Be precise about today. Set a high bar for what comes next.

The Bammerce website currently processes only free-beta application information and does not connect Amazon seller accounts. Production SP-API access will not open until the corresponding safeguards are actually implemented.

The website today

Collect less. Explain more.

The following applies to this public website and its early-access application form today.

Data collected

Only application information

Name, work email, company or brand, target marketplaces, capability interests, and an optional message.

  • No Amazon sign-in credentials
  • No Seller Central connection
  • No buyer PII collected or stored
Processing

No applicant database

After Turnstile verification, the Worker sends the submission to Bammerce and the applicant through the email provider. No application database is created.

  • Cloudflare provides network, security, and compute
  • Resend delivers transactional messages; Feishu Mail receives and stores operational email
  • Retained up to 12 months, with earlier deletion available
Website security

Baseline protection by default

The site uses HTTPS, strict security headers, server-side input validation, Turnstile, and request-rate controls.

  • No ads or visitor analytics scripts
  • No non-essential cookies
  • Secrets stored only as Cloudflare secret bindings
Your choices

You control your application information

Email privacy@bammerce.com to request access, correction, or deletion, or to withdraw an early-access application.

  • Requests are verified through email
  • Deletion also stops further follow-up
  • Except minimal records required by law
SP-API launch gates

These controls must exist before seller data is connected

These are production launch requirements, not claims about a system that is not yet live.

01 · ACCESS

OAuth & least privilege

Use Amazon OAuth, map roles to actual API operations, and enforce least-privilege internal access with multi-factor authentication.

02 · PROTECTION

Transport, storage & secret protection

Encrypt data in transit and at rest, keep tokens and keys in controlled secret storage, and exclude tokens and sensitive payloads from logs.

03 · LIFECYCLE

Retention, deletion & incident response

Define retention by data class, support revocation and deletion, and maintain security-incident detection, response, notification, and review procedures.

Security contact

Found a security or privacy issue?

Send enough information to reproduce the issue, but do not send passwords, access tokens, buyer personal information, or other sensitive data through ordinary email.

privacy@bammerce.com