B2B Direct · 隐私与数据保护

隐私政策

本政策说明 Wynie Holdings 在提供 B2B Direct 企业采购撮合服务时如何收集、使用、共享、跨境传输、保存和保护个人信息,以及您如何行使权利。

  • 版本:1.0
  • 发布日期:2026 年 7 月 29 日
  • 生效日期:2026 年 7 月 29 日
  • 最近更新:2026 年 7 月 29 日

摘要:我们处理的数据以账户、企业采购、询价订单、聊天和安全运行为核心;不出售个人信息,不进行跨应用或跨网站行为广告跟踪,目前未集成第三方广告、行为分析或崩溃分析 SDK。您可在应用内管理资料、权限并申请注销账户。

1. 适用范围与个人信息负责人

本政策适用于 B2B Direct 移动应用及我们通过该应用提供的全球 B2B 商品发现、采购需求、询价、订单与沟通服务。对于商户独立决定如何处理其从交易中取得的信息,商户可能是独立的个人信息处理者;其处理行为受其自身隐私说明和适用法律约束。

个人信息负责人/控制者为:

Wynie Holdings
Rue Ami-Lullin 12
1207 Geneva, Switzerland
隐私联系邮箱:support@b2bdirect.online

我们根据业务发生地及用户所在地适用的数据保护法律处理信息,可能包括中国《个人信息保护法》、欧盟《通用数据保护条例》(GDPR)及瑞士《联邦数据保护法》(FADP)。具体权利和法律基础以实际适用法律为准。

2. 我们收集和处理的信息

“必需”表示不提供会使相应核心功能无法使用;“可选”表示您可以不提供,但相关个性化、媒体或沟通功能可能不可用。某一字段是否必填也会在收集界面标示。

类别与示例用途必要性与拒绝后果
账户与认证
手机号、密码认证数据、短信验证码、用户 ID、会话令牌
创建账户、登录、保持会话、验证身份、找回或保护账户 核心功能必需不提供手机号和认证信息将无法注册或登录。验证码仅用于验证和安全目的。
个人资料
昵称、性别、头像
显示身份、完善资料并便于与商户沟通 部分可选昵称或系统标识用于区分账户;性别和自定义头像可不提供,不影响基本浏览。
收货与联系人
收件人姓名、电话、国家/地区、详细地址、地址标签
准备报价、订单、配送和交易沟通 交易时必需浏览时无需提供;拒绝提供将无法完成需要配送的询价或订单。
浏览与采购偏好
搜索词、浏览和商品互动、收藏、购物车内容
返回搜索结果、保存您主动选择的商品、维持购物车、改善站内查找和功能体验 混合搜索/浏览请求为提供对应功能所需;收藏和购物车由您自愿使用,可随时清除。
询价、订单与配送
商品、数量、金额、币种、报价、订单状态、配送信息及与交易有关的客服请求
将询价发送给商户、形成和管理订单、协调履约、售后、审计和争议 交易时必需不提供相关信息将无法提交或管理对应询价或订单。平台目前不收集在线支付卡或应用内购买信息。
采购需求
标题、描述、类别、目标国家、预算、数量、交付要求、认证要求及图片/视频/文件附件
发布需求并帮助合适商户发现、评估和回应 发布时必需/附件可选不发布不影响其他功能;发布时需提供足够的需求内容,附件通常可选。
聊天与社区内容
聊天文本、图片、视频、文件、已读状态、屏蔽状态;公开评论、点赞和需求广场内容
支持买卖双方沟通、传输资料、显示互动、处理举报和维护社区安全 功能触发由您主动发送或互动;拒绝不影响浏览,但无法使用相应沟通或发布功能。公开区域内容会对相应平台用户可见。
展示媒体
您选择上传的头像、资料图片和视频
完善资料,并按功能向商户或平台用户展示 可选不上传不会影响账户登录或基本采购。
安全与技术日志
IP 地址、User-Agent/设备与应用环境信息、登录时间、登录结果、失败原因、请求 trace ID
防止未授权访问、排障、审计、反欺诈、保障网络与服务安全 运行与安全必需在您连接服务时由系统生成;如阻止必要日志,我们可能无法安全提供在线服务。
本地设置
语言、主题、会话状态、购物车及应用偏好
在设备上保持您的界面和功能选择 功能必需或可选部分只保存在设备本地;清除应用数据后可能需要重新设置或登录。

