Information Security and Data Privacy Policy
1. Purpose and scope
This policy defines how Seller Station protects the information it processes on behalf of marketplace sellers who use the Seller Station dashboard (https://sellerstation.com.br). It applies to all systems, personnel and contractors involved in building and operating the service, and to all data obtained through marketplace APIs (Amazon, Mercado Livre, Shopee, TikTok Shop and others), whether in production, backups or development environments.
2. Data we process and data we do not collect
- Seller account data: seller identifiers, shop names, OAuth tokens issued by the marketplace.
- Commercial data: orders, order items, fees and commissions, shipping costs, inventory levels, product listings, advertising spend.
- User data: name, e-mail address and a salted password hash for each dashboard user.
- Not collected: buyer personal data (names, addresses, phone numbers, tax IDs) is not requested from marketplace APIs and is not stored. The service does not request "sensitive data" scopes.
3. Data isolation (multi-tenancy)
Every dashboard user belongs to exactly one organization. Marketplace accounts, tokens, orders and inventory are stored with the organization identifier and every query is scoped to the organization of the authenticated session. No organization can read, list or infer data from another organization. Platform administrators may access a customer organization only through an audited "act as" session, shown to the administrator with a persistent banner, and only for support purposes.
4. Encryption
- In transit: all traffic uses HTTPS with TLS 1.2 or higher (Let's Encrypt certificates, HTTP redirected to HTTPS). Calls to marketplace APIs use HTTPS only.
- At rest: marketplace refresh tokens and access tokens are encrypted with AES-256-GCM using a server-side key that is never stored in the database or in source code. Backups are compressed and stored with restricted file permissions on the server. Passwords are hashed with scrypt and a per-user random salt; plaintext passwords are never stored or logged.
- Secrets management: API client secrets, partner keys and encryption keys live only in environment configuration on the production host, written through an operator-only script, never in chat, tickets, source control or documentation.
5. Access control
- Production server administration is limited to the technical lead, over SSH with key-based authentication only. Password and keyboard-interactive logins are disabled at the SSH daemon; root access is permitted only with a key.
- Dashboard access requires an individual account (e-mail + password, minimum 8 characters, scrypt-hashed). Sessions use HMAC-signed, HttpOnly, Secure, SameSite cookies with a 30-day expiry.
- Roles inside an organization (owner, operations, finance, traffic) limit what each user can change. Accounts can be deactivated immediately by the platform administrator or the organization owner.
- Marketplace authorization uses the marketplace's own OAuth consent flow (Amazon Login with Amazon, Mercado Livre OAuth with PKCE, TikTok Shop / Shopee authorization); the seller can revoke access from the marketplace at any time.
- Principle of least privilege: the application requests read-only API scopes wherever the marketplace allows it.
6. Network and infrastructure security
- The service runs on a virtual private server hosted by Hostinger in São Paulo, Brazil, behind a host firewall (ufw) that allows only the ports required by the services on the host. The Seller Station application is reachable exclusively on ports 80 and 443; its process and database are not exposed on any other port.
- The application process listens on localhost only and is exposed exclusively through an nginx reverse proxy that terminates TLS. The database is a local file readable only by the application user; it is never exposed on the network.
- The public landing page, the application and the administration panel are separate hosts; the administration panel is restricted to platform-administrator accounts.
- Operating system packages and Node.js dependencies are kept up to date; security updates are applied when released.
7. Logging, monitoring and auditing
Application logs record authentication events, API synchronization runs, marketplace webhook deliveries and errors, without tokens or passwords. Process supervision (pm2) restarts the service on failure and keeps logs for review. Administrator "act as" sessions are explicitly flagged in the session token.
8. Backups and business continuity
A consistent snapshot of the database is taken automatically every day, compressed, stored with owner-only permissions and retained for 30 days. Restoration is tested when the backup procedure changes. The service can be redeployed from source and configuration within hours on a new host.
9. Vulnerability and change management
- Code changes are built and type-checked before deployment; production deploys are performed by the technical lead through a scripted, repeatable process.
- Dependencies are reviewed for known vulnerabilities before release. Findings rated high or critical are fixed before the next deployment.
- Reports from marketplaces, customers or researchers are handled through suporte@sellerstation.com.br or the main contact e-mail.
10. Incident response
A security incident is any confirmed or suspected unauthorized access, disclosure, alteration or loss of customer data. On detection we (1) contain the incident (revoke tokens, rotate keys, isolate the host), (2) assess scope and affected organizations, (3) notify affected customers and the relevant marketplace partner program without undue delay and within 72 hours of confirmation, (4) remediate root cause and (5) document the incident and lessons learned.
11. Data retention and deletion
- Commercial data is retained while the organization is a customer, to provide historical analytics.
- When a seller disconnects a marketplace account, its tokens are deleted immediately. When an organization is removed, all of its users, tokens, orders, inventory and synchronization logs are deleted from the live database; backups expire within 30 days.
- Customers may request deletion at any time through the dashboard or by e-mail; requests are fulfilled within 30 days.
12. Third parties and data location
| Provider | Role | Location |
|---|---|---|
| Hostinger International Ltd. | Virtual private server, DNS | Data center in Brazil (São Paulo region) |
| Let's Encrypt | TLS certificates | United States |
| Marketplace APIs (Amazon, Mercado Livre, Shopee, TikTok Shop) | Data sources authorized by the seller | Provider regions |
Customer data is not sold, shared with advertisers or used for any purpose other than delivering the dashboard to the organization that owns it. Marketplace data is never used to redirect transactions outside the marketplace.
13. People
Everyone with production access is bound by confidentiality obligations, receives this policy on onboarding and reviews it annually. Access is removed on the same day a person leaves the project.
14. Compliance
Seller Station follows the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the partner program rules of each marketplace it integrates with, including their data protection policies. Contact: contato@sellerstation.com.br.