Document version: 20260923 Cookie notice version: 1 Scope: pp20260923_cn1

Privacy Policy

Last updated: 23 September 2026

1.Introduction

Welcome to the cross-border overseas warehousing, dropshipping and after-sales return logistics storage services provided by Nanjing Yidaou Warehouse Co., Ltd. (hereinafter referred to as "we" or "Yidaou") based on the OMS Order Management System and WMS Warehouse Management System.

We are committed to protecting and respecting your privacy. We will collect and use your personal data during your use of our products and services. This Privacy Policy sets out the purposes, methods and scope of our processing of your personal data, your rights in relation to your personal data, and the security safeguards we implement to protect your personal data.

This Privacy Policy applies to two groups of parties:

cooperating e-commerce merchants that use the OMS/WMS systems, and natural persons located in the European Union under each order (including consignees and return senders, collectively referred to as "data subjects").

We act as the controller under the General Data Protection Regulation (GDPR) when processing the personal data of cooperating e-commerce merchants.

When processing the personal data of EU natural person consumers contained in orders, we act as the processor under the GDPR, and the cross-border e-commerce merchant entrusting us with order processing shall be the corresponding data controller.

As a processor not established in the European Economic Area (EEA), we have appointed EDA WAREHOUSING DE GMBH (Germany) as our representative in the European Union pursuant to Article 27 of the GDPR. The EU representative's contact details are set out in Section 13 (Contact Us).

This policy applies to information we collect:

On this website and the Services.

In email,text,and other electronic messages between you and us or this website.

When you register to use our website or any tools/applications/software available on/through our website.

it does not apply to information collected by:

any other means,including on any other website operated by us or any third party including our affiliates and subsidiaries.

any third party(including our affiliates and subsidiaries)through any application or content (including advertising) may link to or be accessible from or on the website.

2.Notice

Please read this policy carefully to our website policy and practice regarding your information and how we will treat it. If you do not agree with our policy and practice,your choice is not to use our Services.By ticking the checkbox or clicking the consent button, you acknowledge and agree to our Policy.This policy may change from time to time (see Changes to Our Privacy Policy),your continued use of this website after we make changes is deemed acceptance of those changes,so please check the policy periodically for update.

Our website is not intended for children under 16 years of age. No one under age 16 may provide any information to or on the website. We do not knowingly collect Personal Data from children under 16.

If you are under 16,do not use or provide any information on this website or through any of its features,register on the website,make any purchases through the website,use any of the interactive features of this website,or provide any information about yourself to us.

If we learn we have collected or received Personal Data from a child under 16 without verification of parent,we will delete that information.If you believe that we might have any consent information from or about a child under 16,please contact us via our contact email address at the end of this privacy policy.

3.What Information We Collect

We collect three categories of information:Information You Provide,Automatically Collected Information,and Information From Other Sources.More detail about each of the categories is provided below.

1. Account Registration, Login & Account Security Management

Purposes of Processing: Merchant onboarding, activation of OMS/WMS system accounts, identity verification for login, password reset, account security risk control, business reconciliation and push of merchant service notifications.

Merchant personal data collected: Email, Chinese company name, English company name, country, province, city, postal code, contact phone number and street address.Email, contact name, company name and contact phone number are mandatory information for account registration and login. If you refuse to provide such mandatory data, you will not be able to complete account registration, log in or use basic system functions. You may withhold other non-mandatory information without affecting core functions such as account login and basic operations.

2. Consignee Information for Outbound Orders

Purposes of Processing: Overseas warehouse outbound sorting, goods packaging and delivery, logistics tracking matching, after-sales order verification and communication regarding logistics abnormalities.

EU natural person data collected: Consignee full name, country, province, city, postal code, email address, contact number and street address. All the above information is mandatory for order outbound fulfilment. Failure to provide such data will render us unable to process order outbound delivery.

3. Sender Information for Return Shipments

Purposes of Processing: Inbound sorting of returned parcels, after-sales return & exchange handling, communication over logistics anomalies, reconciliation and verification of return orders.

EU natural person data collected: Return sender full name, country, province, city, postal code, email address, contact number and street address. All the above information is mandatory for cross-border return inbound procedures. Failure to provide such data will render us unable to accept and process returned parcels.

We only obtain information indirectly from compliant third parties to the extent necessary for performing cross-border warehousing and logistics services, and will not actively collect irrelevant third-party data. All information acquisition activities comply with the EU GDPR, as detailed below:Cooperating merchants upload the aforesaid "consignee information for outbound orders" and "sender information for return shipments" to our OMS/WMS systems, from which we receive logistics information of EU natural person consignees and return senders. Such information shall only be used for overseas warehouse sorting, goods delivery and after-sales return fulfilment.