请勿在自由文本、附件或聊天中提供与交易无关的身份证件、财务账户、健康、精确位置或其他敏感个人信息。确有业务和法律需要时,请先确认传输对象和安全方式。

3. 信息来源

  • 您直接提供:注册、资料、地址、询价、需求、内容、附件和客服沟通。
  • 您使用服务时产生:搜索、浏览、收藏、购物车、消息状态、订单流程和安全日志。
  • 商户或交易参与方提供:对您询价的报价、订单确认、发货状态、售后信息,以及与您共同参与的聊天或争议材料。
  • 设备提供:仅在您触发功能并授权后读取相机、照片、麦克风或您选择的文件;我们不在后台无故持续读取这些内容。

4. 处理目的与法律基础

我们将信息用于以下目的:提供账户和采购撮合服务;连接您与商户;处理询价、订单、配送和客服;提供聊天与社区功能;防欺诈、审核和保障安全;遵守法律、响应合法请求及建立、行使或抗辩法律权利;在汇总或去标识后分析服务运行并改进功能。

根据适用法律,我们依赖的法律基础可能包括:

  • 履行合同或订立合同前措施:注册、登录、搜索、询价、订单、聊天及您请求的其他服务;
  • 同意:设备权限、可选资料、依法需要同意的处理或跨境传输;您可随时撤回,但不影响撤回前处理的合法性;
  • 法定义务:监管、税务、审计、安全、投诉及依法保存或披露记录;
  • 合法利益:在适用法律允许并经利益衡量后,用于保障账户和网络安全、防欺诈、排障、维护服务及处理法律主张;
  • 中国法下的其他依据:为订立或履行您作为一方的合同所必需、履行法定职责或义务、应对公共卫生或紧急保护生命财产,以及法律规定的其他情形。

我们不会将个人信息用于与上述目的不合理相关的新目的;如新目的依法需要告知或同意,我们会在处理前另行完成。

5. 设备权限

权限触发场景控制方式
相机拍摄头像、商品/需求资料或聊天媒体仅在您触发拍摄时申请;可在系统设置撤回,之后仍可使用不需要相机的功能。
照片读取与保存选择要上传的图片/视频,或将您主动选择的媒体保存到相册可拒绝或使用系统提供的有限照片选择;拒绝后不能从相册上传或保存,但可使用文本功能。
麦克风在您使用视频录制功能时录制视频中的声音仅在对应操作时申请;拒绝后无法为所录视频采集声音。
文件选择选择并上传采购需求、聊天或争议所需文件仅处理您在系统选择器中明确选择的文件;不授予我们浏览设备全部文件的权限。

权限可在 iOS 系统设置中撤回。撤回不影响此前基于有效授权完成的处理,但我们会停止新的权限访问。应用当前不要求精确位置或通讯录权限。

6. 信息共享、公开与接收方

我们不出售个人信息,也不将其提供给数据经纪商。我们仅在下列范围共享:

  • 商户与交易参与方:当您发起聊天时,我们仅向相关商户显示沟通所需的昵称、头像、您按资料功能选择展示的媒体,以及您发送的消息和媒体;普通客户资料或聊天不会自动向商户显示电话或收货地址。当您提交询价、订单且报价或履约确有需要时,我们才向对应商户提供必要的联系人姓名、电话、收货地址、采购需求、商品和订单内容。商户对其独立留存和使用的信息承担相应责任。
  • 其他平台用户:您主动发布的采购需求、评论、点赞及公开资料按页面提示展示。请不要在公开内容中写入不希望公开的联系方式或个人信息。
  • 服务提供商:云托管、数据库、对象存储、内容分发、安全日志和短信验证供应商仅按我们的指示及提供服务所需处理数据,并受合同、保密和安全义务约束。
  • 专业顾问与监管机构:在必要范围向审计、法律、安全顾问,法院、执法、监管或政府机构披露,以履行法律义务、保护权利或应对紧急风险。
  • 企业交易:如发生合并、重组、融资或业务承继,可在保密与法律要求下向相关方提供必要信息;控制者变化时,我们会依法通知并继续保护您的权利。

除依法独立履职的有权公共机关外,我们通过合同、平台规则或其他适当安排,要求从平台获得共享个人信息的接收方根据其角色提供与本政策及适用的数据保护要求相同或同等的保护,包括目的限制、安全、保密、保存与删除及协助响应个人权利。

对于涉及另一人的收货或联系人信息,您应确保有权为交易目的提供,并向其说明必要的处理。

7. 主要服务提供商

Amazon Web Services(AWS)

地点:意大利米兰区域(eu-south-1)及为内容分发所需的网络节点。

服务与数据:应用托管、数据库、对象存储、CDN、网络安全和运行日志;相应处理可能涉及账户、资料、交易、内容、媒体和技术日志。

角色:代表我们提供基础设施的服务提供商/处理者。

供应商、区域或处理安排可能随服务可靠性和合规需要调整。若变更显著影响您的权利,我们会更新本政策并按法律要求告知或取得同意。

8. 中国与欧洲之间的跨境传输

B2B Direct 是全球平台。由于运营方位于瑞士、主要云基础设施位于意大利米兰,且内容传输可能经过为提高访问速度所需的网络节点,您的信息可能从您所在国家或地区传输至欧洲经济区、瑞士或相关网络节点,或由获授权人员在提供服务确有必要时远程访问。例如,中国用户的账户、交易或媒体可能存储在意大利。

我们会依实际适用法律采用相应机制,例如数据处理协议、访问与最小化控制、欧盟标准合同条款或其他认可机制、传输影响评估,以及中国法律要求的安全评估、标准合同、个人信息保护认证或其他合法路径。我们不会声称在尚不适用或尚未完成时已取得某项认证。依法需要单独同意时,我们会在跨境处理前另行向您告知接收方、目的、方式、类别和权利行使方式并取得单独同意。

不同国家的数据保护水平可能不同,但我们要求接收方按照适用法律、合同和本政策采取保护。您可联系我们了解与您相关的适用传输保障摘要。

9. 保存期限与账户注销

账户存续期间,我们在提供功能、安全运营和履行义务所需范围保存个人信息。具体期限依据数据类型、交易周期、风险、争议和法律要求确定:

  • 账户凭证、资料、地址、收藏、购物车、互动和通知通常保存至您删除相应内容或注销账户;短期安全日志仅在排障、防欺诈和安全审计所需期间保存。
  • 应用内注销生效后,账户凭证、个人资料和个人媒体、地址、收藏、购物车、互动、通知以及可识别登录日志会立即删除或匿名化。
  • 订单、报价、配送、相关聊天及附件等交易记录会保存至交易完成,并自交易完成之日起至少保留三年。注销后,这些记录及其中的收货信息、相关聊天和附件在买方与商户端均不可见,仅平台运营人员可在履约、审计、争议处理、防欺诈或履行法律义务确有必要时依规调取。
  • 最低期限届满且无法律要求、欺诈调查或未决争议需要继续保存时,系统将自动彻底删除或销毁相关记录。如确需更长时间,我们仅在相应目的所需范围延长,理由消失后即删除或销毁。
  • 设备本地偏好可通过应用设置、系统设置或删除应用清除;删除本地数据不会自动删除服务器账户。

