1. Who we are and how to contact us
China Travel Companion is operated by 盛欣怡 (Sheng Xinyi), an individual based in Hangzhou, Zhejiang, China ("we", "us"). We operate www.thetravel.cn, a digital guide website for international visitors travelling to China. The operator is the controller / personal information handler responsible for the information processed to operate this website.
For privacy questions or requests, email gochinatravel@hotmail.com with the subject "Privacy request". You can also find this contact through Help & Support.
2. Information we collect
- Account information: when email sign-in is available and you use it, your email address, account identifier, verification-related records and account creation / last sign-in dates. We use email codes, not a password you create with us.
- Access and browser records: registered-browser identifiers, broad browser / operating-system labels, hashed session and browser tokens, registration / activity dates, expiry or revocation records, and account events such as browser removal. These support the two-browser access limit; we do not create a hardware fingerprint.
- Feedback: usefulness rating, what helped, improvement suggestions, optional city and email, submission identifier / date, and your optional permission to feature feedback publicly. Feedback is private by default and is not automatically published.
- Support correspondence: your sender email, message, and any city, location, order reference or screenshot you choose to send. The Help form opens your own email app; filling it in does not upload or send the draft to us. We receive it only if you send the email.
- Technical information: hosting and authentication services can process IP addresses, request / access times, browser information and operational logs. For feedback rate limiting, our application stores a daily-derived keyed hash of the client address, not the raw IP address in the feedback record.
- Order and access information: our account database supports city product identifiers, payment provider / transaction references, amount, currency, purchase date and status, and access grants or revocations. Checkout is not live; this does not mean that every visitor has an order record or that a payment is currently taken.
We do not request your passport, travel booking credentials, bank login, full card number, security code or precise GPS location. Do not include these in feedback or support messages. A location you type in a support email is information you choose to provide, not automatic location tracking.
3. Purposes and legal bases
Where applicable law requires a legal basis, we use the following bases only for the corresponding purpose:
- Providing the service / taking steps at your request: verifying an email, managing your account, restoring purchased city access, delivering digital content and answering service or order questions.
- Security and service improvement: website reliability, prevention of abuse or unauthorised account sharing, troubleshooting and private feedback. We rely on legitimate interests only where recognised by the applicable law and balanced against your rights; otherwise we use the applicable basis, such as your consent, necessary contract performance or a legal obligation. We do not treat legitimate interests as a universal legal basis under Chinese law.
- Consent: optional public use of your feedback. This checkbox is unchecked by default, requires review before publication, and is separate from submitting private feedback. You can withdraw permission by emailing us; this does not affect lawful processing before withdrawal.
- Legal obligations: retaining transaction records where required and handling applicable consumer, tax, fraud-prevention or lawful authority requirements.
We do not use sign-in emails or feedback submissions to enrol you in a marketing mailing list. We do not sell personal information or use it for targeted advertising. We do not make automated decisions determining your travel eligibility; software checks registered browsers and city-access records.
4. Orders and Creem checkout
Creem is our planned checkout provider and Merchant of Record (contractual reseller). Checkout is currently unavailable, so the website does not take a Creem payment or unlock a city through a simulated transaction.
When Creem checkout becomes available, its checkout may collect buyer contact, billing and payment information for payment, receipts, tax and fraud checks. We expect to receive the order information needed to identify your purchased city, verify payment, provide access and handle support or refunds. We do not need your full payment-card details for guide access.
Creem handles transaction-related information under its own Privacy Notice and Buyer Terms. Our Terms of Service explain the separate responsibility for digital-guide delivery. We will update this policy if the final checkout integration changes the data exchanged.
5. Service providers and sharing
- Supabase: account authentication and database storage for application accounts, sessions, browsers, city access, order records and private feedback. See Supabase privacy information.
- Resend: delivery of transactional sign-in code emails through Supabase’s custom email service, including recipient address, message content and delivery records. It is not a newsletter subscription. See Resend’s Privacy Policy.
- Vercel: website hosting and delivery, including request and operational information needed to serve and secure the website. See Vercel’s Privacy Notice.
- Cloudflare: domain DNS management. Our current domain setup uses DNS-only records rather than Cloudflare’s proxied website delivery; we have not added Cloudflare visitor analytics to the application.
- Email services: when you send support email, your email provider and our support mailbox provider process that correspondence.
- Creem: planned transaction and checkout services as described above, not an active payment integration.
Authorised team members access information as needed for service, support and review. Necessary disclosure may also occur to comply with law or establish or defend legal claims. External transport, maps, restaurants and booking services have their own privacy practices when you choose to visit or use them; we do not send your account database to them merely because they are mentioned in a guide.
