This statement summarizes the technical and organizational measures we use to protect order data and personal information, including data obtained through the Amazon Selling Partner API for our own selling account.
Our systems run on Cloudflare (serverless application on Cloudflare Pages with a Cloudflare D1 database). Traffic passes through Cloudflare's edge, which provides WAF and DDoS protection.
Access requires authenticated login with role-based permissions (least privilege). Account-level multi-factor authentication is enforced on the administrative accounts used to operate the system. Access is reviewed on personnel changes and revoked promptly on termination.
We maintain audit logs of order changes and of authentication and personal-data access events (with user, IP and timestamp) for forensic review, alongside platform request logs. Login is rate-limited to mitigate brute-force attempts.
Buyer personal information is retained only as long as needed for fulfillment and legal obligations. A scheduled job is configured to redact buyer personal data from active order records approximately 30 days after shipment.
Source code is kept in private repositories with automated dependency updates, static analysis (CodeQL) and secret scanning enabled to detect and prevent accidental exposure of credentials.
We maintain an incident response plan covering identification, containment, notification, investigation and remediation. Security incidents involving data obtained via the Amazon Selling Partner API are reported to security@amazon.com within 24 hours of detection. The plan is reviewed at least every six months.
Security or privacy questions: ha@donomi.jp.