Information Security & Privacy Policy Pack
Organization: Lingxiao Cross-Border Commerce Technology Services (TikTok Shop Partner: ppdxx)
Policy owner: Management / Security & Privacy Lead
Effective date: 18 July 2026
Next review: 18 July 2027
Version: 1.0
This policy pack establishes mandatory security and privacy requirements for the Lingxiao platform and its processing of TikTok Shop seller, creator, product, order, finance, logistics, affiliate, and authorization data. Requirements apply to all personnel and systems within scope.
1. Information Security Governance Policy
The organization maintains an information security program approved by management and applicable to employees, contractors, systems, cloud services, and third parties that process company or customer data.
- Management appoints a Security & Privacy Lead responsible for risk management, policy maintenance, incident coordination, access reviews, security awareness, and regulatory communication.
- Security risks are reviewed at least annually and whenever a material system, supplier, market, or data flow changes.
- Personnel receive security and privacy training on onboarding and annually. Confidentiality obligations continue after termination.
- Exceptions require written management approval, a documented risk assessment, compensating controls, and an expiry date.
- Compliance is monitored through access reviews, vulnerability reviews, incident exercises, backup tests, and policy attestations.
2. Network Security and Segmentation Standard
- Production, management, development, and user-facing environments must be logically separated. Administrative services and databases must not be directly exposed to the public Internet.
- Inbound access follows default-deny rules. Only required HTTPS and explicitly approved management paths may be exposed.
- Administrative access requires named accounts, strong authentication, restricted source networks or VPN/allowlists, and logging.
- TLS 1.2 or later protects data in transit. Firewalls, reverse proxies, rate limits, and security headers protect public services.
- Network and authentication logs are centrally retained and reviewed for suspicious access, repeated failures, privilege changes, and unusual data transfer.
3. Endpoint Protection Policy
- Company endpoints must use supported operating systems, automatic security updates, host firewall, real-time anti-malware protection, disk encryption where available, and screen locking.
- Users may not disable endpoint security controls. Local administrator privileges are restricted to approved operational need.
- Lost, stolen, infected, or suspected compromised devices must be reported immediately and isolated from company systems.
- Removable media and unapproved software are prohibited for customer data processing.
4. Security Baseline Standard
- Passwords must be unique, at least 12 characters for privileged accounts, and protected by MFA where supported.
- Sessions expire after inactivity; failed authentication is rate-limited; default credentials are prohibited.
- Systems follow least-functionality principles, remove unused services, apply secure configuration, and receive critical patches promptly.
- Secrets are stored in protected configuration or secret-management facilities and never committed to source control or exposed in logs.
- Backups are encrypted, access-controlled, tested at least quarterly, and separated from production credentials.
- Work areas follow clean-desk and clear-screen requirements. Sensitive information may not be left unattended.
5. Access Control Policy
- Access is granted only for documented business need, approved by the data or system owner, and limited by role, organization, shop, and environment.
- Every user has a unique account. Shared accounts are prohibited except controlled service accounts with documented ownership.
- Privileged access requires stronger authentication, separate administrative identities where practical, and auditable activity.
- Access is reviewed quarterly and immediately upon role change or termination. Departing personnel are disabled no later than the end of employment.
- TikTok Shop credentials and seller data are isolated by authorizing employee, tenant organization, and shop. Access tokens are not shared across unrelated sellers.
6. Data Classification, Handling and Encryption Policy
Data is classified as Public, Internal, Confidential, or Restricted.
- Authentication credentials, access tokens, personal data, seller financial information, and security records are Restricted.
- Restricted and Confidential data are collected only for documented purposes, limited to the minimum necessary, and accessible only to approved roles.
- Data in transit uses TLS 1.2 or later. Sensitive secrets and backups are encrypted or protected using equivalent platform controls at rest.
- Restricted data must not be sent through personal messaging, unapproved email, public links, or unmanaged storage.
- Production data is not copied to development environments unless anonymized or specifically approved and protected.
7. Incident Response and Data Breach Notification Plan
- Report and triage: Personnel immediately report suspected incidents to the Security & Privacy Lead. Events are classified by impact, scope, data sensitivity, and legal obligation.
- Contain: Disable affected credentials, isolate systems, block malicious access, preserve evidence, and prevent further disclosure.
- Investigate and eradicate: Determine root cause, affected systems and people, remove malicious artifacts, rotate secrets, and patch weaknesses.
- Recover: Restore from trusted sources, validate controls, monitor for recurrence, and obtain owner approval before full service restoration.
- Notify: Notify TikTok Shop, affected merchants, individuals, and regulators without undue delay when contractually or legally required. Initial notification includes known facts, impact, containment, and contact details.
- Improve: Complete a documented post-incident review, corrective action plan, and lessons-learned exercise.
8. Vulnerability and Threat Management Policy
- Dependencies, operating systems, cloud services, and Internet-facing applications are reviewed for known vulnerabilities.
- Critical exploitable findings are remediated as soon as practicable, targeted within 72 hours; high findings within 14 days; medium findings within 30 days unless formally risk-accepted.
- Security updates are tested proportionately and deployed through controlled change procedures.
- Application changes undergo code review and relevant authentication, authorization, input-validation, secret-exposure, and dependency checks.
- Threat intelligence, vendor advisories, logs, and anomalous behavior are monitored to identify emerging risks.
9. Personal Data Protection and Privacy Policy
- Personal data is processed lawfully, fairly, transparently, and only for specified service, security, support, and legal purposes.
- Data collection follows minimization, accuracy, purpose limitation, storage limitation, integrity, and confidentiality principles.
- Requests to access, correct, export, restrict, or delete personal data are verified, recorded, and handled within applicable legal and contractual deadlines.
- Processors and vendors are assessed for security and privacy obligations and receive only the data necessary for their service.
- Cross-border transfers use applicable contractual, technical, and organizational safeguards.
- The Security & Privacy Lead maintains processing records and serves as the privacy contact. A formal certified DPO is not claimed unless legally appointed.
10. Data Retention, Deletion and Contract Termination Procedure
- Customer and TikTok Shop data is retained only while needed to provide the authorized service, meet security/audit needs, or satisfy legal obligations.
- OAuth credentials are revoked or deleted when authorization ends, the seller requests removal, or the service relationship terminates, subject to legally required records.
- Operational records use documented retention periods. Expired records are securely deleted or anonymized from active systems and aged out of backups through normal rotation.
- Deletion requests are identity-verified, logged, assigned to an owner, completed across relevant systems, and confirmed to the requester where appropriate.
- At contract termination, customer data is returned or deleted within 30 days unless a shorter contractual period or legal hold applies.
11. Assurance, Review and Enforcement
- Policies are reviewed at least annually and after material incidents, legal changes, platform changes, or major system changes.
- Management may require evidence of compliance, corrective action, training, or disciplinary measures for violations.
- This document does not claim ISO 27001, ISO 27701, SOC 2 Type II, ePrivacy, or any other certification that has not been independently awarded.
Approved by: Management, Lingxiao Cross-Border Commerce Technology Services (TikTok Shop Partner: ppdxx)
Approval date: 18 July 2026
Contact: contact@lingxiaochuhai.com