QPG WORKSPACE / PRIVACY

Privacy & data handling

Effective 9 October 2026. QPG Workspace is operated by Zhongfu Intl Co., Limited for authorized internal store operations.

1. Purpose and scope

We use information to manage authorized stores, reconcile financial ledgers, control staff access and investigate operational or security issues. We do not sell information or use it for unrelated advertising.

2. Information processed

The current system stores staff names and account identifiers, password hashes, store identifiers, encrypted application credentials, order references, SKUs, financial amounts and audit records. Order references may be linkable to individuals in the originating platform. Sample records are labelled and separated from real records.

We do not currently collect buyer names, shipping addresses, telephone numbers, email addresses, shipping labels or receipt images. Imports must exclude these fields. Live Temu synchronization is not yet active. Collecting additional fields will require corresponding permissions, protection controls and an updated notice.

Essential session and security cookies support login and abuse prevention. Application sessions expire after eight hours; web-server security cookies may remain for up to ten days. These cookies are not used for advertising.

3. Authorization and access

Access requires authentication and is restricted by staff role and assigned store scope. Platform authorization takes place through Temu. Saving credentials locally does not validate an authorization, and deleting them locally does not revoke it at Temu.

4. Protection and service providers

Passwords are stored as one-way hashes. Application credentials and scheduled database backups are encrypted using AES-256-GCM; the encryption key is stored outside the database. HTTPS is used for browser and API communication. Database encryption does not mean every field is individually encrypted.

The production application is hosted by Amazon Web Services in Oregon, United States. Cloudflare provides DNS and, where enabled, reverse-proxy services; proxied requests may be processed through its global network. These services are used to operate and protect the workspace. Authorized staff may access it from their working locations.

5. Retention and deletion

Sessions expire after eight hours and expired sessions are cleared daily. Login-attempt records older than one day and application audit records older than 90 days are cleared daily. Scheduled encrypted database backups are retained for seven days.

Staff accounts and store credentials are kept while their authorized use continues. When use ends, the administrator disables access immediately and removes unnecessary personal data and credentials within 30 days. Requests cover associated ledger references and copies in backups; backup copies expire under the seven-day rotation and deleted data must not be reintroduced during recovery. Data subject to a documented legal retention requirement is restricted to that purpose; this is not a blanket exception for all records.

6. Access, correction and requests

To request access, correction, export or deletion, contact 3526861@gmail.com. An administrator verifies identity and authority, records the request, identifies relevant active and backup data, and confirms the result. Requests are handled without undue delay and under the applicable platform and legal requirements.

7. Incidents and updates

Suspected or confirmed breaches are escalated to the company administrator, contained and investigated. The administrator coordinates notification to Temu and, where required, affected people and competent authorities under the applicable deadlines. We review this notice when data use changes and review internal data-protection procedures at least quarterly.

8. Operator and contact

Zhongfu Intl Co., Limited
Privacy and security contact: 3526861@gmail.com.

This notice does not claim Temu approval or ISO/SOC certification.