Last Updated / 最后更新: August 21, 2026 / 2026 年 8 月 21 日

Platform Operator / 运营主体: Ronghe International / 嵘禾国际

This Privacy Policy explains how Tinplate Community (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you use the Tinplate Community website and services (the “Platform”). By accessing or using the Platform, you agree to the collection and use of information in accordance with this policy.
本隐私政策说明了马口铁社区(以下简称”我们”)在您使用马口铁社区网站及服务(以下简称”本平台”)时,如何收集、使用、存储和保护您的个人信息。访问或使用本平台,即表示您同意按照本政策规定收集和使用信息。


1. Information We Collect / 我们收集的信息

1.1 Minimum Necessary Collection / 最小必要收集原则

We collect only the information directly necessary for providing our core services. We do not collect any personal information unrelated to the operation of the Platform.
我们仅收集与提供平台核心服务直接相关的必要信息,不收集任何与服务运行无关的个人信息。

1.2 Account Registration / 注册账号时收集

When you register as a Publisher, we collect:

  • Username
  • Company name
  • Email address
  • Password (encrypted and never stored in plain text)

当您注册成为发布者时,我们收集:

  • 用户名
  • 公司名称
  • 邮箱地址
  • 密码(加密存储,永不以明文形式保存)

1.3 Contact Publisher Submissions / 联系发布者表单提交

When you submit a “Contact Publisher” inquiry form, whether as a visitor or logged-in user, we collect:

  • Your full name
  • Company name
  • Email address
  • Phone number (optional)
  • Country / Region (optional)
  • Inquiry message content
  • Stock IDs or content references associated with your inquiry

当您以访客或登录用户身份提交”联系发布者”询盘表单时,我们收集:

  • 您的姓名
  • 公司名称
  • 邮箱地址
  • 联系电话(选填)
  • 国家 / 地区(选填)
  • 留言正文内容
  • 您询盘所关联的现货编号或内容引用信息

1.4 Publishing Content / 发布内容时收集

When you publish Supply or Demand content (structured or non-structured), we collect product specifications, company location fields, and any rich-text notes you provide. These are displayed as business information per the Platform’s content visibility rules.
当您发布供应或需求内容(结构化或非结构化)时,我们收集产品规格、所在地区字段以及您填写的富文本说明。这些信息按照平台的内容可见规则作为业务信息公开展示。

1.5 Security Audit Logs / 安全审计日志

For security and compliance purposes, every critical business operation records the following information in an immutable audit log:

  • User ID (if logged in)
  • User role
  • Action type
  • Precise timestamp
  • Client IP address
  • Operation context and parameters

出于安全与合规目的,每一次关键业务操作均会写入不可篡改的审计日志,记录以下信息:

  • 用户 ID(若已登录)
  • 用户角色
  • 操作类型
  • 精确时间戳
  • 客户端 IP 地址
  • 操作上下文与参数

Audit logs are retained for a maximum of 90 days and then automatically purged via scheduled cron task. Logged IP addresses are used exclusively for security incident traceback and anomaly detection — they are never used for user profiling, behavioral advertising, or business analytics.
审计日志最长保留 90 天,到期后通过定时任务自动清理。日志中记录的 IP 地址仅用于安全事件追溯与异常排查,绝不用于用户画像、行为广告投放或商业分析。


2. Information Visibility and Display / 信息可见性与展示规则

2.1 Contact Information is Not Publicly Listed / 联系方式不在公开页面批量展示

Your sensitive contact information (personal email address, mobile phone number, private WeChat etc.) is never displayed in bulk on the Platform’s four public listing pages. Only business-relevant information necessary for product discovery (company name, product specifications, quality level, location, publishing timestamp) is shown publicly.
您的敏感联系方式(个人邮箱、手机号码、私人微信等)绝不会在平台四页公开列表中批量展示。公开展示的仅为与产品检索直接相关的必要业务信息:企业名称、产品规格、质量等级、所在地区、发布时间。

