FeiruLink commerce circuit

Privacy Policy

How Kunming Feiruling E-Commerce Co., Ltd. and the developer behind it, FeiruLink, collect, use and protect your information across the sites and systems we build, run and support.

Back to the Homepage

Contents of this policy

Use these links to move straight to the section you need. Every heading below also appears in the body with the same anchor.

  • 1. Introduction
  • 2. Who We Are and How to Reach Us
  • 3. What This Policy Covers
  • 4. Information You Give Us
  • 5. Information Collected Automatically
  • 6. Information from Other Sources
  • 7. How We Use Your Information
  • 8. Legal Bases for Processing
  • 9. When We Share Information
  • 10. Cookies, Pixels and Local Storage
  • 11. Cross-Border Data Transfers
  • 12. How Long We Keep Information
  • 13. How We Protect Information
  • 14. Your Rights and Choices
  • 15. Children Personal Data
  • 16. Third-Party Sites and Services
  • 17. Marketing and Unsubscribe
  • 18. Data Breach Response
  • 19. International Visitors Outside China
  • 20. Changes to This Policy
  • 21. Contacting the Privacy Owner

1. Introduction

This Privacy Policy explains the way FeiruLink, the developer and service mark operated by Kunming Feiruling E-Commerce Co., Ltd., treats personal information when you visit a site we made, use a platform we run, or ask us to build, refine or support an online commerce system. We want you to understand what data moves across our circuit and why, because trust is the voltage that keeps any commerce connection alive.

Reading in place of a handshake, this document is written in plain English. Whenever we say the Company, we mean Kunming Feiruling E-Commerce Co., Ltd.; whenever we say the Services, we mean the websites, storefronts, portals, integration work and engineering support we provide; and whenever we say you, we mean the person using them. FeiruLink is the developer name behind these Services and appears on our boards as the brand you meet first.

We encourage you to read the whole policy once. It sets out your rights, our duties and the few honest situations in which your data must travel across a border or to a processor on our behalf.

2. Who We Are and How to Reach Us

We are Kunming Feiruling E-Commerce Co., Ltd., a company active in computer systems design and related services, with registered details as follows: Room 402, Floor 4, Yinzuo Building, No. 219 Baoshan Street, Wuhua District, Kunming - 650000, China (CN). The website through which this policy is published is https://www.feirulink.buzz.

For any question about your data, our privacy choices or this policy itself, the fastest route is our care inbox. Write to care@feirulink.buzz and a member of the small team who understands both the policy and the platform will reply. You may also telephone us at +17248817363 during the office hours set out on our Contact page.

When you contact us we aim to answer plainly. If a request is complicated we tell you the steps and the time we need, and we never hide a rights request behind marketing language.

3. What This Policy Covers

This policy covers personal data collected on or through the Services that carry the FeiruLink brand, including our own marketing and company sites. It also covers data you send us directly by email, by phone, through our contact form, through a quote or through a project intake form.

Where we build or run a storefront or commerce system for a client, that client remains the operator of their own business and largely the controller of the data their customers give them. This policy describes our role as the Service provider. Where a specific client agreement gives you other assurances, that agreement governs those particular systems; we describe those roles in the Data and Order Analytics services and in the contracts behind them.

If a page links to a partner or an external processor, and that entity runs its own privacy notice, we expect you to read that notice as well. We list which of those situations occur in section 16.

4. Information You Give Us

You choose to share some data with us directly, and that sharing is always voluntary even when a field appears required for a specific task. Examples include the name and email you type into our contact form, the subject of your note, the content you write to us, your company name, your delivery town, and anything you attach for the purpose of letting us advise on your systems.

If you engage us for a build we gather what is needed to do the work well: catalogue structure, staff roles and permissions, administrator contacts, a billing address, an invoice contact and an account for our project workspace. We keep that set minimal and we do not ask for data we do not need.

Please be careful when you paste technical files or a full export into a support request. Before you send logs, dumps or spreadsheets to us, remove any rows that contain payment card numbers, national identity numbers, health details or the records of other people who have not consented to sharing. If you are unsure what a file holds, mask it first and we will ask only for what proves necessary.

