隐私政策Privacy Policy
这份政策说明纵途(Journeyor)在你使用我们的网站和 ERP 服务时,如何收集、使用、保存和保护信息。我们尽量用平实的话写,有不清楚的地方欢迎来信。This policy explains how Journeyor collects, uses, stores and protects information when you use our website and ERP service. We've tried to write it in plain language; if anything is unclear, write to us.
1. 适用范围
本政策适用于网站 journeyor.com 及其子域名,以及我们提供的 ERP 服务(通过 erp.journeyor.com 或我们指定的其他地址访问,下称「服务」)。
服务面向企业客户(亚马逊卖家及其团队)。就你店铺的业务数据和其中包含的买家个人信息而言,你是数据的控制者,我们按你的指示处理这些数据;就你和团队成员的登录账号信息而言,我们是控制者。
2. 我们处理的信息
2.1 账号信息
你或你的管理员为团队成员开通账号时,我们记录:姓名或昵称、登录账号、密码(仅保存不可逆的加密散列,我们看不到原密码)、角色与权限、是否开启两步验证及其密钥(加密保存)、登录时间与来源 IP、登录失败记录。
2.2 店铺业务数据(来自亚马逊)
在你授权后,我们通过亚马逊官方的 Selling Partner API 和 Amazon Ads API 获取并处理你店铺的数据,包括:订单与订单项、结算与财务交易、库存与 FBA 报表、货件、商品目录、退货与退款、多渠道配送(MCF)订单,以及广告组合、活动、广告组、投放与其绩效数据。我们只获取服务功能所需、且你授权范围内的数据。
2.3 买家个人信息
部分功能会涉及你的买家(即亚马逊顾客)的个人信息,例如订单中的收件人姓名、地址、电话,以及售后沟通中的买家信息。我们仅在履约、售后、退货处理等你明确使用的功能所必需的范围内处理这些信息,并按第 4 条和第 6 条的规定限制保存期限。
2.4 邮箱数据(仅在你接入邮箱时)
如果你选择把店铺客服邮箱接入服务(例如通过 Gmail API),我们会读取该邮箱中的邮件以识别和处理售后请求,并在你操作时代你发送回复。我们不会读取与服务无关的邮件内容用于其他目的。你可以随时在邮箱账号的安全设置中撤销授权。
2.5 你录入的数据
你在服务中手工录入的采购、物流、成本、现金流、客户档案等业务记录与上传的凭证文件。
2.6 技术信息
为了保障服务正常运行与安全,我们记录服务器访问日志(请求时间、路径、来源 IP、浏览器类型)和错误日志。日志中不写入买家个人信息。
2.7 我们不收集的信息
我们不收集你的亚马逊账号密码、支付卡号、银行账号密码。本网站不使用任何广告追踪或第三方分析脚本。
3. 用途
- 向你提供服务的全部功能:多店铺管理、利润与现金流核算、广告管理、库存与货件、MCF 配送、售后与退货。
- 身份验证、权限控制、安全防护(如异常登录锁定)。
- 按你的请求提供技术支持。只有在你明确要求我们协助排查问题时,我们的人员才会查看你的业务数据,且仅限解决该问题所需的范围。
- 服务运行所需的备份、监控与故障恢复。
- 遵守法律义务。
我们不会出售你的数据,不会将你的店铺数据用于向你或他人投放广告,不会用它分析你的竞争对手或与其他客户的数据合并分析,也不会用它训练通用的人工智能模型。
如果你开启了售后邮件的智能分类功能,相关邮件内容会发送给我们合同约束下的 AI 服务提供商进行一次性处理,我们要求其不得保留内容或用于训练。
4. 对亚马逊数据的特别承诺
作为亚马逊 Selling Partner API 的注册开发者,我们受亚马逊《可接受使用政策》和《数据保护政策》约束。针对通过亚马逊 API 获取的信息(下称「亚马逊信息」),我们承诺:
- 目的限制:仅为向你提供你所授权的服务功能而使用亚马逊信息,不用于任何其他目的。
- 最小化:只请求功能所需的 API 权限角色和数据字段。
- 加密:亚马逊信息在传输中使用 TLS 加密,在存储中加密,加密密钥与数据分开保管并限制访问。
- 买家个人信息的保存期限:订单中的买家个人信息在订单完成(送达或关闭)后最多保存 30 天,期满自动删除,除非法律要求更长的保存期(例如税务或会计凭证),在此情形下仅保留法律要求的部分并同样加密保护。
- 不写入日志:买家个人信息不出现在日志、报错信息或调试输出中。
- 访问控制:只有被授权的、有业务需要的人员才能访问生产系统,所有访问均经身份验证并记录日志。
- 不共享:除第 5 条所列为提供服务所必需的子处理者外,不与任何第三方共享亚马逊信息。
- 安全事件通知:如发生涉及亚马逊信息的安全事件,我们将在发现后 24 小时内通知亚马逊,并及时通知受影响的你。
- 撤销授权后的删除:你在亚马逊卖家后台撤销授权或终止服务后,我们按第 6 条的期限删除相关亚马逊信息,并可在删除前按你的请求导出。
