Privacy Policy

Privacy Policy

How Kunming Weijilan E-commerce Co., Ltd. handles the personal data of growers, wholesalers, marketplace sellers, buyers and every user who steps onto the auction floor of our systems.

Table of Contents
  1. Introduction and the Companies That Care
  2. Scope of This Policy
  3. What Personal Data We Collect
  4. Where the Data Comes From
  5. How We Use Personal Data
  6. Lawful Bases for Processing
  7. Privacy for Children
  8. Cookies, Pixels and Tracking
  9. Who We Share Data With
  10. Where and How Long We Store Data
  11. Security Measures We Take
  12. Your Rights and Choices
  13. Your California Privacy Rights
  14. International Transfers
  15. Data Retention Periods
  16. Data Breach Response
  17. Automated Decisions and Profiling
  18. Changes to This Policy
  19. Contact and the Data Protection Desk

1. Introduction and the Company That Cares

This Privacy Policy explains what we do. The platform systems described here are designed and engineered by the developer entity WeiJiLanEcom, which builds the trading software used across the services that we operate, and the daily care of the products and the data belongs to the company that delivers them.

We are Kunming Weijilan E-commerce Co., Ltd., a company formed to design e-commerce systems and to run online retail operations for the flower and produce markets of Kunming. Our registered office stands at:

Kunming Weijilan E-commerce Co., Ltd.
Rm 1106 11/F Wenhua Science and Technology Building, No. 371 Qingnian Road, Wuhua District, Kunming - 650000, China (CN)

Auction and checkout activity on our platforms touches a great deal of personal detail. This policy is the plain-language account of how that detail is gathered, used, kept safe and, when you ask, given back to you. It is written to be read fully before you join a crowd of bidders, register as a grower or launch a storefront on the marketplace. If a term here is unclear, our data protection desk at the end of this page will answer it.

By proceeding past the welcome screen of any WeiJiLanEcom built service, you accept the practices set out below. Please do not register or place a bid if you do not consent to them. You may always browse the public parts of the floor without giving us your name.

2. Scope of This Policy

This policy covers the websites, the storefronts, the auction applications, the settlement tools and the analytics dashboards that Kunming Weijilan E-commerce Co., Ltd. controls and that carry the lot flow described across our public pages. Where a separate legal page governs the terms of trade, such as our Terms of Service, this policy works alongside it rather than against it.

The scope is narrow in one important way. We are the people who build and run the platform. We are not the growers who list the stems, the couriers who carry the cases or the marketplace operators whose shops we link into. Each of those parties keeps their own responsibility over the data they touch, and this policy does not reach beyond what we ourselves control.

If you reach our platform through a marketplaces page, that marketplace handles some of your details under its own privacy notice. Read that notice as well. A careful floor reads every sheet on the desk before it bids.

3. What Personal Data We Collect

We collect only the data that a wholesale flower market genuinely needs to run. The list below is the whole list for the most part. Each category is described plainly.

  • Account data: your name, company name, place of business, a working email address and a telephone number when you register.
  • Identity detail: your user account identifier, your login password held as a scrambled hash, and a record of when you last signed in.
  • Bidding data: the lots you watch, the bids you place, the hammer price you accept and the settlement you complete.
  • Transaction records: your order history, your invoices, your refunds and your correspondence about a specific lot.
  • Payment data: we do not read your full card numbers. Your bank or payment rail holds those under its own security, and we receive only a confirmation token and the last few digits for your own receipt.
  • Technical data: an internet protocol address, browser name, device type, operating system and coarse location drawn from the signal itself, never from any hidden tracker.
  • Attendance data: if you visit a physical floor, logs that a cold room access system keeps of entry, kept separately from this platform by the venue operator.
  • Correspondence: the messages you send to our desk, including the notes you type into our contact form and the replies you receive.

We never gather data that is not needed for the market to work. We do not sweep your camera roll, your contact book or your browsing history when you are away from our floor, and we do not purchase lists of names from third parties to pad our grower rolls.

4. Where the Data Comes From

Most personal data arrives from one of four doors, and each door you can walk through yourself.

