Policy Purpose & Scope of Applicable Personal Information Collection
This official privacy policy is formulated to clearly explain the complete rules regarding the collection, storage, usage, protection, and legal disclosure of all personal information submitted by users when browsing, registering accounts, placing orders, and contacting customer service on our online shopping website, fully complying with mainstream global personal data protection regulations applicable to cross-border e-commerce retail platforms. This privacy policy applies to all website visitors, registered account users, order purchasers, and all individuals who submit any form of personal data through all functional pages and service channels of our website, covering all personal data collection behaviors generated by all website operation links including homepage browsing, account registration, product page viewing, shopping cart operation, order payment, logistics delivery address filling, after-sales service application, and customer service message consultation. The core original intention of formulating this privacy policy is to fully guarantee the absolute data security of every user’s personal private information, eliminate user concerns about unauthorized personal data leakage, illegal commercial sales of personal information, or improper third-party sharing of private data, and establish transparent, standardized personal information processing rules that users can fully understand and trust. All personal information collection behaviors carried out by our website strictly follow the minimum necessary collection principle: we only collect the limited personal data content that is absolutely required to complete core shopping service links such as order generation, logistics delivery arrangement, payment transaction verification, and after-sales service processing, and we never actively collect unnecessary sensitive personal data that has no direct connection with website shopping service provision. All personal information processing activities stated in this policy are independently managed by our website operation system, and we never carry out any personal data processing operation that violates the complete clauses of this privacy policy without obtaining explicit user consent through standardized website consent confirmation pop-ups during account registration and first-time order placement. This privacy policy document is the sole authoritative standard for resolving all personal data security disputes between users and our store, and all supplementary privacy notification prompts displayed on individual website functional pages serve only as auxiliary reminders consistent with the core clauses recorded in this official policy document.
Types of User Personal Information Collected & Legitimate Usage Purposes
All personal information collected through our website is divided into two core categories: basic voluntary submitted personal data and automatically collected anonymous browsing technical data, and we clarify the specific legitimate usage purposes for each type of collected information one by one within this policy clause. The first category is basic voluntary personal information actively submitted by users themselves through website operation links, including full recipient names, detailed receiving street addresses, regional postal zip codes, recipient contact communication information submitted when filling in order logistics delivery address forms; account login identification information set by users during website account registration; payment transaction verification data generated during order payment processing; text message content, personal contact information attached to consultation records submitted by users when communicating with website customer service staff; and photographic image materials uploaded by users as supporting evidence for return, refund, or logistics dispute after-sales applications. All voluntarily submitted personal information is collected solely to complete the corresponding shopping service links required by users, with specific legitimate usage purposes including accurate generation of complete order delivery information to arrange global logistics parcel transportation; verify user identity authenticity to complete secure payment transaction settlement; accurately respond to user consultation questions and process submitted after-sales service requests; confirm user identity qualifications when handling return, refund, and logistics dispute resolution procedures; send website order status update notifications, logistics tracking information synchronization reminders, and after-sales service processing progress feedback messages to users through website internal message channels. We never use voluntarily submitted user personal information for irrelevant commercial marketing purposes that exceed the service demand scope of completing user orders and after-sales services without obtaining separate explicit additional consent from users. The second category is anonymous browsing technical data automatically collected by our website server system when users visit all pages of our website, which does not contain any identifiable personal private information that can correspond to specific individual users, including website page access timestamp records, browsing page category records, device model and operating system information of user access terminals, anonymous network access address segments, website page click operation tracks, shopping cart product browsing and collection records, and anonymous website access frequency statistical data. All automatically collected anonymous browsing technical data is used only for internal website operation optimization analysis, with legitimate usage purposes including counting website daily visitor volume to adjust website server operation load configuration; analyzing user product browsing preference data to optimize website product category layout and homepage product display logic; counting page access error records to repair website functional page technical bugs in a timely manner; counting shopping cart operation data to optimize website shopping cart function operation fluency; completing anonymous overall website operation data statistical analysis to formulate targeted website service optimization plans. All anonymous browsing technical data collected by the system is automatically processed into desensitized aggregate statistical data that cannot trace back to specific individual users before internal operation analysis use, and we never combine anonymous browsing technical data with users’ voluntarily submitted identifiable personal information to establish traceable individual user data profiles without separate user consent.
