Governance
Youyoumi maintains documented policies for information security, access control, data classification, incident response, vulnerability management, retention, and data-subject requests. Policies are reviewed at least annually and after material changes or incidents.
Identity and access
Operational systems require authentication and use member and administrator roles. New portal passwords must contain at least 12 characters. Access is approved for a defined business purpose, reviewed periodically, and removed when no longer needed.
Encryption and application security
Traffic is protected with HTTPS and HSTS. Session cookies use Secure and HttpOnly attributes. Passwords are stored as salted PBKDF2-SHA-256 hashes. TikTok Shop access tokens persisted by the application are encrypted with AES-GCM before database storage, and Cloudflare-hosted objects are encrypted at rest.
Network protection and monitoring
The website runs behind Cloudflare's global network with managed web-exploit and DDoS protections. Worker service logs are enabled for operational monitoring and incident investigation. Security headers restrict framing, content types, referrers, browser permissions, and content sources.
Endpoint baseline
Company-managed Windows endpoints are required to run supported operating systems, active anti-malware protection, automatic security updates, screen locking, and device encryption where supported. A reviewed Windows endpoint showed Microsoft Defender real-time, behavior, and network inspection enabled with current signatures on 4 August 2026.
Data locations and retention
Primary application storage is placed in Cloudflare's Asia-Pacific region. Authorized personnel may process data from China, while Cloudflare's network may process traffic globally. Following service termination or valid authorization revocation, eligible active customer data is deleted or anonymized within 30 days and residual backups age out within 90 days, subject to documented legal-retention exceptions.
Requests and incident reporting
To request access, correction, portability, deletion, authorization revocation, or to report a suspected security or privacy incident, contact chuan@youyoumi.asia. We aim to acknowledge requests within 5 business days and complete valid requests within 30 calendar days, subject to applicable law.