Privacy Policy

During anonymous website browsing sessions, we passively collect non-identifiable user metadata without explicit customer input, including visitor IP geolocation tags, browser version, screen resolution, page dwell duration, internal site click paths and first-party cookie interaction logs. All passively gathered browsing data undergoes automatic anonymization immediately after collection and cannot be linked to individual user identities without separate written user consent. We never embed third-party advertising, remarketing or tracking cookies on any public page of the website, and all deployed cookies only support basic site function operation such as cart memory.
We only collect personally identifiable information actively submitted voluntarily by users during checkout, return or account registration, including full recipient names, detailed shipping addresses, postal codes, valid contact emails and visual evidence uploaded for return reviews. All sensitive payment credentials such as full credit card numbers, CVV codes and payment passwords are processed solely by PCI DSS certified external payment gateways. Our internal website servers never store complete payment credential data at any stage of transaction processing or post-order archiving.
All collected personal user data is restricted to four legally compliant use cases with no expanded usage permitted. We use shipping and contact data to complete warehouse picking, cross-border carrier handover and parcel delivery; we verify user identity via order-linked personal data to authenticate return and refund applications; we send automated transaction and delivery status alerts via verified customer emails; we compile fully de-identified sales statistics for internal inventory restocking planning. Unsolicited marketing emails using user personal contact details will only be sent if customers submit explicit opt-in authorization, and opt-out requests are honored within 5 business days.
We limit third-party data sharing strictly to regulated service partners required for order fulfillment, with granular data segmentation for each partner type. Global logistics carriers only receive recipient names and physical shipping addresses with no access to payment or browsing data; PCI-compliant payment processors only access transaction amounts and unique order identifiers without user personal details; cloud backup providers only store fully anonymized order metadata stripped of all identifiable tags. Under no circumstances will we sell, lease or trade user personal data to data brokers, social media platforms or digital advertising agencies.
All global website users hold standard data subject rights aligned with cross-border privacy regulations, including the right to access, download, correct and permanently delete stored personal order records via verified identity support tickets. Completed order personal data is retained for 7 years post-delivery to satisfy international tax and logistics record-keeping mandates, while anonymized browsing logs are automatically purged every 90 calendar days with no manual intervention. After approving valid data deletion requests, we erase all primary and backup identifiable user records across all server clusters within 15 business days with no residual copies retained.
End-to-end TLS 1.3 encryption protects all user data transmitted between customer devices and our website servers. Internal staff access to user databases requires multi-factor authentication including device token and password verification, and every data access action generates immutable audit logs. Independent cybersecurity firms conduct quarterly vulnerability penetration testing to patch system loopholes proactively. In the event of confirmed unauthorized data leakage, we notify all affected users and local regulatory authorities within 72 hours and initiate mandatory security remediation per regional privacy laws.

Â