Privacy Policy

Your privacy matters

SuperDesk is committed to protecting the privacy and security of your personal information and Amazon seller data. This policy explains exactly how we collect, use, store, and protect your data.

Effective Date: 1st January 2025  ·  Last Updated: May 2025

1. Who We Are & Scope of This Policy

SuperDesk E-thrust Services Pvt. Ltd. ("SuperDesk", "we", "our", "us") is an Amazon marketplace management company registered in India. We provide Amazon account management, product listing optimization, A+ Content, Brand Store development, Sponsored Ads management, FBA compliance, and related ecommerce services.

This Privacy Policy applies to:

  • All visitors to our website at superdesk.in
  • All clients and prospective clients who engage with our services
  • Any individual whose personal data we process in connection with the delivery of Amazon marketplace management services
  • Third parties who communicate with us on behalf of clients

By accessing our website or engaging our services, you acknowledge and agree to the practices described in this Policy.


2. What Information We Collect

We collect only the information necessary to deliver our services effectively and securely. This includes:

Category Examples How Collected
Identity Data Full name, business name, designation Contact form, onboarding
Contact Data Email address, phone number, office address Contact form, email, calls
Amazon Account Data Seller Central access credentials (where granted), ASIN lists, account health metrics, sales performance data, listing content Directly shared by client during onboarding
Business & Financial Data GST number, PAN, bank details (for account setup services only), brand registration details Directly provided by client
Product Data Product descriptions, images, pricing, dimensions, inventory data Shared by client for listing work
Technical Data IP address, browser type, device information, pages visited, session duration Automatically via website analytics

3. Handling of Amazon Seller Data

This section is critically important. SuperDesk operates directly within your Amazon Seller Central account. The safeguarding of your Amazon seller data is our highest operational priority and a non-negotiable standard across every engagement.

When a client engages SuperDesk for Amazon account management services, we may be granted access to their Amazon Seller Central account. This access is handled as follows:

  • Access Scope: We request only the minimum level of Seller Central permissions necessary to perform the specific services contracted. We do not request admin-level access unless explicitly required and approved by the client in writing.
  • Credential Handling: Amazon Seller Central login credentials shared with SuperDesk are stored in encrypted, access-controlled password management systems. Credentials are never stored in plain text, spreadsheets, email, or unencrypted documents.
  • Dedicated Access Management: All Seller Central access activity is conducted through named, identifiable team accounts. Anonymous or shared logins are not permitted under our internal access policy.
  • No Third-Party Sharing: Amazon account credentials and seller data are never shared with third parties, subcontractors, or external individuals without explicit, documented client consent.
  • Account Actions: All actions taken within a client's Seller Central account are performed as instructed or within pre-agreed operational scope. SuperDesk will not take actions within an account beyond the agreed service scope without client approval.
  • Access Revocation: Upon termination of a service agreement, SuperDesk will immediately cease all access to the client's Amazon account and confirm in writing that access has been removed. Clients are also strongly advised to revoke access directly from their Seller Central permissions settings.
  • Amazon MWS / SP-API Compliance: Where SuperDesk uses Amazon's APIs to manage account operations, all usage complies with Amazon's Developer and Data Use Policies. Client data accessed via API is not used for any purpose beyond service delivery.

SuperDesk will never use a client's Amazon account to conduct activities for other clients, personal gain, or any purpose outside the contracted scope. Any breach of this commitment may be reported to Amazon and relevant authorities


4. How We Use Your Information

Personal and business data collected is used strictly for the following purposes:

  • Service Delivery: To perform contracted Amazon marketplace management services including listing creation, account management, A+ Content, advertising, and FBA support.
  • Communication: To respond to enquiries, provide service updates, share reports, and coordinate with clients on project progress.
  • Account Setup: To complete Amazon seller account registration, brand registry, GTIN exemption, and related documentation processes on behalf of clients.
  • Legal Compliance: To comply with applicable Indian law, GST obligations, and any regulatory requirements relevant to our business operations.
  • Improvement of Services: Anonymised and aggregated data may be used to improve our internal workflows and service quality. No individually identifiable client data is used for this purpose.
  • Security: To detect and prevent unauthorised access, fraud, or misuse of our systems or client accounts.

We do not use client data for marketing to third parties, profiling, automated decision-making, or any purpose not listed above.


