Privacy Policy

CIEL TERRE takes user privacy seriously. This policy explains how we collect, use, share, and protect personal information, particularly personally identifiable information (PII) relating to Amazon sellers and their customers. We commit to complying with applicable privacy laws, including the laws of the People's Republic of China, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), as well as Amazon SP-API privacy and security requirements.

This website, including http://vmrsaas.com and its subdomains, respects and protects the privacy of its users. To provide more accurate and personalized services, including online ordering, order fulfillment and shipping, and online order processing, we collect, use, and disclose information as described in this policy. We handle that information with care. Except as provided here, we do not disclose it to third parties without your prior permission. We may update this policy from time to time. The website is developed and maintained by CIEL TERRE Questions may be sent to support@vmrsaas.com.

1. Information We Collect

(a) Personal registration information you provide when creating an account on this website;

(b) Browser and device information automatically received when you use our services or visit our pages, including IP address, browser type, language, access time, device and software characteristics, and pages requested;

(c) Customer information you provide to a store operator at registration, and recipient details maintained in the store or included in orders;

(d) Personal information entered when your company registers internal user accounts; and

(e) Personal data obtained lawfully from business partners.

When working with Amazon sellers through Amazon SP-API, we may process seller account details, order data, and buyer contact information such as name, shipping address, and telephone number. We follow Amazon's API data access rules and do not collect, store, or process PII unrelated to the service.

1. Sharing

We do not share your information with other organizations or individuals except in the following cases:

1) With your explicit consent: We may share information with another party after receiving your explicit consent;

2) When required by law: We may share information under applicable laws, for litigation or arbitration, or in response to lawful requests from administrative or judicial authorities;

3) We require recipients of shared information to enter into confidentiality and information-protection agreements and handle the data according to our instructions, this policy, and applicable security measures.

2. Transfers

We do not transfer your information to other companies, organizations, or individuals except as follows:

1) With your explicit consent: We may transfer information to another party after receiving your explicit consent;

2) In a merger or acquisition involving another legal entity, we will require the new holder of your information to continue complying with this policy. Otherwise, the new holder must seek your consent again.

3. Exceptions to Prior Consent for Sharing or Transfers

Your prior consent is not required for sharing, transferring, or publicly disclosing information in the following circumstances:

1) Matters relating to national or defense security;

2) Matters relating to public safety, public health, or significant public interests;

3) Criminal investigation, prosecution, trial, or enforcement of judgments;

4) Protection of your or another person's life, property, or other significant lawful interests when consent is difficult to obtain;

5) Personal information you have made public yourself; or

6) Information collected from lawful public sources, such as news reports or government disclosures.

The personal information we collect may include:

• Identification details: name, email address, phone number, etc.

• Account details: username, password, login logs, etc.

• Transaction details: orders, payments, etc.

• Device details: IP address, device type, operating system, browser, etc.

• Location: we may collect location information with your consent.

• Other information you voluntarily provide when using our services.

2. How We Use Information

(a) We do not provide, sell, rent, share, or trade your personal information with unrelated third parties unless you give prior permission or those parties provide services to you independently or jointly with this website or its affiliates. For example, we may provide order details to warehouse and logistics partners for fulfillment, or, with your authorization, to third-party software providers for order processing.

(b) We do not permit third parties to collect, alter, sell, or distribute your personal information without payment. We may terminate a platform user's service agreement immediately if such conduct is discovered.

(c) To serve users, we may use your information to send you material that may interest you, including product and service updates.

We use personal information obtained from Amazon only for:

• Providing Amazon seller services, including order processing, fulfillment management, and financial reporting.

• Sharing order information, including buyer PII, with logistics and third-party warehouse partners only when necessary to fulfill and deliver orders.

• Collecting, processing, and using only the order data necessary under Amazon's requirements and not using it for unrelated purposes.

• Processing your data in a lawful and secure environment in accordance with Amazon API security and privacy requirements.

3. Legal Bases and Disclosures

We may disclose all or part of your personal information with your consent or as permitted by law in the following cases:

(a) Disclosure to a third party with your prior consent;

(b) Sharing necessary to provide products or services you request;

(c) Disclosure under applicable law or at the request of an administrative or judicial authority;

(d) Disclosure required because you violate Chinese law, this website's service agreement, or related rules;

(e) If a party to a transaction on the platform has fulfilled or partly fulfilled its obligations and requests disclosure, we may provide necessary details, such as the other party's contact information, to help complete the transaction or resolve a dispute; or

(f) Other disclosures we consider appropriate under law, regulation, or website policy.

We process personal information on the following bases:

• Explicit consent: in most cases, we seek your explicit consent.

• Contract performance: to provide services you request.

• Legitimate interests: to protect our lawful interests without harming your rights.

• Legal obligations: to comply with laws and regulations.

4. Your Data Rights

Information collected about you is stored on servers operated by this website or its affiliates. It may be transferred outside your country or the place where it was collected, and accessed, stored, or displayed there.

