Skip to content
SunCroix
Operational Reality Core Engines Pricing Tiers Technical Docs Security & DPP
🇻🇳 VI 🇨🇳 中文 🇺🇸 EN
Connect SP-API ↗

✳ DEVELOPER DOCUMENTATION & FAQ

Amazon SP-API Integration & Technical FAQ

App: SunCroix Operations & Financial Console Protocol: SP-API OAuth 2.0 (LWA) Updated: September 2026

Overview: This documentation provides enterprise brand leaders, chief financial officers, cross-border e-commerce operators, and Amazon SP-API compliance auditors with complete transparency regarding SunCroix’s technical integration, authorization workflow, data governance, and policy compliance.

1. Authorization & Onboarding Workflow

How does a seller authorize SunCroix via the Amazon Appstore?

SunCroix strictly utilizes the official Amazon Login with Amazon (LWA) OAuth 2.0 protocol. The authorization workflow follows three simple steps:

  1. Initiation: The seller clicks "Authorize Now" on the Amazon Selling Partner Appstore or inside the SunCroix console.
  2. Consent Screen: The seller is redirected to the official Amazon Seller Central consent page (hosted entirely on Amazon.com), which explicitly lists the requested roles (Finance and Accounting, Inventory and Order Tracking, Pricing).
  3. Token Handshake: Upon seller consent, Amazon redirects back to SunCroix’s secure callback endpoint with a temporary spapi_oauth_code. Our backend securely exchanges this code over TLS 1.3 for an encrypted LWA refresh token stored in HashiCorp Vault.
Does SunCroix ever ask for or store my Seller Central username or password?

Never. SunCroix strictly adheres to Amazon's Acceptable Use Policy (AUP). We never ask for, inspect, or store your Amazon Seller Central credentials. All communication is authenticated using temporary cryptographic access tokens derived from your official OAuth grant.

How can I revoke SunCroix’s access to my store?

Merchants retain 100% control at all times. You can revoke access instantly at any time directly through Amazon Seller Central: Navigate to Partner Network > Manage Your Apps, locate SunCroix Operations & Financial Console, and click Revoke. When access is revoked, Amazon notifies our webhook and our system immediately ceases all data retrieval.

2. Supported Amazon Regions & Marketplaces

SunCroix is a global multi-tenant platform architected to support all major Amazon Selling Partner API production regions:

Region Supported Marketplaces SP-API Endpoint Host
North America (NA) United States (US), Canada (CA), Mexico (MX) sellingpartnerapi-na.amazon.com
Europe (EU) United Kingdom (UK), Germany (DE), France (FR), Italy (IT), Spain (ES), Netherlands (NL), Poland (PL), Sweden (SE) sellingpartnerapi-eu.amazon.com
Far East (FE) Japan (JP), Singapore (SG), Australia (AU) sellingpartnerapi-fe.amazon.com

3. Data Protection, Privacy & Non-PII Philosophy

What data does SunCroix collect, and what is the Non-PII policy?

SunCroix is engineered on a strict Non-PII (Personally Identifiable Information) architectural standard. We do not request, ingest, process, or persist any Amazon buyer personal data (no customer names, phone numbers, or delivery addresses).

We only ingest operational and business data: aggregated order totals, SKU numbers, currency fee lines, settlement flat files, and warehouse inventory movement logs. This eliminates data privacy risks for buyers while delivering complete accounting transparency for operators.

What is your data retention schedule and 30-Day Purge SLA?

In strict compliance with Amazon Data Protection Policy (DPP) Section 3.2, SunCroix does not retain Amazon information longer than necessary to provide contracted services. When a seller disconnects their account or revokes OAuth authorization, our automated data lifecycle scheduler permanently deletes all cached historical records, tokens, and database rows within 30 calendar days.

How does the platform enforce data isolation between independent brands and enterprise seller accounts?

Each independent merchant or brand operates within an isolated tenant environment. We enforce PostgreSQL Row-Level Security (RLS) where every database row is partitioned by an immutable, cryptographically generated tenant_id. Cross-tenant querying is blocked at the database engine level, mathematically preventing data leakage between independent brands.

4. FBA Inventory Auditing & Marketplace Reimbursement Packages

How does SunCroix identify lost and damaged warehouse units?

SunCroix uses the official Amazon FBA Inventory API and historical movement ledger reports (GET_LEDGER_DETAIL_VIEW_DATA, GET_FBA_FULFILLMENT_CUSTOMER_RETURNS_DATA). Our algorithms trace inventory across up to 18 months of warehouse receipts, comparing inbound deliveries, customer returns, and disposal records to detect discrepancies that Amazon has not yet automatically reimbursed.

Does SunCroix automatically spam claims into Seller Central?

No. SunCroix strictly adheres to Amazon Customer Service and AUP policies. We do not engage in automated bot claim submissions. Instead, SunCroix compiles verified, policy-compliant claim packages with all requisite shipment IDs, transaction logs, and ASIN documentation. Sellers or account managers review and submit cases manually or via authorized review workflows.

5. Corporate Governance & Support

Operating Entity: SunCroix Technology Group Co., Ltd.
Operational Office: Floor 12, Keangnam Hanoi Landmark Tower, Pham Hung Road, Hanoi, Vietnam.
Customer Support: support@suncroix.com (Response within 24–48 hours)
Information Security & Incident SLA: security@suncroix.com (Acknowledged within 4 hours, 24-hour notification to Amazon SIRT at 3p-security@amazon.com)
Data Protection Officer (DPO): dpo@suncroix.com

SunCroix

Independent multi-tenant platform for cross-border e-commerce operations & FBA audit.

↑

© 2026 SunCroix Technology Group Co., Ltd. All rights reserved.

Privacy Policy Terms of Service Security & DPP FAQ & Docs Pricing Support

Amazon Marketplace Disclaimer: Amazon, Amazon Services, and Selling Partner API are trademarks of Amazon.com, Inc. or its affiliates. SunCroix is an independent multi-tenant software application integrated via the Amazon Selling Partner API (SP-API) and is not affiliated with or endorsed by Amazon.com, Inc.