2.2 Controlled Disclosure via Contact Forms / 联系表单主动提交后定向披露

Contact information flows through a controlled, single-entry pipeline: when you actively submit a “Contact Publisher” form, the contact details you voluntarily provide are delivered exclusively — and in full — to the specific Publisher you are contacting. Disclosure is at the discretion of the initiating party: “who initiates contact, who voluntarily discloses their identity.”
联系方式通过受控的单一路径流转:当您主动填写”联系发布者”表单并提交时,您主动提供的联系信息会完整、定向、非脱敏地送达您所联系的那一位发布者,不会扩散给其他任何第三方。信息披露的主动权在发起方手中:“谁主张联系,谁主动披露身份”。

2.3 Post-Session Mutual Visibility / 会话建立后双向可见

Once an inquiry session is established in the Publisher’s Inbox, both parties to the conversation may view each other’s submitted contact details to enable efficient direct business communication. This follows standard B2B matchmaking practice to build trust and reduce communication friction.
询盘会话在发布者收件箱建立后,沟通双方的身份信息(姓名、公司、已验证邮箱)均以非脱敏形式互相可见,便于高效直接沟通。这一做法遵循 B2B 行业撮合对接的通用惯例,以建立商业信任并降低沟通成本。

2.4 Email Verification Status Markers / 邮箱验证状态标识

Every inquiry record carries an email_verified flag. Inquiries initiated by logged-in Publishers who have completed email verification are automatically marked as verified; those initiated by unauthenticated visitors are marked as unverified. This marker is displayed in the receiving Publisher’s Inbox to help distinguish the reliability of the contact and reduce the risk of email impersonation.
每条询盘记录均带有 email_verified 验证状态标记。已登录且完成邮箱验证的发布者发起的联系自动标记为”已验证”,访客未验证邮箱发起的联系标记为”未验证”,接收方收件箱中会显著显示此标识,帮助判断沟通可信度、降低邮箱假冒风险。


3. Data Retention and Account Lifecycle / 数据保留期限与账号生命周期

  1. Publisher accounts rejected during approval: Accounts are soft-deleted (role downgraded to Subscriber, status flag tp_approved = -1, timestamp tp_rejected_at recorded) and retained for a 30-day appeal period before permanent cleanup eligibility begins.

被拒绝审批的发布者账号:采用软删除处理(角色降级为订阅者,审批状态标 tp_approved = -1,记录 tp_rejected_at 时间戳),保留 30 天申诉期,期满后方可进入永久清理。

  1. Closed inquiry sessions: Once an inquiry is closed, messages within that session are preserved for compliance and dispute resolution reference, but are marked read-only. New follow-up contacts after session closure must be initiated as a new inquiry rather than appended to the closed session.

已关闭的询盘会话:询盘关闭后,会话内消息保留用于合规审计与纠纷处理参考,但标记为只读不可追加。关闭后的后续联系必须发起新询盘,不得追加到旧会话。

  1. Audit logs: Automatically deleted 90 days after creation via scheduled daily cleanup cron.

审计日志:创建满 90 天后,通过每日定时清理任务自动删除。

  1. User profile self-service: Publishers may view, edit, or update their company information, contact email, phone, and location fields at any time via the Publisher Dashboard → Profile page.

个人资料自助管理:发布者可随时通过发布者工作台 → 个人资料页查看、编辑或更新自己的企业信息、联系邮箱、电话、地区字段。

  1. Data reassignment on user deletion: When a WordPress user account is permanently deleted via the WordPress Users admin, the Platform automatically reassigns all associated fields (publisher_user_id, moderated_by, inquiry ownership, and message authorship) across all 8+ business tables to a designated reassigned user ID, preventing orphaned records and preserving data integrity.

