Legal
Privacy Policy
This policy explains how BLOSSOMFASHION INC, registered at 1500 N GRANT ST STE 4226, DENVER, CO 80203 (“we,” “us,” or “our”), handles information when you use the anonymous, read-only Dropshipping Product Scout tools in ChatGPT.
1. Scope
Version 1 does not require an account or sign-in. This read-only service searches a small, manually reviewed, general-audience curated catalog, retrieves current product, approved variant, and warehouse availability, and estimates shipping for an approved variant. Restricted and unknown products are not supported. It does not connect to or access CJ customer accounts, orders, tracking, payment details, store accounts, disputes, or customer records, and it cannot make purchases, reserve inventory, book shipments, place orders, or publish products.
2. Information processed
Lookup data
We process only validated arguments needed for the requested lookup: a product keyword or SKU, catalog filters, variant identifiers, quantity, and origin and destination country codes. Version 1 does not request a name, email address, phone number, street address, postal code, tax number, payment information, account password, or upstream access token.
Please do not place personal, customer, credential, payment, or confidential information in tool fields. The service does not need it to perform these lookups.
Operational and security data
The application processes a random request identifier, request method and route, response status, latency, coarse error category, and rate-limit state to operate and protect the service. Source IP addresses are processed transiently in memory to apply rate limits, but are not included in application log fields. The application does not log full ChatGPT prompts, request or response bodies, tool arguments, CJ credentials, access tokens, refresh tokens, or raw upstream responses. Caddy per-request access-log output is discarded. Hosting, DNS, certificate, and network providers may still process IP addresses and TLS or security events as part of their infrastructure.
Support communications
If you email support, we process your email address and the message and attachments you choose to send.
3. How information is used
- to perform the product, availability, or shipping lookup you requested;
- to maintain reliability, diagnose failures, enforce limits, and prevent abuse;
- to comply with applicable legal obligations and protect the service; and
- to respond to support, privacy, and security requests.
We do not sell personal information, use lookup data for targeted advertising, or display advertisements.
4. Service providers and third-party data
The minimum validated lookup arguments are sent to CJ Dropshipping product and logistics APIs to return the requested data. We do not intentionally send your ChatGPT identity, full conversation, or unrelated content to those APIs. This statement does not claim ownership of CJ names or trademarks.
The current deployment uses Alibaba Cloud Hong Kong ECS for hosting, Volcengine for authoritative DNS, Caddy for HTTPS automation, and a public certificate authority selected by Caddy for certificate issuance. Users access the tools through ChatGPT, which OpenAI operates under its own terms and privacy notice. The application/Compose configuration has no separate analytics, advertising, application-database, monitoring, or support-ticket provider. Providers may process information under their own terms and privacy notices. We may also disclose information where required by law or reasonably needed to protect users, rights, or service security.
5. Cookies and accounts
The public pages and Version 1 tools do not set application cookies, create user profiles, or maintain user accounts.
6. Retention
Application and Caddy runtime logs use Docker size rotation: each log file is limited to 5 MB and each container keeps at most two files, with older data overwritten as the size limit is reached. This is a size-based limit, not a promise of a fixed number of retention days. In-memory rate-limit data expires automatically after its configured window. The application has no user database and no application backup containing tool requests configured in Compose. Infrastructure providers may retain their own security, DNS, billing, or platform logs under their terms. Support mail is hosted by Tencent Enterprise Mail. Support messages are retained under the mailbox account's provider and administrator settings; access and deletion requests can be sent to the contact below.
7. Security
We use HTTPS, server-side credential storage, restricted containers, input and output validation, request-size limits, rate limiting, timeouts, response field allowlists, and log minimization. No system is completely secure, and we cannot guarantee absolute security.
8. International processing and your rights
The service is configured for worldwide availability, subject to applicable law and local availability. Service providers may process information in countries other than your own. Depending on applicable law, you may have rights to request access, correction, deletion, restriction, or objection, or to complain to a regulator. Because Version 1 has no user accounts and does not intentionally log request bodies, we may be unable to locate a lookup by identity. We will respond to verifiable requests as required by applicable law.
9. Children
The service is not directed to children under 13. Where local law requires a higher minimum age, that requirement applies.
10. Changes and contact
We may update this policy and will post the revised effective date on this page.
Privacy, support, and security contact:
wangshucheng@youxiu.shop.
Operator: BLOSSOMFASHION INC
Registered address: 1500 N GRANT ST STE 4226, DENVER, CO 80203