5. 第三方服务(子处理者)
为提供服务,我们使用以下第三方服务。它们只能在为我们提供服务所必需的范围内处理数据,并受合同或其服务条款约束。
| 服务 | 用途 | 涉及的数据 |
|---|---|---|
| 腾讯云(服务器与网络) | 托管服务、存储数据与备份 | 全部服务数据(加密存储) |
| Amazon(Selling Partner API、Amazon Ads API) | 按你的授权获取店铺数据、创建 MCF 订单与广告 | 店铺业务数据、买家个人信息 |
| Google(Gmail API,仅在你接入邮箱时) | 读取与发送售后邮件 | 邮件内容与收发件人 |
| 地址校验服务(如美国邮政 USPS 地址 API) | 在创建 MCF 订单时校验收件地址 | 收件地址(不含姓名以外的其他信息) |
| AI 服务提供商(仅在开启邮件智能分类时) | 对售后邮件做一次性分类 | 邮件文本 |
我们不会向上述以外的第三方出售、出租或提供你的数据,除非法律要求、为保护我们或他人的合法权益所必需,或经你明确同意。
6. 保存期限
| 数据 | 保存期限 |
|---|---|
| 账号信息 | 账号存续期间;账号删除或服务终止后 30 天内删除 |
| 店铺业务数据、你录入的记录 | 服务存续期间;撤销授权或服务终止后 30 天内删除(期间可申请导出) |
| 买家个人信息 | 订单完成后最多 30 天,自动删除(法律要求的除外) |
| 邮箱数据 | 服务存续期间;撤销邮箱授权后 30 天内删除 |
| 访问与安全日志 | 不少于 90 天、不超过 12 个月 |
| 备份 | 随主数据的删除在最多 35 天内滚动过期 |
7. 安全措施
- 浏览器到服务器全程 HTTPS(TLS 1.2 及以上),证书自动更新。
- 数据与备份加密存储;密码只保存加盐散列;两步验证密钥加密保存。
- 账号密码登录,支持基于验证器 App 的两步验证;连续登录失败自动锁定;会话有有效期并可由管理员随时终止。
- 按店铺、按功能板块的最小权限控制;每家店铺的数据相互隔离。
- 操作审计日志与访问日志,定期审查。
- 服务器仅开放必要端口,管理访问使用密钥认证并限制来源。
- 人员离职或角色变更时及时撤销权限。
- 制定并演练安全事件响应流程。
没有任何系统能保证绝对安全。请你也保护好自己的登录凭据,为所有账号开启两步验证,并及时移除离开团队的成员。
8. 你的权利
你可以随时:
- 访问与导出:查看服务中的数据,或要求我们导出一份副本(常用格式,如 CSV / JSON)。
- 更正:更正不准确的账号或业务信息。
- 删除:要求删除你的账号、店铺数据或全部数据。
- 撤销授权:在亚马逊卖家后台「管理你的应用」中撤销对纵途的授权;在 Google 账号的安全设置中撤销邮箱授权。
- 投诉:向你所在地的数据保护监管机构投诉。
请把请求发到本页顶部的邮箱并注明「数据请求」。我们会先核实你的身份,并在 30 天内完成处理。如果你是某位亚马逊买家,对你个人信息的处理由相应卖家决定,请直接联系该卖家,我们会协助其完成你的请求。
9. Google 用户数据
如果你把 Gmail 邮箱接入服务,我们对通过 Google API 获取的信息的使用和向其他应用的转移,将遵守 Google API 服务用户数据政策,包括其「有限使用」(Limited Use)要求。具体而言:我们只用邮件数据提供你可见的售后处理功能;不用于投放广告;除为提供该功能所必需的处理、经你同意、为安全目的或法律要求外,不向他人转移;人员不会阅读邮件内容,除非你明确要求协助、为安全目的或法律要求。
10. Cookie
本网站只使用一个用于记住你所选语言的本地存储项。ERP 服务使用一个登录会话 Cookie(HttpOnly、仅 HTTPS)以维持登录状态,以及少量用于记住你的界面偏好(如列宽、筛选条件)的本地存储项。我们不使用广告 Cookie,不使用第三方追踪脚本。
11. 跨境传输
我们的服务器位于 。你的数据会在亚马逊、Google 等服务提供商所在地(主要是美国)与我们的服务器之间传输。我们通过加密传输和本政策所述的保护措施保障这些传输的安全。
12. 未成年人
服务面向企业用户,不面向 18 岁以下的个人。我们不会有意收集未成年人的个人信息。
13. 本政策的变更
我们可能随服务或法律的变化更新本政策。重大变更会在服务内或通过邮件提前通知你。更新后的政策以页面顶部标注的「最后更新」日期为准。
14. 联系我们
1. Scope
This policy applies to the website journeyor.com and its subdomains, and to the ERP service we provide (accessed at erp.journeyor.com or another address we designate; the “Service”).
