最后更新日期 / Last Updated: 2026年4月30日 / April 30, 2026
本隐私协议已根据亚马逊数据保护政策(DPP)和可接受使用政策(AUP)的要求进行了补充和修订,以涵盖通过亚马逊SP-API获取的卖家数据处理活动。思拓云尊重并保护所有用户的个人隐私和数据安全。本协议解释了我们如何收集、使用、保护您的信息。
This Privacy Policy has been supplemented and revised in accordance with the requirements of the Amazon Data Protection Policy (DPP) and Acceptable Use Policy (AUP) to cover the processing of seller data obtained via Amazon SP-API. Sitaoyun respects and protects the personal privacy and data security of all users. This policy explains how we collect, use, and protect your information.
一、信息收集 / 1. Information We Collect
在您使用我们的ERP系统及授权我们访问您的亚马逊卖家账户时,我们会收集以下信息:
- 账户信息:您在注册思拓云时提供的公司名称、联系人姓名、电子邮件地址等。
- 授权数据:通过亚马逊SP-API,在您明确授权后,我们获取的卖家业务数据,包括商品目录、Listing信息、库存水平及非敏感的订单状态数据。
When you use our ERP system and authorize us to access your Amazon seller account, we collect the following information:
- Account Information: Company name, contact name, email address, etc., provided when you register for Sitaoyun.
- Authorized Data: Seller business data obtained via Amazon SP-API after your explicit authorization, including product catalogs, Listing information, inventory levels, and non-sensitive order status data.
二、信息使用 / 2. How We Use Information
我们收集的信息仅用于提供、维护和改进我们的ERP服务,具体包括:
- 同步亚马逊商品和库存数据,以实现自动化管理。
- 跟踪订单状态和 Listing 变更通知,提供业务数据同步。
- 为卖家提供数据核算、对账和售后支持服务。
(注:我们绝对不会将您的数据用于营销或广告目的。)
The information we collect is used solely to provide, maintain, and improve our ERP services, specifically including:
- Synchronizing Amazon product and inventory data for automated management.
- Tracking order status and Listing change notifications to provide business data synchronization.
- Providing sellers with accounting, reconciliation, and after-sales support services.
(Note: We will absolutely not use your data for marketing or advertising purposes.)
三、数据访问与应用功能 / 3. Data Access and Application Functions
我们申请的每项SP-API权限均与ERP系统的具体功能直接对应:
- Orders API(订单):检索订单详情,自动同步新订单、跟踪订单状态(如待处理、未发货),提取履约所需的买家和配送信息,帮助卖家及时处理订单、管理自发货(FBM)并避免发货延误。
- Catalog & Feeds API(商品目录与上传):在ERP与亚马逊之间同步商品目录数据(SKU、商品属性、状况等),批量创建和更新Listing,确保数据一致性。
- Merchant Fulfillment API(商家配送):支持FBM发货流程,生成承运商运输标签、验证地址,并向亚马逊提交承运商名称和追踪号以确认发货,确保订单状态正确更新、买家收到追踪信息。
- SQS Notifications(消息队列):订阅订单、Listing及BrowseNode变更通知,实现近实时数据同步,无需持续轮询API,减少服务器负载并防止API限流。
Each SP-API permission we request corresponds directly to a specific function of our ERP system:
- Orders API: Retrieve order details, automatically sync new orders, track order status (e.g., Pending, Unshipped), and extract buyer and shipping information for fulfillment, enabling sellers to process orders promptly, manage FBM shipments, and avoid shipping delays.
- Catalog & Feeds APIs: Synchronize product catalog data (SKU, product attributes, condition, etc.) between the ERP and Amazon to ensure data consistency, and batch create/update Listings.
- Merchant Fulfillment API: Facilitate FBM shipping by generating carrier shipping labels, validating addresses, and submitting carrier names and tracking numbers to Amazon to confirm shipments, ensuring correct order status updates and timely buyer tracking information.
- SQS Notifications: Subscribe to Order, Listing, and BrowseNode change notifications for near real-time data synchronization without constant API polling, reducing server load and preventing API throttling.
四、信息共享 / 4. Information Sharing
我们不会出售、出租或与任何第三方共享您的卖家数据。仅在以下情况下,我们可能会披露必要数据:
- 服务提供商:我们仅在与亚马逊卖家数据处理相关的服务中,向受保密协议约束的服务提供商(如云服务器提供商)共享必要数据,且该等共享绝不得用于营销、广告或任何其他商业目的。
- 法律要求:如法律法规要求,或应政府主管部门的合法要求而披露时。
(注:卖家数据仅代表授权卖家用于ERP系统的功能运作,绝不用于其他目的。)
We do not sell, rent, or share seller data with any third parties. We may only disclose necessary data in the following circumstances:
- Service Providers: We only share necessary data with service providers bound by confidentiality agreements (such as cloud server providers) in relation to Amazon seller data processing, and such sharing must not be for marketing, advertising, or any other commercial purposes.
- Legal Requirements: When required by law or legal requests from competent government authorities.
(Note: Seller data is used solely for the functional operation of the ERP system on behalf of the authorized seller and never for any other purpose.)
五、亚马逊SP-API数据保护 / 5. Amazon SP-API Data Protection
以下条款专门适用于通过亚马逊卖家伙伴API("SP-API")获取的数据:
- 合规承诺:我们严格遵守亚马逊数据保护政策(DPP)、可接受使用政策(AUP)、亚马逊开发者服务协议及所有适用的API条款。我们仅在应用描述所定义的功能所必需的范围内访问、处理和存储数据。
- 数据最小化:我们遵循数据最小化原则,仅申请必需的API角色并获取应用目的所必需的数据字段。
- 禁止用途:我们不会将亚马逊卖家数据用于向卖家提供授权服务以外的任何目的。我们不会将该类数据出售、出租或用于营销、广告、竞争分析或机器学习模型训练。
The following provisions apply specifically to data accessed through the Amazon Selling Partner API ("SP-API"):
- Compliance Commitment: We strictly comply with the Amazon Data Protection Policy (DPP), Acceptable Use Policy (AUP), Amazon Developer Services Agreement, and all applicable API terms. We only access, process, and store data to the extent necessary to provide the functionalities described in our application description.
- Data Minimization: We adhere to the principle of data minimization and only request API roles and retrieve data fields strictly necessary for the defined application purposes.
- Prohibited Uses: We will not use Amazon seller data for any purpose other than providing the authorized services to the selling partner. We will not sell, rent, or use such data for marketing, advertising, competitive analysis, or training machine learning models.
六、数据保留与删除 / 6. Data Retention and Deletion
- 业务数据保留期:非PII业务数据(如订单状态历史和交易记录)保留12个月,以支持核算和售后服务。
- 撤销授权:一旦卖家撤销SP-API授权或删除其思拓云账户,我们将在30天内从服务器永久清除其所有个人身份信息(PII)及相关亚马逊业务数据。备份数据将在下一个备份周期内覆盖或删除,不超过30天。
- 未来PII处理声明:如未来因应用功能扩展需要请求买家个人身份信息(PII),我们将严格遵守亚马逊DPP要求,保留期不超过30天,并届时更新本隐私协议。
- Business Data Retention: Non-PII business data (such as order status history and transaction records) is retained for 12 months to support accounting and after-sales services.
- Revocation of Authorization: Upon a selling partner's revocation of SP-API authorization or deletion of their Sitaoyun account, we will permanently purge all their Personally Identifiable Information (PII) and associated Amazon business data from our servers within 30 days. Backed-up data will be overwritten or deleted within the next backup cycle, not exceeding 30 days.
- Future PII Processing Statement: If future application functionality requires requesting Buyer PII, we will strictly comply with Amazon's DPP requirements, retaining it for no longer than 30 days, and will update this Privacy Policy accordingly at that time.
七、信息安全措施 / 7. Information Security Measures
我们实施行业标准的安全措施以保护亚马逊卖家数据:
- 静态加密:所有存储数据均采用AES-256加密技术进行加密。
- 传输加密:所有数据传输均使用TLS 1.3协议进行保护,确保ERP与亚马逊之间的所有API通信安全。
- 凭证管理:SP-API凭证(包括LWA令牌)安全存储,绝不硬编码,并按照亚马逊要求每180天轮换一次。
- 访问控制:实施严格的基于角色的访问控制(RBAC)。仅具有合法业务需求的授权人员方可访问卖家数据。所有访问均被记录并可审计。
- 基础设施安全:所有数据存储在中国大陆的企业级云服务器(阿里云)上,配备严格的防火墙配置、网络访问控制列表(ACL)。
- 安全审计:我们定期进行安全审计和漏洞评估。
We implement industry-standard security measures to protect Amazon seller data:
- Encryption at Rest: All stored data is encrypted using AES-256 encryption technology.