It should be noted that cooperating merchants synchronising orders bear the responsibility of fulfilling the prior disclosure obligation to EU data subjects. Meanwhile, we will post the link to this Privacy Policy on parcel labels, delivery SMS, logistics notifications, delivery emails, return guidelines, official website and OMS/WMS systems to inform you of our personal data processing activities. If you are a consumer located in the European Union, please take note of the above.

Pursuant to Article 14(3) GDPR, we shall provide you with this Privacy Policy within a reasonable period after obtaining your personal data, and in any event no later than one month. Where your personal data is used to communicate with you, the information shall be provided at the latest at the time of the first communication. Where your personal data is to be disclosed to another recipient, the information shall be provided at the latest when the personal data is first disclosed.

The obligation to provide you with the above information shall not apply where:
(a) you already have the information;
(b) provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, provided that appropriate technical and organisational measures are taken to protect your rights and freedoms;
(c) obtaining or disclosing the personal data is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate safeguards for your legitimate interests; or
(d) the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy.

We guarantee that we will strictly process your Personal Data in accordance with the agreements between us and third parties and comply to relevant legal provisions. Please read the privacy policy and user agreement of the third party in detail before using its service. If you refuse to allow the third party to collect,use,or transmit your Personal Data,the corresponding service is unusable for you.

We also collect,use and share Aggregated Data such as statistical or from demographic data for any purpose. Aggregated Data could be derived your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity,for example,we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature.

However,if we combine or connect Aggregated Data with your personal data so that can directly or indirectly identify you,we will treat such combined data as personal data in accordance with this privacy policy.

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnic,religious or philosophical beliefs,sex life,sexual orientation,political opinions,trade union membership information about your health,and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses.

4. How We Use Cookies

4.1 What Are Cookies?

Cookies are small text files transmitted by our website, applications or services and stored on your device. Our website, online services, interactive features and advertising systems may deploy Cookies and similar tracking technologies, including pixel tags, web beacons and user agents. Cookies are used to enable, secure and optimise website service functions and enhance your browsing experience.

4.2 Cookies We Use

Based on their functions, purposes and compliance requirements, we divide Cookies we deploy into two categories: Strictly Necessary Cookies and Preference Functional Cookies. Only Strictly Necessary Cookies are exempted from obtaining user consent under legitimate interests. Preference Functional Cookies are non-essential and shall only be activated upon your active and explicit consent, which you may withdraw at any time.

Strictly Necessary Cookies

These Cookies are technically mandatory for website operation and a prerequisite for you to access and use core website functions, and cannot be manually disabled.

They mainly include PHP Session Cookies (e.g. PHPSESSID) and cookie_expire login timeout Cookies, which sustain system login sessions, complete identity authentication, permission verification and login security control, and guarantee the basic security and normal operation of the website backend.

PHP Session Cookie (Session Cookie):

Primarily deployed for login scenarios of the web backend (warehousing/index.php, admin.php). It maintains your logged-in status and supports passing session_id parameters across exports and cross-request operations to retain consistent sessions. This Cookie only stores a randomly generated system Session ID. Its core purpose is to complete user identity authentication and RBAC permission verification, and associate all business operations under your account. It shall not be used for cross-site tracking, user profiling or ad delivery.

cookie_expire (Persistent Security Cookie):

It has a default lifespan of approximately 3600 seconds and refreshes automatically with every request you submit for login security management. When a logged-in user visits authentication pages, the system automatically detects idle time. If the idle period exceeds the limit, the system triggers login timeout and redirects you to log out or shows a timeout prompt. This Cookie solely stores a Unix timestamp representing the login expiry time without core user identity data. The timestamp is calculated by adding a configurable account-specific idle timeout to the current time; the default timeout is 300 seconds if no configuration is set. Its core function is automatic logout upon inactivity to mitigate risks of account theft and unauthorised access.

Strictly Necessary Cookies shall not be used for personalised tracking or advertising. If you disable all Cookies globally via your browser, core backend functions including login, identity verification, permission access and business operations will become unavailable.

