Full Send PCMS
SP API Compliance
A product of Bracken Labs LLC
Full Send PCMS is a warehouse and fulfillment management software platform operated by Bracken Labs LLC. Full Send PCMS enables authorized fulfillment providers, warehouses, and logistics operators to process Amazon fulfillment workflows on behalf of sellers who authorize access through Amazon.
This page describes how Bracken Labs LLC protects Amazon data processed through Full Send PCMS, including Restricted Data Access, data governance, encryption, retention, logging, credential management, vulnerability management, and incident response.
Legal Entity and Product Ownership
Legal entity: Bracken Labs LLC
Product: Full Send PCMS
Role: Amazon Solution Provider requesting SP-API access
Bracken Labs LLC is responsible for the operation, security, and compliance of Full Send PCMS. Amazon data is accessed only through authorized SP-API integrations and only for approved fulfillment purposes.
Purpose of SP-API Access
Full Send PCMS accesses Amazon Selling Partner API data solely to support fulfillment operations for sellers who authorize access.
SP-API access is used to:
- Retrieve Fulfilled by Merchant orders.
- Process shipping and fulfillment workflows.
- Generate shipping labels and carrier manifests.
- Confirm shipment and tracking information back to Amazon.
- Support inventory coordination required for fulfillment operations.
Full Send PCMS does not provide advertising, buyer profiling, data brokerage, data resale, or data monetization services.
Seller Authorization
Full Send PCMS accesses Amazon data only after a seller grants authorization through Amazon’s authorization process.
Bracken Labs LLC does not access, retrieve, or process Amazon seller or buyer data without seller authorization. Access is limited to the minimum scope required to provide the authorized fulfillment function.
Sellers may revoke authorization through their Amazon account at any time.
Amazon Data Lifecycle
Bracken Labs LLC handles Amazon data across the following six lifecycle stages.
1. Collection
Amazon customer information is collected through Amazon Selling Partner API after seller authorization. Restricted customer information is retrieved only when required to fulfill an open FBM order.
Data collected may include buyer name, shipping address, phone number where required by the carrier, order identifiers, SKU, quantity, and shipping service level.
Full Send PCMS does not collect Amazon data through scraping, browser automation, third-party enrichment, or unauthorized access methods.
2. Processing
Amazon data is processed by Full Send PCMS for fulfillment purposes only.
Processing includes order import, pick and pack workflow creation, carrier label generation, shipping manifest preparation, shipment confirmation, and tracking update submission.
Customer PII is not used for marketing, advertising, profiling, analytics, model training, resale, or any secondary purpose.
3. Storage
Amazon data is stored only in approved cloud infrastructure used by Full Send PCMS.
Customer PII is encrypted at rest using AWS KMS-backed encryption with AES-256 or stronger controls. SP-API credentials are stored in AWS Secrets Manager and are not stored in source code, local files, removable media, personal devices, or unmanaged storage.
4. Use
Amazon data is used solely to fulfill and ship customer orders on behalf of authorized sellers.
Access is limited to authorized personnel and application services based on role, least privilege, and operational need.
5. Sharing
Amazon customer PII is shared only with the shipping carrier required to create the shipping label, generate the manifest, and complete delivery for the associated order.
Data is transmitted using TLS 1.2 or higher.
Amazon data is never sold, rented, monetized, used for advertising, or shared outside the scope required for fulfillment.
6. Disposal
Customer PII is deleted within 30 days after order delivery unless longer retention is required by law.
Deletion is performed through an automated purge process. Deletion logs include timestamp, data category, and record count, but do not include PII.
Non-PII Amazon data is retained only as long as operationally required and no longer than 18 months unless longer retention is required by law.
Encryption at Rest and Key Management
Full Send PCMS encrypts Amazon data at rest using industry-standard encryption.
Encryption controls include:
- Amazon RDS encryption using AES-256 with AWS KMS-managed keys for databases that store Amazon order data.
- Amazon EBS volume encryption using AES-256 for compute resources.
- Amazon S3 server-side encryption with AWS KMS where object storage is used.
- AWS Secrets Manager encryption for SP-API credentials, LWA credentials, database credentials, and application secrets.
Encryption keys are managed through AWS Key Management Service. Key access is restricted through least-privilege IAM policies.
