Shenchi ERP Report Receiver

Privacy Policy

Effective date: October 11, 2026

This policy describes the Shenchi ERP Report Receiver and its connected internal delivery-reporting workflow.

Data accessed and processed

The application processes exported ERP shipment reports and their filenames, report dates, file hashes, and upload results. Reports may contain customer names and codes, product information, shipment quantities, currency, and sales amounts. The application also accesses the authorizing Google account's email address to check access to account-specific setup functions.

Google permissions

The receiver requests Google Drive's per-file permission (drive.file), covering files created by or explicitly authorized for this application, and permission to read the authorizing account's email address (userinfo.email). It does not request unrestricted access to the entire Google Drive or permission to read Gmail.

Purpose and storage

Data is used to receive reports, check upload integrity, avoid duplicate uploads, and prepare delivery details and monthly reports. Exported reports are stored in the configured Google Drive folder. Reporting data and import results are stored in the connected Google Sheets. Execution and diagnostic records may be retained in the application environment and on the company server. Import errors and missing customer-name mappings may be sent to the configured reporting administrator by email.

Sharing and service providers

Google services process and store application data as part of this workflow. Authorized company users and administrators may access reports according to the permissions configured in Google Drive and Google Sheets. The workflow is not intended to publish reports or customer data publicly. Application data is not used for advertising or sold to third parties.

Security

The receiver uses HTTPS and checks a separate upload key before accepting a report. Uploads are limited in size and checked for expected file format and hash integrity. These controls do not eliminate all risks. Credentials must be protected by authorized administrators, and suspected compromised credentials should be replaced.

Retention, revocation and deletion

Cloud reports and reporting records remain until removed by an authorized administrator according to business needs. After a confirmed successful upload, the configured server workflow moves its local exported report to the Windows Recycle Bin; that copy remains recoverable until the Recycle Bin is emptied. Revoking Google authorization stops the application's authorized access but does not automatically delete previously stored reports or spreadsheet records. Contact the administrator to request review or deletion of stored data.

Google API user data

The application's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

This information website

This website has no report upload form, ERP login form, advertising, or application analytics code. The website hosting provider may process standard connection information to deliver and secure the pages.

Contact and changes

For privacy questions or data requests, contact austinyangwork@gmail.com. This policy will be updated when the application's data practices change.