This Privacy Policy explains how Yuanyun Technology (圆蕴科技) ("Yuanyun Technology", "we", "us", or "our") collects, uses, shares, and protects information in connection with our software-as-a-service platform and related websites and applications (collectively, the "Service"). The Service helps Chinese manufacturers market to and communicate with overseas B2B customers, including through a unified messaging inbox that connects Facebook Messenger, Instagram, and WhatsApp.
1. Who we are & how to contact us
The Service is operated by Yuanyun Technology (圆蕴科技).
- Legal company name: 佛山圆蕴科技有限公司 (Foshan Yuanyun Technology Co., Ltd.)
- Registered address: 佛山市禅城区石湾镇街道魁奇西路宝利莱装饰材料城B座三楼303房Q180室, Foshan, Guangdong, China
- Unified Social Credit Code: 91440604MAEQY88L66
- Contact email: [email protected]
- Website: roundluck.com
If you have any questions about this policy or about how your data is handled, please contact us at the email above.
2. What data we collect
(a) Account data of our business users
When a business signs up for and uses the Service, we collect account and profile information such as name, business name, email address, login credentials, billing details, and configuration settings, as well as usage and log data (for example, IP address, device and browser information, and actions taken within the Service) needed to operate and secure the product.
(b) Messaging data from connected channels
When a business connects their Facebook Page (Messenger), Instagram professional account, or WhatsApp to the Service, we receive the messages that the business's customers send to that business. This may include:
- Message content (text, and any attachments such as images, files, or other media sent in the conversation);
- The sender's name and platform-scoped identifier (such as a Facebook Page-Scoped ID (PSID) or Instagram-Scoped ID (IGSID)) and, for WhatsApp, the phone number used to contact the business;
- Message timestamps and basic conversation metadata.
We receive and process this messaging data solely to display the messages in the connecting business's inbox and to enable that business to send replies. The business is the controller of its own customers' messages; we act as a processor that provides the inbox service on the business's behalf.
(c) Access tokens and account identifiers
To receive and send messages on a business's behalf, we store the Facebook / Instagram Page access tokens, and the page, account, and business identifiers, that the business authorizes during connection. These tokens are used only to operate the inbox for that business and are protected as described in the Security section.
3. Cookies and similar technologies
We — and, for the embedded third-party content described in (b) below, those third parties — store, access and collect information on and from your device, including by placing, reading or recognising cookies, browser local storage and similar technologies in your browser. This section explains what is stored, why, and how you can control it.
(a) What Roundluck stores on your device
The Roundluck platform (app.roundluck.com) and this website (roundluck.com) use your browser's local storage for strictly functional purposes:
- Keeping you signed in — when you sign in to the platform we store your session token in local storage, so you are not asked to sign in again on every page. It is removed when you sign out.
- Remembering your settings — for example the interface language you selected on this website, the workspace you last worked in, and which panels, filters and options you had open, so the product looks the same when you return.
We do not use cookies, local storage or similar technologies for advertising, ad targeting, ad measurement, or to track you across other websites, and we do not run third-party analytics or advertising tags on our own websites or in the platform.
(b) Third-party content we embed, including the YouTube embedded player
Parts of the Service display content that is served directly by the platform it comes from. When that content loads, your browser connects to that third party, which can set and read its own cookies and similar identifiers on your device and receive information such as your IP address, browser and device type, and the page you were viewing. This happens under that third party's own privacy policy:
- YouTube embedded player (Google LLC). In our market-research feature you can preview a publicly available YouTube video without leaving the Service. The video is played by the YouTube embedded player loaded from youtube.com, and Google may place and read cookies and similar technologies on your device through that player. Use of the embedded player is subject to the YouTube Terms of Service and the Google Privacy Policy; see also how Google uses information from sites or apps that use its services.
- TikTok embedded player (TikTok Pte. Ltd.). Previews of publicly available TikTok videos are played by TikTok's embedded player loaded from tiktok.com, which may likewise set and read cookies and similar identifiers on your device.
