CURRENT TEST SERVICE · 当前测试服务

Privacy notice
隐私说明

Updated · 更新于 2026 年 9 月 14 日

This page describes the current implementation. 本页说明当前版本实际处理数据的方式。

1. Who operates this service

This notice is provided by the operators of the SEXY DOLL website. For privacy questions or requests, contact [email protected].

The storefront is currently a test service: products, images and prices are previews. New orders require Google sign-in, but they remain test records. The production storefront does not collect PayPal or other payments. Only the isolated staging USD 1 virtual test uses PayPal Sandbox simulated funds, with no real charge, physical product or shipment. No order emails are sent. Please use fictional shipping details for regular catalogue tests and do not enter payment-card details, passwords or identity documents in address fields.

2. Google sign-in and account information

When you open sign-in and it is available, the site loads Google Identity Services and connects your browser to Google. Google may receive connection information, such as your IP address and browser details. Google’s own handling of that connection is described in the Google Privacy Policy.

After you choose to sign in, our server verifies Google’s signed identity credential. We store Google’s stable account identifier (sub), your profile name and email, an internal account ID, and account creation/update times in Cloudflare D1. These identify your account and associate new orders with it; matching email addresses do not automatically link old orders.

The credential may also contain a profile-picture claim. We do not store that claim or add a picture to your site account profile; Google’s own sign-in interface may display your Google profile picture. We do not request permission to read your Gmail messages, contacts or Drive files. The Google identity credential is processed for verification; our application does not save it in D1 or browser storage, or write it to application logs.

3. Order and shipping records

Submitted orders are stored in Cloudflare D1 and linked to your signed-in account. Records include the order ID, product and quantity snapshots, test prices, order/payment status, timestamps, and the shipping and contact fields you submit: recipient, email, phone, company, street/unit details, country, city, region, district, postal code and delivery notes, where provided.

We use these records to show your own orders across devices and test the ordering process. Site operators can access service data through operational tools. The IP-restricted order-summary page shows reduced order fields, the linked account’s current Google email and the contact email submitted with the order, where available; it does not show names, phone numbers or full addresses. Cancelling a test order changes its status and retains its record and history.

The staging virtual payment test does not request a shipping address. Its server sends the test order identifier, USD 1 amount and virtual item description to the official PayPal Sandbox service. PayPal handles the test buyer login and approval on its own site; do not use a real PayPal account. We store the provider order/capture identifiers, payment state and processing timestamps in the staging database. Provider responses and signed notifications are processed for verification; the application does not store full notification payloads, PayPal passwords or buyer profile details. Verified event identifiers and types are retained to prevent duplicate processing. Payment records have the same current retention policy as test orders.

Our application keeps address drafts only in page memory and discards them on reload. Your browser’s own autofill features may separately save or refill information according to your browser settings. New account-order details and private order lookup credentials are not saved by our application in browser local storage. Records from earlier test versions remain separate and are not automatically claimed by a Google account.

4. Cookies and browser storage

  • Sign-in cookie: a random, opaque session value, valid for up to 7 days unless revoked earlier. It is not a Google identity credential.
  • Sign-in challenge cookie: a random value valid for up to 5 minutes, used to bind a sign-in attempt to the initiating browser and cleared after successful sign-in.
  • Cookie safeguards: the HTTPS site uses host-only, Secure, HttpOnly, SameSite=Lax cookies. HttpOnly prevents our page scripts from reading those cookie values. The database stores hashes of the session/challenge values, together with expiry information and session-security data.
  • Local storage: the site saves the cart, language preference and your smooth-scrolling choice in this browser. These remain until updated or cleared through your browser. The scrolling choice stays in browser storage; it is not sent to our server or linked to your account. Earlier test versions may also have left private order-retrieval credentials; this version does not automatically erase those existing entries.

Signing out revokes this site’s current session; it does not sign you out of Google, delete your account/orders, or necessarily end sessions on other devices. Clearing cookies can end sign-in on that browser, but does not delete server records. Google may use its own cookies or browser mechanisms under its own policies.

5. Hosting, security and service providers

Cloudflare hosts the pages and server functions and provides the D1 database. Serving and protecting requests involves technical information such as IP addresses and request metadata. The application uses time-limited, IP-derived hashed rate-limit keys to reduce automated abuse. See Cloudflare’s Privacy Policy for information about its own processing.

The current application does not include advertising trackers or request Google services merely to display this notice. If you email the contact address, your email provider and the recipient’s Gmail service process that message; it is separate from automated checkout, which currently sends no emails.

6. Retention, access, correction and deletion

Expired login sessions, challenges and rate-limit records are subject to bounded cleanup during service requests. Account profiles and order records do not currently have an automatic deletion schedule or a self-service deletion button. Signing out, clearing browser storage, cancelling an order or disconnecting Google does not automatically delete those database records.

You can ask about access, correction or deletion by emailing [email protected]. Identify the relevant site and account email and describe the request; do not send passwords, Google credentials or full identity documents. We may need to verify that the account or order belongs to you before acting. The site operators will review the request and explain the available steps; this notice does not promise an automatic deletion deadline.

7. Changes to the test service

This notice reflects the version described on 14 September 2026. Data handling and this notice will need to be updated as the service changes, including before real payments, fulfilment or additional data uses are introduced. This page is a privacy notice, not commercial purchase terms or a claim of provider approval or certification.

