1. Responsible business
The following business is responsible for personal information and seller data handled by GRT Store Operations Management.
- Name
- GRT LLC
- Address
- Room 206, 3275-22 Fusa, Abiko-shi, Chiba 270-1101, Japan
- Representative
- Motoki Shiozawa, Representative Member
Retained personal data disclosures: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
Privacy manager: Motoki Shiozawa. Subscriber, store staff and inquiry information is used for identity verification, integration setup, contracts and billing, support, important notices and abuse prevention. Purposes are stated before direct written collection. Retention and deletion of subscriber, store staff and inquiry information (including email): Inquiries are kept for at most one year after resolution; contract and billing records for at most seven years after termination. Unnecessary information is deleted sooner. Statutory retention identifies the law, fields and deadline and is separately controlled. The same deadlines apply to backups. Platform rules take priority for API-supplied information.
Handling of Amazon data
2. Information collected (Collected)
Users provide names, company names, contact details, email addresses, contract and billing information, and inquiry content when contacting us or contracting. The SaaS collects OAuth authorization information, activity records, authentication events and transient IP processing. We obtain Amazon data through SP-API after each seller authorizes access. We do not collect Amazon login passwords.
The SaaS processes full IPs transiently in transit and memory for abuse detection, discarding them at request end and within 15 minutes. Retained Amazon-data system logs exclude full IPs and other PII, except documented legal requirements specifying law, fields and expiry. Static-site delivery logs are a separate class.
Information obtained from Amazon
- Orders and sales: Order identifiers, creation dates, SKUs/ASINs, item quantities and sales totals by product. Operations and fields are reviewed; Japan postal codes are discarded after receipt without storage.
- Amazon Fulfillment: FBA available, reserved, inbound and unfulfillable inventory; inbound shipment identifiers, quantities and status; GET_FBA_MYI_ALL_INVENTORY_DATA inventory reports.
- Finance and Accounting: Transaction, fee, refund, deposit and settlement amounts, transaction dates, and GET_V2_SETTLEMENT_REPORT_DATA_FLAT_FILE_V2 settlement reports.
- Product Listing: SKUs/ASINs, product names and attributes, listing status and errors, quantities and the seller’s own listing prices.
- Selling Partner Insights: We display Japan marketplace participation from Sellers API getMarketplaceParticipations and account status (accountStatuses), order defect rate (orderDefectRate) and late shipment rate (lateShipmentRate) from the Seller Performance Report (GET_V2_SELLER_PERFORMANCE_REPORT). Metrics are limited to non-restricted aggregates and reporting periods returned for the authorized Japanese store; unavailable metrics are not displayed. We do not obtain buyer-level or free-text feedback reports or traffic reports requiring Brand Analytics.
The initial release requests no restricted roles and does not obtain restricted buyer PII such as names, street addresses, emails and phone numbers. In Japan, Orders API can still return postal codes without restricted roles; DPP classifies postal codes as PII. Orders v2026-01-01 searchOrders/getOrder use basic datasets without includedData; BUYER, RECIPIENT and PAYMENT are not requested. FULFILLMENT is also not requested; individual order shipping and fulfillment status is outside the display scope. FBA inbound shipment status comes from the separately listed Fulfillment Inbound API. Postal codes and other unneeded non-restricted location fields are discarded in memory before logs or storage. Unexpected restricted fields stop processing. FBA/FBM responses, free text and field combinations are reviewed before enablement. Seller identity and telemetry PII require applicable safeguards before enablement.
Amazon: Orders PII / Amazon: DPP
Role definitions: https://developer-docs.amazon.com/sp-api/docs/roles-in-the-selling-partner-api
Type-to-role mappings: https://developer-docs.amazon/sp-api/docs/role-mappings-for-types
Japanese order field rules: https://developer-docs.amazon/sp-api/docs/access-orders-pii
3. Purposes of use (Used)
- Names, contacts and contract information: registration, identity verification, contract administration, inquiries, support and important notices.
- Billing/payment information: invoicing, payment confirmation and legally required records.
- Authorization information and Amazon data: the authorizing seller’s order, listing, inventory and inbound management, financial reconciliation and store performance display.
- Activity, authentication and access logs: abuse prevention, troubleshooting, security monitoring and quality improvements to this service.
We explain purposes before directly collecting personal information through the relevant screen or notice. Changes beyond reasonably related purposes require prior consent unless a legal exception applies. Amazon data is used only as needed to serve the authorizing seller, never for data sales, advertising, external AI training or analysis/disclosure for other customers. Store comparisons are limited to authorized data within the same subscription.
Purposes of use: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
Amazon data use: https://sellercentral.amazon.com/solution-provider/policy?policyType=AUP&locale=en_US
4. Storage (Stored)
Cloud storage and provider countries: 日本 / Japan. Processing countries, including staff and suppliers, and safeguards addressing foreign environments: Japan. Access is limited to managed Japan-based staff and suppliers. We assess the legal system and protect data through contracts, access controls and annual reviews. Amazon data is attributed to its seller, tenant and source, separated and encrypted in access-controlled databases, object storage and backups. Authorization tokens are never stored on the public website or in browsers.
