Datenschutz Amazon
Hinweis für Kundinnen und Kunden: Diese Seite beschreibt ausschließlich den Umgang mit Bestelldaten aus dem Amazon-Marktplatz. Die allgemeine Datenschutzerklärung unseres Shops finden Sie unter Datenschutzerklärung.
Amazon Data Protection and Data Handling Policy
Controller: Eve Textile GmbH, Röhrstraße 14, 64372 Ober-Ramstadt, Germany
Contact: info@evetextile.de
Last updated: 18 August 2026
1. Scope
This policy describes how Eve Textile GmbH collects, processes, stores, uses, shares and disposes of “Amazon Information” — data we retrieve through the Amazon Selling Partner API (SP-API) for our own Amazon selling account. Our application is private and self-authorised. It is not published, not listed in the Marketplace Appstore, and cannot be authorised by any other selling partner. We are not a solution provider for third parties and we neither receive, process nor store Amazon Information belonging to any other selling account.
2. Data we collect
Only the data required to fulfil an order:
- Order identifier and order status
- Buyer name, delivery address and billing address
- The anonymised buyer contact address provided by Amazon
- Item, quantity, price, tax and shipping data
We never request, receive or store payment card data or bank details of Amazon buyers. Restricted data is retrieved exclusively through Restricted Data Tokens (RDT), limited to the data elements required for the specific purpose.
3. How we process the data
Order import into our warehouse management system, picking and packing, creation of shipping labels, shipping confirmation with tracking, invoicing and statutory bookkeeping. Amazon Information is never used for profiling, advertising, market research, resale, licensing or the training of machine-learning models.
4. Where and how we store the data
- Encrypted PostgreSQL database located in Frankfurt am Main, Germany
- Application servers located in Nuremberg, Germany
- AES-256 encryption at rest; TLS 1.2 or higher in transit, with HSTS enabled
- SP-API refresh tokens and API credentials are additionally encrypted at application level with AES-256-GCM before being written to the database
- Access is restricted to individually named accounts with mandatory multi-factor authentication, granted on a least-privilege basis and fully logged
- The database accepts no direct public connections; access is brokered through an authenticated API layer with Row Level Security
5. Who the data is shared with
Only with parties strictly necessary to fulfil an order. All of them are located within the EU/EEA and each is bound by a data processing agreement pursuant to Article 28 GDPR:
- Pixkom GmbH, Hohentrüdinger Str. 11, 91747 Westheim, Germany — our software provider, which operates our single-tenant warehouse management instance on our behalf and strictly on our documented instructions, together with its EU hosting and database providers.
- Shipping carriers (DHL, DPD) — receive only the recipient name and delivery address of the individual parcel, solely to produce the shipping label and deliver the shipment.
- Our external tax advisor — receives invoice data only to the extent required for statutory bookkeeping and VAT reporting under German law.
No party receives Amazon Information for its own purposes. Amazon Information is never sold, rented or licensed, and is never transferred outside the EU/EEA.
6. How long we keep the data and how we dispose of it
- Minimisation after 30 days: an automated daily job irreversibly removes buyer telephone numbers and the Amazon relay e-mail address 30 days after shipment.
- Statutory exception: invoice records — including the buyer name and address that § 14 UStG requires on an invoice — are retained for 10 years, as mandated by § 147 AO and § 14b UStG. The Amazon Data Protection Policy expressly permits retention where a binding legal obligation applies.
- Security logs: retained for 12 months; they contain no personally identifiable information.
- Backups: encrypted; snapshots expire after 7 days and off-site copies after 30 days, after which they are destroyed automatically.
7. Data subject rights
Data subjects may request information, rectification, erasure, restriction of processing and data portability under Articles 15 to 20 GDPR at any time by writing to info@evetextile.de. We respond within 30 days. Erasure is carried out unless a statutory retention obligation prevents it, in which case processing is restricted instead.
8. Security incidents
We maintain a documented incident response plan with named roles, reviewed at least every six months. Security incidents involving Amazon Information are reported to security@amazon.com within 24 hours of detection. Where legally required, the competent supervisory authority is notified under Article 33 GDPR within 72 hours and affected data subjects under Article 34 GDPR.
9. Incident Management Point of Contact
Deniz Koçak, Managing Director — info@evetextile.de
Deputy: Ayhan Duran, Managing Director
Eve Textile GmbH, Röhrstraße 14, 64372 Ober-Ramstadt, Germany
Reachable Monday to Friday 09:00–18:00 CET; for critical incidents within 2 hours at any time.