Three ways tools get Amazon data
- A browser extension with access to Amazon's sites. It runs in the browser where someone at your DSP is signed in to Amazon, and it reads what that person's pages show.
- People or software signing in with your credentials. You give a vendor, or a service the vendor runs, a username and password to sign in to Amazon's tools as you.
- Report files you download. Someone at your DSP downloads the reports from Amazon's tools as they do today, and sends the files to the product.
Some products combine these. The vendor's privacy policy and the permissions an extension asks for usually tell you which ones a product uses, even when the marketing page doesn't.
What an extension with site access can see
Chrome and Firefox show an extension's permissions before you install it. Look for site access: a list of web addresses the extension can work on. Chrome's developer documentation says host permissions let an extension inject scripts into those pages, read cookies, and watch and change network requests to those sites, among other things.
An extension with access to an Amazon site can therefore read what you can read there while you are signed in. That is how it gets data without a password. It also means the extension can see everything on those pages, not only the parts the product uses, and that an update to the extension can change what it does without you reinstalling anything.
None of that makes an extension bad. It means the questions to ask are what it reads and where that data goes. You can see an extension's site access in your browser's extension settings at any time.
What sharing a login means for your account
Sharing an Amazon login with a vendor puts a third party inside your account with your permissions. Whatever that login can see and change, they can too. If their systems are breached, your credentials are part of what leaks. If someone there makes a change, the account history shows it as you.
Your agreement with Amazon may say something about who can use your access. Read your own DSP agreement and Amazon's policies, and ask your Amazon contact if you are unsure. We don't interpret those documents for anyone, and you shouldn't rely on a vendor's interpretation either, including ours.
Working from report files
With report files, nobody outside your DSP touches Amazon's tools. Someone on your team downloads the reports they already use, and the product reads the files. The cost is a manual step: someone has to download and send the files, and if they forget, the data is a day behind.
Good file-based tools make that step small. They accept the files by upload, by forwarded email, or from a shared folder, recognize which report each file is, and show what is missing each morning so it gets done.
What happens when Amazon changes a page or a report
Amazon changes its pages and reports. Every approach above has to cope with that, in different ways.
- An extension that works from page content can stop working, or read the wrong field, when a page layout changes. You may not notice until the numbers look odd.
- A sign-in service can break when the sign-in flow changes, for example a new verification step.
- A file import can meet a report whose columns changed. A careful tool holds that file for review instead of guessing, so nothing wrong is saved, and someone maps the new columns once.
Ask any vendor what happened the last time Amazon changed something their product depends on, and how long the fix took.
Questions to ask any vendor
- Exactly how does Amazon data get into your product?
- Do you, or does anything you run, ever sign in to Amazon as us? Do you ever ask for or store an Amazon password?
- If there is a browser extension, which sites does it have access to, and what does it read there?
- What do you do with data you collect that your product doesn't use?
- What happens when Amazon changes a page or a report? When did that last happen, and what broke?
- Who at your company can see our data, and how is access recorded?
- If we leave, how do we get our data out, and how do you confirm it is deleted?
Write the answers down and keep them with the contract. If an answer to either of the first two questions is vague, ask again in writing.
How SXT Ops works
SXT Ops works from report files. It never signs in to Amazon and never asks for, sees or stores an Amazon password. You send the files by upload, email forward, an upload link from a folder, or the SXT Ops Companion extension for Chrome, which has no access to any web page; Chrome lists no site access for it. When a report's columns change, SXT Ops holds the file for review and nothing wrong gets saved. Every list downloads as CSV from its screen if you leave.
To see what the files you already download can show, read the fleet invoice audit guide. More on security and data handling, the Companion extension, how SXT Ops compares with LinqOps, or bring one station to the pilot.