Purpose and scope

CoolHealth uses a private application to support internal operations for explicitly authorized Amazon seller accounts. It is not offered as a public data service and does not provide public access to Amazon information.

Encrypted transport

External and connector traffic is protected with HTTPS. Credentials are not placed in public website code.

Signed connector requests

Connector requests use HMAC signatures, short-lived timestamps and unique nonces to reduce tampering and replay risk.

Restricted destinations

The connector allows outbound requests only to approved Amazon and AWS service domains.

Role-based access

System access is limited by employee role, department and operational responsibility.

Encrypted credentials

Seller authorization credentials are encrypted at rest and are not displayed again after storage.

Audit visibility

Administrative actions, sign-ins and sensitive configuration changes are recorded for review.

Data minimization

The integration is designed around business and operational reports. CoolHealth does not use the system to sell buyer information or build unrelated consumer profiles.

Separate connector environments

When authorized seller organizations require separate API operating environments, independent connector servers and domains can be used. Synchronized operational results are then processed within the central internal workflow according to store access controls.

Security contact

Security or privacy questions may be reported to contact@coolhealth.online. Please do not include passwords, access tokens or other secrets in email.