Privacy Policy

Last updated: August 20, 2026

This Privacy Policy explains how 深圳市开心鱼科技有限公司 (Shenzhen HappyFish Technology Co., Ltd., “HappyFish,” “we,” or “us”) collects, uses, stores, protects, shares, and deletes information when organizations use HappyFish ERP.

1. Information we process

We process information provided by account administrators and authorized users, including names, business contact details, account identifiers, user roles, store bindings, access logs, and user-entered product or copy content.

After a seller explicitly authorizes HappyFish ERP through OAuth, we may process seller-authorized marketplace participation, product, listing, pricing, inventory, and operational order data, together with authorization credentials needed to provide the service.

When an authorized seller enables direct-to-consumer delivery or shipping-label creation, we may use a Restricted Data Token to retrieve the minimum recipient information required to fulfill that order, such as the recipient name, shipping address, and telephone number. We do not request restricted information for advertising, analytics, product development, or unrelated workflows, and we do not request payment-card information or buyer tax information for this purpose.

2. How we use information

We use information only to authenticate users, connect authorized stores, provide product and listing workflows, review pricing, display inventory and order status, create seller-requested shipping labels, coordinate direct-to-consumer delivery, maintain security and audit records, support customers, and comply with legal obligations. Restricted recipient information is available only to authorized users and processes that need it for fulfillment. We do not sell Amazon Information or use it for advertising.

3. AI processing

Information retrieved through Amazon Selling Partner API, including restricted recipient information, is not sent to OpenAI or other artificial intelligence providers. AI-assisted copy features process only content that a user separately and actively enters or selects for that purpose.

4. Service providers and international processing

Tencent Cloud provides application hosting and storage. Cloudflare provides DNS, content delivery, traffic security, and encrypted delivery. When a seller configures and requests a shipment, YunExpress may receive the minimum recipient and shipment information needed to create a label and provide delivery services. These providers act only as infrastructure, security, or fulfillment processors under controlled access and may not use Amazon Information for advertising or their own independent purposes. Information may be processed in jurisdictions where these providers operate, subject to contractual and technical safeguards.

5. Security

We use role-based access, store bindings, least-privilege SP-API permissions, encryption in transit, encrypted storage for restricted recipient fields and credentials, access logging, and an incident response process. Access to restricted information is limited to authorized fulfillment purposes. No method of transmission or storage is completely secure, but we review and improve controls appropriate to the service.

6. Retention and deletion

Restricted recipient information used for fulfillment is deleted no later than 30 days after order delivery. Non-restricted Amazon Information is retained only as needed for the service and for no longer than 18 months unless a shorter period applies. Security and audit logs are retained for at least 12 months and are designed not to contain restricted recipient information or credentials.

When authorization is revoked, the service is terminated, or we approve a verified deletion request, we delete or anonymize associated data unless limited retention is required by law or for documented security purposes. Deletion also applies to service-controlled copies and backups according to their controlled expiration lifecycle.

7. Choices and rights

Seller administrators may revoke OAuth authorization through their Amazon account. Subject to applicable law, an authorized representative may request access, correction, export, restriction, or deletion by emailing support@happyfisherp.com. We may verify identity and authority before completing a request.

8. Cookies

This public website does not use advertising or analytics cookies. Essential infrastructure may process basic request information needed to deliver and protect the site.

9. Changes to this policy

We may update this policy to reflect service, legal, or security changes. The “Last updated” date identifies the current version. Material changes will be communicated through the service or by an appropriate contact method.

10. Contact

深圳市开心鱼科技有限公司
深圳市龙岗区龙城街道黄阁坑社区黄阁北路449号天安数码创新园三号厂房A1402
Email: support@happyfisherp.com