Last updated: July 22, 2026
AstralQ (operated by Hatch Ecom, LLC.) is an Amazon Solution Provider. We comply with and adhere to the Amazon Services Data Protection Policy, which governs the receipt, storage, usage, transfer, and disposal of information accessed through the Selling Partner API and the Amazon Advertising API.
This page describes how AstralQ implements the controls required by the DPP. Our Terms of Service and Privacy Policy incorporate the DPP, the Acceptable Use Policy (AUP) and the Solution Provider Agreement (SPA) by reference.
AstralQ accesses only the data of the Seller who expressly authorizes it via Login with Amazon: catalog, orders, inventory, sales, traffic, financial reports and advertising campaign metrics. We do not access end-buyer data except what Amazon delivers in standard reports, and we delete it per section 4.
AstralQ maintains an incident response plan approved by management and reviewed every 6 months, or after material infrastructure changes.
We delete Personally Identifiable Information (PII) within 30 days after order delivery or after the authorization is revoked. Encrypted backup copies are purged within the following 90 days. Access tokens are deleted when authorization is revoked.
Information is processed solely on Amazon Web Services (AWS), US region, under confidentiality and compliance agreements. AWS is both the original source and the hosting provider. We notify the Seller of any material change to the subprocessor list at least 30 days in advance.
We restrict access to personnel with a need to know. When someone leaves AstralQ, we revoke their access to Covered Systems and Amazon Information within 24 hours.
We monitor and remediate vulnerabilities within the following maximum windows from discovery: critical within 7 days, high within 30 days. Dependencies are kept updated and scanned.
For data protection questions, security incidents or deletion requests: jonathan.a@hatchecom.com · +591 77965862
Hatch Ecom, LLC · 4996 SW 162nd Ave, Miramar, FL 33027, USA