1. Purpose
SalesDash uses Amazon Information to provide services to customers who sell products through Amazon.
This policy establishes how Amazon Information and SalesDash systems may and may not be used. It also establishes our requirements for preventing prohibited marketplace activity, protecting intellectual property, and complying with applicable Amazon Selling Partner and Vendor agreements.
Our basic rule is that Amazon Information may only be used for legitimate SalesDash services authorized by the customer whose information we are accessing.
SalesDash may not be used to violate Amazon policies, manipulate the Amazon marketplace, infringe intellectual property rights, or help a customer or other party violate its agreement with Amazon. Violations of those policies and agreements will result in immediate termination of your SalesDash account and be reported to Amazon.
2. Scope
This policy applies to all Pexium employees and contractors who have access to:
- Amazon Information;
- SalesDash systems that process Amazon Information; or
- credentials, tokens, databases, infrastructure, or administrative tools associated with these systems.
This policy also applies to the development, operation, support, and use of SalesDash functionality that interacts with Amazon.
3. Permitted Use of Amazon Information
Amazon Information may be accessed and used when necessary to provide SalesDash services requested or authorized by the applicable customer.
Permitted uses include:
- Sales and order reporting.
- Inventory management and forecasting.
- Financial and profitability reporting.
- Advertising reporting and management.
- Buy Box and product performance analysis.
- Dashboards and analytics.
- Detecting listing issues.
- Repricing.
- Customer support and troubleshooting.
- Maintaining and securing the SalesDash platform.
- Detecting fraud, misuse, unauthorized access, and security problems.
- Meeting applicable legal, contractual, security, and Amazon requirements.
4. Prohibited Activities
SalesDash and Amazon Information may not be used to engage in, assist with, conceal, or facilitate activities prohibited by Amazon.
Prohibited activities include:
Brushing and Marketplace Manipulation
SalesDash prohibits brushing and other attempts to create artificial or misleading marketplace activity.
SalesDash systems or Amazon Information may not be used to:
- Create or facilitate fake or fraudulent orders.
- Create transactions for the purpose of artificially increasing sales volume or sales rank.
- Send unsolicited merchandise as part of a brushing scheme.
- Generate or facilitate fake reviews or ratings.
- Compensate or improperly incentivize customers for reviews in violation of Amazon requirements.
- Manipulate reviews, ratings, rankings, sales history, Buy Box performance, or other marketplace metrics.
- Create false customer activity or otherwise make a product or seller appear more popular than it actually is.
- Conceal or assist another party in conducting this type of activity.
Employees who become aware of suspected brushing or marketplace manipulation involving SalesDash must report it to management.
Agreement and Policy Violations
SalesDash may not knowingly be used to violate or help another party violate an applicable Amazon Selling Partner, Vendor, or other Amazon agreement or policy.
This includes using SalesDash or Amazon Information to:
- Circumvent Amazon account restrictions or enforcement actions.
- Circumvent Amazon technical or security controls.
- Obtain information that the customer is not authorized to access.
- Misrepresent products, transactions, customers, sellers, or business activity.
- Facilitate fraudulent or deceptive marketplace activity.
- Evade Amazon policies or enforcement mechanisms.
- Assist a customer or other party in conduct that SalesDash knows violates its applicable Amazon agreement.
Suspected violations identified by SalesDash personnel must be reported internally for review and appropriate action.
Other Prohibited Uses of Amazon Information
Amazon Information may not be:
- Sold or rented.
- Used for unrelated advertising or marketing.
- Used for an employee's or contractor's personal purposes.
- Used to market or solicit Amazon customers.
- Provided to unauthorized third parties.
- Used by one customer for the benefit of another customer.
- Used to disclose one customer's information to another customer.
- Combined across customers for unauthorized competitive intelligence or benchmarking.
- Used to develop unauthorized information about Amazon's business or internal operations.
- Downloaded or copied to unauthorized systems or devices.
- Stored in personal cloud storage or personal accounts.
- Used after authorization has ended except as permitted by applicable Amazon requirements or law.
5. Intellectual Property Protection
Pexium respects the intellectual property rights of Amazon, our customers, and third parties.
