本政策说明 Global Fact Hub(以下简称「我们」)在你使用我们的网站、客户门户与各项服务时,如何收集、使用、存储、共享与删除你的信息。我们只收集为提供服务所必需的信息,并且不会把你委托给我们的数据用于与提供服务无关的目的。
一、我们收集哪些信息
1. 你主动提供的信息
- 账户信息:注册邮箱、密码(以不可逆哈希形式存储,我们无法看到原始密码)。
- 订单与交付信息:所购服务、金额、币种、下单时填写的品牌名称、官网地址、目标国家、行业与产品、监测关键词等。
- 业务事实材料:你提供的品牌事实(公司信息、产品参数、资质、案例、目标市场)及其出处链接。这些材料仅用于生成经你确认的内容。
- 沟通内容:你通过邮件、表单或 WhatsApp 与我们沟通的内容。
2. 服务运行中自动产生的信息
- 访问日志:IP 地址、浏览器标识(User-Agent)、访问时间与路径,用于安全防护、限流与故障排查。
- 监测与报告数据:我们按你的指令向第三方 AI 搜索服务发起查询,并记录返回的回答与引用来源,用于生成可见度报告。
- 网站线索追踪数据(仅在你主动部署埋点后):我们在你的官网上提供一段接入代码,用于统计页面访问、按钮点击与表单提交,并记录来源页面(referrer)、UTM 参数、落地页与提交时间,以便你判断询盘来源。这些数据归你所有,仅你在门户中可见。
3. 支付信息
支付通过第三方渠道(PayPal 或收款码)完成。我们不接收也不存储你的银行卡号、CVV 或完整支付凭证,仅保存交易号、金额、币种与支付状态。
二、来自 Google 的数据(Google Business Profile)
2.1 我们请求的授权范围
当你主动点击「授权 Google 商家」时,我们请求以下唯一一个权限范围:
https://www.googleapis.com/auth/business.manage
我们不会请求或访问 Gmail、Google Drive、Google 日历、通讯录、位置历史、Google Photos 或任何其他 Google 服务的数据。
2.2 我们访问的 Google 数据
仅限你自己名下、且你有权管理的 Google 商家资料(Business Profile)中的商业信息,例如:商家名称、地址、电话号码、官方网站、营业分类、商家简介,以及代表你更新这些字段所需的权限。
2.3 我们如何使用这些数据
- 列出你授权账号名下的商家条目,供你在门户中确认「授权的是哪一家」;
- 在你主动点击「自动更新」后,使用你已确认的定位与卖点文案,更新该商家的标题、简介与标签。
我们不会:创建或验证商家条目、修改你未确认的内容、编造地址或评分评论、读取你的个人 Google 账号资料。
2.4 存储与共享
- 存储:OAuth 访问令牌与刷新令牌保存在我们的服务器上,仅服务进程可读,且不对公网暴露(相关目录已禁止外部访问)。我们不存储你的 Google 账号密码。
- 不共享:我们不与任何第三方共享、出售或转让从 Google API 获取的数据。
- 不用于广告与 AI 训练:不用于广告投放或定向、不出售给数据经纪商、不用于训练或改进通用人工智能/机器学习模型、不用于信用评估或借贷目的。
- 商家资料数据仅为完成上述展示与更新目的而即时读取,我们不建立独立的长期副本。
2.5 Google API Services User Data Policy 合规声明
Global Fact Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
(译文:Global Fact Hub 对从 Google API 获得的信息的使用及向任何其他应用的传输,将遵守 Google API 服务用户数据政策,包括其中的有限使用要求。)
2.6 保留期限与删除方式
三、我们如何使用信息
- 提供、维护与交付你购买的服务;
- 生成监测报告、内容方案与交付物;
- 账户安全(登录校验、异常登录识别、防暴力破解);
- 就订单、交付与服务变更与你沟通;
- 履行法律义务与解决争议。
我们不会把你的数据出售给第三方,也不会用于与你无关的营销推送。
四、第三方服务
为提供服务,我们使用以下类别的第三方服务,并仅在必要范围内向其传输数据:
- 云主机与数据库(服务器托管、数据存储);
- 支付服务(PayPal 等,处理付款);
- 邮件服务(发送订单确认与报告通知);
- AI 搜索与语言模型服务(执行可见度监测查询、生成内容草稿)。我们不会向这些服务传输你的 Google 授权数据。
向 AI 服务发起的监测查询仅包含公开的品牌名与查询问题,不包含你的个人信息。
五、数据安全
- 全站启用 HTTPS 加密传输;
- 密码以不可逆哈希存储,我们无法读取原始密码;
- 客户数据按账户隔离:每个账户只能访问自己的项目、报告与线索数据;
- 为防暴力破解,登录失败次数受限;日志与异常会记录以便审计;
- 敏感目录(令牌文件、客户报告)禁止公网直接访问,交付物一律通过带鉴权的接口下载。
六、数据保留
- 账户与订单数据:在服务期内及之后为履行法定义务所必需的期间保留;
- 报告与交付物:保留至你要求删除;
- Google 授权令牌:在授权有效期内保留,授权失效或你要求删除时立即删除;
- 访问日志:保留不超过 12 个月。
七、你的权利
你可以随时要求:查阅、更正、导出或删除我们保存的你的个人信息;撤销 Google 授权;注销账户。请发邮件至 business@globalfacthub.com,我们将在 7 个工作日内响应。
八、未成年人
我们的服务面向企业与商业用户,不面向 16 岁以下未成年人,也不会有意收集其个人信息。
九、政策变更
本政策如有更新,我们将修改本页顶部的「最后更新」日期;涉及重大变更时,我们会通过邮件或门户公告另行通知。
十、联系我们
Global Fact Hub · 邮箱:business@globalfacthub.com · 网站:globalfacthub.com
This policy explains how Global Fact Hub ("we", "us") collects, uses, stores, shares and deletes your information when you use our website, client portal and services. We collect only what is necessary to deliver the services you request, and we do not use data entrusted to us for unrelated purposes.
