Amazon access through Amazon
You connect Amazon Ads on Amazon-hosted authorization screens. SellerPilot never asks for or stores your Amazon password, and you can revoke access from Amazon at any time.
This page brings together how SellerPilot handles account access, customer data, and changes to your campaigns, with links to the full policies. It describes controls built into the product. It is not a third-party audit report, and SellerPilot does not claim certifications such as SOC 2 or ISO 27001. SellerPilot is not affiliated with or endorsed by Amazon.
Each item below reflects how the product works today.
You connect Amazon Ads on Amazon-hosted authorization screens. SellerPilot never asks for or stores your Amazon password, and you can revoke access from Amazon at any time.
Amazon refresh credentials are encrypted with AES-256-GCM before they are stored, bound to your organization, and never sent to the browser.
Customer tables use PostgreSQL row-level security, and every request runs scoped to the signed-in organization, on top of server-side permission checks.
Passwords are hashed with scrypt and a per-user salt. Sessions use HTTP-only cookies that expire after 8 hours, and sign-in and recovery endpoints are rate limited.
Recommendations and Autopilot run in observe, shadow, recommend, or approval modes. Nothing is changed in your Amazon account until a person on your team approves it.
Account owners and admins can review an activity log of who did what, and synchronization status shows when your data was last refreshed.
There is no help center yet. For how-to questions, contact support or browse the guides in Resources.
Architecture, identity, Amazon connection, synchronization, and how to report a security issue.
What we collect, why, how long we keep it, analytics and cookie choices, and your data rights.
The agreement that governs your use of SellerPilot.
How to reach us about your account, Amazon connection, billing, security, or a privacy request, and how quickly we respond.
How the Amazon Ads connection works, what it covers, and how data freshness is shown.
Guides on Amazon PPC software, ACoS versus ROAS, and running a PPC audit.
Email support@getsellerpilot.com. To report a suspected vulnerability, include the affected URL and safe reproduction steps. Never send passwords, access tokens, refresh credentials, or full payment-card details.
No online service can promise absolute security. Read the security overview, privacy policy, and terms before authorizing account access.