删除用户时的数据重新分配:当通过 WordPress 后台永久删除一个用户账号时,平台会自动将 8+ 张业务表中所有关联字段(发布者 ID、审核人 ID、询盘归属人、消息发送人)重新分配到指定的接管用户 ID,避免悬垂数据并保障数据完整性。

  1. “Right to Erasure” requests: Registered users may submit a data deletion request via the Platform contact email. We will respond within 15 business days and confirm when deletion is complete. Certain records required by applicable law or legitimate compliance obligations (e.g., audit logs within retention windows, completed contract records) may be retained until those obligations expire.

“删除权”请求:注册用户可通过平台联系邮箱提交数据删除请求。我们将在 15 个工作日内响应并在删除完成时通知您。依据适用法律或合法合规义务必须保留的特定记录(如保留期内的审计日志、已完成合同记录等),将在相关义务到期后方可删除。


4. Children’s Privacy / 未成年人隐私

The Platform is intended exclusively for use by businesses and industry professionals and is not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will promptly delete that information.
本平台面向企业与行业专业人士运营,不面向 16 周岁以下(或您所在司法辖区数字同意适用年龄以下)的未成年人。我们不会故意收集未成年人的个人信息。若您认为我们收集了未成年人信息,请联系我们,我们将立即删除相关数据。


5. Cross-Border Data Transfers / 跨境数据传输

The Tinplate Community serves a global tinplate ecosystem and our primary infrastructure is hosted in [请填入服务器所在国家/地区, e.g., Singapore / Singapore]. If you are accessing the Platform from a jurisdiction with data localization requirements, please be aware that your information may be transferred to, stored, and processed in our host jurisdiction. We rely on recognized transfer mechanisms (standard contractual clauses where required) to ensure your data receives an equivalent level of protection.
马口铁社区服务于全球马口铁生态圈,平台主基础设施托管于 [请填入服务器所在国家/地区,例如:新加坡 / Singapore]。若您所在司法辖区有数据本地化要求,请注意您的信息可能会被传输、存储并处理至托管地司法辖区。我们依托业界公认的跨境传输机制(适用时签署标准合同条款)确保您的数据获得等效保护水平。


6. Changes to This Privacy Policy / 隐私政策变更

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Material changes will be notified via prominent notice on the Platform login and register pages at least 7 days prior to the effective date, and the “Last Updated” date at the top of this page will be revised accordingly. Your continued use of the Platform after the effective date of the revised policy constitutes your acceptance of the changes.
我们可能会不时更新本隐私政策,以反映业务实践的变化或出于法律、运营、合规要求。实质性变更将在生效日前至少 7 天,于平台登录页与注册页显著位置通知用户;本页顶部”最后更新”日期也会同步更新。您在修订政策生效日后继续使用本平台,即视为您接受变更内容。


7. Contact Us / 联系我们

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your legal rights regarding your personal information, please contact our Data Protection Officer at:
若您对本隐私政策、数据处理方式有任何疑问,或希望行使关于您个人信息的法定权利,请通过以下邮箱联系我们的数据保护专员:

📧 Email / 邮箱: [email protected]
🏢 Data Controller / 数据控制者: Ronghe International / 嵘禾国际



Data Use Policy / 数据合理化使用说明

Platform Operator / 运营主体: Ronghe International / 嵘禾国际

This document complements the Privacy Policy and sets out the specific principles under which the Tinplate Community processes user data.
本文档是隐私政策的补充说明,明确马口铁社区处理用户数据的具体原则与边界。


1. Scope of Data Use / 使用范围——仅限平台核心功能

All user information collected by the Platform is used exclusively for the operation of the following core Platform services. It is never sold, rented, traded, or shared with any third party unrelated to the delivery of these core services.
平台收集的所有用户信息仅用于以下核心服务功能的正常运行。绝不会出售、出租、交易或共享给任何与提供核心服务无关的第三方。