Retention is defined by data class. For Amazon operational data, we apply the shortest of the published ceiling of 90 days, the class-specific ceiling, purpose expiry and applicable deletion deadline. Superseded snapshots have a 30-day ceiling, reviewed business history a 12-month class ceiling, temporary data 24 hours and backups seven days, all subject to that shorter rule. The 30-day deletion deadline following the earliest applicable trigger takes precedence. Credentials, sanitized security logs and legal records are separately classified; that does not permit longer storage of raw business data or PII.
Tokens are retained only while authorization is valid and the service needs them. Personal and contract record terms: Inquiries are kept for at most one year after resolution; contract and billing records for at most seven years after termination. Unnecessary information is deleted sooner. Statutory retention identifies the law, fields and deadline and is separately controlled. The same deadlines apply to backups. Static-site logs are described below.
Source attribution and storage: https://sellercentral.amazon.com/solution-provider/policy?policyType=DPP&locale=en_US
5. Security measures (Protected)
The following are mandatory measures under our security policy.
- Organizational: designated accountable owner and Incident Management Point of Contact (IMPOC), handling rules, periodic access reviews, incident response and supplier oversight.
- Personnel: annual training, confidentiality obligations and access limited to staff with business need.
- Physical: managed devices/media, loss prevention, storage encryption on every handling device, screen lock within 15 minutes of inactivity, and secure disposal.
- Technical: WAF on public ingress, TLS 1.2 or later, AES-256 or approved equivalent encryption of data, backups and credentials at rest, KMS key management, MFA for all users, lockout for at least 30 minutes after no more than 10 consecutive login failures, monitoring, vulnerability assessments and penetration tests including APIs.
- Foreign environments: review of processing-country systems and safeguards through contracts and ongoing checks.
See our Security Policy. We explain specific measures on inquiry through the privacy contact to the extent that disclosure does not compromise security.
Security measures: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
Policy update effective 2026-08-25: https://developer.amazonservices.com/policy-update-for-sp-api
Employees and approved contractors located in Japan may access Amazon data for service operation, store-requested support, troubleshooting and security. Access is limited to authorization information, store operational data and sanitized logs necessary for the task, restricted by staff member, store and task using least privilege, and logged and supervised. Data is not used for our own advertising, external AI training or disclosure to other stores. Access, processing, disclosure and outsourcing outside Japan are prohibited.
7. Deletion and revocation (Deleted)
You may revoke app authorization at any time through Seller Central’s Apps and Services. Collection, access and synchronization stop on revocation. We securely delete data within 30 days of the earliest deletion trigger, including revocation, contract termination, Amazon’s request, loss of entitlement or data becoming unnecessary. Any shorter applicable deadline takes precedence.
Deletion includes authorization tokens, production data, replicas, caches, queues, exports, supplier copies, snapshots and backups. Deletion and revocation records are reapplied during backup restoration to prevent reuse of deleted information. We record completion and provide certification if Amazon requests it. Legally required records are separately retained after documenting the law, fields and deadline, with access limited to the legal purpose, and deleted after that period. Subscription cancellation and authorization revocation require separate steps.
Deletion: https://sellercentral.amazon.com/solution-provider/policy?policyType=DPP&locale=en_US
Revocation: https://developer-docs.amazon.com/sp-api/docs/revoke-authorizations
If we reasonably determine that a personal data breach has occurred, we immediately notify Amazon at security@amazon.com. If we suspect unauthorized third-party access to Amazon Information, we report to the same contact within 24 hours of becoming aware of the suspicion, never more than 24 hours, without waiting for confirmation, and provide updates as needed. The immediate personal data breach notice is not delayed until this deadline.
Handling of Yahoo! Shopping information
We do not retain any Yahoo! Shopping purchaser personal information, without exception. Order numbers, related identifiers, products, statuses and inquiry text that may identify a purchaser are subject to the same restriction. They are excluded from databases, files, logs, caches, backups and persistent sessions. Other information supplied by LY Corporation through the Shopping Store API or test API is also not retained unless LY Corporation separately instructs its storage. Such instructions apply only to other information and never to purchaser personal information. Any instructed storage is limited to specified fields, purposes and periods.
利用者は、ショッピング出店 API の利用により取得することができる利用者または顧客から購入した購入者の個人情報を一切保持しないものとする.
また、利用者は、ショッピング出店 API およびテスト環境API の利用に伴い LINE ヤフーから提供を受ける情報について、別途 LINE ヤフーが保管を指示する情報を除き、一切保持しないものとする.