- Encryption in Transit: All data transmissions are protected using TLS 1.3 protocol, ensuring all API communications between our ERP and Amazon remain strictly secure.
- Credential Management: SP-API credentials (including LWA tokens) are stored securely, never hard-coded, and rotated every 180 days in compliance with Amazon requirements.
- Access Control: Strict role-based access control (RBAC) is enforced. Only authorized personnel with a legitimate business need can access seller data. All access is logged and auditable.
- Infrastructure Security: All data is stored on enterprise-grade cloud servers (Alibaba Cloud) located in mainland China, with strict firewall configurations and network access control lists (ACLs).
- Security Audits: We conduct regular security audits and vulnerability assessments.
八、数据泄露响应 / 8. Data Breach Response
如发生涉及亚马逊卖家数据的疑似或确认的数据泄露事件,我们将:
- 立即控制泄露并开展调查;
- 在发现后72小时内通知受影响的卖家及亚马逊开发者服务团队;
- 提供详细的事件报告,包括范围、原因和补救措施;
- 实施纠正措施以防止再次发生。
In the event of a suspected or confirmed data breach involving Amazon seller data, we will:
- Immediately contain the breach and conduct an investigation;
- Notify the affected selling partners and Amazon's Developer Services team within 72 hours of discovery;
- Provide a detailed incident report including the scope, cause, and remediation measures;
- Implement corrective actions to prevent recurrence.
九、用户权利 / 9. Your Rights
您对您的数据享有以下权利:
- 访问与更正:您有权访问和更正您的账户信息。
- 撤销授权与删除:您有权随时在亚马逊卖家平台撤销我们的SP-API访问权限。一旦撤销,我们将按本协议第六条的规定在30天内删除您的相关数据。
You have the following rights regarding your data:
- Access and Correction: You have the right to access and correct your account information.
- Revocation and Deletion: You have the right to revoke our SP-API access at any time on Amazon Seller Central. Upon revocation, we will delete your relevant data within 30 days in accordance with Section 6 of this policy.
十、儿童隐私 / 10. Children's Privacy
我们的服务面向企业和成年人,我们不会故意收集13岁以下儿童的个人信息。如果我们发现错误收集了儿童数据,将立即删除。
Our services are aimed at businesses and adults. We do not knowingly collect personal information from children under 13. If we discover that we have inadvertently collected children's data, we will delete it immediately.
十一、国际传输 / 11. International Transfers
由于您的数据存储在中国的阿里云服务器上,我们不进行常规的跨境数据传输。如因技术支持等特殊原因需要跨境传输,我们将严格遵守中国相关数据出境法律法规,并事先征得您的同意。
Since your data is stored on Alibaba Cloud servers in China, we do not routinely conduct cross-border data transfers. If cross-border transfer is required for special reasons such as technical support, we will strictly comply with applicable data export laws and regulations and obtain your prior consent.
十二、政策更新 / 12. Policy Updates
我们可能会不时更新本隐私协议。更新后的协议将在本页面上发布,并更新"最后更新日期"。建议您定期查阅本页面以了解最新信息。
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with an updated "Last Updated" date. We recommend that you review this page periodically to stay informed.
十三、客户支持 / 13. Customer Support
我们为所有ERP用户提供专门的技术支持。商家可通过以下方式联系我们:
- 支持邮箱:yisijie@sxtayun.com
- 应用内工单系统:通过ERP系统内置的工单功能提交问题
我们的支持团队经过培训,可协助解决亚马逊API集成问题和一般软件咨询。
We provide dedicated technical support for all users of our ERP. Merchants can contact us through:
- Support Email: yisijie@sxtayun.com
- In-App Ticketing System: Submit issues through the built-in ticketing feature in the ERP system
Our support team is trained to assist with Amazon API integration issues and general software inquiries.
十四、联系我们 / 14. Contact Us
如有隐私相关咨询、数据主体请求或数据泄露报告,请联系我们的支持团队:
- 电子邮件 / Email:yisijie@sxtayun.com
For privacy-related inquiries, data subject requests, or data breach reports, please contact our support team.