01 / SCOPE & OPERATING ENTITIES

前言与主体架构Scope & Operating Entities

本隐私政策阐明了 GP Fulfillment Store Cloner(以下简称“应用”或“我们”)如何处理通过 Chrome 浏览器扩展及后台服务收集的信息。本应用由 PGS Tech Limited (Gray Poplar) 开发并运营,注册地址位于中国香港与中国深圳。应用专门为独立站商户提供商品一键同步、AI 文案重构、商标合规检测与仓储代发自动化服务。This Privacy Policy outlines how GP Fulfillment Store Cloner ("the App", "we", "us") processes information gathered through our Chrome Extension and associated back-end services. Developed and operated by PGS Tech Limited (Gray Poplar) with operations in Hong Kong and Shenzhen, the App provides 1-click catalog synchronization, AI paraphrasing, trademark compliance screening, and automated fulfillment routing for Shopify e-commerce merchants.

02 / ZERO-CLOUD ARCHITECTURE

零云端留存与纯本地化架构Zero-Cloud & Client-Side Architecture

我们恪守数据最小化(Data Minimization)零云端私密化(Client-Side Privacy)原则。我们绝不建立中心化数据库上传、转储或出售商户及消费者的任何私密商业数据。We adhere strictly to Data Minimization and Client-Side Privacy principles. We NEVER build centralized cloud databases to upload, store, sell, or share merchant or customer catalog data.

在扩展运行过程中,所有解析的商品标题、变体属性、价格矩阵与配图 URL 均完全运行在商户本地浏览器的沙盒环境中(Chrome Local Storage / IndexedDB),不经过任何第三方服务器中转。During operation, all parsed product titles, options matrices, pricing data, and image URLs execute entirely within your browser's local sandbox (Chrome Local Storage / IndexedDB) without passing through intermediary scraping servers.

03 / DATA COLLECTION CATEGORIES

数据收集分类与处理用途明细Data Collection Categories & Processing Purposes

下表详细列出了应用在不同运行场景下处理的数据类别、存储介质及用途:The following table itemizes all data categories processed by the App, their storage location, and processing purposes:

数据类别Data Category 存储载体Storage Location 保留期限Retention Period 处理用途Processing Purpose
商品数据与变体矩阵Catalog & Variant Data Chrome LocalStorage / 内存Chrome LocalStorage / RAM 本地保留,直至清空缓存Until cache manual wipe 展示同步暂存队列,向 Shopify 推送Render staging queue for Shopify push
Shopify OAuth 凭证Shopify OAuth Tokens 本地加密 Chrome StorageEncrypted Chrome Storage 凭证有效期间Active token lifetime 调用 Shopify 官方 API 写入商品Authenticate direct REST/GraphQL API calls
AI 优化与商标比对词AI & Trademark Cache 本地浏览器沙盒Local Browser Sandbox 临时会话期间Session duration 商标敏感词扫描与文本重构Execute pre-listing compliance checks
仓储 WMS 绑定 SKUWarehouse WMS Mappings GPF 代发系统加密通信Encrypted WMS Payload 订单履约期间Order lifecycle duration 自动分发订单至深圳/香港仓拣货Route order picks to Shenzhen/HK warehouse
04 / OAUTH CREDENTIALS & SECURITY

OAuth 凭证安全与 TLS 直连传输加密OAuth Credentials & TLS Direct Transit

应用使用行业标准的最高安全规范保障与 Shopify 平台的数据交互:We enforce rigorous security standards for all interactions with the Shopify platform:

  • 零密码索取:Zero Password Access: 应用绝不索取或储存商户的 Shopify 登录密码,所有连接均通过 Shopify 官方 OAuth 2.0 授权机制完成。 The App never requests or stores merchant passwords. Connections execute exclusively via official Shopify OAuth 2.0.
  • 短期访问凭证(Expiring Tokens):Short-Lived Access Tokens: 支持并全面对接 Shopify 自动过期 Access Token 规则,本地存储附带安全失效逻辑,防止长期静态凭证风险。 Supports Shopify expiring access tokens, implementing automatic token lifecycle cleanup within extension storage.
  • TLS 1.3 直连加密:TLS 1.3 Direct Transit: 所有 API 请求直接由商户浏览器向 https://YOUR-STORE.myshopify.com/admin/api 发起,全程采用 TLS 1.3 强加密,无中间节点拦截。 API calls transmit directly from your browser to Shopify's admin API using TLS 1.3 encryption without proxy interception.
05 / GDPR & CCPA COMPLIANCE