1. 服务运营方

本说明由 SEXY DOLL 网站运营方提供。如有隐私问题或相关请求,请联系 [email protected]

本店目前属于测试服务,商品、图片及价格为预览内容。新订单必须使用 Google 登录后创建,但仍是测试记录。正式站不通过 PayPal 或其他方式收款;仅隔离的 staging 站点提供 1 美元虚拟测试,使用 PayPal Sandbox 模拟资金,不涉及真实扣款、实物商品或配送。本站不发送订单邮件。普通目录测试请使用虚构收货信息,不要在地址字段中填写银行卡资料、密码或身份证明文件。

2. Google 登录与账户信息

当您打开登录界面且登录可用时,本站会加载 Google Identity Services,并使浏览器连接 Google。Google 可能收到您的 IP 地址、浏览器信息等连接数据,其自身处理方式见 Google 隐私权政策

您选择登录后,服务器会验证 Google 签发的身份凭据。我们在 Cloudflare D1 中保存 Google 稳定账户标识(sub)、姓名、邮箱、本站账户 ID,以及账户创建和更新时间,用于识别账户并关联新订单。邮箱相同不会自动关联原有订单。

Google 凭据也可能包含头像字段;我们不会保存该字段或将头像添加到本站账户资料中,Google 自身的登录界面可能显示您的 Google 头像。我们不申请读取 Gmail 邮件、联系人或 Drive 文件的权限。Google 身份凭据仅用于验证;本站应用不会将其保存在 D1、浏览器存储或应用日志中。

3. 订单与收货信息

提交后的订单保存在 Cloudflare D1,并关联当前登录账户。记录包含订单编号、商品及数量快照、测试价格、订单和支付状态、时间,以及您实际填写的收货与联系方式:收货人、邮箱、电话、公司、街道和单元信息、国家、城市、州省、区县、邮编及配送备注。

这些记录用于跨设备展示您自己的订单并测试下单流程。网站运营方可通过运营工具访问服务数据。受 IP 白名单限制的订单概览页面展示精简订单字段、关联账户当前的 Google 邮箱,以及下单时填写的联系邮箱(如有);不展示姓名、电话或完整地址。取消测试订单会变更状态,但保留订单记录与历史。

staging 的虚拟支付测试不要求收货地址。服务器会将测试订单编号、1 美元金额及虚拟商品说明发送至官方 PayPal Sandbox 服务。测试买家的登录与批准在 PayPal 自身页面完成,请勿使用真实 PayPal 账号。本站在 staging 数据库保存服务商订单及扣款标识、支付状态和处理时间。服务商响应与签名通知仅用于验证;本站应用不保存完整通知内容、PayPal 密码或买家个人资料,仅保留已验证事件的标识和类型以防重复处理。支付记录适用与测试订单相同的现行保存规则。

本站应用仅将地址草稿保存在当前页面内存中,刷新后清除。浏览器自身的自动填充功能可能根据您的浏览器设置,另行保存或重新填入信息。本站应用不会将新的账户订单详情和私有订单查询凭据保存到浏览器本地存储。早期测试版本的订单记录仍独立保留,不会自动归入某个 Google 账户。

4. Cookie 与浏览器存储

  • 登录 Cookie:保存随机、不包含身份资料的会话值,最长有效期为 7 天,也可能提前撤销。它不是 Google 身份凭据。
  • 登录挑战 Cookie:保存最长有效期为 5 分钟的随机值,用于将登录尝试与发起登录的浏览器绑定,登录成功后清除。
  • Cookie 保护:HTTPS 站点使用仅限当前主机、Secure、HttpOnly、SameSite=Lax Cookie。HttpOnly 防止本站页面脚本读取 Cookie 值。数据库保存会话和挑战值的哈希,以及有效期与会话安全数据。
  • 本地存储:本站在当前浏览器保存购物车、语言偏好和平滑滚动选择,直到这些信息被更新或通过浏览器清除。滚动选择仅保存在浏览器,不发送至本站服务器,也不关联您的账户。早期测试版本可能还留下过私有订单查询凭据,本版本不会自动删除已有条目。

退出登录会撤销本站当前会话,不会退出您的 Google 账户、删除本站账户或订单,也不一定结束其他设备的会话。清除 Cookie 可以结束当前浏览器登录,但不会删除服务器记录。Google 可能按自身政策使用自己的 Cookie 或浏览器机制。

5. 托管、安全与服务提供方

Cloudflare 托管本站页面、服务器函数及 D1 数据库。提供并保护网络服务会涉及 IP 地址、请求元数据等技术信息。本站应用使用根据 IP 派生的限时哈希限流键,以减少自动化滥用。Cloudflare 自身的数据处理说明见 Cloudflare 隐私政策

当前应用未包含广告追踪器,展示本隐私说明本身不会请求 Google 服务。如果您向联系邮箱发送邮件,您的邮件服务商及收件方的 Gmail 服务会处理该邮件;这与当前不会发送邮件的自动结账流程不同。

6. 保存、访问、更正与删除

过期的登录会话、挑战和限流记录,会在服务请求期间进行分批清理。目前账户资料与订单记录没有自动删除计划,也没有自助删除按钮。退出登录、清空浏览器存储、取消订单或断开 Google 关联,都不会自动删除这些数据库记录。

如需咨询访问、更正或删除,请发送邮件至 [email protected],说明相关站点、账户邮箱及请求内容。请勿发送密码、Google 登录凭据或完整身份证明文件。处理前可能需要核实账户或订单归属。网站运营方将审阅请求并说明可采取的步骤;本说明不承诺自动删除期限。

7. 测试服务的变更

本说明反映 2026 年 9 月 14 日所述版本。后续服务发生变化,包括引入真实支付、履约或新的数据用途之前,需要更新数据处理方式与本说明。本页是隐私说明,不是商业购买条款,也不代表服务商审批通过或取得认证。