CCT CRM Privacy Policy - Local Data Security & Compliance
Last updated: June 2026
English Version
CCT CRM Privacy Policy
Last updated: June 2026
Welcome to CCT CRM (hereinafter referred to as "the System"). We fully understand the importance of personal information and business data to you, and are committed to protecting your privacy. This Privacy Policy is intended to explain how we collect, use, store and protect your information.
1. Scope of Information Collection
1.1 Account Information
When you register or use the System, we may collect the following account-related information:
- Login account (username)
- Login password (stored in encrypted form)
- Employee name (Chinese and English)
- Job title
- Contact information (mobile number, personal phone, email, QQ, MSN, fax)
- Company and department information
- Permission roles and data access permission levels
1.2 Business Data
As a management platform for foreign trade enterprises, the System processes the following business data during your use:
- Customer information: customer name, contact details, address, bank account information, customer classification, etc.
- Supplier information: supplier name, contact details, qualification information, etc.
- Product information: product name, specifications, price, BOM list, etc.
- Transaction data: inquiry sheets, quotation sheets, sales contracts, purchase contracts, orders, shipping orders, etc.
- Financial data: accounts receivable, accounts payable, invoices, settlement statements, payment records, etc.
- Inventory data: goods receipt, goods issue, inventory counting, warehouse location information, etc.
- Production data: production orders, work orders, quality inspection records, equipment information, etc.
- Email communications: email content and email logs sent and received through the System
- Schedules and tasks: schedule planning, work reports, task assignment, etc.
Important Statement: All the above business data is stored on your own or rented servers, and is kept and managed by you. We will not collect, access, transmit or use your business data. You have full control and ownership of your business data.
1.3 Login and Usage Logs
- Login time, login IP address, login client information
- Number of failed login attempts
- System operation logs (for audit and security purposes)
1.4 AI Assistant Related Data
The AI assistant function built into the System runs in your local environment. The following data is all stored on your server and will not be collected by us:
- Your conversation records with the AI assistant
- Operation logs of actions performed by the AI assistant
- Business knowledge data stored in the knowledge base
1.5 Subscription and Payment Information
If you use paid subscription services:
- Subscription plan selection
- Payment transaction records (processed through Stripe; we do not directly collect or store your bank card information)
2. Purposes of Information Use
We collect and use your information only for the following purposes:
- Provide core services: provide you with all functions of the CRM system, including customer management, sales management, purchasing management, financial management, inventory management, production management, etc.
- Identity authentication and security: verify user identity, prevent unauthorized access, and ensure system security.
- AI intelligent assistance: provide AI business assistant functions to help you query data, analyze business, generate emails, etc.
- Subscription management: handle subscription renewals and payment management.
- System improvement: analyze system usage and optimize functional experience.
- Compliance and audit: meet legal and regulatory requirements and retain necessary business operation logs.
3. Information Storage and Protection
3.1 Storage Location
All data is stored on your own or rented servers, in a MySQL database with Redis for caching. You have full control over the data storage location.
3.2 Security Measures
- User passwords are stored using encryption algorithms, not in plain text
- JWT (JSON Web Token) is used for identity authentication to ensure session security
- Role-Based Access Control (RBAC) is supported to refine data access permissions
- Operation logs are recorded to support audit traceability
- Spring Security framework is adopted for security protection
3.3 Data Retention
- Account information: retained during the validity period of the account, and retained or deleted according to business needs after account cancellation
- Business data: retained according to your business needs and legal and regulatory requirements
- Login logs: retained for a reasonable period for security audit purposes
4. Third-Party Services
The System may integrate the following third-party services:
| Third-Party Service | Purpose | Data Involved |
|---|---|---|
| Stripe | Subscription payment processing | Payment amount, transaction records (not including complete bank card information) |
| Email service (SMTP) | Sending business emails | Email content, recipient information |
| Track17 | Logistics tracking | Tracking number, logistics status |
Each of the above third-party services has its own privacy policy. We recommend that you also understand the privacy protection measures of the relevant third parties.
5. Cookies and Local Storage
The System front-end uses the following browser storage technologies:
- localStorage: stores non-sensitive information such as user onboarding status and interface preference settings
- JWT Token: stored in the browser to maintain login session status
We do not use cookies for user behavior tracking or advertising.
6. Data Control Rights
As the deployer and user of the System, you have full control over your data:
- You can view and export your business data at any time
- You can modify or delete your account information
- You can configure data access permissions to control the visibility range of data for different users
- You can determine the data retention period
7. Protection of Minors
This System is intended for enterprise users and does not provide services to minors. If you are a minor, please use this System under the guidance and consent of your legal guardian.
8. Privacy Policy Updates
We may update this Privacy Policy from time to time. The updated policy will be published in the System, and material changes will be notified to you through system notifications or email.
9. Contact Us
If you have any questions, comments or suggestions about this Privacy Policy, please contact us through:
- Email: support@cctcrm.com.cn
- In-system feedback: submit through the "Help and Feedback" function
This Privacy Policy is formulated and maintained by the CCT CRM team.