Why avoid fully automated scraping or replies on 1688, Taobao, JD.com, and Xiaohongshu?
An account's ability to view or reply manually does not authorize bulk collection or bot posting. Automation without permission from the platform and data rights holders is unstable and may violate platform contracts, personal-information duties, and competition rules. Prefer official platform capabilities and merchant authorization. Where none exists, use human operation or explicitly approved assistance—not hidden endpoints, shared cookies, rotating IPs, or CAPTCHA evasion.
Not every automation on these platforms is prohibited. Official APIs, service marketplaces, merchant tools, and partner programs differ and change by entity, scenario, and version. Verify who owns the target shop, whether the application is approved, which objects the merchant or user authorized, whether the interface permits this purpose and retention, and whether a message may be sent automatically.
When translating compliance duties into evidence and controls, also compare How can authorized web-data collection reduce blocking and anti-bot risk? and What content-governance duties apply to a community posting platform?; the linked guidance adds context that should be considered in the same decision.
| Route | Authority | Recommendation |
|---|---|---|
| Official API, event subscription, or marketplace app | Reviewed application, merchant grant, documented scope | First choice; maintain versions and quotas |
| Platform's own support and operating tools | Normal merchant permission | Use directly when sufficient |
| AI reply draft approved by staff | Staff sends through the official workspace | Preferred when reliable send permission is absent |
| RPA explicitly approved in writing | Named account, action, frequency, and data | Transitional only, with a stop mechanism |
| Hidden API, reused cookie, CAPTCHA or anti-bot evasion | No formal authorization | Do not implement |
Official access is still bounded. Taobao's developer materials describe merchant grants, certificates, transaction APIs, messaging, and protected fields; JD's developer platform offers official commerce capabilities. They do not grant every developer every dataset. Record application ID, shop, scopes, API version, quota, fields, and expiry. Stop synchronization and delete as agreed after revocation.
Even the client's own orders may contain consumer names, phones, and addresses. Supply only necessary fields to fulfilment, support, and finance, mask sensitive values, and audit export and viewing. Cross-shop products, reviews, and profiles add the rights of other merchants, consumers, and the platform.
Automated replies create more than account risk: an old price, incorrect stock statement, or unauthorized refund promise can become a commercial and brand problem. Limit any approved automation to low-risk stable facts such as logistics status, opening hours, or reviewed FAQs. Send refund, compensation, complaint, health, and legal matters to people. Retain the knowledge version, sent identity, message, and feedback, with human takeover.
Draft assistance is often safer: use authorized conversation context and a governed knowledge base to suggest a response that staff confirm in the official client. Evaluate response time, adoption, false promises, handoff, complaints, and resolution—not a promotional “80% solved.” High rewrite rates indicate missing context or a bad scenario boundary.
For collection, ask first for an API, data product, export, or partnership. Public visibility, permissive robots.txt, or absence of a technical block does not grant commercial copying or redistribution. CAPTCHA, access restriction, or account anomaly triggers a stop and platform contact. Acceptance for official integration covers authorization and revocation, shop isolation, token rotation, rate limits, masking, duplicate messages, order changes, and API retirement.
Wavesteam begins with the platform, shop ownership, action, and data purpose, then checks current official documentation. We integrate the minimum official scope, or build internal organization and reply drafts when work must remain manual. Unauthorized cross-shop collection, bulk messaging, artificial traffic, and control evasion are refused. References include the Taobao developer guide, JD developer centre, and China's Data Security Law.