GDPR、CCPA 与国际数据主体权益GDPR, CCPA & International Data Rights

我们全面符合欧盟《通用数据保护条例》(GDPR)及加州《消费者隐私法案》(CCPA/CPRA)的合规要求:We fully respect international privacy mandates under GDPR (EU) and CCPA/CPRA (California):

  • 知情权与访问权 (Right of Access):Right of Access: 由于所有暂存数据均存放在本地,您可在扩展控制台随时查阅所有缓存商品。All data resides locally in browser sandbox for immediate audit.
  • 被遗忘权与擦除权 (Right to Erasure):Right to Erasure: 您可随时一键清空扩展暂存队列,或卸载插件以立即抹除所有本地记录。Wipe staging cache anytime or uninstall extension to purge files instantly.
  • 拒绝数据销售 (Do Not Sell My Info):Do Not Sell My Info: 我们从不出售、租赁或以任何对价向第三方转让任何商户数据。We never sell, rent, or monetize merchant data.
06 / DELETION & REMOVAL POLICY

数据擦除与卸载清空政策Data Deletion & Extension Removal

卸载与数据永久擦除:Uninstall & Permanent Data Wipe: 由于应用不设云端数据存储,当您从 Chrome 浏览器卸载或移除本插件时,保存在本地的所有商品缓存、店铺连接凭证及设置项将被 Chrome 浏览器自动且不可逆地彻底清空。 Uninstalling or removing this extension from Chrome permanently and irreversibly wipes all locally stored catalog caches, tokens, and settings.

07 / THIRD-PARTY INTEGRATIONS

第三方服务集成与 CDN 节点Third-Party Integrations & CDN Processing

在商品图片同步与托管过程中,应用仅与公认的合规基础设施交互:During catalog media processing, the App interacts solely with verified infrastructure providers:

  • Shopify CDN:Shopify CDN: 抓取的高清商品图在同步时,由 Shopify 官方 CDN 服务器进行托管与加载分发。Product images host directly on official Shopify CDN servers during sync.
  • Google Cloud / Cloudflare:Google Cloud / Cloudflare: 静态网页资源与全局 SSL 证书由 Cloudflare 与 Google Cloud 节点安全加密加速。Static website assets and SSL connections are protected by Cloudflare & Google Cloud.
08 / COOKIES & STORAGE

Cookie 与本地存储技术说明Cookies & Browser Storage Technologies

应用使用 Chrome 扩展底层的 LocalStorage 和 SessionStorage 仅用于保存商户界面语言偏好(中文/英文)、加价倍数模板及当前暂存队列,不使用任何追踪性第三方 Advertising Cookies。The App utilizes standard Chrome LocalStorage and SessionStorage solely to store interface language toggles, pricing multiplier templates, and current staging queues. No third-party ad tracking cookies are deployed.

09 / COMMERCIAL SCOPE

商业适用范围与未成年人保护Commercial Scope & Children's Privacy

本应用属于纯 B2B 商业软件,专门面向具有完全民事行为能力的独立站电商从业者。我们不面向 16 岁以下的未成年人提供服务,亦不主动收集任何未成年人个人信息。The App is a dedicated B2B enterprise software designed exclusively for adult e-commerce merchants. We do not offer services to or knowingly collect personal information from individuals under the age of 16.

10 / CONTACT INFORMATION

官方联系方式与监管通知Contact Information & Regulatory Notices

如您对本隐私政策、数据安全或合规保障有任何疑问,欢迎通过以下官方渠道联系 Gray Poplar 技术与法务团队:For inquiries concerning privacy policies, security audits, or compliance validation, contact the Gray Poplar legal team:

  • Email: contact@gp-fulfillment.com
  • WhatsApp Support: +852 6250 8059
  • Shenzhen Office: 28/F, 168 Fuhua 3rd Road, Futian District, Shenzhen, China
  • Hong Kong Office: 2/F, 204-210 Texaco Road, Tsuen Wan, Hong Kong