Personal Information Protection Policy

Effective Date: June 21, 2026

Our organization ("we", "our", or "us") respects your privacy and is committed to protecting the personal and business information of our users. This policy explains how we collect, use, store, transmit, and safeguard information through our application and related services across all integrated e-commerce platforms.

Table of Contents

1. Applicable Scope

This policy applies to all personal data processed through our application and its integrations with the following e-commerce platforms:

This policy applies to all employees, contractors, and third-party service providers who access personal data on our behalf.

2. Information Collection

We collect only the minimum personal data necessary to provide our services, based on the principle of data minimization:

2.1 Data Collected from Platform APIs

Data Category Examples Source
Account Credentials API access tokens, refresh tokens, shop identifiers Platform OAuth authorization
Order Information Order ID, buyer name, shipping address, phone number Platform order APIs
Product Information Product titles, SKUs, pricing, inventory levels Platform product APIs
Seller Information Seller name, shop region, seller type Platform authorization APIs

2.2 Data Collected Directly

We do not collect data beyond what is necessary for service provision. All data collection is based on explicit user authorization through each platform's OAuth flow.

3. How We Use Information

We use collected information solely for the following purposes:

We do not use personal data for marketing, profiling, or any purpose beyond the scope of service provision without explicit consent.

4. Data Storage & Encryption

All personal data is encrypted at rest using industry-standard cryptographic algorithms before being written to the database. No sensitive data is stored in plaintext.

4.1 Encryption Standards

Data Type Encryption Method Key Management
API Tokens (access_token / refresh_token) AES-128-CBC + HMAC-SHA256 (Fernet) Environment variables
Buyer Personal Data (name, address, phone) AES-128-CBC + HMAC-SHA256 (Fernet) Environment variables
Seller Identifiers (open_id, shop_cipher) AES-128-CBC + HMAC-SHA256 (Fernet) Environment variables
Database Backups AES-256 full-disk encryption Cloud KMS

4.2 Key Management

5. Data Transmission & Sharing

5.1 Transmission Security

5.2 Third-Party Sharing

We do not sell, rent, or trade personal data. Data may be shared only under the following circumstances:

Recipient Purpose Legal Basis
Cloud infrastructure providers Server hosting, database storage Data Processing Agreement (DPA)
Logistics providers Order fulfillment and shipping Platform integration terms
Legal authorities Compliance with legal obligations Applicable laws and regulations

All third-party service providers must hold recognized security certifications (ISO 27001, SOC 2, or equivalent) and sign a Data Processing Agreement (DPA) before any data sharing occurs.

6. Access Control

6.1 Role-Based Access Control (RBAC)

We enforce the principle of least privilege. Access to personal data is granted based on job responsibilities:

Role Access Level
System Administrator Infrastructure access, no direct data access
Developer Test environment only, no production data access
Operations Staff Application-level access via role-based permissions
Contractor Temporary, time-limited, scoped access

6.2 Access Logging

6.3 Permission Audits

6.4 Contractor Management

7. Data Retention & Deletion

7.1 Retention Periods

Data Type Retention Period Basis
API Tokens Until deauthorization or token expiry + 30 days Platform terms
Order & Transaction Data 3 years from order completion Tax & legal requirements
Buyer Personal Data Duration of order processing + 30 days Data minimization
Audit Logs Minimum 180 days Security compliance
Account Registration Data Until account closure + 30 days User consent

7.2 Deletion Procedures

8. Your Rights

Data subjects have the following rights regarding their personal data:

Requests are acknowledged within 48 hours and processed within 15 business days. To exercise these rights, contact us at the email provided below.

9. Security Measures

10. Incident Response

We maintain an Information Security Incident Response Plan with the following procedures:

11. Policy Updates

This policy is reviewed and updated at least annually, or when significant changes occur in applicable laws, platform requirements, or our data processing practices. Users will be notified of significant changes via email or in-app notifications at least 30 days before the changes take effect.

12. Contact Us

Data Protection Officer

If you have any questions about this policy or wish to exercise your data rights, please contact:

Email: saletoolbox@163.com

Response Time: Within 48 hours