At a glance: We process data mainly for accounts, business sourcing, enquiries and orders, chat, and secure operation. We do not sell personal data or track behaviour across apps or websites for advertising. We currently do not integrate third-party advertising, behavioural analytics or crash analytics SDKs. You can manage profile information and permissions and request account deletion in the app.
1. Scope and data controller
This Policy applies to the B2B Direct mobile app and the global B2B product discovery, sourcing request, enquiry, order and communication services provided through it. Where a merchant independently decides how to process information received in a transaction, it may act as an independent controller and its practices are governed by its own notice and applicable law.
The data controller or personal information handler is:
We process data under laws applicable to where business takes place and where users are located. These may include China's Personal Information Protection Law, the EU General Data Protection Regulation (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”). The precise rights and legal bases depend on the law that actually applies.
2. Data we collect and process
“Required” means the relevant core feature cannot operate without the data. “Optional” means you can withhold it, although a related profile, media or communication feature may not work. Collection screens also identify fields that are mandatory in context.
| Category and examples | Purpose | Whether required and effect of refusal |
Account and authentication Phone number, password authentication data, SMS verification code, user ID and session token |
Create an account, sign in, maintain a session, verify identity, and recover or protect an account |
Required for core service Without phone and authentication information, you cannot register or sign in. Codes are used only for verification and security. |
Profile Nickname, gender and avatar |
Display identity, complete the profile and support merchant communication |
Partly optional A nickname or system identifier distinguishes the account. Gender and a custom avatar may be omitted without affecting basic browsing. |
Recipient and contact Recipient name, phone, country/region, full address and address label |
Prepare quotations, orders, delivery and transaction communications |
Required for a transaction Not needed merely to browse. Without it, you cannot complete an enquiry or order that requires delivery. |
Browsing and sourcing preferences Search terms, browsing and product interactions, favourites and cart contents |
Return search results, save products you select, maintain a cart and improve in-service finding and functionality |
Mixed Search and browsing requests are needed for those functions. Favourites and cart are voluntary and can be cleared. |
Enquiries, orders and delivery Products, quantities, amounts, currency, quotations, order status, delivery details and transaction-related support requests |
Send enquiries to merchants, form and manage orders, coordinate fulfilment, after-sales issues, audits and disputes |
Required for a transaction Without it, you cannot submit or manage that enquiry or order. The Platform currently does not collect online payment-card or in-app-purchase data. |
Sourcing requests Title, description, category, target country, budget, quantity, delivery and certification requirements, and image/video/file attachments |
Publish a request and help suitable merchants discover, evaluate and respond to it |
Required to post / attachments optional Not posting does not affect other features. Enough request content is required to post; attachments are generally optional. |
Chat and community content Chat text, images, video, files, read and block status; public comments, likes and sourcing-plaza content |
Enable buyer–seller communications and file transfer, display interactions, handle reports and maintain community safety |
Feature-triggered You choose to send or interact. Refusal does not affect browsing, but the related communication or posting feature will not work. Public-area content is visible to the relevant Platform users. |
Display media Avatar, profile images and video you choose to upload |
Complete your profile and display it to merchants or Platform users as indicated by the feature |
Optional Uploading is not required for sign-in or basic sourcing. |
Security and technical logs IP address, User-Agent/device and app environment, login time and result, failure reason and request trace ID |
Prevent unauthorised access, troubleshoot, audit, prevent fraud and secure networks and the Service |
Required for operation and security Generated when you connect. If necessary logging is blocked, we may be unable to provide a secure online service. |
Local settings Language, theme, session state, cart and app preferences |
Keep interface and feature choices on your device |
Functional or optional Some remain only on the device. Clearing app data may require you to select them again or sign in again. |
Do not place unrelated identity documents, financial-account data, health data, precise location or other sensitive personal data in free text, attachments or chat. If business and law genuinely require such data, first verify the recipient and transmission method.
3. Sources of data
- Directly from you: registration, profile, addresses, enquiries, sourcing requests, content, attachments and support communications.
- From your use: search, browsing, favourites, cart, message state, order flow and security logs.
- From merchants or transaction participants: quotations responding to your enquiry, order confirmations, shipping and after-sales status, and chats or dispute material in which you jointly participate.
- From the device: camera, photos, microphone or files you select only after you trigger a feature and grant permission. We do not continuously read this content in the background without reason.
4. Purposes and legal bases
We use data to provide accounts and business matching; connect you with merchants; process enquiries, orders, delivery and support; provide chat and community features; prevent fraud, moderate and secure the Service; comply with law, respond to lawful requests and establish, exercise or defend legal rights; and analyse operation and improve features using aggregated or de-identified information.
