1. Who We Are & Scope of This Policy
Saratu (“Saratu,” “we,” “our,” or “us”) is an Amazon marketplace management agency operating in India. We provide Amazon seller account management, product listing optimization, A+ Content design, Sponsored Ads management, FBA compliance, and related ecommerce services.
This Privacy Policy applies to:
- All visitors to our website saratu.in
- All clients and prospective clients who engage with our services
- Any individual whose personal data we process in connection with the delivery of Amazon marketplace management services
- Third parties who communicate with us on behalf of clients
By accessing our website or engaging our services, you acknowledge and agree to the practices described in this Policy.
2. What Information We Collect
We collect only the information necessary to deliver our services effectively and securely. This includes:
| Category | Examples | How It’s Used |
|---|---|---|
| Identity Data | Full name, business name, designation | Contact form, onboarding |
| Contact Data | Email address, phone number, office address | Communication, support |
| Amazon Account Data | Seller Central access credentials (where granted), GST/PAN details, account performance data, listing content | Directly shared by client during onboarding |
| Business & Financial Data | GST number, PAN, bank details (for account setup/registration support) | Account setup, compliance filings |
| Product Data | Product descriptions, images, dimensions, inventory data | Listing optimization, A+ Content, imaging |
| Technical Data | IP address, browser type, device information, pages visited | Automated, via website analytics |
3. Handling of Amazon Seller Data
This section is critically important. The safeguarding of your Amazon seller data is our highest operational priority and a non-negotiable standard across every engagement.
When a client engages Saratu for Amazon account management services, we may be granted access to their Amazon Seller Central account. This access is handled as follows:
Access Scope. We request only the minimum level of Seller Central permissions necessary to perform the specific services contracted. We do not request admin-level access unless explicitly required and approved by the client in writing.
Credential Handling. Amazon Seller Central login credentials shared with Saratu are stored in encrypted, access-controlled password management systems. Credentials are never stored in plain text, spreadsheets, email, or unencrypted documents.
Dedicated Account Management. All Seller Central access activities are conducted through named, identifiable team accounts. Access logs are not permitted, and we are not permitted to use shared or anonymous logins.
No Third-Party Sharing. Amazon account credentials and data are never shared with subcontractors, advertising platforms, or other ecommerce service providers without explicit client consent.
Account Actions. All actions taken within a client’s Seller Central account are performed as instructed or within agreed operational scope. Saratu does not take actions beyond the agreed service scope without prior client approval.
Revocation Access. Upon termination of a service agreement, Saratu will immediately deactivate any saved access credentials, revoke account access, and confirm in writing that all access has been removed.
Amazon MWS / SP-API Compliance. Where Saratu uses Amazon’s APIs to manage account operations, all usage complies with Amazon’s Acceptable Use Policy and Data Protection Policy. Client data accessed via API is not used for any purpose beyond service delivery.
Saratu will never use a client’s Amazon account to conduct activities for other clients, personal gain, or any purpose outside the contracted scope. Any breach of this commitment may be reported to Amazon and relevant authorities.
4. How We Use Your Information
Personal and business data collected is used strictly for the following purposes:
- Service Delivery. To perform contracted Amazon marketplace management services including listing creation, account management, A+ Content, advertising, and FBA support.
- Communication. To respond to inquiries, provide service updates, share reports, and coordinate with clients on project progress.
- Account Setup. To complete Amazon seller account registration, brand registry, GTIN exemption, and related documentation processes on behalf of clients.
- Legal Compliance. To comply with applicable Indian law, GST obligations, and any regulatory requirements relevant to our business.
- Improvement of Services. Anonymized and aggregated data may be used to improve our internal workflows and service quality. We do not individually identify clients within any such use of this data.
- Security. To detect and prevent unauthorized access, fraud, or misuse of systems or any data we collect.
We do not use client data for marketing to third parties, profiling, automated decision-making, or any purpose not listed above.
5. Limited Employee Access
Access to client data within Saratu is governed by the principle of least-privilege access — team members are granted access strictly on a need-to-know basis specific to their role.
- Role-Based Access Control (RBAC). Each team member is assigned an access level based on the specific services they deliver for a client. Access to seller documents and Seller Central is granted only to the relevant individuals.
