Privacy Policy
This policy covers an internal application used only for authorized operations of the organization's own Temu stores.
1. Purpose and scope
The application uses authorized Temu interfaces only for purposes covered by the applicable cooperation agreement. Intended functions may include product listing and drafts, product and operational data export, compliance workflows, shipping operations, campaign registration, advertising and ROAS management, and other management functions for the organization's own Temu stores. Each function is enabled only after Temu has approved the corresponding interface permission. Personal data is not sold, used for unrelated profiling, or used for any purpose outside the approved cooperation scope.
2. Data minimization
The current product-listing functions do not request or persist buyer names, postal addresses, phone numbers, email addresses, payment data, shipping or logistics data, or customized-product personal information. If a future Temu-approved shipping or store-management function requires limited order or delivery fields, the application will process only the fields necessary for that authorized operation, will not use them for unrelated purposes, and will apply the retention and security controls described below. Product and operational information supplied by the seller may be processed for approved store-management functions.
3. Temporary data and retention
Temporary working data, if generated during an authorized operation, is stored in a restricted application directory and is automatically deleted within 30 days. The active technical control purges eligible temporary files after 29 days to maintain a compliance buffer. Authentication secrets are not written to application logs.
4. Hosting and service providers
The application is hosted on Amazon Web Services infrastructure in Singapore. Amazon.com, Inc. acts as a cloud infrastructure sub-processor. Data is not intentionally transferred to or processed by unrelated service providers.
5. Security
Access is limited by authentication, least privilege, restricted file permissions, and purpose limitation. Communications with external APIs use TLS 1.2 or higher. API credentials must be protected and rotated when compromise is suspected. Logs are configured to avoid request or response bodies, authorization headers, access tokens, and unnecessary personal data.
6. Personal data rights
Where applicable, individuals may request access, correction, deletion, restriction, portability, or opt-out. Identity and authority will be verified proportionately before action is taken. Requests received from Temu will be handled through Temu's designated authenticated channel. Because the application is not intended to persist consumer personal data beyond authorized temporary processing, a verified search may result in confirmation that no data is held.
7. Security incidents
Suspected or confirmed security incidents are contained, assessed, documented, and escalated promptly. Temu and relevant authorities will be notified when required by contract or applicable law.
8. Changes to this policy
This policy is reviewed when the application's functions, permissions, hosting, or legal obligations change. The effective date above identifies the current version.
9. Contact
Privacy and personal-data rights inquiries: a853549329@163.com.