5. Information Collected Automatically

Like nearly every service on the open web, our own sites collect basic technical signals when you load a page. We may record your internet protocol address, the type and version of your browser, your operating system, the device model and screen size, the referring page that brought you in, the rough region you appear to be in, the pages you looked at and roughly how long you stayed.

We gather these signals to keep the Services secure, to understand which pages are genuinely useful and to smooth out performance problems. Most of this record is kept in an aggregated form that does not single you out.

We do our best not to build detailed behavioural profiles of anonymous visitors to marketing pages. Where we do measure click flow, we usually measure the crowd rather than the individual, and we make an aggregate report instead of a personal file.

6. Information from Other Sources

In the course of honest business we combine a view of you from a few places. If you have written on an earlier channel, our support tool carries that history. If your company has engaged us before, our project record holds the notes your colleagues have shared with us in good faith.

We may also receive limited business contact data supplied by a directory, a partner or a tradeshow list, if that data was lawfully obtained and offered for outreach. We treat such records with the same care as data you give us directly.

We never buy lists meant for aggressive cold outreach, and we do not purchase personal data about children, about health, or about membership of sensitive categories. If a record arrives that we cannot trace to a lawful and honest origin we delete it.

7. How We Use Your Information

We use your information for the reasons that brought you to us in the first place, and for the few administrative reasons that follow from that. We reply to your questions, prepare a quote or a route plan, deliver the Services you paid for, invoice you correctly, provide support and keep you informed about the health of the build while the project is open.

Operationally, your contact data lets us run an account, enforce fair use of the Services, investigate misuse, respond to legal process, and keep our own records honest enough to defend a transaction if it is ever questioned. Where you have agreed, we send you the occasional note about a service we think genuinely fits the project we already discussed.

We do not sell personal data, and we state that plainly because some readers need to hear it in those words. We do not trade your records for advertising placements, and we do not hand your project files to a competitor so that others undercut your route.

8. Legal Bases for Processing

Where a data protection law such as the European Union General Data Protection Regulation applies to you, our processing rests on a set of recognised bases. When we deliver a Service you asked for, we rely on the performance of our contract with you or with the client that engaged us. When we protect a system, keep a ledger or answer to a court, we rely on our legitimate interests or on a legal obligation.

When we market to you purely because you gave us a card at an event, we rely on the overlap between that new lead and the legitimate interests a consultancy has in pursuing relevant work, subject to your right to object. When we ever ask for consent that stands alone, such as an optional newsletter subscription, we record that consent and we honour a later withdrawal at once.

You can object to a legitimate-interest purpose at any time. To learn which base applies to a particular activity, write to us and we will give you a plain answer rather than a clause maze.

9. When We Share Information

We share personal data only with the helpers our operations genuinely depend on, and only as far as the task demands. These helpers sit in clear groups: our hosting provider that runs the servers your pages and data live on; our email and calendar provider that lets us talk to you; our accounting application that keeps invoices straight; and occasionally a security or backup vendor.

When a client owns a storefront we run for them, we share operational telemetry with that client so they can run their own business and answer their own regulators and customers. We do not treat a client storefront as a private exhibit of the boss; so far as the privacy of that storefront customers is concerned we help the client meet our shared standards.

We also disclose data when the law compels us. That includes a valid court order, a lawful regulator request or a genuine emergency where action appears necessary to protect safety. Before we hand over a voluntary request we review it against the scope of the law and we prefer to tell you, where the law does not stop us from doing so.

10. Cookies, Pixels and Local Storage

Our own marketing and legal pages are kept intentionally light on trackers. We use only what is needed to run a secure, working site, such as small local storage entries that remember whether you closed a notice or agreed to a setting. These entries are not built to follow you around the open internet.

A few of the Services we operate for clients may place cookies, pixels and local storage on the stores they power. That is a decision made by the client for their own business, in line with their own policies and the consent banners they choose to run. We document the purpose of each storage item we help install and we keep our client notes clear about what is set and why.

Your browser gives you the controls. You can block third-party cookies, clear site data and refuse optional marketing storage without stopping the core checkout from working. If you notice an unusual or unexplained cookie on a service we run, report it to us so we can trace whether it belongs to a supplier or to something that should not be there.

