This is a working draft. Have counsel review it before the application is submitted for listing.
When you authorize the application, Amazon gives us a refresh token tied to your seller account and your merchant token. When you ask the assistant a question, we call the Selling Partner API on your behalf and retrieve only the data needed to answer it.
Refresh tokens are encrypted at rest with AES-256-GCM under a key held separately from the datastore. Data retrieved from the Selling Partner API is used to answer your request and is not retained beyond the period required to serve it.
Revoke access at any time from Manage Your Apps in Seller Central. On revocation or on written request we delete the stored authorization and any associated records.
support@shiptronix.com