Security & Data Handling
Last reviewed: 11 September 2026
This page describes the security and data-handling principles used by SSP Ecommerce Services Pvt. Ltd. for the Seller Selling Point service. Security controls are reviewed according to the services, systems and marketplace information involved.
Responsible access
- Seller accounts remain owned and controlled by the seller.
- Marketplace permissions are requested for the documented service purpose.
- Access should be limited to personnel with an approved business need.
- Access is reviewed and removed when no longer required or when compromise is suspected.
- Multi-factor authentication is required where the applicable system supports it.
Credentials and information
Credentials must not be placed in public documents, ordinary chat messages or source code. Sensitive credentials are handled through approved access methods and should be rotated when exposure or compromise is suspected. Marketplace information is used only for the authorised service and is not sold.
System and network protection
Our security approach is designed around layered access control, secure transmission, supported software, endpoint protection, logging, monitoring, backups and protection of public-facing systems. Applicable hosting and service providers may supply additional infrastructure controls. SSP remains responsible for assessing whether controls are appropriate for the information processed.
Incident response
Our incident-response process addresses database compromise, unauthorised access, credential exposure and data leakage through the following phases:
- Preparation: maintain responsibilities, escalation contacts, inventories, backups, logging and response procedures.
- Identification: record the event, assess severity and scope, identify affected systems and information, and preserve relevant evidence.
- Containment: isolate affected systems, restrict access, revoke compromised credentials or permissions, and block further exposure.
- Eradication: remove malicious access, patch identified weaknesses, rotate affected secrets and review privileges.
- Recovery: restore from verified sources where required, test integrity and security, and increase monitoring during restoration.
- Lessons learned: document cause and actions, assign corrective work, and update procedures and risk records.
Incident notification
Incidents are escalated to appropriate management and technical contacts. If Amazon Information is involved, Amazon is notified at security@amazon.com within 24 hours of detection in accordance with Amazon’s Data Protection Policy. Customers, regulators and other parties are notified when legally or contractually required.
Retention and deletion
Information is kept only for the authorised service purpose, applicable marketplace requirements, contractual recordkeeping and legal obligations. Access is removed when no longer needed. Information is deleted or rendered inaccessible when its applicable retention period ends, subject to protected backups and records that must legally be retained.
Reporting a concern
To report a suspected security or privacy issue involving SSP, email info@sspecommerce.com with a concise description and a safe way to contact you. Do not include passwords, access tokens or unnecessary personal information.
Scope and review
This public overview does not disclose confidential defensive details. Clients may request additional security information relevant to their engagement. Security policies and incident procedures should be reviewed at least every six months and after material infrastructure changes or significant incidents.