11. Cross-Border Data Transfers

Commerce is a global activity and so is the effort to keep it running. When you visit a site engineered by the Company, or send us email, your data may leave your own country and be stored or processed in servers located elsewhere, including regions where Kunming Feiruling E-Commerce Co., Ltd. or its vendors operate.

Where data protection law requires an adequate safeguard for such a transfer, we put a suitable arrangement in place. That usually means a binding contract with standard contractual clauses, a lawful adequacy decision for a destination, or an equivalent scheme recognised in your jurisdiction. We review these safeguards when covered transfer mechanisms change.

We keep stays abroad to the minimum the work needs. If a report says which country a server sits in, we can explain that to you on request; the larger promise is that a transfer never loosens the protections this policy promises you at home.

12. How Long We Keep Information

We keep personal data only as long as the reason for keeping it is alive. Contact messages and quotes are retained while we are in conversation and for a short window after, so that a client who returns next season still meets a team that remembers their context. Account and billing records follow the rules we are bound by for tax, audit and dispute purposes.

Project working files are kept for the length stated in the relevant client agreement, and technical backups that make disaster recovery possible are held on a rolling schedule and then aged out. When an old backup reaches the end of its life we delete or securely overwrite it rather than keeping it for no purpose.

If you ask us to delete your data but the law still requires us to keep an invoice or a record of consent, we keep only that narrowed residue and make clear what remains and why, rather than deleting everything and pretending the limitation does not exist.

13. How We Protect Information

Security is engineered into the Services we deliver. Every page we deploy runs over an encrypted connection in transit, access to our own systems is kept to the few people who genuinely need it, and passwords and keys are stored in a way that resists casual reading. We treat two-step verification as the default for staff that touch client systems, not as an optional extra.

For client storefronts we apply the security practices common to well-run commerce: least-privilege staff accounts, careful logging, review before releasing a change to production and a prompt to update the underlying platform when a fix becomes available. We also restrict what support workers can copy out of a live store.

No method is perfect, and we say so plainly. What we promise is a defence in depth: layers between your records and the outside world, tested recovery so a restored system still works, and an honest process that reports findings to the right owner without burying them.

14. Your Rights and Choices

Depending on where you live, the law gives you a family of rights over your own data. You may ask us for a readable copy of the personal data we hold about you, ask us to correct an error, ask us to delete records you no longer want us to keep, ask us to stop a use you object to, and ask us to move the data the law lets you move to another provider.

You can exercise any of these by writing to care@feirulink.buzz. To keep your records safe we ask you to confirm who you are before we act, and we may ask for a little detail if your request could otherwise hand data to an imposter. We act on clear requests within the time the law allows and we tell you when we cannot and why, so refusal is never silent.

Where we process data for a client as their processor, your direct rights lie in the first place with that client as controller. We support the client by engineering the tools they need to honour your requests, and we answer to them as their processor rather than deciding unilaterally what belongs to you.

15. Children Personal Data

Our Services are not aimed at children, and we do not knowingly collect personal data from a child below the age set by the law where the child lives. We design FeiruLink intake forms and marketing pages for business owners and professionals, and we do not structure them to attract young users.

If you believe a child has given us personal data without a parent or guardian acting for them, tell us at once and we will work to remove it. Where the law asks for verified parental consent before a specific use, we will not rely on a guessed permission; we only proceed when that consent can be shown.

Keeping the storefront route free of children data also protects our clients, who must run their own age-gate where the goods they sell require one. That duty sits with the merchant and we help them meet it in the way their catalogue demands.

16. Third-Party Sites and Services

Every so often a service we provide must hand you onward to a third party for a reason that belongs to that party. A payment step may open at a gateway owned by the bank that authorises the card; an analytics widget may be served by an analytics provider; a social share button may belong to a network. Those third parties have their own policies that start when you leave our board.

We try to keep these handoffs honest and small. Where we can switch off a tracker to deliver a quieter page we do. When a client insists on a widely used widget because their sales team relies on it, we flag what that widget captures so the client can update their own notice.

