This Privacy Policy explains how Yuanyun Technology (圆蕴科技) ("Yuanyun Technology", "we", "us", or "our") collects, uses, shares, and protects information in connection with our software-as-a-service platform and related websites and applications (collectively, the "Service"). The Service helps Chinese manufacturers market to and communicate with overseas B2B customers, including through a unified messaging inbox that connects Facebook Messenger, Instagram, and WhatsApp.
1. Who we are & how to contact us
The Service is operated by Yuanyun Technology (圆蕴科技).
- Legal company name: 佛山圆蕴科技有限公司 (Foshan Yuanyun Technology Co., Ltd.)
- Registered address: 佛山市禅城区石湾镇街道魁奇西路宝利莱装饰材料城B座三楼303房Q180室, Foshan, Guangdong, China
- Unified Social Credit Code: 91440604MAEQY88L66
- Contact email: [email protected]
- Website: roundluck.com
If you have any questions about this policy or about how your data is handled, please contact us at the email above.
2. What data we collect
(a) Account data of our business users
When a business signs up for and uses the Service, we collect account and profile information such as name, business name, email address, login credentials, billing details, and configuration settings, as well as usage and log data (for example, IP address, device and browser information, and actions taken within the Service) needed to operate and secure the product.
(b) Messaging data from connected channels
When a business connects their Facebook Page (Messenger), Instagram professional account, or WhatsApp to the Service, we receive the messages that the business's customers send to that business. This may include:
- Message content (text, and any attachments such as images, files, or other media sent in the conversation);
- The sender's name and platform-scoped identifier (such as a Facebook Page-Scoped ID (PSID) or Instagram-Scoped ID (IGSID)) and, for WhatsApp, the phone number used to contact the business;
- Message timestamps and basic conversation metadata.
We receive and process this messaging data solely to display the messages in the connecting business's inbox and to enable that business to send replies. The business is the controller of its own customers' messages; we act as a processor that provides the inbox service on the business's behalf.
(c) Access tokens and account identifiers
To receive and send messages on a business's behalf, we store the Facebook / Instagram Page access tokens, and the page, account, and business identifiers, that the business authorizes during connection. These tokens are used only to operate the inbox for that business and are protected as described in the Security section.
3. How we use data
We use the data described above to:
- Deliver the unified inbox — receiving, organizing, and displaying customer messages from connected channels;
- Enable replies — allowing the business's team members to respond, and generating AI-assisted reply suggestions to help them respond faster and more clearly;
- Generate marketing content (such as social copy, content calendars, and product images) that the business requests;
- Provide customer support, maintain and secure the Service, prevent abuse, and comply with legal obligations.
We do not sell personal data. We do not use the content of customer messages for advertising or ad targeting, and we do not use it to build profiles unrelated to providing the inbox service.
4. Third-party processors
We rely on a limited number of service providers ("sub-processors") to operate the Service. They process data only on our instructions and only as needed to deliver the Service:
- Meta Platforms, Inc. — to receive and send messages on the business's behalf via the Meta / Facebook Graph API across Messenger, Instagram, and WhatsApp.
- Google LLC (YouTube API Services) — to upload videos to the business's own YouTube channel when the business connects its Google account and requests a publish.
- TikTok Pte. Ltd. — to publish content to the business's own TikTok account when the business connects its TikTok account and requests a publish.
- LinkedIn Corporation — to publish content to the business's own LinkedIn profile or LinkedIn Page when the business connects its LinkedIn account and requests a publish.
- OpenAI — to generate AI-assisted reply suggestions and marketing content. To draft a suggested reply, relevant message text may be transmitted to and processed by OpenAI. We do not permit such content to be used to train third-party models where that option is available to us.
- Cloud hosting and infrastructure providers — to host the Service, store data, and deliver the application securely.
5. Data sharing
We share data only: (i) with the sub-processors listed above; (ii) with the business that connected the channel, whose customers' messages are displayed in that business's own inbox; (iii) where required by law, legal process, or to protect rights, safety, and the integrity of the Service; and (iv) in connection with a corporate transaction (such as a merger or acquisition), subject to this policy. We do not sell or rent personal data to third parties.