The Service is for business customers — Amazon sellers and their teams. For your store's business data and any buyer personal information it contains, you are the data controller and we process that data on your instructions; for the login account information of you and your team members, we are the controller.
2. Information we process
2.1 Account information
When you or your administrator opens an account for a team member we record: name or nickname, username, password (stored only as an irreversible salted hash — we cannot see the original), role and permissions, whether two-factor authentication is enabled and its secret (stored encrypted), login times and source IP addresses, and failed login attempts.
2.2 Store business data (from Amazon)
Once you authorize us, we retrieve and process your store's data through Amazon's official Selling Partner API and Amazon Ads API, including: orders and order items, settlements and financial transactions, inventory and FBA reports, shipments, catalog listings, returns and refunds, multi-channel fulfillment (MCF) orders, and advertising portfolios, campaigns, ad groups, targets and their performance data. We retrieve only data the Service's features need and that falls within the scope you authorized.
2.3 Buyer personal information
Some features involve personal information of your buyers (Amazon customers), such as the recipient name, address and phone number on an order, or buyer details in after-sales correspondence. We process this information only to the extent necessary for the fulfillment, after-sales and returns features you actively use, and limit its retention as set out in Sections 4 and 6.
2.4 Mailbox data (only if you connect a mailbox)
If you choose to connect your store's support mailbox to the Service (for example via the Gmail API), we read messages in that mailbox to identify and handle after-sales requests and send replies on your behalf when you instruct us to. We do not read mail unrelated to the Service for any other purpose. You can revoke this access at any time in your mailbox account's security settings.
2.5 Data you enter
Business records you enter manually — purchasing, logistics, costs, cash flow, customer records — and supporting documents you upload.
2.6 Technical information
To keep the Service running and secure we keep server access logs (request time, path, source IP, browser type) and error logs. Buyer personal information is never written to logs.
2.7 What we do not collect
We do not collect your Amazon account password, payment card numbers or bank credentials. This website uses no advertising trackers or third-party analytics scripts.
3. How we use it
- To provide every feature of the Service: multi-store management, profit and cash-flow accounting, advertising management, inventory and shipments, MCF fulfillment, after-sales and returns.
- Authentication, permission control and security protection (such as lockout after abnormal login attempts).
- Technical support at your request. Our staff view your business data only when you explicitly ask us to help investigate an issue, and only to the extent needed to resolve it.
- Backups, monitoring and recovery needed to operate the Service.
- Compliance with legal obligations.
We do not sell your data, use your store data to advertise to you or anyone else, use it to analyze your competitors or combine it with other customers' data for analysis, or use it to train general-purpose AI models.
If you enable smart classification of after-sales email, the relevant message content is sent to an AI service provider bound by contract with us for one-time processing; we require that it neither retain the content nor use it for training.
4. Commitments for Amazon data
As a registered Selling Partner API developer we are bound by Amazon's Acceptable Use Policy and Data Protection Policy. For information obtained through Amazon's APIs (“Amazon Information”) we commit to the following:
- Purpose limitation: Amazon Information is used solely to provide the Service features you authorized, and for no other purpose.
- Minimization: we request only the API roles and data fields the features require.
- Encryption: Amazon Information is encrypted in transit with TLS and encrypted at rest; encryption keys are stored separately from the data with restricted access.
- Retention of buyer personal information: buyer personal information on an order is kept for no more than 30 days after the order is completed (delivered or closed) and then deleted automatically, unless the law requires a longer period (for example tax or accounting records), in which case only the legally required portion is retained, still encrypted.
- No logging: buyer personal information does not appear in logs, error messages or debug output.
