选品侠 · 隐私政策

我们如何收集、使用、存储、保护与共享您的数据

← 返回首页

最后更新日期:2026-08-09 | Last Updated: 2026-08-09

1. 我们收集哪些信息

本节详细说明选品侠 Product Hunter(以下简称"我们"或"本产品")收集的所有用户数据类型、收集方式与技术实现。

1.1 用户主动提供的信息

  • 邮箱地址:用于注册、登录、邮箱验证、订单通知与密码找回。存储于数据库 users.email 字段,建立唯一索引。
  • 手机号码:可选提供,用于注册、登录与短信验证码校验。仅支持中国大陆手机号,存储于数据库 users.phone 字段。
  • 密码:使用 bcrypt 算法加盐哈希存储(cost factor = 10),我们不存储明文密码。
  • 用户昵称:可选,用于界面展示。
  • 反馈内容与截图:用户主动提交的问题反馈与附件。

1.2 插件自动收集的信息

  • 设备指纹:采集 Canvas 绘制特征、WebGL 渲染信息、屏幕分辨率、时区、语言、操作系统平台、字体列表等特征,生成设备指纹哈希(格式如 fp_<32位hash>)。用途:设备授权识别、防多账号注册滥用、一机一号试用限制。这些特征不包含个人身份信息,用户可通过清除插件存储数据重置指纹。
  • 设备标识符:插件生成唯一的设备 ID(格式如 dev_<timestamp>_<random>),存储于浏览器本地(chrome.storage.local),用于许可证验证、防多设备滥用与使用统计关联。用户可通过清除插件数据移除设备 ID。
  • 浏览器与系统信息:User-Agent 字符串(可能包含操作系统与浏览器版本)、浏览器语言设置、插件版本号。用途:兼容性判断、使用统计、技术诊断。
  • IP 地址:用户访问我们的 API 时记录请求 IP,用于安全防护、限流、防滥用(如限制同 IP 24 小时内注册次数与试用激活次数)。IP 地址不会用于识别个人身份,日志保留 30 天后自动删除。
  • 注册来源信息:用户首次访问落地页时的 UTM 参数(source/medium/campaign)、referrer、landing page 路径。用途:市场推广效果分析。
  • 使用统计:功能使用频率、数据查看次数、导出次数、AI 调用次数。用途:产品优化与限额管理。

1.3 商品数据(用户主动采集)

  • 收藏商品:用户主动收藏的商品 ASIN/ID、URL、标题、价格、平台来源。
  • 监控商品:用户主动添加监控的商品及其历史价格、BSR 排名、评论数据。
  • 1688 采集数据:用户在浏览器中主动访问 1688 公开页面时,插件读取已渲染的公开数据(商品标题、价格、规格、供应商信息)。采集在用户浏览器内完成,不绕过任何反爬机制。
  • 供应商收藏:供应商 member_id、公司名称、店铺 URL、评分、自定义标签、询价记录。

1.4 交易数据

  • 订单记录:订单号、用户 ID、套餐等级、计费周期、金额、币种、支付方式、支付状态、创建时间、支付时间。
  • 许可证信息:许可证密钥(HMAC 签名)、套餐等级、计费周期、最大设备数、到期时间、状态。
  • 支付凭证:支付渠道返回的交易 ID(如 PayPal capture ID、支付宝交易号、微信支付交易号),用于对账与退款。我们不存储完整的银行卡号或支付账户信息。

1.5 AI 服务调用数据

插件的 AI 洞察功能(如 AI 选品分析、AI 评论总结、AI 单品洞察)在用户主动点击分析按钮时,会将脱敏后的商品公开数据发送至第三方 AI 服务进行分析:

  • 发送内容:商品标题、价格、评论摘要、BSR 排名、类目等公开数据。不发送 user_id、邮箱、设备 ID 等个人身份信息。
  • 触发方式:仅在用户主动点击 AI 分析按钮时调用,不自动发送。
  • AI 服务商:当前使用 DeepSeek(深度求索)作为 AI 服务提供商,其数据处理遵守其隐私政策。
  • 数据保留:AI 服务商的数据保留策略由其政策决定,我们无法控制。

