This page is an English translation of the Chinese original. In case of any discrepancy, the Chinese version shall prevail.
GroupGoods Platform Privacy Policy
Effective: 26 April 2026 · Last updated: 11 August 2026
Publisher and operator
Platform operator: Kaituan Youhuo (Hangzhou) Biotechnology Co., Ltd. operates the GroupGoods platform and is the controller of the personal information described in this policy.
Google Play publisher: Group Goods Limited publishes the GroupGoods Android app on Google Play as the listed developer. Personal information collected through the app installed from Google Play is still processed by the platform operator in accordance with this policy.
For all other channels — Apple App Store, Huawei AppGallery, Chinese Android app stores, the website and the desktop clients — the platform operator is both publisher and operator.
Introduction
Kaituan Youhuo (Hangzhou) Biotechnology Co., Ltd. (“GroupGoods”, “we” or “us”) understands how important your personal information is to you. We comply with the Personal Information Protection Law, the Cybersecurity Law and the Data Security Law of the People’s Republic of China, as well as other applicable laws and regulations, and are committed to keeping your personal information secure.
This policy applies to your use of the GroupGoods website, iOS app, Android apps, HarmonyOS app, desktop clients and other official channels. Please read and understand it before using our services; by continuing to use them you agree that we may process your personal information as described here.
Clauses shown in bold have a material effect on your rights. Please read them carefully.
1. Personal information we collect
Following the principle of minimum necessity, we collect only what is required to provide our services:
1.1 Registration and sign-in.Mobile phone number and verification code. Merchant users additionally provide company name, unified social credit code, business licence, the legal representative’s name and ID number, and contact details.
1.2 Sourcing and communication. Chat messages exchanged with merchants, favourites and follows, browsing and search history, and download records.
1.3 Device and log information. Device model, operating system version, app version, IP address, network type, access time and client type (iOS / Android / HarmonyOS / Web / desktop), used for service operation, security auditing and troubleshooting. We do not use device identifiers for cross-app tracking unrelated to this platform. After you accept this policy, the iOS app and the Chinese-mainland Android app report conversion events such as launch, registration and sign-in, together with the necessary device and network information, through the Tencent Ads conversion SDK (DataNexus), solely for attribution and performance measurement of advertising we have purchased. The Google Play version of the Android app contains no advertising or attribution SDK. HarmonyOS signed releases use the system AppGallery Kit attribution service to register activation, launch, registration and sign-in event codes on-device; no GroupGoods user_id, phone number, chat content or device identifier is transmitted to that service (see section 8). The JPush SDK bundled with the Chinese-mainland Android app collects device identifiers in order to generate a push registration ID. The HarmonyOS app obtains a push token through the system HarmonyOS Push Kit and reports redacted runtime, network-error and crash diagnostics to our self-hosted Seq service (see section 8).
1.4 Location.When you use the “Nearby” feature we obtain your device’s location after your explicit consent, solely to find nearby cluster merchants and products. The accuracy requested differs by client: the Android apps request precise location permissionand read the position using the system’s balanced-power strategy (typically accurate to within a few hundred metres); on Android 12 and above you may choose to grant approximate location only. The iOS app requests kilometre-level accuracy only, and the HarmonyOS app requests the approximate-location permission. We do not store your location history, and you can turn the permission off in your system settings at any time. On the Google Play version of the Android app this location is obtained through Google Play services Location.
1.5 Camera and photo library. When you publish a product, search by image or upload verification documents, we request camera or photo library access and use it only for the action you initiated.
1.6 Contacts. We do not collect your address book.
2. How we use personal information
- To complete account registration, sign-in and identity verification;
- To provide core features such as browsing, search, favourites, follows, chat and order matching;
- To provide personalised recommendations based on your browsing and interaction behaviour (you can turn personalised recommendations off in Settings);
- To operate risk control, anti-fraud, anti-abuse and prohibited-content detection;
- To provide customer support and handle your enquiries and complaints;
- To meet obligations imposed by law and regulation (for example cooperating with regulatory inspections and retaining logs).
3. Sharing, transfer and disclosure
We do not sell your personal information. We disclose it only in the following circumstances:
3.1 With your explicit consent. For example, when you share your profile page to a third-party social platform.
3.2 Necessary service providers. To deliver core platform services we entrust the minimum necessary information to the providers below, and bind them by contract to confidentiality and security obligations:
- Alibaba Cloud SMS (DySMS): sends registration / sign-in verification codes; processes phone number and sending IP;
- Alibaba Cloud DirectMail: sends email verification codes; processes email address and sending IP;
- Alibaba Cloud Object Storage (OSS) + CDN: stores and delivers the product images, videos and avatars you upload;
- Alibaba Cloud image recognition: de-duplicates product model photos; processes feature vectors of the uploaded images;
- Amap Open Platform: resolves place names you enter into coordinates, used to find nearby merchants;
- Google Play services Location (Google Play version of the Android app only): provides the device’s location on-device, used to find nearby merchants;
- WeChat Open Platform (OAuth): when you choose WeChat sign-in, processes openid, unionid, nickname and avatar;
- Alipay in-app payment: when you choose Alipay, processes payment order information and the necessary device information;
- WeChat Pay: when you choose WeChat Pay, processes payment order information and the necessary device information;
- Sign in with Apple: when you choose Apple sign-in, processes the private relay email address from your Apple ID;
- Tencent Ads (DataNexus conversion SDK): used solely for attribution and performance measurement of advertising we have purchased; processes launch, registration and sign-in conversion events together with the necessary device and network information;
- HarmonyOS AppGallery Kit attribution service: only on HarmonyOS signed releases and after you accept this policy, registers activation, launch, registration and sign-in event codes, matched on-device by the system attribution policy; no GroupGoods user_id, phone number, chat content or device identifier is transmitted;
- Google Vertex AI / Gemini and OpenAI: only when you actively use features such as “AI Design” and “Smart Search”; processes the text prompts and images you submit in order to generate results;
- LangSmith and Seq: used for server-side logging, AI trace analysis and client crash diagnostics; processes technical logs such as request_id, user_id, app version and error type. After you accept this policy the HarmonyOS app reports redacted runtime, network-error and crash diagnostics to Seq; it does not transmit your chat content, verification codes, access tokens or personal identifiers in clear text.
3.3 Merchant matching. When you contact a merchant or favourite their products, we show the merchant your nickname, avatar and chat messages. We do not give merchants your phone number, delivery address or other sensitive information unless you disclose it yourself.
3.4 Legal requirements. Where required by law or regulation, by litigation or arbitration, or by a lawful request from an administrative or judicial authority.
4. Cookies and similar technologies
We store cookies and LocalStorage in your browser to keep the website working, remember your sign-in state and understand how the service is used. You may refuse or delete cookies through your browser settings, though some features may then not work properly.
5. Storage and protection of personal information
5.1 Storage location.Your personal information is stored in data centres within the People’s Republic of China. Where a cross-border transfer is genuinely required, we will complete the security assessment or standard contract formalities required by law and obtain your separate consent.
5.2 Retention period. We retain your personal information only for the shortest period necessary to achieve the purposes described in this policy: it is retained while your account is active; after account deletion we anonymise or delete it within 30 days, except for logs we are required by law to keep.
5.3 Security measures. We protect your personal information with HTTPS transport encryption, encrypted storage of sensitive fields, tiered access control, least-privilege authorisation, security auditing and regular penetration testing.
5.4 Security incidents. In the event of a personal information security incident we will promptly inform you, as required by law, of the nature of the incident, its likely impact, the measures we have taken and the steps you can take to protect yourself, and we will report it to the competent authorities.
6. Your rights
Under applicable law you have the following rights over your personal information:
- Access and portability: view and export the personal information you submitted, under “Me → Settings” in the app or on the website;
- Correction: if information is inaccurate or incomplete you can amend it yourself or ask customer support to correct it;
- Deletion: where the statutory conditions are met (for example withdrawal of consent or termination of service) you may request deletion of your personal information;
- Withdrawal of consent: you can revoke individual permissions such as camera, location and notifications, or turn off personalised recommendations in Settings;
- Account deletion: submit a deletion request under “Me → Settings → Account & Security”, or see Account and data deletion;
- Complaints: if you believe our processing infringes your rights, contact us using the details at the end of this policy, or complain to the competent authority.
We respond to such requests within 15 working days of receipt.
7. Children's personal information
GroupGoods is a B2B wholesale platform for business users. We do not target children under 14, and we do not design features, content or campaigns aimed at children. If a child needs to browse or use the platform under supervision, their guardian should read this policy carefully and consent on their behalf.
When a child uses the platform, features such as sign-in, product browsing, search, favourites, follows, chat enquiries, customer support, risk control and complaint handling may collect and use the child’s phone number, nickname, avatar, chat messages, browsing and search history, favourites and follows, device and log information, camera or photo library uploads, and location (if the child grants the “Nearby” permission).We process children’s personal information only to deliver those features, to keep accounts and transactions secure and to meet our legal obligations. We never use it for marketing or cross-app tracking unrelated to those purposes.
We protect children’s personal information with encrypted transport, access control, least-privilege authorisation and security auditing. We do not share, transfer or publicly disclose it to third parties except where the law provides otherwise, where a judicial or administrative authority lawfully requires it, where it is necessary to perform a statutory duty, or with the guardian’s explicit consent.
