Privacy Policy

12 SECTIONS · Last updated: April 2026

Welcome to this Privacy Policy. Next Generation Artificial Intelligence Gaming Labs Inc. (hereinafter "the Company" or "we/us") recognizes the significance of personal information security to you. We adhere to the principles of lawfulness, legitimacy, necessity, and good faith in carefully handling every piece of data you entrust to us. This Policy is designed to help you fully understand our data processing practices in providing the Merry Amazon Seller ERP management service, as well as the rights you are entitled to under applicable law.

Please read and understand the entire content of this Policy carefully before registering an account or using our services. If you have any questions about any provision of this Policy, please contact us through the methods provided at the end of this Policy. This Policy is governed by the laws of the United States of America. Any dispute arising out of or relating to this Policy shall be resolved exclusively in the federal or state courts located in the State of Delaware.

§01 — About This Policy

Scope of This Policy

This Privacy Policy applies to all personal information processing activities that arise when you interact with the Company through the following channels: visiting the Merry official website (including desktop and mobile pages); registering for and using the various functions of the Merry ERP system; connecting your Amazon seller account to the Merry system through the authorization process; and contacting our customer service team via phone, email, or tickets. This Policy does not apply to any third-party websites, applications, or services, even if such websites or services may be linked to this website.

Legal Basis

This Policy is formulated in accordance with applicable United States federal and state privacy laws, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Amazon Developer Acceptable Use Policy and Data Protection Policy. We commit to meeting the requirements of all applicable regulations and policies in all data processing activities, and regularly review our compliance status. For users located in the European Union, the UK, or other jurisdictions with additional data protection laws, supplemental protections may apply as described herein.

Your Consent

When registering a Merry account, you must check and confirm that you have read and agree to this Policy, which is a prerequisite for completing registration. When you proactively authorize the Merry system to access your Amazon store data, the system will clearly display the data categories and specific uses intended, allowing you to independently decide whether to grant permissions. For non-essential information collection (such as analytics cookies), we will separately seek your explicit consent. You have the right to withdraw previously given consent at any time, though withdrawal does not affect the validity of lawful processing activities completed prior to withdrawal.

Legal Effect

This Policy constitutes a legally binding agreement between you and the Company regarding personal information processing matters. This Policy remains in effect during your use of the Company's services and until the relevant data has been deleted or anonymized in accordance with this Policy. This Policy is governed by and construed in accordance with the laws of the United States of America, without regard to conflict of law principles.

§02 — Who We Are

Company Overview

Next Generation Artificial Intelligence Gaming Labs Inc. is a corporation incorporated under the laws of the State of Delaware, United States of America, dedicated to providing efficient enterprise resource management tools for cross-border e-commerce practitioners and AI-enhanced business solutions. Our principal place of business is located in the State of Delaware. For service delivery purposes, we may utilize infrastructure and service providers located within and outside the United States, all of whom are contractually bound to comply with applicable data protection standards.

Products and Services

Merry is an ERP management system designed specifically for Amazon sellers, aimed at helping sellers efficiently manage core business processes in their daily operations. The functional modules provided by the system include: order fulfillment tracking and management, inventory level viewing and replenishment planning, sales data and profit report generation, advertising data consolidation and analysis, and procurement process management. As an Amazon Public Developer, the Company has obtained official Amazon authorization to lawfully access and process user-authorized business data in accordance with the Amazon Developer Agreement to deliver the aforementioned services to users.

Data Roles

With respect to account information and personal contact details you actively provide during registration, the Company acts as a "business" under the CCPA and a "data controller" under the GDPR, independently determining the processing purposes and methods for such information. With respect to business operations data you manage through the Merry system, you are the "business" or data controller, and the Company serves as a "service provider" or data processor entrusted by you, processing such data only according to your instructions and the purposes agreed in this Policy, and will not use your business data beyond the authorized scope.

§03 — Information We Collect

We strictly follow the principle of data minimization, collecting only information necessary to provide services to you, and will not cross-compare or consolidate data from different users. The following lists the information we may collect by category:

Account and Identity Information

When you register a Merry account, we will collect the following information:

Business Operations Data

After you authorize the Merry system to connect with your Amazon seller account, the system will obtain the following business data from the Amazon platform according to the scope of permissions you grant. We only request the minimum permissions necessary to deliver the corresponding system functions:

Technical and Device Information

When you visit this website or use the Merry system, our servers will record the following technical information:

§04 — How We Use Information

We use the collected information exclusively for the following purposes, and will not use your personal information beyond these purposes without first obtaining your separate consent:

Service Delivery

Service Improvement

Legal and Security Compliance

§05 — Storage and Protection

Data Storage Location

We primarily store data on secure cloud infrastructure located within the United States. Subject to applicable legal requirements, we may also utilize infrastructure in other jurisdictions through service providers that maintain equivalent or higher data protection standards. All data storage providers are subject to contractual obligations requiring compliance with this Policy and applicable law.