1.6 跨用户匿名聚合数据

为提供更准确的市场趋势分析与 AI 洞察能力,用户使用商品分析功能时,被分析商品的公开市场数据会进行跨用户匿名聚合处理:

  • 聚合范围:商品 ASIN/ID、价格、BSR 排名、评论数、评分、类目、采集时间。不包含 user_id、邮箱、设备 ID 等任何个人身份信息。
  • 匿名性保证:聚合表 schema 中不含 user_id 字段,无法反向追溯到具体用户。
  • 用途:提供历史趋势曲线;为 AI 洞察注入专有趋势数据;按类目校准销量估算模型。

1.7 我们不会收集的信息

  • 用户在任何电商平台的店铺登录密码
  • 用户的支付密码或完整银行卡信息
  • 用户在任何平台的卖家后台敏感页面数据
  • 用户浏览器历史记录或非电商网站数据
  • 用户的精确地理位置(GPS 定位)
  • 用户通讯录或社交媒体账户信息

2. 信息用途

收集的信息用于以下目的:

  • 提供核心功能:商品数据分析、利润计算、竞品监控、AI 选品洞察、价格波动监控、供应商管理。
  • 账户管理:用户注册、登录、密码找回、邮箱/手机验证、会员套餐与订阅管理。
  • 数据同步:将用户收藏和监控数据同步到云端,支持跨设备访问。
  • 通知服务:发送监控告警、系统通知、订单确认、试用到期提醒。
  • 安全防护:设备指纹验证、防多账号滥用、IP 限流、异常行为检测。
  • 产品优化:根据使用统计改进产品功能、修复技术问题、提升用户体验。
  • 合规要求:保留交易记录用于财务合规与税务申报。

我们不将用户数据用于:个性化广告投放、出售给第三方、用于非本产品功能相关的商业用途。

3. 信息存储与保护

3.1 存储位置

  • 服务器位置:用户数据存储在中国大陆阿里云服务器(数据中心位于中国杭州)。
  • 数据库:使用 SQLite 数据库,存储于服务器本地,启用外键约束与访问控制。
  • 本地存储:部分非敏感数据(设备 ID、用户偏好设置、缓存数据)存储于浏览器 chrome.storage.local。
  • 备份:数据库定期备份,备份文件存储于服务器本地,不传输至境外。

3.2 安全措施

  • 传输加密:所有客户端与服务器之间的通信使用 HTTPS (TLS 1.2+) 加密。
  • 密码加密:用户密码使用 bcrypt 算法加盐哈希存储,不存储明文。
  • JWT 认证:使用 JSON Web Token 进行会话管理,密钥长度 ≥ 32 字符。
  • CORS 策略:严格限制跨域请求来源,仅允许已注册的浏览器扩展 ID 与官方域名访问 API。
  • 输入验证:所有 API 请求参数经过 Zod schema 验证,防止注入攻击。
  • 速率限制:API 实施速率限制,防止暴力破解与滥用。
  • 访问控制:服务器仅授权人员可访问,数据库不暴露公网端口。

3.3 数据安全事件响应

如发生数据安全事件,我们将在 72 小时内启动应急响应流程,评估影响范围,采取必要补救措施,并通过邮件通知受影响用户。

4. 信息共享与第三方服务

我们不会出售用户个人信息。以下是我们共享数据的第三方服务及其数据范围:

4.1 支付服务商

  • PayPal:用于国际支付。共享数据:订单金额、订单号、回调 URL。PayPal 隐私政策:https://www.paypal.com/webapps/mpp/ua/privacy-full
  • 支付宝 (Alipay):用于国内支付。共享数据:订单金额、订单号、商品标题、异步通知 URL。支付宝隐私政策:支付宝隐私权政策
  • 微信支付 (WeChat Pay):用于国内支付。共享数据:订单金额、订单号、商品描述、异步通知 URL。微信支付隐私政策:微信隐私保护指引

以上支付服务商均遵循 PCI-DSS 支付安全标准。我们不存储完整的银行卡号或支付账户信息,支付凭证由各支付渠道直接处理。

4.2 AI 服务提供商

  • DeepSeek(深度求索):用于 AI 选品分析、评论总结、单品洞察。共享数据:脱敏后的商品公开数据(标题、价格、评论摘要)。不共享用户个人身份信息。DeepSeek 隐私政策:DeepSeek Privacy Policy