Preference Functional Cookies

These are non-essential Cookies that require your consent before activation. We only deploy the think_language Cookie for interface language preferences with a lifespan of 3600 seconds to deliver personalised multilingual adaptation based on the system’s language switching module. This Cookie serves multilingual switching scenarios. You may manually switch languages via URL parameters (cn|en|de...), or the system automatically matches and saves your selection based on your browser’s default language. It only stores your selected language code (e.g. cn, en, de, it, es, pl, fr). Its sole purpose is to remember your interface language preference and load the corresponding language pack for a tailored browsing experience. This Cookie contains no login credentials and will not be used for identity recognition, behavioural tracking or user profiling.

In addition to Cookie technologies, we automatically collect server access log data based on our legitimate interests in lawful website operation and cybersecurity protection. Such data includes IP address, browser type, internet service provider, referring page, exit page, accessed files, operating system, access timestamp and clickstream data. The above data shall only be utilised for cybersecurity defence, fault troubleshooting, website stability monitoring and performance statistical analysis. It will not be used for commercial marketing or disclosed to external third parties.

4.3 How to Clear or Disable Cookies

You may manage, disable or erase Cookies stored on your device at any time via your browser’s built-in functions to delete local Cookies and block future Cookie storage. For non-essential Preference Functional Cookies, you may enable, disable or withdraw your consent instantly through the "Cookie Settings" entry at the bottom of our website. For Strictly Necessary Cookies, dedicated removal methods are available as follows:

PHP Session Cookie: Destroy the server-side session by clicking the "Log Out" button within the system, clear all Cookies for this site via your browser, or close the browser entirely;

cookie_expire Cookie: Automatically cleared when you visit the unauthenticated login page or log out of your account; you may also manually delete this specific Cookie or wipe all site data in your browser;

think_language Preference Cookie: Manually delete this single Cookie in your browser, overwrite existing data by switching languages, or clear all Cookies of this website.

Disabling non-essential Cookies will not affect basic website access and core functions, yet the personalised language adaptation feature will cease to work. Global disabling of Strictly Necessary Cookies will render backend login, permission verification, business operations and login security protection unavailable.

4.4 Further Information Regarding Cookies

For detailed information about Cookies and guidance on configuring your browser to accept, delete or disable Cookies, please visit www.allaboutcookies.org. Please note that browser incognito/private browsing modes can restrict local Cookie storage but cannot fully block all session Cookies, nor halt our legitimate collection of server-side log data. Accordingly, private browsing cannot deliver fully anonymous access and merely reduces local tracking records. If you adjust your browser settings to turn off Cookies or activate the browser’s private browsing function, Cookies will stop collecting your Personal Data, but certain website features designed to improve your browsing experience will no longer operate. Furthermore, disabling non-essential Cookies will not interfere with basic website operation, though some personalised services and performance optimisation features may fail to function properly.

5.How We Use Your Information

We use your information to operate,provide,develop,and improve our Services,including for the following purposes. You can find more detail in“Our Legal Bases and How We Process Your Information”.

Enforce our Terms,Guidelines,and other policy that apply to you.

We review User Content and other information to protect the safety and well-being of our community.

Maintain and enhance the safety,security,and stability of our Services by identifying and addressing technical or security issues or problems (such as technical bugs,spam accounts,and detecting abuse,fraud,and illegal activity).

Review,improve,and develop our Services,including by monitoring interactions and usage across your devices,analysing how people are using our Services,and informing our algorithms.

Share your information with third party platforms at your request to provide you with features,like content sharing when you integrate your account with a third party service.

Comply with our legal obligations,or as necessary to perform tasks in the public interest,or to protect the vital interests of our users and other people.

6.How We Share Your Information

Necessary sharing with service providers: including providers of Cloud storage service providers located within the European Economic Area (EEA), cloud storage service providers located in China, European domestic cross-border courier service providers (including DHL, GLS, UPS, DPD, Correos, ASM, Colissimo, Inpost, Chronopost, Geodis, Kaprcel) and cross-border e-commerce platform eBay. We only share data necessary to deliver, support and improve our Services, and will conduct security assessment for all data receivers beforehand.We share Information You Provide,Automatically Collected Information,and Information From Others with these service providers as necessary to enable them to provide their services.

6.1 Partners

Integration Partners:When you choose to access third party services from our Platform,we may share your [Usage Information ]with third party partners to help them integrate with technology and to provide you with a seamless experience.

As a global company,our Services are supported by a number of affiliated entities within our corporate group (“Corporate Group”). We share Information You Provide,Automatically Collected Information,and Information From Others with our Corporate Group as necessary to enable them to provide important functions such as cloud hosting,security,research and development,analytics,customer and technical support.

6.2 Others

We share your information in other limited scenarios as follows.