Depending on applicable law, our legal bases may include:
- Contract and pre-contract steps: registration, sign-in, search, enquiries, orders, chat and other services you request;
- Consent: device permissions, optional profile data and processing or transfers for which consent is legally required. You may withdraw consent, without affecting processing already lawfully carried out;
- Legal obligations: regulatory, tax, audit, safety and complaint requirements and legally required retention or disclosure;
- Legitimate interests: where applicable law permits and after balancing interests, account and network security, fraud prevention, troubleshooting, Service maintenance and legal claims; and
- Other grounds under Chinese law: necessity to enter or perform a contract to which you are party, perform legal duties, respond to public-health needs or urgently protect life or property, and other grounds provided by law.
We do not use personal data for a new purpose that is unreasonably unrelated to these purposes. If notice or consent is legally required for a new purpose, we will complete it before processing.
5. Device permissions
| Permission | When used | Your control |
| Camera | Take an avatar, product/sourcing material or chat media | Requested only when you initiate capture. Withdraw in system settings and continue using features that do not need the camera. |
| Photo read and save | Select an image/video to upload, or save media you expressly select to Photos | Refuse or use limited photo selection where available. Refusal prevents gallery upload or saving but not text features. |
| Microphone | Capture sound when you use the video-recording feature | Requested only for that action. Refusal prevents sound from being captured in the recorded video. |
| File selection | Select and upload a file for sourcing, chat or a dispute | We process only files you expressly select in the system picker; this does not give us permission to browse all files. |
You can withdraw permissions in iOS Settings. Withdrawal does not affect processing already completed under valid permission, but stops new permission access. The app currently does not require precise location or contacts permission.
6. Sharing, public disclosure and recipients
We do not sell personal data or provide it to data brokers. We share only as follows:
- Merchants and transaction participants. When you start a chat, we show the relevant merchant only the nickname, avatar, media you choose to display through profile features, and messages and media you send as needed for communication; an ordinary customer profile or chat does not automatically reveal your phone number or delivery address. We provide the necessary contact name, phone number, delivery address, sourcing request, product and order content to the corresponding merchant only when you submit an enquiry or order and that information is needed for quotation or fulfilment. A merchant is responsible for information it independently retains and uses.
- Other Platform users. Sourcing requests, comments, likes and public profile elements you choose to post are displayed as indicated on the screen. Do not include contact or personal data you do not want made public.
- Service providers. Providers of cloud hosting, databases, object storage, content delivery, security logging and SMS verification process data only under our instructions and as needed to provide the service, subject to contractual, confidentiality and security duties.
- Professional advisers and authorities. We may provide necessary data to audit, legal or security advisers, courts, law enforcement, regulators or public authorities to meet legal duties, protect rights or address an emergency.
- Corporate transactions. In a merger, reorganisation, financing or business succession, necessary data may be provided under confidentiality and law. If the controller changes, we will give legally required notice and continue to protect your rights.
Except for competent public authorities acting independently under law, we use contracts, Platform rules or other appropriate arrangements to require recipients of personal data shared from the Platform to provide the same or equivalent protection required by this Policy and applicable data-protection requirements, appropriate to their role, including purpose limitation, security, confidentiality, retention and deletion, and assistance with individual rights.
If you provide another person's recipient or contact details, ensure you are entitled to provide them for the transaction and explain the necessary processing to that person.
7. Key service providers
Amazon Web Services (AWS)
Location: Milan, Italy region (eu-south-1), together with network points needed for content delivery.
Services and data: application hosting, databases, object storage, CDN, network security and operational logs. The related processing may cover account, profile, transaction, content, media and technical-log data.
Role: infrastructure service provider/processor acting for us.
Providers, regions and arrangements may change for reliability and compliance. If a change materially affects your rights, we will update this Policy and provide notice or obtain consent where law requires.
8. Transfers between China and Europe
B2B Direct is a global Platform. Because the operator is in Switzerland, primary cloud infrastructure is in Milan, Italy, and content delivery may use network points needed to improve access speed, your data may be transferred from your country or region to the European Economic Area, Switzerland or a relevant network point, or remotely accessed by authorised personnel where genuinely necessary to provide the Service. For example, a Chinese user's account, transaction or media may be stored in Italy.
Depending on the law that actually applies, we will adopt the required safeguards, which may include data-processing agreements, access and minimisation controls, EU Standard Contractual Clauses or another recognised mechanism, transfer impact assessments, and a Chinese security assessment, standard contract, personal-information protection certification or other lawful route where required. We do not claim that a certification has been obtained where it is not yet applicable or complete. Where separate consent is required, before transfer we will separately explain the recipient, purpose, means, categories and rights method and obtain that consent.