A link to another site is not our endorsement of how that site treats you. Once a follow lands on a page that carries its own privacy commitment, read that commitment. We cannot answer for how a stranger page behaves several clicks off our rail.

17. Marketing and Unsubscribe

We keep our own marketing modest. When we send an email about project work we follow it with no more than a proportionate number of useful, genuinely relevant messages, and every such mail that is primarily promotional carries a plain way to stop future marketing messages.

Opting out of marketing never touches the service messages you need. We still send you a confirmation of an order, a note that a build reached its midpoint, an invoice reminder or an alert that a system that powers your shop is down. These are part of the Service, not an advertising layer, and they are not covered by a marketing unsubscribe box.

If you ask us to remove you from outreach we honour that quickly and we keep a small suppression record so we do not contact you again by mistake. Suppression records exist to obey your wish, not to annoy you, and they hold the minimum needed to make your silence stick.

18. Data Breach Response

We have a response plan ready for the kind of event no one wants to plan around. Should a breach of security expose personal data in a way that creates a real risk to the people it belongs to, we move to contain it first, then to understand whose records were touched and what was actually exposed rather than only what was claimed.

Where the law requires us to notify a supervisory authority or the affected people, we will do so without undue delay and in the clear, unvarnished terms this policy has used. That means telling you what happened, what kinds of data were involved, what we have done and what you can sensibly do, in plain words and without a legal fog to hide behind.

For storefronts we operate for clients, we report a finding to the client controlling that store promptly and we support them in meeting their own notification duties. A breach shared early is a breach we can help soften; a breach kept secret is how small harm becomes large distrust.

19. International Visitors Outside China

FeiruLink serves clients across borders, and our team and our servers often span more than one country. If you are reading this from a jurisdiction with its own data protection rules beyond our home region, we respect the obligations that the activity genuinely attracts rather than pretending geography does not exist.

Visitors in the European Economic Area, the United Kingdom and Switzerland may rely on the rights set out in section 8 and section 14, including the right to lodge a complaint with their own supervisory authority. We work with a representational and cooperating posture toward those authorities and we answer their lawful questions about our processing.

Whether the law that reaches you is generous or lean, we keep one steady line: fewer records, plain promises and a human to answer. That posture costs us very little and it protects everyone who relies on our circuit, wherever the circuit happens to run.

20. Changes to This Policy

The web changes and so does the law that governs it, so we may update this policy from time to time. When the change is only cosmetic or touches wording rather than behaviour we simply revise the page and note the new date. When the change narrows your rights or meaningfully widens what we collect, we will make the change visible rather than slip it past you.

We will date each version at the end of this page so you can tell at a glance what you are reading. A materially different policy will be announced on this site and, where we hold a live contact for a client project, we will write to that account as well because a change in how we treat data deserves a direct word.

Your continued use of the Services after a posted change means you accept the updated version, but you always keep the rights given to you by the version of law and the choices this policy itself has not taken away from you.

21. Contacting the Privacy Owner

The person at the other end of a privacy question is a human who reads the mail. Anything in this policy, any exercise of a right, or any worry about how we handle a record can be sent to care@feirulink.buzz or posted to our registered address: Room 402, Floor 4, Yinzuo Building, No. 219 Baoshan Street, Wuhua District, Kunming - 650000, China (CN). Our telephone number is +17248817363.

We treat a privacy question with the same seriousness as a security finding. Tell us what you have seen that troubles you, and we will give you a straight account of what happens next and by when. When you are not content with our answer, the law points you toward your own regulator, and we would rather you raise the matter openly than sit on a worry that keeps you from trusting your systems.

Thank you for reading this far. That you cared enough to read our policy is the first sign of the partnership this page was written to protect: a quiet, honest circuit between the people who build our commerce and the people who trust it with their data.

Version: 1.0. This policy was last revised and published by Kunming Feiruling E-Commerce Co., Ltd. on the current site date shown on our footer.

This Privacy Policy is part of the FeiruLink service from Kunming Feiruling E-Commerce Co., Ltd. Our legal pages in short, honest English live on our own board rather than in a distant vault.

Written and maintained by FeiruLink. Return to the homepage or read the companion Terms of Service.