1. Who we are
KingKung is a cross-border ecommerce SaaS platform operated by Zhengzhou Jindouyun Industrial Co., Ltd. (郑州金抖云实业有限公司). We provide software for advertising management, store management, reporting, and automation.
Registered office: Room 1001, Unit 1, Building 5, Mingxuan International, No. 1 Baizhuang Street, Zhengdong New District, Zhengzhou, Henan, China (河南省郑州市郑东新区白庄街1号铭轩国际5号楼1单元1001).
2. Purpose of processing
We process data to deliver KingKung SaaS features to business customers, including campaign management, store management, analytics, automation, troubleshooting, and security.
Amazon Data Protection — the sections below are written for Amazon Ads API and SP-API reviewers.
3. Amazon Data Protection
3.1 Amazon OAuth
Access to Amazon Ads API and/or Selling Partner API (SP-API) requires official Amazon OAuth (Login with Amazon / Amazon authorization). We do not collect, buy, sell, or store Amazon passwords. Developer credentials are not shared with unauthorized parties.
3.2 Amazon Data Usage
Amazon data is accessed only within the permissions granted by each customer through Amazon OAuth, and is used only to provide the requested software features:
- Account metadata — connect the correct seller / Ads profile
- Campaign structure — manage Ads campaigns in granted scopes
- Store-management data — orders, inventory, listings, catalog, and operational reports in granted SP-API roles
- Fulfillment and logistics data — FBA/AWD inventory, inbound and replenishment status, shipping options, labels, and tracking
- Financial and pricing data — settlement, fee, transaction, financial-event, offer, and seller-pricing information for reconciliation and authorized price workflows
- Brand and seller insights — approved search, catalog, operational, and performance insights for authorized sellers and brand owners
- Certification data — applicable sustainability certification information and status for authorized product listings
- Buyer contact data (Restricted / PII) — buyer name, shipping address, and phone number where Amazon provides it for the seller’s own merchant-fulfilled orders, used only for pick, pack, shipping-label, delivery, return, and after-sales workflows; never used for marketing, advertising, profiling, buyer solicitation, resale, or cross-customer sharing
- Communications and solicitations — only seller-authorized order-related communications and Amazon-approved solicitation types for eligible orders; Restricted buyer PII is not used directly for solicitation workflows
- Performance metrics — reporting and optimization
- Operational logs — security and audit
Amazon data is never shared across customers. We do not sell Amazon data or use it for unauthorized interest-based advertising.
3.3 Amazon Data Retention
Buyer PII from an order is retained only for the connected seller’s fulfillment workflow and is permanently deleted no later than 30 days after order delivery. Non-PII Amazon data is retained only while strictly necessary to provide an enabled feature, with the purpose and retention period documented internally. Security logs are designed not to contain buyer PII.
3.4 Amazon Revocation
Customers may revoke KingKung’s access at any time through Amazon’s authorization management. When authorization is revoked, API access tokens are invalidated and platform access for that account is disabled.
3.5 Amazon Deletion
We permanently and securely delete all live instances of Amazon Information within 30 days after the earliest of: an Amazon deletion notice; customer revocation or termination; loss of authorization; the data no longer being required; or termination of our participation in the applicable Amazon service. Retention beyond that point is limited to documented legal, tax, or regulatory obligations. Backup copies expire under the same retention schedule. Deletion is logged; see security.html for disposal controls.
4. Security
Role-based access, least privilege, per-customer isolation, audit logs, encrypted token storage, and HTTPS for all KingKung web traffic. Detailed security controls — network protection, asset management, encryption at rest and in transit, backups (RTO/RPO), logging and monitoring, incident response, credential management, and vulnerability management — are published at security.html.
5. Sharing
We do not sell customer or Amazon data. We may use infrastructure providers strictly as needed to host and operate the SaaS platform, under confidentiality and security controls, or disclose information when required by law or platform investigations.
6. Website and quote-request data
When a visitor requests a quote, we process the company name, contact name, business email, optional phone number, country or region, store count, advertising-spend range, requested seats, selected modules, and notes. We use this information only to prepare and follow up on the requested quote, prevent abuse, and keep necessary business correspondence. Submitting the form opens the visitor’s email application; it does not create an account, place an order, or incur a fee.
Quote-request data is retained only while the inquiry is active and for up to 12 months afterward, unless a contract is signed or a longer period is required for legal, tax, or dispute purposes. Visitors may request access, correction, or deletion using the contact details below.
7. Other platforms
Where KingKung connects to Shopee, Lazada, TikTok, Meta, or Google under those platforms’ approved programs, the same principles apply: official authorization only, least privilege, no password collection, and use limited to the agreed software features.
8. Contact & requests
- Email: rentianyu02@jdy.kingkungmeta.com · subject “Privacy/Security Report”
- Phone: +86 182 0397 7118 · Mon–Fri 09:00–18:00 (UTC+8)
- Acknowledgement target: within 3 business days
9. Policy updates
We may update this policy to reflect product or legal changes. The “Last updated” date above will change accordingly.