Our organization ("we", "our", or "us") respects your privacy and is committed to protecting the personal and business information of our users. This policy explains how we collect, use, store, transmit, and safeguard information through our application and related services across all integrated e-commerce platforms.
1. Applicable Scope
This policy applies to all personal data processed through our application and its integrations with the following e-commerce platforms:
- TikTok Shop Data accessed via TikTok Shop Open API
- Amazon Data accessed via Amazon SP-API
- Shopee Data accessed via Shopee Open Platform API
- eBay Data accessed via eBay Developer API
- AliExpress Data accessed via AliExpress Open Platform
- Other Any additional platform integrations as configured
This policy applies to all employees, contractors, and third-party service providers who access personal data on our behalf.
2. Information Collection
We collect only the minimum personal data necessary to provide our services, based on the principle of data minimization:
2.1 Data Collected from Platform APIs
| Data Category |
Examples |
Source |
| Account Credentials |
API access tokens, refresh tokens, shop identifiers |
Platform OAuth authorization |
| Order Information |
Order ID, buyer name, shipping address, phone number |
Platform order APIs |
| Product Information |
Product titles, SKUs, pricing, inventory levels |
Platform product APIs |
| Seller Information |
Seller name, shop region, seller type |
Platform authorization APIs |
2.2 Data Collected Directly
- Account registration details (name, email address)
- Usage analytics and application performance metrics
We do not collect data beyond what is necessary for service provision. All data collection is based on explicit user authorization through each platform's OAuth flow.
3. How We Use Information
We use collected information solely for the following purposes:
- Service Provision: Provide ERP services, platform integrations, and order management
- Business Operations: Support product listings, pricing, inventory sync, and order fulfillment
- Analytics: Generate insights and performance reports for authorized users
- Security: Ensure platform security, fraud prevention, and legal compliance
- Communication: Respond to user inquiries and provide service notifications
We do not use personal data for marketing, profiling, or any purpose beyond the scope of service provision without explicit consent.
4. Data Storage & Encryption
All personal data is encrypted at rest using industry-standard cryptographic algorithms before being written to the database. No sensitive data is stored in plaintext.
4.1 Encryption Standards
| Data Type |
Encryption Method |
Key Management |
| API Tokens (access_token / refresh_token) |
AES-128-CBC + HMAC-SHA256 (Fernet) |
Environment variables |
| Buyer Personal Data (name, address, phone) |
AES-128-CBC + HMAC-SHA256 (Fernet) |
Environment variables |
| Seller Identifiers (open_id, shop_cipher) |
AES-128-CBC + HMAC-SHA256 (Fernet) |
Environment variables |
| Database Backups |
AES-256 full-disk encryption |
Cloud KMS |
4.2 Key Management
- Encryption keys are managed via environment variables and never hardcoded in source code
- Keys are not stored in version control systems
- Keys are rotated periodically (at least every 90 days)
- Key access is restricted to authorized system administrators only
5. Data Transmission & Sharing
5.1 Transmission Security
- All data transmissions use HTTPS / TLS 1.2+ encryption
- Internal service-to-service communication uses TLS or mutual TLS (mTLS)
- Plaintext protocols (HTTP, FTP) are strictly prohibited for personal data transmission
- API requests to e-commerce platforms are signed using HMAC-SHA256
5.2 Third-Party Sharing
We do not sell, rent, or trade personal data. Data may be shared only under the following circumstances:
| Recipient |
Purpose |
Legal Basis |
| Cloud infrastructure providers |
Server hosting, database storage |
Data Processing Agreement (DPA) |
| Logistics providers |
Order fulfillment and shipping |
Platform integration terms |
| Legal authorities |
Compliance with legal obligations |
Applicable laws and regulations |
All third-party service providers must hold recognized security certifications (ISO 27001, SOC 2, or equivalent) and sign a Data Processing Agreement (DPA) before any data sharing occurs.
6. Access Control
6.1 Role-Based Access Control (RBAC)
We enforce the principle of least privilege. Access to personal data is granted based on job responsibilities:
| Role |
Access Level |
| System Administrator |
Infrastructure access, no direct data access |
| Developer |
Test environment only, no production data access |
| Operations Staff |
Application-level access via role-based permissions |
| Contractor |
Temporary, time-limited, scoped access |
6.2 Access Logging
- All database queries, API calls, and administrative operations involving personal data are recorded in audit logs
- Logs capture: operator identity, timestamp, target object, operation type, and outcome
- Audit logs are retained for a minimum of 180 days
- Logs are tamper-proof and access to logs is itself logged
6.3 Permission Audits
- Quarterly user permission reviews to verify alignment between active personnel and system accounts
- Redundant or outdated privileges are removed promptly
- Comprehensive annual permission audit producing a formal audit report
- All privilege changes require supervisor approval before execution
6.4 Contractor Management
- External contractors must sign a Non-Disclosure Agreement (NDA) before access is granted
- Temporary accounts are provisioned with explicit expiry dates
- Access is revoked within 24 hours of project completion
7. Data Retention & Deletion
7.1 Retention Periods
| Data Type |
Retention Period |
Basis |
| API Tokens |
Until deauthorization or token expiry + 30 days |
Platform terms |
| Order & Transaction Data |
3 years from order completion |
Tax & legal requirements |
| Buyer Personal Data |
Duration of order processing + 30 days |
Data minimization |
| Audit Logs |
Minimum 180 days |
Security compliance |
| Account Registration Data |
Until account closure + 30 days |
User consent |
7.2 Deletion Procedures
- Upon user deauthorization, API tokens are deleted within 30 days
- Upon expiry of retention period, data is irreversibly deleted (including ciphertext and backups)
- Deletion operations are logged with operator, timestamp, and data scope
- Database records are physically removed, not soft-deleted
8. Your Rights
Data subjects have the following rights regarding their personal data:
- Right of Access: Request a copy of personal data we hold
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of personal data ("right to be forgotten")
- Right to Data Portability: Receive personal data in a structured, machine-readable format
- Right to Object: Object to processing of personal data
- Right to Withdraw Consent: Withdraw authorization at any time
Requests are acknowledged within 48 hours and processed within 15 business days. To exercise these rights, contact us at the email provided below.
9. Security Measures
- Encryption at Rest: All personal data encrypted with AES-128-CBC + HMAC-SHA256
- Encryption in Transit: TLS 1.2+ for all data communications
- Access Control: Role-based permissions with least privilege principle
- Audit Logging: Comprehensive audit trail for all data access operations
- Network Security: Firewall, VPN, and IP whitelisting for production access
- Environment Isolation: Production and development environments are fully separated
- Key Management: Encryption keys managed via environment variables, rotated every 90 days
- Regular Reviews: Quarterly permission reviews, annual security audits
10. Incident Response
We maintain an Information Security Incident Response Plan with the following procedures:
- Detection & Reporting: Any suspected security incident must be reported within 1 hour
- Assessment & Response: Security lead assesses and initiates response within 4 hours
- Notification: If a breach involves platform data (e.g., TikTok Shop, Amazon), the affected platform's security team is notified within 72 hours
- Remediation: Root cause analysis and remediation plan within 7 days
- Post-Incident Review: Formal review and policy update within 30 days
11. Policy Updates
This policy is reviewed and updated at least annually, or when significant changes occur in applicable laws, platform requirements, or our data processing practices. Users will be notified of significant changes via email or in-app notifications at least 30 days before the changes take effect.