Privacy Policy
Effective Date: November 3, 2025 | Last Updated: 4/23/2026
1. Introduction
Welcome to Rigor Universe, operated by Fatih Alkan (sole proprietorship, Tax ID: 0530596162), trading as Rigor Universe ("we," "us," "our," or "the Developer"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-marketplace e-commerce integration platform.
Rigor Universe provides software-as-a-service (SaaS) that integrates with multiple e-commerce marketplaces including Amazon (via SP-API), TikTok Shop (via Open API), eBay, Allegro, Ozon, AliExpress, and Walmart. By using our services, you consent to the data practices described in this policy.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Information We Collect
We collect several types of information to provide and improve our services:
2.1 Account Information
- Full name and business contact details
- Email address and phone number
- Company name and business registration information
- Billing address and payment information
- Password (encrypted and hashed)
2.2 Marketplace API Credentials
To enable marketplace integrations, we securely store your API credentials for:
- Amazon Selling Partner API (SP-API) - OAuth 2.0 tokens, seller IDs, marketplace IDs
- eBay Trading API - OAuth tokens, eBay user IDs
- Allegro REST API - Client credentials and access tokens
- Ozon Seller API - API keys and client IDs
- AliExpress Open Platform - App keys and session tokens
- TikTok Shop Open API - App keys, access tokens, and shop IDs
- Walmart Marketplace API - Consumer IDs and private keys
All API credentials are encrypted at rest using AES-256 encryption and transmitted over TLS 1.3.
2.3 Transaction and Business Data
- Order data synchronized from connected marketplaces (order IDs, customer names, shipping addresses)
- Product listings, SKUs, descriptions, images, and pricing
- Inventory levels and warehouse locations
- Sales reports and financial data
- Shipping and tracking information
2.4 Usage Data and Analytics
- Login timestamps and IP addresses
- Browser type, operating system, and device information
- Feature usage patterns and navigation data
- API call logs and performance metrics
- Error logs and diagnostic data
2.5 Communications
- Customer support conversations (email, chat, phone)
- Feedback and survey responses
- Marketing communications preferences
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Provision
- Connect to and sync data from marketplace APIs (Amazon SP-API, eBay, etc.)
- Process and manage orders across multiple marketplaces
- Synchronize inventory levels in real-time
- Update product listings and pricing automatically
- Generate analytics dashboards and reports
- Automate repricing based on your pricing rules and market conditions
3.2 Account Management
- Create and maintain your account
- Process payments and manage subscriptions
- Send transactional emails (order confirmations, receipts, password resets)
- Provide customer support and respond to inquiries
3.3 Service Improvement
- Analyze usage patterns to improve features and performance
- Conduct A/B testing and user research
- Debug errors and fix technical issues
- Develop new integrations and capabilities
3.4 Legal and Security
- Prevent fraud and unauthorized access
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service
- Protect our rights, property, and safety
3.5 Marketing (With Consent)
- Send promotional emails about new features and offers (opt-in)
- Provide personalized product recommendations
- Share industry insights and best practices
You can opt-out of marketing communications at any time.
