Privacy Policy

Last updated 19 August 2026

This policy covers the warehouse management and order management service operated by [registered legal entity name] ("we") at meirun.com and its subdomains, including wms.meirun.com and oms.meirun.com.

Who the data belongs to

Almost all personal data we hold arrives from a business customer, not from the person it describes. A seller connects their sales channel or files an order, and the order carries the name, address and telephone number of the buyer who placed it. For that data the seller is the controller and we are their processor: we hold it to receive, store, pack and ship the goods they instruct us to ship, and for no other purpose.

We are the controller for the account data of the people who sign in to the service: their name, email address, and the record of what they did in it.

What we collect

We do not collect buyer payment details. Payment is taken by the sales channel, and card and bank numbers do not reach this service.

Where it goes

Recipient details are disclosed to the parties that have to have them for a parcel to arrive: the carrier or freight forwarder handling the shipment, and the customs authorities of the destination country where a declaration is required. Nothing is sold, rented, or shared for advertising. We do not use recipient data to build profiles and we do not market to buyers.

Where a seller's sales channel requires it, order status and tracking numbers are sent back to that channel.

Where it is held

Data is held on servers we control, located in the United States. Each business customer's records live in a separate database file, so a query made for one customer cannot reach another's records. Traffic to the service is encrypted in transit with TLS. Backups are taken every six hours and kept for fourteen days.

How long we keep it

Shipment records are kept for as long as the customer's account is open and for seven years afterwards, which is the period customs and tax authorities may ask us to produce them for. Personal data that is not part of a shipment record is deleted within 90 days of an account closing. Platform credentials are deleted as soon as a connection is removed.

Your rights

You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. If the data reached us from one of our business customers, we will pass the request to that customer and act on their instruction, because the data is theirs and not ours to give away. Write to [postal address] or email privacy@meirun.com. We answer within 30 days.

Security

Access to the service requires an individual account. Passwords are stored only as a salted one-way hash, computed with scrypt. Session tokens are stored only as a hash, so a copy of our database is not a set of usable sessions. A session expires after twelve hours, or after two hours of inactivity. Changing a password ends every session belonging to that account.

Credentials and access tokens belonging to a seller's sales channels are never returned to a browser: a screen is told whether one is stored and the last four characters of the identifier, and nothing more.

Access to a seller's account by warehouse staff, where a seller has asked for help, is recorded against the person who performed each action and the operator acting on their behalf, and that record is visible to the seller.

Children

The service is sold to businesses and is not directed at children.

Changes

If this policy changes materially we will tell account holders by email before the change takes effect. The date at the top is the date of the current version.

Contact

[registered legal entity name], [postal address]. Email privacy@meirun.com.