Authorization
Connections are created only after a seller owner or administrator approves access. Sellers can revoke access from their own account settings.
Security and data handling
We limit data collection to the agreed operating work, keep credentials away from browser code, and restrict access by customer workspace and job responsibility.
Control areas
Security controls are reviewed as the service, infrastructure, staffing, and applicable policies change.
Connections are created only after a seller owner or administrator approves access. Sellers can revoke access from their own account settings.
Application secrets and authorization tokens are processed server-side and excluded from public pages, browser scripts, screenshots, support messages, and public repositories.
Customer workspaces are separated. Staff access is limited according to assigned accounts and job responsibilities, with administrative access kept to necessary personnel.
Public web traffic uses HTTPS/TLS. Sensitive service credentials and retained operational records are protected through server-side storage controls and restricted system access.
Operational and security events are logged for troubleshooting, access review, incident investigation, and service continuity without intentionally logging secret token values.
Data is retained only for active services, agreed reporting periods, business records, legal requirements, and security review, then deleted, anonymized, or restricted.
Shared responsibility
Only an account owner or authorized administrator should approve a connection.
Customers decide which employees may request reports and use the workspace.
Seller passwords, API secrets, refresh tokens, and buyer personal information must not be sent by email or support chat.
Tell us when staff, ownership, service scope, or authorization requirements change.
Security contact
Include your company name, a safe description of the concern, the affected marketplace, and a contact person. Do not include passwords, tokens, secret keys, or buyer personal information.