Amazon integration

How DEDALO connects
to the Amazon SP-API

This page describes exactly which data from your Amazon account the platform reads, under which roles, for which purpose and with what guarantees. It is the reference document for sellers, accountants and for Amazon's review team.

Manual upload today, direct connection shortly

Current situation. DEDALO processes the reports that the seller downloads from Seller Central and uploads to the platform. This channel will always remain available.

Being activated. A direct connection to the Selling Partner API, which will remove the manual download: reports will be retrieved automatically from your account, only after your explicit authorisation through Amazon's official OAuth flow, and revocable at any time from your Seller Central account. The SP-API integration will be an option, not a requirement.

What we read, and why

We request only the roles strictly necessary to deliver the service, in accordance with the data minimisation principle of Amazon's Acceptable Use Policy.

Data SP-API report Role Purpose in DEDALO
VAT transactions GET_VAT_TRANSACTION_DATA Tax Invoicing Computing daily sales records and the OSS return
VAT calculations SC_VAT_TAX_REPORT Tax Invoicing Verifying the rates applied by Amazon and invoice numbers
Inventory movements GET_LEDGER_DETAIL_VIEW_DATA Amazon Fulfillment Detecting FC_TRANSFER movements between EU fulfilment centres
Storage fees GET_FBA_STORAGE_FEE_CHARGES_DATA Amazon Fulfillment Allocating warehouse costs to the correct period
Payments and fees Settlement report Finance and Accounting Reconciling Amazon payouts and commissions
Orders All Orders report Inventory and Order Tracking Matching transactions to their corresponding orders
We do not request the Brand Analytics role. DEDALO does not process consumer behaviour data, search terms, market basket, repeat purchase or brand performance data. Such information is unrelated to VAT compliance and has no use anywhere in the platform.

The flow, step by step

You authorise access

From Settings you connect your account through Amazon's official consent flow. DEDALO never asks for your Seller Central credentials.

We receive a token

Amazon issues us a refresh token, stored encrypted and separately from operational data. No credential of your account is ever transmitted or stored.

We retrieve the reports

On a scheduled basis we request only the reports listed above, for only the periods needed. Restricted reports use the Restricted Data Tokens provided by Amazon.

We process and produce

The data feeds the three tax modules and generates daily sales records, the OSS return and intra-community transfer documents.

Guarantees and limits of use

โœ… What we do
๐Ÿ‡ช๐Ÿ‡บ

EU datacentres only

Processing and backups exclusively in European datacentres. No transfer outside the European Economic Area.

๐Ÿ”

Encryption and isolation

Encryption in transit (TLS) and at rest. Each customer in a dedicated container with its own databases, no sharing between accounts.

๐Ÿงน

Revocation and deletion

Revoking the authorisation from your Seller Central account terminates access immediately, and data no longer needed is deleted.

๐Ÿงพ

Minimisation

We do not retain end-buyer identifying data: name, address, email, phone and payment details are excluded from processing.

๐Ÿšซ What we never do
๐Ÿšซ

No selling of data

Amazon data is never sold, rented or transferred to third parties for any purpose.

๐Ÿšซ

No marketing or profiling

No use for marketing, profiling or model training.

๐Ÿšซ

No aggregation across sellers

One seller's data is never aggregated with another's, nor used for another seller's benefit.

๐Ÿšซ

No use beyond the mandate

Data is processed only on the Customer's instructions and for the VAT purposes described.

Compliance with Amazon policies

Processing of data obtained through the Selling Partner API is carried out in compliance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy, as well as the GDPR.

Amazon Acceptable Use Policy Amazon Data Protection Policy Restricted Data Token OAuth โ€” explicit authorisation GDPR โ€“ Reg. EU 2016/679 EU datacentre hosting
Learn more

Related documents

Full details on retention, deletion, sub-processors and data subject rights are in our privacy policy, section 3.1.

Privacy policy โ†’