Effective July 13, 2026 · Shaazford Global LLC
This document describes the technical and organizational measures Shaazford Global LLC applies to protect data processed by Shaazford OS. It answers marketplace developer-program security questionnaires (including the Amazon SP-API Data Protection Policy) and gives clients a plain account of how their data is handled. Security contact: info@shaazford.com.
Shaazford OS is a multi-tenant operations platform operated by Shaazford Global LLC. Each customer organization is an isolated tenant. Through the platform we may process operational business data (projects, tasks, documents, messages, time logs, client accounts, invoices), ecommerce performance metrics (product-level sales, units, sessions, conversion, ad spend and inventory, pulled from connected stores or uploaded via CSV), account data (name, email, role, hashed credentials), and integration credentials (OAuth/API tokens for services a user connects).
We do not collect or store buyer/consumer personally identifiable information (PII). Marketplace pulls are limited to non-restricted roles — aggregate product sales, traffic and inventory. We do not request order-level buyer names, shipping addresses, or contact details, and we request the narrowest scopes needed.
ufw) default-denies inbound traffic except SSH/HTTP/HTTPS; fail2ban provides intrusion detection/prevention against brute-force attempts; ClamAV and rkhunter provide anti-malware/rootkit scanning; the application runs in isolated Docker networks; and unattended-upgrades applies OS security patches automatically.Operational and metric data is retained while the workspace/account is active. Integration credentials are deleted on disconnect. On a verified deletion request or account termination, associated data is deleted from the live database within a commercially reasonable period and purged from backups on the normal rotation cycle.
Nightly on-box database backups (consistent, integrity-checked, compressed SQLite snapshots retained 14 days) plus a weekly off-box backup of the latest snapshot. Backups carry the same at-rest encryption for credential fields as the live database.
An append-only audit trail records security-relevant actions (logins, permission/role changes, integration connect/disconnect, approvals, exports). Application logs exclude secrets and tokens. Server access is restricted to authorized administrators via SSH key authentication.
| Provider | Purpose | Data shared |
|---|---|---|
| Hostinger | VPS hosting | All application data (at rest on the VPS) |
| Cloudflare | DNS / edge | Domain resolution; no application data stored |
| SSO / optional Workspace sync | Account email; user-authorized scopes | |
| Amazon (SP-API) | Marketplace metrics | Seller-authorized non-restricted analytics/inventory |
| Shopify | Marketplace metrics | Store-authorized product/order/inventory reads |
| Stripe | Billing (when enabled) | Billing contact; payment handled by Stripe |
| Anthropic | Optional in-app AI | Only the workspace data needed to answer a prompt; scoped per user/role |
| Twilio | Optional SMS 2FA | Phone number + one-time code (only if enabled) |
We do not sell data, and we do not share client data with any party other than the subprocessors above in service of the product.
We maintain a written Incident Response Plan with defined roles, a 6-month review cadence, and a 24-hour notification target. Suspected incidents are reported to the Incident Response Lead and triaged immediately; affected credentials are rotated/revoked and integrations disconnected. Where an incident involves Amazon Information, we notify Amazon at security@amazon.com within 24 hours of detection; affected sellers/clients are notified without undue delay. A root-cause review follows every incident.
Access to production systems and credentials is limited to authorized personnel on a need-to-know basis, protected by SSH keys and, where applicable, 2FA. Personnel maintain confidentiality of any data they can access. Secrets are managed via server environment configuration and excluded from source control.
We align with widely accepted data-protection principles (lawfulness, purpose limitation, data minimization, integrity and confidentiality). This is a policy statement, not a claim of formal certification (e.g. SOC 2, ISO 27001). Clients requiring contractual data-processing terms should contact us at info@shaazford.com.