(1)Corporate transactions

Your information may be disclosed to third parties in connection with a corporate transaction,such as a merger,sale of assets or shares,reorganisation,financing,change of control,or acquisition of all or a portion of our business.

(2)Legal obligations and rights

We may access,preserve,and share the information described in "What Information We Collect" with law enforcement agencies,public authorities,copyright holders,or other third parties if we have good faith belief that it is necessary to:

comply with applicable law,legal process or government requests,as consistent with internationally recognised standards;

protect the rights,property,and safety of our users,copyright holders,and others,including to protect life or prevent imminent bodily harm. For example,we may provide information (such as your IP address) to law enforcement in the event of an emergency where someone’s life or safety is at risk.

investigate potential violations of and enforce our Terms,Guidelines,or any other applicable terms,policy,or standards; or detect,investigate,prevent,or address misleading activity,copyright infringement,or other illegal activity.

For details on the types of Personal Data collected by our cooperating parties and the purposes of such collection, please refer to the List of Personal Data Shared with Third Parties.

The List of Personal Data Shared with Third Parties

Third Party Name Category Shared Data Purpose of Use Scenarios of Use Sharing Method Third-Party Data Processing Policy Link
DHL Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.dhl.com/global-en/footer/privacy-notice.html
GLS Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://gls-group.eu/EU/en/data-protection
UPS Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.ups.com/gb/en/support/shipping-support/legal-terms-conditions/privacy-notice.page
DPD Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.dpd.com/pt/en/privacy/
Correos Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.correos.es/es/es/legales/otros/politica-de-proteccion-de-datos-correos-logistica
ASM Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.asm.com/privacy-notice
Colissimo Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.colissimo.entreprise.laposte.fr/donnees-personnelles
Inpost Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://inpost.eu/privacy-and-cookies-policy
Chronopost Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.chronopost.fr/en/data-protection-policy
Geodis Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.geodis.com/in-en/privacy-policy
Kaprcel Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://carousel.eu/privacy/
DHL Express Logistics Carrier Consignee full name, country, province, city, postal code, street address, telephone number Generate shipping labels, deliver parcels, synchronise logistics tracking, handle after-sales exceptions Shipping label generation, outbound delivery, return inbound API transmission https://www.dhl.com/content/dam/dhl/global/core/documents/pdf/glo-core-privacy-notice-express.pdf
eBay E-commerce Platform Order information Upload eBay orders Order data upload API transmission https://www.ebay.com/help/policies/member-behaviour-policies/user-privacy-notice-privacypolicy?id=4260

In the event of a corporate transaction, the transferee shall be bound by the data protection obligations set out in this Privacy Policy and our Standard Contractual Clauses. If the transferee cannot maintain an equivalent level of data protection, we shall anonymise or permanently erase all personal data prior to transfer.

We shall only disclose personal data to law enforcement or public authorities upon production of binding, formal legal orders (court orders, official warrants, or statutory demands). Where legally permitted, we will notify you of such disclosure before complying with the request.

7.the Role as Data Processor

7.1 data processor under the GDPR

When processing the personal data of EU natural persons contained in orders, we act as a data processor under the GDPR. Our processing is governed by a written data processing agreement (DPA) with each merchant data controller. The DPA sets out the following core obligations:

Processing only on documented instructions: We shall process personal data only on documented instructions from the merchant controller, including with regard to transfers to third countries or international organisations, unless required to do so by Union or Member State law.

Confidentiality: All persons authorised to process personal data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

Security measures: We implement all technical and organisational measures required under GDPR.

Sub-processors: We only engage sub-processors with the prior general or specific written authorisation of the controller.

Assistance with data subject rights: We assist the controller in fulfilling data subject rights requests through appropriate technical and organisational measures.

Assistance with security obligations: We assist the controller in ensuring compliance with GDPR.

Return or deletion at end of service: At the choice of the controller, we shall delete or return all personal data after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage.

Audit and demonstration of compliance: We provide the controller with all information necessary to demonstrate compliance and allow for and contribute to audits conducted by the controller or another auditor mandated by the controller.

7.2 Sub-Processor Management

We engage sub-processors (including logistics carriers and cloud service providers) to assist in providing our services. Where we have general written authorisation from the merchant controller to engage or replace sub-processors, we shall give the merchant controller at least 14 calendar days' prior written notice of any intended additions or replacements, allowing the controller to object to such changes. All sub-processors are bound by the same data protection obligations as set out in our DPA with the controller.

7.3 Processor Liability as Controller

Without prejudice to our liability as a processor, if we determine the purposes and means of processing in violation of the GDPR, we shall be considered a controller for that processing activity and bear full responsibility as such.

