Privacy policy
How we process personal information
This policy covers browsing and contact forms on dataflowforever.com, Meta Ads connection, authorization, and Meta Conversions API features provided by Hangzhou DataFlowForever Technology Co., Ltd., and information processed through Amazon Selling Partner API (Amazon SP-API) or Amazon Ads API after Amazon approval and seller or advertiser authorization. A project data-processing agreement may supplement this policy but cannot expand Amazon-permitted uses or extend applicable deletion deadlines. We are not Amazon, and we are not an Amazon partner unless Amazon has listed us in a named program.
Controller: Hangzhou DataFlowForever Technology Co., Ltd. · Contact: wusu@dataflowforever.com
Last updated: September 8, 2026
1. Scope and our role
For website inquiries, business contact, and our own Meta connection records, we generally determine the purpose and means of processing as the controller or personal information processor.
When we transmit a merchant's customer events through Meta Conversions API under the merchant's instructions, the merchant is generally the controller and we act as its processor or entrusted party within the agreement and configuration.
Amazon approval for the relevant API and verifiable seller or advertiser authorization are prerequisites to access. As of this update, our Amazon Ads Partner Network registration has been approved, while Amazon Ads API access has not been granted; Partner Network membership does not confer API access. Our Amazon SP-API developer application remains pending review. Once approved, we process account data under the client’s instructions and the rules for each API. Browsing, submitting a form, or signing a project agreement does not create API access.
2. Information we may process
The categories depend on the feature you use. Browsing this site alone does not grant us access to your advertising accounts.
- Website inquiries: company, name, email, WeChat, site, offer intent, selected services, problem description, source page, referrer, UTM values, consent, and processing status.
- Technical and security data: hosting, security, and abuse-prevention systems may temporarily process IP address, browser, device, time, and request logs; the lead record does not store the raw IP address.
- Meta connections: Meta app-scoped user ID, authorized Business, Page, ad-account or pixel identifiers, permissions, token and expiry information, connection status, and necessary audit records.
- Meta Conversions API: merchant-configured event name, time, source, page or transaction context, and normalized or hashed matching identifiers. The exact fields are set by merchant configuration and contract.
- Amazon SP-API data: within approved roles and seller authorization, seller identifiers, marketplaces, listings, inventory, pricing, order and fulfillment summaries, settlements, and operating metrics. Restricted buyer PII such as names, addresses, or phone numbers requires Amazon approval of restricted roles and a specific project need; our current application does not request those roles.
- Amazon Ads API data: after the relevant API approval and explicit advertiser authorization, approved advertising profiles, account identifiers, Sponsored Products campaigns, ad groups, targets or keywords, budgets, bids, and performance reports. Uses are limited to approved Amazon advertising management, analysis, and authorized adjustments.
- Connection and security records: account-specific OAuth permissions, access and refresh tokens, expiry, connection status, and necessary audit records. We do not collect Seller Central passwords or ask for Amazon Ads login passwords.
3. Purposes and legal bases
We process information to answer inquiries, assess fit, provide requested features, maintain authorized connections, transmit merchant-configured events, process authorized Amazon Information, secure the service, prevent duplicate or abusive activity, perform contracts, and comply with law.
Depending on the context, the legal basis may be consent, steps requested before a contract, performance of a contract, legal obligation, or legitimate operational and security interests where permitted. We obtain separate or written consent when applicable law requires it.
4. Amazon Information: collect, use, store, protect, share, and delete
This section explains how Amazon SP-API and Amazon Ads API information is collected, used, stored, protected, shared, and deleted. Amazon SP-API processing follows the applicable Amazon Selling Partner API developer agreement, Data Protection Policy, and Acceptable Use Policy. Amazon Ads API processing follows the Amazon Ads Partner Network Agreement, Amazon Ads Partner Network Policies, and applicable API terms; Amazon SP-API rules do not replace Amazon Ads rules.
Collection and use: obtain Amazon approval, verify permissions and seller or advertiser authorization, then enable the specific account and feature. Amazon SP-API data supports agreed catalog, pricing, inventory, fulfillment, settlement, and operating reports; Amazon Ads API data supports only approved advertising functions. Account changes require express, verifiable authorization and the agreed approval process. We do not collect Seller Central passwords or log into client stores from office or datacenter browsers.
Use limits: no sale, public release, commercialization outside the approved integration, use for other clients, individual profiling, or public-model training. Sharing or combining Amazon Ads data with other third-party sources requires Amazon's express prior written approval; client consent or a project contract cannot replace it. Cross-platform audiences and remarketing require the applicable permissions.
Storage and access: we plan to use Google Cloud Platform (GCP) for hosting and storage of Amazon data, with account isolation, attribution, and retention controls. Database writes are restricted to the seller or advertiser account to which the data belongs. Human access is limited to authorized seller or advertiser personnel who need it for the authorized service. Amazon Ads service providers must meet Amazon approval requirements and confidentiality and purpose limits for operating the approved integration. Naming a provider does not mean Amazon has approved the arrangement; required approvals must precede processing.
Planned AI inference: we propose using Google Gemini and OpenAI services, including ChatGPT, through API calls or web interfaces to process the minimum necessary, permitted Amazon Ads data exclusively for that advertiser's performance analysis and inference. We do not use this data to train or fine-tune models. AI processing may create copies in prompts, outputs, attachments, and security logs. No training does not mean zero retention or processing exclusively within GCP.
Conditions for enabling AI processing: first obtain the required Amazon approvals and advertiser authorization, then verify the specific product, account plan, confidentiality and no-training terms, data settings, processing locations, and applicable deletion mechanisms. API and web products are assessed separately; protections for one do not automatically apply to the other. Services, accounts, or features without these checks must not receive Amazon data. Disabling training cannot replace required Amazon approval.