5. Data Encryption & Security Measures

SuperDesk implements industry-standard technical measures to protect all client data:

  • Encryption in Transit: All data transmitted between clients and SuperDesk systems — including via our website, email communications, and file transfers — is encrypted using TLS 1.2 or higher (HTTPS). Unencrypted transmission of sensitive data is prohibited.
  • Encryption at Rest: Sensitive data stored in our systems, including Amazon credentials, financial documents, and client business data, is encrypted at rest using AES-256 encryption or equivalent standards.
  • Password Management: All team members use enterprise-grade, encrypted password managers for storing client credentials. Weak, reused, or plain-text passwords are not permitted under our internal security policy.
  • Multi-Factor Authentication (MFA): MFA is mandatory for all SuperDesk team members accessing internal systems, client accounts, and communication platforms where sensitive data may be present.
  • Secure File Transfer: Client documents containing sensitive business or financial information are transferred only through secure, encrypted channels. Email attachments containing sensitive data are sent in encrypted or password-protected formats.
  • Network Security: Our internal systems are protected by firewalls, intrusion detection systems, and regular security assessments to identify and address vulnerabilities.

6. Limited Employee Access

Access to client data within SuperDesk is strictly governed by the principle of least privilege — team members are granted access only to the client data necessary to perform their specific role.

  • Role-Based Access Control (RBAC): Each team member is assigned a defined role with specific data access permissions. A listing specialist, for example, does not have access to client financial documents or Seller Central credentials unless directly assigned to that client's account management.
  • Named Access Only: All access to client systems, credentials, and documents is tied to specific named individuals. Generic or shared team logins are prohibited.
  • Confidentiality Agreements: All SuperDesk employees and contractors sign a Non-Disclosure Agreement (NDA) and data confidentiality agreement before being granted access to any client data.
  • Access Logging: Access to sensitive client data and systems is logged and auditable. Logs are reviewed periodically to detect any anomalous or unauthorised access patterns.
  • Offboarding Procedure: When a team member leaves SuperDesk, all their access to client systems, internal tools, and data repositories is revoked immediately on their last working day.

7. Secure Storage & Infrastructure

Client data is stored on secure, access-controlled infrastructure. SuperDesk does not store sensitive client data on personal devices, local hard drives, or unprotected storage media.

  • Cloud Storage: Client files, project assets, and business documents are stored on enterprise cloud platforms with access controls, version history, and audit trails.
  • Physical Security: Any physical documents containing sensitive client information (e.g., signed agreements, compliance documents) are stored in locked, restricted-access locations within our premises.
  • Device Security: All devices used by SuperDesk team members to access client data are enrolled in our device management policy, which requires disk encryption, automatic screen-lock, and up-to-date security patches.
  • Backup & Recovery: Client data is backed up regularly to a secure, encrypted backup environment to ensure availability and recovery in the event of system failure.
  • No Unauthorised Devices: Access to client accounts and data from personal, unmanaged devices is prohibited without prior approval from management and appropriate security configuration.

8. Data Retention & Deletion Policy

SuperDesk retains client data only for as long as is necessary to fulfil the purpose for which it was collected, comply with legal obligations, or resolve disputes.

Data Type Retention Period Reason
Active client project data Duration of engagement + 12 months Service continuity, dispute resolution
Amazon Seller Central credentials Deleted immediately upon contract termination Security & client trust
Financial & compliance documents (GST, PAN, etc.) 7 years from date of receipt Statutory requirement under Indian law
Communication records (emails, messages) 3 years post-engagement Legal reference, dispute resolution
Website enquiry / contact form data 12 months from submission Sales follow-up and service improvement
Product images & creative assets 12 months post-project, unless archived by agreement Client revisions, reference
Analytics / technical data 13 months (rolling) Website performance analysis

Upon expiry of the applicable retention period, data is securely deleted or anonymised such that it can no longer be attributed to any individual or business. Secure deletion includes overwriting or cryptographic erasure of stored files.

Right to Erasure: Clients may request early deletion of their data at any time by contacting us at hello@superdesk.in. We will process verified deletion requests within 30 days, except where retention is required by law.


9. No Unauthorized Sharing of Data

SuperDesk does not sell, rent, trade, or share client data — including Amazon seller data, business information, financial documents, or personal details — with any third party without explicit written consent from the client.

Limited and controlled data sharing may occur only in the following specific circumstances:

  • With Amazon directly: Where required to complete account setup, brand registry, or GTIN exemption processes on the client's behalf, information is submitted to Amazon's official platforms only.
  • Legal obligation: Where required by Indian law, court order, or government authority, we may disclose information to the extent legally required. We will notify the client of any such request unless prohibited by law from doing so.
  • With the client's explicit consent: Where a client specifically requests or authorises us to share their data with a named third party (e.g., a freight partner, legal consultant), we will do so only upon written confirmation from the client.