Security Measures

We implement and maintain appropriate technical and organizational security measures to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

Incident Response

In the event of a data security incident that may materially affect your personal information, we will notify you and the relevant supervisory authorities (where required by law) without undue delay after becoming aware of the incident. Our incident response plan includes immediate containment, forensic investigation, remediation, and notification procedures.

§06 — Sharing and Disclosure

Service Providers

We may share your personal information with third-party service providers who perform services on our behalf, such as cloud hosting, data analytics, customer support, and email delivery. All service providers are contractually bound to process your information only for the specific purposes we specify and to maintain the confidentiality and security of your information. We require all service providers to comply with data protection obligations equivalent to those set forth in this Policy. A list of our current service provider categories is available upon request.

Legal Compliance and Protection

We may disclose your personal information if required to do so by law, regulation, legal process (such as a court order or subpoena), or governmental request. We may also disclose your information to enforce our agreements, protect the rights, property, or safety of the Company, our users, or others, or as otherwise required by applicable law. Where permitted, we will make reasonable efforts to notify you in advance of such disclosure.

Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your personal information may be transferred to the acquiring entity. We will require any such successor entity to honor the commitments made in this Policy or provide you with notice and an opportunity to opt out of any material changes.

No Sale of Personal Information

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising. We do not trade, rent, or otherwise monetize your personal information.

§07 — Cross-border Data Transfers

Given that the Merry system serves users in the cross-border e-commerce industry, cross-border transfer of personal information may be involved in system operations. We adopt the following measures to ensure the legality and security of cross-border data flows.

Legal Compliance

The Company is headquartered in the United States. For users located outside the United States, we ensure that cross-border data transfers are conducted in compliance with applicable local laws. For transfers involving personal data of data subjects in the European Economic Area (EEA), the UK, or other jurisdictions with transfer restrictions, we rely on one or more of the following mechanisms: (i) Standard Contractual Clauses (SCCs) approved by the European Commission or the UK; (ii) an adequacy decision by the relevant authority; or (iii) other lawful transfer mechanisms recognized under applicable law.

Transfer Security Measures

§08 — Data Retention

We follow the retention principle of "purpose limitation, minimum duration," setting differentiated retention periods for different types of data. Retention periods are determined by comprehensively considering: the necessity of continuing service provision, minimum retention periods prescribed by law, reasonable periods needed for potential dispute resolution, and the need to maintain system security.

Retention Rules by Data Type

Special Rules for PII (Personally Identifiable Information)

For data containing Personally Identifiable Information (PII) obtained through Amazon authorization — such as buyer names, mailing addresses, and contact details — we strictly limit its use to order fulfillment purposes only. After relevant orders have been shipped and delivery confirmed, all associated PII data will be securely and irreversibly deleted within 30 days. If extended retention is mandated by applicable law, such data will be stored encrypted in an isolated secure environment, used only within the scope permitted by law, and destroyed at the earliest time permitted.

Deletion Methods

Data deletion uses secure erasure methods to ensure data is thoroughly overwritten and irrecoverable on storage media. Data copies in backup systems are deleted together with the normal rotation cycle of backup files. After each deletion operation, the system generates a deletion confirmation record for audit traceability.

§09 — Your Rights

Under applicable data protection laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the General Data Protection Regulation (GDPR) where applicable, you enjoy the following rights regarding your personal information. You may submit requests to us through the contact methods listed in §12 of this Policy, and we will respond without undue delay, and in any event within the timeframes required by applicable law (generally 30 to 45 calendar days).

Right to Know / Right of Access

You have the right to know what personal information about you we are collecting, using, disclosing, and selling (if any), the categories of sources from which it is collected, the business or commercial purpose for collection, the categories of third parties with whom we share it, and the specific pieces of personal information we have collected. You have the right to request a copy of your personal information we hold.

Right to Correct / Right to Rectification

When you discover that personal information we hold about you is inaccurate or incomplete, you have the right to request correction or supplementation.

Right to Delete / Right to Erasure

You have the right to request deletion of your personal information in the following circumstances: the original purpose of collection and processing has been fulfilled and the information is no longer needed for that purpose; you have withdrawn consent and no other lawful basis for processing exists; information was collected or processed unlawfully; or as otherwise provided by applicable law. Under the CCPA, you have the right to request deletion of personal information we have collected from you, subject to certain exceptions.

How to Delete Your Data from Merry

As required by Amazon's Selling Partner API Data Protection Requirements, we provide the following methods for you to request deletion of your data from Merry:

Upon receiving a valid deletion request, we will: (1) revoke all SP-API access tokens associated with your account; (2) delete your account information, business operations data, and any PII stored in our systems within the timeframes specified in §08; (3) confirm completion to you in writing. If you revoke Merry's authorization to access your Amazon seller account directly through Amazon Seller Central (Partner Network → Manage Your Apps), this will also automatically stop all data retrieval, but you must still submit a separate deletion request to remove data already in our systems.