您可在应用的账户设置中发起注销。为防止冒名操作,我们可能验证当前会话或身份。注销不可恢复,且不会取消已经与商户成立的合同;请先保存必要记录并处理未完成交易。

10. 安全措施与事件处理

我们根据数据和风险采取合理的管理与技术措施,包括传输保护、访问权限和职责分离、身份认证、日志与异常监测、备份、供应商管理及人员保密要求。只有因工作需要获得授权的人员可以访问个人信息。

互联网服务不存在绝对安全。请使用独立且强度足够的密码,不要向他人提供验证码,并核验商户和付款指示。如发生可能对您权益造成风险的个人信息事件,我们会调查、控制影响并按照适用法律向监管机构和受影响个人通知,说明事件性质、可能影响、已采取措施及您可采取的保护步骤。

11. 您的个人信息权利

根据适用法律及其例外,您可能有权:

  • 了解、查阅或取得我们持有的个人信息副本;
  • 更正或补充不准确、不完整的信息;
  • 删除信息、注销账户或限制/反对特定处理;
  • 在法律规定范围内取得结构化、常用、机器可读的数据并要求转移;
  • 撤回同意、关闭设备权限或选择退出非必要处理;
  • 要求说明处理规则、跨境接收方和重要自动化决定;
  • 向有管辖权的数据保护或网信监管机构投诉。

您可以在应用内编辑资料和地址、管理内容与权限,并在账户设置中申请注销;也可通过 support@b2bdirect.online 提交请求。请说明账户、请求范围和所在地区。为保护账户,我们会进行与请求风险相称的身份核验,不要求不必要的信息。

我们会在适用法律期限内答复:中国相关请求通常在 15 个工作日内处理或说明合理延期;GDPR 适用时通常在一个月内答复,复杂或多项请求可依法延长并告知理由。瑞士及其他地区按当地法定期限处理。对明显无根据、重复或过度的请求,我们仅在法律允许时拒绝或收取合理费用,并说明救济方式。

撤回设备权限可在 iOS 设置完成;撤回同意不影响撤回前处理的合法性。因合同履行、法定义务或法律主张必须保留的信息,可能无法立即删除,但会限制用途与访问。

12. 自动化处理、分析与广告

平台可使用搜索条件、类别及您主动进行的商品互动来提供站内搜索和相关内容,但当前不会仅依自动化处理作出对您产生法律效果或类似重大影响的决定。我们目前未集成第三方广告、行为分析或崩溃分析 SDK,不进行跨应用或跨网站跟踪,也不基于个人信息向您投放第三方行为广告。

我们可能使用汇总或去标识的运行统计了解功能稳定性和使用情况。我们会采取措施避免合理地重新识别;如数据仍可识别个人,则继续按本政策处理。

13. 未成年人信息

服务面向企业和专业采购,不以儿童为目标。您应达到所在地法律要求的独立行为能力;未达到时,只能在父母或法定监护人同意和监督且法律允许的情况下使用。我们不会明知而为儿童进行行为广告画像。

如监护人认为儿童在未经有效授权情况下提供了信息,请联系我们。我们会核验并依法删除或采取其他适当措施。

14. 本政策的更新

我们可能因法律、功能、数据实践或服务提供商变化更新本政策,并在页面顶部标注版本、发布日期和生效日期。对处理目的、数据类别、共享或您的权利有重大影响的变更,我们会通过应用内提示或其他合理方式提前告知;依法需要同意时,会在新处理开始前取得同意。

您可以打印或保存本版本,也可联系我们查询适用于特定期间的历史版本。

15. 联系我们与投诉

如需行使权利、询问本政策、举报安全事件或提出投诉,请联系:

Wynie Holdings — Privacy
Rue Ami-Lullin 12, 1207 Geneva, Switzerland
邮箱:support@b2bdirect.online