A guardian may use the contact details at the end of this policy to access, copy, correct or delete a child’s personal information, or to withdraw consent to its processing. After verifying the guardian’s identity and relationship to the child, we respond within 15 working days. If we find that we have collected a child’s personal information without a guardian’s consent, we delete or anonymise it as soon as possible.
8. Third-party SDKs
To provide sign-in, payment, social sharing, push notifications, location and advertising attribution, our clients integrate the third-party SDKs listed below. Their collection and processing of personal information is governed by their own privacy policies. Each SDK is bundled only in the clients listed under “Applies to”:
| SDK | Provider | Applies to | Purpose | Information collected | Privacy policy |
|---|---|---|---|---|---|
| WeChat OpenSDK Android (com.tencent.mm.opensdk; iOS counterpart) and HarmonyOS WeChat OpenSDK | Shenzhen Tencent Computer Systems Co., Ltd. | iOS, Android (Chinese mainland), HarmonyOS | WeChat sign-in, WeChat Pay, sharing to WeChat | WeChat openid / unionid / nickname / avatar, device model and OS version, network information; the Android build may also process the Android ID | View |
| Alipay in-app payment SDK (com.alipay.sdk) | Alipay (Hangzhou) Information Technology Co., Ltd. | iOS, Android (including the Google Play version) | Alipay payment (wallet top-up and other payment flows) and payment risk control | Payment order information, device identifiers (Android ID / OAID), device model and OS version, network information (IP address, network type, Wi-Fi state) | View |
| JPush SDK for Android (cn.jpush.android) | Shenzhen Hexun Huagu Information Technology Co., Ltd. | Android (Chinese mainland) only | Push notifications for enquiry replies and order status | Device identifiers (Android ID), device model and OS version, network information, push registration ID | View |
| HarmonyOS Push Kit | Huawei Software Technologies Co., Ltd. | HarmonyOS only | Push notifications for enquiry replies and order status | App package name, device model and OS version, network information, push token | View |
| Tencent Ads conversion SDK for Android (com.qq.gdt.action / DataNexus, plus its iOS counterpart) | Shenzhen Tencent Computer Systems Co., Ltd. | iOS, Android (Chinese mainland) | Advertising conversion attribution and performance measurement | Launch, registration and sign-in conversion events; device identifiers, device model and OS version, network information | View |
| AppGallery Kit attribution service | Huawei Software Technologies Co., Ltd. | HarmonyOS signed releases only | On-device conversion attribution for advertising we have purchased | Activation, launch, registration and sign-in event codes; contains no GroupGoods user_id, phone number, chat content or device identifier | View |
| Apple AuthenticationServices | Apple Inc. | iOS only | Sign in with Apple | Apple ID private relay email, optional name | View |
| Google Play services (Location, com.google.android.gms:play-services-location) | Google LLC | Android (Google Play version) only | Obtains the device’s location, with your permission, for the “Nearby” feature | Device location (read with the balanced-power strategy, typically within a few hundred metres), device model and OS version, network information | View |
| Alibaba Cloud OSS SDK | Alibaba Cloud Computing Co., Ltd. | All clients | Direct upload of product images, videos and avatars from the client | The images and videos you upload, device network information | View |
The JPush SDK and HarmonyOS Push Kit initialise only after you accept this policy and only while you have a signed-in session; they are used solely to deliver notifications, never for advertising or profiling. The Tencent Ads conversion SDK initialises only after you accept this policy and is used solely for attribution and performance measurement of advertising we have purchased — never for on-platform recommendations, buyer profiling or selling data to merchants. Alipay and WeChat SDKs are invoked only when you actively start a payment, sign-in or sharing action. Google Play services Location is invoked only when you have granted the location permission and are using the “Nearby” feature. The Google Play version of the Android app bundles no WeChat SDK, no JPush SDK and no advertising or attribution SDK, and offers no in-app self-update. Apart from the Tencent Ads conversion SDK named above, we integrate no other third-party advertising, analytics, profiling or cross-app tracking SDK (Firebase Analytics, Umeng, Google Ads and Mixpanel are all absent).
9. Changes to this policy
We may update this policy in response to changes in law, regulatory requirements or our business. Updated versions are published in a prominent place on the platform with the revision date. For changes that materially affect your rights we will notify you prominently, for example by in-app message or push notification.
10. Contact us
If you have questions, comments or complaints about this policy or about how we handle personal information, please contact us:
- Platform operator: Kaituan Youhuo (Hangzhou) Biotechnology Co., Ltd.
- Registered address: Room 2109, 1888 Jianghui Road, Changhe Subdistrict, Binjiang District, Hangzhou, Zhejiang, China
- Unified social credit code: 91330108MA2H3XC84R
- Mobile app filing number: 浙ICP备2020031019号-3A
- Customer service: +86-0312-2815168
- Google Play publisher: Group Goods Limited