01Introduction
Tolmere ("we," "us," or "our") is a product developed and operated by Changsha Gaolunbu Composite Materials Co., Ltd. (长沙高伦布复合材料有限公司) under the parent company Global TradeHub Limited, registered in Hong Kong. This Privacy Policy explains how we collect, use, store, protect, and share your personal information when you use the Tolmere platform, website, and related services (collectively, the "Services"). This policy is drafted in compliance with the Personal Information Protection Law of the People's Republic of China (PIPL), the Cybersecurity Law, the Data Security Law, and applicable international data protection standards including GDPR where relevant.
02Information We Collect
Account information
Company name, business registration number, contact person name, email address, phone number, and WeChat ID.
Usage data
IP address, browser type, device information, access logs, pages visited, and interaction data with our AI automation tools.
Business data
Inquiry content, quotation records, buyer lead information, and customs data processed through our platform. This may include personal data of your overseas buyers (procurement contacts) that you choose to import or manage via Tolmere.
Payment information
Billing details and transaction records. We do not store full credit card numbers; payment processing is handled by licensed third-party payment providers.
Communication data
Emails, WhatsApp messages, WeChat messages, and other communications processed through our AI reply and follow-up systems.
03How We Use Your Information
We use your personal information solely for the following purposes:
- To provide, operate, and maintain the Tolmere platform and AI automation services;
- To process your inquiries, generate quotations, and manage buyer leads;
- To communicate with you regarding your account, service updates, and support requests;
- To improve our AI models and service quality through anonymized analytics;
- To comply with legal obligations, including tax, customs, and export compliance requirements;
- To prevent fraud, abuse, and security incidents.
We do not sell your personal information to third parties.
04Data Storage and Security
Your data is stored on servers located within the People's Republic of China (mainland China) and/or Hong Kong SAR, depending on the service module. All data transfers between mainland China and Hong Kong are conducted under lawful grounds as prescribed by PIPL and applicable cross-border data transfer regulations. We implement industry-standard encryption (TLS 1.3 for transmission, AES-256 for storage), access controls, and regular security audits.
Data retention. We retain personal information for as long as your account is active or as required by law (typically 3–5 years for business transaction records under Chinese commercial and tax regulations). After account closure, data is anonymized or securely deleted within 30 days unless legal retention obligations apply.
05Cross-Border Data Transfers
As a cross-border trade automation platform, Tolmere may process overseas buyer contact information (names, emails, company addresses) that you import. When personal information of overseas individuals is processed within our China-based systems, we ensure: (1) explicit consent or contractual necessity as the legal basis; (2) standard contractual clauses (SCCs) or other PIPL-compliant transfer mechanisms; (3) data minimization — only necessary contact fields are retained. For EU-based buyer data, GDPR Article 49 derogations (explicit consent / contract performance) may apply where standard adequacy decisions are not available.
06Your Rights (PIPL & GDPR)
You have the right to:
- know and decide how your personal information is processed;
- access and obtain a copy of your personal information;
- correct or supplement inaccurate personal information;
- request deletion under lawful conditions;
- withdraw consent at any time (without affecting prior lawful processing);
- request explanation of our processing rules.
To exercise these rights, contact our Data Protection Officer at [email protected].
07Cookies and Tracking Technologies
We use essential cookies to maintain session state and login status. Analytics cookies (if any) are used only with your consent and can be disabled. Third-party cookies from WeChat, WhatsApp Business API, and Alibaba International Station integrations are governed by those platforms' respective cookie policies.
08Third-Party Services and Integrations
Tolmere integrates with: WeChat Official Account API, WhatsApp Business API, Alibaba International Station, Made-in-China, and customs data providers. When you connect these channels, their privacy policies also apply. We only share the minimum data necessary to enable the integration functionality. We are not responsible for the privacy practices of third-party platforms.
09Children's Privacy
Tolmere is a B2B trade automation platform intended for business users only. We do not knowingly collect personal information from individuals under 18 years of age. If we discover such data, we will delete it immediately.
10Company & Personal-Information Handling
This section governs how Tolmere handles both (a) corporate/company information and (b) personal information of individuals (employees, representatives of client companies, and overseas buyer contacts) within our platform.
Company information we process
Business registration details, tax ID, import/export license numbers, bank account information for proforma invoice generation, company addresses, and trade history. This information is used strictly for: (1) generating compliant trade documents; (2) customs data matching and buyer lead verification; (3) billing and subscription management.
Personal information of representatives
When you register a company account, we collect the name, phone number, and email of the authorized representative. This is necessary for: (1) account verification and security; (2) legal notification requirements; (3) emergency contact for account issues. We treat representative personal data with the same protection level as direct consumer data.
Overseas buyer contact data
Our Buyer Finder feature extracts publicly available import records. When buyer contact details (names, emails, job titles) are surfaced, they are: (1) limited to business contact information only; (2) not used for mass unsolicited marketing by Tolmere itself; (3) provided to you as the data controller for your own lawful outreach; (4) subject to opt-out mechanisms upon buyer request.
Data minimization and purpose limitation
We collect only the data necessary for the specific trade automation function you use. We do not repurpose business inquiry data for unrelated marketing. AI-generated replies and quotations are logged for quality assurance but are not used to train general-purpose language models without anonymization.
Security measures
Role-based access control; TLS in transit and AES-256 at rest; audit logging of all data access; a 72-hour breach-notification process to regulators and affected users where required by law; and annual PIPL compliance training for all personnel with data access.
11Sub-processors and Infrastructure
- Cloud infrastructure: Cloudflare (global CDN and edge security), Tencent Cloud (China mainland).
- AI services: Large language model APIs (anonymized prompts, no persistent storage of raw prompts).
- Email / SMS: Third-party transactional email providers.
A full list of sub-processors is available upon request.
12Contact / Data Protection Officer
Email: [email protected]
Phone / WeChat: +86 177 7302 2019
Address: No. 662 Qingshan Road, Dongfanghong Subdistrict, Xiangjiang New Area, Changsha, Hunan, China (Xincheng Tech Park, Phase II)
A Data Protection Officer is appointed under PIPL requirements. You also have the right to file a complaint with the Cyberspace Administration of China (CAC) or your local cyberspace administration office.