我们收集什么、怎么用、存在哪、怎么保护、给谁看、什么时候删。逐条写清楚。What we collect, how we use it, where it is stored, how it is protected, who it is shared with, and when it is deleted. Stated item by item.
生效日期 2026-09-01Effective 2026-09-01
卖家店铺经营数据 —— 经你授权,从你的 ERP(领星)与亚马逊卖家账户读取:商品与 SKU 信息、库存与可售天数、订单与销量、退货、广告花费与搜索词报告、成本与毛利。这些数据描述的是你的生意,不是消费者个人。 Seller shop operating data — read, with your authorisation, from your ERP (LingXing) and your Amazon seller account: product and SKU records, inventory and cover days, orders and sales, returns, ad spend and search-term reports, cost and margin. This data describes your business, not individual consumers.
联系与账号信息 —— 你主动提供的姓名、邮箱、公司名,以及用于接收报告的飞书/Telegram 会话标识。 Contact and account information — the name, email and company name you give us, plus the Feishu/Telegram conversation identifier used to deliver reports.
我们不收集的 —— 我们不请求、不存储消费者个人身份信息(买家姓名、收货地址、电话、邮箱)。我们只申请亚马逊 SP-API 的非受限角色(库存、定价、财务、商品listing、品牌分析、卖家洞察),不申请任何需要处理买家 PII 的受限角色。 What we do not collect — we neither request nor store consumer personally identifiable information (buyer names, shipping addresses, phone numbers, email addresses). We apply only for non-restricted Amazon SP-API roles (Inventory, Pricing, Finance, Product Listing, Brand Analytics, Selling Partner Insights) and for none of the restricted roles that would involve buyer PII.
只有一个用途:为你的店铺生成分析与建议 —— 断货风险、广告浪费、亏损 SKU、退货异常、竞品变化,按「不处理的代价」排序后交给你。 One purpose only: to produce analysis and recommendations for your shop — stockout risk, ad waste, loss-making SKUs, return anomalies, competitor movement — ranked by what it costs to ignore and handed to you.
你的店铺数据不会被用来训练模型、不会与其他客户的数据合并、不会用于广告投放,也不会转售。分析在你的租户内进行,结果只回到你指定的接收渠道。 Your shop data is not used to train models, not pooled with other customers' data, not used for advertising, and never resold. Analysis runs within your tenant and results return only to the channel you nominate.
数据存放在我们控制的服务器上,按客户隔离。每个客户有独立的数据目录与配置,处理过程不跨租户。 Data is held on servers we control, isolated per customer. Each customer has its own data directory and configuration, and processing does not cross tenants.
保留期限:非个人身份信息最长保留 18 个月,到期清除。这是我们自己设定的上限,用于满足亚马逊对第三方开发者的数据留存要求。用于生成报告的中间产物在报告交付后清除。 Retention: non-PII is kept for at most 18 months and purged thereafter. This is a ceiling we set ourselves, to meet Amazon's data-retention expectations of third-party developers. Intermediate artifacts used to produce a report are cleared once the report is delivered.
只读架构。 系统对你的亚马逊、ERP 与广告账户没有任何写入路径 —— 不是"关掉了",是代码里不存在。这一条由自动化测试与失败时默认关闭的桥接层强制执行。 Read-only architecture. The system holds no write path to your Amazon, ERP or ad accounts — not disabled, absent. This is enforced by automated tests and a fail-closed bridge.
传输全程 TLS 1.2 及以上。凭据存放在专用密钥管理服务中,不落在代码库、日志或消息里。访问采用多因素认证与最小权限,并定期复核。 All transport is TLS 1.2 or above. Credentials live in a dedicated secret manager and never appear in the repository, in logs, or in messages. Access uses multi-factor authentication and least privilege, reviewed periodically.
我们维护书面安全策略与事件响应计划,指定事件联系人,并在确认安全事件后 24 小时内通知受影响客户与亚马逊。运行日志保留 12 个月以供追溯。 We maintain a written security policy and an incident-response plan, name an incident point of contact, and notify affected customers and Amazon within 24 hours of confirming a security incident. Operational logs are retained for 12 months for traceability.
不出售,不交换,不用于广告。 你的店铺数据只在两处离开我们的服务器:一是发回给你(飞书/Telegram/邮件),二是发往为我们提供推理能力的模型服务商,且仅限完成你请求的那一次分析。 Never sold, never traded, never used for advertising. Your shop data leaves our servers in exactly two directions: back to you (Feishu/Telegram/email), and to the model provider that supplies our reasoning, solely to complete the analysis you asked for.
我们不会把你的可识别信息 —— ASIN、店铺标识、品牌名、单店财务数字 —— 公开在本站、案例或对外材料中,除非你逐份书面同意。 We do not publish your identifiable information — ASINs, store identifiers, brand names, per-shop financial figures — on this site, in case studies, or in outward-facing material, unless you agree in writing, per item.
法律强制要求时(法院命令、监管调查)我们可能须披露;在法律允许的范围内我们会先通知你。 We may be compelled to disclose by law (a court order, a regulatory investigation); where the law permits, we will tell you first.
你随时可以要求删除。 写信到下面的邮箱,我们在 30 天内删除你的店铺数据、配置与派生产物,并回信确认删了什么。 You can ask for deletion at any time. Write to the address below and we will delete your shop data, configuration and derived artifacts within 30 days, and write back confirming what was removed.
你撤销授权或终止服务时,同样的删除流程自动执行,无需你再提出。到期的非个人身份信息按上面的 18 个月上限自动清除。备份介质中的副本在备份轮转周期内清除。 Revoking authorisation or ending the service triggers the same deletion automatically, with nothing further required from you. Non-PII ages out automatically under the 18-month cap above. Copies on backup media are cleared within the backup rotation cycle.
你也可以要求查看我们持有的关于你的数据,或更正其中不准确的部分。 You may also ask to see the data we hold about you, or to correct anything inaccurate in it.
隐私、数据删除、安全事件,都发到这个地址,我们是同一个负责人在看: Privacy questions, deletion requests and security incidents all reach the same responsible person at:
本政策如有变更,我们会更新页首的生效日期;实质性变更会另行通知在服务期内的客户。 If this policy changes we will update the effective date at the top of this page, and material changes will be notified separately to customers under service.