1. Introduction and scope
Multigraphite Enterprises LLC (“Multigraphite,” “we,” “us,” or “our”), a Florida limited liability company with its principal office at 7901 4th St N, STE 33435, St. Petersburg, FL, 33702, provides automated Fulfillment by Amazon (“FBA”) inventory auditing and ledger reconciliation software for Amazon Selling Partners (the “Service”).
This Privacy Policy explains what information we collect, why we collect it, how we protect it, how long we keep it, and how it is deleted. It applies to the Service, to this website, and to communications with us. It should be read together with our Terms of Service.
Multigraphite acts as a service provider to the sellers who use the Service. As between you and us, you retain ownership of your Seller Data, and we process it only on your behalf and on your instructions, as described below.
2. Definitions
- “Amazon” means Amazon.com, Inc. and its affiliates.
- “SP-API” means the Amazon Selling Partner API.
- “DPP” means the Amazon Data Protection Policy, and “AUP” means the Acceptable Use Policy applicable to the SP-API, each as published and amended by Amazon from time to time.
- “Customer” or “you” means the Amazon Selling Partner or business entity that registers for and uses the Service.
- “Seller Data” means all data obtained from a Customer’s Amazon Selling Partner account through the SP-API, including inbound shipment records, inventory ledger records, catalog dimension and weight data, and fee data, and any data derived from it.
- “Account Data” means information you provide to establish and administer your Multigraphite account, such as your name, business name, business email address, and billing details.
3. Information we collect
3.1 Account Data
When you request access to or register for the Service, we collect your name, business name, business email address, and, where applicable, billing and payment information. Payment card details are handled by our payment processor and are not stored on our systems.
3.2 Seller Data obtained through the SP-API
After you authorize the Multigraphite application, we retrieve only the Seller Data necessary to provide the Service. This consists of operational and financial records about your FBA inventory, such as:
- Inbound shipment plans and shipment line items, including quantities shipped and received;
- FBA inventory ledger and adjustment events;
- Product catalog attributes relevant to fee determination, including item dimensions and weights; and
- Fulfillment fee estimates and fees assessed.
The Service is designed not to require access to buyer personally identifiable information (“PII”), such as buyer names, shipping addresses, or contact details. We do not request SP-API roles that provide such data. If PII is ever received inadvertently, we will not use it, will isolate it, and will delete it promptly in accordance with Section 10.
3.3 Technical and usage information
We automatically collect limited technical information necessary to operate and secure the Service, including IP address, browser type, device type, timestamps, and security and audit logs of access to the Service.
3.4 Communications
If you contact us, for example at enterprise@multigraphite.com, we retain the content of your message and our reply so that we can respond and maintain a record of the request.
4. Read-only SP-API access
The Service accesses your Amazon Selling Partner account exclusively through the SP-API and exclusively through your explicit authorization using Amazon’s standard authorization workflow. Our application requests read-only roles and permissions. The Service does not create or modify shipments, listings, prices, orders, or inventory in your account.
You may revoke Multigraphite’s authorization at any time in Seller Central. Upon revocation, we cease all retrieval of Seller Data and initiate deletion in accordance with Section 10. Authorization credentials (such as refresh tokens) are stored in encrypted form, are accessible only to the systems and personnel that require them to operate the Service, and are never exposed in client-side code, logs, or support communications.
5. Purpose limitation
We access, collect, and use Seller Data strictly and solely to provide the inventory auditing and ledger reconciliation service to the Customer who authorized access. We do not access, retrieve, or process Seller Data for any other purpose. Specifically, we use it to:
- Compare shipped and received inbound quantities and identify discrepancies;
- Monitor item dimensions, weights, and fulfillment fees for changes;
- Reconcile the FBA inventory ledger against shipment, receipt, and adjustment events; and
- Generate, deliver, and retain the reports and audit records that constitute the Service.
We do not use Seller Data for advertising, marketing, profiling, market research, competitor benchmarking, product development for third parties, training of generalized or third-party machine-learning models, or any purpose unrelated to the Customer’s own reconciliation. Seller Data from one Customer is never combined with, or made visible to, another Customer.
Account Data is used to create and administer accounts, provide support, process billing, secure the Service, and comply with legal obligations. We may send you service-related notices; we do not send unsolicited marketing to Account Data contacts without a lawful basis, and every marketing message, if any, will include a means to opt out.
6. No sale, rental, monetization, or third-party sharing of seller data
Seller Data is never sold, rented, licensed, traded, monetized, or shared with third parties by Multigraphite Enterprises LLC. This applies to Seller Data in whole or in part, and in identifiable, aggregated, anonymized, or de-identified form. We do not provide Seller Data to data brokers, advertisers, analytics or marketing vendors, affiliates, or any other party for that party’s own purposes, and we receive no payment or other consideration in exchange for Seller Data. This commitment is absolute and is consistent with the requirements of the DPP and AUP.