- Thumbnails and images shown in search and preview results are loaded from the source platforms' own content networks (for example i.ytimg.com for YouTube thumbnails). Loading them sends a request from your browser to that network, which receives your IP address and browser information.
- Google Fonts. Our public website loads web fonts from fonts.googleapis.com and fonts.gstatic.com; Google receives that request, including your IP address, in order to serve the font files.
(c) How you can control this
You can block or delete cookies and clear local storage at any time in your browser settings, and most browsers allow you to refuse third-party cookies specifically. Blocking the storage used by embedded players affects only those players — the rest of the Service continues to work. Blocking the storage the platform itself uses will sign you out and reset your saved preferences, because that storage is what keeps you signed in. You can also control what Google associates with your Google Account in your Google Account privacy settings.
4. How we use data
We use the data described above to:
- Deliver the unified inbox — receiving, organizing, and displaying customer messages from connected channels;
- Enable replies — allowing the business's team members to respond, and generating AI-assisted reply suggestions to help them respond faster and more clearly;
- Generate marketing content (such as social copy, content calendars, and product images) that the business requests;
- Provide customer support, maintain and secure the Service, prevent abuse, and comply with legal obligations.
We do not sell personal data. We do not use the content of customer messages for advertising or ad targeting, and we do not use it to build profiles unrelated to providing the inbox service.
5. Third-party processors
We rely on a limited number of service providers ("sub-processors") to operate the Service. They process data only on our instructions and only as needed to deliver the Service:
- Meta Platforms, Inc. — to receive and send messages on the business's behalf via the Meta / Facebook Graph API across Messenger, Instagram, and WhatsApp.
- Google LLC (YouTube API Services) — to upload videos to the business's own YouTube channel when the business connects its Google account and requests a publish.
- TikTok Pte. Ltd. — to publish content to the business's own TikTok account when the business connects its TikTok account and requests a publish.
- LinkedIn Corporation — to publish content to the business's own LinkedIn profile or LinkedIn Page when the business connects its LinkedIn account and requests a publish.
- OpenAI — to generate AI-assisted reply suggestions and marketing content. To draft a suggested reply, relevant message text may be transmitted to and processed by OpenAI. We do not permit such content to be used to train third-party models where that option is available to us.
- Cloud hosting and infrastructure providers — to host the Service, store data, and deliver the application securely.
6. Data sharing
We share data only: (i) with the sub-processors listed above; (ii) with the business that connected the channel, whose customers' messages are displayed in that business's own inbox; (iii) where required by law, legal process, or to protect rights, safety, and the integrity of the Service; and (iv) in connection with a corporate transaction (such as a merger or acquisition), subject to this policy. We do not sell or rent personal data to third parties.
7. Data retention
We retain account data and messaging data while the business's account is active and the relevant channel remains connected, as needed to provide the inbox service. Data is deletable on request, and messaging data and stored access tokens for a channel are deleted when the business disconnects that channel or closes its account, subject to limited retention required for legal, security, or backup purposes. See our Data Deletion instructions for details.
8. Security
We apply administrative, technical, and organizational safeguards designed to protect data against unauthorized access, disclosure, alteration, and loss. These include encryption in transit, access controls, restricted handling of access tokens, and monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues we identify.
9. Your rights & data deletion
Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Business users and end customers can request deletion of their data at any time. End customers may also contact the business they messaged.
To exercise any of these rights, email [email protected] or follow the steps in our Data Deletion instructions.
10. Meta Platform compliance
We adhere to the Meta Platform Terms and the Meta Developer Policies. Data obtained through Meta (Facebook Pages, Instagram, and the Graph API) is used only to provide the services described below to the business that connected its own accounts.
(a) Content publishing. When a business connects its Facebook Page and Instagram professional account, we read the list of Pages that business manages so it can choose which one to connect, and we publish to that business's own Page and Instagram account only the content that business has created and approved inside our platform — either immediately, or at the date and time that business schedules. Drafts may be AI-assisted. Content goes out either after the business approves that individual post, or automatically according to a content plan and schedule the business has set up in our platform. After publishing we read only the post identifier and its publication status, solely so the business can see inside our platform whether its post went out successfully. We do not read likes, comments, reach, or any other insights data.
