SP-API compliance
Last Updated: September 29, 2026
Current managed-service data handling and the narrow boundary for the planned Public SP-API integration.
BFarm is a trading name of Maksym Lazuto, Individual Entrepreneur, registered in Ukraine.
Current managed reporting
BFarm imports client-provided Search Query Performance and Sales and Traffic exports into a reporting workspace. Reports are separated by client and marketplace, show their source period, and do not make changes in Seller Central.
Sellers authorize any managed-service account access through Seller Central Authorized Partners and retain permission and revoke control. Assigned BFarm personnel use individual verified accounts and least-privilege access for the documented non-PII scope.
Planned Public SP-API boundary
BFarm currently has no approved or active SP-API application or production OAuth integration. Amazon API access remains planned. Activation requires the relevant Amazon approval, seller authorization, and verification of the live connection and its security controls.
The planned request contains one non-restricted role, Brand Analytics, and only the two read-only report types listed on the BFarm Insights page. SQP remains limited to eligible Brand Registry sellers.
Seller isolation and prohibited uses
BFarm does not sell or license access to Amazon data or combine Amazon Information between sellers. The planned SP-API integration does not use external Amazon-derived datasets. A client's source files and reports remain isolated to that client and the written service purpose. Current managed-service data sources are disclosed in the Privacy Policy, section 9.
The following are excluded from the planned SP-API integration. They describe the requested API scope, not the existing managed service, which is described in the Privacy Policy.
- Buyer names, addresses, phone numbers, communications, and other buyer PII
- Seller Central passwords, private applications, Client IDs, Client Secrets, refresh tokens, and other client API credentials
- Orders, Listings, Pricing, Finance, FBA, and Amazon Ads API data
- Listing, pricing, advertising, or other write operations
- Use of Amazon Information to train, fine-tune, or evaluate any model
- Automated or model-initiated action on a seller account without operator review and seller approval
- External Amazon-derived datasets, resale of Amazon data access, and cross-seller pooling or aggregation
The planned SP-API scope also excludes transferring Amazon Information to language-model providers. The managed-service AI disclosure in the Privacy Policy, section 8 does not expand that API scope.
What the system checks establish
The reporting workspace is in use with manual imports. An owner sign-in with multi-factor authentication, access to the selected reports, and automatic startup after a server restart were checked in September 2026. These checks do not verify live Amazon API access.
Authorization and encrypted-credential components have been implemented, but the Amazon connection remains disabled. No seller is connected through a BFarm OAuth flow, and no production Amazon authorization code or token is processed.
An encrypted external backup was restored and checked in isolation. Running the application on that restored database, a full production recovery, and delivery of emergency notifications have not been verified.
Storage, retention, and incidents
Main storage locations for managed-service information are on a managed work device, in Google Workspace, on a managed application server that runs the BFarm reporting database, and in encrypted off-site backups. Backups are encrypted before they leave the server and are stored encrypted. The Privacy Policy separately describes development and processing providers, including historical AI use and technical review. BFarm requires operator review and client approval before account or listing changes. The Privacy Policy lists the storage locations and the service providers in full. Non-PII Amazon Information is retained only while it is needed for the agreed service; an automatic upper limit is specified and scheduled but is not yet enforced, and records are removed on request rather than on a schedule. Amazon's current Data Protection Policy requires permanent, secure deletion of all Amazon Information, including all live copies, within 30 days of the earliest applicable trigger: an Amazon deletion notice, seller revocation or termination, loss of authorization to use the information, or the end of participation in Amazon's services. Deletion requests can be sent to max@bfarm.top. Suspected incidents involving Amazon Information are escalated to Amazon within 24 hours of discovery.
Report a suspected security issue or ask a compliance question at security@bfarm.top.
Separate Ads authorization
Amazon Ads API is outside this planned SP-API role. Any future Ads API integration would require a separate Amazon authorization and its own checks before activation.