Merchant Data Processing Terms

Effective 2026-09-13

These Merchant Data Processing Terms (the "Data Terms") form part of the Xinzhi ERP Terms of Service and apply when 武汉聚商信息科技有限公司 (the "Provider") processes personal data on behalf of a merchant through Xinzhi ERP. By installing, accessing or continuing to use Xinzhi ERP on or after the effective date, the merchant accepts these Data Terms. If the merchant and Provider sign a separate data processing agreement, the signed agreement controls to the extent of a conflict.

1. Roles

For store, order, customer, recipient and storefront visitor data, the merchant determines the purposes and means of processing and acts as the controller, business or equivalent role under applicable data protection law. The Provider acts as the processor, service provider or equivalent role and processes that data only on the merchant's documented instructions.

When the Provider independently determines processing necessary for its own account administration, security, audit, compliance and support records, the Provider is responsible for that processing as described in the Privacy Policy. These Data Terms do not change the separate agreements that apply between Shopify, the merchant and the Provider.

2. Merchant instructions and responsibilities

The merchant instructs the Provider to process data for the purposes in these Data Terms through Shopify permissions authorized by the merchant and features enabled by the merchant. The merchant must have authority to provide the data and instructions, provide required notices and obtain consent where applicable, protect credentials, restrict access to authorized personnel, avoid submitting unnecessary sensitive data, review irreversible actions and provide accurate information needed to complete customer requests.

3. Data subjects, data and duration

Data subjects can include merchant customers, prospective customers, order recipients, storefront visitors and authorized merchant users. Processed data can include store, product and variant, location, inventory and merchant-managed fulfillment records; current and authorized historical order identifiers, line items, quantities, amounts, status, returns, refunds and dispute records; name, shipping address, broad location, phone and email; storefront support messages and attachments, visitor-provided order number or email, random browser and conversation identifiers and page or product context; and ERP account identifiers, permissions, support communications, security events and necessary audit records.

Processing begins when the merchant installs or enables a relevant feature and continues until the data is no longer needed to provide the service, the merchant stops using the service or the applicable deletion process is completed, subject to the retention rules below.

4. Permitted purposes and limits

The Provider processes data only to identify, import and match the merchant's own Shopify orders and products; publish inventory and perform warehouse, delivery and merchant-managed fulfillment work; perform eligible order edits, cancellations, returns, refunds, after-sales support and dispute-metadata monitoring; maintain visitor-initiated support conversations, requested order-status lookups and merchant-agent replies; and secure, authorize, audit, back up, recover and operate the service and handle compliance requests.

The Provider does not sell personal data or use Shopify customer or storefront support data for unrelated advertising, profiling, lead generation or Xinzhi ERP marketing. The reviewed service does not make automated decisions that have legal or similarly significant effects on customers.

5. Data minimization and confidentiality

The Provider processes only the minimum data required for enabled functionality and limits access to authorized personnel and systems that need it for their duties. Personnel with access to personal data are subject to confidentiality obligations. Data is scoped by merchant and shop and protected through role-based access controls.

6. Security

The Provider applies measures appropriate to the processing risk, including TLS for public endpoints and data in transit; encryption at rest for production data, credentials and backups; storage of Shopify credentials in the Connector service without returning them to browsers or ERP clients; tenant isolation, role controls, least-privilege access, audit controls and recovery procedures; and restrictions on tokens, addresses and protected customer data in logs and audit details.

To the extent permitted by law, after confirming that a security incident affects merchant personal data, the Provider will notify the merchant through its recorded contact information without undue delay and provide information reasonably available at that time.

7. Subprocessors

The merchant authorizes the Provider to use these subprocessors as necessary to provide the service:

The Provider requires subprocessors to process data only for the agreed service and to apply appropriate protections. The current list and material changes are disclosed in the Privacy Policy or updated Data Terms. A merchant that does not want to use an optional integration can leave it disabled or disable it.

8. Processing locations and transfers

The primary production processing region is Amazon Web Services Singapore. Shopify processes source-platform data in the regions described in Shopify's service and privacy terms. Merchant-enabled integrations can process data in regions published by the relevant provider.

International or other transfers are limited to the stated purposes and providers and protected by TLS, least-privilege access, data minimization and applicable provider contractual safeguards. These Data Terms do not claim an unsigned standard contractual clause, certification or adequacy decision. If applicable law requires additional transfer documentation, the parties will complete the required arrangement before that transfer.

9. Retention, deletion and uninstall

Personal data is retained only while the merchant uses the service and it remains necessary for fulfillment, after-sales work or support. Verified access, deletion and Shopify redaction requests are completed within 30 days after receipt. Transaction or security facts that must be retained by law are retained only in de-identified form and only to the necessary extent.

Encrypted rolling backups are retained for no more than 30 days. Deleted personal data expires from backups within that period and is not restored for normal operations. After disaster recovery, applicable deletion requests are reapplied.

Uninstall revokes Shopify credentials and removes the Theme App Embed from the installed app. After receiving and verifying a Shopify customers/data_request, customers/redact or shop/redact webhook, the Provider records the request, uses an authorized administrator to perform the applicable export, anonymization or deletion, and retries and escalates failures. Webhook receipt alone is not represented as completed deletion. More information is available in Data Access and Deletion.

10. Data-subject requests

The merchant is the primary contact for customer-rights requests. The Provider will reasonably assist the merchant in locating, exporting, correcting, restricting, anonymizing or deleting data held by the service. Merchants and data subjects can contact privacy@xzkj.ai. The Provider can verify identity and authority before disclosing or deleting data.

11. Assistance and evidence

On reasonable request, the Provider can supply published policies, processing descriptions and appropriately redacted control evidence relevant to these Data Terms. To protect other merchants, system security and confidential information, the Provider will not disclose other tenants' data, keys, unredacted logs or uncontrolled production access. This limitation does not restrict a legally required regulatory inspection.

12. Termination and priority

After the merchant stops using the service or the service ends, the Provider handles remaining data under these retention and deletion rules and applicable law. If these Data Terms conflict with the main Terms of Service on personal-data processing, these Data Terms control. The main Terms of Service control all other matters.

13. Contact

武汉聚商信息科技有限公司 · 湖北省武汉市东湖新技术开发区关南科技工业园现代国际设计城三期3幢20层5号-4,中国 · Privacy officer/contact: Company owner serving as the privacy contact; no separately appointed data protection officer. · privacy@xzkj.ai