Protection: before enabling Amazon data access, verify TLS 1.2 or higher in transit, encryption at rest, least privilege, unique accounts, MFA, account isolation, auditing, and key management. These requirements cover the full data-access path.
Stopping and deletion: on revocation, an Amazon deletion request, loss of authority, or the end of the engagement, stop the relevant synchronization and account actions, clear access and refresh tokens, and determine scope through manual review. Permanently delete Amazon Information, including live copies and backups, within 30 days of the earliest applicable trigger. If Amazon requests return, follow its instructions and clear retained copies. Any earlier applicable deadline controls.
Amazon Ads program materials: permanently and securely delete all online, network-accessible, and offline copies of Amazon Ads Program Materials within 90 days after Amazon's notice. The clock starts at that notice, not after live-data deletion. If materials are also Amazon Information subject to an earlier deadline, the earlier deadline applies. Backup rotation cannot extend either deadline. Before processing Amazon data, verify that the selected cloud service, recovery windows, and backup deletion mechanisms meet these deadlines; storage configurations without that verification must not receive Amazon data.
Retention limits: keep data only as needed for its authorized purpose. Amazon SP-API non-PII is generally retained no longer than 18 months. If restricted buyer PII is approved in future, retain it no longer than 30 days after delivery except for legal duties permitted by applicable rules. Necessary security audit logs are kept for at least 12 months without retaining expired Amazon data or tokens as logs. Retain Amazon Ads data beyond its permitted purpose only when specifically required by law, with restricted access and use solely for that duty, and delete it when the duty ends. Anonymization or hashing does not replace required deletion.
Requests and evidence: the Data Deletion page provides a reference and status lookup. Amazon deletion is handled through manual verification and execution; submitting the form does not automatically revoke platform authorization or erase all data. We record the resolution and provide compliance evidence when Amazon requires it.
5. Cookies and website tracking
This website currently does not deploy Meta Pixel, third-party advertising cookies, or cross-site behavioral profiling. Your language choice may be stored locally in the browser to preserve the selected version.
If we add non-essential analytics, advertising, or behavioral tracking, we will update this policy first and provide consent controls where required.
6. Sharing, processors, and sale
We share or entrust information only as needed to cloud hosting, database, email notification, security, and platform providers, with contractual, access, and security limits. Meta features interact with Meta Platforms under your authorization or the merchant's instructions. Amazon Information is handled under section 4.
We do not sell personal information or provide client, lead, or Amazon Information to third parties for their independent advertising profiles or public-model training. We may disclose necessary information when legally required or to resolve disputes and protect lawful interests.
7. International processing
Platforms and providers used in cross-border commerce may operate in different countries or regions. When calling North America Amazon APIs, Amazon Information may be processed in China and in the cloud regions used for those API calls. We identify the actual data flow, location, and applicable requirements before using contracts, assessments, certifications, separate consent, or other required safeguards.
Where a client project involves transfers beyond this general notice, project documents or a separate notice will identify the recipient, purpose, data categories, and rights channel as required.
8. Retention
Website inquiries that do not become a client relationship are generally retained for 24 months after the last substantive interaction. Client records are retained as needed for contract, tax, dispute, and legal obligations.
Verified Meta deletion or disconnect requests are generally completed within 30 days. Amazon information and backups follow section 4, measured from the original trigger. Restricted backups of other data are cleared within 90 days of verification of the relevant deletion request, or sooner when law or platform rules require it. Security logs and legally required records contain only necessary information.
9. Your rights
Subject to applicable law, you may request notice, access, a copy, correction, completion, restriction or objection, withdrawal of consent, deletion, Meta disconnection, revocation of Amazon app authorization, explanation, or complaint. Withdrawing consent does not affect prior lawful processing.
We verify identity and scope before responding. For merchant customer events, requests should normally begin with the merchant that collected the information; we assist that merchant with its obligations. Amazon sellers or advertisers can revoke the relevant authorization in Seller Central or the Amazon Ads console, or request assistance and deletion through our Data Deletion page or email. Inability to sign in to the platform does not prevent a request to us.
10. Security, children, and updates
Report a privacy concern, security vulnerability, or actual or suspected misuse of Amazon data promptly to the privacy and security email below, with “Security report” in the subject. Include the affected page or feature, discovery time, reproduction steps, potential impact, and a reply address. Do not send passwords, tokens, or unnecessary personal information.
We log the report, assign an owner, and reply by email with a tracking reference and follow-up channel. The owner assesses impact, contains exposure such as by restricting access, coordinates investigation and remediation, provides progress updates, and communicates the resolution. Use the original email thread and reference to follow up. Urgent security incidents do not wait for the ordinary 30-day deletion-request period.
For Amazon SP-API data incidents, we notify security@amazon.com within 24 hours of discovery as required by the applicable Amazon rules. Amazon Ads incidents are reported promptly under the applicable agreement through Amazon-designated channels. We cooperate with investigation and remediation and provide legally required notices. No networked system guarantees absolute security.
The site and services are for business users, not children under 18. We update this policy and date when features, providers, or applicable rules change, with appropriate notice of material changes.
Access, correction, deletion, or disconnection
Use the public data-request workflow or contact us by email. For Meta authorization, disconnection also attempts to revoke the related permissions and stop future synchronization. For Amazon SP-API or Amazon Ads, revoke the app in Seller Central or the Amazon Ads console and request assistance or deletion from us; requests are manually verified and executed.
Open data deletion and rights requests