4.3 邮件服务提供商

  • SMTP 邮件服务:用于发送验证码、订单通知、监控告警。共享数据:收件人邮箱、邮件主题、邮件正文。邮件内容不包含密码等敏感信息。

4.4 短信服务提供商

  • 短信验证码服务:用于手机号注册验证。共享数据:手机号码、验证码内容。仅在用户主动注册时发送,不用于营销。

4.5 其他共享场景

  • 法律要求:在法律法规要求、政府机构强制要求或保护我们合法权益时,我们可能披露必要信息。
  • 业务转让:如发生合并、收购或资产转让,用户数据可能作为资产转移,我们将确保接收方继续遵守本隐私政策。

5. 国际数据传输

用户数据主要存储在中国大陆服务器。以下场景涉及跨境数据传输:

  • AI 服务调用:脱敏后的商品公开数据会传输至 DeepSeek(中国境内服务商)进行处理。不传输个人身份信息。
  • PayPal 支付:订单基本信息(金额、订单号)通过 PayPal API 传输至 PayPal(美国)。PayPal 遵守其全球隐私政策与 GDPR 合规要求。
  • 海外用户访问:海外用户访问我们的网站时,其数据存储在中国大陆服务器,受中国法律管辖。

我们确保所有跨境数据传输符合适用法律法规要求,并采取合理措施保护数据安全。

6. 信息保留周期

  • 账号数据:保留至用户主动删除账号。账号删除后,个人身份信息在 30 天内永久删除。
  • 收藏与监控数据:保留至用户主动删除或账号注销。
  • 订单与许可证数据:保留 5 年,用于财务合规与税务申报。
  • AI 建议反馈数据:保留 24 个月,到期自动删除。
  • IP 日志:保留 30 天,用于安全防护,到期自动删除。
  • 使用统计数据:匿名化后长期保留用于产品优化。
  • 聚合市场数据:因已去标识化,不构成个人信息,可长期保留。

7. Cookie 与类似技术

本产品使用以下存储技术:

  • chrome.storage.local:存储设备 ID、用户偏好设置、缓存数据。仅本扩展可访问。
  • localStorage:落地页存储 JWT 认证令牌(auth_token),用于维持登录状态。退出登录时自动清除。
  • HTTP Cookie:不主动设置跟踪 Cookie。

我们不使用第三方广告 Cookie 或行为追踪 Cookie。我们不响应浏览器的"Do Not Track"信号,因为我们本身不进行跨站追踪。

8. 用户权利

您享有以下权利:

  • 访问权:查看您的个人信息,包括账号信息、订单记录、收藏数据。
  • 更正权:修改您的个人信息,如昵称、密码。
  • 删除权:删除特定数据或注销整个账号。
  • 数据可携权:导出您的数据(JSON 格式)。
  • 撤回同意权:撤回对特定数据处理的同意。
  • 异议权:对特定数据处理提出异议。

行使以上权利,请发送邮件至 2761373261@qq.com,我们将在 15 个工作日内回复。

9. 儿童隐私

本产品面向跨境电商从业者,不面向 16 岁以下儿童。我们不会故意收集儿童的个人信息。如果您是儿童的监护人,发现我们无意中收集了您孩子的信息,请立即联系我们删除。

10. 联系我们

如有隐私相关问题、数据删除请求或投诉,请联系:

11. 政策更新

本隐私政策可能不定期更新。重大变更时(如新增数据收集类型、新增第三方服务、变更数据用途),我们会通过插件内通知或邮件方式告知用户。继续使用本产品即视为同意更新后的政策。


Privacy Policy (English)

This Privacy Policy describes how Product Hunter ("we", "us", or "our") collects, uses, stores, and shares user data. By using our Chrome extension and website, you agree to the practices described in this policy.

1. Information We Collect

1.1 Information You Provide

  • Email address: Used for registration, login, verification, order notifications, and password recovery. Stored in the database with a unique index.
  • Phone number (optional): Used for registration, login, and SMS verification. Only Chinese mainland phone numbers are supported.
  • Password: Stored using bcrypt hashing algorithm with salt (cost factor = 10). We do not store plaintext passwords.
  • Display name (optional): Used for UI display.
  • Feedback and screenshots: Content you voluntarily submit.

