English
阅读中文 ↓1. Who operates this service
This notice is provided by the operators of the SEXY DOLL website. For privacy questions or requests, contact [email protected].
The storefront is currently a test service: products, images and prices are previews. New orders require Google sign-in, but they remain test records. The production storefront does not collect PayPal or other payments. Only the isolated staging USD 1 virtual test uses PayPal Sandbox simulated funds, with no real charge, physical product or shipment. No order emails are sent. Please use fictional shipping details for regular catalogue tests and do not enter payment-card details, passwords or identity documents in address fields.
2. Google sign-in and account information
When you open sign-in and it is available, the site loads Google Identity Services and connects your browser to Google. Google may receive connection information, such as your IP address and browser details. Google’s own handling of that connection is described in the Google Privacy Policy.
After you choose to sign in, our server verifies Google’s signed identity credential. We store Google’s stable account identifier (sub), your profile name and email, an internal account ID, and account creation/update times in Cloudflare D1. These identify your account and associate new orders with it; matching email addresses do not automatically link old orders.
The credential may also contain a profile-picture claim. We do not store that claim or add a picture to your site account profile; Google’s own sign-in interface may display your Google profile picture. We do not request permission to read your Gmail messages, contacts or Drive files. The Google identity credential is processed for verification; our application does not save it in D1 or browser storage, or write it to application logs.
3. Order and shipping records
Submitted orders are stored in Cloudflare D1 and linked to your signed-in account. Records include the order ID, product and quantity snapshots, test prices, order/payment status, timestamps, and the shipping and contact fields you submit: recipient, email, phone, company, street/unit details, country, city, region, district, postal code and delivery notes, where provided.
We use these records to show your own orders across devices and test the ordering process. Site operators can access service data through operational tools. The IP-restricted order-summary page shows reduced order fields, the linked account’s current Google email and the contact email submitted with the order, where available; it does not show names, phone numbers or full addresses. Cancelling a test order changes its status and retains its record and history.
The staging virtual payment test does not request a shipping address. Its server sends the test order identifier, USD 1 amount and virtual item description to the official PayPal Sandbox service. PayPal handles the test buyer login and approval on its own site; do not use a real PayPal account. We store the provider order/capture identifiers, payment state and processing timestamps in the staging database. Provider responses and signed notifications are processed for verification; the application does not store full notification payloads, PayPal passwords or buyer profile details. Verified event identifiers and types are retained to prevent duplicate processing. Payment records have the same current retention policy as test orders.
Our application keeps address drafts only in page memory and discards them on reload. Your browser’s own autofill features may separately save or refill information according to your browser settings. New account-order details and private order lookup credentials are not saved by our application in browser local storage. Records from earlier test versions remain separate and are not automatically claimed by a Google account.
4. Cookies and browser storage
- Sign-in cookie: a random, opaque session value, valid for up to 7 days unless revoked earlier. It is not a Google identity credential.
- Sign-in challenge cookie: a random value valid for up to 5 minutes, used to bind a sign-in attempt to the initiating browser and cleared after successful sign-in.
- Cookie safeguards: the HTTPS site uses host-only, Secure, HttpOnly, SameSite=Lax cookies. HttpOnly prevents our page scripts from reading those cookie values. The database stores hashes of the session/challenge values, together with expiry information and session-security data.
- Local storage: the site saves the cart, language preference and your smooth-scrolling choice in this browser. These remain until updated or cleared through your browser. The scrolling choice stays in browser storage; it is not sent to our server or linked to your account. Earlier test versions may also have left private order-retrieval credentials; this version does not automatically erase those existing entries.
Signing out revokes this site’s current session; it does not sign you out of Google, delete your account/orders, or necessarily end sessions on other devices. Clearing cookies can end sign-in on that browser, but does not delete server records. Google may use its own cookies or browser mechanisms under its own policies.
5. Hosting, security and service providers
Cloudflare hosts the pages and server functions and provides the D1 database. Serving and protecting requests involves technical information such as IP addresses and request metadata. The application uses time-limited, IP-derived hashed rate-limit keys to reduce automated abuse. See Cloudflare’s Privacy Policy for information about its own processing.
The current application does not include advertising trackers or request Google services merely to display this notice. If you email the contact address, your email provider and the recipient’s Gmail service process that message; it is separate from automated checkout, which currently sends no emails.
6. Retention, access, correction and deletion
Expired login sessions, challenges and rate-limit records are subject to bounded cleanup during service requests. Account profiles and order records do not currently have an automatic deletion schedule or a self-service deletion button. Signing out, clearing browser storage, cancelling an order or disconnecting Google does not automatically delete those database records.
You can ask about access, correction or deletion by emailing [email protected]. Identify the relevant site and account email and describe the request; do not send passwords, Google credentials or full identity documents. We may need to verify that the account or order belongs to you before acting. The site operators will review the request and explain the available steps; this notice does not promise an automatic deletion deadline.
7. Changes to the test service
This notice reflects the version described on 14 September 2026. Data handling and this notice will need to be updated as the service changes, including before real payments, fulfilment or additional data uses are introduced. This page is a privacy notice, not commercial purchase terms or a claim of provider approval or certification.