Privacy & Data Handling Policy
Last updated: May 19, 2026
This policy explains how Stainless Steel Tool Wrap (“SSTW,” “we,” “us”) collects, processes, stores, uses, shares, and disposes of personal and order data, including information obtained from the Amazon Selling Partner API in connection with orders placed through our Amazon storefront. Stainless Steel Tool Wrap is a family-owned, veteran-owned business operating StainlessSteelToolWrap.com.
1. Scope
This policy covers data we handle to operate our retail and wholesale business, including information from our own website, our payment processor, our accounting system, and the Amazon Selling Partner API (collectively, “Information”). It applies to any Amazon Information we are authorized to access, including order, financial-event, and shipping data.
2. Information We Collect
- Order information — order identifiers, item and quantity details, order totals, order status, and fulfillment channel.
- Shipping information — recipient name and destination address used solely to pick, pack, label, and ship the physical product the customer purchased.
- Financial information — settlement and financial-event data (fees, refunds, reimbursements) used to reconcile our books.
- Account & contact information — email address and shipping preferences for customers who create an account directly on StainlessSteelToolWrap.com.
We collect only the minimum data necessary to fulfill orders and maintain accurate financial records. We do not collect Amazon buyer payment-instrument data; payments are processed by Amazon or by our PCI-compliant payment processor and are never stored on our systems.
3. How We Process and Use Information
We use Information strictly for these purposes:
- Fulfilling, packing, labeling, and shipping orders.
- Generating and printing carrier shipping labels for orders we ship ourselves.
- Reconciling sales, fees, and refunds into our accounting system for tax and bookkeeping purposes.
- Customer service and resolving order or delivery issues.
- Complying with legal, tax, and regulatory obligations.
We never use Amazon Information for advertising, marketing retargeting, resale, profiling, or any purpose other than fulfilling the customer’s order and meeting our legal obligations.
4. How We Store and Secure Information
- Information is stored on access-controlled systems operated by SSTW and a limited set of vetted service providers.
- Data is encrypted in transit (TLS) and encrypted at rest. API credentials and tokens are stored as protected secrets, never in source code, and are rotated periodically.
- Access is restricted to authorized personnel on a least-privilege, need-to-know basis and is logged.
- We maintain network controls, patching, and least-privilege access controls, and we monitor for unauthorized access.
5. How We Share Information
We do not sell, rent, or trade personal information. We share Information only as needed to operate the business:
- Shipping carriers (e.g., UPS, USPS) — recipient name and address, solely to deliver the purchased product.
- Accounting provider (Intuit QuickBooks Online) — order and financial totals for bookkeeping and tax reconciliation.
- Legal & regulatory authorities — only when required by law or to comply with a valid legal process.
Service providers are bound by confidentiality and data-protection obligations and may use the data only to provide their service to us. We do not transfer Amazon Information to any party except as necessary to fulfill orders or as required by law.
6. Data Retention and Disposal
We retain Information only as long as necessary to fulfill the purposes above and to meet legal, tax, and accounting requirements (generally up to seven years for financial records). Personally identifiable shipping information is retained only as long as needed to complete fulfillment and resolve any related customer-service or returns issues, after which it is securely deleted or anonymized. When data is no longer required, it is permanently destroyed using secure deletion methods.
7. Data Breach Handling
We maintain an incident-response process. In the event of a confirmed data breach affecting Amazon Information or customer personal data, we will investigate, contain, and remediate the incident, and notify Amazon and affected individuals or authorities as required by applicable law and Amazon’s Data Protection Policy, within required timeframes.
8. Your Rights
Depending on your location, you may have the right to access, correct, or request deletion of the personal information we hold about you, subject to legal record-keeping obligations. To make a request, contact us using the details below.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.
10. Contact Us
Questions about this policy or our data practices? Contact Stainless Steel Tool Wrap:
