Security and data handling

Controls built around separate seller authorization

We limit data collection to the agreed operating work, keep credentials away from browser code, and restrict access by customer workspace and job responsibility.

Control areas

How we protect seller data

Security controls are reviewed as the service, infrastructure, staffing, and applicable policies change.

01

Authorization

Connections are created only after a seller owner or administrator approves access. Sellers can revoke access from their own account settings.

02

Credential handling

Application secrets and authorization tokens are processed server-side and excluded from public pages, browser scripts, screenshots, support messages, and public repositories.

03

Access control

Customer workspaces are separated. Staff access is limited according to assigned accounts and job responsibilities, with administrative access kept to necessary personnel.

04

Encryption

Public web traffic uses HTTPS/TLS. Sensitive service credentials and retained operational records are protected through server-side storage controls and restricted system access.

05

Logging and review

Operational and security events are logged for troubleshooting, access review, incident investigation, and service continuity without intentionally logging secret token values.

06

Retention and deletion

Data is retained only for active services, agreed reporting periods, business records, legal requirements, and security review, then deleted, anonymized, or restricted.

Shared responsibility

What customers must protect

Use an authorized account administrator

Only an account owner or authorized administrator should approve a connection.

Manage internal user access

Customers decide which employees may request reports and use the workspace.

Do not send credentials

Seller passwords, API secrets, refresh tokens, and buyer personal information must not be sent by email or support chat.

Report changes promptly

Tell us when staff, ownership, service scope, or authorization requirements change.

Security contact

Report a security or privacy concern

Include your company name, a safe description of the concern, the affected marketplace, and a contact person. Do not include passwords, tokens, secret keys, or buyer personal information.

Email1357553438@qq.comCompanyHONG KONG INNOVATION STARLIGHT LIMITEDPrivacy Policy