You give it to us. When you fill in a registration form, type a support request or choose a payment method, you hand over the detail with your own hands.

Your device gives it to us. As you move across the auction clock, our servers receive the technical signal of your connection so that the floor loads and stays honest for you.

A partner hands it over only where agreed. If a marketplace forwards a sale order to our settlement rail, it may pass the buyers email so that the receipt can be delivered. We tell you that this happens in the moment before it does.

A public source may add detail. Where you list your business on a public register, we may confirm your company name and address so that your standing as a grower can be checked before credit is offered on an order.

5. How We Use Personal Data

Every use of your data traces to a reason the market depends on. The headline uses are these.

  • Setting up and running your account so that you can watch lots, place bids and settle orders.
  • Processing the payment for a winning lot and sending the receipt that closes the sale.
  • Reconciling the auction settlement so that growers are paid on schedule and buyers receive clean invoices.
  • Protecting the integrity of the clock, which means watching for duplicate accounts, bid rigging, fraud and abuse of the floor.
  • Sending you the essential notices: a bid accepted, a lot sold, a dispatch on its way, an invoice ready.
  • Answering your support questions and repairing a system when it misbehaves.
  • Improving the platform by studying how rooms load and flow, always in aggregate and without singling you out.
  • Meeting the legal duties of a regulated commerce company, including tax records and accounting obligations we cannot set aside.

We do not sell your personal data, and we will never barter a grower list or a bidder address book for any sum. We do not use your data to decide insurance premiums or loan interest, and we do not let advertisers tail you across the web using a profile built from your bids.

6. Lawful Bases for Processing

Where the data protection law of your region requires us to name the ground that permits a use, we rely on four solid bases.

Consent. Where the law asks for your clear yes, as with some marketing messages, we ask for it separately and record your answer. You may withdraw that yes at any time without penalty.

Contract. Where we need your data to run the account and settle the lot you have agreed to trade, the use sits on the contract between us.

Legal obligation. Where a court, a tax authority or an accounting rule requires a record, we keep it because the law compels us rather than because we choose to.

Legitimate interest. Where a use benefits the safety and health of the market without overriding your own rights, such as fraud detection and technical security, we balance that interest against your expectations and keep the use modest.

If you want the precise reasoning for one of your uses, the data protection desk can set it out in a letter you can keep.

7. Privacy for Children

A wholesale flower auction is a trade floor, not a playground. Our platforms are built for growers, wholesalers, marketplace operators and adult buyers, and none of our services are directed at children under the age of sixteen.

We do not knowingly collect the personal data of children. If a parent or guardian believes a child below the age of sixteen has given us personal detail, they should write to the data protection desk at once so that we can remove it. When we learn that such data has reached us by accident, we delete it without delay and we never put it to a second use.

Where the law sets a higher age of consent, we respect the higher mark for that territory. A young user in a region that sets the threshold at sixteen must wait until they pass it to hold an account in their own name.

8. Cookies, Pixels and Tracking

Like every commerce floor, our systems use small pieces of code, called cookies, that keep your session steady as you move from lot to lot. These are the workhorse cookies of the auction: one holds your basket, another remembers your clock language, a third keeps you signed in on the device you trust.

A necessary cookie keeps the floor secure and running. An analytics cookie, set only where you accept it, helps us see how many buyers reach the settlement page and where the flow stalls so that we can shorten it.

We do not use advertising cookies to build a profile for ads aimed at you elsewhere, and we do not pass a bidder cookie across to a marketplace to shadow your shopping. The pixels that some linked marketplaces place belong to them and fall under their own notices.

You can turn off non-necessary cookies in your browser at any time. The floor still opens and lots still drop; you simply lose a little convenience and we lose a little understanding of how the traffic moves.

9. Who We Share Data With

We keep your data close, but a market that spans a cold store, a courier van and a bank cannot run alone. The confined circle we share with is listed here, each member bound by contract to use your data only for the task we set.

Hosting and infrastructure providers keep the servers running in secure data centres under our instruction. We never let a host read through our ledgers for its own gain.

