Privacy Policy

Last updated: October 3, 2026

This Privacy Policy explains how Chaperon Co., Ltd. (“Chaperon Supply”, “we”, “us”) collects, uses, and shares personal data when you use our services.

Entity: Chaperon Co., Ltd. Location: Hong Kong Contact: privacy@chaperon.supply

Network early-access interest

When intake is open, sign up or sign in to share your broad sourcing need, requested services and selected source countries (or openness to suggestions). We use your account email. Delivery destination, quantities, timing, budgets, location details and product links are optional. We use these details privately for review, demand analysis, partner recruitment planning and expansion planning. China is our first planned active source region; other countries are expansion interest, not a promise of coverage. Do not submit personal documents, payment information or confidential designs. Image uploads are unavailable.

Authorised staff review requests privately. We record terms acceptance, separate consent choices, the wording and policy version shown, timestamps, confirmation and operational history. Contact-email confirmation is separate from account registration.

Permission for later partner sharing is optional and initially unchecked. We will ask you to approve the exact brief before sharing with eligible partners when participation is ready. Terms acceptance does not grant partner sharing, marketing or social-media publication permission.

To correct or withdraw sourcing interest or revoke a consent choice, email info@chaperon.supply or privacy@chaperon.supply from your account email. You can approve source-country corrections in My Network interest. Original selections remain in the private history. Revoking sharing permission prevents later sharing through this intake. Minimal consent and operational records remain under the retention policy below. Simulations are excluded from genuine demand; China-first, mixed-country and expansion interest are reported separately.

Updates-only signup, basic partner interest and suggestions have separate, explicit permissions. They are associated with your account and are not applications or sourcing posts. You can withdraw their permissions in My Network interest. Suggestions are not published without permission. We record stable country codes for selector events, not country-search text or confidential request details.

We retain a minimal record of the early-access offer with your account, separately from your sourcing details. This lets us honour the offer if your brief is later removed under our retention policy. Recording the offer does not start a trial.

1) What we collect

  • Account information: email address, username/name, password (stored as a hash), account type and membership tier/status.
  • Product usage: actions you take in the product (for example, viewing or saving sourcing comparisons). We record these as first‑party analytics events in our database.
  • Optional advertising measurement: if you allow it, Google Ads may receive limited browser and conversion information so we can measure whether an ad led to a paid supplier check or subscription. We do not send supplier names, sourcing requirements, scam reports, or payment card details in those conversion events.
  • Payments: Stripe customer/subscription identifiers and payment metadata needed to provide subscriptions and verification payments. We do not store full card details; Stripe handles card processing.
  • User-submitted content: information you submit in forms (e.g., suspected scam reports, factory verification requests) and any files you upload as evidence.
  • Private founding-buyer requests: contact details, non-confidential sourcing context, consent choices, campaign attribution, and review status when that intake is available. These requests are not automatically published or shown to partners.
  • Communications: messages you send to us (for example, support and operational emails).

2) How we use personal data

  • Provide and operate the service: authentication, search, saved items, verification request workflows, and account management.
  • Trust & safety: prevent abuse, investigate suspicious activity, and maintain platform integrity.
  • Improve the product and advertising: understand feature usage with first‑party analytics and, where you allow it, measure whether advertising led to a paid supplier check or subscription.
  • Communications: send transactional emails (e.g., email verification) via Resend.
  • Legal compliance: comply with applicable laws, respond to lawful requests, and enforce our terms.

3) Legal bases (EEA/UK users)

If you are in the EEA/UK, we rely on one or more of these legal bases: performing our contract with you; our legitimate interests (such as security and service improvement); your consent for optional advertising measurement; and compliance with legal obligations.

4) Analytics and cookies

Our product analytics are primarily first‑party: we record certain in‑product actions as events in our own database (e.g., when a sourcing comparison is viewed or saved). If you allow optional Google Ads measurement, Google may set or read advertising-related cookies and receive a paid-conversion event. You can allow or decline this measurement in the consent prompt shown on the site.

Our site also uses cookies that are necessary for core functionality (for example, security and session handling). We will update this policy and provide choices and controls if we introduce additional non-essential tracking technologies.

5) How we share data

  • Service providers: we use vendors to run the service, including Stripe for payments, Resend for transactional email delivery, and, when you allow optional advertising measurement, Google for Google Ads measurement.
  • Public/community information: some user-submitted reports may be displayed to other users after review (for example, suspected scam reports marked open/resolved). We aim to minimize personal data in what we publish.
  • Legal: we may disclose information if required by law or to protect rights, safety, and security.

6) International transfers

We are based in Hong Kong and may process or store data in other jurisdictions (for example, where our service providers operate). Where required, we use appropriate safeguards for cross‑border transfers.

7) Data retention

We keep personal data only as long as necessary for the purposes described above. Our current retention approach includes:

  • First‑party analytics events: retained for up to 12 months, then deleted.
  • Private founding-buyer requests: unconfirmed and withdrawn requests are scheduled for review after 30 days; declined or duplicate requests after 90 days; and deferred requests after 180 days. Active requests receive at least annual review. When no longer needed, identifying and free-text business context is anonymized while bounded aggregate and audit records may remain.
  • Verification requests and outcomes: retained as part of product records and trust/safety history, with efforts to minimize personal data.
  • Suspected scam reports: retained as product records; corrections/removals may be handled with verifiable evidence.
  • Uploaded files: retained as needed for review, evidence, and product records; we may remove or anonymize files where appropriate.

8) Your rights

  • Access/correction: request access to or correction of your personal data.
  • Deletion: request deletion of personal data, subject to legal and operational requirements.
  • Objection/restriction (EEA/UK): object to processing or request restriction in certain circumstances.
  • Withdraw consent (EEA/UK): where we rely on consent, you can withdraw it at any time.

To exercise rights, contact privacy@chaperon.supply.

9) Security

We use reasonable technical and organizational measures designed to protect personal data. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

10) Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the effective date where appropriate.