- Named Access Only. All access to client systems, credentials, and documents is tied to specific, named individuals. Generic or shared team logins are not permitted.
- Confidentiality Agreements. All Saratu employees and contractors sign written Non-Disclosure Agreements (NDA) and data confidentiality agreements before being granted access to any client data.
- Access Logging. Access to sensitive client data and systems is logged and auditable, ensuring internal accountability and visibility into who has accessed client data and when.
- Offboarding Procedure. When a team member leaves Saratu or changes roles, all their account access, including client systems and data permissions, is immediately revoked.
6. Data Encryption & Security Measures
Saratu implements industry-standard technical measures to protect client data.
- Encryption in Transit. All data transmitted between clients and Saratu systems — including via our website, email correspondence, and file transfers — is encrypted using TLS/SSL or higher industry-standard protocols, ensuring confidentiality of sensitive data in transit.
- Encryption at Rest. Sensitive data stored in our systems, including Amazon credentials, financial documents, and client business data, is encrypted at rest using AES-256 encryption or equivalent standards.
- Password Management. All team members who access client systems use unique, strong, system-generated passwords for storing client credentials. Weak, reused, or plain-text passwords are not permitted under any circumstances.
- Multi-Factor Authentication (MFA). MFA is mandatory for all Saratu team members who access internal client systems, business accounts, and administrative panels where sensitive client data is accessible.
- Secure File Transfer. Documents containing sensitive business or client information, such as financial statements and account credentials, are shared exclusively through encrypted, secure file-transfer channels.
- Network Security. Our internal systems are protected by firewalls, intrusion detection systems, and routine security audits.
7. Secure Storage & Infrastructure
Client data is stored on secure, access-controlled infrastructure. Saratu does not store sensitive client business or personal data loosely on unprotected storage media.
- Cloud Storage. Client files, project assets, and business documents are stored on secure cloud platforms with access controls, version history, and recovery options.
- Physical Security. Any physical documents containing sensitive client information (e.g., signed agreements, compliance documents) are stored in locked, restricted-access locations within our office.
- Device Security. All devices used by Saratu team members to access client data are enrolled in our device management policy, which requires disk encryption, automatic screen-lock, and up-to-date security patches.
- Backups & Recovery. Client data is backed up regularly in a secure, encrypted environment to ensure availability and recovery in the event of system failure.
- No Unauthorized Devices. Access to client accounts and data from personal, unmanaged, or unapproved devices is strictly prohibited.
8. Data Retention & Deletion Policy
Saratu retains client data only for as long as is necessary to fulfill the purpose for which it was collected, comply with legal obligations, or resolve disputes.
| Data Type | Retention Period | Reason |
|---|---|---|
| Active client project data | Duration of engagement + 12 months | Service continuity, dispute resolution |
| Amazon Seller Central credentials | Deleted immediately upon offboarding | Security and client confidentiality |
| Financial and compliance documents (GST, PAN, etc.) | 7 years (statutory requirement) | Statutory requirement under Indian tax law |
| Communication records (emails, support tickets) | 3 years post-engagement | Legal retention, dispute resolution |
| Website analytics / contact form data | 12 months from submission | Sales follow-up, performance analysis |
| Product images / creative assets | Duration of engagement + 6 months | Client deliverable archiving |
| Marketing / newsletter contacts | Until unsubscribed | Email marketing performance analysis |
Upon expiry of the applicable retention period, client data is securely deleted or anonymized such that it can no longer be linked to an individual or business. Clients may request early deletion of their data at any time by contacting us at info@saratu.in. We will process verified deletion requests within 30 days, except where retention is legally required.
9. No Unauthorized Sharing of Data
Saratu does not sell, rent, trade, or share client data — including Amazon seller account information, business documents, or financial details — with any third party outside the scope of an active service agreement.
Limited and controlled data sharing may occur only in the following specific circumstances:
- With Amazon directly. Where required to complete account setup, brand registry, or compliance actions on the client’s behalf, information is submitted to Amazon strictly as required to deliver the contracted service.
- Legal obligation. Where required by Indian law, court order, or government authority, we may disclose information to the extent legally required, while notifying the client wherever permitted.