1.2 Automatically Collected Information

  • Device fingerprint: Canvas rendering features, WebGL info, screen resolution, timezone, language, OS platform, font list — hashed to generate a device fingerprint (format: fp_<32-char-hash>). Used for device authorization and anti-abuse. Does not contain PII. Users can reset by clearing extension storage.
  • Device identifier: Unique device ID (format: dev_<timestamp>_<random>) stored in chrome.storage.local. Used for license validation and usage statistics. Users can remove by clearing extension data.
  • Browser and system info: User-Agent string, browser language, extension version. Used for compatibility and diagnostics.
  • IP address: Logged for security, rate limiting, and anti-abuse (e.g., limiting registrations per IP within 24 hours). Not used for personal identification. Logs retained for 30 days.
  • Acquisition source: UTM parameters, referrer, landing page path from first visit. Used for marketing analytics.
  • Usage statistics: Feature usage frequency, data views, exports, AI calls. Used for product optimization and quota management.

1.3 Product Data (User-Initiated Collection)

  • Favorited products: ASIN/ID, URL, title, price, platform source.
  • Monitored products: Products being tracked with historical price, BSR rank, and review data.
  • 1688 collected data: Public product data (title, price, specs, supplier info) read from 1688 public pages the user actively visits. Collection happens in the user's browser; no anti-scraping mechanisms are bypassed.
  • Supplier favorites: Supplier member_id, company name, shop URL, rating, tags, inquiry records.

1.4 Transaction Data

  • Order records: Order ID, user ID, tier, billing cycle, amount, currency, payment method, status, timestamps.
  • License info: License key (HMAC-signed), tier, billing cycle, max devices, expiry, status.
  • Payment credentials: Transaction IDs returned by payment processors (PayPal capture ID, Alipay transaction number, WeChat Pay transaction number). We do not store full card numbers or payment account details.

1.5 AI Service Data

When users actively click the AI analysis button, anonymized public product data is sent to third-party AI services:

  • Data sent: Product title, price, review summary, BSR rank, category. Not sent: user_id, email, device ID, or other PII.
  • Trigger: Only when the user actively clicks the AI analysis button.
  • AI provider: DeepSeek. Data processing follows DeepSeek's privacy policy.

1.6 Cross-User Aggregated Data

  • Scope: Product ASIN/ID, price, BSR, review count, rating, category, collection time. Excludes user_id, email, device ID.
  • Anonymity: Aggregated tables contain no user_id field; cannot be traced back to individual users.
  • Purpose: Historical trend curves, AI insight grounding, sales estimation calibration.

1.7 Information We Do Not Collect

  • Store login passwords on any e-commerce platform
  • Payment passwords or full bank card information
  • Sensitive seller dashboard data on any platform
  • Browser history or non-e-commerce website data
  • Precise geolocation (GPS)
  • Contacts or social media account information

2. How We Use Information

  • Core functionality: Product data analysis, profit calculation, competitor monitoring, AI insights, price monitoring, supplier management.
  • Account management: Registration, login, password recovery, verification, subscription management.
  • Data sync: Sync favorites and monitored data to cloud for cross-device access.
  • Notifications: Alerts, system notifications, order confirmations, trial expiry reminders.
  • Security: Device fingerprint verification, anti-abuse, IP rate limiting, anomaly detection.
  • Product improvement: Usage statistics for feature optimization and bug fixing.
  • Compliance: Transaction records for financial compliance and tax reporting.

We do NOT use user data for: Personalized advertising, selling to third parties, or commercial purposes unrelated to this product.

3. Data Storage and Protection

3.1 Storage Location

  • Server location: Alibaba Cloud servers in mainland China (Hangzhou data center).
  • Database: SQLite database on local server with foreign key constraints and access controls.
  • Local storage: Non-sensitive data (device ID, preferences, cache) stored in chrome.storage.local.
  • Backups: Database backed up periodically; backup files stored locally, not transferred overseas.

3.2 Security Measures

  • Transport encryption: All client-server communication uses HTTPS (TLS 1.2+).
  • Password encryption: bcrypt with salt (cost factor = 10). No plaintext storage.
  • JWT authentication: Session management via JWT with secret key ≥ 32 characters.
  • CORS policy: Strict origin allowlist; only registered extension IDs and official domains can access APIs.
  • Input validation: All API parameters validated via Zod schema to prevent injection attacks.
  • Rate limiting: API rate limits to prevent brute force and abuse.
  • Access control: Server access restricted to authorized personnel; database not exposed on public ports.