7.4 Processing Only Under Controller Authority

Any person acting under the authority of the controller or of the processor who has access to personal data shall not process them except on instructions from the controller, unless required to do so by Union or Member State law.

8.Our Legal Bases and How We Process Your Information

We may only use your information when we have a“legal basis” to do so. We use different legal bases depending on why we use your information (in other words,the“purpose”of our processing). These legal bases involve contractual necessity,legitimate interests (ours,yours or those of another party),consent,compliance with a legal obligation,performing a task in the public interest,and protection of vital interests.

Here we explain the legal bases we rely on when we process your information. This section also describes why we use your information,how this information is processed,the categories of information involved,and the associated rights (which always includes the right to access your information).

For more information on how to exercise any of your rights,please check out the“Your Rights and Choices”section in the Privacy Policy.

8.1 Contractual Necessity

We use Information You Provide,Automatically Collected Information,and Information From Other Sources where it is necessary to perform the contract you enter into (our Terms) when you register for,access,or use our Services. This means we use your information to:

(1)provide you with our Services.

We use your information to provide you with our Services. This includes using your information mentioned in the section of What Information We Collect,so you can[login to the website,receive messages,feedback problems,and use our services].

(2)Enforce our Terms,Guidelines,or policy.

We use your information to enforce our Terms,Guidelines,and policy. This may include removing content or suspending or banning your account if we determine that you are violating our Terms or Guidelines.

(3)Administer our Services.

We also use the information we have to administer our Services,such as communicate with you on service related matters and respond to your queries (including when you tell us about a problem or ask for a copy of your information).

Your Rights: Whenever we use your information on the basis that it is necessary for the contract we have with you,you have the right to port information you have provided to us.

8.2 Legitimate Interests

We use your information where this is necessary to achieve legitimate interests - whether belonging to us,you,or a third party - provided these interests are not outweighed by your interests or fundamental rights and freedoms. We use your information to:

(1)We use your information to ensure your safety and well-being,including by reviewing User Content (and if permitted under applicable law,direct messages and associated metadata) for breaches of our Terms,Guidelines,and other policy.

Legitimate Interest relied upon:To keep our users safe,review compliance with our Guidelines,and prevent misuse of our Services.

Information used: Information You Provide,Automatically Collected Information,and Information From Other Sources.

(2)Ensure the security and stability of our Services.

We use your information to carry out testing and analysis to ensure the stability and security of our Services,including by identifying and combating technical or security issues (such as technical bugs,spam accounts,and detecting abuse,fraud,and illegal activity).

Legitimate Interest relied upon: To ensure the ongoing stability and security of our Services and to ensure they are continuously available and functioning.

Information used: Information You Provide,Automatically Collected Information,and Information From Other Sources.

(3)Share your information with third parties to provide additional features.

We share your information with third parties providing additional features when you choose to use these features.

Legitimate Interest relied upon: To enable those third party service providers to better authenticate users and optimise the user experience.

Information used: Information You Provide,Automatically Collected Information,and Information From Other Sources.

Your rights:Whenever we use your information on the basis that it is necessary for Legitimate Interests,you can object to,and request restriction of,such usage.

8.3 Your Consent

We bear the burden of proving that you have validly consented to the processing of your personal data for the specified purposes. We maintain records of consent (including timestamps and consent method) to demonstrate compliance with GDPR.

We ask for your consent to access or use your information for specific purposes. If we do,you’ll always be able to revoke your consent through the device permissions or in-website settings or sending your request to our contact email address.

Your rights: Whenever we use your information based on your consent,you can withdraw your consent at anytime. However,your withdrawal of consent will not affect the lawfulness of processing your information based on your consent prior to your withdrawal of consent.You also have the right to port information you have provided to us that we use based on your consent.

Consent shall be freely given. We will not make the performance of a contract or service conditional on consent to processing of personal data that is not strictly necessary for the performance of that contract. You may refuse non-essential consent without any negative impact on your access to core services.

8.4 Compliance with a legal obligation

We may use your information including your Profile Information or User Content where it is necessary to comply with a legal obligation. This includes situations where we have obligations to take measures to ensure the safety of our users or comply with a valid legal request such as an order from law enforcement agencies or courts. We generally use Information You Provide and Automatically Collected Information,although it depends on the specific situation.

8.5 To perform a task in the public interest

We may use your information where it is necessary to perform a task in the public interest,including undertaking research,preventing and detecting crime,safeguarding children and promoting public safety,security,and integrity as laid down by applicable law. We generally use Information You Provide and Automatically Collected Information,although it depends on the specific situation.