1. Information we collect
1.1 Information you provide
- Account information: email address and password (stored as an irreversible hash; we cannot read your original password).
- Order and delivery information: services purchased, amount, currency, brand name, website URL, target country, industry, product and monitoring keywords you submit.
- Business facts: brand facts you provide (company details, product specifications, certifications, case studies, target markets) and their source links. These are used only to generate content that you confirm.
- Communications: messages you send us by email, forms or WhatsApp.
1.2 Information generated while using the services
- Access logs: IP address, user agent, timestamp and path, used for security, rate limiting and troubleshooting.
- Monitoring data: we send queries to third-party AI search services on your instruction and record the answers and cited sources to produce visibility reports.
- Website lead-tracking data (only if you deploy our snippet): a snippet we provide for your website records page visits, button clicks and form submissions, together with the referring page, UTM parameters, landing page and timestamp, so you can judge where enquiries come from. This data belongs to you and is visible only in your portal.
1.3 Payment information
Payments are processed by third parties (PayPal or payment QR codes). We never receive or store your card number, CVV or full payment credentials — only the transaction reference, amount, currency and payment status.
2. Data received from Google (Google Business Profile)
2.1 Scope we request
When you explicitly click "Authorize Google Business", we request exactly one scope:
https://www.googleapis.com/auth/business.manage
We do not request or access Gmail, Google Drive, Calendar, Contacts, location history, Google Photos or any other Google service data.
2.2 Google data we access
Only the business information in the Google Business Profile(s) that you own and are authorized to manage: business name, address, phone number, website, categories, business description, and the permission required to update those fields on your behalf.
2.3 How we use it
- To list the business locations under the account you authorize, so you can confirm which business is connected;
- To update that business's title, description and labels using the positioning and selling points you have confirmed, and only after you click "Apply".
We never create or verify business listings, never change content you have not confirmed, never fabricate addresses, ratings or reviews, and never read your personal Google account profile.
2.4 Storage and sharing
- Storage: OAuth access and refresh tokens are stored on our server, readable only by the service process and not exposed to the public internet (the relevant path is blocked from external access). We never store your Google password.
- No sharing: we do not share, sell or transfer data obtained from Google APIs to any third party.
- Not for advertising or model training: not used for advertising or retargeting, not sold to data brokers, not used to train or improve generalized AI/ML models, and not used for credit-worthiness or lending purposes.
- Business Profile data is read on demand to fulfil the purposes above; we do not maintain a separate long-term copy.
2.5 Google API Services User Data Policy — Limited Use disclosure
Global Fact Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.6 Retention and deletion
- You can revoke access at any time at myaccount.google.com/permissions — find this app and remove access. We then lose access to your Google data immediately.
- When we detect that an authorization is no longer valid (expired or revoked), we automatically delete the stored token.
- You may also email business@globalfacthub.com to request deletion of the stored token; we will delete it and confirm within 7 business days.
3. How we use information
- To provide, maintain and deliver the services you purchase;
- To generate monitoring reports, content plans and deliverables;
- For account security (login verification, anomaly detection, brute-force protection);
- To communicate with you about orders, deliveries and service changes;
- To comply with legal obligations and resolve disputes.
We do not sell your data to third parties and do not use it for unrelated marketing.
4. Third-party services
- Cloud hosting and database (server hosting and data storage);
- Payment providers (e.g. PayPal) to process payments;
- Email delivery (order confirmations and report notifications);
- AI search and language model services (to run visibility queries and draft content). We do not transmit your Google authorization data to these services.
Monitoring queries contain only public brand names and query questions — no personal information.
5. Data security
- HTTPS encryption in transit across the site;
- Passwords stored as irreversible hashes;
- Per-account data isolation: each account can only access its own projects, reports and lead data;
- Login attempts are rate-limited and logged for audit;
- Sensitive paths (token files, client reports) are blocked from public access; deliverables are served only through authenticated endpoints.
6. Data retention
- Account and order data: for the service period and as long as required to meet legal obligations;
- Reports and deliverables: until you request deletion;
- Google authorization tokens: while the authorization is valid; deleted immediately once it expires, is revoked, or you request deletion;
- Access logs: no longer than 12 months.
7. Your rights
You may request access to, correction of, export of, or deletion of your personal information, revoke Google authorization, or close your account at any time by emailing business@globalfacthub.com. We respond within 7 business days.
8. Children
Our services are intended for businesses and commercial users. They are not directed to children under 16 and we do not knowingly collect their personal information.
9. Changes
If this policy changes we will update the "Last updated" date above; for material changes we will notify you by email or an in-portal notice.
10. Contact
Global Fact Hub · Email: business@globalfacthub.com · Website: globalfacthub.com