You have the right to:

• Access your personal information

• Correct inaccurate personal information

• Delete your personal information

• Restrict processing of your personal information

• Data portability

• Object to processing

Authorization and Data Access Limits

To use the platform, sellers must grant the API access needed for our services. We request permissions only for order processing, inventory management, shipment tracking, and reporting, and do not seek access beyond the service scope.

Revoking access: Sellers may review or change their API authorization and request the revocation of all or part of it at any time.

You may review, change, or revoke granted API permissions on our API management page at any time. Changes or revocations take effect within 24 hours; we will delete or stop accessing the relevant data accordingly.

5. Data Security

(a) Website accounts include security protections. Please keep your username and password safe. We use measures such as password encryption to protect information from loss, misuse, or alteration, although no security measure on the internet is perfect.

(b) In using our services, you may need to disclose contact details or postal addresses to partners such as carriers and overseas warehouses. Please protect your information and provide it only when necessary.

Whenever data is shared with a third party, such as a logistics or accounting provider, we use contractual safeguards and data processing agreements (DPAs) to require the same privacy and security standards.

We use technical and organizational measures to protect personal information, including:

• Encryption: Sensitive data transmitted through Amazon SP-API, including buyer PII, is protected using AES-256 encryption and secured in storage.

• Access control: Only authorized staff and partners may access Amazon seller or buyer personal data. Access is reviewed and limited to the minimum necessary.

• Reviews and monitoring: We scan systems regularly, monitor for potential threats, and remediate vulnerabilities when needed.

• Incident response: In the event of a data breach, we will activate our response plan immediately and notify affected users and relevant regulators within 24 hours, following Amazon's reporting requirements.

1. Data you process, store, upload, download, distribute, or otherwise handle through CIEL TERRE services is your business data, which you own. As a cloud service provider, we process it under your instructions and do not use or disclose it without authorization except as agreed with you or required by law.

2. You are responsible for the source and content of your business data. Please assess its legality carefully. You bear responsibility for consequences arising from data that violates laws, regulations, departmental rules, or national policy.

3. To improve service quality and offer new products and services, CIEL TERRE analyzes transaction, process, and order data within its products and shares this business data, excluding sensitive information, with its affiliates.

Data Access Permissions

We minimize access permissions to protect data security and privacy.

• Administrator role: Only administrators may view, change, or delete sensitive data, such as customer PII and order history. All such actions require two-factor authentication and are logged internally.

• Staff role: Staff may view only order and shipping data relevant to their duties, not buyer PII or account information.

• API permissions: We follow Amazon SP-API rules, limit access to sensitive data to service needs such as order processing and logistics fulfillment, and review permissions regularly.

• System access and data actions are logged. We review sensitive data access regularly to maintain least-privilege permissions and prevent unauthorized access.

• Every Amazon API call is logged with the caller's identity, the request type, and the time.

• We review permissions internally each quarter for compliance with Amazon requirements and remove unnecessary access.

6. Data Retention

We retain personal information only as necessary and follow the data-minimization principle. When it is no longer needed for the stated purposes, we take reasonable steps to delete or anonymize it.

You may request access to, correction of, or deletion of your data at any time through the system administration interface or customer support.

For requests to delete or change Amazon buyer PII, we first verify your identity and ensure compliance with Amazon API data-handling rules. We will complete the data operation within 30 business days of receiving the request and provide a record and confirmation of the change.

7. Cross-Border Data Transfers

Information collected about you is stored on servers operated by this website or its affiliates. It may be transferred outside your country or the place where it was collected, and accessed, stored, or displayed there.

We may transfer data obtained through Amazon SP-API to servers in other countries or regions for processing. For any cross-border transfer, we follow relevant data protection laws and apply safeguards such as encryption and data protection agreements.

8. Privacy Impact Assessments (PIA)

We store, transfer, and use collected information in accordance with the rules where it is stored. Personal information in orders, primarily recipient details, is deleted within one month of order completion, and total retention does not exceed three months. Personal information of users, including internal users and external customers, is deleted within one month of account closure.

Before processing activities that may involve large amounts of Amazon seller or buyer personal information, we conduct a privacy impact assessment (PIA) to evaluate privacy risks and compliance with relevant GDPR and CCPA provisions.

9. Cookies

We use cookies to collect information and improve our services. You can manage cookies through your browser settings.

10. Children's Privacy

1. Our products and services are intended primarily for adults. If you are a minor, please ask a parent or guardian to read this policy and obtain their consent before using our services or providing information.

2. If we collect information about a minor using our services with parental or guardian consent, we use, share, transfer, or disclose it only when permitted by law, explicitly consented to by the parent or guardian, or necessary to protect the minor.

11. Changes to This Policy

We may update this policy. When terms change, we will present the updated policy through website notices, push notifications, or pop-ups when you sign in or the version is updated. Continued use of CIEL TERRE services is treated as acceptance of the updated policy.

12. Contact Us

For questions about this policy, contact support@vmrsaas.com. We will reply within 10 business days of receiving your message.

13. Complaints

If you are dissatisfied with how we handle personal information, you may complain to your local data protection authority.

Important Notices:

• This policy may be updated when laws or regulations change. Please refer to the latest version.

• This policy applies only to CIEL TERRE services, not to third-party websites or applications.