(b) Messaging. When a business connects its Instagram professional account, we receive and display the messages that business's own customers send to it, so its team can read and reply to them in one place.
We do not use Meta data for advertising or ad targeting, do not sell it, do not use it to train third-party models, and do not transfer it except to the sub-processors and for the limited purposes described in this policy. Stored Meta access tokens and the related data are deleted when the business disconnects the channel, closes its account, or removes our app from its Facebook settings. A business can revoke our access at any time in its own Facebook settings; once revoked, we can no longer publish to, or receive messages from, its accounts.
10.1 YouTube API Services & Google user data
Roundluck uses YouTube API Services. By connecting a Google account, you agree to be bound by the YouTube Terms of Service. The Google Privacy Policy also applies.
What we access, use, store and share: when a business connects its Google account, we request only the permission to upload videos to that business's own YouTube channel. We store the OAuth tokens securely and use them solely to upload the videos the business explicitly asks us to publish, and to show the upload result. We do not read channel analytics, subscriber lists, or other YouTube data beyond what is needed for the upload the user requested; we do not share Google user data with third parties except the infrastructure sub-processors listed above; and we never sell it.
Deletion and refresh: stored Google authorization data is refreshed or deleted at least every 30 days; tokens are deleted immediately when the business disconnects the channel or on request (see Data Deletion).
Revoking access: in addition to disconnecting inside Roundluck, you can revoke Roundluck's access to your Google data at any time via the Google security settings page at https://security.google.com/settings/security/permissions.
10.2 TikTok data
When a business connects its TikTok account, we access only the basic profile information (open id, display name, avatar) needed to show which account is connected, and we publish only the content the business explicitly submits, to that business's own TikTok profile. Stored TikTok access tokens are deleted when the channel is disconnected or on request.
10.3 LinkedIn data
When a business connects a LinkedIn account or LinkedIn Page, we access only what is needed to identify which account or Page the content will be published to, and we publish only the content the business explicitly submits, to that business's own LinkedIn profile or Page. In line with the LinkedIn API Terms of Use, we do not retain LinkedIn member profile data (such as name or profile picture) beyond 24 hours, and we do not retain LinkedIn member social action data beyond 48 hours; our records keep only the LinkedIn identifier (URN) of the connected account and the access token needed to publish on the business's behalf. We do not use LinkedIn data for advertising, profiling, resale, or to build any independent database of members. Stored LinkedIn access tokens are deleted when the channel is disconnected or on request, and the business can also revoke our access at any time from its LinkedIn account settings.
11. Children
The Service is a business tool intended for organizations and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.
12. International transfers
We operate internationally, and data may be processed in countries other than the one in which you are located, including where our sub-processors operate. Where required, we use appropriate safeguards for such transfers.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated as appropriate. Your continued use of the Service after an update constitutes acceptance of the revised policy.
本隐私政策说明圆蕴科技("圆蕴科技""我们")如何就我们的软件即服务(SaaS)平台及相关网站与应用(统称"本服务")收集、使用、共享和保护信息。本服务帮助中国制造企业面向海外 B2B 客户开展营销与沟通,其中包括一个连接 Facebook Messenger、Instagram 与 WhatsApp 的统一消息收件箱。
1. 我们是谁及联系方式
本服务由圆蕴科技运营。
- 公司法定名称: 佛山圆蕴科技有限公司 (Foshan Yuanyun Technology Co., Ltd.)