Your rights: When we use your information on the basis that it is necessary for a task carried out in the public interest,you have the right to object to,and seek restriction of,our usage.

8.6 To protect someone's vital interests

We may use your information where it is necessary to protect your or someone else's life,physical integrity,or safety. This include providing law enforcement agencies or emergency services with information in urgent situations to protect health or life. We generally provide Information You Provide and Automatically Collected Information,although it depends on the specificsituation.

9.Your Rights and Choices

You have rights and choices when it comes to your information. Some of these rights apply generally, while others will only apply in certain circumstances. These rights may be subject to lawful limitations prescribed under the GDPR and other applicable data protection laws.

9.1 Access your information

You may request us, free of charge, to confirm whether we process your Personal Data, obtain full details of our processing activities, and receive an official copy of your stored personal data. You can view part of your publicly visible Personal Data via the “My Account” tab in your account.

Please note that self-service viewing functions do not substitute your statutory right to obtain an official data copy issued by us.

You can exercise your access right by sending an email to the contact address listed in the “Contact us” section below.

When exercising your right of access, you are entitled to obtain confirmation of whether we process your personal data and, if so, access to the following information:
(a) the purposes of the processing;
(b) the categories of personal data concerned;
(c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
(d) where possible, the envisaged retention period or, if not possible, the criteria used to determine that period;
(e) the existence of your rights to request rectification, erasure, restriction of processing, or objection to processing;
(f) the right to lodge a complaint with a supervisory authority;
(g) where the personal data are not collected from you, any available information as to their source;
(h) the existence of automated decision-making, including profiling, and meaningful information about the logic involved and the significance and envisaged consequences for you.

9.2 Right to Erasure

You have the right to request us to delete your personal data without undue delay where one of the following grounds applies:

the personal data is no longer necessary for the original processing purposes;

you withdraw your consent which serves as the legal basis of processing;

you lodge a valid objection to the processing;

the processing is unlawful;

deletion is required to comply with our legal obligation; or

the data concerns a child and collected without sufficient parental consent.

We may refuse your erasure request only where processing is necessary for exercising the right of freedom of expression and information, compliance with a legal obligation, public interest purposes, scientific or historical research purposes, or the establishment, exercise or defence of legal claims.

You may submit a deletion request for part of your Personal Data or a full account deletion request via the contact email address provided in the “Contact us” section below.

9.3 Rectify your information

You have the right to request us to correct inaccurate or incomplete Personal Data concerning you.

You may submit a rectification request via the contact email address provided in the “Contact us” section below.

9.4 Port your information

You are entitled to data portability where our processing is based on your explicit consent or the performance of a contract with you. You may obtain your personal data in a structured, commonly used and machine-readable format, transmit such data to another data controller, or require us to directly transfer your data to a designated alternative controller where technically feasible.

Please note that your exercise of the data portability right shall not adversely affect the rights and freedoms of other individuals. You can exercise this right via the contact email address provided below.

9.5 Object to the processing of your information

You have the right to object to our processing of your personal data under the following circumstances:

Processing based on legitimate interest or public interest:

You may object on grounds relating to your specific personal situation. We will cease the relevant processing activities unless we prove compelling legitimate grounds for processing that override your rights and freedoms, or processing is necessary for the establishment, exercise or defence of legal claims.

Processing for direct marketing (including related profiling):

You have an absolute, unconditional right to object at any time, with no justification required. Upon receipt of your objection, we will immediately terminate all processing of your data for direct marketing purposes.

You can submit an objection request by sending us an email via the “Contact us” channel below.

9.6 Restrict the processing of your information

You may request restriction of your personal data processing in the following scenarios:

you dispute the accuracy of your personal data, pending verification;

processing is unlawful, and you refuse data deletion and request restricted use instead;

we no longer need your data for processing purposes, but you require the data for legal claim establishment or defence;

you have submitted an objection to processing, pending our legitimacy assessment.

During restricted processing, we will only store your personal data and will not conduct further processing unless permitted by mandatory law. You can exercise this right via email contact.

During the period of restricted processing, we may only process the personal data, other than for storage purposes, in the following circumstances:

(a) with your consent;

(b) for the establishment, exercise or defence of legal claims;

(c) for the protection of the rights of another natural or legal person; or

(d) for reasons of important public interest of the Union or of a Member State.

We will notify you before lifting the restriction on processing.