6. Data retention
We retain account data and messaging data while the business's account is active and the relevant channel remains connected, as needed to provide the inbox service. Data is deletable on request, and messaging data and stored access tokens for a channel are deleted when the business disconnects that channel or closes its account, subject to limited retention required for legal, security, or backup purposes. See our Data Deletion instructions for details.
7. Security
We apply administrative, technical, and organizational safeguards designed to protect data against unauthorized access, disclosure, alteration, and loss. These include encryption in transit, access controls, restricted handling of access tokens, and monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues we identify.
8. Your rights & data deletion
Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Business users and end customers can request deletion of their data at any time. End customers may also contact the business they messaged.
To exercise any of these rights, email [email protected] or follow the steps in our Data Deletion instructions.
9. Meta Platform compliance
We adhere to the Meta Platform Terms and the Meta Developer Policies. Data obtained through Meta (Messenger, Instagram, and the Graph API) is used only to provide the unified inbox service to the business that connected its account — to receive, display, and reply to that business's own customer messages. We do not use Meta data for advertising, do not sell it, and do not transfer it except to the sub-processors and for the limited purposes described in this policy.
9.1 YouTube API Services & Google user data
Roundluck uses YouTube API Services. By connecting a Google account, you agree to be bound by the YouTube Terms of Service. The Google Privacy Policy also applies.
What we access, use, store and share: when a business connects its Google account, we request only the permission to upload videos to that business's own YouTube channel. We store the OAuth tokens securely and use them solely to upload the videos the business explicitly asks us to publish, and to show the upload result. We do not read channel analytics, subscriber lists, or other YouTube data beyond what is needed for the upload the user requested; we do not share Google user data with third parties except the infrastructure sub-processors listed above; and we never sell it.
Deletion and refresh: stored Google authorization data is refreshed or deleted at least every 30 days; tokens are deleted immediately when the business disconnects the channel or on request (see Data Deletion).
Revoking access: in addition to disconnecting inside Roundluck, you can revoke Roundluck's access to your Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions.
9.2 TikTok data
When a business connects its TikTok account, we access only the basic profile information (open id, display name, avatar) needed to show which account is connected, and we publish only the content the business explicitly submits, to that business's own TikTok profile. Stored TikTok access tokens are deleted when the channel is disconnected or on request.
9.3 LinkedIn data
When a business connects a LinkedIn account or LinkedIn Page, we access only what is needed to identify which account or Page the content will be published to, and we publish only the content the business explicitly submits, to that business's own LinkedIn profile or Page. In line with the LinkedIn API Terms of Use, we do not retain LinkedIn member profile data (such as name or profile picture) beyond 24 hours, and we do not retain LinkedIn member social action data beyond 48 hours; our records keep only the LinkedIn identifier (URN) of the connected account and the access token needed to publish on the business's behalf. We do not use LinkedIn data for advertising, profiling, resale, or to build any independent database of members. Stored LinkedIn access tokens are deleted when the channel is disconnected or on request, and the business can also revoke our access at any time from its LinkedIn account settings.
10. Children
The Service is a business tool intended for organizations and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.
11. International transfers
We operate internationally, and data may be processed in countries other than the one in which you are located, including where our sub-processors operate. Where required, we use appropriate safeguards for such transfers.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated as appropriate. Your continued use of the Service after an update constitutes acceptance of the revised policy.
本隐私政策说明圆蕴科技("圆蕴科技""我们")如何就我们的软件即服务(SaaS)平台及相关网站与应用(统称"本服务")收集、使用、共享和保护信息。本服务帮助中国制造企业面向海外 B2B 客户开展营销与沟通,其中包括一个连接 Facebook Messenger、Instagram 与 WhatsApp 的统一消息收件箱。
1. 我们是谁及联系方式
本服务由圆蕴科技运营。
- 公司法定名称: 佛山圆蕴科技有限公司 (Foshan Yuanyun Technology Co., Ltd.)