Personal Information Secure Storage, Encryption Protection & Data Retention Time Limits
Our website operation team implements multi-layer comprehensive technical and management security protection mechanisms for all stored user personal information to completely prevent personal data risks including unauthorized internal staff access, external network hacker intrusion data theft, accidental system data loss, and improper personal data leakage caused by system operation negligence. All user personal information stored in our website backend server database is protected by bank-grade end-to-end data encryption technology during both server storage and data transmission processes between user terminal devices and website servers, all identifiable private data fields are converted into encrypted ciphertext format inside the database, and only designated core website operation management staff with unique decryption authority can view complete plaintext personal information after passing multi-level identity authentication verification steps. Our website server equipment is deployed in professional standardized data center facilities equipped with 24-hour uninterrupted video monitoring, physical access identity swipe verification, constant temperature and humidity control, and independent fire prevention and power supply backup systems, and all network transmission channels connected to website servers are protected by high-performance enterprise-grade network firewalls and real-time network intrusion detection systems to continuously monitor and block abnormal network attack behaviors attempting to steal stored user personal data. We formulate strict internal staff personal data access management rules: all website operation customer service, warehouse logistics, and financial settlement staff are only assigned the minimum limited personal information access permissions required to complete their respective job responsibilities, all staff personal data viewing and operation behaviors are automatically recorded in the server permanent operation log system with unique staff identity labels, and the internal management team regularly audits all staff personal data access log records to discover and stop unauthorized private information viewing behaviors in a timely manner. In addition to multi-layer security protection mechanisms, we set clear standardized data retention time limits for all types of stored user personal information, and we automatically execute permanent irreversible data deletion procedures for all expired personal information after the retention cycle ends. The data retention cycle for all voluntarily submitted order-related personal information is set as a fixed time period counting from the completion date of the corresponding order’s full after-sales service processing flow, after which all delivery address, contact, payment, and customer service consultation personal data associated with the order is permanently deleted from website server databases. Automatically collected anonymous browsing technical data is only retained for a short-term fixed statistical analysis cycle, and all anonymous browsing records are automatically cleared by the server system after the analysis cycle ends, with no long-term storage of historical anonymous browsing data. If users actively submit a formal personal information deletion application through our website dedicated privacy service entry, we will manually execute full permanent deletion of all personal data associated with the user’s account within the standard customer service response cycle, and confirm the completion of data deletion to users via website internal message notifications.
Rules of Personal Information Third-Party Sharing, Legal Data Disclosure & User Privacy Rights
We adhere to a strict non-sharing basic principle for all user personal information stored on our website: we will never sell, rent, trade, or transfer any user identifiable personal information to unrelated third-party commercial companies, marketing institutions, data collection platforms, or advertising service providers for independent commercial marketing use without obtaining separate explicit written consent from corresponding users through standardized website consent confirmation procedures. Limited third-party personal information sharing behaviors are only allowed with designated cooperative service providers that are absolutely necessary to complete core website shopping service links, and all cooperative third-party service providers must sign binding official data confidentiality cooperation agreements with our store before accessing any user personal information, which clearly restricts third parties to only use shared personal information to complete the designated single service cooperation project with our store, prohibits third parties from storing, copying, re-sharing, or using shared user personal information for any other independent purposes, and stipulates strict data leakage liability compensation clauses for third-party confidentiality agreement violations. The designated limited cooperative third-party service providers allowed to access partial user personal information include international logistics carriers responsible for completing global parcel delivery of user orders (only obtain user submitted delivery address and recipient contact information required to complete parcel transportation), cross-border payment service platforms responsible for processing user order payment transactions (only obtain payment verification data required to complete fund settlement), and professional after-sales service auxiliary institutions authorized to assist in processing user return and refund applications (only obtain order number and limited delivery information required to verify order authenticity). Except for the above designated necessary cooperative service providers with signed confidentiality agreements, we never share any user personal information with any other third-party entities under any circumstances without separate user consent. We reserve the right to legally disclose stored user personal information to relevant official regulatory authorities only when receiving formal legal documents including court subpoenas, official administrative law enforcement investigation notices, or other legally binding official data disclosure requests issued by legitimate government regulatory institutions, and all legal data disclosure operations strictly comply with local data protection legal requirements, with only the minimum personal information content required to respond to official legal requests provided to regulatory authorities. All users who browse and use our website possess complete standardized privacy management rights clearly defined in this policy, including the right to independently refuse website collection of non-necessary personal information by closing relevant data consent switches on website account setting pages; the right to log into personal website accounts at any time to view, modify, update or correct all self-submitted personal information such as delivery addresses and contact information; the right to submit a formal application to permanently delete all personal data associated with personal website accounts through the dedicated privacy service entry; the right to withdraw previously authorized consent for third-party limited personal information sharing through account setting privacy switches at any time; and the right to submit privacy policy consultation or personal information leakage risk feedback through the website customer service channel at any time. If users discover suspected personal information leakage risks related to their own data when using our website, they can submit detailed feedback through customer service channels immediately, and our dedicated privacy management team will launch a full independent security investigation within the standard service response cycle and issue a complete risk handling and rectification result feedback to users via website internal message notifications.