我们会确认并调查投诉。若您对处理结果不满意,可向所在地有管辖权的监管机构投诉;例如瑞士联邦数据保护和信息专员、适用的欧洲数据保护机构,或中国有管辖权的网信和个人信息保护主管部门。向我们投诉不影响您直接寻求监管或司法救济的权利。

本政策的中英文版本旨在表达相同含义。如翻译存在歧义,将在不限制强制性权利的前提下,根据适用法律和对用户清晰合理的方式解释。

B2B Direct · Privacy & Data Protection

Privacy Policy

This Policy explains how Wynie Holdings collects, uses, shares, transfers, retains and protects personal data when providing the B2B Direct business sourcing and matching service, and how you can exercise your rights.

  • Version: 1.0
  • Published: July 29, 2026
  • Effective: July 29, 2026
  • Last updated: July 29, 2026

At a glance: We process data mainly for accounts, business sourcing, enquiries and orders, chat, and secure operation. We do not sell personal data or track behaviour across apps or websites for advertising. We currently do not integrate third-party advertising, behavioural analytics or crash analytics SDKs. You can manage profile information and permissions and request account deletion in the app.

1. Scope and data controller

This Policy applies to the B2B Direct mobile app and the global B2B product discovery, sourcing request, enquiry, order and communication services provided through it. Where a merchant independently decides how to process information received in a transaction, it may act as an independent controller and its practices are governed by its own notice and applicable law.

The data controller or personal information handler is:

Wynie Holdings
Rue Ami-Lullin 12
1207 Geneva, Switzerland
Privacy email: support@b2bdirect.online

We process data under laws applicable to where business takes place and where users are located. These may include China's Personal Information Protection Law, the EU General Data Protection Regulation (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”). The precise rights and legal bases depend on the law that actually applies.

2. Data we collect and process

“Required” means the relevant core feature cannot operate without the data. “Optional” means you can withhold it, although a related profile, media or communication feature may not work. Collection screens also identify fields that are mandatory in context.

Category and examplesPurposeWhether required and effect of refusal
Account and authentication
Phone number, password authentication data, SMS verification code, user ID and session token
Create an account, sign in, maintain a session, verify identity, and recover or protect an account Required for core service Without phone and authentication information, you cannot register or sign in. Codes are used only for verification and security.
Profile
Nickname, gender and avatar
Display identity, complete the profile and support merchant communication Partly optional A nickname or system identifier distinguishes the account. Gender and a custom avatar may be omitted without affecting basic browsing.
Recipient and contact
Recipient name, phone, country/region, full address and address label
Prepare quotations, orders, delivery and transaction communications Required for a transaction Not needed merely to browse. Without it, you cannot complete an enquiry or order that requires delivery.
Browsing and sourcing preferences
Search terms, browsing and product interactions, favourites and cart contents
Return search results, save products you select, maintain a cart and improve in-service finding and functionality Mixed Search and browsing requests are needed for those functions. Favourites and cart are voluntary and can be cleared.
Enquiries, orders and delivery
Products, quantities, amounts, currency, quotations, order status, delivery details and transaction-related support requests
Send enquiries to merchants, form and manage orders, coordinate fulfilment, after-sales issues, audits and disputes Required for a transaction Without it, you cannot submit or manage that enquiry or order. The Platform currently does not collect online payment-card or in-app-purchase data.
Sourcing requests
Title, description, category, target country, budget, quantity, delivery and certification requirements, and image/video/file attachments
Publish a request and help suitable merchants discover, evaluate and respond to it Required to post / attachments optional Not posting does not affect other features. Enough request content is required to post; attachments are generally optional.
Chat and community content
Chat text, images, video, files, read and block status; public comments, likes and sourcing-plaza content
Enable buyer–seller communications and file transfer, display interactions, handle reports and maintain community safety Feature-triggered You choose to send or interact. Refusal does not affect browsing, but the related communication or posting feature will not work. Public-area content is visible to the relevant Platform users.
Display media
Avatar, profile images and video you choose to upload
Complete your profile and display it to merchants or Platform users as indicated by the feature Optional Uploading is not required for sign-in or basic sourcing.
Security and technical logs
IP address, User-Agent/device and app environment, login time and result, failure reason and request trace ID
Prevent unauthorised access, troubleshoot, audit, prevent fraud and secure networks and the Service Required for operation and security Generated when you connect. If necessary logging is blocked, we may be unable to provide a secure online service.
Local settings
Language, theme, session state, cart and app preferences
Keep interface and feature choices on your device Functional or optional Some remain only on the device. Clearing app data may require you to select them again or sign in again.