Users, Employees and contractors may not use SalesDash, or Amazon Information to knowingly infringe or facilitate infringement of copyrights, trademarks, patents, trade secrets, or other intellectual property rights.
This includes:
- Using copyrighted images, photographs, text, product descriptions, software, or other content without appropriate authorization.
- Knowingly assisting a customer in creating or maintaining listings that infringe another party's intellectual property rights.
- Using another party's trademarks or branding without authorization or in a misleading manner.
- Copying or distributing proprietary Amazon materials except as permitted by Amazon.
- Copying, disclosing, or improperly using another customer's confidential or proprietary information.
- Using Amazon Information to obtain or disclose trade secrets or other protected information.
- Removing or attempting to circumvent intellectual property protections or restrictions.
SalesDash employees are not expected to make legal determinations regarding ownership of intellectual property. However, if an employee becomes aware of a credible claim or clear indication that SalesDash is being used to facilitate infringement, the matter must be reported to management for review.
Where appropriate, access or related activity may be restricted while the matter is reviewed.
6. Protection of SalesDash Intellectual Property and Source Code
Pexium also protects its own intellectual property and the systems used to process Amazon Information.
Access to SalesDash source code, system documentation, credentials, infrastructure, and other proprietary information is limited according to job responsibilities.
Users, Employees and contractors may not:
- Provide SalesDash source code or proprietary technical information to unauthorized parties.
- Place proprietary source code in public repositories.
- Place credentials, tokens, passwords, or other secrets in source-code repositories.
- Copy proprietary software or technical documentation for personal use.
- Disclose confidential system information to unauthorized parties.
Access to source code and development systems is restricted to authorized personnel.
7. Compliance With Amazon Selling Partner and Vendor Agreements
SalesDash provides tools and information to assist customers in managing their Amazon businesses. Customers remain responsible for complying with their agreements with Amazon.
SalesDash will not knowingly develop, configure, or operate functionality for the purpose of helping a customer violate an Amazon Selling Partner Agreement, Vendor Agreement, or other applicable Amazon policy.
When assisting customers, SalesDash personnel must not knowingly advise or instruct a customer to circumvent Amazon rules, restrictions, security controls, or enforcement actions.
If a customer requests functionality or assistance that appears intended to violate an Amazon agreement or policy, the employee must stop and refer the matter to management.
Management will determine whether the requested activity is permitted before work continues.
8. Customer Authorization
SalesDash accesses Amazon Information through authorization provided by the applicable customer.
If a customer's authorization is revoked or terminated, access through that authorization stops.
Amazon Information remaining in our systems after authorization ends is handled according to our Data Retention and Secure Deletion Policy and applicable Amazon requirements.
9. Access to Amazon Information
Access to Amazon Information is limited to employees and contractors who require it to perform their jobs.
Our access requirements include:
- Unique user accounts.
- No shared accounts for access to Amazon Information.
- Least-privilege access based on job responsibilities.
- Quarterly access reviews.
- Removal or adjustment of access within 24 hours following termination or a role change when access is no longer required.
- Account lockout after no more than 10 consecutive failed login attempts.
- Appropriate authentication controls for systems containing Amazon Information.
Detailed requirements are maintained in our Identity and Access Management Policy.
10. Personal Devices and Local Copies
Amazon Information is not stored on personal devices.
Employees and contractors may not copy Amazon Information to personal computers, phones, tablets, USB drives, personal cloud storage, or other unauthorized locations.
Amazon Information must remain within approved SalesDash systems and authorized processing environments.
11. Data Minimization
SalesDash only collects and processes Amazon Information needed to provide our services.
12. Retention and Deletion
Amazon Information is retained only as necessary to provide authorized services and as permitted by applicable Amazon requirements.
When Amazon Information must be deleted because of a customer request, an Amazon request, or another applicable requirement, it is handled according to our Data Retention and Secure Deletion Policy.
That policy establishes our deletion timelines, secure destruction methods, backup handling, and deletion confirmation procedures.
13. Sharing Amazon Information
Amazon Information may be shared only with:
- Pexium employees or contractors who require the information to perform their jobs.