- 注册地址: 佛山市禅城区石湾镇街道魁奇西路宝利莱装饰材料城B座三楼303房Q180室, Foshan, Guangdong, China
- 统一社会信用代码: 91440604MAEQY88L66
- 联系邮箱: [email protected]
- 网站: roundluck.com
如对本政策或您的数据处理方式有任何疑问,请通过上述邮箱与我们联系。
2. 我们收集哪些数据
(a)业务用户的账户数据
当企业注册并使用本服务时,我们会收集账户与资料信息,例如姓名、企业名称、电子邮箱、登录凭据、账单信息与配置设置,以及为运营和保障产品所需的使用与日志数据(例如 IP 地址、设备与浏览器信息,以及在本服务内执行的操作)。
(b)来自已连接渠道的消息数据
当企业将其 Facebook 主页(Messenger)、Instagram 专业账号或 WhatsApp 连接至本服务后,我们会接收该企业客户向其发送的消息,可能包括:
- 消息内容(文本,以及对话中发送的图片、文件或其他媒体等附件);
- 发送者的姓名与平台范围标识符(如 Facebook 主页范围 ID(PSID)或 Instagram 范围 ID(IGSID)),对于 WhatsApp 则为用于联系企业的电话号码;
- 消息时间戳及基本对话元数据。
我们接收并处理此类消息数据,仅用于在连接渠道的企业收件箱中展示这些消息,并使该企业能够回复。该企业是其自身客户消息的控制者;我们作为处理方,代表企业提供收件箱服务。
(c)访问令牌与账号标识符
为代表企业接收和发送消息,我们会存储企业在连接过程中授权的 Facebook / Instagram 主页访问令牌,以及主页、账号与商家标识符。这些令牌仅用于为该企业运营收件箱,并按"安全"一节所述加以保护。
3. Cookie 与类似技术
我们——以及下文(b)所述被我们嵌入的第三方内容的提供方——会在您的设备上存储、访问和收集信息,包括在您的浏览器中放置、读取或识别 Cookie、浏览器本地存储(local storage)及类似技术。本节说明存了什么、为什么存,以及您如何控制。
(a)Roundluck 自身在您设备上存储的内容
Roundluck 平台(app.roundluck.com)与本网站(roundluck.com)使用浏览器本地存储,仅用于以下功能性用途:
- 保持登录状态——您登录平台后,我们会把会话令牌存入本地存储,使您不必在每个页面重复登录;退出登录时即清除。
- 记住您的设置——例如您在本网站选择的界面语言、上次使用的工作区,以及您展开的面板、筛选条件与选项,以便您下次回来时界面保持一致。
我们不会将 Cookie、本地存储或类似技术用于广告、广告定向、广告效果衡量或跨网站追踪,也不在自有网站与平台中投放任何第三方分析或广告代码。
(b)我们嵌入的第三方内容,包括 YouTube 嵌入式播放器
本服务的部分功能会直接展示由内容所属平台提供的内容。这些内容加载时,您的浏览器会连接该第三方,该第三方可能在您的设备上设置并读取其自有的 Cookie 与类似标识符,并获得您的 IP 地址、浏览器与设备类型、以及您当时浏览的页面等信息。此类处理适用该第三方自己的隐私政策:
- YouTube 嵌入式播放器(Google LLC)。在市场调研功能中,您可以不离开本服务预览公开的 YouTube 视频。该视频由从 youtube.com 加载的 YouTube 嵌入式播放器播放,Google 可能通过该播放器在您的设备上放置并读取 Cookie 及类似技术。使用该播放器须遵守 YouTube 服务条款 与 Google 隐私权政策;另见 Google 如何使用来自使用其服务的网站或应用的信息。
- TikTok 嵌入式播放器(TikTok Pte. Ltd.)。公开 TikTok 视频的预览由从 tiktok.com 加载的 TikTok 嵌入式播放器播放,同样可能在您的设备上设置并读取 Cookie 与类似标识符。
- 缩略图与图片:搜索与预览结果中的缩略图由来源平台自己的内容分发网络提供(例如 YouTube 缩略图来自 i.ytimg.com)。加载它们会由您的浏览器向该网络发起请求,该网络因此获得您的 IP 地址与浏览器信息。