- 注册地址: 佛山市禅城区石湾镇街道魁奇西路宝利莱装饰材料城B座三楼303房Q180室, Foshan, Guangdong, China
- 统一社会信用代码: 91440604MAEQY88L66
- 联系邮箱: [email protected]
- 网站: roundluck.com
如对本政策或您的数据处理方式有任何疑问,请通过上述邮箱与我们联系。
2. 我们收集哪些数据
(a)业务用户的账户数据
当企业注册并使用本服务时,我们会收集账户与资料信息,例如姓名、企业名称、电子邮箱、登录凭据、账单信息与配置设置,以及为运营和保障产品所需的使用与日志数据(例如 IP 地址、设备与浏览器信息,以及在本服务内执行的操作)。
(b)来自已连接渠道的消息数据
当企业将其 Facebook 主页(Messenger)、Instagram 专业账号或 WhatsApp 连接至本服务后,我们会接收该企业客户向其发送的消息,可能包括:
- 消息内容(文本,以及对话中发送的图片、文件或其他媒体等附件);
- 发送者的姓名与平台范围标识符(如 Facebook 主页范围 ID(PSID)或 Instagram 范围 ID(IGSID)),对于 WhatsApp 则为用于联系企业的电话号码;
- 消息时间戳及基本对话元数据。
我们接收并处理此类消息数据,仅用于在连接渠道的企业收件箱中展示这些消息,并使该企业能够回复。该企业是其自身客户消息的控制者;我们作为处理方,代表企业提供收件箱服务。
(c)访问令牌与账号标识符
为代表企业接收和发送消息,我们会存储企业在连接过程中授权的 Facebook / Instagram 主页访问令牌,以及主页、账号与商家标识符。这些令牌仅用于为该企业运营收件箱,并按"安全"一节所述加以保护。
3. 我们如何使用数据
我们使用上述数据以:
- 提供统一收件箱——接收、整理并展示来自已连接渠道的客户消息;
- 支持回复——允许企业团队成员进行回复,并生成 AI 辅助回复建议,帮助其更快、更清晰地响应;
- 生成企业所请求的营销内容(如社媒文案、内容日历与产品图片);
- 提供客户支持、维护并保障本服务、防止滥用,以及遵守法律义务。
我们不出售个人数据。 我们不将客户消息内容用于广告或广告定向,也不将其用于构建与提供收件箱服务无关的用户画像。
4. 第三方处理方
我们依赖少数服务提供方("子处理方")运营本服务。它们仅按照我们的指示、并仅在提供本服务所必需的范围内处理数据:
- Meta Platforms, Inc. —— 通过 Meta / Facebook Graph API 代表企业在 Messenger、Instagram 与 WhatsApp 上接收和发送消息。
- Google LLC(YouTube API 服务) —— 当企业绑定其 Google 账号并发起发布时,用于将视频上传至该企业自己的 YouTube 频道。
- TikTok Pte. Ltd. —— 当企业绑定其 TikTok 账号并发起发布时,用于将内容发布至该企业自己的 TikTok 账号。
- LinkedIn Corporation —— 当企业绑定其 LinkedIn 账号并发起发布时,用于将内容发布至该企业自己的 LinkedIn 个人主页或公司主页。
- OpenAI —— 用于生成 AI 辅助回复建议与营销内容。为草拟建议回复,相关消息文本可能被传输至 OpenAI 并由其处理。在可由我们选择的范围内,我们不允许此类内容用于训练第三方模型。
- 云托管与基础设施提供方 —— 用于托管本服务、存储数据并安全地交付应用。
5. 数据共享
我们仅在以下情形共享数据:(i)与上述子处理方共享;(ii)与连接渠道的企业共享,其客户消息展示在该企业自己的收件箱中;(iii)法律、法律程序要求时,或为保护权利、安全与本服务完整性所需时;(iv)在公司交易(如并购)中,并受本政策约束。我们不向第三方出售或出租个人数据。
6. 数据保留
