数据安全

最近更新:2026-10-07 · 本页措施与我们的《隐私政策》共同构成完整的数据保护说明

冰川 ERP 的所有亚马逊店铺数据均通过亚马逊官方 Selling Partner API(SP-API)/ 广告 API,在店铺主账号 OAuth 授权后读取。我们把「店铺数据视同客户资产」作为设计底线,并遵循亚马逊 Data Protection Policy(DPP)与 Acceptable Use Policy(AUP)。

1. 数据传输与存储加密

  • 传输:全站 HTTPS,TLS 1.2 及以上;与亚马逊端点之间的调用同样全程加密。
  • 存储:数据库与备份加密存储(AES-256);授权令牌(refresh token)单独加密保存,与业务数据隔离。
  • 凭据:我们不接触、不保存你的亚马逊账号密码;授权只产生 OAuth 令牌。

2. 访问控制

  • 内部最小权限:默认无人可查看客户店铺数据;排查问题需客户授权工单,全程留痕。
  • 服务器与数据库访问强制多因素认证(MFA)与密钥登录,禁用密码登录。
  • 生产环境与办公网络隔离,数据库不暴露公网。

3. 数据最小化

  • 默认不申请买家个人信息(PII)相关的受限角色;订单仅使用运营必需的字段。
  • 只读取完成服务所必需的接口范围(roles),授权页面列明权限清单,你同意后才生效。

4. 数据保留与删除

情形处理
正常使用期间按套餐约定保留(免费版 90 天 / 标准版 2 年),用于趋势与回溯
撤销授权 / 停用30 天内删除该店铺的全部已同步数据(法律法规另有要求的除外)
备份备份随滚动周期自然过期,最长不超过 30 天

5. 数据共享

  • 不出售、不出租、不与任何第三方交换客户店铺数据。
  • 唯一的次级处理方是云基础设施服务商(服务器与存储托管),其仅提供基础设施,不接触业务数据内容。
  • 法律法规强制要求披露时,我们会依法评估并在允许范围内提前告知。

6. 漏洞管理与事件响应

  • 依赖与系统补丁按月滚动更新;高危公告 48 小时内评估处置。
  • 发生数据安全事件时:72 小时内启动通知流程(受影响客户与依法需要通知的监管/平台方),同步给出影响范围、已采取措施与补救方案。

7. 你的控制权

  • 随时在亚马逊后台「管理应用」撤销授权,或在产品内一键断开;撤销即停止一切数据读取。
  • 随时导出你的全部数据(Excel/CSV);随时书面要求我们删除。
  • 安全相关问题与删除请求请联系:联系我们 页所列邮箱。

Data Security

Last updated: 2026-10-07 · Together with our Privacy Policy, this page describes our data protection practices

All Amazon store data in Glacier ERP is read through Amazon's official Selling Partner API (SP-API) and Ads API after OAuth authorization by the store's primary account. We treat store data as the customer's asset and follow Amazon's Data Protection Policy (DPP) and Acceptable Use Policy (AUP).

1. Encryption in transit and at rest

  • In transit: HTTPS everywhere, TLS 1.2+; calls to Amazon endpoints are encrypted end to end.
  • At rest: databases and backups are encrypted (AES-256); OAuth refresh tokens are encrypted separately from business data.
  • Credentials: we never see or store your Amazon password; authorization issues OAuth tokens only.

2. Access control

  • Least-privilege internally: nobody can view customer store data by default; troubleshooting requires a customer-authorized ticket and is fully logged.
  • MFA and key-based login are enforced for server and database access; password login is disabled.
  • Production is isolated from office networks; databases are not exposed to the public internet.

3. Data minimization

  • We do not request restricted roles involving buyer PII by default; orders use only operationally necessary fields.
  • We request only the API roles required to deliver the service; the authorization page lists the exact scopes before you approve.

4. Retention & deletion

CaseAction
Active subscriptionRetained per plan (Free: 90 days / Standard: 2 years) for trends and lookback
Authorization revoked / account closedAll synced store data deleted within 30 days (unless law requires otherwise)
BackupsExpire with the rolling backup cycle, never exceeding 30 days

5. Sharing

  • We never sell, rent, or exchange customer store data.
  • Our only sub-processor is the cloud infrastructure provider (hosting and storage); it has no access to business data content.
  • If disclosure is legally required, we evaluate the request and notify you in advance where lawful.

6. Vulnerability management & incident response

  • Dependencies and system patches roll monthly; critical advisories are assessed within 48 hours.
  • On a data security incident: notification workflow starts within 72 hours (affected customers and regulators/platforms where required), with scope, containment, and remediation.

7. Your controls

  • Revoke access anytime in Amazon's "Manage Apps" or disconnect inside our product — all data reads stop immediately.
  • Export all of your data anytime (Excel/CSV); request deletion in writing at any time.
  • For security questions or deletion requests, use the email listed on our Contact page.