How we handle your account access
Giving an agency access to your seller account is a real risk, and you should interrogate it. This page sets out exactly how we take access, who can use it, what they can see, and what happens if something goes wrong.
Last updated: 19 July 2026
1. Marketplace credentials
Our order of preference for taking access, best first. We always ask for the least access that lets us do the job.
- Delegated sub-user access (preferred). Most marketplaces let you create a secondary user with scoped permissions. We ask for this wherever it is available, so you keep ownership of the account, we get only the permissions the work needs, and you can revoke us in one click without changing your own password.
- OAuth / API authorisation. Where a platform offers a token-based integration, we use it. Tokens are scoped, time-limited and revocable by you at any time.
- Shared primary credentials (last resort). Only where a platform offers no sub-user or API option. Where this is unavoidable we ask you to enable two-factor authentication and to change the password at the end of the engagement.
Credentials are never stored in plain text, never sent over WhatsApp or email, never written into spreadsheets or documents, and never committed to any codebase. They are held in a dedicated password manager with per-entry access control.
We will never ask you for your bank account login, your payment gateway credentials, or an OTP for anything other than the specific marketplace login you have agreed we manage.
2. Who on our team can see what
- Access is granted per client account, not per team. A team member is given access only to the accounts they are assigned to work on.
- Each client has one named account manager. They and their direct supervisor are the default access holders.
- Specialists (advertising, cataloguing, reconciliation) are granted access to a specific account only for the period they are working on it, and it is withdrawn afterwards.
- Access is reviewed when a team member changes role, and revoked the same day they leave.
- Two-factor authentication is required on every account our team uses to access client systems, including our own email and password manager.
3. Separation between clients
We frequently manage more than one seller in the same category. That only works if separation is absolute.
- One client's sales figures, pricing, supplier terms, margins or catalogue data are never shown, described or benchmarked to another client.
- Data from one account is never reused to inform work on a competing account.
- Working files are stored per client, in separately permissioned folders.
- We will tell you if we take on a direct competitor in your category where our agreement requires it, and we will honour any exclusivity term we have signed.
4. Devices and working practices
- Client systems are accessed from managed devices with full-disk encryption and screen lock enabled.
- Client data is not accessed over public or unsecured Wi-Fi networks.
- Downloaded reports and settlement files are stored in the client's permissioned cloud folder, not left on local desktops.
- Personal email and personal messaging accounts are not used to transmit client account data.
5. This website
- Served over HTTPS only, hosted on Vercel.
- Form submissions are validated server-side before anything is done with them.
- No client marketplace data, credentials or reports are stored in this website or its database. Contact and audit form submissions are delivered to our team inbox and internal records, and nothing else.
- Secrets are held as environment variables in the hosting platform and are never committed to source control.
6. Incident response
If we suspect a credential or data compromise affecting your account:
- We revoke or rotate the affected access immediately, before investigating.
- We notify you within 24 hours of becoming aware, by phone and in writing — we will not wait until we have a complete picture.
- We tell you what we know: what was accessed, when, and by what route.
- We give you a written account of what happened and what we changed once the investigation closes.
- Where the DPDP Act or a marketplace's terms require us to notify a regulator or platform, we do so, and we tell you that we have.
To report a security concern, contact team@evaraecomsolutions.com with “Security” in the subject line, or call +91 92508 15889. We treat these ahead of all other correspondence.
7. When an engagement ends
- We revoke our own access on the final day of the engagement and confirm to you in writing that we have done so.
- We ask you to independently remove our sub-user and, where shared credentials were used, to change the password.
- We hand over the working files, reports and reconciliation history for your account.
- Working copies of your data are deleted within 90 days, except records we are legally required to retain. See the privacy policy for retention detail.
8. What we do not claim
We hold no third-party security certification. We are not ISO 27001 or SOC 2 certified. The practices on this page are our operating standards, described honestly, not an audited assurance — and we would rather tell you that than imply otherwise.
If your procurement process requires a signed security schedule, penetration test evidence or a specific data processing agreement, ask us and we will tell you plainly what we can and cannot meet.
See also: Privacy policy and Terms of service.