Below is a comprehensive Privacy Policy tailored for your cross-border e-commerce business, incorporating global compliance standards (GDPR, CCPA, PIPL, etc.) and industry-specific requirements. This template covers critical elements for data handling, user rights, security protocols, and cross-border operations.
PRIVACY POLICY OF [YUZHU Trading]
Effective Date: [2025.07.07]
Last Updated: [2025.07.15]
1. INTRODUCTION
We, [YUZHU Trading Co, LTD] ("we," "us," or "our"), operate the website [yztra.com] and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our Service. By accessing the Service, you consent to the practices described herein.
Scope: This policy applies to all users globally, with specific provisions for the EU/EEA, UK, California, and other regulated jurisdictions .
2. DATA WE COLLECT
A. Directly Provided Data
- Identity & Contact Details: Name, email, phone number, shipping/billing address.
- Payment Information: Credit card details (processed by third-party gateways like Stripe/PayPal), transaction history .
- Account Credentials: Username, password, security questions.
- User Content: Product reviews, customer service inquiries.
B. Automatically Collected Data
- Device & Technical Data: IP address, device ID, browser type, operating system.
- Usage Data: Pages visited, clickstream patterns, session duration, search queries.
- Location Data: Approximate location derived from IP or GPS (with consent) .
- Cookies & Tracking Technologies:
- Necessary Cookies: Essential for site functionality (e.g., login sessions).
- Analytics Cookies: Google Analytics, Adobe Analytics (anonymized where possible).
- Marketing Cookies: Used for personalized ads (opt-in required for GDPR/CCPA users) .
C. Data from Third Parties
- Social Media Platforms: When you link accounts (e.g., Facebook login).
- Payment Processors: Transaction status, fraud risk scores.
- Logistics Partners: Shipping updates, delivery confirmation .
3. HOW WE USE YOUR DATA
Purpose | Legal Basis |
---|---|
Order processing & payment verification | Contractual necessity |
Account management & customer support | Legitimate interests |
Personalized marketing & ads | Consent (opt-in required) |
Fraud prevention & security | Legal obligation & legitimate interests |
Product improvement & analytics | Legitimate interests (anonymized) |
Compliance with tax/law (e.g., VAT) | Legal obligation |
4. DATA SHARING & DISCLOSURE
We share data only under strict safeguards:
- Service Providers:
- Payment gateways (Stripe, PayPal) for transaction processing .
- Logistics partners (e.g., DHL, FedEx) for order fulfillment .
- Cloud hosting providers (AWS, Google Cloud) for data storage.
- Legal & Regulatory Obligations:
- To comply with court orders, tax audits, or anti-fraud investigations .
- Business Transfers:
- During mergers, acquisitions, or asset sales (data subject to confidentiality agreements).
- With Your Consent:
- For marketing partnerships or integrated third-party services.
5. CROSS-BORDER DATA TRANSFERS
- Data may be transferred to and processed in countries outside your residence (e.g., from the EU to the US).
- Safeguards:
- Standard Contractual Clauses (SCCs) for EU→non-EEA transfers.
- Participation in Privacy Shield frameworks (where applicable).
- Encryption during transit/storage .
6. USER RIGHTS
Depending on your jurisdiction, you may:
- Access & Portability: Request a copy of your data in a machine-readable format.
- Rectification: Update inaccurate/incomplete data via your account dashboard.
- Erasure ("Right to Forget"): Delete data not essential for legal/compliance purposes.
- Restriction & Objection: Limit processing of data or opt out of marketing.
- Withdraw Consent: Revoke permissions (e.g., email subscriptions) anytime.
- Non-Discrimination (CCPA): Not be penalized for exercising rights.
To exercise rights: Contact us at [privacy@yourcompany.com]. We respond within 30 days .
7. DATA SECURITY MEASURES
We implement technical and organizational controls:
- Encryption: TLS 1.3 for data transit; AES-256 for storage.
- Access Controls: Role-based permissions, MFA for employee accounts.
- Audits & Testing: Regular vulnerability scans, penetration tests.
- Breach Response: Notify regulators (e.g., within 72hrs under GDPR) and affected users .
8. COOKIE POLICY
- Consent Management: We use a cookie banner for granular opt-in/opt-out (required for GDPR/CCPA users).
- Preferences: Adjust settings via our Cookie Preference Center [link].
9. CHILDREN’S PRIVACY
Our Service does not target users under 16 (or 13 in the US). We delete underage accounts upon verification .
10. POLICY UPDATES
We will notify users of material changes via email or site banners. Continued use constitutes acceptance.
11. CONTACT US
For questions, complaints, or Data Protection Officer (DPO) inquiries:
- Email: [weisberg@foxmail.com]
Supervisory Authority: EU users may lodge complaints with their local DPA (e.g., Ireland’s DPC).
© [2025] [YUZHU Trading Co, LTD]. All Rights Reserved.