Wenzhou Talos Packaging Co., Ltd.
Privacy Policy
This policy explains what data Wenzhou Talos Packaging Co., Ltd. ("we", "us") collects through the
e-commerce platform APIs we are authorised to use, why we collect it, how we protect it, and how to
have it removed.
- Effective date
- 28 August 2026
- Last updated
- 28 August 2026
- Review cycle
- Reviewed at least every six months, and on any material change
- Contact
- sggtong@gmail.com
1. Who we are
Wenzhou Talos Packaging Co., Ltd. is a manufacturer and seller of packaging products, registered in
Wenzhou, Zhejiang Province, People's Republic of China. We sell our products directly to customers on
e-commerce marketplaces and operate an internal ERP application that connects to those marketplaces
through their official APIs.
- Registered name
- Wenzhou Talos Packaging Co., Ltd. (温州市泰洛斯包装有限公司)
- Business licence
- Unified Social Credit Code 91330327MADMBDL93Q, registered 27 May 2024
- Registered office
- No. 15, Yongqing Alley, Yishan Town, Cangnan County, Wenzhou, Zhejiang Province 325800, People's Republic of China
- Data protection contact
- GUANGTONG SHANGGUAN — sggtong@gmail.com · +86 188 6711 6727
2. What data we collect, and where it comes from
We do not collect data directly from consumers through this website. The data we process is obtained
from e-commerce platforms through their official APIs, for seller accounts that have authorised our
application. This includes:
- Order data — order identifiers, order items, quantities, order status,
shipment status and tracking references.
- Product and inventory data — product identifiers, listing attributes,
prices, and available and inbound inventory quantities.
- Fulfilment data — inbound shipment plans, shipment status and received
quantities.
- Financial data — settlement reports, fees, refunds, reimbursements and
related financial events.
- Account and authorisation data — the identifier of the authorising seller
account and the access tokens issued to our application.
We do not request or retrieve consumer personally identifiable information. We do not
collect buyer names, shipping addresses, telephone numbers or email addresses, and we have not
requested any platform permission that grants access to restricted buyer data.
We do not obtain platform data from any external source other than the platform's own APIs. We do not
use data brokers, scraped datasets or third-party data providers.
3. Why we process it
We process this data solely to operate our own selling business on the authorising accounts. Specific
purposes are:
- Consolidating orders and inventory so our operations team can process and monitor fulfilment.
- Planning replenishment and reconciling shipments received against shipments sent.
- Calculating revenue, expenses and product-level profitability by combining platform financial data
with our own product cost data.
- Producing internal reports on sales trends, order volume, product performance and inventory
turnover to support purchasing and operational decisions.
- Monitoring for operational exceptions such as delayed shipments, low stock or price deviations.
We do not use this data for advertising, profiling or automated decision-making about individuals.
4. Who we share it with
We do not sell platform data, and we do not share it with third parties for their own
purposes. It is accessible only to authorised personnel within our organisation, on a
least-privilege basis determined by job function.
Where an infrastructure or logistics provider necessarily processes data on our behalf in order to
deliver a service to us, that provider is bound by contract to equivalent confidentiality and security
obligations and may not use the data for any other purpose. We disclose such arrangements to the
relevant platform where the platform requires it.
5. Where data is stored
Data is stored and processed in China. Any change to
the physical location of stored data is approved internally and disclosed to affected platform
partners.
6. How long we keep it, and how it is deleted
- We retain platform data only for as long as it is needed for the purposes described in Section 3.
- An authorising seller may withdraw authorisation at any time. Our access ceases immediately, and
that account's data is deleted within 30 days.
- At the end of a contractual relationship with a platform, all collected customer data in our
possession is deleted within 30 days, including from backups on their next rotation.
- We assist platforms and sellers in responding to requests to delete, update or provide data, within
the timeframe the platform specifies.
7. How we protect it
- Encryption in transit — all traffic between our application, our users and
platform APIs is encrypted using TLS.
- Encryption at rest — API credentials and tokens are encrypted using AES-256
before storage; storage volumes are encrypted at the disk level. Encryption keys are held separately
from the data they protect and are rotated on a defined schedule.
- Access control — role-based access with least privilege; administrative
access is protected by multi-factor authentication; access is revoked within 24 hours of a change of
role or departure.
- Isolation — each authorising seller account is held in a logically isolated
tenant; data from one account is not readable from another.
- Network — production services are not exposed directly to the public
internet; administrative interfaces are reachable only over a private, authenticated zero-trust
network.
- Governance — these controls are documented in our Information Security
Policy, which is reviewed at least every six months.
8. Security incidents
We maintain a written incident response plan with defined roles and reporting channels, reviewed at
least every six months. If we detect a security incident involving data belonging to a platform or a
seller, we notify the affected platform and seller within 24 hours of detection,
through the channel that platform specifies, and make any regulatory notification required by law.
As at the last update of this policy, we have not experienced any security breach leading to the
accidental or unlawful exposure of personal data, and we have received no complaint or notice from any
data protection or regulatory authority.
9. Your rights
If you believe we hold data relating to you, or you are a seller or platform seeking the deletion,
correction or provision of data we hold, contact us at
sggtong@gmail.com. We will acknowledge your request and respond
within 30 days, or sooner where a platform or applicable law requires it.
Depending on where you are located, you may also have the right to lodge a complaint with your local
data protection authority.
10. Changes to this policy
We review this policy at least every six months and update it whenever our practices, systems or
obligations change materially. The effective date and last-updated date at the top of this page always
reflect the current version. Where a change materially affects an authorising seller or platform
partner, we notify them directly.
11. Contact
- Data protection contact
- GUANGTONG SHANGGUAN, Chief Executive Officer
- Email
- sggtong@gmail.com
- Telephone
- +86 188 6711 6727
- Postal address
- No. 15, Yongqing Alley, Yishan Town, Cangnan County, Wenzhou, Zhejiang Province 325800, People's Republic of China