4. Data Security
We implement industry-standard security measures to protect your personal information:
4.1 Encryption
- Data in Transit: All data transmitted to/from our servers uses TLS 1.3 encryption
- Data at Rest: Database and file storage encrypted with AES-256
- API Credentials: Marketplace credentials encrypted with separate encryption keys
- Passwords: Hashed using bcrypt with salt (never stored in plain text)
4.2 Access Controls & Password Policy
- Multi-factor authentication (MFA) required for all account access
- Role-based access control (RBAC) for team members
- Regular access audits and permission reviews (quarterly)
- Least privilege principle for employee access
- Account lockout after 10 failed login attempts
Password Requirements
- Minimum length: 12 characters
- Complexity: Must include uppercase letters, lowercase letters, numbers, and special characters
- Username check: Cannot contain any part of username
- Minimum age: 1 day (prevents rapid password cycling)
- Maximum age: 365 days (forced expiration)
- History: Cannot reuse last 10 passwords
4.3 Infrastructure Security
- Firewalls and intrusion detection systems (IDS/IPS)
- Regular security patches and updates
- Automated vulnerability scanning (every 180 days minimum)
- Annual penetration testing by third-party security firms
- 24/7 monitoring and incident response
- Anti-malware software on all systems (cannot be disabled)
Vulnerability Remediation Timeline
- Critical vulnerabilities: Remediated within 7 days
- High-risk vulnerabilities: Remediated within 30 days
- Medium/Low vulnerabilities: Remediated within 90 days
- All findings tracked in vulnerability management system with documented remediation status
4.4 Logging and Monitoring
- PII-Free Logs: Our application does NOT log any Amazon customer personally identifiable information (PII) including names, addresses, email addresses, phone numbers, payment details, IP addresses, or device identifiers
- Log Retention: Security logs retained for minimum 90 days; access logs for 12 months
- Real-time Monitoring: SIEM system with automated alerts for suspicious activities
- Audit Trails: All data operations (read, write, modify, delete) are logged with timestamps
- Log Review: Security team reviews logs twice weekly and responds to alerts in real-time
- Debug Logging: Disabled in production environments
Monitoring Alerts: Our system automatically detects and alerts on unauthorized API calls, abnormal request rates, unusual data retrieval patterns, and potential security incidents. Security incidents are reported to Amazon at security@amazon.com within 24 hours.
4.5 Employee Training
- All employees sign confidentiality agreements (NDAs)
- Regular security awareness training
- Background checks for sensitive roles
Note: While we implement robust security measures, no system is 100% secure. You are responsible for keeping your account credentials confidential and reporting any unauthorized access immediately.
5. Third-Party Services and APIs
To provide our integration services, we connect to and share data with third-party marketplace APIs:
5.1 Marketplace APIs
- Amazon Selling Partner API (SP-API)
We use Amazon SP-API to sync your orders, inventory, and product listings. Data is shared in accordance with Amazon's API Terms of Use. - eBay Trading API
Integration for eBay order management and listing synchronization. - Allegro REST API
Connection to Allegro marketplace for Polish and Eastern European markets. - Ozon Seller API
Integration with Ozon Russian marketplace for product and order management. - AliExpress Open Platform
Dropshipping and product sourcing integration. - TikTok Shop Open API
Order management, fulfillment, and product synchronization for TikTok Shop sellers. Data is shared in accordance with TikTok Shop's Developer Terms of Service. - Walmart Marketplace API
Order and inventory management for Walmart sellers.
5.2 Other Service Providers
- Payment Processors: Stripe, PayPal (for subscription billing)
- Cloud Hosting: AWS, Google Cloud (for infrastructure)
- Analytics: Google Analytics (anonymized data)
- Email Services: SendGrid, AWS SES (for transactional emails)
- Customer Support: Intercom, Zendesk
All third-party service providers are required to maintain appropriate data protection measures and comply with GDPR requirements.
6. Data Sharing and Disclosure
We do NOT sell your personal information. We only share data in the following limited circumstances:
- With Your Consent: When you authorize marketplace integrations
- Marketplace APIs: To sync your orders, products, and inventory
- Service Providers: With vendors who perform services on our behalf (under NDA)
- Legal Requirements: When required by law, court order, or regulatory authority
- Business Transfers: In case of merger, acquisition, or sale of assets (with notice)
- Protection: To prevent fraud, protect rights, or ensure safety
7. Your Rights (GDPR Compliance)
Under GDPR and other data protection laws, you have the following rights:
Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data (subject to legal retention requirements).
Right to Data Portability
Export your data in a machine-readable format (CSV, JSON).
Right to Restrict Processing
Limit how we use your data in certain circumstances.
Right to Object
Object to processing for direct marketing purposes.
Right to Withdraw Consent
Withdraw consent for data processing at any time.
To exercise any of these rights, email us at privacy@rigoruniverse.com. We will respond within 30 days.