Keys are rotated at least annually. Any key suspected of compromise is disabled, revoked, and replaced immediately.
Production and non-production environments use separate encryption keys and separate key management boundaries. Non-production keys cannot decrypt production data, and production customer PII is not copied into development or testing environments.
Backups, Archives, and Recovery
Full Send PCMS uses encrypted backups for systems that store Amazon data.
Backup controls include:
- Automated encrypted database backups.
- Point-in-time recovery for production databases.
- Encrypted snapshots before significant infrastructure or database changes.
- Geographically separated backup copies in a secondary AWS region where applicable.
- Backup encryption using the same AES-256 and AWS KMS controls applied to primary data.
Bracken Labs LLC maintains the following recovery objectives:
Recovery Point Objective: 5 minutes for production database data using point-in-time recovery, subject to AWS service availability.
Recovery Time Objective: 4 hours to restore core fulfillment system availability from the latest valid backup or infrastructure-as-code deployment.
Backup and recovery procedures are tested quarterly.
Logging and Monitoring
Bracken Labs LLC maintains centralized security logging and monitoring for systems that process Amazon data.
Logging and monitoring controls include:
- AWS CloudTrail for AWS API and management activity.
- Amazon CloudWatch Logs for application and system logs.
- VPC Flow Logs for network activity.
- Amazon GuardDuty for threat detection.
- Security alerts for unusual access patterns, failed authentication attempts, unexpected request rates, suspicious API activity, unauthorized access attempts, and system errors.
Security logs are retained for a minimum of 12 months.
Customer PII is not written to logs. Application logs exclude buyer names, shipping addresses, phone numbers, email addresses, and other customer PII. Logs may include non-PII operational identifiers such as Amazon order ID, internal record ID, timestamp, user ID, event type, success or failure status, and system error category.
Security events are reviewed through automated alerting and periodic manual review. Investigations are handled under the Bracken Labs LLC Incident Response Plan.
Credential and Password Management
Bracken Labs LLC enforces password and credential controls for all systems that process or administer Amazon data.
Password controls include:
- Minimum password length of 12 characters.
- Required uppercase letters, lowercase letters, numbers, and special characters.
- Passwords may not contain any part of the user’s name, username, or email address.
- Reuse of the last 10 passwords is prohibited.
- Minimum password age of 1 day.
- Maximum password age of 365 days.
- Multi-factor authentication is required for all accounts with access to systems handling Amazon data.
- Accounts are locked after no more than 10 failed login attempts.
SP-API credentials, LWA credentials, database credentials, and other secrets are stored in AWS Secrets Manager or equivalent secure secret storage. Credentials are never committed to source code, stored in plaintext, or logged.
LWA client secrets are rotated in accordance with Amazon requirements, and other API keys or secrets are rotated on a defined schedule or immediately upon suspected compromise.
Vulnerability Management
Bracken Labs LLC maintains a vulnerability management program for systems that process or store Amazon data.
Controls include:
- Code vulnerability scans before production releases.
- Dependency scans before production releases and on a recurring basis.
- Vulnerability scans across systems that process or store Amazon data at least every 30 days.
- Runtime scanning through AWS security services or equivalent tools.
- Annual penetration testing by qualified security professionals or an independent third party.
Vulnerabilities are tracked to closure in a vulnerability register. Critical-risk vulnerabilities are remediated within 7 days of discovery. High-risk vulnerabilities are remediated within 30 days of discovery.
Incident Response
Bracken Labs LLC maintains a documented Incident Response Plan covering preparation, identification, containment, eradication, recovery, and lessons learned.
If a security incident affects Amazon data or customer PII, Bracken Labs LLC will notify Amazon within 24 hours as required by Amazon policy. The incident response process includes access restriction, credential rotation, scope assessment, remediation, evidence preservation, recovery validation, and post-incident review.
Compliance Commitment
Bracken Labs LLC is committed to compliance with:
- Amazon Selling Partner API policies.
- Amazon Data Protection Policy.
- Amazon Acceptable Use Policy.
- Applicable data protection and security requirements.
This page is reviewed periodically and updated as policies, systems, and operational practices evolve.
Contact
For questions related to SP-API compliance, data protection, or security practices, please contact:
Bracken Labs LLC
Full Send PCMS – Security and Systems