Ecomfulfill
  • Startseite
  • Leistungen
    • Verpackung & Versand
    • Schnelle Lieferung
    • Beschaffung & Branding
    • Versand beschränkter Artikel
    • Bekleidungs-Fulfillment
  • FAQ
  • Über uns
  • Kontakt

ECOMFULFILL Shopify Apps — Privacy Policy

Last updated: 2026-06-14

This policy describes how ECOMFULFILL handles data for its Shopify apps:

  • ECOMFULFILL Connector — third-party order fulfilment integration.
  • Taobao Dropship — Taobao product sourcing, inventory sync, and supplier-purchase automation.

For our general website privacy and terms see /en/privacy.

1. What data we collect

ECOMFULFILL Connector receives:

  • Shop metadata: shop domain, shop ID, the access token Shopify issues us, the scopes you approved.
  • Orders: order ID, line items, total prices, currency, payment status, fulfilment status, your store's order numbers.
  • Customer data attached to orders: name, email, phone, billing address, shipping address, postal code, city, country. We receive this only for orders you process through our fulfilment; we don't pull customer records that aren't tied to an order.
  • Products and locations: product titles, SKUs, variant data, your store's fulfilment locations. We use these to match orders to the right ECOMFULFILL SKU and the right shipping origin.

Taobao Dropship receives:

  • Shop metadata: shop domain, the access token Shopify issues us, the scopes you approved.
  • Imported products: Shopify product ID and title, the source Taobao item ID and URL, variant snapshot at import time, image URLs.
  • SKU mappings: the link between each Shopify variant and the corresponding Taobao SKU, cost price, supplier name, stock buffer, and reorder thresholds.
  • Shopify orders: order ID, line items, total price, currency, and — when present on the order — customer name and email. We retain these on the order record because they're needed to place the cross-border supplier purchase order on Taobao on your behalf.
  • Restock (purchase) orders: the supplier purchase orders you create through the app, including shipping name / phone / address (the cross-border destination), itemised costs in CNY, tracking number, status.
  • Wallet ledger: balance, transactions, top-up requests, and the screenshots you upload as proof of bank / Alipay / WeChat transfers.
  • AI processing artifacts: the product images and text we send to AI providers (see §5) for title rewriting, material / care / size-chart extraction, and watermark removal. We do not send customer PII to these providers.
  • Activity audit log: a record of actions taken in the app (mapping created, order placed, stock synced, product imported) for your own audit and our debugging.

Neither app collects: storefront browsing data, marketing analytics, abandoned-cart data, app installation activity, or your Shopify admin login.

2. Why we collect it

ECOMFULFILL Connector: to pick, pack, ship and report on your orders through ECOMFULFILL's fulfilment network.

  • Customer name + address: to print the shipping label.
  • Order line items: to pick the right SKUs.
  • Phone + email: for courier delivery contact and dispute resolution.
  • Product / location data: to match to ECOMFULFILL warehouses.

Taobao Dropship: to keep your Taobao-sourced catalogue in sync with Shopify and to automate the supplier purchase when an order arrives.

  • SKU mappings: to convert a Shopify variant sale into the correct Taobao SKU purchase, and to keep stock numbers in sync.
  • Customer name + email on the Shopify order: required by the Taobao supplier for cross-border shipment labelling and customs declaration when you place a restock order.
  • Receipts (S3): to verify your wallet top-up payments for our accounting and audit.
  • AI processing: to rewrite product titles to your locale, extract product attributes from listing photos, and clean watermarks. None of this involves your customers.

3. Where we store it

In our ERP system, hosted on Amazon RDS in AWS us-east-1 (N. Virginia) — Connector uses PostgreSQL, Taobao Dropship uses MySQL. Both databases are in a private VPC subnet with no public network exposure; ingress is allowed only from our application EC2 instance(s) by AWS security group rule. Access is restricted to ECOMFULFILL operations staff on a least-privilege basis. Data at rest is encrypted with AWS KMS-managed keys; data in transit uses TLS 1.2+.

Receipt screenshots uploaded for Taobao Dropship wallet top-ups are stored in a private AWS S3 bucket in us-east-1 with server-side encryption (SSE-S3). Access requires a short-lived pre-signed URL issued to admin staff during a review.

4. How long we keep it

  • Customer PII (name, contact, address): scrubbed within 48 hours of a Shopify customers/redact or shop/redact webhook, or 48 hours after you uninstall the app, whichever comes first.
  • Order-level financial summary (totals, currency, dates, refund status): retained for 5 years for accounting / audit purposes, but with all PII fields nullified — kept only as anonymised transaction records.
  • Shop credentials (access token): deleted within 48 hours of uninstall.
  • SKU mappings, imported products, restock orders, wallet ledger (Taobao Dropship): deleted in full on shop/redact (within 48 hours of uninstall).
  • AI processing artifacts: prompts/responses are not retained by us beyond the immediate request lifecycle; whatever short-term logging the AI provider keeps is governed by their own policy (see §5).

5. Who we share it with

ECOMFULFILL Connector — minimum data necessary to ship your order:

  • Shipping carriers chosen by you (e.g. China Post, Yanwen, ePacket, EUB, your nominated express carriers). Each receives just the shipping address + parcel details for the label.
  • Government customs systems when required for cross-border shipments (the importer-of-record's address, contents, declared value).

Taobao Dropship — required for sourcing and AI features:

  • Taobao / Alimama (the supplier marketplace): when you place a restock order, we send the order's SKUs, quantities, and the cross-border shipping address (name, phone, address) to Taobao's purchase API so the supplier can ship to your customer.
  • Google Gemini: product listing images and titles for AI-assisted title rewriting, material / care / size-chart extraction, and SEO tag suggestions. No customer PII is sent.
  • DeepSeek (optional fallback for some text tasks): same scope as Gemini. No customer PII.
  • Replicate (Florence-2 + LaMa models): product images only, for watermark detection and removal. No customer PII.
  • AWS S3 (our account): storage of merchant-uploaded payment receipts. Not a third-party recipient — same data controller, separate storage tier.

We do not sell your data, share it with advertisers, or use it for any purpose other than operating the app you installed.

6. Your rights

  • Access: request a copy of the data we hold on your customers via Shopify's customers/data_request webhook (we'll send the data to the contact email registered for your shop) or by emailing [email protected].
  • Deletion: trigger a customers/redact request from Shopify, or uninstall the app to trigger shop/redact. Either fully scrubs the data within 48 hours.
  • Correction: contact [email protected].

EU/UK merchants have additional rights under GDPR; California merchants under CCPA; mainland China merchants under PIPL. Email us and we'll honour them.

7. Contact

  • App support / operations: [email protected]
  • Privacy / data questions: [email protected]

8. Changes

We'll update this page when our practices change. Material changes will be announced in-app (via the embedded status page) at least 30 days before they take effect.

Skalieren Sie Ihren Shop heute!

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
  • Allgemeine Geschäftsbedingungen
  • Datenschutz & Richtlinien
Sprache
  • English
  • Deutsch
  • Français
Copyright © Promax Ltd. - 2025