在企业账户处于活跃状态且相关渠道保持连接期间,我们会保留账户数据与消息数据,以提供收件箱服务。数据可应请求删除;当企业断开某渠道连接或关闭其账户时,该渠道的消息数据与已存储的访问令牌将被删除,但出于法律、安全或备份目的所需的有限保留除外。详情请见我们的数据删除说明。
7. 安全
我们采取管理、技术与组织层面的保护措施,以防止数据遭未经授权的访问、披露、篡改与丢失,包括传输加密、访问控制、对访问令牌的受限处理与监控。没有任何传输或存储方式是绝对安全的,但我们会努力保护您的信息,并及时处理我们发现的任何问题。
8. 您的权利与数据删除
根据您所在地区,您可能有权访问、更正、导出、限制或删除您的个人数据,并反对某些处理。业务用户与终端客户可随时请求删除其数据。终端客户亦可联系其曾发送消息的企业。
如需行使上述任何权利,请发送邮件至 [email protected],或按照我们的数据删除说明操作。
9. Meta 平台合规
我们遵守 Meta 平台条款与 Meta 开发者政策。通过 Meta(Messenger、Instagram 与 Graph API)获取的数据,仅用于向连接其账号的企业提供统一收件箱服务——即接收、展示并回复该企业自己的客户消息。我们不将 Meta 数据用于广告,不出售此类数据,除向本政策所述的子处理方并出于本政策所述的有限目的外,不进行转移。
9.1 YouTube API 服务与 Google 用户数据
Roundluck 使用 YouTube API 服务。绑定 Google 账号即表示你同意受 YouTube 服务条款约束,同时适用 Google 隐私政策。
我们如何访问、使用、存储与共享:企业绑定 Google 账号时,我们仅申请"向该企业自己的 YouTube 频道上传视频"这一项权限。我们安全存储 OAuth 令牌,仅用于上传企业明确要求发布的视频并展示上传结果;不读取频道分析、订阅者列表等其他 YouTube 数据;除上文所列基础设施处理方外不与任何第三方共享 Google 用户数据,也绝不出售。
删除与刷新:存储的 Google 授权数据至少每 30 天刷新或删除一次;企业解绑渠道或提出请求时立即删除(见数据删除)。
撤销授权:除在 Roundluck 内解绑外,你可随时通过 Google 安全设置页 https://security.google.com/settings/security/permissions 撤销 Roundluck 对你 Google 数据的访问权限。
9.2 TikTok 数据
企业绑定 TikTok 账号时,我们仅访问用于显示"当前绑定了哪个账号"的基础资料(open id、昵称、头像),且仅将企业明确提交的内容发布到该企业自己的 TikTok 账号。企业解绑或提出请求时,存储的 TikTok 访问令牌将被删除。
9.3 LinkedIn 数据
企业绑定 LinkedIn 账号或公司主页时,我们仅访问用于识别"内容将发布到哪个账号/主页"所必需的信息,且仅将企业明确提交的内容发布到该企业自己的 LinkedIn 个人主页或公司主页。依照 LinkedIn API 使用条款,我们不会将 LinkedIn 会员资料数据(如姓名、头像)保留超过 24 小时,也不会将会员社交行为数据保留超过 48 小时;我们的记录中仅保存所绑定账号的 LinkedIn 标识符(URN)与代企业发布所需的访问令牌。我们不会将 LinkedIn 数据用于广告投放、用户画像、转售,也不会据此建立任何独立的会员数据库。企业解绑或提出请求时,存储的 LinkedIn 访问令牌将被删除;企业亦可随时在其 LinkedIn 账号设置中撤销我们的访问权限。
10. 儿童
本服务是面向组织的商业工具,并非面向儿童。我们不会在明知的情况下收集儿童的个人数据。若您认为儿童向我们提供了个人数据,请与我们联系以便删除。
11. 跨境传输
我们在全球范围内运营,数据可能在您所在国家/地区以外被处理,包括我们的子处理方所在地。在法律要求时,我们会对此类传输采取适当的保护措施。
12. 政策变更
我们可能不时更新本隐私政策。我们将在此处发布更新后的版本并修订上方的生效日期。重大变更将以适当方式告知。更新后您继续使用本服务,即表示接受修订后的政策。