Do not place unrelated identity documents, financial-account data, health data, precise location or other sensitive personal data in free text, attachments or chat. If business and law genuinely require such data, first verify the recipient and transmission method.

3. Sources of data

  • Directly from you: registration, profile, addresses, enquiries, sourcing requests, content, attachments and support communications.
  • From your use: search, browsing, favourites, cart, message state, order flow and security logs.
  • From merchants or transaction participants: quotations responding to your enquiry, order confirmations, shipping and after-sales status, and chats or dispute material in which you jointly participate.
  • From the device: camera, photos, microphone or files you select only after you trigger a feature and grant permission. We do not continuously read this content in the background without reason.

4. Purposes and legal bases

We use data to provide accounts and business matching; connect you with merchants; process enquiries, orders, delivery and support; provide chat and community features; prevent fraud, moderate and secure the Service; comply with law, respond to lawful requests and establish, exercise or defend legal rights; and analyse operation and improve features using aggregated or de-identified information.

Depending on applicable law, our legal bases may include:

  • Contract and pre-contract steps: registration, sign-in, search, enquiries, orders, chat and other services you request;
  • Consent: device permissions, optional profile data and processing or transfers for which consent is legally required. You may withdraw consent, without affecting processing already lawfully carried out;
  • Legal obligations: regulatory, tax, audit, safety and complaint requirements and legally required retention or disclosure;
  • Legitimate interests: where applicable law permits and after balancing interests, account and network security, fraud prevention, troubleshooting, Service maintenance and legal claims; and
  • Other grounds under Chinese law: necessity to enter or perform a contract to which you are party, perform legal duties, respond to public-health needs or urgently protect life or property, and other grounds provided by law.

We do not use personal data for a new purpose that is unreasonably unrelated to these purposes. If notice or consent is legally required for a new purpose, we will complete it before processing.

5. Device permissions

PermissionWhen usedYour control
CameraTake an avatar, product/sourcing material or chat mediaRequested only when you initiate capture. Withdraw in system settings and continue using features that do not need the camera.
Photo read and saveSelect an image/video to upload, or save media you expressly select to PhotosRefuse or use limited photo selection where available. Refusal prevents gallery upload or saving but not text features.
MicrophoneCapture sound when you use the video-recording featureRequested only for that action. Refusal prevents sound from being captured in the recorded video.
File selectionSelect and upload a file for sourcing, chat or a disputeWe process only files you expressly select in the system picker; this does not give us permission to browse all files.

You can withdraw permissions in iOS Settings. Withdrawal does not affect processing already completed under valid permission, but stops new permission access. The app currently does not require precise location or contacts permission.

6. Sharing, public disclosure and recipients

We do not sell personal data or provide it to data brokers. We share only as follows:

