PODJST uses business and personal information to provide product, sample, production, quality control, packing, shipping, support, and integration services.
For merchant customer and recipient data used to fulfill orders, the merchant generally decides why the data is processed and PODJST processes it to provide the requested service.
PODJST does not sell merchant customer order data or use recipient details for cross-context behavioral advertising.
Who We Are and When This Policy Applies
JST COMMERCE LIMITED operates PODJST, the service brand used for the website and print-on-demand workflows described in this Policy. Our operational contact address is RM D07, 8/F, KAI TAK FTY BUILDING, NO. 99 KING FUK STREET, SAN PO KONG, HK.
This Policy applies to the PODJST website, support channels, merchant accounts, sample and fulfillment workflows, and PODJST-managed integrations. A separate written agreement may include additional terms for a specific customer or service.
Our Data Protection Roles
PODJST acts as a controller or business for information about website visitors, prospective customers, merchants, account users, and business contacts when we decide how and why that information is used.
When a merchant sends its customer's or recipient's information to PODJST only so that we can produce, pack, ship, or support an order, the merchant is generally the controller or business and PODJST acts as its processor or service provider. Our Data Processing Terms apply to that processing.
Information We Collect
We collect information provided directly by you, received from a connected platform at your direction, generated while providing services, or collected automatically when you use the website.
- Contact and business data: name, business name, email, phone number, role, country, platform, expected order volume, and communications.
- Account and integration data: account identifiers, store domain, platform identifiers, authorization tokens, permission scopes, connection status, and synchronization logs.
- Product and content data: product ideas, artwork, logos, images, text, mockups, product variants, packaging instructions, and sample requests.
- Order and recipient data: order identifiers, product and variant details, recipient name, email or phone where required, delivery address, tracking details, and issue evidence.
- Transaction data: quote, invoice, payment status, currency, discounts, taxes, refunds, and accounting records. Full payment card details are handled by the relevant payment provider where available.
- Technical and usage data: IP address, approximate location, browser, device, referring page, visited pages, timestamps, consent choice, session identifiers, and security or error logs.
How and Why We Use Information
We process information to perform a contract or take requested pre-contract steps, comply with legal obligations, pursue legitimate interests that do not override individual rights, and obtain consent where consent is required.
- Respond to inquiries and provide product, sample, quote, packaging, production, quality control, fulfillment, and support services.
- Authenticate users, maintain accounts, connect supported stores, synchronize approved data, and troubleshoot integrations.
- Produce and ship approved orders, provide tracking, handle delivery issues, and maintain required transaction records.
- Protect accounts, detect fraud or abuse, enforce policies, investigate incidents, and meet legal or platform obligations.
- Improve website content and service workflows using limited first-party analytics while honoring supported browser privacy signals and consent where required.
- Send service communications and, where permitted, marketing messages that recipients can unsubscribe from.
Connected Stores and Platform Data
When you authorize a Shopify, Etsy, WooCommerce, TikTok Shop, Temu, SHEIN, API, CSV, or other supported connection, PODJST receives only the data and permissions required for the enabled workflow. Available integrations and data fields vary by platform and may change as platform requirements change.
Typical connected-store data can include store identifiers, products and variants, inventory or fulfillment settings, orders, recipient details, shipping status, tracking numbers, and synchronization logs. PODJST uses that data to provide the integration and fulfillment functions requested by the merchant.
For Shopify public apps, PODJST handles valid customer data access, customer deletion, and shop deletion requests received through Shopify's mandatory compliance process. Access tokens are disabled when a connection is removed, and personal data subject to a valid platform deletion request is deleted or de-identified unless retention is legally required.
International Data Transfers
PODJST supports cross-border ecommerce and may process information in Hong Kong and in other locations where our infrastructure, production, support, or delivery providers operate.
Where applicable law requires a transfer mechanism, PODJST uses contractual protections or another recognized safeguard and limits provider access to the information needed for the service.
Data Retention
We retain each category only for the period reasonably required for its stated purpose, an active service relationship, dispute handling, fraud prevention, or a legal recordkeeping obligation. Unless a longer period is required by law or contract, our operating schedule is:
- Website analytics identifiers: up to 13 months after collection unless browser storage is cleared earlier.
- General inquiries, quote requests, and support conversations: up to 24 months after the last interaction.
- Store configuration and access credentials: while connected; credentials are disabled promptly after disconnection or uninstall.
- Merchant customer fulfillment data: while needed to fulfill and support the order, then deleted or de-identified when no longer required; valid platform redaction requests are completed within the applicable platform or legal deadline.
- Order, invoice, tax, payment, refund, and dispute records: up to 7 years where needed for accounting, legal, or fraud-prevention obligations.
- Artwork and production files: while the merchant account or repeat-production workflow remains active, or until deletion is requested and no legal or operational exception applies.
Security
PODJST uses administrative, technical, and organizational measures intended to protect information, including access controls, role restrictions, protected service credentials, transport encryption for production services, logging, and provider security controls.
No system is completely secure. Users must protect account credentials, limit uploaded data to what the service needs, and notify PODJST promptly if they suspect unauthorized access.
Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, or appeal a decision concerning a request.
Merchants should normally submit requests concerning their own customers. We will assist merchants with verified requests where PODJST processes the relevant data on their behalf. See our Data Requests page for the required information and process.
Changes and Contact
We may update this Policy to reflect service, provider, platform, or legal changes. Material changes will be identified by a revised effective date and, where appropriate, an additional notice.
Privacy and policy questions for JST COMMERCE LIMITED, operating as PODJST, can be sent to support@podjst.com, by phone at +852 64203057, or by mail to RM D07, 8/F, KAI TAK FTY BUILDING, NO. 99 KING FUK STREET, SAN PO KONG, HK.
Questions or requests?
Contact JST COMMERCE LIMITED, operating as PODJST, and include the policy or request type.