Last Updated: 2026/07/09
Company Registration Information
- Company Name: 万宁市稳恰英商贸有限公司
- Legal Representative: 朱兴标
- Phone: +86 16521681221
- Email: service@mail.vwxyzac.com
- Date of Establishment: 2026-03-31
- Unified Social Credit Code: 91460000MAKAKQTFX7
- Company Address: 海南省万宁市东澳镇中海神州半岛一期二区T30楼1单元14层1406房号
万宁市稳恰英商贸有限公司 (“we,” “our,” or “the store”) attaches great importance to the security of customer information. We are committed to protecting all personal information and transaction data you provide when shopping on our website, registering an account, or communicating with us. This policy explains the technical, administrative, and physical measures we use to safeguard your information and our commitment to data protection.
We strictly comply with applicable U.S. data protection laws and regulations, including relevant guidelines from the Federal Trade Commission (FTC). If you have any questions about this policy, please contact us:
- Phone: +86 16521681221
- Email: service@mail.vwxyzac.com
- Address: 海南省万宁市东澳镇中海神州半岛一期二区T30楼1单元14层1406房号
- Business Hours: Monday through Friday: 9:00 AM to 6:00 PM (Online chat and email support,Saturday through Sunday: 10:00 AM to 4:00 PM (Limited email support only
2. Technical and Administrative Security Measures
We employ multi-layered security measures covering data transmission, storage, access control, and incident response. Key measures include:
2.1 Transmission and Storage Encryption
- All customer data transmissions (e.g., order submission, account login) use SSL/TLS 256-bit encryption to prevent interception or tampering.
- Payment information (e.g., credit card numbers) is encrypted immediately after submission. We do not store full credit card numbers, CVV codes, or expiration dates; only the payment method type and transaction outcome are retained for order verification.
- Customer passwords are stored using salted hash algorithms, ensuring they cannot be reversed even if the server is compromised.
2.2 Access Control
- Only authorized employees who have completed security training may access customer information, on a least-privilege basis (i.e., only the data necessary for their job function).
- All system operations are logged and reviewed periodically for anomalous access.
2.3 Payment Security
- Our payment partners (Visa, MasterCard, American Express,PayPal, Klarna) are all PCI DSS (Payment Card Industry Data Security Standard) compliant, ensuring safe transaction processing.
- Payments are processed directly through the payment gateway; we only receive confirmation of successful or failed transactions.
2.4 Network Security and Audits
- The website server is protected by firewalls, intrusion detection systems, and anti-malware software. Third-party security vulnerability scans are performed monthly.
- We engage an independent security firm for penetration testing annually, with vulnerabilities patched promptly.
2.5 Employee Training
- All employees sign a confidentiality agreement upon hiring and undergo basic security training (password management, phishing identification, data classification, etc.).
- An annual refresher training ensures awareness of the latest threats and countermeasures.
2.6 Data Backup and Recovery
- Customer order and account data are backed up daily with encryption and stored in a secure location separate from the main server.
- A Business Continuity Plan (BCP) is in place to restore core services within 24 hours in the event of natural disasters, system failures, or cyberattacks.
2.7 Incident Response
- If a suspected data breach occurs, we will launch an internal investigation within 24 hours and notify affected customers within 72 hours via email or website announcement.
- The notification will include the type of data involved, actions taken, and recommended protective steps (e.g., password change, account monitoring).
3. Information Security Policy Summary Table
The table below summarizes the core security measures of this policy:
| Security Area | Specific Measures | Frequency |
|---|---|---|
| Data Transmission Encryption | SSL/TLS 256-bit encryption | Every transaction & login |
| Payment Data Protection | No full card number stored; PCI DSS compliant partners | Continuous |
| Access Control | Least privilege principle; access logging | Real-time + monthly audit |
| Network Security | Firewall, intrusion detection, anti-malware | 24/7 monitoring |
| Vulnerability Scanning | Third-party automated scanning | Monthly |
| Penetration Testing | Independent security firm manual testing | Annually |
| Employee Training | Confidentiality agreement + basic & annual training | Onboarding + annually |
| Data Backup | Full encrypted backup | Daily |
| Incident Response | Investigation within 24h, notification within 72h | As needed |
4. Third-Party Service Provider Security
Our shipping carriers (USPS, Uniuni, GOFO Express, Easy) and other service providers are required to sign data processing agreements, committing to reasonable security measures for your shipping information. We only provide them with the name, address, and phone number necessary for delivery, and they are prohibited from using it for any other purpose.
5. Your Responsibilities
While we take extensive measures to protect your information, please also help by:
- Using strong passwords (at least 8 characters, including uppercase, lowercase, numbers, and symbols) and avoiding reuse across websites.
- Never sharing your account password or payment verification codes with others.
- Regularly reviewing your order history and contacting us immediately if you notice anything unusual.
6. Policy Updates
We may update this policy from time to time due to business changes or legal requirements. Updated versions will be posted on our website with the effective date. We encourage you to review it periodically.