3.3 Security Incident Response

In the event of a data security incident, we will initiate emergency response within 72 hours, assess the impact, take remedial measures, and notify affected users via email.

4. Information Sharing and Third-Party Services

We do not sell user personal information. The following are third-party services we share data with:

4.1 Payment Processors

  • PayPal: For international payments. Shared data: order amount, order ID, callback URL. Privacy policy: PayPal Privacy Policy
  • Alipay: For domestic payments. Shared data: order amount, order ID, product title, async notification URL. Privacy policy: Alipay Privacy Policy
  • WeChat Pay: For domestic payments. Shared data: order amount, order ID, product description, async notification URL. Privacy policy: WeChat Privacy Policy

All payment processors comply with PCI-DSS standards. We do not store full card numbers or payment account details.

4.2 AI Service Provider

  • DeepSeek: For AI product analysis, review summarization, and insights. Shared data: anonymized public product data (title, price, review summary). No PII shared. Privacy policy: DeepSeek Privacy Policy

4.3 Email Service

  • SMTP service: For sending verification codes, order notifications, and alerts. Shared data: recipient email, subject, body. No passwords or sensitive info in email content.

4.4 SMS Service

  • SMS verification: For phone number registration verification. Shared data: phone number, verification code. Sent only during active registration; not used for marketing.

4.5 Other Sharing Scenarios

  • Legal requirements: We may disclose necessary information when required by law, government agencies, or to protect our legitimate rights.
  • Business transfers: In the event of a merger, acquisition, or asset transfer, user data may be transferred as an asset. We will ensure the recipient continues to comply with this privacy policy.

5. International Data Transfers

User data is primarily stored on servers in mainland China. The following scenarios involve cross-border data transfers:

  • AI service: Anonymized public product data is transferred to DeepSeek (a provider within China). No PII is transferred.
  • PayPal payments: Basic order information (amount, order ID) is transferred to PayPal (USA) via PayPal API. PayPal complies with its global privacy policy and GDPR.
  • International users: Data of international users is stored on servers in mainland China and is subject to Chinese law.

6. Data Retention

  • Account data: Retained until the user deletes their account. PII is permanently deleted within 30 days of account deletion.
  • Favorites and monitored data: Retained until user deletion or account cancellation.
  • Order and license data: Retained for 5 years for financial compliance and tax reporting.
  • AI feedback data: Retained for 24 months, then automatically deleted.
  • IP logs: Retained for 30 days for security purposes, then automatically deleted.
  • Usage statistics: Anonymized and retained long-term for product optimization.
  • Aggregated market data: De-identified; may be retained long-term.

7. Cookies and Similar Technologies

  • chrome.storage.local: Stores device ID, user preferences, cached data. Accessible only by this extension.
  • localStorage: Stores JWT auth token on the landing page for session management. Cleared on logout.
  • HTTP Cookies: We do not actively set tracking cookies.

We do not use third-party advertising cookies or behavioral tracking cookies. We do not respond to browser "Do Not Track" signals as we do not engage in cross-site tracking.

8. Your Rights

  • Access: View your personal information, including account info, order records, and favorites.
  • Rectification: Modify your personal information, such as display name and password.
  • Erasure: Delete specific data or cancel your entire account.
  • Data portability: Export your data in JSON format.
  • Withdraw consent: Withdraw consent for specific data processing.
  • Object: Object to specific data processing.

To exercise these rights, email 2761373261@qq.com. We will respond within 15 business days.

9. Children's Privacy

This product is intended for cross-border e-commerce professionals and is not directed at children under 16. We do not knowingly collect personal information from children. If you are a parent or guardian and believe we have collected your child's information, please contact us immediately for deletion.

10. Contact Us

11. Policy Updates

This privacy policy may be updated periodically. For material changes (e.g., new data collection types, new third-party services, changed data purposes), we will notify users via in-extension notifications or email. Continued use of this product constitutes acceptance of the updated policy.

← 返回首页 / Back to Home