Frequently asked questions
Refund policy: refunds are handled according to the terms of our T&Cs, a full refund if a technical issue occurred on our side, and a partial (50%) refund if Amazon questions your business legitimacy. We never promise approval, because Amazon keeps the final decision.
What are Amazon SP-API restricted roles?
Restricted roles are elevated Selling Partner API permissions that grant access to buyer Personally Identifiable Information (PII), names, shipping addresses, contact details and order data. They include Direct-to-Consumer Shipping, Tax Invoicing and Tax Remittance. Because they expose sensitive data, Amazon only grants them after a Restricted Data Access (RDA) review, and for software offered to many sellers, a third-party Data Security Assessment (DSA).
Why was my Amazon restricted-role application rejected?
By far the most common reason is that your security and compliance documentation did not meet requirements. Amazon does not reject because your product is weak; it rejects when the application does not demonstrate compliance, or when the application answers, the privacy policy and the security procedures contradict each other. Reviewers look for contradictions, vague wording, generic copy-paste answers, weak justifications and incomplete policies.
Does Amazon approve an application because it is well written?
No. Amazon approves because the application demonstrates compliance: a valid business justification for each role, a credible security architecture, and documentary consistency across the whole file. Good writing alone is not enough, every document has to tell the same story and align with Amazon's policies.
Which restricted roles do you cover?
We prepare applications for the PII-bearing restricted roles, most often Direct-to-Consumer Shipping, Tax Invoicing and Tax Remittance, plus Professional Services for in-person add-on services such as assembly and installation. We also handle related roles such as Buyer Communication and Buyer Solicitation. Each role is justified on its own terms, because the reviewer weighs the roles you request against your use case and Amazon's policies together.
What is the difference between a private and a public application?
A private application is for software used only inside your own company (a single seller). The review is documentary, your application answers and your public Data Handling & Privacy Policy, and is genuinely simpler. A public application is for software you offer to many sellers (SaaS, ERP, WMS, integrators); it is far harder and adds a business-criteria review, additional security questions, and a live security-architecture review with an Amazon solution architect, a Data Security Assessment (DSA) across twelve assessment domains.
Do you need access to our code, servers or Amazon account?
No. We are a marketplace-compliance firm, not a development agency. We prepare the documentation and the application Amazon requires; your own IT lead implements the checklist on your infrastructure. Knowing exactly what Amazon expects and how to present it is our field; implementing it on your systems is where your IT lead is strongest.
Will getting approved require changing our source code?
Rarely. The large majority of what Amazon evaluates is documentation, security procedures and infrastructure configuration. The few items that can need a small development task are an automated routine that deletes customer data within 30 days of shipment, making sure logs do not store customer PII, and connecting through Amazon's official OAuth instead of storing credentials. None of these is a rewrite; a developer usually handles them in a few days.
How long can we keep customer PII under Amazon's policy?
The standard, safe position is to keep PII no longer than 30 days after order delivery, and only to fulfil orders or as required by law. Data must then be securely deleted (for example per NIST 800-88), PII must be removed within 30 days of an Amazon deletion request, and all live copies removed within 90 days of an Amazon notice.
What encryption and security does Amazon expect?
TLS 1.2 or higher for data in transit (TLS 1.3 recommended) and AES-128 or higher at rest (AES-256 recommended), with RSA-2048 or higher, managed with a key management system (KMS) and at least annual key rotation. Credentials are never hardcoded or stored, access is least-privilege with multi-factor authentication and quarterly reviews, logs are PII-free and retained 12+ months with alerting, and an incident-response runbook notifies Amazon within 24 hours of a breach.
What exactly do you deliver?
Three things, ready to use: every application answer written and ready to submit (the questionnaire plus the free-form security and architecture responses); a publishable Data Handling & Privacy Policy page for your website; and a plain-language implementation checklist of every control Amazon requires. You also get a role-by-role justification, an incident-response plan, and handling of Amazon's follow-up questions.
How long does it take and how does pricing work?
The standard restricted-role file is a one-time fee of 650 EUR, delivered within 48 hours of payment. After that, submission timing depends on how fast your team implements the checklist, and Amazon controls its own review time. Public apps offered to many sellers are a larger engagement and are quoted after a short call. Support covers up to 3 submission attempts.
What if Amazon rejects it, or asks more questions? Can you guarantee approval?
We never promise approval, because Amazon keeps the final decision. What we do is rebuild the exact point Amazon scores, your security and compliance documentation, so the previous reason for refusal is removed. Follow-up questions are included, we revise on Amazon's feedback across up to 3 attempts, and refunds follow our T&Cs: a full refund for a technical issue on our side, a partial refund if Amazon questions your business legitimacy.
Do we need an EU company to apply?
Not strictly, but a properly established company with a clean public presence and a real data-handling policy makes approval easier, and a compliant EU structure helps with VAT and data-protection expectations. We help you
set up a compliant Bulgarian company, 100% remotely, and can align your structure, your VAT and your Amazon application so they all support each other.
What are the 12 domains of Amazon's Data Security Assessment?
For public apps, Amazon's Data Security Assessment (DSA) evaluates twelve domains: (1) business and system overview, (2) security governance, (3) infrastructure security, (4) data protection, (5) network security and vulnerability management, (6) application security, (7) identity and access management, (8) security monitoring and incident response, (9) privacy, (10) data handling and management, (11) third-party integration, and (12) customer support. The assessment is run by an Amazon-authorised agent at no cost; we prepare your evidence for every domain.
How long does Amazon take to review a restricted-role application?
Amazon controls its own timing, so there is no guaranteed deadline. For a public app, the Data Security Assessment typically takes about a month of elapsed time and roughly 8 hours of your team's effort (around 4 to 6 hours of written responses, a 2-hour call, and about 2 hours of follow-up). A private (documentary) application is usually quicker. We deliver your complete file within 48 hours, so the only variable left is Amazon's review and how fast your team implements the checklist.