- Google Fonts。本公开网站从 fonts.googleapis.com 与 fonts.gstatic.com 加载网页字体;为提供字体文件,Google 会收到该请求(含您的 IP 地址)。
(c)您如何控制
您可随时在浏览器设置中阻止或删除 Cookie、清除本地存储,多数浏览器还可单独拒绝第三方 Cookie。阻止嵌入式播放器所用的存储只影响这些播放器,本服务其余功能照常可用;阻止平台自身所用的存储会使您退出登录并重置已保存的偏好,因为正是这部分存储在维持您的登录状态。您也可在 Google 账号的数据与隐私设置 中管理 Google 与您账号关联的信息。
4. 我们如何使用数据
我们使用上述数据以:
- 提供统一收件箱——接收、整理并展示来自已连接渠道的客户消息;
- 支持回复——允许企业团队成员进行回复,并生成 AI 辅助回复建议,帮助其更快、更清晰地响应;
- 生成企业所请求的营销内容(如社媒文案、内容日历与产品图片);
- 提供客户支持、维护并保障本服务、防止滥用,以及遵守法律义务。
我们不出售个人数据。 我们不将客户消息内容用于广告或广告定向,也不将其用于构建与提供收件箱服务无关的用户画像。
5. 第三方处理方
我们依赖少数服务提供方("子处理方")运营本服务。它们仅按照我们的指示、并仅在提供本服务所必需的范围内处理数据:
- Meta Platforms, Inc. —— 通过 Meta / Facebook Graph API 代表企业在 Messenger、Instagram 与 WhatsApp 上接收和发送消息。
- Google LLC(YouTube API 服务) —— 当企业绑定其 Google 账号并发起发布时,用于将视频上传至该企业自己的 YouTube 频道。
- TikTok Pte. Ltd. —— 当企业绑定其 TikTok 账号并发起发布时,用于将内容发布至该企业自己的 TikTok 账号。
- LinkedIn Corporation —— 当企业绑定其 LinkedIn 账号并发起发布时,用于将内容发布至该企业自己的 LinkedIn 个人主页或公司主页。
- OpenAI —— 用于生成 AI 辅助回复建议与营销内容。为草拟建议回复,相关消息文本可能被传输至 OpenAI 并由其处理。在可由我们选择的范围内,我们不允许此类内容用于训练第三方模型。
- 云托管与基础设施提供方 —— 用于托管本服务、存储数据并安全地交付应用。
6. 数据共享
我们仅在以下情形共享数据:(i)与上述子处理方共享;(ii)与连接渠道的企业共享,其客户消息展示在该企业自己的收件箱中;(iii)法律、法律程序要求时,或为保护权利、安全与本服务完整性所需时;(iv)在公司交易(如并购)中,并受本政策约束。我们不向第三方出售或出租个人数据。
7. 数据保留
在企业账户处于活跃状态且相关渠道保持连接期间,我们会保留账户数据与消息数据,以提供收件箱服务。数据可应请求删除;当企业断开某渠道连接或关闭其账户时,该渠道的消息数据与已存储的访问令牌将被删除,但出于法律、安全或备份目的所需的有限保留除外。详情请见我们的数据删除说明。
8. 安全
我们采取管理、技术与组织层面的保护措施,以防止数据遭未经授权的访问、披露、篡改与丢失,包括传输加密、访问控制、对访问令牌的受限处理与监控。没有任何传输或存储方式是绝对安全的,但我们会努力保护您的信息,并及时处理我们发现的任何问题。
9. 您的权利与数据删除
根据您所在地区,您可能有权访问、更正、导出、限制或删除您的个人数据,并反对某些处理。业务用户与终端客户可随时请求删除其数据。终端客户亦可联系其曾发送消息的企业。
如需行使上述任何权利,请发送邮件至 [email protected],或按照我们的数据删除说明操作。
10. Meta 平台合规
我们遵守 Meta 平台条款与 Meta 开发者政策。通过 Meta(Facebook 公共主页、Instagram 与 Graph API)获取的数据,仅用于向授权我们的企业本人提供以下服务。