7. How long information is kept
We keep personal information only for the relevant purpose or applicable legal requirement. Our retention rules are:
- Account and active city access: while your account remains open and the records are needed to provide or restore your valid access. Inactivity alone does not cancel a purchased city. After a verified account-closure request, we aim to remove information no longer needed within 30 days, subject to legal retention and dispute exceptions.
- Private feedback and ordinary support messages: normally no longer than 12 months after submission or resolution, respectively. Useful findings may be kept in genuinely anonymised form. Correspondence needed for an order, legal claim or unresolved issue follows that purpose’s retention rule.
- Publicly approved feedback: while the permission remains valid and the feedback is in use, with a relevance review at least annually. You may withdraw permission at any time. Approval and permission records may remain where needed to demonstrate lawful publication.
- Application security events: normally up to 90 days after the event. Expired or revoked session records are normally kept for up to 90 days after expiry or revocation. Revoked browser records are normally removed within 90 days once linked sessions no longer need them. Active browser registrations remain while needed for access.
- Necessary order and refund records: normally 3 years after the transaction or final resolution of the related issue, with a longer period only where required for applicable accounting, tax, consumer or legal-claim obligations. We retain the minimum required information, not unrelated feedback or browsing data.
These rules are handled through periodic manual review. The application does not currently have a fixed automated deletion schedule or a self-service deletion button. Cookie expiry, session expiry and a rate key’s daily rotation do not themselves delete database records.
Where an unresolved dispute, legal hold or statutory duty requires longer retention, we limit the retained data and its use to that reason and review it when the reason ends. Provider-managed logs and backups have their own documented retention cycles; we cannot promise immediate removal from all backups. Email us for a deletion request or details of the applicable exception.
8. Security and international processing
We use HTTPS on the public website, server-side credentials, hashed application tokens, revocable sessions and restricted database access. Application tables have row-level security enabled and are not directly readable by anonymous browser clients. These safeguards reduce risk; no online system can guarantee absolute security.
Our Supabase project is hosted in Singapore. Hosting, email delivery, provider support and an authorised team member’s access can involve processing in other countries, including the United States, with privacy rules different from your home country. Creem’s planned checkout is provided by an Estonia-based Merchant of Record and its service providers.
We limit transfers to information necessary for hosting, account access, email delivery, support and, when enabled, checkout. We restrict access to authorised personnel, use encrypted connections and server-side credentials, and review the provider’s processing location, subprocessors and data-processing terms. Supabase and Vercel publish data-processing addenda with transfer clauses; their availability is not a claim that every clause, certification or statutory exemption automatically applies to this service.
Where applicable law requires a particular transfer mechanism, notice, assessment or separate consent, it must be addressed for the relevant processing before relying on that transfer. Reading this policy is not separate consent or a waiver of your rights. We do not claim to have completed a Chinese data-export filing, certification or EU / UK transfer assessment merely because a provider offers standard terms. Contact us for the arrangements and safeguards applicable to your data and how to obtain a copy. Your information is not necessarily stored or processed only in China or your country of residence.
9. Your privacy rights
Depending on applicable law, you may request access or a copy of your information, correction, deletion, restriction of processing, portability, or object to processing based on legitimate interests. You may withdraw consent for public feedback use without losing access to your guide. You may also complain to your local data-protection authority.
Email gochinatravel@hotmail.com from your account or submission address, describe the request, and provide an order or submission reference if relevant. We may need proportionate identity verification; do not email a passport or full payment details. We aim to acknowledge requests within 5 business days and respond within 30 days of receiving sufficient verification, or sooner where the law requires. If a lawful extension is necessary, we explain the reason and applicable deadline rather than silently postponing the request.
There is no self-service account deletion button at present; requests are handled by email. Account deletion can remove the identity needed to restore paid access, so we explain that consequence before acting. For information held independently by Creem, use its privacy contact too; we can help identify the relevant transaction.
10. Children and sensitive information
The website is intended for travellers able to enter into a purchase contract, and is not directed at children. A parent or guardian should manage access for a child. If you believe a child supplied personal information without appropriate permission, contact us.
Reading an allergy card does not submit a medical profile to us. Please avoid medical records, identity documents and other sensitive personal details in feedback or email unless we have agreed on a necessary, appropriate way to handle them.
11. Policy updates
We update this page when relevant services or processing change and revise the date above. Material changes affecting existing accounts will be communicated through the website or account contact where required. This policy does not replace notices or choices required for a future new data use.