Payment processors hold the mechanics of the checkout. The bank or rail confirms that a card is good, guards the full number and reports success to us in a token we can match to the lot.

Couriers and logistic partners receive enough to deliver a case: a name, an address on the route and a contact number for the day of dispatch. They do not see your bidding history.

Marketplace operators receive the minimum to honour the sale we agreed for you, which is usually the buyers email for a receipt and the order line for the goods.

Professional advisors and the authorities may see data where a rule of law demands it. Outside those cases, no third party stands behind the desk, and no partner is allowed to sell on anything we hand across.

10. Where and How Long We Store Data

Your data rests in secure centres at the edge of the trade region we serve, chosen for speed and for protection. We hold information only as long as the market genuinely needs it.

An account that stays active keeps its records while you trade and for a sensible period after you close the door, so that a dispute over a single case can still be made good. A payment record is kept for the number of years the tax law of the region demands. A support conversation is held for the time needed to settle your matter and then trimmed.

When a purpose is served, we delete or anonymise the data rather than hoard it. We do not keep a copy of a market alive past its season, and we do not leave test accounts open in a shadow of the real floor.

11. Security Measures We Take

A live auction clock is a tempting target, so the room is guarded at every step. The security of your data rests on layers we renew as the trade changes.

  • Encryption in transit: every page travels to you over a sealed channel, so a bid cannot be read as it flies.
  • Encryption at rest: the ledgers we hold are scrambled with strong keys that live apart from the data itself.
  • Role-based access: a courier sees a delivery note and nothing more, and a desk clerk never stands where an auditor sits.
  • Login protection: passwords are stored as scrambled hashes, and repeated failed tries slow the door against guessers.
  • Audit logs: a careful trail shows who looked at what, so that any stray glance at a ledger is caught and questioned.
  • Continuous checking: our engineers watch the floor for unusual traffic and patch a weakness before it becomes a wound.

No room is ever perfectly sealed, so we are honest with you about that. What we promise is a floor guarded consistently, tested often and governed by people who treat the settlement ledger as the treasure it is.

12. Your Rights and Choices

Where the law of your region grants you rights over your own data, we honour them fully. The principal rights are these, and you may ask for any of them at the data protection desk.

You may ask to see the personal data we hold about you and to receive a copy in a readable form. You may ask us to correct a detail that has drifted, such as a phone number that changed with a new grower shed.

You may ask us to erase your data where we hold it without a duty to keep it, and you may object to a use that rests on our own interest rather than on your consent or a contract.

You may ask us to pause a use while you question its fairness, and in a few regions you may ask for a portable copy of the data you gave us so that it can move to another floor.

You may bring a complaint to the supervising authority in your territory if you feel we have failed you. We hope you write to us first, because a fault on the desk is usually a fault we can mend.

13. Your California Privacy Rights

Residents of California may hold rights under the California Consumer Privacy Act and related rules. Under that law we tell you plainly that we do not sell or share your personal information as those words define a sale, and we have not done so in the past twelve months.

A California resident may ask twice a year to know what categories of personal information we collect, what we use it for and whom we disclose it to, and may ask us to delete personal information we hold, subject to the exceptions the law allows.

We will not treat you differently because you choose to exercise a right under this part of the policy. The floor price, the lot access and the quality of the service you receive do not turn on whether you ask us to delete your data.

To make a request, contact the desk at the address below. We will verify that the request truly comes from you before we act on it, which may mean matching a few details we already hold. We answer every verified request within the window the law sets.

14. International Transfers

The flower trade is a world trade. A buyer in one nation bids on a lot grown in another, so it is natural that some data crosses a border on its way to the settlement rail.

When we store or move personal data outside the region where you live, we keep that data protected to a standard at least as strong as the rules of your home market. We rely on approved safeguards, careful contracts and the published decisions of data authorities where one is available.

If you would like a copy of the safeguards we use to carry your data across a border, the data protection desk will send one. Nothing leaves our care on a loose handshake; every transfer has a paper trail behind it.

