Privacy & Data Handling Policy

Maan Global — E-Commerce Operations & Marketplace Management

Effective Date: 1 August 2026  | Last Updated: 1 August 2026  | Version: 1.0

1. Introduction

Maan Global ("we", "our", "us") is a United Kingdom-based e-commerce reseller operating across multiple online marketplaces. This Privacy and Data Handling Policy describes how we collect, process, store, use, share, and dispose of data obtained through marketplace APIs, including the Amazon Selling Partner API (SP-API), in the course of our business operations.

This policy applies to all personnel, systems, and processes within our organisation that handle marketplace data, including personally identifiable information (PII) of marketplace customers.

2. Data We Collect

Through authorised marketplace API integrations, we collect and process the following categories of data:

2.1 Order Information

  • Order identifiers (order IDs, item IDs)
  • Product details (SKU, ASIN, title, quantity, price)
  • Order status and fulfilment information
  • Transaction amounts and fees

2.2 Customer Personally Identifiable Information (PII)

  • Buyer shipping name
  • Shipping address (street, city, postcode, country)
  • Contact telephone number (where provided by the marketplace for delivery purposes)

2.3 Product and Inventory Data

  • Product catalogue information (titles, descriptions, images, EAN/UPC codes)
  • Inventory levels and pricing data
  • Listing status and performance metrics

3. How We Use Data

Data obtained through marketplace APIs is used strictly for the following legitimate business purposes:

  • Order fulfilment: Processing customer orders, generating shipping labels, coordinating delivery with carriers, and confirming shipment to the marketplace.
  • Inventory management: Synchronising stock levels and pricing across multiple sales channels to prevent overselling.
  • Financial reporting: Calculating profit and loss, tracking fees, and preparing VAT returns as required by UK tax law.
  • Customer service: Responding to delivery queries, processing returns, and resolving order disputes.
  • Regulatory compliance: Maintaining records as required by HMRC, Companies House, and applicable UK/EU regulations.

We do not use marketplace customer data for marketing, advertising, profiling, resale, or any purpose unrelated to order fulfilment and legitimate business operations.

4. Data Storage and Security

4.1 Infrastructure

All marketplace data is stored on infrastructure hosted within Amazon Web Services (AWS) in the EU West (London, eu-west-2) region. Our systems run on dedicated EC2 instances with encrypted EBS storage volumes.

4.2 Encryption

  • In transit: All external communications are encrypted using TLS 1.2 or higher. HTTP traffic is redirected to HTTPS. Internal service-to-service communication occurs over localhost.
  • At rest: Data is encrypted at rest using AES-256 encryption via AWS EBS volume encryption. Database backups are stored on encrypted volumes. Application configuration files containing API credentials are encrypted and access-restricted.

4.3 Access Controls

  • Access to production systems requires SSH key authentication (password authentication disabled).
  • Multi-factor authentication (MFA) is enforced on AWS Console, code repositories, and marketplace seller accounts.
  • Application access is role-based: only authorised personnel (Director, Operations Manager) can access customer PII.
  • The principle of least privilege is applied across all systems.

4.4 Network Protection

  • Databases (MongoDB, PostgreSQL) are bound to localhost only — not accessible from the public internet.
  • AWS Security Groups restrict inbound traffic to HTTPS (443) and SSH (22, IP-whitelisted) only.
  • A reverse proxy (Nginx) handles all external traffic with rate limiting and security headers.

5. Data Sharing

Customer PII is shared only with the following categories of recipients, strictly for order fulfilment purposes:

  • Shipping carriers: Royal Mail, DPD, Evri, Yodel, UPS, and other carriers as needed, to deliver orders to customers.
  • Suppliers: Shipping name and address only, when the supplier dispatches directly to the customer (dropship fulfilment).

We do not sell, rent, trade, or otherwise disclose customer data to any third party for marketing, analytics, or any purpose other than order fulfilment. We do not transfer customer data outside the United Kingdom and European Economic Area unless required for delivery to an international address provided by the customer.

6. Data Retention and Disposal

6.1 Retention Periods

  • Customer PII (shipping name, address, phone): Retained for a maximum of 30 days after order completion or the conclusion of any return/refund process, whichever is later. After this period, PII is permanently deleted from our systems.
  • Order transaction data (order IDs, amounts, fees): Retained for 7 years as required by UK tax law (HMRC record-keeping requirements).
  • Product and inventory data: Retained for the duration of our business relationship with the marketplace, plus 12 months.

6.2 Disposal Method

When data reaches the end of its retention period, it is permanently deleted using cryptographic erasure. Database records are hard-deleted (not soft-deleted). Backups containing expired data are overwritten through the rolling backup cycle (7-day retention). Decommissioned storage volumes are destroyed through AWS's secure media destruction process.

7. Logging and Monitoring

All access to systems containing marketplace data is logged, including:

  • API requests with timestamps, user identity, and action performed
  • SSH access attempts (successful and failed)
  • Database authentication events
  • Administrative actions on marketplace seller accounts

Logs are retained for 90 days and reviewed regularly for suspicious activity. Automated alerts are configured for anomalous access patterns.

8. Incident Response

In the event of a data breach or security incident involving marketplace customer data:

  • The affected systems are immediately isolated to prevent further exposure.
  • The scope of the breach is assessed within 24 hours.
  • The relevant marketplace (including Amazon, per the SP-API Data Protection Policy) is notified within 72 hours.
  • Affected individuals are notified in accordance with UK GDPR requirements.
  • The Information Commissioner's Office (ICO) is notified within 72 hours where required.
  • A root cause analysis is completed and remediation measures are implemented to prevent recurrence.

9. Vulnerability Management

We maintain the security of our systems through:

  • Automated operating system security updates (unattended-upgrades)
  • Monthly vulnerability scans of production infrastructure
  • Dependency monitoring for known vulnerabilities in application frameworks
  • Annual review of security controls and access permissions
  • Prompt patching of critical vulnerabilities (within 72 hours of disclosure)

10. Your Rights

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, individuals whose data we process have the right to:

  • Request access to their personal data
  • Request correction of inaccurate data
  • Request deletion of their data (subject to legal retention requirements)
  • Object to processing of their data
  • Lodge a complaint with the Information Commissioner's Office (ICO)

11. Changes to This Policy

This policy is reviewed and updated at least annually, or whenever significant changes are made to our data processing activities or infrastructure. The "Last Updated" date at the top of this page reflects the most recent revision.

12. Contact

Maan Global

Email: info@maanglobal.co.uk

For data protection enquiries, please contact us using the email address above with the subject line "Data Protection Enquiry".