Brecx and the Amazon Selling Partner API
Last updated: September 2026
Brecx connects to a seller's own Amazon Seller Central account through the Amazon Selling Partner API (SP-API). This page explains exactly how sellers authorize Brecx, which SP-API roles we use and why, and how Amazon data is protected, retained and deleted.
Overview
Brecx is a multichannel operations platform for third-party sellers who sell on Amazon (US and Canada) alongside other channels such as Walmart, eBay and Shopify. Once a seller connects their Amazon account, Brecx calls SP-API on that seller's behalf to:
- Keep FBA and merchant-fulfilled stock in sync with other channels to prevent overselling.
- Bring Amazon orders into one order queue and send shipment tracking back to Amazon.
- Update prices using repricing rules the seller controls (floor, ceiling, margin).
- Plan FBA inbound shipments, and fulfil orders from other channels with Multi-Channel Fulfillment.
- Include stock held in Amazon Warehousing and Distribution (AWD) in inventory and replenishment planning.
- Calculate profit per SKU from Amazon fees, refunds and settlements.
- For brand owners, use Brand Analytics reports to improve demand forecasts for their own brands.
Brecx is used only by sellers to run their own business. It is not a data broker: each seller's Amazon data is used solely to operate that seller's account, and is never pooled, shared or resold across sellers.
How sellers connect Amazon
- The seller signs in to Brecx and chooses Connect Amazon.
- Brecx redirects the seller to Amazon Seller Central, where Amazon shows the Brecx app name and the data access being requested. Only a user with permission to authorize apps on that account can approve it.
- When the seller approves, Amazon returns an authorization code, which Brecx exchanges with Login with Amazon for a refresh token. The token is encrypted and kept in our secrets store; it is never stored in source code.
- The seller can revoke access at any time - by disconnecting Amazon in Brecx, or in Seller Central under Apps and Services → Manage Your Apps. Brecx then stops calling SP-API for that account and deletes the associated Amazon data within 30 days.
Brecx never asks for a Seller Central password or two-step verification code, and never scrapes Seller Central or amazon.com. All access goes through Amazon's official authorization flow.
SP-API roles and how each one is used
We request the minimum set of roles our features need. Each role below is tied to a specific Brecx feature.
| SP-API role | Brecx feature | How the data is used |
|---|---|---|
| Product ListingNo buyer PII | Listings & catalog | Create and update the seller's own offers, match products to the Amazon catalog, and read product-type requirements so listings are submitted correctly.Listings Items · Catalog Items · Product Type Definitions · Feeds |
| PricingNo buyer PII | Repricing | Read pricing and fee estimates for the seller's own offers and update prices within the floor and ceiling rules the seller sets.Product Pricing · Product Fees · Listings Items (price) |
| Inventory and Order TrackingNo buyer PII | Unified inventory, order management, forecasting | Read FBA and merchant inventory levels, order status (without buyer PII) and order reports, to keep one stock count across channels and forecast demand.Orders · FBA Inventory · Reports |
| Amazon FulfillmentNo buyer PII | Shipment prep (FBA) and Multi-Channel Fulfillment | Plan and create FBA inbound shipments with box contents and labels, and fulfil orders from the seller's other sales channels using their FBA stock.Fulfillment Inbound · FBA Inbound Eligibility · Fulfillment Outbound |
| Amazon Warehousing and DistributionNo buyer PII | Unified inventory and replenishment | Read inventory held in AWD and the status of AWD inbound shipments, so upstream stock is included in the seller's stock count and in FBA replenishment plans.Amazon Warehousing and Distribution (AWD) |
| Finance and AccountingNo buyer PII | Profit analytics | Read fees, refunds, reimbursements and settlement data to calculate true profit per SKU and per channel.Finances · Settlement reports |
| Brand AnalyticsNo buyer PII | Forecasting and analytics (brand owners) | For sellers enrolled in Amazon Brand Registry, read aggregated search-term, sales-and-traffic and repeat-purchase reports for their own brands to improve demand forecasts and product performance reporting. Contains no buyer PII.Reports (Brand Analytics) |
| Selling Partner InsightsNo buyer PII | Account connection & health | Read the marketplaces the seller participates in and account-health information, so the correct storefronts are connected and issues are surfaced.Sellers · Account health reports |
| Direct-to-Consumer ShippingRestricted · PII | Merchant-fulfilled shipping | Read the ship-to name and address of a merchant-fulfilled order only when the seller buys a shipping label, then confirm shipment with tracking.Merchant Fulfillment · Orders (Restricted Data Token) |
The Brecx Advertising module uses Amazon's separate Amazon Ads API, which has its own authorization and is not part of the SP-API access described here.
Buyer personally identifiable information (PII)
Brecx accesses buyer PII only through the restricted Direct-to-Consumer Shipping role, and only for merchant-fulfilled orders the seller ships themselves. Amazon ships FBA orders, so Brecx does not need buyer PII for them.
- PII is requested with a Restricted Data Token only when it is needed - to buy a shipping label or confirm shipment for that order.
- It is used only to ship that order. It is never used for marketing, never sold or shared, and never combined across sellers.
- It is encrypted in transit (TLS 1.2+) and at rest (AES-256), and access is limited to named personnel with a documented business need.
- It is deleted no later than 30 days after order delivery, unless a longer period is required by law.
What Brecx never does with Amazon data
- Sell, rent, share or transfer Amazon data or buyer PII to any third party.
- Contact or market to Amazon buyers, or use buyer data outside order fulfilment.
- Use one seller's data to benefit another seller, or for cross-account competitive analysis.
- Show Brand Analytics data to anyone other than the brand owner's own account, or use it for brands the seller doesn't own.
- Use Amazon data to train external or third-party AI models.
- Scrape Amazon websites, or access accounts and marketplaces the seller hasn't authorized.
- Request roles or data that no Brecx feature needs.
We handle Amazon data in line with the Amazon Services API Developer Agreement, the Acceptable Use Policy and the Data Protection Policy.
Retention and deletion
| Data | Retention |
|---|---|
| Buyer PII (ship-to name and address) | Deleted no later than 30 days after order delivery |
| Other Amazon data (orders without PII, FBA and AWD inventory, listings, finances, Brand Analytics and other reports) | Deleted within 18 months, unless a longer period is legally required |
| Amazon disconnected or Brecx account closed | All associated Amazon data purged within 30 days, and the seller can export it first |
| Backups | Encrypted, and expire on a defined schedule, so deleted data leaves backups on the next cycle |
Security
- TLS 1.2+ for all data in transit, and AES-256 encryption at rest.
- Refresh tokens and credentials are kept in an encrypted secrets store, never in code.
- Multi-factor authentication on every system that can access Amazon data.
- Role-based, least-privilege access with quarterly access reviews.
- Access logs are kept for at least 12 months, with alerting on unusual activity.
- A documented incident response plan: we notify Amazon at security@amazon.com within 24 hours of detecting a security incident that involves Amazon data.
Read the full security overview and our Privacy Policy.
Contact
For questions about this integration, data requests or security, email contact@brecx.com or visit our contact page.
Amazon and Seller Central are trademarks of Amazon.com, Inc. or its affiliates. Brecx is an independent product and is not affiliated with or endorsed by Amazon.