Yahoo! Shopping Store API Terms, Article 10 (Japanese)
Features involving purchaser information follow lawful store instructions and the non-retention obligation in Article 10. Temporary memory processing is limited to what is necessary, and information is discarded when processing ends. It is never recorded in databases, logs, caches, queues, files or backups. Purchaser-data storage, file exports and saved shipping labels are outside the feature scope.
Use is limited to the authorized store’s order, product, inventory and inquiry operations, excluding our own advertising, external AI training and disclosure to other stores. Yahoo! Shopping API calls and information processing are limited to controlled environments and personnel in Japan. No production data is accessed from outside Japan.
Authorization credentials are encrypted, limited to what is necessary and contain no purchaser data. Disconnecting in this service immediately stops the affected store’s API calls and deletes credentials held by us. Withdrawal of Yahoo! JAPAN consent is a separate action in its official interface. Our deletion does not guarantee immediate invalidation of all platform tokens.
Common: sharing, outsourcing and foreign processing
No joint use of personal data. Third-party disclosure requires prior consent or a legal exception; legally required checks and records apply to disclosures and receipts. Processors, work, data and processing countries: GMO Internet, Inc. (Japan): provision of the servers (Onamae.com VPS) for this site and the service. Data is processed and stored on servers in Japan. GMO Internet, Inc. (Japan): email service for receiving inquiries and requests, including sender names, contact details, message bodies and attachments, received and stored through its email service. Storage countries: 日本 / Japan. Staff/supplier processing countries and protections: Japan. Access is limited to managed Japan-based staff and suppliers. We assess the legal system and protect data through contracts, access controls and annual reviews. Selection, confidentiality, security requirements, re-outsourcing approval and periodic review govern suppliers. Suppliers must not retain Yahoo! Shopping purchaser information.
Common exceptions for statutory retention or foreign disclosure and outsourcing do not apply to Yahoo! Shopping purchaser information. Subscriber contract and billing records and public static-site delivery logs are separate data classes; their rules do not authorize purchaser-information retention. All production-data processing and access, including credentials, by employees and contractors is limited to Japan. We do not disclose or outsource production data outside Japan or allow access from outside Japan.
Common: security and breach response
Mandatory policy controls cover organizational measures (owners, handling rules, access reviews and incident response), personnel measures (confidentiality, education and supervision), physical measures (device/media management, encryption and secure disposal) and technical measures (protected transport/storage, MFA, store separation, access control and monitoring). Foreign environments require assessment of local frameworks and safeguards. Reportable breaches are notified to the Personal Information Protection Commission and affected individuals. For entrusted store information, we notify and assist the store. Further safeguards can be explained through our contact without compromising security.
8. Individual rights and requests
You may request notice of purposes, disclosure of retained personal data and third-party disclosure records, corrections, additions, deletion, suspension of use, erasure or cessation of third-party provision. Contact the address below with your name, contact details, relevant information and request. We verify you or an authorized representative using the minimum necessary documentation, respond without delay and explain any refusal. Disclosure normally uses your preferred method, including electronic records. Requests are free. Do not attach identity documents to your initial email.
Individual rights procedures: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
9. Cookies and external transmissions
This public static website uses no cookies, analytics or advertising tools, tracking tags, local storage, external fonts or third-party embeds. HTML, CSS and images are served from this site; no program instructing external information transmission is delivered to browsers. External links navigate to another site when clicked.
We collect IP address, request URL excluding query strings, time, HTTP status and user agent from normal HTTPS requests on our web server running on a VPS in Japan (provided by GMOインターネット株式会社 / GMO Internet, Inc.(日本 / Japan、お名前.com VPS / Onamae.com VPS)) and use them for page delivery, troubleshooting and abuse prevention. We manage these logs, retain them for no more than 14 days and then delete them. The VPS provider supplies the infrastructure. These requests are distinguished from external transmissions through analytics tags.
Applicability of external transmission rules is assessed for each service’s features and actual transmissions. We do not assume the authenticated SaaS is universally exempt. Before adding analytics, advertising, error monitoring or embeds, we inventory transmitted data, recipients and purposes and, where applicable, provide easily accessible Japanese disclosures and required consent or other measures.
External transmission rules: https://www.ppc.go.jp/files/pdf/260614_telecom_GLs_description.pdf
10. Contact and complaints
- Privacy and complaints
- app@grtllc.jp
- Business hours
- 平日 10:00–18:00(日本時間)/ Weekdays 10:00–18:00 JST
- Postal address
- Room 206, 3275-22 Fusa, Abiko-shi, Chiba 270-1101, Japan
- Accredited personal information protection organization
- None
Complaints contact: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
11. Changes to this policy
We update and publish this policy as laws or the service change, notify individuals of material changes and obtain any legally required consent.
Policy changes: https://www.ppc.go.jp/personalinfo/legal/guidelines_tsusoku/
Rights requests concerning purchaser information entrusted by a store should be directed to that store, which determines its purposes. We refer requests to the store and assist on lawful instructions. Privacy contact telephone: +81-50-5526-2688.