Vataxus ("we", "our", or "us") provides sales tax reporting, compliance, and financial data synchronization services for e-commerce merchants.
Vataxus("我们")为电商商家提供销售税申报、税务合规以及财务数据同步服务。
This Privacy Policy explains how we collect, use, process, and protect information obtained through our website, applications, and authorized integrations with e-commerce platforms, including Shopify and Amazon (the Amazon Selling Partner API / SP-API). It applies to all merchants who connect a sales channel to Vataxus.
本隐私政策说明我们如何收集、使用、处理和保护通过我们的网站、应用程序以及与 Shopify、Amazon(Amazon Selling Partner API / SP-API)等电商平台的授权集成所获得的信息。本政策适用于所有将销售渠道连接至 Vataxus 的商家。
Where information is obtained through a platform, we also comply with that platform's data protection requirements, including the Amazon Acceptable Use Policy and Data Protection Policy and Shopify's Protected Customer Data requirements. In case of conflict, the stricter requirement applies.
当信息通过平台获取时,我们同时遵守该平台的数据保护要求,包括 Amazon 可接受使用政策与数据保护政策(Acceptable Use Policy & Data Protection Policy) 以及 Shopify 受保护客户数据(Protected Customer Data) 要求。如存在冲突,以更严格的要求为准。
When you authorize a platform connection, we store OAuth access and refresh tokens (e.g., Amazon LWA tokens, Shopify access tokens). We never receive or store your platform account password.
当您授权平台连接时,我们会存储 OAuth 访问令牌与刷新令牌(例如 Amazon LWA 令牌、Shopify 访问令牌)。我们绝不会接收或存储您的平台账户密码。
To calculate tax jurisdiction and prepare filings, we access only the minimum customer information necessary, which may include personally identifiable information ("PII"):
为判断税务辖区并准备申报,我们仅访问所需的最少客户信息,其中可能包含个人身份信息("PII"):
We practice data minimization: we do not request or retain customer names, payment card data, phone numbers, or email addresses unless strictly required by a tax authority. We do not use customer data for advertising or marketing, and we never sell it.
我们践行数据最小化原则:除非税务机关严格要求,我们不会请求或保留客户姓名、支付卡数据、电话号码或电子邮箱。我们不会将客户数据用于广告或营销,也绝不出售。
We use collected information solely to provide the tax and compliance service you have requested, specifically for:
我们仅将收集的信息用于提供您所请求的税务与合规服务,具体包括:
We do not use platform or customer data for any purpose other than those listed above, and never for advertising, profiling, resale, or training of unrelated systems.
我们不会将平台或客户数据用于上述以外的任何目的,绝不用于广告、用户画像、转售或训练无关系统。
Where the GDPR or similar laws apply, we process data on the basis of: (a) performance of our contract with the merchant; (b) compliance with legal and tax obligations; and (c) our legitimate interest in operating and securing the service. The merchant acts as the data controller for its customer data; Vataxus acts as a data processor / service provider.
在适用 GDPR 或类似法律的情况下,我们基于以下依据处理数据:(a) 履行与商家的合同;(b) 遵守法律与税务义务;(c) 我们运营和保护服务的合法利益。商家是其客户数据的数据控制者,Vataxus 作为数据处理者/服务提供商。
We do not sell personal data. We share data only:
我们不会出售个人数据。我们仅在以下情况下共享数据:
Sub-processors are permitted to use data only to provide services to us and are prohibited from using it for their own purposes.
子处理方仅可为向我们提供服务而使用数据,禁止将其用于自身目的。
We implement technical and organizational measures aligned with the Amazon Data Protection Policy and Shopify security requirements, including:
我们采取符合 Amazon 数据保护政策及 Shopify 安全要求的技术和组织措施,包括:
We retain data only as long as necessary to provide the service and to meet legal obligations. Consistent with the Amazon Data Protection Policy, we delete customer PII within 30 days after it is no longer needed to perform the service, except where retention is required to comply with tax, accounting, or other legal obligations — in which case we retain only the data required, for the legally mandated period, and then securely delete it.
我们仅在提供服务及履行法律义务所需的期间内保留数据。依照 Amazon 数据保护政策,在客户 PII 不再用于履行服务后,我们将在 30 天内删除,但为遵守税务、会计或其他法律义务而需要保留的除外——此时我们仅保留所需数据,保留至法律规定的期限,随后安全删除。
We maintain an incident response plan. In the event of a confirmed security incident affecting platform or customer data, we will investigate, remediate, and notify affected merchants and the relevant platform without undue delay. As required by Amazon, we will notify Amazon within 24 hours of confirming a breach involving Amazon Information, and will cooperate with required investigations.
我们制定了事件响应计划。如发生涉及平台或客户数据的已确认安全事件,我们将进行调查、补救,并在不无故拖延的情况下通知受影响的商家及相关平台。按照 Amazon 要求,我们将在确认涉及 Amazon 信息的泄露后 24 小时内通知 Amazon,并配合必要的调查。
Our application accesses Shopify merchant data through Shopify-authorized APIs and OAuth permissions granted by the merchant, requesting read-only scopes limited to orders and products. We honor Shopify's mandatory compliance webhooks — customers/data_request, customers/redact, and shop/redact — to support customer data access and deletion requests and to remove data after app uninstallation.
我们的应用程序通过 Shopify 授权 API 和商家授予的 OAuth 权限访问 Shopify 商家数据,仅请求限于订单与商品的只读权限。我们遵守 Shopify 强制的合规 Webhook——customers/data_request、customers/redact 和 shop/redact——以支持客户数据访问与删除请求,并在应用卸载后删除数据。
Our application accesses Amazon selling account data through the Amazon Selling Partner API (SP-API) under authorization granted by the seller via Login with Amazon (LWA). We use Amazon Information solely to provide the tax and compliance service, in compliance with the Amazon Acceptable Use Policy and Data Protection Policy. A seller may revoke access at any time from Amazon Seller Central, after which we cease access and delete the associated tokens.
我们的应用程序通过 Amazon Selling Partner API(SP-API),在卖家经由 Login with Amazon(LWA)授权的前提下访问 Amazon 销售账户数据。我们仅将 Amazon 信息用于提供税务与合规服务,并遵守 Amazon 可接受使用政策与数据保护政策。卖家可随时在 Amazon Seller Central 撤销授权,撤销后我们将停止访问并删除相关令牌。
Subject to applicable law (including the GDPR and the CCPA/CPRA), merchants and data subjects may request to:
在适用法律(包括 GDPR 与 CCPA/CPRA)范围内,商家及数据主体可请求:
For customer-level requests originating from a Shopify or Amazon shopper, please contact the merchant (the data controller); we will assist the merchant in fulfilling the request. Submit requests to the contact below; we respond within the timeframe required by law.
对于来自 Shopify 或 Amazon 购物者的客户级请求,请联系商家(数据控制者);我们将协助商家履行该请求。请通过下方联系方式提交请求,我们将在法律规定的期限内回复。
Data may be processed in countries other than where you or your customers are located. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
数据可能在您或您客户所在地以外的国家/地区进行处理。在需要时,我们对跨境传输采用适当的保障措施(如标准合同条款)。
Our website uses only essential cookies needed for authentication and security. Our service is intended for businesses and is not directed to children under 16; we do not knowingly collect children's data.
我们的网站仅使用认证与安全所需的必要 Cookie。我们的服务面向企业,不面向 16 岁以下儿童;我们不会有意收集儿童数据。
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above and, where appropriate, by notifying merchants.
我们可能会不时更新本隐私政策。重大变更将通过更新上方的"最后更新"日期予以体现,并在适当情况下通知商家。
If you have questions or requests regarding this Privacy Policy or your data, please contact:
如果您对本隐私政策或您的数据有任何疑问或请求,请联系: