1. Introduction and scope
Cloudray (HK) Limited (鐳雲(香港)有限公司), Hong Kong Business Registration No. 72775485, operates CloudrayAI. In this policy, “Cloudray”, “we”, “us” and “our” mean that company. Our correspondence address is Office 5, 8/F, Mega Cube, 8 Wang Kwong Road, Kowloon Bay, Kowloon, Hong Kong.
This policy explains our handling of personal information through cloudrayai.com, www.cloudrayai.com, the CloudrayAI application, and related onboarding, reporting, reconciliation and support services. It applies to website visitors, customer representatives, account users and Amazon selling partners who authorize our application. It does not govern Amazon's own websites or processing.
We determine the purposes of processing our own website, account, billing and business-contact information. When handling Selling Partner Data on a customer's behalf, we act as that customer's processor to the extent applicable data protection law recognizes that role. Our Data Processing Addendum (“DPA”) governs that processing. A business record may also be personal information if it identifies or can be linked to an individual.
This policy takes effect on the date above. Section 12 explains how we communicate changes. This policy provides information about processing; it is not a request for blanket consent to all processing.
2. Information we collect
Information you provide. We collect the email address used to invite you to an account and information you send during onboarding or support, such as your name, company, contact details, questions and relevant business records. Where we enter a paid engagement, we collect the billing contact, invoice details and payment-status information needed to administer it. Please do not send Amazon passwords, buyer contact information, payment-card credentials or unnecessary personal information in support requests.
Account and authentication information. Accounts are invitation-only. There is no self-service registration or password-based CloudrayAI login. We process one-time login links, store a SHA-256 digest of the login token rather than the original token, and maintain session information. We also process the account-to-seller connection, authorization status and credentials needed for the Amazon authorization flow.
Technical information. Server access logs may contain IP addresses, request times, requested resources, response codes and browser or device information supplied by the browser. Cookies or similar session technologies support authentication and requested functionality. Section 9 and the Cookie Statement explain these technologies. External resources used by a page may also receive connection information when your browser requests them.
Amazon information. After authorization, we retrieve the categories described in section 3, including seller identifiers and marketplace or seller-account information needed to connect the correct stores. We do not request Restricted Roles or retrieve buyer names, shipping addresses, telephone numbers or email addresses. This does not mean that we collect no personal information: seller contact details, identifiable account information and technical identifiers can be personal information.
3. Amazon Selling Partner data
“Selling Partner Data” means information made available through the Amazon Selling Partner API (“SP-API”) for the seller's authorized services, including related seller-specific reports we produce. Our requested roles and their purposes are:
| SP-API role | Data accessed | Purpose | Availability |
|---|---|---|---|
| Finance and Accounting | Financial event groups, transactions, settlement reports | Produce profit, fee and settlement reporting | Current service scope |
| Amazon Fulfillment | FBA inventory summaries, FBA inventory reports, inbound plans | Track FBA stock and inbound shipments for reconciliation | Current service scope |
| Inventory and Order Tracking | Orders, order items, merchant listings data | Reconcile orders against inventory and cost records | Current service scope |
| Selling Partner Insights | Marketplace participations, seller account information | Discover active marketplaces to scope data pulls | Current service scope |
| Product Listing | Catalog items, product fees | Listing-health and fee analysis | Planned |
| Pricing | Product pricing data | Price monitoring and repricing analytics | Planned |
| Brand Analytics | Search-term and promotion-performance reports | Traffic and promotion analytics | Planned |
The table describes service scope, not a representation that Amazon has approved a public application or every requested role. Planned features are not currently offered. We will not retrieve data for a planned feature until that feature is available, the access is necessary, and applicable Amazon approval and customer instructions are in place. Marketplace coverage depends on the seller's eligibility and available Amazon functionality.
We use each seller's data only to deliver the services to that seller, within its express written instructions and the permitted purposes of Amazon's applicable policies. We do not sell Selling Partner Data, use it to compete with the seller, disclose it to other sellers for their purposes, or combine it across authorized sellers' businesses or customers to provide or sell to any party. Removing names or aggregating records does not create an exception to these restrictions. Necessary service-provider access is subject to section 7 and the DPA.
You grant access through Amazon's official OAuth authorization flow. We do not request your Amazon username or password. You can revoke authorization at any time in Seller Central under Apps and Services → Manage Your Apps, using Amazon's current equivalent menu if its interface changes. Revocation ends our authority to retrieve further data. We cease further access and apply the deletion rules in section 6.
Our handling of Selling Partner Data is subject to the applicable Amazon Data Protection Policy, Acceptable Use Policy and Solution Provider Portal Agreement. These restrictions are not waived by customer consent.
4. How we use information
We use information for the following separate purposes:
| Purpose | Information involved | Basis where EU or UK data protection law applies |
|---|---|---|
| Invite users, authenticate access and administer accounts | Contact details, token digests, sessions and account records | Performance of a contract with an individual customer; legitimate interests in administering a business customer's authorized users |
| Deliver seller-specific reports and reconciliation | Authorized Selling Partner Data and customer-provided business inputs | Processing on the customer's documented instructions under the DPA; the customer determines the lawful basis for its personal data |
| Respond to enquiries and support requests | Contact details and relevant correspondence | Pre-contractual steps requested by an individual, contract performance, or legitimate interests in business support, as appropriate |
| Issue invoices and administer payment | Billing contacts and transaction records | Contract performance or business-administration legitimate interests; legal obligations for tax records |
| Diagnose faults, protect accounts and maintain the website | Minimized technical logs and authentication events | Legitimate interests in a secure, functioning service, subject to individuals' rights; applicable legal obligations |
| Comply with legal obligations and respond to lawful requests | Information relevant to the obligation or request | The applicable legal obligation; legitimate interests in legal claims where permitted |
We do not use Amazon data or materials, including derived seller-specific outputs, to train, fine-tune, develop or improve large language, multimodal or machine-learning models, and do not permit service providers to do so. Seller authorization does not override this restriction. Any model-based inference used to deliver a feature must remain within the seller's instructions, be described in the service description, and satisfy our provider and transfer requirements before activation. This paragraph is not a representation that an AI feature is currently enabled.
We do not use Selling Partner Data for general product research, advertising, cross-customer benchmarking or model development. We may use separate, minimized website diagnostics to correct faults and improve usability, without incorporating Selling Partner Data. We send optional promotional emails only where permitted by law and obtain consent where required. You may opt out through the message's unsubscribe method or by emailing us; necessary account and security messages will continue.
5. How we store and protect data
The public website is hosted on Tencent Cloud in Hong Kong. Our product and engineering team is based in Nanjing, Jiangsu, mainland China, and is directly employed by Cloudray (HK) Limited. The Service Provider and Processing Location Schedule identifies the systems and providers used for customer data, their locations and permitted access. The website's hosting location alone should not be understood as the location of every customer-data system. We provide the applicable schedule before enabling a customer's connection.
The website uses HTTPS. Stored Amazon refresh tokens are encrypted using Fernet authenticated encryption. Secrets are read from server environment variables rather than embedded in the source repository, and the production service refuses to start if required keys are absent. Login-token originals are not stored in the database; their SHA-256 digests are stored instead. The OAuth flow uses a one-time, server-stored state value and rejects mismatches. Database queries are parameterized. Application logging excludes access tokens, refresh tokens, authorization codes and application secrets. Availability monitoring can attempt recovery and issue alerts.
These statements describe particular controls and do not represent that every business record is encrypted at rest. Access by personnel must be limited to the work necessary to serve the relevant customer, under confidentiality obligations and approved access arrangements. Personnel authentication and additional controls applicable to a customer engagement must meet the applicable Amazon and legal requirements before that processing starts.
If we detect an actual or suspected security incident involving Amazon Information, we will notify Amazon at security@amazon.com within 24 hours of detection. We will investigate, contain and address the incident and preserve appropriate evidence. Where we process affected personal data for a customer, we will notify that customer without undue delay and in accordance with the DPA, and provide updates as facts become available. We will make notifications to authorities and affected individuals when required by applicable law. We do not speak on Amazon's behalf unless it expressly requests this in writing. Security reports may be sent to the contact in section 13 at any time.
6. Data retention and deletion
We retain Selling Partner Data only for as long as, and to the extent, it is strictly necessary to provide the authorized services or meet an applicable legal, tax or regulatory obligation. Active authorization alone does not justify keeping unnecessary data.
We will permanently and securely delete all relevant Selling Partner Data, including all live, online or network-accessible copies, within 30 days of the earliest of: (a) Amazon giving notice requiring deletion; (b) the seller revoking authorization, terminating the service, closing the account or otherwise removing our access; (c) our determining that we are no longer authorized or entitled to access or process the data; or (d) termination or expiry of our participation in the relevant Amazon services. We will retain only the specific information that an applicable legal, tax or regulatory requirement obliges us to keep, solely for that requirement and for no longer than it requires. That exception does not permit continued analytics or service use. We will securely delete the retained information when the requirement ends.
The same deadline covers seller-specific derived reports, exports held by us and copies held for us by providers. We will not use a backup cycle to extend the deadline: all copies under our control, including backups, must be deleted or rendered irrecoverable within it unless the stated legal exception applies. We invalidate and delete connection credentials when they are no longer authorized or required; the deletion deadline is an outer limit, not permission to continue access.
For information separate from Selling Partner Data, our retention rules are:
| Category | Retention rule |
|---|---|
| Account email and profile | While the account is needed; delete within 30 days after closure, except specific mandatory records |
| Login-token digests and sessions | Only for their authentication or session purpose; invalidate expired or used credentials and remove residual records within 30 days after expiry or account closure, whichever is earlier |
| OAuth temporary records | Cleaned periodically under the configured retention period, normally seven days; any shorter required deletion deadline controls |
| Ordinary support correspondence | Up to 12 months after the request is resolved, unless an earlier deletion request applies or a specific legal obligation requires longer; embedded Selling Partner Data follows the stricter rule above |
| Website security and access logs separate from Selling Partner Data | Up to 12 months, limited to necessary diagnostic and security records, subject to applicable minimum legal retention requirements |
| Our own invoices and business accounting records | Seven years where required by Hong Kong tax law, or longer only where a particular mandatory requirement applies; this is not a seven-year retention rule for sellers' Amazon records |
Email rayner@cloudrayai.com to request account closure or deletion. We may verify the request through the account email or proportionate evidence of authority. We do not require your Amazon password. We will identify any mandatory retention exception and its duration where legally permitted. Deletion may be performed through controlled manual procedures; we do not represent that it is automatic.
7. Sharing with third parties
Our employees, agents and contractors may process or access information when necessary to provide the authorized services, support, maintenance or security. Access must be limited to the relevant work. A separate employing company or contractor that processes customer data is treated as a service provider or subprocessor where the law requires, rather than assumed to be part of Cloudray merely because it is affiliated with us.
The Service Provider and Processing Location Schedule identifies hosting and other service providers, the data involved, purposes and locations. Tencent Cloud provides the public website's Hong Kong hosting. The public website currently loads no external website resources: fonts and styling are served from cloudrayai.com itself. Any external website resource would involve separate requests from a visitor's browser and would be described in that schedule. Such resource providers are not automatically authorized to receive Selling Partner Data.
We permit disclosure of Selling Partner Data only where necessary for acceptable activities for the authorizing seller and permitted by applicable Amazon policies and law. Providers must be subject to appropriate written restrictions, confidentiality, security, use, deletion and onward-transfer requirements. Customer authorization for subprocessors and changes is governed by the DPA. There is no general right to disclose seller data to affiliates or unrelated parties. We do not sell it or share it for advertising.
We may disclose the minimum information legally required in response to a binding legal obligation, informing the customer where permitted and assessing available protections. A merger, acquisition or asset sale is not an unrestricted permission to disclose or transfer Selling Partner Data. Any continuation or transfer must preserve the permitted purpose, required authorizations and applicable Amazon and data protection requirements; otherwise the data must be excluded or deleted. Business due diligence should use information that does not expose seller records.
8. International data transfers
Hong Kong website hosting and access by our team in mainland China may involve processing outside your country. Further locations must be identified in the applicable Service Provider and Processing Location Schedule before the relevant processing begins. Amazon may separately process information through its regional infrastructure under its own terms.
Where a transfer is subject to EU or UK transfer restrictions, we require a valid mechanism before it begins. Depending on the parties' roles and the applicable law, this may include the European Commission's applicable standard contractual clauses and, for UK transfers, an approved UK Addendum or International Data Transfer Agreement, together with the required transfer assessment and supplementary safeguards. We do not treat acceptance of this policy as a substitute for those arrangements or claim that such instruments have already been signed for every data flow.
Where mainland China's personal information rules apply, relevant notices, lawful grounds, impact assessments and any required outbound-transfer procedures must also be satisfied. The DPA and transfer schedules govern customer processing. You may request information about relevant safeguards and a copy, subject to necessary redactions, by contacting us.
9. Cookies and similar technologies
CloudrayAI uses session technologies to remember authenticated access and support functionality you request. Strictly necessary technologies are used only for their necessary purpose. Blocking them in your browser may prevent login or other requested functions. Their names, providers, purposes and lifetimes are described in our Cookie Statement.
If optional analytics, advertising or other non-essential technologies are introduced, we will explain them and obtain prior consent where required. You may refuse or withdraw that consent without losing functionality that does not require them. Browser settings can also remove stored cookies. Continuing to browse is not treated as consent to optional tracking.
External font and script requests can disclose an IP address and browser information even if no cookie is set. The Cookie Statement describes this distinction. Visiting Amazon during authorization is governed by Amazon's own cookie notices.
10. Your rights and choices
Depending on the law applicable to you and the processing, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, and withdraw consent without affecting earlier lawful processing. You may object to direct marketing at any time. Certain rights are qualified by legal exceptions; we explain any refusal and available review route where required.
Where California privacy law applies, relevant rights may include knowing categories and specific pieces of personal information, correction, deletion, opting out of sale or sharing, limiting qualifying uses of sensitive information, and non-discrimination for exercising rights. We do not authorize sale or advertising sharing of Selling Partner Data. An authorized agent may submit a request with appropriate evidence of authority.
Where mainland China's Personal Information Protection Law applies, relevant rights include knowing and deciding about processing, restricting or refusing processing, access and copying, correction, deletion and an explanation of processing rules. Hong Kong law provides applicable access and correction rights.
Send requests to rayner@cloudrayai.com. We will use proportionate identity checks and respond within the applicable statutory period: normally one month under EU or UK GDPR, 45 days under the CCPA, and 40 days for relevant Hong Kong access or correction requests, subject to permitted extensions and exceptions. For other requests we aim to respond within 30 days or any shorter mandatory period. We will explain an extension before the original deadline where required.
When we process data for a seller, we will refer the request to that seller and assist it under the DPA. You may also complain to the appropriate authority, including your EEA supervisory authority, the UK Information Commissioner's Office, Hong Kong's Privacy Commissioner for Personal Data, the California Privacy Protection Agency or competent mainland Chinese authority, as applicable. You need not contact us first where the law allows a direct complaint.
11. Children's privacy
The services are business services intended for adults aged 18 or older with authority to act for a selling business. They are not directed to children. If we learn that a child has provided personal information through an account or enquiry, we will investigate, disable any ineligible account and delete the information unless a specific legal duty requires retention. Contact us if you believe this has occurred.
12. Changes to this policy
We display the effective and last-updated dates at the top of this policy. We will give at least 30 days' advance notice of material changes through an email to account contacts or a prominent service notice, unless a legal or urgent security requirement requires earlier action. In that case, we will explain the change as soon as reasonably practicable. We will obtain fresh consent where the law requires it. A policy change does not itself expand a seller's processing instructions or authorize a prohibited Amazon-data use. Previous versions can be requested by email.
13. Contact us
Privacy enquiries and rights requests: rayner@cloudrayai.com — please use the subject “Privacy”.
Security incidents: rayner@cloudrayai.com — please use the subject “Urgent security incident”. This shared address routes security reports to our incident contact; it is not an Amazon address.
Company: Cloudray (HK) Limited, BR No. 72775485.
Postal address: Office 5, 8/F, Mega Cube, 8 Wang Kwong Road, Kowloon Bay, Kowloon, Hong Kong.
Telephone: +852 5315 0045 or +86 133 0516 3900.
Ordinary support hours: Monday–Friday, 09:00–18:00, UTC+8; we aim to respond within one business day. These ordinary support hours do not extend security-notification deadlines.
Where we appoint a statutory data protection officer or an EU or UK representative for relevant processing, we will publish its contact details here before that processing requires the appointment. Our general privacy mailbox does not itself constitute such an appointment.