- With the client’s explicit consent. Where a specific requirement calls for involving a third-party tool or service (e.g., a design tool, advertising platform), we obtain prior client consent before any data is shared.
Saratu will never share your Amazon Seller Central credentials, business documents, or proprietary data with any other seller, competitor, or third party for any commercial purpose.
10. GDPR & Privacy Compliance
Although Saratu is incorporated in India and primarily serves Indian sellers, we are also mindful of compliance with international privacy frameworks when serving clients with operations or customers across the UK, UAE, EU, and other Amazon marketplaces.
- GDPR (EU). For clients or individuals in the EU/EEA, we process personal data lawfully, fairly, and transparently, in accordance with applicable General Data Protection Regulation principles where relevant.
- UK GDPR. For individuals in the UK, we comply with UK data protection principles consistent with general international data protection standards.
- India DPDP Act. We comply with the Digital Personal Data Protection (DPDP) Act, 2023 and align our practices with the obligations it places on data fiduciaries operating in India.
- Data Minimization. We collect only the data necessary to perform the contracted purpose — never more than what’s required.
- Purpose Limitation. Data collected for one purpose (e.g., Amazon listing setup) is not subsequently used for an unrelated purpose without informing the client.
- International Transfers. Where client data is transferred or stored using infrastructure outside India, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses) for any such transfer.
11. Cookies & Tracking Technologies
Our website (saratu.in) may use cookies and similar tracking technologies to support functionality, improve user experience, and gather anonymized performance analytics.
- Essential Cookies. Required for the website to function correctly (e.g., session management, form submission). Cannot be disabled.
- Analytics Cookies. Used to understand how visitors navigate our website (e.g., pages visited, session duration). Data collected is anonymized and aggregated.
- No Advertising Cookies. We do not use third-party advertising cookies or behavioral tracking cookies on our website.
You may manage or disable non-essential cookies at any time through your browser settings. Disabling cookies may affect some website functionality but will not restrict access to our content.
12. Incident Response Process
Saratu maintains a formal incident response process to detect, contain, and respond to any data security or confidentiality risk — including any unauthorized access to a client’s Amazon Seller Central account.
- Detection. Our team monitors all signs of unusual account activity, suspicious login attempts, or unauthorized access across systems we manage on behalf of clients.
- Client Notification. If a confirmed data breach occurs that affects a client’s Amazon account or business information, we notify the affected client within 72 hours of identifying the breach.
- Containment & Remediation. We will take immediate steps to contain the breach, revoke compromised access, reset affected credentials, and prevent further unauthorized exposure.
- Investigation & Resolution. We will conduct a full investigation to determine the breach’s root cause, scope, and impact, and implement corrective measures to prevent recurrence.
To report a suspected security incident involving your account or data, contact us immediately at info@saratu.in or call +91 82 00 16 77 41. We take all security reports seriously and respond promptly.
13. Your Rights
As a client or website visitor, you have the following rights regarding your personal data, where applicable under Indian and international privacy law:
- Right to Access. Request a copy of the personal data we hold about you.
- Right to Rectification. Request correction of any inaccurate or incomplete personal data.
- Right to Erasure. Request deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing. Request that we limit how your data is processed in certain circumstances.
- Right to Data Portability. Request your data in a commonly used, machine-readable format.
- Right to Object. Object to the processing of your personal data for specific purposes.
- Right to Withdraw Consent. Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at info@saratu.in. We will respond within 30 days.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. Any material changes will be posted on this page with an updated revision date. Significant changes affecting how we handle your data will be communicated directly to active clients via email wherever possible.
Continued use of our website or services following any update constitutes acceptance of the revised Policy. We encourage you to review this page periodically to stay informed.
15. Contact Our Data Team
If you have any questions, concerns, or requests related to this Privacy Policy or how Saratu handles your data, please reach out to our team.
Saratu
📞 Call: +91 82 00 16 77 41 ✉️ Mail: info@saratu.in 📍 Address: Dev Prime, Corporate Road, Near Makarba Railway Crossing, S. G. Highway, Ahmedabad – 380051
We aim to respond to all privacy-related inquiries within 5 business days.