Privacy Policy

Effective 2026-09-13

武汉聚商信息科技有限公司 operates Xinzhi ERP, an order, inventory, fulfillment and storefront support application for Shopify merchants. The Merchant Data Processing Terms describe the Provider's processing commitments to merchants.

Data we process

Through Shopify APIs and at a merchant's direction, we process store, product and variant, location, inventory, current order, customer, merchant-managed fulfillment order, return, refund and Shopify Payments dispute metadata, including status, amount, reason and processing deadlines. We do not access dispute evidence in the current release. Customer and order records can include line items, amounts, status, recipient or customer name, shipping address, broad location, phone and email. Directly from merchant users, we process ERP account identifiers, permissions, app-support communications, security events and audit records required to operate and secure the service.

If a merchant enables the Xinzhi Chat app embed, we process messages and attachments submitted by storefront visitors, a random browser identifier and conversation identifier used for chat continuity, the page and product context where the chat was opened, and any order number or email a visitor voluntarily enters for order-status help. A signed-in Shopify customer may also choose to share their customer session with the widget so the merchant can provide authenticated support. The widget defaults continuity data to session-only browser storage and uses persistent first-party storage only while Shopify's Customer Privacy API reports that preference processing is allowed. If that permission is withdrawn, the widget removes its persistent continuity data. It does not use this data for third-party advertising or unrelated behavior tracking.

Purposes and limits

We use customer and recipient data only to identify, import, fulfill and handle after-sales work for the merchant's own orders. We use storefront chat data only to maintain the visitor's conversation, provide requested self-service information and let the merchant's authorized support agents respond. We use other Shopify data only for merchant-authorized product matching, order operations, inventory publication, merchant-managed fulfillment, returns, refunds and dispute-metadata monitoring. We do not sell personal data or use Shopify customer or storefront chat data for unrelated advertising, profiling, lead generation or Xinzhi ERP marketing.

Sharing, locations and transfers

Subprocessors: Amazon Web Services (hosting, database, encrypted storage and backups); DeepSeek API (merchant-enabled AI support assistance); Google and Microsoft (merchant-enabled email integrations); Cuqiu enterprise email service (privacy and support communications).. Processing regions: Singapore (Amazon Web Services). Shopify processes source-platform data in the regions described in Shopify's services and privacy terms.. International or other transfer safeguards: Data transfers are limited to the listed purposes and providers and protected by TLS, least-privilege access, data minimization and applicable provider contractual safeguards.. Data is otherwise disclosed only to the merchant's authorized users or where law requires it. Access is tenant-scoped and role controlled. Shopify credentials are encrypted and kept in the connector service.

Retention and deletion

Operational customer, order, storefront conversation, attachment, return, refund and dispute-metadata retention: Personal data is retained while the merchant uses the service and it remains necessary for order fulfillment or support. Verified deletion and Shopify redaction requests are completed within 30 days; only anonymized transaction or security facts required by law may be retained longer.. Backup retention and deletion: Encrypted rolling backups are retained for no more than 30 days. Deleted personal data expires from backups within that period and is not restored for normal operations; after disaster recovery, applicable deletion requests are reapplied.. Deletion and verified-request process: Verified Shopify privacy requests are recorded, tenant-scoped, exported or redacted by an authorized administrator, checked for ERP and customer-service records and attachments, and completed within 30 days with retry and escalation for failures.. Uninstall revokes Shopify credentials and removes the theme app embed from the installed app; stored operational data follows the stated deletion process. Mandatory Shopify privacy webhooks record verified requests for the approved operational process; webhook receipt alone is not represented as completed deletion.

Security and rights

We use encryption in transit, encrypted credential storage, least-privilege access, audit controls and recovery procedures. Merchants and data subjects may request access, correction, deletion or restriction of processing, and exercise other applicable rights, by contacting privacy@xzkj.ai.

Contact

武汉聚商信息科技有限公司 · 湖北省武汉市东湖新技术开发区关南科技工业园现代国际设计城三期3幢20层5号-4,中国 · Privacy officer/contact: Company owner serving as the privacy contact; no separately appointed data protection officer. · privacy@xzkj.ai