- Approved service providers when access is necessary to operate or secure SalesDash and is permitted by Amazon.
- Amazon when required.
- Government or legal authorities when required by applicable law or valid legal process.
Amazon Information may not be disclosed to unauthorized third parties.
14. Credentials and Authentication Information
Credentials may not be:
- Shared with unauthorized people.
- Stored in publicly accessible locations.
- Placed in public source-code repositories.
- Sent through unauthorized communication methods.
- Used by someone other than the person or system authorized to use them.
Suspected credential exposure or compromise must be reported immediately.
15. Reporting Suspected Violations
Users, Employees and contractors must report suspected:
- Brushing.
- Fake or fraudulent orders.
- Review or ratings manipulation.
- Marketplace manipulation.
- Intellectual property infringement involving SalesDash.
- Violations of Amazon Selling Partner or Vendor agreements.
- Attempts to circumvent Amazon controls or enforcement actions.
- Unauthorized access to Amazon Information.
- Unauthorized disclosure or transfer of Amazon Information.
- Improper use of Amazon Information.
- Lost or exposed credentials.
- Other suspected violations of Amazon requirements.
Reports should be made promptly to management or the appropriate security contact.
Employees should report a reasonable concern even when they do not have enough information to determine whether an actual violation occurred.
Management will review the matter and determine what action is appropriate.
16. Response to Suspected Violations
When a suspected violation is reported, Pexium will review the available information and determine the appropriate response.
Depending on the circumstances, actions may include:
- Investigating the activity.
- Restricting or suspending access.
- Preserving relevant logs and records.
- Contacting the affected customer.
- Requiring corrective action.
- Disabling functionality associated with prohibited activity.
- Escalating the matter internally.
- Reporting the matter to Amazon when required.
- Handling the matter under the Incident Response Plan when it involves a security incident.
Pexium will not knowingly continue providing functionality that is being used for prohibited activity.
17. Organizational Changes
Pexium reviews significant organizational and technical changes to determine whether they affect our security controls or handling of Amazon Information.
Examples include:
- Significant IT or information security projects.
- Changes to Amazon Information storage or processing locations.
- Mergers, acquisitions, or divestitures.
- Changes to subcontractors with access to Amazon Information.
- Major infrastructure changes.
The detailed process is maintained in our Organizational Change Notification Policy.
18. Employee Responsibilities
Users, Employees and contractors with access to Amazon Information are expected to:
- Use Amazon Information only for legitimate SalesDash business purposes.
- Access only the information required for their jobs.
- Follow applicable Amazon requirements when working with Amazon-related functionality.
- Protect Amazon Information and credentials.
- Respect intellectual property rights.
- Never knowingly assist a customer in violating an Amazon agreement or policy.
- Never participate in or facilitate brushing, fake reviews, fraudulent transactions, or marketplace manipulation.
- Use only approved systems and accounts.
- Complete required security training.
- Report suspected violations promptly.
If an employee is unsure whether an activity is permitted, the employee should obtain approval from management before proceeding.
19. Violations of This Policy
Violations of this policy will be investigated.
Depending on the circumstances, Pexium may:
- Remove or restrict access.
- Suspend the activity involved.
- Investigate affected systems and information.
- Require corrective action or additional training.
- Take disciplinary action, including termination of employment or contract.
- Notify Amazon when required.
- Take legal action when appropriate.
Access may be suspended immediately when necessary to protect Amazon Information, our customers, Amazon, or Pexium systems.
20. Exceptions
Exceptions must be documented and approved by management.
An exception cannot authorize activity prohibited by applicable Amazon agreements.
21. Related Policies
This policy should be read together with our other security policies, including:
- Data Usage Policy
- Identity and Access Management Policy
- Data Retention and Secure Deletion Policy
- Incident Response Plan
- Backup, Restore and Disaster Recovery Policy
- Data Loss Prevention Policy
- Organizational Change Notification Policy
- Security Awareness and Training Policy
The detailed technical controls and procedures supporting this policy are maintained in those documents.
22. Review
Management reviews this policy at least annually and when significant changes are made to our systems, Amazon Information handling, or applicable Amazon requirements.