Right to Data Portability

You have the right to receive personal information you have provided to us in a structured, commonly used, machine-readable format, and to request direct transmission to another entity where technically feasible.

Right to Opt Out of Sale/Sharing

We do not sell or share your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA. However, you retain the right to opt out of any future sale or sharing of your personal information should our practices change.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. This means we will not deny you services, charge you different prices, or provide you a different quality of service because you exercised a privacy right.

Right to Withdraw Consent

For data processing activities based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the validity of lawful processing completed based on your consent prior to withdrawal. If you withdraw authorization for data required by core functions, those functions may no longer be usable, but this will not affect the normal operation of other independent functions.

Right to Lodge a Complaint

If you believe our processing of your personal information violates applicable law, you have the right to lodge a complaint with the competent data protection supervisory authority. In the United States, you may also contact the Federal Trade Commission (FTC) or your state's attorney general. We also welcome you to first contact us directly through the methods listed in §12 of this Policy, so that we have the opportunity to address your concerns promptly.

Identity Verification

To ensure information security, we need to verify the requester's identity before processing your rights request. Verification methods may include account login verification, email confirmation, or other reasonable identity verification means. We use commercially reasonable efforts to verify your identity before granting access or acting on your request. We will not charge you for exercising your rights, but we reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests, as permitted by law.

§10 — Cookie Policy

This website and the Merry ERP system use cookies and similar technologies to maintain normal service operation and enhance user experience. We do not use any cookies for cross-site tracking or building personal user profiles.

Necessary Cookies

These cookies are essential for the system to function properly, used to maintain your login session, perform identity authentication, and manage CSRF security tokens. They fall within basic functional assurance and may be used without your consent under the "strictly necessary" exception under most privacy laws. If you disable these cookies, core system functions (such as login state maintenance, security verification) will not work properly.

Functional Cookies

These cookies remember your interface preferences — such as language options (English/Chinese), table display density, timezone settings — to provide an experience tailored to your habits on subsequent visits. Functional cookies do not collect information that can identify you.

Analytics Cookies

With your explicit consent (where required by law), we may use analytics cookies to collect anonymous visit statistics, including page views, feature module usage frequency, and user dwell time. This data is used only in anonymous aggregated form to help us understand product usage and optimize feature design.

Managing Your Cookies

You can view, manage, or delete cookies at any time through your browser settings. Major browsers (Chrome, Firefox, Safari, Edge) provide corresponding management options. Please note: deleting necessary cookies may require you to log in again; disabling functional cookies will prevent preference settings from being saved; refusing analytics cookies will not affect core system functionality.

§11 — Protection of Minors

Service Audience Statement

The Merry ERP system is a business management tool for enterprise users, targeting adults with full legal capacity (aged 18 and above or the age of majority in their jurisdiction). This system and website are explicitly not intended to provide services to minors under 18 years of age, and we do not knowingly collect any personal information from minors. Our services are directed to businesses and are not intended for children.

Children's Privacy (COPPA Compliance)

We comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws regarding children's privacy. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us immediately.

Discovery and Remediation

If we subsequently discover that we have inadvertently collected personal information from a minor under 18, we will immediately take the following steps: first, suspend all functional permissions of the account and flag it as pending; second, securely delete all personal information related to the minor (including backup copies) after verification; third, where possible, notify the minor's parent or guardian of the circumstances and our remediation measures. If you have reason to believe we may hold a minor's personal information, please immediately contact us through the methods listed in §12 of this Policy, and we will prioritize such reports.

§12 — Updates and Contact Information

Policy Revisions

We may revise this Policy based on the following circumstances: changes in applicable laws and regulations, adjustments in regulatory policies, updates to Amazon developer policies, changes in the Company's business scope, or improvements in security practices. The "Last updated" date noted at the top of the page is the effective date of the current version.

Material Change Notification

When this Policy undergoes changes that may significantly affect your rights, we will notify you at least 30 days in advance through one or more of the following methods:

Continuing to use the system's services after receiving the change notification is deemed as your acceptance of the updated terms. If you disagree with the updated content, please stop using the relevant services before the new Policy takes effect and contact us to handle account cancellation.

Contact Us

If you have any questions or suggestions about this Policy, or wish to exercise the data rights described in §09, please contact us through the following channels. We will respond to your request within the timeframes required by applicable law.

Company Name Next Generation Artificial Intelligence Gaming Labs Inc.
Data Protection Officer Ji Mengqi
Email Merry520@boattosea.net
Phone 3522263142
Registered Office State of Delaware, United States of America
Subject Reference Please indicate "Privacy Policy Inquiry" or "Data Rights Request" in your correspondence for prompt response

Thank you for taking the time to read this Privacy Policy. Safeguarding your data security and privacy rights is the Company's core commitment. We will continuously review and improve our data protection practices to ensure your information is always properly protected.

This Policy is governed by the laws of the United States of America. Any disputes arising out of or related to this Policy shall be resolved in the courts located in the State of Delaware.