MerchantSpring connects marketplace, ecommerce, advertising, and retail-media data through authorised access, then governs how dashboards, APIs, and AI workflows use it.
Authorised platform accessAWS hosted data layerScoped AI workflows
Trust starts with how the platform is built.
The strongest security story is not a badge wall. It is being able to explain what enters MerchantSpring, where it lives, who can reach it, how AI requests are governed, and what happens when a customer leaves.
120+authorised marketplace, ecommerce, advertising, and retail-media channels.
300+agencies manage client marketplace data with MerchantSpring.
On requestaudit information, DPA, sub-processor list, security questionnaire, and AI-handling summary.
Authorised data from official sources.
Every connection runs through the marketplace's official API, authorised by the account owner. We never scrape, under any circumstances. If marketplace data is not available through an official channel, it is not in the platform.
We follow each marketplace's data-use and privacy policies to the letter, including Amazon's developer policies. MerchantSpring is an official partner to a number of marketplaces, including Amazon, Walmart, and TikTok Shop, with authorised developer access to each platform's official APIs.
Profit inputs stay private.
COGS, fees, landed costs, and margin assumptions are used for reporting inside MerchantSpring. They are not used to enrich marketplace destinations or unmanaged exports.
Every number has a source.
Every figure in the platform traces back to the marketplace data behind it. When you need to prove where a number came from, for an audit or a sceptical client, ask our support team. They run the full trace for you and walk you through it, end to end.
Buyer data handled to policy.
Where restricted marketplace data is accessed, it is scoped, encrypted, and deleted on the platform's required schedule.
AI gets the context it needs. Nothing more.
When an AI tool connects to MerchantSpring, three controls determine what it can access and how the data is handled.
Task-level contextOnly the data needed to answer the question is returned, not an account-wide export.
Permission-bound accessExisting user, account, and channel permissions still apply.
No model trainingYour data is never used to train AI models.
MerchantSpring MCP (Model Context Protocol) connects compatible AI tools to your live workspace data.
AI clients
ClaudeChatGPTCursorCodexGemini CLIVS Codeand more supported
Official platform APIs feed a governed MerchantSpring data layer. From there, dashboards, reports, integrations, and AI requests receive only the accounts, channels, and task context permitted for that surface.
Official API access
Marketplace, ecommerce, advertising, and retail-media data enters through official APIs authorised by the account owner. MerchantSpring does not scrape.
Official APIsNo scrapingAccount-owner authorisation
Governed data layer
MerchantSpring normalises marketplace, advertising, profit, and reporting data within one governed layer. Customer organisations remain logically separated, and access is controlled by user and integration permissions.
Organisation separationPermission boundariesSource traces on request
Permitted outputs
Dashboards, reports, the API Gateway, and connected AI workflows receive only the accounts, channels, and task context permitted for that surface.
Dashboards and reportsAPI GatewayMerchantSpring MCP
Security controls, in practical terms.
The essentials security reviewers ask about: hosting, encryption, access, and independent assurance. Region, backup, retention, and access-review details are available during review.
AWS hosting and organisation separation.
MerchantSpring runs on AWS, with customer organisations logically separated from one another. Users can access only the accounts, channels, reports, and integrations permitted by their role. Region and backup details are provided during review.
Encryption and key management.
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Connection credentials and keys are managed separately from customer data in a dedicated secrets manager. Rotation and monitoring details are available during review.
Identity and access controls.
Role-based access includes admin and owner controls, with SSO and MFA available for enterprise accounts. MFA is required for staff with infrastructure access. Internal access follows least privilege, with periodic reviews and audit logs retained for at least 12 months.
Independent review and annual testing.
MerchantSpring is audited as part of wider security processes involving PwC and Accenture and has passed Amazon’s security review for Restricted Data Token (RDT) access. Under Amazon’s requirements, we complete annual security assessments and annual penetration testing. Supporting audit information and incident-response documentation are available during customer review.
A clear process when your subscription ends.
Offboarding follows an agreed sequence, so your team knows what happens before and after the subscription ends.
Active subscription
Authorised users can access account data according to their existing permissions while the subscription remains active.
Confirm the exit plan
Before cancellation, we document the available export formats, applicable retention and deletion windows, and how completion will be confirmed.
Channel syncs stop
When the subscription ends, new syncs from connected channels stop and the account enters the agreed offboarding process.
Retention and deletion
The account follows the agreed retention and deletion lifecycle, with completion confirmed through the process set before cancellation.
The questions security teams ask first.
How does MerchantSpring connect to marketplace data?
MerchantSpring connects to marketplace, ecommerce, advertising, and retail-media data only through official, authorised platform channels—never by scraping. We follow each marketplace’s data-use and privacy policies and are an official API partner to marketplaces including Amazon, Walmart, and TikTok Shop.
What can a connected AI tool see?
Connected AI tools are governed by account context and API Gateway permissions. They receive data according to the accounts, channels, brands, and data surfaces the user or key is entitled to access.
Are profitability inputs shared outside MerchantSpring?
No. COGS, fees, landed costs, and margin assumptions stay inside MerchantSpring reporting and are not used to enrich external destinations.
Does MerchantSpring use my data to train AI models?
No. Your data is not used to train MerchantSpring models, and where a request is routed to an external AI provider, it goes through terms that exclude your data from training.
Where is MerchantSpring data hosted?
MerchantSpring is hosted on AWS. Region, residency, backup, monitoring, and infrastructure details are covered with your security or procurement team.
Can I trace where a number came from?
MerchantSpring’s support team can trace a reported figure back to its source channel and provide the relevant lineage or audit detail on request. This is not currently a self-service feature in the product.
What happens to data if I cancel?
Channel syncs stop and the account follows the agreed retention and deletion lifecycle. Available export formats, applicable windows, and the confirmation process are covered before cancellation.
What compliance documentation is available?
MerchantSpring supports security reviews with a DPA, sub-processor details, security questionnaire responses, AI data-handling information, and relevant audit material.
What external security reviews and testing has MerchantSpring completed?
MerchantSpring is audited as part of wider security processes involving PwC and Accenture and has passed Amazon’s security review for Restricted Data Token (RDT) access. Under Amazon’s requirements, we complete annual security assessments and annual penetration testing. Relevant audit information is available directly to clients who require it.
Bring your security questions.
Bring your security or procurement team. We’ll cover authorised data access, AWS hosting, permission boundaries, AI handling, and the documentation available for your review.
Book a walkthrough
Tell us what your review needs to cover so we can prepare the relevant documentation.