Protection levels differ by country, but we require recipients to protect data under applicable law, contract and this Policy. Contact us for a summary of safeguards relevant to you.
9. Retention and account deletion
While an account exists, we retain data only as needed to provide features, operate securely and meet obligations. The period depends on data type, transaction cycle, risk, disputes and legal requirements:
- Account credentials, profile, addresses, favourites, cart, interactions and notifications are generally retained until you delete the item or account. Short-term security logs are kept only as needed for troubleshooting, fraud prevention and security audit.
- When in-app account deletion takes effect, credentials, personal profile and media, addresses, favourites, cart, interactions, notifications and identifiable login logs are immediately deleted or anonymised.
- Transaction records covering orders, quotations, delivery, related chats and attachments are kept until the transaction is completed and for at least three years from completion. After account deletion, these records—including delivery details, related chats and attachments—are not visible on either the buyer or merchant side. Only authorised Platform operations personnel may retrieve them under controlled procedures where genuinely necessary for fulfilment, audit, dispute resolution, fraud prevention or a legal duty.
- At the end of the minimum period, the system automatically and permanently deletes or destroys the records unless law, a fraud investigation or an unresolved dispute requires longer retention. Any extension is limited to what is needed for that purpose, followed by deletion or destruction when the reason ends.
- Local device preferences can be cleared through app settings, system settings or by deleting the app. Clearing local data does not itself delete the server account.
You can initiate deletion in account settings. We may verify the current session or identity to prevent impersonation. Deletion cannot be reversed and does not cancel a contract already made with a merchant, so save necessary records and address incomplete transactions first.
10. Security and incident response
We apply reasonable organisational and technical measures appropriate to the data and risk, including protections in transit, access permissions and separation of duties, authentication, logging and anomaly monitoring, backups, provider management and staff confidentiality. Only personnel authorised for a work-related need may access personal data.
No internet service is absolutely secure. Use a unique, sufficiently strong password, never give another person a verification code, and verify merchants and payment instructions. If a personal-data incident may risk your rights, we will investigate, contain impact, and notify regulators and affected people as applicable law requires, describing the nature, possible effect, response and protective steps available to you.
11. Your data rights
Subject to applicable law and its exceptions, you may have the right to:
- be informed, access data and receive a copy;
- correct or complete inaccurate or incomplete data;
- erase data, delete an account, or restrict or object to particular processing;
- receive data in a structured, commonly used and machine-readable form and request transfer where law provides;
- withdraw consent, disable device permissions or opt out of non-essential processing;
- request an explanation of processing rules, cross-border recipients and significant automated decisions; and
- complain to a competent data-protection or cyberspace authority.
You can edit profile and addresses, manage content and permissions, and request deletion in account settings. You may also email support@b2bdirect.online. State the account, scope of request and location. To protect the account, we perform verification proportionate to the request's risk and do not require unnecessary data.
We respond within the time under applicable law. China-related requests are normally addressed, or a reasonable extension explained, within 15 working days. Where GDPR applies, we normally respond within one month and may lawfully extend for complex or multiple requests with reasons. Swiss and other requests follow local statutory periods. We reject or charge a reasonable fee for manifestly unfounded, repetitive or excessive requests only where law permits and will explain available remedies.
Withdraw an iOS permission through Settings. Withdrawal does not affect processing lawfully carried out beforehand. Data required for contract performance, legal duties or legal claims may not be immediately erased, but its purpose and access will be restricted.
12. Automated processing, analytics and advertising
The Platform may use search criteria, categories and product interactions you initiate to provide in-service search and relevant content. It currently does not make decisions producing legal or similarly significant effects solely by automated processing. We currently do not integrate third-party advertising, behavioural analytics or crash analytics SDKs, do not track across apps or websites, and do not use personal data for third-party behavioural advertising.
We may use aggregated or de-identified operational statistics to understand stability and use. We take measures to prevent reasonable re-identification. If data remains identifiable, this Policy continues to apply.
13. Children's data
The Service is for businesses and professional sourcing and is not directed to children. You must have the legal capacity required in your location. If you do not, use is permitted only with parental or legal-guardian consent and supervision and where law allows. We do not knowingly create behavioural-advertising profiles of children.
If a guardian believes a child provided data without valid authorisation, contact us. We will verify the request and erase the data or take other appropriate action under law.
14. Updates to this Policy
We may update this Policy for changes in law, features, data practices or providers. The version, publication and effective dates appear at the top. For a change materially affecting purposes, data categories, sharing or your rights, we will give advance in-app or other reasonable notice. Where consent is required, we will obtain it before the new processing begins.
You may print or save this version and contact us for a historical version applicable to a particular period.
Related document: Read the B2B Direct User Agreement