SP-API compliance
Summary
BFarm Insights keeps each seller isolated, does not sell access to Amazon data, and excludes buyer PII, client credentials, cross-seller aggregation, Ads API, write operations, and any use of Amazon Information to train, fine-tune, or evaluate a model from the planned integration.
Last Updated: August 10, 2026
Available today through Amazon analytics exports supplied directly by the managed-service client, with client-scoped storage and read-only reporting.
BFarm currently has no approved or active SP-API application or production OAuth integration. Planned only after the required Amazon approval, production implementation, security verification, and seller authorization.
- Planned role: Brand Analytics
- Search Query Performance (SQP) (GET_BRAND_ANALYTICS_SEARCH_QUERY_PERFORMANCE_REPORT): Read-only API request after approval. Available only to eligible Brand Registry sellers.
- Sales and Traffic (GET_SALES_AND_TRAFFIC_REPORT): Read-only API request after approval. Available to eligible seller accounts.
- Current storage: managed work device, Google Workspace, managed application server, and encrypted off-site backups
- Clients do not provide private applications, API credentials, refresh tokens, or Seller Central passwords
- Buyer PII, communications, restricted tax data, and DTC-shipping data are not used
- Language models assist the work under operator review and seller approval; no model has account access and none takes an action
- Non-PII Amazon Information is kept only while needed for the agreed service; an automatic retention limit is specified and scheduled, not yet enforced
- Amazon deletion requests are processed within 30 days and applicable live copies within 90 days
- Suspected Amazon Information incidents are escalated to Amazon within 24 hours
- Primary security contact: security@bfarm.top
- The following are excluded from the planned SP-API integration. They describe the requested API scope, not the existing managed service, which is described in the Privacy Policy.
- Buyer names, addresses, phone numbers, communications, and other buyer PII
- Seller Central passwords, private applications, Client IDs, Client Secrets, refresh tokens, and other client API credentials
- Orders, Listings, Pricing, Finance, FBA, and Amazon Ads API data
- Listing, pricing, advertising, or other write operations
- Use of Amazon Information to train, fine-tune, or evaluate any model
- Automated or model-initiated action on a seller account without operator review and seller approval
- External Amazon-derived datasets, resale of Amazon data access, and cross-seller pooling or aggregation