GuardPanda

GuardPanda · Merchant resources

Data Processing Terms

Last updated: September 27, 2026

These terms supplement the Terms of Service when GuardPanda processes personal information on a merchant’s behalf. They describe the service’s processing instructions and responsibilities; they do not replace any separate cross-border transfer agreement required by law.

1. Scope and roles

The merchant determines the purposes and lawful basis for its customer-data processing. 徐敏学 (Minxue Xu), China, processes that data to provide GuardPanda under the merchant’s documented instructions, including app configuration, uploads, exports, and verified support requests. Processing covers customers, merchant staff, and persons referenced in submitted evidence for the duration of the service and the retention described in the Privacy Policy.

2. Processing details

Operations include collecting authorized Shopify data, storing source versions, retrieving shipment and IP-country information, organizing cases, rendering PDFs, and responding to access and deletion requests. Data can include names, shipping addresses, order IP addresses, order and customer IDs, masked payment details and verification outcomes, tracking records, staff notes, uploaded communications, and merchant-entered case information. No full card numbers or actual security codes should be provided.

3. Instructions, confidentiality, and security

We process customer data to deliver the service and follow lawful instructions, unless applicable law requires otherwise. Authorized personnel must keep it confidential and use access only for service operations. We maintain appropriate access controls, encrypted transport, authenticated store boundaries, and webhook verification and review security measures as the service changes. We will inform the merchant if we believe an instruction violates applicable data-protection law.

4. Service providers

Current providers are AWS (application hosting, database, delivery and operational infrastructure; primary deployment in United States/Ohio), 17TRACK (tracking numbers and shipment events), and IPinfo (order IP addresses for country/network enrichment). Shopify is the platform and source system under the merchant’s separate relationship with Shopify. Support correspondence is received at a Gmail address and may therefore be processed by Google; avoid sending complete evidence packages through ordinary support email.

The merchant authorizes use of these providers for the stated service functions. We will give notice of material changes to this list and an opportunity to raise data-protection concerns before a new provider begins relevant processing. Where applicable, we will require appropriate contractual protections. Required provider contracts and transfer safeguards must be established before regulated processing that depends on them.

5. Assistance and incidents

We assist merchants with verified data-subject requests, relevant security information, and data-protection assessments to the extent required by applicable law and reasonably available to us. If we become aware of a personal-data breach affecting the merchant’s data, we will notify the merchant without undue delay and provide available information needed to respond. Contact x17661959@gmail.com for privacy and security matters.

6. Return, deletion, and verification

Merchants can export evidence before uninstalling and request further data return or deletion. We process Shopify compliance webhooks and review unlinked evidence, backups, and applicable provider copies when fulfilling deletion instructions. Minimal suppression identifiers may be retained to prevent re-import, and legally required retention remains subject to applicable restrictions. We make appropriate information about our compliance available and cooperate with reasonable verification requests subject to confidentiality and protection of other merchants’ data.

7. International transfers

The operator is in China and the primary AWS deployment is in the United States. Other providers may operate internationally. Where data-protection law requires standard contractual clauses or another transfer mechanism, the parties must arrange the appropriate mechanism and assess the transfer before processing affected data. These terms do not assert that installing the app automatically executes standard contractual clauses or constitutes consent for every transfer.