1. Scope
This policy describes information associated with our public company website and email communications. It also sets out the intended data practices for Xinyiming Amazon ERP, an internal system being developed for our company's own Amazon operations.
The public website does not provide ERP access, account registration or an Amazon authorization flow. Planned API integrations depend on approval and authorization. Descriptions of planned ERP data handling do not indicate that a particular integration is already live.
2. Website and email information
This website uses static HTML and CSS. It does not include analytics, advertising trackers, tracking cookies or a form that collects information. The hosting provider may process technical request information, such as IP addresses, browser information and request times, to deliver and secure the website. Its actual logging practices depend on the hosting configuration.
If you email us, we receive the information you choose to provide, such as your email address, name and message content. We use that information to respond to your inquiry and keep relevant business correspondence. Please do not send passwords, API secrets or access tokens by email.
3. Intended internal ERP data
Subject to the permissions granted, the ERP is intended to process information from our own authorized Amazon seller and advertising accounts. This may include product and listing information, inventory, order and fulfillment records, sales reports, and campaign performance and spending data.
We intend to request only the access required for a defined business function. Any access to restricted or personal customer information requires the relevant Amazon permissions and safeguards before that function is enabled. This public website does not collect Amazon customer information.
4. Purpose and access
Amazon API information is intended for managing our own products, stock, orders, sales reporting and advertising activities. The ERP is for internal company use and is not provided to external sellers.
Access is to be limited to authorized personnel who require it for their duties. Credentials and tokens must remain in the internal system and must not be included in public website files. API use must remain within approved scopes and applicable Amazon requirements.
6. Retention and deletion
Email correspondence is to be retained only for as long as needed to respond to inquiries, maintain relevant business records or meet applicable obligations.
Before API integrations are enabled, retention and deletion rules must be established for each data category under the applicable Amazon policies. API information is to be retained only for its authorized operational purpose and within any required retention limits. Revocation of authorization, loss of permission or an Amazon deletion request must trigger the required access removal and deletion process, including applicable copies and backups.
7. Security
Before processing Amazon API information, the internal system must implement the protections required for the data it accesses. These include appropriate access controls, protection of credentials, secure transmission and storage, and procedures for identifying and responding to security incidents.
These statements describe requirements for the planned ERP. They do not assert a completed security certification or an Amazon endorsement. No public website file contains operational API credentials.
8. Privacy inquiries and requests
Contact zf1334619610@outlook.com with questions about this policy or requests concerning information you provided to us. We will review requests, verify identity where appropriate and respond in accordance with applicable requirements.
For information managed directly by Amazon, you may also use the relevant Amazon account and privacy channels.
Mianyang Xinyiming E-commerce Co., Ltd
zf1334619610@outlook.com
9. Policy updates
We will update this policy when our website, system functionality or data practices change. The effective date at the top identifies the current version. The policy must reflect the actual deployment and processing practices when the ERP becomes operational.