We shall communicate any rectification, erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. We shall inform you about those recipients if you request it.

9.7 Right to Withdraw Consent

Where our data processing is based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent shall be as easy as giving consent. Withdrawing your consent will not affect the lawfulness of any processing carried out prior to your withdrawal. You may adjust the scope of authorization for our continued collection and processing of your Personal Data or withdraw your authorization by deleting your personal data, disabling device permission settings, or deactivating your account.

You may also exercise this right by submitting a request via the contact email address provided in the “Contact us” section below.

9.8 Automated individual decision-making and profiling

You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significant adverse impacts on you. Where such automated decision-making is permitted by applicable law (i.e., necessary for contract performance, based on your explicit consent, or authorised by statutory provisions), you retain the right to require human intervention, express your opinions and contest the automated decision outcome. You can exercise this right via the contact email address below.

Our OMS/WMS systems do not conduct automated profiling or purely automated decision-making that produces legal effects or similarly significant adverse effects on you. Should we deploy automated risk verification for logistics fraud prevention purposes in the future, you will be informed in advance and will have the right to request human review and contest automated outcomes via our DPO.

9.9 Exercising your rights

To exercise any of the aforementioned data subject rights, you may use the corresponding functions available on the "My Account" page of our website. If no relevant functions for exercising such rights are provided on our website, please contact us via the email address set out in the "Contact Us" section.

We may verify your identity and account details or request supplementary information to authenticate and process your request legitimately.

We will respond to all valid data subject right requests without undue delay, and in any case within one (1) calendar month of receipt. Where requests are complex or voluminous, we may extend the response period by up to two (2) additional months. We will notify you of any extension and the corresponding reasons within the initial one-month period. Electronic requests will receive responses in a standard electronic format unless you explicitly request an alternative form.

If we decline any valid request, we will fully inform you of the refusal grounds and your right to lodge a complaint with the competent data protection supervisory authority. You may contact us for inquiries regarding our response to your requests, and you reserve the right to submit a complaint to the local supervisory authority at any time.

If we determine that a request is manifestly unfounded, excessive or repetitive, we reserve the right to charge a reasonable administrative fee or deny the request. Prior to imposing any fee, we will clearly inform you of the basis and applicable standards used to calculate such fee.

All initial data subject rights requests are provided free of charge under GDPR. We may charge a reasonable administrative fee based on actual administrative costs only for requests that are manifestly unfounded, excessive or repetitive. We bear the burden of proving that a request is manifestly unfounded or excessive. Prior to imposing any fee, we will clearly inform you of the basis and applicable standards used to calculate such fee.

10.Data Security, Data Retention and Data Breach Notification

10.1 Data Security

We have implemented a comprehensive set of technical and organisational measures to ensure a level of security appropriate to the risk, including:

Pseudonymisation and encryption of personal data in transit (SSL/TLS) and at rest;

Confidentiality, integrity, availability and resilience of processing systems and services through role-based access control, least privilege principle, and system hardening;

Rapid restoration of availability and access to personal data in a timely manner in the event of a physical or technical incident through regular disaster recovery backups and incident response procedures;

Regular testing, assessment and evaluation of the effectiveness of technical and organisational measures for ensuring the security of processing through periodic security audits, vulnerability scanning and penetration testing.

10.2 Data Retention

Personal data is initially stored in Alibaba Cloud servers located in Frankfurt, Germany. For the purpose of warehouse operation, order reconciliation and after-sales return verification of merchants based in China, partial encrypted data will be transmitted to our servers located within China for storage and processing.

We retain information for as long as necessary to provide our Services and for the other purposes set out in this Privacy Policy. We also retain information when necessary to comply with contractual and legal obligations,when we have a legitimate business interest to do so (such as improving and developing our Services,and enhancing the safety,security and stability of our Services),and for the exercise or defence of legal claims.

Specific Retention Periods by Data Category

Merchant account data: Retained for the duration of the active account. After account closure, retained for 7 years for tax, accounting and dispute resolution purposes, then deleted or anonymised.

EU consignee / return sender logistics data: Retained for 24 months after order fulfilment or return completion for logistics dispute resolution and platform audit purposes, then automatically deleted or anonymised.

Server access logs (IP address, browser data): Retained for 90 days for cybersecurity and troubleshooting purposes, then automatically purged.

Cookie data: Strictly Necessary Cookies expire at the end of the session or after 3600 seconds; Preference Functional Cookies expire after 3600 seconds.

