Only application information
Name, work email, company or brand, target marketplaces, capability interests, and an optional message.
- No Amazon sign-in credentials
- No Seller Central connection
- No buyer PII collected or stored
The Bammerce website currently processes only free-beta application information and does not connect Amazon seller accounts. Production SP-API access will not open until the corresponding safeguards are actually implemented.
The following applies to this public website and its early-access application form today.
Name, work email, company or brand, target marketplaces, capability interests, and an optional message.
After Turnstile verification, the Worker sends the submission to Bammerce and the applicant through the email provider. No application database is created.
The site uses HTTPS, strict security headers, server-side input validation, Turnstile, and request-rate controls.
Email privacy@bammerce.com to request access, correction, or deletion, or to withdraw an early-access application.
These are production launch requirements, not claims about a system that is not yet live.
Use Amazon OAuth, map roles to actual API operations, and enforce least-privilege internal access with multi-factor authentication.
Encrypt data in transit and at rest, keep tokens and keys in controlled secret storage, and exclude tokens and sensitive payloads from logs.
Define retention by data class, support revocation and deletion, and maintain security-incident detection, response, notification, and review procedures.
Send enough information to reproduce the issue, but do not send passwords, access tokens, buyer personal information, or other sensitive data through ordinary email.