(a)内容发布。企业接入自己的 Facebook 公共主页与 Instagram 专业账号后,我们读取该企业名下的主页列表,供其选择要接入哪一个;并仅将该企业在我们平台内撰写并确认过的内容,发布到它自己的公共主页与 Instagram 账号——可立即发布,也可按该企业设定的日期与时间发布。草稿可由 AI 辅助生成。内容的发出方式由该企业自行设定:或由其逐条确认后发出,或按其在我们平台内设定的内容计划与排期自动发出。发布后我们只读取该帖子的编号与发布状态,仅用于让该企业在平台内确认这条内容是否发布成功。我们不读取点赞、评论、覆盖人数等任何互动或分析数据。
(b)消息。企业接入自己的 Instagram 专业账号后,我们接收并展示其客户发给它的消息,供其团队在一处阅读与回复。
我们不将 Meta 数据用于广告或广告定向,不出售此类数据,不用于训练第三方模型;除向本政策所述的子处理方并出于本政策所述的有限目的外,不进行转移。企业解绑渠道、注销账户,或在自己的 Facebook 设置中移除我们的应用时,已存储的 Meta 访问令牌及相关数据将被删除。企业可随时在自己的 Facebook 设置中撤销授权;撤销之后,我们无法再向其账号发布内容,也无法再接收其消息。
10.1 YouTube API 服务与 Google 用户数据
Roundluck 使用 YouTube API 服务。绑定 Google 账号即表示你同意受 YouTube 服务条款约束,同时适用 Google 隐私政策。
我们如何访问、使用、存储与共享:企业绑定 Google 账号时,我们仅申请"向该企业自己的 YouTube 频道上传视频"这一项权限。我们安全存储 OAuth 令牌,仅用于上传企业明确要求发布的视频并展示上传结果;不读取频道分析、订阅者列表等其他 YouTube 数据;除上文所列基础设施处理方外不与任何第三方共享 Google 用户数据,也绝不出售。
删除与刷新:存储的 Google 授权数据至少每 30 天刷新或删除一次;企业解绑渠道或提出请求时立即删除(见数据删除)。
撤销授权:除在 Roundluck 内解绑外,你可随时通过 Google 安全设置页 https://security.google.com/settings/security/permissions 撤销 Roundluck 对你 Google 数据的访问权限。
10.2 TikTok 数据
企业绑定 TikTok 账号时,我们仅访问用于显示"当前绑定了哪个账号"的基础资料(open id、昵称、头像),且仅将企业明确提交的内容发布到该企业自己的 TikTok 账号。企业解绑或提出请求时,存储的 TikTok 访问令牌将被删除。
10.3 LinkedIn 数据
企业绑定 LinkedIn 账号或公司主页时,我们仅访问用于识别"内容将发布到哪个账号/主页"所必需的信息,且仅将企业明确提交的内容发布到该企业自己的 LinkedIn 个人主页或公司主页。依照 LinkedIn API 使用条款,我们不会将 LinkedIn 会员资料数据(如姓名、头像)保留超过 24 小时,也不会将会员社交行为数据保留超过 48 小时;我们的记录中仅保存所绑定账号的 LinkedIn 标识符(URN)与代企业发布所需的访问令牌。我们不会将 LinkedIn 数据用于广告投放、用户画像、转售,也不会据此建立任何独立的会员数据库。企业解绑或提出请求时,存储的 LinkedIn 访问令牌将被删除;企业亦可随时在其 LinkedIn 账号设置中撤销我们的访问权限。
11. 儿童
本服务是面向组织的商业工具,并非面向儿童。我们不会在明知的情况下收集儿童的个人数据。若您认为儿童向我们提供了个人数据,请与我们联系以便删除。
12. 跨境传输
我们在全球范围内运营,数据可能在您所在国家/地区以外被处理,包括我们的子处理方所在地。在法律要求时,我们会对此类传输采取适当的保护措施。
13. 政策变更
我们可能不时更新本隐私政策。我们将在此处发布更新后的版本并修订上方的生效日期。重大变更将以适当方式告知。更新后您继续使用本服务,即表示接受修订后的政策。