15. Data Retention Periods

Retention is not a single number, because the market treats a receipt differently from a password. The guide below is the honest shape of how long we keep things.

  • Core account data: kept while your account is active, then removed or made anonymous within a set period after you request closure.
  • Transaction and invoice records: kept for the number of years the local tax and accounting laws require, then erased.
  • Payment tokens and confirmations: held only as long as the refund window and audit trail need them.
  • Support messages and tickets: kept to settle the matter and closed records trimmed on a fixed cycle.
  • Security logs: may be held longer where they protect the floor, but only in a form that does not single you out beyond the need.

At the end of each period the data is deleted from the live system, then scrubbed from the backups on their own slower schedule. We do not advertise a longer keeper to suit ourselves; the seasons of the market, not our convenience, set the clock.

16. Data Breach Response

If personal data is ever lost, stolen or exposed through a fault in our room, we answer with speed and with honesty rather than with silence.

On learning of a breach we first contain it, closing the door and protecting what remains. We then judge how serious the exposure is and who it might touch. Where the risk to you is real, we tell the people affected, describe what happened, what detail was at risk and what steps we are taking, and we explain what you can sensibly do to guard yourself.

Where the law of your region obliges us, we also report the breach to the relevant authority within the window it sets. We keep a record of every incident, however small, so that a repeated weakness cannot hide behind a single apology.

A breach report is never dressed up or softened on the desk. You would rather know the truth of a leak than believe in a false all clear, and we would rather give it to you.

17. Automated Decisions and Profiling

Most of the auction is a machine that follows clear rules set by people. Where we use software to take or to prepare a decision, we do so openly and only where the call is fair and explainable.

One honest example is fraud screening on a large order. Our systems may mark a checkout for review because the amount is unusual or the device pattern is new, so that a human on the desk can double check before a case ships. The machine flags; the person decides. It never quietly denies service without a person being able to see the reason.

We do not run a silent bidder algorithm against you, and we do not set prices against a hidden profile of your income or your age. Where we hold a profile for your own convenience, such as remembering the flower families you watch, you can clear it from your account settings whenever you like.

18. Changes to This Policy

The market changes, the law changes and so occasionally this policy must change with them. When we revise it we fix the date at its foot and set the new version live on this page.

For a change that widens what we may do with your data, we will give you notice before it takes effect, by a message in your account or at the email you gave us, so that you can decide whether the new terms still suit you. A change that narrows our use or sharpens our promises takes effect for your benefit at once.

We do not rewrite history quietly. The earlier versions of this policy remain available on request at the data protection desk, so that the promises we made to you when you joined can always be compared with the promises we make today. If you do not accept a revised policy, you may close your account and ask us to remove your data as this policy describes.

19. Contact and the Data Protection Desk

All questions, requests and complaints about this policy or about your personal data go to one honest place: the data protection desk of Kunming Weijilan E-commerce Co., Ltd. You may write by email or by post, and you may ask for a reply in the language of the original room.

Kunming Weijilan E-commerce Co., Ltd.
Rm 1106 11/F Wenhua Science and Technology Building, No. 371 Qingnian Road, Wuhua District, Kunming - 650000, China (CN)

Email: connect@weijilanecom.lol

Telephone: +14349395907

Our desk answers within a matter of days, and usually on the same working day for a data question. Your email and your lot are both treated with the same care: they land on the desk, they are handled by a person, and they are answered fully.

Thank you for reading this policy. A market that states its own rules plainly, and keeps them, is a market that deserves your trust on the floor as well.

WEIJILANECOM
  • Home
  • Privacy Policy
  • Terms of Service

Kunming Weijilan E-commerce Co., Ltd. — Rm 1106 11/F Wenhua Science and Technology Building, No. 371 Qingnian Road, Wuhua District, Kunming - 650000, China (CN)

Email: connect@weijilanecom.lol  |  Phone: +14349395907

This Privacy Policy was last revised on 7 September 2026. Return to the auction floor at any time by following the Home link above.

WEIJILANECOM © Kunming Weijilan E-commerce Co., Ltd. All rights reserved. Privacy Policy page.