PRIVACY POLICY

Privacy policy

This policy explains how Xingyun Compute handles company information, account details, authorization data, usage records, and business data when providing data collection, AI analysis, reviewed execution, and operational review.

ScopeApplies to the Xingyun Compute website, demo onboarding, and SaaS services.
PrinciplesUse the minimum data needed for the purpose and enforce company and permission boundaries.
UpdatedLast updated: May 27, 2026.

1. Data scope

To provide website inquiries, demo onboarding, account access, data collection, AI analysis, and reviewed execution, Xingyun Compute may process:

  • Company information: company name, contact, email, business region, and service status.
  • Account information: name, email, role, permission group, login state, and session records.
  • Authorization data: store, Marketplace, Ads Profile, SP-API / Ads API relationships and authorization state.
  • Business data: advertising, orders, inventory, Listings, reviews, keywords, collection tasks, run state, AI recommendations, and review records.
  • Technical data: access logs, device information, IP address, browser type, error logs, and security audit information.

2. How we use data

We use data for clear product and service purposes, including:

  • Creating company spaces, managing members, maintaining store authorization, and enforcing permission scope.
  • Running official Ads API / SP-API collection, standardizing records, and showing freshness.
  • Generating AI recommendations, action drafts, review records, and operational learning.
  • Maintaining security, service stability, incident investigation, and product improvement.
  • Providing support, demos, training, billing, and service notices at the user's request.

3. Storage and protection

Xingyun Compute stores data according to deployment, compliance, and continuity requirements, and uses access control, encrypted transport, permission isolation, and operation audit measures to protect it.

  • Business data is isolated by company, store, authorization, and resource scope.
  • Sensitive authorization information is used only for collection and service calls within the user's authorized scope.
  • Key operations, task runs, and permission changes are recorded for security review.

4. Sharing and disclosure

Unless authorized, required to perform a contract, required by law, or necessary to protect system security, Xingyun Compute does not sell or rent user data to unrelated third parties.

  • Service providers process data only as needed for cloud resources, notifications, logging, security, or operations support.
  • We handle disclosures required by legal process, regulators, or security incidents within applicable law.
  • Exports, sharing, and integrations authorized by a company administrator follow the configured permission scope.

5. Retention and deletion

We retain data according to service purpose, contract, audit needs, and applicable law. After service termination or a deletion request, Xingyun Compute deletes or anonymizes relevant data where practicable.

  • Collection tasks, run logs, review records, and security audit records may be retained for traceability.
  • Company administrators may request account closure, authorization removal, data export, or data deletion.
  • After deletion or anonymization, the data is no longer used to identify a specific company or person.

6. User rights

Where allowed by applicable law, users and company administrators may request access to, correction of, export of, restriction of processing of, or deletion of relevant data.

  • Company administrators can maintain member roles, permission groups, store authorizations, and access scope.
  • Individual users can contact their company administrator or the Xingyun Compute team about account data requests.
  • We process requests within a reasonable period after identity and permission checks.

7. Permissions and audit

Xingyun Compute treats permissions and auditability as default product capabilities so data access and growth actions can be traced, reviewed, and assigned.

  • Business tables, collection tasks, and actions use company boundaries such as company_id as a core scope control.
  • High-impact actions retain recommendation source, review notes, executor, execution time, and result state.
  • System and company administrators can view key audit records within their authorized scope.