We build and integrate Amazon Selling Partner API applications, guide sellers and software teams through Amazon’s Restricted Data (PII) approval and Data Protection Policy audit, and review integration code for security and compliance.
Restricted data flows through a scoped, short-lived token, never a long-lived key.
Pinkontin is a software agency that works with the Amazon Selling Partner API. We integrate SP-API into seller and vendor tools (orders, inventory, listings, reports, FBA and finance), help teams qualify for restricted PII roles and pass Amazon’s Data Protection Policy audit, and run independent security code reviews of SP-API integrations. We work with sellers, aggregators and SaaS vendors worldwide, in English and Turkish.
Build the integration, clear the compliance bar, and keep the code secure. Take one or all three.

From a first integration to migrating a legacy Amazon MWS app, we design SP-API connections that are reliable, rate-limit aware and easy to maintain.

Reading a buyer’s name, address or phone number through SP-API means clearing Amazon’s restricted data process. We prepare your architecture, controls and evidence so the review goes smoothly, and help you recover from a rejection.

We review SP-API integrations and wider codebases for security, correctness and compliance, then hand you a prioritized, actionable report instead of a wall of noise.
Amazon’s Data Protection Policy expects specific safeguards around restricted data. These are the controls we design, implement and document with you.
Every call and internal hop protected with modern TLS.
Restricted data encrypted in storage, backups included.
Role-based access so people and services see only what they need.
Keep restricted data only as long as needed, then delete it cleanly.
Audit trails and alerts for access to sensitive data.
A tested plan to detect, contain and report incidents quickly.
Patching, dependency scanning and regular review.
No hardcoded credentials; rotated, centrally managed keys.
PII in SP-API is gated behind specific roles and a short-lived token. Here is what that means in practice.
The role required to read shipping address information for an order.
The roles required to read buyer information for tax documents.
Amazon reviews your app, data flows and controls before granting PII access.
Approved apps do not read PII with a normal token. They request a Restricted Data Token, scoped to a single resource and only the data points they truly need, and it expires within roughly an hour. We design your integration around the RDT so access stays minimal and auditable.
Amazon updated its Data Protection Policy and Acceptable Use Policy in late 2025, so existing integrations may need to revisit their controls.
A clear path, whether you are building new or fixing an integration that stalled at the audit.
We map your Amazon use case, the data you need and the roles it requires.
We implement the SP-API connection, or review the one you already have.
We put the Data Protection Policy controls in place and document them.
We prepare your architecture review, questionnaire and evidence for Amazon.
You get access, and we keep the integration healthy as Amazon’s rules evolve.
SP-API integration, PII compliance and secure code review from a single team.
We design for the Data Protection Policy review from day one, not as an afterthought.
A written estimate before we start, with no surprises later.
We work with sellers and software teams in both languages.
A track record across SaaS, mobile apps and API integrations.
Amazon’s policies change, and we keep your integration compliant.
The Selling Partner API is Amazon’s official API for sellers and vendors to access their data on orders, inventory, listings, reports, FBA and finance, and to automate their Amazon operations.
You request the restricted roles your app needs, then pass Amazon’s review of your data flows and security controls, known as the Data Protection Policy. We prepare the architecture, controls and evidence so that review goes smoothly.
It varies by app and by how ready your controls are. A first approval usually takes several weeks of preparation and review; annual re-checks are faster once your evidence base is in place.
Yes. We review the rejection, find the gaps in your architecture or controls, fix them and help you resubmit with a stronger case.
It is a short-lived, tightly scoped token an approved app uses to read a specific piece of restricted data instead of a long-lived token. It expires within roughly an hour, which keeps access minimal and auditable.
Yes. Amazon MWS is deprecated, and we migrate integrations to the Selling Partner API while keeping your existing workflows running.
Yes. We do standalone security and compliance code reviews of your SP-API integration or wider codebase, with a prioritized report and concrete fixes.
Yes. We work with sellers, aggregators and software vendors worldwide, in English and Turkish.