SuperDesk will never share your Amazon Seller Central login credentials, account health data, sales performance data, or business financial information with any third party under any commercial arrangement.


10. GDPR & Privacy Compliance

Although SuperDesk is incorporated in India and primarily serves Indian Amazon sellers, we also work with international clients — including those based in the European Union (EU), United Kingdom (UK), and other jurisdictions with data protection laws. We are committed to meeting the standards set by applicable privacy regulations.:

  • GDPR (EU): For clients or individuals in the EU/EEA, we process personal data in accordance with the General Data Protection Regulation (GDPR). Our legal bases for processing include contract performance, legitimate interests, and legal obligation. We do not rely on consent as a basis for processing operational data.
  • UK GDPR: For individuals in the United Kingdom, we comply with UK GDPR as retained in domestic law following Brexit.
  • India DPDP Act: We comply with the Digital Personal Data Protection Act, 2023 (India) and the obligations it places on data fiduciaries handling personal data of Indian residents.
  • Data Minimisation: We collect only the minimum data necessary for each purpose — no data is collected speculatively or "just in case."
  • Purpose Limitation: Data collected for one purpose (e.g., Amazon listing work) is not subsequently used for another purpose (e.g., marketing to third parties) without consent.
  • International Transfers: Where client data is processed or stored on cloud infrastructure hosted outside India, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses for EU data transfers).

11. Cookies & Tracking Technologies

Our website (superdesk.in) may use cookies and similar technologies to support functionality, improve user experience, and gather anonymous analytics data.

  • Essential cookies: Required for the website to function correctly (e.g., session management, form handling). These cannot be disabled.
  • Analytics cookies: Used to understand how visitors navigate our website (e.g., pages visited, session duration). Data collected is anonymised and aggregated.
  • No Advertising Cookies: We do not use third-party advertising cookies or behavioural tracking cookies on this website.

You may manage or disable non-essential cookies through your browser settings at any time. Disabling cookies may affect some website functionality but will not impact your ability to contact us or receive our services.


12. Incident Response Process

SuperDesk maintains a formal incident response process to detect, contain, and respond to any data security incidents — including potential or confirmed unauthorised access to client data or Amazon accounts.

  • Detection: Our team monitors for signs of unusual activity across internal systems, client account access logs, and communication channels. Alerts are reviewed within business hours.
  • Containment: Upon identifying a potential incident, affected systems or accounts are immediately isolated or access is suspended to prevent further exposure.
  • Client Notification: If a confirmed incident involves your personal data or Amazon account data, we will notify you within 72 hours of becoming aware of the breach. Notification will include the nature of the incident, data involved, steps taken, and recommended actions for the client.
  • Regulatory Reporting: Where required by applicable law (including the DPDP Act 2023 or GDPR), we will report confirmed personal data breaches to the relevant data protection authority within the legally prescribed timeframe.
  • Investigation & Remediation: We will conduct a full root-cause investigation for every confirmed incident, implement corrective measures to prevent recurrence, and document the incident and our response for accountability and compliance purposes.
  • Client Support: In the event that a client's Amazon account has been compromised, our team will work with the client and Amazon Seller Support to assist with account recovery, credential reset, and restoration of operations.

To report a suspected security incident involving your account or data, contact us immediately at: hello@superdesk.in or call +91 83207 71779. We treat all security reports as high priority.


13. Your Rights

Depending on your location and applicable law, you may have the following rights in relation to your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request corrections to inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data where it is no longer necessary or where you withdraw consent.
  • Right to Restrict Processing: Request that we limit processing of your data in certain circumstances.
  • Right to Data Portability: Request your data in a structured, machine-readable format (where technically feasible).
  • Right to Object: Object to processing of your data based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at privacy@superdesk.in. We will respond within 30 days.


14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or regulatory requirements. Any material changes will be posted on this page with an updated effective date. Where changes are significant, we will notify active clients by email.

Continued use of our website or services following the posting of an updated Policy constitutes acceptance of the revised terms. We encourage you to review this page periodically.


15. Contact Our Data Team

If you have any questions, concerns, or requests regarding this Privacy Policy or the way your personal or business data is handled by SuperDesk, please contact us:

SuperDesk E-thrust Services Pvt. Ltd.

Address

A-2 307, Palladium, Makarba, Prahladnagar, Ahmedabad-380051.

We aim to respond to all privacy-related enquiries within 5 business days.