Use Case / 使用场景Description / 说明
Content Publishing and Display / 供需内容发布与展示Structured product specifications, quality levels, location and rich-text notes are displayed on the four public supply/demand pages for matching purposes. 结构化产品规格、质量等级、地区字段、富文本说明用于四页公开供需列表页展示与匹配对接。
Inquiry Communication / 询盘沟通对接Contact publisher submissions are delivered to the targeted Publisher, enabling two-way communication via the Platform Inbox and email notification channels. 联系发布者表单提交内容定向送达目标发布者,通过平台收件箱与邮件通知两个渠道实现双向沟通。
Moderation and Approvals / 内容审核与用户审批Publisher registration applications, submitted supply, and submitted demand content are presented to TPP Managers for moderation decision-making. 发布者注册申请、供应与需求提交内容,展示给 TPP 管理员用于审核与审批决策。
Security Risk Control / 安全风控Audit logs, moderation status, and email verification flags are used to prevent unauthorized access, detect malicious account registration, identify impersonation attempts, and mitigate spam or fraud. 审计日志、审核状态、邮箱验证标记用于防止未授权访问、识别恶意注册、侦测身份冒用、防范垃圾邮件与欺诈行为。
Compliance Audit and Dispute Handling / 合规审计与纠纷处理Retained inquiry records and audit trails are used to respond to lawful data subject access requests or resolve disputes arising from published content and communications. 保留的询盘记录与审计追踪数据,用于响应合法的数据主体访问请求或解决因发布内容与沟通引发的纠纷。
Aggregated Platform Analytics / 平台级聚合统计TPP Manager Dashboard displays user registration counts, publish counts, contact event volumes, user activity rankings, and publish failure anomaly metrics. All such analytics are produced in de-identified, aggregated form and do not expose individual user sensitive attributes. 管理端仪表盘展示用户注册量、内容发布量、联系事件量、用户活跃度排行、发布失败异常指标等数据。所有统计均采用脱敏、聚合形式,不暴露单用户敏感信息。

2. CRM Synchronization Scope / 客户关系管理(CRM)系统同步范围

When a Contact Publisher submission is successfully processed, the Platform performs a limited synchronization to Jetpack CRM (via TPP_CRM_Bridge::sync_to_jetpack_crm) to enable the Platform operator to follow up on inquiries and provide service continuity.
联系发布者表单处理成功后,平台会将有限范围的字段同步至 Jetpack CRM 系统(通过 TPP_CRM_Bridge::sync_to_jetpack_crm 执行),供平台运营方跟进询盘、保障服务连续性。

The synchronized data is limited to:

  • Inquirer name
  • Inquirer email
  • Company name
  • Phone number (if provided)
  • Country / Region (if provided)
  • A copy of the inquiry message
  • Basic metadata (inquiry ID, associated content reference, creation timestamp)

同步范围仅限:

  • 咨询人姓名
  • 咨询人邮箱
  • 公司名称
  • 联系电话(如填写)
  • 国家/地区(如填写)
  • 询盘留言正文副本
  • 基本元数据(询盘编号、关联内容引用编号、创建时间戳)

This data is used exclusively by Ronghe International for Platform customer service operations and is never transmitted onward to any unrelated third party, advertisers, brokers, or data brokers.
上述数据仅由嵘禾国际用于平台客户服务运营,绝不进一步转发给任何无关第三方、广告商、中间商或数据掮客。


3. Principle of Informed Consent for Extended Usage / 超出范围使用的知情同意原则

Any data processing use case not explicitly listed in Section 1 (Core Services) or Section 2 (CRM Sync) above — including but not limited to marketing email campaigns, advertising targeting, cross-platform user profiling, and data monetization partnerships — will be explicitly disclosed to you in a clear, standalone notice. We will obtain your explicit, opt-in consent before such processing begins, and you will retain the full right to withdraw your consent at any time without detriment.
任何未在上述第 1 节(核心服务)与第 2 节(CRM 同步)明确列明的数据使用场景——包括但不限于营销邮件群发、广告投放定向、跨平台用户画像、数据变现合作——均会以清晰、独立的告知形式向您单独说明,并在处理开始前取得您的明示同意(opt-in),且您保留随时以不受歧视的方式撤回同意的完整权利。


