Data Protection Policy

Charming Holdings LLC · Reviewed and updated: May 17, 2026 · Next review due: November 17, 2026 (every 6 months)

This policy describes how Charming Holdings LLC collects, processes, stores, shares, and disposes of buyer data received from the online marketplaces where we sell. It is the internal operational counterpart to our public-facing privacy policy.

1. Data inventory and classification

FieldSourceClassification
Buyer name (recipient_name)Marketplace APIPII — restricted
Shipping address (lines, city, state, ZIP, country)Marketplace APIPII — restricted
Buyer email (when carrier-required)Marketplace APIPII — restricted
Order ID, order date, items, quantities, pricesMarketplace APIBusiness data — internal
Refunds, fees, financial eventsMarketplace APIFinancial — internal
Payment informationNot collectedn/a (handled by marketplace)

2. Collection

Buyer data is collected only via the marketplaces' official APIs (Amazon SP-API, Walmart Marketplace API, eBay Trading API). We do not collect buyer data from any other source. Each API call is authenticated with credentials tied to our own seller account on that marketplace.

3. Processing

Processing is limited to the following purposes:

Buyer data is never used for marketing, profiling, analytics, machine learning, or any purpose other than fulfilling the specific order it belongs to.

4. Storage and encryption at rest

5. Encryption in transit

6. Access control

7. Logging and monitoring

8. Sharing

Buyer data is not sold, leased, or shared with any third party for marketing, analytics, brokerage, or advertising purposes. The only outside parties involved in handling buyer data are: the marketplaces themselves, the shipping carriers we hand packages to, and the infrastructure providers (cloud host, content-delivery network) that host or secure our systems.

9. Retention and disposal

10. Backup

11. Testing and development

12. Incident response

Refer to the Incident Response Plan for the detection, containment, notification, remediation, and recovery process. Security incidents involving marketplace data trigger notification to the affected marketplace's security team within 24 hours of detection.

13. Policy ownership and review

This policy is owned by the Incident Management Point of Contact (Betzalel Bree) and reviewed every six months. Changes are committed to our private repository with an audit trail of who changed what and when.