  • Merchants and transaction participants. When you start a chat, we show the relevant merchant only the nickname, avatar, media you choose to display through profile features, and messages and media you send as needed for communication; an ordinary customer profile or chat does not automatically reveal your phone number or delivery address. We provide the necessary contact name, phone number, delivery address, sourcing request, product and order content to the corresponding merchant only when you submit an enquiry or order and that information is needed for quotation or fulfilment. A merchant is responsible for information it independently retains and uses.
  • Other Platform users. Sourcing requests, comments, likes and public profile elements you choose to post are displayed as indicated on the screen. Do not include contact or personal data you do not want made public.
  • Service providers. Providers of cloud hosting, databases, object storage, content delivery, security logging and SMS verification process data only under our instructions and as needed to provide the service, subject to contractual, confidentiality and security duties.
  • Professional advisers and authorities. We may provide necessary data to audit, legal or security advisers, courts, law enforcement, regulators or public authorities to meet legal duties, protect rights or address an emergency.
  • Corporate transactions. In a merger, reorganisation, financing or business succession, necessary data may be provided under confidentiality and law. If the controller changes, we will give legally required notice and continue to protect your rights.

Except for competent public authorities acting independently under law, we use contracts, Platform rules or other appropriate arrangements to require recipients of personal data shared from the Platform to provide the same or equivalent protection required by this Policy and applicable data-protection requirements, appropriate to their role, including purpose limitation, security, confidentiality, retention and deletion, and assistance with individual rights.

If you provide another person's recipient or contact details, ensure you are entitled to provide them for the transaction and explain the necessary processing to that person.

7. Key service providers

Amazon Web Services (AWS)

Location: Milan, Italy region (eu-south-1), together with network points needed for content delivery.

Services and data: application hosting, databases, object storage, CDN, network security and operational logs. The related processing may cover account, profile, transaction, content, media and technical-log data.

Role: infrastructure service provider/processor acting for us.

Providers, regions and arrangements may change for reliability and compliance. If a change materially affects your rights, we will update this Policy and provide notice or obtain consent where law requires.

8. Transfers between China and Europe

B2B Direct is a global Platform. Because the operator is in Switzerland, primary cloud infrastructure is in Milan, Italy, and content delivery may use network points needed to improve access speed, your data may be transferred from your country or region to the European Economic Area, Switzerland or a relevant network point, or remotely accessed by authorised personnel where genuinely necessary to provide the Service. For example, a Chinese user's account, transaction or media may be stored in Italy.

Depending on the law that actually applies, we will adopt the required safeguards, which may include data-processing agreements, access and minimisation controls, EU Standard Contractual Clauses or another recognised mechanism, transfer impact assessments, and a Chinese security assessment, standard contract, personal-information protection certification or other lawful route where required. We do not claim that a certification has been obtained where it is not yet applicable or complete. Where separate consent is required, before transfer we will separately explain the recipient, purpose, means, categories and rights method and obtain that consent.

Protection levels differ by country, but we require recipients to protect data under applicable law, contract and this Policy. Contact us for a summary of safeguards relevant to you.

9. Retention and account deletion

While an account exists, we retain data only as needed to provide features, operate securely and meet obligations. The period depends on data type, transaction cycle, risk, disputes and legal requirements:

  • Account credentials, profile, addresses, favourites, cart, interactions and notifications are generally retained until you delete the item or account. Short-term security logs are kept only as needed for troubleshooting, fraud prevention and security audit.
  • When in-app account deletion takes effect, credentials, personal profile and media, addresses, favourites, cart, interactions, notifications and identifiable login logs are immediately deleted or anonymised.
  • Transaction records covering orders, quotations, delivery, related chats and attachments are kept until the transaction is completed and for at least three years from completion. After account deletion, these records—including delivery details, related chats and attachments—are not visible on either the buyer or merchant side. Only authorised Platform operations personnel may retrieve them under controlled procedures where genuinely necessary for fulfilment, audit, dispute resolution, fraud prevention or a legal duty.
  • At the end of the minimum period, the system automatically and permanently deletes or destroys the records unless law, a fraud investigation or an unresolved dispute requires longer retention. Any extension is limited to what is needed for that purpose, followed by deletion or destruction when the reason ends.
  • Local device preferences can be cleared through app settings, system settings or by deleting the app. Clearing local data does not itself delete the server account.

You can initiate deletion in account settings. We may verify the current session or identity to prevent impersonation. Deletion cannot be reversed and does not cancel a contract already made with a merchant, so save necessary records and address incomplete transactions first.