The only handling of Seller Data that involves any party other than you and Multigraphite is the narrow, non-commercial processing described in Section 7 (infrastructure providers acting solely on our behalf and under our instructions, disclosures you direct in writing, and disclosures compelled by law). None of these is a sale, rental, or sharing of Seller Data for the recipient’s own use.
We also do not “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act, as amended, or comparable state laws.
7. Disclosure and service providers
Except as set out below, Seller Data is not disclosed to anyone other than the Customer who owns it. We disclose information only in the following limited circumstances:
- Infrastructure and service providers. We use vetted providers for cloud hosting, secure data storage, payment processing, and email delivery. These providers act solely as processors on our behalf: they process information only on our documented instructions, may not use it for their own purposes, are bound by written confidentiality and data protection obligations, and are subject to security requirements no less protective than those in this Policy and the DPP. Seller Data is made available to such providers only to the extent strictly necessary to host and operate the Service, and payment processors do not receive Seller Data.
- At your direction. When you export a report or instruct us to share information with a person you designate.
- Legal requirements. When required by law, regulation, subpoena, or valid legal process. Where legally permitted, we will notify the affected Customer before disclosing Seller Data and will disclose only the minimum information required. We will also notify Amazon where required by the DPP.
- Business transfers. In connection with a merger, acquisition, or sale of assets, provided that Seller Data remains subject to the commitments in this Policy and to Amazon’s requirements, and that Customers are given notice and the opportunity to delete their data beforehand.
8. Security and encryption
We maintain a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle and consistent with industry-standard practices and the DPP. Key controls include:
- Encryption in transit. All data transmitted between your browser and the Service, between Multigraphite systems, and between Multigraphite and Amazon’s APIs is transmitted over HTTPS and protected using Transport Layer Security (TLS) version 1.2 or higher. Unencrypted (HTTP) connections and deprecated protocols (SSL and TLS versions earlier than 1.2) are not accepted.
- Encryption at rest. All Seller Data, Account Data, and authorization credentials are encrypted at rest using AES-256, with encryption keys managed separately from the data they protect and rotated periodically.
- Access control. Access to Seller Data is restricted to authorized personnel with a documented business need, follows the principle of least privilege, is protected by multi-factor authentication, and is promptly removed when no longer required.
- Logical separation. Each Customer’s Seller Data is logically segregated from that of other Customers.
- Logging and monitoring. Access to Seller Data and administrative actions are logged, and logs are protected from tampering and reviewed for anomalous activity.
- Vulnerability management. We apply security updates to systems and dependencies on a regular basis and review our infrastructure for vulnerabilities.
- Personnel. Personnel with access to Seller Data are bound by confidentiality obligations and receive security and data-handling guidance.
- Data handling. Seller Data is not stored on personal or removable devices, and production data is not used in development or testing environments.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will, however, act in accordance with Section 11 if a security incident occurs.
9. Amazon SP-API and Data Protection Policy compliance
Multigraphite operates as an Amazon Selling Partner API developer and agrees to adhere to the Amazon Services API Developer Agreement, the AUP, and the DPP. Without limiting Section 5 through Section 11, we specifically commit that:
- We access Seller Data only with the Customer’s authorization and only for the purposes described in this Policy.
- We never sell, rent, monetize, or share Seller Data with third parties, and we do not use it for any purpose other than ledger reconciliation and inventory auditing for the authorizing Customer.
- We encrypt Seller Data in transit using HTTPS with TLS 1.2 or higher and at rest using AES-256.
- We limit access to Seller Data to personnel and service providers with a legitimate need, and we maintain access logs.
- We retain Seller Data no longer than necessary to provide the Service and delete it as set out in Section 10.
- We maintain and follow an incident response plan and will notify Amazon and affected Customers of security incidents as set out in Section 11.
- We do not request, store, or process buyer PII as part of the Service. If Amazon Restricted Data or PII were ever required for a future feature, we would obtain the necessary Amazon approvals, update this Policy, and apply the additional controls required by the DPP before processing any such data.
- We do not attempt to re-identify any data, and we do not use Seller Data to contact Amazon buyers.
- We will promptly comply with valid requests from Amazon related to data protection, including requests for information, cooperation with security reviews, and deletion of data.
- We review our security practices at least annually and update them as required by changes to Amazon policies and applicable law.
10. Data retention and deletion
We retain information only for as long as necessary to provide the Service and satisfy our legal obligations. The following schedule applies.
10.1 Retention periods
- Seller Data is retained while your account is active and authorization remains in effect, for the period needed to produce reconciliation reports and preserve your audit trail. Seller Data that is no longer needed to provide the Service is deleted, and in all cases upon a deletion trigger described in Section 10.2, in accordance with the schedule below.
- Authorization credentials are retained only while authorization is active and are deleted immediately upon revocation, account closure, or termination.
