-IT B.V., Bennekomseweg 43, 6717 LL Ede, The Netherlands

More detailed technical and organisational security information is available to selling partners and to Amazon on request.

Tinx-IT B.V
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.