10. Security and incident response

We apply reasonable organisational and technical measures appropriate to the data and risk, including protections in transit, access permissions and separation of duties, authentication, logging and anomaly monitoring, backups, provider management and staff confidentiality. Only personnel authorised for a work-related need may access personal data.

No internet service is absolutely secure. Use a unique, sufficiently strong password, never give another person a verification code, and verify merchants and payment instructions. If a personal-data incident may risk your rights, we will investigate, contain impact, and notify regulators and affected people as applicable law requires, describing the nature, possible effect, response and protective steps available to you.

11. Your data rights

Subject to applicable law and its exceptions, you may have the right to:

  • be informed, access data and receive a copy;
  • correct or complete inaccurate or incomplete data;
  • erase data, delete an account, or restrict or object to particular processing;
  • receive data in a structured, commonly used and machine-readable form and request transfer where law provides;
  • withdraw consent, disable device permissions or opt out of non-essential processing;
  • request an explanation of processing rules, cross-border recipients and significant automated decisions; and
  • complain to a competent data-protection or cyberspace authority.

You can edit profile and addresses, manage content and permissions, and request deletion in account settings. You may also email support@b2bdirect.online. State the account, scope of request and location. To protect the account, we perform verification proportionate to the request's risk and do not require unnecessary data.

We respond within the time under applicable law. China-related requests are normally addressed, or a reasonable extension explained, within 15 working days. Where GDPR applies, we normally respond within one month and may lawfully extend for complex or multiple requests with reasons. Swiss and other requests follow local statutory periods. We reject or charge a reasonable fee for manifestly unfounded, repetitive or excessive requests only where law permits and will explain available remedies.

Withdraw an iOS permission through Settings. Withdrawal does not affect processing lawfully carried out beforehand. Data required for contract performance, legal duties or legal claims may not be immediately erased, but its purpose and access will be restricted.

12. Automated processing, analytics and advertising

The Platform may use search criteria, categories and product interactions you initiate to provide in-service search and relevant content. It currently does not make decisions producing legal or similarly significant effects solely by automated processing. We currently do not integrate third-party advertising, behavioural analytics or crash analytics SDKs, do not track across apps or websites, and do not use personal data for third-party behavioural advertising.

We may use aggregated or de-identified operational statistics to understand stability and use. We take measures to prevent reasonable re-identification. If data remains identifiable, this Policy continues to apply.

13. Children's data

The Service is for businesses and professional sourcing and is not directed to children. You must have the legal capacity required in your location. If you do not, use is permitted only with parental or legal-guardian consent and supervision and where law allows. We do not knowingly create behavioural-advertising profiles of children.

If a guardian believes a child provided data without valid authorisation, contact us. We will verify the request and erase the data or take other appropriate action under law.

14. Updates to this Policy

We may update this Policy for changes in law, features, data practices or providers. The version, publication and effective dates appear at the top. For a change materially affecting purposes, data categories, sharing or your rights, we will give advance in-app or other reasonable notice. Where consent is required, we will obtain it before the new processing begins.

You may print or save this version and contact us for a historical version applicable to a particular period.

15. Contact and complaints

To exercise a right, ask about this Policy, report a security event or make a complaint, contact:

Wynie Holdings — Privacy
Rue Ami-Lullin 12, 1207 Geneva, Switzerland
Email: support@b2bdirect.online

We will acknowledge and investigate a complaint. If you are dissatisfied, you may complain to a competent authority where you live, such as the Swiss Federal Data Protection and Information Commissioner, the applicable European data protection authority, or a competent Chinese cyberspace and personal-information protection authority. Contacting us does not limit your right to seek regulatory or judicial relief directly.

The Chinese and English versions are intended to have the same meaning. An ambiguity will be interpreted under applicable law and in a clear and reasonable manner for users, without limiting mandatory rights.