CCT CRM Privacy Policy - Local Data Security & Compliance

Last updated: June 2026

English Version

CCT CRM Privacy Policy

Last updated: June 2026

Welcome to CCT CRM (hereinafter referred to as "the System"). We fully understand the importance of personal information and business data to you, and are committed to protecting your privacy. This Privacy Policy is intended to explain how we collect, use, store and protect your information.


1. Scope of Information Collection

1.1 Account Information

When you register or use the System, we may collect the following account-related information:

  • Login account (username)
  • Login password (stored in encrypted form)
  • Employee name (Chinese and English)
  • Job title
  • Contact information (mobile number, personal phone, email, QQ, MSN, fax)
  • Company and department information
  • Permission roles and data access permission levels

1.2 Business Data

As a management platform for foreign trade enterprises, the System processes the following business data during your use:

  • Customer information: customer name, contact details, address, bank account information, customer classification, etc.
  • Supplier information: supplier name, contact details, qualification information, etc.
  • Product information: product name, specifications, price, BOM list, etc.
  • Transaction data: inquiry sheets, quotation sheets, sales contracts, purchase contracts, orders, shipping orders, etc.
  • Financial data: accounts receivable, accounts payable, invoices, settlement statements, payment records, etc.
  • Inventory data: goods receipt, goods issue, inventory counting, warehouse location information, etc.
  • Production data: production orders, work orders, quality inspection records, equipment information, etc.
  • Email communications: email content and email logs sent and received through the System
  • Schedules and tasks: schedule planning, work reports, task assignment, etc.

Important Statement: All the above business data is stored on your own or rented servers, and is kept and managed by you. We will not collect, access, transmit or use your business data. You have full control and ownership of your business data.

1.3 Login and Usage Logs

  • Login time, login IP address, login client information
  • Number of failed login attempts
  • System operation logs (for audit and security purposes)

1.4 AI Assistant Related Data

The AI assistant function built into the System runs in your local environment. The following data is all stored on your server and will not be collected by us:

  • Your conversation records with the AI assistant
  • Operation logs of actions performed by the AI assistant
  • Business knowledge data stored in the knowledge base

1.5 Subscription and Payment Information

If you use paid subscription services:

  • Subscription plan selection
  • Payment transaction records (processed through Stripe; we do not directly collect or store your bank card information)

2. Purposes of Information Use

We collect and use your information only for the following purposes:

  1. Provide core services: provide you with all functions of the CRM system, including customer management, sales management, purchasing management, financial management, inventory management, production management, etc.
  2. Identity authentication and security: verify user identity, prevent unauthorized access, and ensure system security.
  3. AI intelligent assistance: provide AI business assistant functions to help you query data, analyze business, generate emails, etc.
  4. Subscription management: handle subscription renewals and payment management.
  5. System improvement: analyze system usage and optimize functional experience.
  6. Compliance and audit: meet legal and regulatory requirements and retain necessary business operation logs.

3. Information Storage and Protection

3.1 Storage Location

All data is stored on your own or rented servers, in a MySQL database with Redis for caching. You have full control over the data storage location.

3.2 Security Measures

  • User passwords are stored using encryption algorithms, not in plain text
  • JWT (JSON Web Token) is used for identity authentication to ensure session security
  • Role-Based Access Control (RBAC) is supported to refine data access permissions
  • Operation logs are recorded to support audit traceability
  • Spring Security framework is adopted for security protection

3.3 Data Retention

  • Account information: retained during the validity period of the account, and retained or deleted according to business needs after account cancellation
  • Business data: retained according to your business needs and legal and regulatory requirements
  • Login logs: retained for a reasonable period for security audit purposes

4. Third-Party Services

The System may integrate the following third-party services:

Third-Party Service Purpose Data Involved
Stripe Subscription payment processing Payment amount, transaction records (not including complete bank card information)
Email service (SMTP) Sending business emails Email content, recipient information
Track17 Logistics tracking Tracking number, logistics status

Each of the above third-party services has its own privacy policy. We recommend that you also understand the privacy protection measures of the relevant third parties.


5. Cookies and Local Storage

The System front-end uses the following browser storage technologies:

  • localStorage: stores non-sensitive information such as user onboarding status and interface preference settings
  • JWT Token: stored in the browser to maintain login session status

We do not use cookies for user behavior tracking or advertising.


6. Data Control Rights

As the deployer and user of the System, you have full control over your data:

  • You can view and export your business data at any time
  • You can modify or delete your account information
  • You can configure data access permissions to control the visibility range of data for different users
  • You can determine the data retention period

7. Protection of Minors

This System is intended for enterprise users and does not provide services to minors. If you are a minor, please use this System under the guidance and consent of your legal guardian.


8. Privacy Policy Updates

We may update this Privacy Policy from time to time. The updated policy will be published in the System, and material changes will be notified to you through system notifications or email.


9. Contact Us

If you have any questions, comments or suggestions about this Privacy Policy, please contact us through:


This Privacy Policy is formulated and maintained by the CCT CRM team.