Purpose
目的
This Privacy Policy explains how the Company collects, processes, stores, uses, and protects data in connection with its business operations and lawful, authorized integrations with external platforms and services. The Company is committed to maintaining the confidentiality, integrity, and security of such data and to ensuring that all related activities are conducted in a lawful, compliant, prudent, and responsible manner.
本隐私政策说明公司在业务运营及与外部平台和服务进行合法、授权集成过程中,对相关数据的收集、处理、存储、使用与保护方式。公司致力于维护该等数据的机密性、完整性与安全性,并确保所有相关活动均以合法、合规、审慎和负责任的方式开展。
Scope
适用范围
This Policy applies to business operational data processed by the Company in the course of its daily activities, data obtained through lawful and authorized integrations, employees and authorized personnel who access or handle such data, and all systems, services, and technical infrastructure used for processing, transmitting, storing, and managing that data.
本政策适用于公司在日常经营活动中处理的业务运营数据、通过合法授权集成方式获取的数据、接触或处理相关数据的员工及授权人员,以及用于数据处理、传输、存储与管理的全部系统、服务和技术基础设施。
Data Usage
数据使用
Data is used solely for the Company’s legitimate internal business operations, including but not limited to order processing, inventory management, customer support, fulfillment support, operational analysis, and related business optimization. Such data is processed only in connection with business accounts lawfully owned, managed, and operated by the Company. Except where required by applicable law or expressly authorized, the Company does not sell, lease, transfer, or distribute such data to unauthorized third parties.
相关数据仅用于公司内部合法业务运营,包括但不限于订单处理、库存管理、客户服务、履约支持、经营分析以及相关业务优化。该等数据仅在公司合法拥有、管理并运营的业务账号及其对应业务活动范围内处理。除适用法律法规要求或获得明确授权外,公司不会将相关数据出售、出租、转让或分发给未经授权的第三方。
Data Sharing
数据共享
The Company does not share relevant data with unauthorized third parties. Where third-party service providers are necessary to support system operations, maintenance, or business delivery, access is limited to the minimum level required to perform those services, and the Company makes reasonable efforts to engage established commercial providers with mature security practices and sound reputations.
公司不会与未经授权的第三方共享相关数据。在确有必要使用第三方服务提供商支持系统运行、维护或业务交付时,公司仅授予其完成相关服务所必需的最小访问权限,并将尽合理努力选择具备成熟安全管理措施和良好商业信誉的服务提供商。
Data Protection Measures
数据保护措施
The Company implements appropriate technical and organizational safeguards to reduce the risk of data leakage, misuse, loss, unauthorized access, or tampering. Such measures include, without limitation, secure cloud storage, encrypted transmission, authentication controls, internal role-based access restrictions, activity monitoring, logging mechanisms, and necessary system maintenance and security review procedures.
公司采取适当的技术和组织保护措施,以降低数据泄露、滥用、丢失、未经授权访问或篡改的风险。相关措施包括但不限于安全云存储、加密传输、身份认证控制、内部基于职责的权限限制、访问控制、操作监控、日志记录以及必要的系统维护和安全审查机制。
Data Retention and Deletion
数据保留与删除
Data is retained only for as long as necessary to satisfy legitimate business, audit, risk control, or compliance requirements. When such data is no longer required, the Company handles it in accordance with internal procedures and applicable requirements through secure deletion, de-identification, or anonymization as appropriate.
相关数据仅在满足合法业务运营、审计、风险控制或合规要求所必需的期限内保留。当相关数据不再具有保留必要性时,公司将依据内部流程及适用要求,视情况采取安全删除、去标识化或匿名化处理。
Platform-Authorized Data Use and Deletion
平台授权数据的使用与删除
Data obtained through platform-provided authorized APIs is processed strictly within the scope of authorization and solely for legitimate business purposes. The Company does not use, disclose, or transfer such data beyond the authorized scope. When platform authorization is terminated, the business relationship ends, or the data is no longer required for legitimate retention purposes, the Company will cease processing and delete, de-identify, or anonymize the relevant data in accordance with internal procedures and applicable requirements.
通过平台提供的授权接口获取的数据,仅在授权范围内并基于合法业务目的进行处理,公司不会超出授权范围使用、披露或转移相关数据。当平台授权终止、业务关系结束,或相关数据不再具有合法保留必要性时,公司将依据内部流程及适用要求停止处理,并对相关数据进行删除、去标识化或匿名化处理。
Employee Responsibilities
员工责任
Employees and authorized personnel may access or process relevant data only to the extent necessary for the performance of their duties. They must properly safeguard accounts, passwords, and other access credentials, and must prevent unauthorized disclosure, copying, dissemination, or use of data. Any suspicious activity, abnormal access, or potential security incident must be reported promptly in accordance with internal procedures.
员工及授权人员仅可在履行职责所必需的范围内访问或处理相关数据,并应妥善保护账号、密码及其他访问凭证,防止未经授权披露、复制、传播或使用数据。如发现可疑行为、异常访问或潜在安全事件,应按照内部流程及时上报并配合处理。
Policy Review
政策审查
This Policy will be reviewed periodically and may be updated or revised as necessary in light of business developments, changes in the technical environment, and compliance requirements, so as to maintain its continued relevance and effectiveness.
本政策将根据业务发展、技术环境变化及合规要求进行定期审查,并在必要时作出更新或修订,以确保其持续适用性与有效性。