Amazon SP-API experts

Amazon SP-API development, PII access and code review

We build and integrate Amazon Selling Partner API applications, guide sellers and software teams through Amazon’s Restricted Data (PII) approval and Data Protection Policy audit, and review integration code for security and compliance.

Selling Partner API Restricted Data / PII Data Protection Policy
Amazon marketplaceSP-API + RDTYour application

Restricted data flows through a scoped, short-lived token, never a long-lived key.

What does Pinkontin do with the Amazon SP-API?

Pinkontin is a software agency that works with the Amazon Selling Partner API. We integrate SP-API into seller and vendor tools (orders, inventory, listings, reports, FBA and finance), help teams qualify for restricted PII roles and pass Amazon’s Data Protection Policy audit, and run independent security code reviews of SP-API integrations. We work with sellers, aggregators and SaaS vendors worldwide, in English and Turkish.

Three services, one Amazon SP-API team

Build the integration, clear the compliance bar, and keep the code secure. Take one or all three.

Illustration of an Amazon SP-API integration: a central API hub connected to marketplace services by glowing data lines
Selling Partner API, built right

SP-API development and integration

From a first integration to migrating a legacy Amazon MWS app, we design SP-API connections that are reliable, rate-limit aware and easy to maintain.

  • Login with Amazon (LWA) OAuth and secure token handling
  • Orders, Inventory, Listings, Catalog, Reports and Feeds
  • FBA, Fulfillment, Finances and Notifications
  • Amazon MWS to SP-API migration
  • Rate-limit, retry and error handling that survives production
  • Private and public multi-seller app models
Illustration of SP-API restricted data protection: a glowing shield with a padlock guarding buyer records, with an approval badge
Get and keep restricted data access

PII access and Data Protection Policy compliance

Reading a buyer’s name, address or phone number through SP-API means clearing Amazon’s restricted data process. We prepare your architecture, controls and evidence so the review goes smoothly, and help you recover from a rejection.

  • Restricted role qualification (shipping, tax remittance, tax invoicing)
  • Restricted Data Token (RDT) design and least-privilege access
  • Data Protection Policy gap assessment and remediation
  • Architecture review and security questionnaire preparation
  • Data-flow diagrams, retention and deletion policy, evidence pack
  • Appeal support after a PII access rejection
Illustration of a secure code review: a code editor window with a flagged line under a magnifying glass
An expert second pair of eyes

Secure code review

We review SP-API integrations and wider codebases for security, correctness and compliance, then hand you a prioritized, actionable report instead of a wall of noise.

  • SP-API and PII data-flow review against the DPP controls
  • Authentication, secrets handling and access control
  • Input and output validation and safe logging with no PII leaks
  • Dependency, API and integration risk review
  • Prioritized findings with concrete fixes
  • Re-review to confirm issues are closed

The controls we put in place

Amazon’s Data Protection Policy expects specific safeguards around restricted data. These are the controls we design, implement and document with you.

Encryption in transit

Every call and internal hop protected with modern TLS.

Encryption at rest

Restricted data encrypted in storage, backups included.

Least-privilege access

Role-based access so people and services see only what they need.

Retention and deletion

Keep restricted data only as long as needed, then delete it cleanly.

Logging and monitoring

Audit trails and alerts for access to sensitive data.

Incident response

A tested plan to detect, contain and report incidents quickly.

Vulnerability management

Patching, dependency scanning and regular review.

Key and secret management

No hardcoded credentials; rotated, centrally managed keys.

Restricted roles and the RDT, explained

PII in SP-API is gated behind specific roles and a short-lived token. Here is what that means in practice.

01

Direct-to-consumer shipping

The role required to read shipping address information for an order.

02

Tax remittance and invoicing

The roles required to read buyer information for tax documents.

03

Restricted role approval

Amazon reviews your app, data flows and controls before granting PII access.

The Restricted Data Token (RDT)

Approved apps do not read PII with a normal token. They request a Restricted Data Token, scoped to a single resource and only the data points they truly need, and it expires within roughly an hour. We design your integration around the RDT so access stays minimal and auditable.

Amazon updated its Data Protection Policy and Acceptable Use Policy in late 2025, so existing integrations may need to revisit their controls.

From use case to approved access

A clear path, whether you are building new or fixing an integration that stalled at the audit.

1

Discover

We map your Amazon use case, the data you need and the roles it requires.

2

Build or integrate

We implement the SP-API connection, or review the one you already have.

3

Harden

We put the Data Protection Policy controls in place and document them.

4

Review and audit

We prepare your architecture review, questionnaire and evidence for Amazon.

5

Approved and maintained

You get access, and we keep the integration healthy as Amazon’s rules evolve.

A partner that builds for the audit

All three under one roof

SP-API integration, PII compliance and secure code review from a single team.

Security-first engineering

We design for the Data Protection Policy review from day one, not as an afterthought.

Clear, honest scoping

A written estimate before we start, with no surprises later.

English and Turkish

We work with sellers and software teams in both languages.

8+ years building software

A track record across SaaS, mobile apps and API integrations.

We stay after launch

Amazon’s policies change, and we keep your integration compliant.

Amazon SP-API and PII, answered

The Selling Partner API is Amazon’s official API for sellers and vendors to access their data on orders, inventory, listings, reports, FBA and finance, and to automate their Amazon operations.

You request the restricted roles your app needs, then pass Amazon’s review of your data flows and security controls, known as the Data Protection Policy. We prepare the architecture, controls and evidence so that review goes smoothly.

It varies by app and by how ready your controls are. A first approval usually takes several weeks of preparation and review; annual re-checks are faster once your evidence base is in place.

Yes. We review the rejection, find the gaps in your architecture or controls, fix them and help you resubmit with a stronger case.

It is a short-lived, tightly scoped token an approved app uses to read a specific piece of restricted data instead of a long-lived token. It expires within roughly an hour, which keeps access minimal and auditable.

Yes. Amazon MWS is deprecated, and we migrate integrations to the Selling Partner API while keeping your existing workflows running.

Yes. We do standalone security and compliance code reviews of your SP-API integration or wider codebase, with a prioritized report and concrete fixes.

Yes. We work with sellers, aggregators and software vendors worldwide, in English and Turkish.

Talk to an SP-API team that understands compliance

Whether you are starting an integration, chasing PII access, or need a second pair of eyes on your code, tell us your case and we will map the path.