SCOUT CANTON SCOUT CANTON中文

Privacy Policy

Public sourcing inquiries and infrastructure

The short public form collects email, product/industry, inquiry category, challenge, optional name and country, contact consent, reference and timestamp. Only utm_source, utm_medium and utm_campaign are retained from the landing URL. Records are stored in the existing Cloudflare D1 database through ChatGPT Sites; ChatGPT provides sign-in and Cloudflare operates the hosting infrastructure. This application does not specify a guaranteed storage country. No marketing subscription or automated email is created by submission. Existing longer forms may collect the additional fields described below.

Information we collect

Signing in supplies a site-specific user identifier and email, and may supply a display name. Inquiries store your name, email, country of residence, optional international mobile, preferred language, party size, destination cities, arrival status/date, stay length, primary purpose, other needs and purpose-specific practical support answers. We also store contact preference, optional WeChat/other contact details, separate contact consent, optional discovery source and URL campaign parameters (UTM), request text, membership status and privacy consent version. Administration stores private notes, public replies, quotes, currency, service scope, next actions and audit history. Partner applications use the same form and store your service introduction.

Why we use it

We use account information to enforce access and show your own requests. Inquiry information is used for manual review and follow-up, administration and any agreed service. It is not used for automated marketing in this release. Do not include passport numbers, bank credentials, clinical records or other sensitive documents.

Protection and provider sharing

Only the designated administrator can view all submissions and internal notes. Signed-in users can view only submissions linked to their own account. Initial submission is not permission to forward your request to independent providers; we first explain the recipient and necessary information and request separate consent. Platform infrastructure processes data to operate the site.

Abuse prevention and retention

Public forms use a short-lived single-use token, a hidden spam field and rate limits. A salted hash derived from the request IP address is stored for rate limiting; the raw IP is not stored in our application database. Temporary verification records are removed as they expire during subsequent form requests. Account and inquiry records remain in the database for ongoing administration; this release has no automatic retention schedule.

Questions and data requests

Use the Contact page and describe your privacy/data request. Include your account email or inquiry reference and describe what you need. Requests are reviewed manually and identity may need to be verified before access, correction or deletion. Do not send additional sensitive information to prove identity in the initial form.

Page reviewed: 4 October 2026