Back to home

Security & data use

Understand the data boundaries, store authorization safeguards and operation records behind 互拓ERP. Permissions, data minimization and explicit confirmation support everyday business workflows.

Use only the data needed for the service

The data scope includes Seller and marketplace identifiers, existing listings and product mappings, orders and after-sales records without buyer personal information, FBA inventory, settlements and fees, plus company-maintained SKUs, purchases and local stock records. Data supports the authorized workspace’s analysis and supply-chain execution. Buyer names, addresses, phone numbers and emails are excluded.

Workspace isolation and business roles

Reads, writes, exports and background tasks follow workspace and operation permissions. Six business roles cover ERP Owner, operations, purchasing, warehouse, finance and read-only access. Members can combine roles for their responsibilities, with permissions limited to their own workspace.

Connect through official authorization

Store connections use official Amazon OAuth. Long-lived credentials are encrypted on the server with versioned keys. Plaintext credentials do not belong in pages, ordinary exports, logs or audit bodies. Unlinking, formal cancellation, Amazon revocation or a confirmed security incident triggers credential destruction. Connecting again requires new authorization.

Confirm external actions before execution

Amazon business writes are limited to Fulfillment Inbound. Authorized users confirm Seller, marketplace, origin warehouse, SKUs, quantities and external effects. Each operation retains a stable identity and execution record. Uncertain outcomes are recovered through status queries to avoid duplicate shipments.

Keep records that can be checked

Sync records retain sources, update and cutoff times, and failure states. Money retains its currency and calculation basis; inventory uses traceable movements. Missing, unknown, unsynced and not-applicable inputs remain distinct. Important operations retain safe audit summaries without sensitive payloads.

Report security or data concerns

Use the privacy and data-request channel to describe the issue, its scope and how to reach you. Do not include passwords, authorization tokens or buyer personal information. Provide only the necessary, redacted details.

Contact us