Maximum Solution India Logo
Maximum Solution India Seller Growth & Support
Location Get in Touch
• DATA PRIVACY

Data Privacy & Security Policy

How Maximum Solution India collects, uses, protects, and manages client and seller data in the course of providing Amazon account management services.

Last Updated: June 2025 Amazon SP Portal Compliant

Maximum Solution India ("we", "us", "our") is committed to protecting the confidentiality, integrity, and availability of data entrusted to us by our clients. This policy describes our practices for collecting, using, storing, securing, and disposing of personal and business data in the course of providing Amazon seller account management services.

1. Data We Collect

Amazon Required

We collect the following categories of data from clients and their Amazon accounts:

  • Business Information Company name, registered address, GST/business registration number, contact person name and designation.
  • Personal Identifiable Information (PII) Name, email address, phone/WhatsApp number.
  • Seller Account Data Amazon Seller Central login credentials (where access is granted), ASIN data, inventory levels, order history, advertising performance data, account health metrics, and sales reports.
  • Communication Records Emails, WhatsApp messages, and form submissions related to service delivery.

We collect only the minimum data necessary to deliver contracted services. We do not collect payment card information, bank account details, or personal government ID numbers unless explicitly required for a specific account management task.

2. How We Use Your Data

We use collected data solely for the following purposes:

  • Managing and operating your Amazon Seller Central account on your behalf
  • Creating, optimizing, and monitoring product listings
  • Managing PPC advertising campaigns
  • Monitoring and maintaining account health
  • Preparing performance reports and strategy recommendations
  • Responding to Seller Support cases and account issues
  • Internal team coordination and service delivery

We do not use your data for any marketing, advertising, or commercial purpose unrelated to the delivery of your contracted services.

3. PII Data Retention

Amazon Required — PII Retention
  • Active Engagement We retain client PII and seller account data for the full duration of the active service engagement.
  • Post-Contract Retention Following contract termination, we retain the minimum necessary records (invoices, summary reports) for up to 90 days for administrative and legal compliance purposes.
  • Deletion All client PII, Seller Central access credentials, account data, and communication records are permanently deleted from our systems within 30 days of written contract termination notice, unless a longer retention period is required by Indian law.
  • Backup Systems Backup copies are purged on the same schedule as primary data, within 30 days of the deletion request.

Upon request, clients may receive written confirmation that their data has been deleted. Submit deletion requests to info@maximumsolutionindia.com.

4. Credential Management

Amazon Required — Credential Management
  • Storage Amazon Seller Central credentials are never stored in plaintext. Where credential storage is required, we use encrypted password management tools with AES-256 encryption.
  • Access Controls Seller Central access is granted on a role-based, minimum-privilege basis. Only team members directly assigned to your account are permitted to access your Seller Central environment.
  • Shared Logins Prohibited We do not use shared login accounts. Each authorized team member uses individually identifiable credentials where possible.
  • Rotation Client credentials provided to us are stored only for the duration of active account management. Clients are encouraged to update or revoke access immediately upon contract termination.
  • User Invitations Preferred Where Amazon permits, we request Sub-User account invitations through Seller Central rather than requesting primary login credentials, providing granular permission controls.
  • Audit Access to client accounts is logged and reviewed by our account lead on a monthly basis to ensure continued appropriateness.

5. Network Protection

Amazon Required — Network Protection
  • Encryption in Transit All data transmitted between our team and client accounts is encrypted using TLS 1.2 or higher. We do not transmit sensitive account data over unencrypted channels.
  • Encrypted Storage Client data stored on our systems is encrypted at rest. We use reputable, enterprise-grade cloud storage and collaboration tools with built-in encryption.
  • Device Security All team members accessing client accounts are required to use updated, password-protected devices with active antivirus/endpoint protection software.
  • Network Security Team members are required to access client accounts only over secured, private networks. Use of public Wi-Fi networks to access Seller Central is prohibited.
  • Access Monitoring We maintain access logs for Seller Central sessions managed on behalf of clients.
  • Software Updates All software and operating systems used in service delivery are kept up to date with current security patches.

We conduct periodic internal security reviews to assess and update our network protection practices in line with current industry standards.

6. Incident Management & Breach Response

Amazon Required — Incident Management
  • Detection We monitor our systems for unauthorized access, data exposure, or security anomalies on an ongoing basis.
  • Containment Upon detecting a security incident, we immediately isolate affected systems and revoke any potentially compromised credentials.
  • Client Notification We will notify affected clients within 48 hours of confirming a security incident that involves their data. Notification will be sent to the registered email address on file and will include: the nature of the incident, data categories affected, immediate steps taken, and recommended client actions.
  • Remediation Following containment, we conduct a root cause analysis and implement corrective measures to prevent recurrence.
  • Reporting Where required by applicable Indian data protection regulations, we will notify relevant authorities within the legally mandated timeframe.
  • Documentation All security incidents are documented, including the incident timeline, response actions, and outcome, and records are retained for a minimum of 2 years.

To report a security concern or suspected data breach involving your account data, contact us immediately at info@maximumsolutionindia.com or +91 81785 76972.

7. Third-Party Data Sharing

We do not sell, rent, or share client data with third parties. Data is shared only with:

  • Internal team members on a need-to-know basis
  • Amazon Seller Central systems as part of account management activities
  • Tool providers strictly necessary for service delivery (e.g., advertising dashboards, keyword research tools), under appropriate data handling agreements

All third-party tools used in service delivery are reviewed for security compliance before adoption.

8. Client Rights & Contact

Clients have the right to:

  • Request a copy of all data we hold relating to them
  • Request correction of inaccurate data
  • Request deletion of their data (see Section 3)
  • Withdraw consent for data processing (subject to contractual obligations)

To exercise any of these rights, contact us:

Phone / WhatsApp
Hours
Mon – Sat, 10:00 AM – 7:00 PM IST
Address
RZf-1/90A, Gali No. 1, Mahavir Enclave, Palam, New Delhi - 110045

This policy was last reviewed in June 2025. We reserve the right to update this policy as our practices evolve. Material changes will be communicated to active clients via email.

Questions About Our Privacy Practices?

Contact our team directly. We're committed to full transparency about how we handle your data.

Message sent successfully!