- Account Data is retained while your account is active and thereafter for the period required to meet tax, accounting, and legal obligations.
- Security and access logs are retained for up to twelve (12) months for security and audit purposes and then deleted.
10.2 Deletion triggers
We initiate deletion of your Seller Data when any of the following occurs:
- You revoke Multigraphite’s authorization in Seller Central;
- You close your account or your subscription is terminated or lapses;
- You submit a written deletion request to enterprise@multigraphite.com; or
- Amazon requires deletion, or we are otherwise obligated to delete under applicable law.
10.3 Deletion procedure and timing
- Active systems: Seller Data is permanently deleted within thirty (30) days of a deletion trigger, or sooner where Amazon or applicable law requires.
- Backups: Seller Data in encrypted backups is overwritten or expires in the ordinary course of backup rotation, and in any event within ninety (90) days of a deletion trigger. Data in backups is not accessed or restored for any purpose other than disaster recovery, and any restored data is re-deleted.
- Method: Deletion is performed using methods intended to render data unrecoverable, including cryptographic erasure and secure deletion. We will confirm completion of deletion in writing upon request.
- Exports: Before deletion, you may request an export of your reports. Unless you request otherwise, we do not retain copies after deletion.
10.4 Customer deletion request procedure
You may request deletion of your Seller Data or Account Data at any time, at no charge, by following these steps:
- Submit the request. Email enterprise@multigraphite.com from the address associated with your account, with the subject line “Data Deletion Request,” identifying your business name and the Amazon Selling Partner account(s) concerned. You may also revoke authorization in Seller Central, which independently triggers deletion under Section 10.2.
- Verification. We may verify that the request comes from an authorized representative of the account holder, and will do so within five (5) business days of receipt.
- Acknowledgment. We will acknowledge the request in writing within five (5) business days of verification.
- Execution. We will delete the data in active systems within thirty (30) days of the request and in backups within ninety (90) days, as described in Section 10.3.
- Confirmation. We will confirm in writing to the requester once deletion of active-system data is complete and again when backup expiry is complete.
10.5 Legal holds
If we are required by law to retain certain information, for example under a legal hold, we will retain only what is required, restrict its use to that legal purpose, and delete it when the obligation ends.
11. Security incidents
We maintain an incident response plan that provides for detection, containment, investigation, remediation, and post-incident review. If we become aware of a confirmed or reasonably suspected security incident affecting Seller Data, we will:
- Notify Amazon within twenty-four (24) hours of detection, at the contact address specified by Amazon (currently security@amazon.com), as required by the DPP;
- Notify affected Customers without undue delay, and in any event as required by applicable law, describing the nature of the incident, the data involved, and the remedial steps taken; and
- Take prompt measures to contain and remediate the incident, cooperate with Amazon and Customers in their investigations, and document the incident and our response.
12. Your rights and choices
Depending on your location, you may have rights under applicable privacy laws with respect to personal information, including the right to request access to, correction of, deletion of, or a copy of the personal information we hold about you, and the right to object to or restrict certain processing. We do not discriminate against anyone for exercising these rights.
To exercise these rights, or to request deletion of Seller Data, email enterprise@multigraphite.com. We may need to verify your identity before responding. We will respond within the time required by applicable law, generally within thirty (30) days. Because we process Seller Data as a service provider, requests concerning Seller Data may be directed to the Customer who controls the account; where a request is made to us, we will assist the Customer as needed.
You may also revoke our access to your Amazon account at any time in Seller Central, and you may unsubscribe from any non-essential communications by using the link provided or contacting us.
13. Cookies and website data
This marketing website does not use advertising or cross-site tracking cookies and does not embed third-party advertising trackers. Our web servers and hosting providers may record standard request logs (such as IP address, user agent, and requested page) for security and operational purposes. This website loads fonts and stylesheet resources from third-party content delivery networks, which may receive your IP address and browser information as part of delivering those resources. If we introduce authenticated application features that use cookies, we will limit them to those strictly necessary for authentication, security, and session management, and will update this Policy accordingly.
14. Children
The Service is intended for businesses and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
15. Data location
Multigraphite is based in the United States, and Seller Data and Account Data are processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have data protection laws different from those of your jurisdiction. Where required, we rely on appropriate legal mechanisms for such transfers.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service, legal requirements, or Amazon policies. We will post the updated version on this page with a revised “Last updated” date. For material changes, including any change affecting how Seller Data is used, we will provide notice by email to the address associated with your account at least thirty (30) days before the change takes effect, except where a shorter period is required by law or by Amazon. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17. Contact us
Questions, requests, or concerns about this Privacy Policy, our data practices, or our compliance with the DPP may be directed to our primary contact and privacy address, enterprise@multigraphite.com, or by mail to:
Multigraphite Enterprises LLC Attn: Privacy & Compliance7901 4th St N, STE 33435
St. Petersburg, FL, 33702
Email: enterprise@multigraphite.com