8. Data Retention
We retain your data only for as long as necessary to provide our services and comply with legal obligations:
- Active Accounts: Retained for as long as your account is active
- Deleted Accounts: 30-day grace period, then permanently deleted
- Backups: Retained for 90 days for disaster recovery
- Financial Records: 7 years (tax and accounting requirements)
- Logs: 12 months for security and compliance audits
📦 Amazon Selling Partner API (SP-API) - Special Data Retention Policy
In strict accordance with Amazon's Data Protection Policy (DPP), we implement the following retention rules for customer data obtained through Amazon Selling Partner API integrations:
🔒 Customer PII (Personally Identifiable Information)
Amazon customer PII obtained from orders (such as buyer names, shipping addresses, phone numbers, and email addresses) is retained for a maximum of 30 days after order delivery.
After this 30-day period, all customer PII is automatically and permanently deleted from our systems, except where:
- Longer retention is required by law (e.g., tax regulations requiring 7 years for financial records)
- Necessary for fraud prevention or legal disputes (minimal data retained with documented justification)
- Explicitly required by regulatory authorities
📊 Non-PII Order Data
Anonymized order data (order IDs, SKUs, quantities, prices) that does NOT contain customer PII may be retained longer for:
- Business analytics and reporting
- Inventory forecasting
- Tax and accounting compliance (up to 7 years)
🛡️ Automated Deletion Process
We have implemented automated systems that:
- Track the delivery date of each Amazon order
- Automatically flag customer PII for deletion 30 days after delivery
- Permanently erase flagged PII from all databases and backups
- Generate audit logs for compliance verification
Note: This 30-day retention policy applies specifically to Amazon SP-API data. Data from other marketplaces (TikTok Shop, eBay, Allegro, Ozon, AliExpress, Walmart) follows their respective retention policies and applicable regulations, which may differ.
🛍️ TikTok Shop Open API - Data Handling Policy
In compliance with TikTok Shop's Developer Terms of Service and applicable data protection regulations, we implement the following data handling practices for data obtained through TikTok Shop Open API integrations:
📋 Data We Access via TikTok Shop API
- Order information (order IDs, order status, shipping details)
- Product and listing data (SKUs, descriptions, pricing, inventory)
- Fulfillment and shipping information (tracking numbers, carrier details)
- Shop and seller profile information
🔒 Data Protection Measures
- All TikTok Shop data is encrypted at rest (AES-256) and in transit (TLS 1.3)
- Access restricted to authorized personnel on a need-to-know basis
- Customer PII is not shared with third parties beyond what is necessary for order fulfillment
- We assist sellers and TikTok Shop in responding to user data access, correction, and deletion requests
- Upon termination of the integration, all TikTok Shop customer data is permanently deleted
Note: Our use of TikTok Shop API data is strictly limited to providing order management and fulfillment services as described in this policy. We do not use TikTok Shop data for advertising, profiling, or any purpose unrelated to the services we provide to sellers.
You may request early deletion of your data at any time by contacting us at privacy@rigoruniverse.com. We will process your request within 30 days, subject to legal retention requirements.
10. International Data Transfers
Your data may be processed in the European Union, United States, or Turkey. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with all service providers
- Adherence to EU-U.S. Data Privacy Framework principles
11. Children's Privacy
Our services are intended for businesses and users aged 18 and older. We do not knowingly collect data from children under 18.
12. Changes to This Privacy Policy
We may update this policy periodically. Material changes will be communicated via:
- Email notification to registered users
- In-app notification banner
- Updated "Last Modified" date at the top of this page
Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Developer: Fatih Alkan, trading as Rigor Universe
Email: privacy@rigoruniverse.com
Data Protection Officer: dpo@rigoruniverse.com
Address: Fenerbahce Mah. Igrip Sk. No: 13, Kadikoy, Istanbul 34726, Turkey
Response Time: Within 30 days
You also have the right to lodge a complaint with your local data protection authority.