- Access control: only authorized personnel with a business need can access production systems; all access is authenticated and logged.
- No sharing: Amazon Information is not shared with any third party other than the sub-processors listed in Section 5 that are necessary to provide the Service.
- Incident notification: if a security incident involving Amazon Information occurs, we notify Amazon within 24 hours of discovery and notify you promptly if you are affected.
- Deletion after revocation: when you revoke authorization in Seller Central or terminate the Service, we delete the related Amazon Information within the periods in Section 6, and can export it for you first on request.
5. Third-party services (sub-processors)
We use the following third-party services to provide the Service. Each may process data only to the extent necessary to provide its service to us and is bound by contract or its terms of service.
| Service | Purpose | Data involved |
|---|---|---|
| Tencent Cloud (servers and network) | Hosting the Service, storing data and backups | All Service data (encrypted at rest) |
| Amazon (Selling Partner API, Amazon Ads API) | Retrieving store data, creating MCF orders and ads as you authorize | Store business data, buyer personal information |
| Google (Gmail API, only if you connect a mailbox) | Reading and sending after-sales email | Message content, senders and recipients |
| Address verification (e.g. the USPS Addresses API) | Verifying the recipient address when creating an MCF order | Shipping address only |
| AI service provider (only if smart email classification is enabled) | One-time classification of after-sales email | Message text |
We do not sell, rent or provide your data to third parties beyond those listed, except where required by law, necessary to protect our or others' legal rights, or with your explicit consent.
6. Retention
| Data | Retention |
|---|---|
| Account information | While the account exists; deleted within 30 days after account deletion or termination |
| Store business data and records you entered | For the duration of the Service; deleted within 30 days after revocation or termination (export available during that time) |
| Buyer personal information | No more than 30 days after order completion, deleted automatically (except where the law requires otherwise) |
| Mailbox data | For the duration of the Service; deleted within 30 days after mailbox access is revoked |
| Access and security logs | At least 90 days and no more than 12 months |
| Backups | Expire on a rolling basis within at most 35 days of the primary data's deletion |
7. Security
- HTTPS (TLS 1.2 or higher) from browser to server, with certificates renewed automatically.
- Data and backups encrypted at rest; passwords stored only as salted hashes; two-factor secrets stored encrypted.
- Username/password login with authenticator-app two-factor authentication; automatic lockout after repeated failures; sessions expire and can be terminated by an administrator at any time.
- Least-privilege permissions per store and per module; each store's data isolated from the others.
- Audit and access logs, reviewed regularly.
- Servers expose only necessary ports; administrative access uses key-based authentication and source restrictions.
- Permissions revoked promptly when staff leave or change roles.
- A documented and rehearsed security-incident response process.
No system can be guaranteed to be completely secure. Please protect your own credentials, enable two-factor authentication on every account, and remove team members promptly when they leave.
8. Your rights
At any time you may:
- Access and export: view your data in the Service, or ask us for a copy in a common format (such as CSV or JSON).
- Correct: correct inaccurate account or business information.
- Delete: ask us to delete your account, your store data or all of your data.
- Revoke: revoke Journeyor's authorization under “Manage your apps” in Seller Central; revoke mailbox access in your Google account's security settings.
- Complain: lodge a complaint with the data-protection authority where you are located.
Send requests to the email address at the top of this page with “Data request” in the subject. We will verify your identity first and complete the request within 30 days. If you are an Amazon buyer, the processing of your personal information is decided by the seller concerned; please contact that seller directly, and we will assist them in fulfilling your request.
9. Google user data
If you connect a Gmail mailbox to the Service, Journeyor's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use mailbox data only to provide the user-facing after-sales features; we do not use it for advertising; we do not transfer it to others except as necessary to provide those features, with your consent, for security purposes or to comply with the law; and humans do not read message content unless you explicitly ask for help, for security purposes or as required by law.
10. Cookies
This website uses a single local-storage item to remember your language choice. The ERP Service uses one login session cookie (HttpOnly, HTTPS-only) to keep you signed in, plus a few local-storage items that remember interface preferences such as column widths and filters. We use no advertising cookies and no third-party tracking scripts.
11. International transfers
Our servers are located in . Your data travels between our servers and the locations of service providers such as Amazon and Google (primarily the United States). We protect these transfers with encryption in transit and the safeguards described in this policy.
12. Children
The Service is for business users and is not directed at individuals under 18. We do not knowingly collect personal information from minors.
13. Changes to this policy
We may update this policy as the Service or the law changes. We will give advance notice of material changes in the Service or by email. The version in effect is the one with the “Last updated” date shown at the top of this page.