The retention periods will be different depending on the type of information and the purposes for which we use the information. For example,when we process your information to provide you with the Service,we keep this information for as long as you have an account. This information includes your Profile Information,User Content,and Direct Messages. If you infringe our Guidelines or Terms,we may remove your Profile Information and/or User Content from public view immediately but keep your information as is necessary to process the infringement.

10.3 Personal Data Breach Notification

We maintain a personal data breach response plan to ensure timely detection, assessment and response to any data security incident.

In the event of a personal data breach, we shall notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification to the supervisory authority is not made within 72 hours, we shall provide reasons for the delay.

When a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we shall communicate the personal data breach to the data subject without undue delay. The communication shall describe the nature of the breach in clear and plain language and include at least:

the name and contact details of our DPO or other contact point where more information can be obtained;

the likely consequences of the personal data breach;

the measures taken or proposed to be taken to address the breach and mitigate its possible adverse effects.

We are not required to notify data subjects if:
(a) we have implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the breach (e.g. encryption rendering the data unintelligible);
(b) we have taken subsequent measures ensuring that the high risk to your rights and freedoms is no longer likely to materialise; or
(c) notification would involve disproportionate effort, in which case we shall make a public communication or similar measure.

We maintain a record of all personal data breaches, including facts relating to the breach, its effects and the remedial action taken, which shall be made available to the supervisory authority on request.

10.4 Our Global Operations and Data Transfers

To support our global operations,we share your information with members of our Corporate Group and other entities outside of your country of residence as described in the“How We Share Your Information”section. These entities are committed to using and storing information in compliance with applicable privacy laws and to implementing appropriate security measures to protect your information.For example,in order to store the data collected from you as described in the“What Information We Collect section,We will transfer the Personal Data collected from you to the China,where the information will be stored or processed.

When we transfer your information outside of the European Economic Area (EEA),the United Kingdom,or Switzerland,we ensure it benefits from an adequate level of data protection by:using European Commission approved standard contractual clauses under the GDPR for the transfer of information to all other third countries. We have signed EU Standard Contractual Clauses (SCCs) with EEA-based storage service providers to stipulate reciprocal data protection obligations.

All cross-border data is transmitted via end-to-end SSL/TLS encryption. A data isolation mechanism is implemented between domestic and overseas servers, together with minimum access permission control. Supplementary safeguards are deployed to address disparities in the legal regulatory frameworks of third countries.

You may submit a request at any time to review records of cross-border data transfers and breakdowns of storage locations related to your personal data. If you object to cross-border processing and request erasure, we will delete all your personal data stored on servers in the EU and China simultaneously, excluding logs required to be retained by law.

11.Younger Users

You must be at least 16 years old to use the Services. If you believe that we have information about someone younger than this,please contact us via the details set out in the“Contact Us”section below.

If you are the guardian of a teen,our Safety Centre contains information and resources to help you understand the Platform and the tools and controls you and your teen can turn on together.

12.Changes to Our Privacy Policy

It is our policy to post any changes we make to our privacy policy on this page.If we make material changes to how we treat our users' Personal Data,we will notify you by email to the primary email address specified in you account or through a notice on the website home page. The date the privacy policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you,and for periodically visiting our website and this privacy policy to check for any changes.

13.Contact us

The Company is the controller and responsible for your personal data. We have appointed a data protection officer (the "DPO") who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy or our privacy practice,including any requests to exercise your legal rights,please contact the DPO using the details set out below.

Full name of legal entity: Nanjing Yidaou Warehouse Co., Ltd.

Email address: liu@edaeu.com

Postal address: Room 413, No. 19, Bailongjiang East Street, Jianye District, Nanjing, Jiangsu, China

Our DPO operates independently from commercial teams and oversees all data processing compliance activities. You may contact our DPO on any matter related to the processing of your personal data and the exercise of your rights under the GDPR.

You have the right to make a complaint at any time to the supervisory authority for data protection issues in your jurisdiction. We would,however,appreciate the chance to deal with your concerns before you approach the supervisory authority so please contact us in the first instance.

We have appointed EDA WAREHOUSING DE GMBH as our representative in the European Union pursuant to Article 27 of the GDPR. You may contact our EU representative on all matters related to the processing of your personal data and the exercise of your rights under the GDPR at:

Name: EDA WAREHOUSING DE GMBH

Email: hao.jiang@eda-hamburg.com

Postal address: Industriestr. 114, 21107 Hamburg, Germany

For the avoidance of doubt, EDA WAREHOUSING DE GMBH, being established in Germany, does not require an Article 27 representative for its own processing activities as an entity established within the EEA.