4. Data Minimization and Purpose Limitation / 数据最小化与目的限定

We adhere strictly to the principles of data minimization and purpose limitation, as defined under the General Data Protection Regulation (GDPR), the Personal Information Protection Law of the People’s Republic of China (PIPL), and the California Consumer Privacy Act (CCPA):
我们严格遵循欧盟 GDPR、中华人民共和国《个人信息保护法》(PIPL)及加州 CCPA 规定的数据最小化与目的限定两大原则:

  1. Minimum Necessary: No data field is collected “just in case” or for speculative future use. Every data field collected has a specific, documented purpose and is validated server-side.

最小必要:绝不为了”以防万一”或猜测未来可能用到而收集字段。每一个收集到的数据字段都有明确的、已文档化的使用目的,并在服务端接受校验。

  1. Purpose Lock: Data collected for one purpose is never repurposed for a secondary, incompatible processing purpose without a new legal basis and fresh informed consent.

目的锁定:为某一目的收集的数据,在未取得新的合法基础与新的知情同意前,绝不会被挪用于另一项性质不同的处理目的。

  1. No Secondary Sale or Monetization: Platform revenue comes from Platform operator activities, not from the resale or licensing of user data. There is no business model, pipeline, or partnership in place that monetizes personal information collected by this Platform.

绝不二次售卖或变现:平台收入来源于平台运营者的自有运营活动,绝不来源于用户数据的转售或授权许可。不存在任何以本平台收集的个人信息为变现手段的商业模式、数据流转管道或商务合作。


5. Your Rights / 您的权利

Depending on your jurisdiction, you may have the following rights regarding your personal information, which you may exercise free of charge and without discriminatory effect:
根据您所在司法辖区的适用法律,您对自己的个人信息享有以下权利,您可免费且不受歧视地行使:

Right / 权利Description / 说明
Right of Access / 知情权Obtain confirmation of whether we process your data and receive a copy of the personal data we hold about you. 确认我们是否处理您的数据,并获取我们持有的您个人信息的副本。
Right to Rectification / 更正权Request correction of any inaccurate or incomplete personal information we hold about you (also available self-service via the Publisher Dashboard → Profile page). 请求更正我们持有的任何不准确或不完整的个人信息(也可通过发布者工作台 → 个人资料页自助完成)。
Right to Erasure (Right to be Forgotten) / 删除权(被遗忘权)Request deletion of your personal information subject to applicable legal retention periods. 依据适用的数据保留期限,请求删除您的个人信息。
Right to Restrict Processing / 限制处理权Request that we suspend processing of your personal information under specific circumstances. 在特定情形下请求我们暂停处理您的个人信息。
Right to Data Portability / 可携带权Request export of personal information you provided to us in a structured, commonly used, and machine-readable format. 请求将您提供给我们的个人信息,以结构化、通用、机器可读的格式导出。
Right to Object to Processing / 拒绝处理权Object to specific processing of your personal information on grounds relating to your particular situation. 基于您的特定情形,拒绝对您个人信息的特定处理行为。
Right to Withdraw Consent / 撤回同意权Withdraw any consent previously granted to specific processing at any time. 随时撤回之前对特定数据处理行为给予的同意。
Right to Lodge a Complaint / 投诉权Lodge a complaint with your local data protection supervisory authority if you believe our processing violates applicable law. 若认为我们的数据处理行为违反适用法律,可向当地数据保护监管机构投诉。

To exercise any of the above rights, please contact: [email protected]. We will respond to valid requests within 15 business days.
行使以上任何权利,请发送邮件至:[email protected]。我们将在 15 个工作日内回应合法的请求。


6. Contact / 联系方式

For questions about this Data Use Policy or any data processing matter:
对本数据合理化使用政策或任何数据处理事宜有疑问,请联系:

📧 [email protected]
🏢 Ronghe International / 嵘禾国际
🌐 Operator of Tinplate Community / 马口铁社区运营主体