Privacy Policy
Effective date: 1 June 2026 · Last revised: 1 September 2026
This privacy policy explains how the trading house called CuBaiTrade, operated by the company Nanning Cubai Trading Co., Ltd., handles personal information. CuBaiTrade acts as the marketing and sales face of the wholesale distribution floor, while Nanning Cubai Trading Co., Ltd. is the legal entity that signs documents and holds responsibility for the data. The developer name CuBaiTrade is used across this web site to keep the writing simple, but every commitment in this document binds the company itself. Please read the whole policy so you understand what we collect, why we collect it, how long we keep it and what you can ask us to do with it. If a section leaves a question, contact the data office at the address given near the end of this page.
This web site serves as the outward counter of a wholesale trading operation. It introduces the merchandise we source, the inspection steps every lot passes and the services offered to retail groups. Visitors use the site for three main reasons: to read about the floor, to request a lot list and to ask a buying desk a question. Each of those reasons may involve some personal data, and this policy sets the rules for handling that data. The purpose of the policy is to give a clear and honest account of our practices in plain language. We prefer a review that a buyer can read in one sitting over a wall of clauses. The policy applies to data gathered through the web site, through direct email to the desk and through telephone calls placed to the counter. It does not apply to data you may give to a completely separate organisation whose web site we happen to link to.
The names CuBaiTrade and Cubai both refer to the trading brand used on this web site. The legal controller of the personal data is Nanning Cubai Trading Co., Ltd. Its full postal address is Room 1603 Building C, No. 14 Jinlong Road, Nanning Area of China (Guangxi) Pilot Free Trade Zone, Nanning - 530000, China (CN). The company operates in the field of computer systems design and related professional and technical services, and it applies those exact, system driven methods to the physical trade of general merchandise. Because CuBaiTrade is the brand shown in the navigation and in documents, this policy sometimes uses that brand name for convenience, but wherever responsibility must rest on a legal person, it rests on the company named above. When you contact us, you deal with the staff of that company, and any request you make about your data is answered by that company and no other.
This policy covers personal data collected from any person who visits the web site, sends a message through the contact form, telephones the trading desk or emails the address assist@cubaitrade.buzz. Business contact details of a purchasing officer are treated as personal data so far as the law of the reader applies, and we handle them with the same care as private details. The policy also covers data acquired during supplier qualification and inspection where that data belongs to an individual employee of a partner factory. It does not cover warehouse health and safety records about our own staff, because that data is governed by separate employment and workplace rules. If you read the site from a jurisdiction whose privacy law grants further rights, the stronger local rule is respected wherever we can lawfully apply it, though our primary home base is China.
We collect only the data needed to run the trading floor and to answer you. The contact form asks for your name, your email address, an optional phone number, a subject line and the text of your message. If you place an order or ask for a lot list, your message may add the name of your company, the country you buy for and the volume you expect, because shipping and customs work cannot be quoted without those facts. When you telephone the counter we may keep a short note of the matter discussed so that the buyer who promised to follow up can do so. We do not ask for sensitive categories of data such as health history, religious belief or political opinion, and we ask that you do not include such detail in a message because it is not needed for wholesale trade. We do not buy lists of contacts and we do not pay a data broker for your address.
Like most web servers, ours records a basic access line for each visit. That line holds the Internet protocol address of the device, the date and time of the request, the page asked for, the type of browser and operating system and the referring page. We store these lines for the short time needed to detect a fault, to protect the site from abuse and to understand which pages are actually read. The access logs are not joined to the contact form data by ordinary staff, so a specific visitor cannot usually be linked to a submitted message from the log alone. Our hosting arrangement keeps the logs on servers inside secure facilities, and access to the raw logs is limited to the people who run and repair the site. Automated data of this type never shapes a commercial decision about you.
We process personal data for a limited set of tasks that serve the wholesale trade. We answer your enquiry and send the sourcing notes you asked for. We prepare a quotation, a lot list or a proforma invoice when you request one. We confirm your identity as the buyer for the purpose of entering an order and for customs documentation. We check a factory worker file during supplier qualification only where the law requires a named contact for safety or export records. We keep a correspondence history so that a returning buyer does not have to repeat its story to a new desk clerk. We protect the web site from attack and investigate a failure. We comply with audit, tax, customs and regulator rules that demand certain records. We never process data to sell a marketing list to another company, and we never use your health details in any decision about a lot.
Different laws use different words for the ground on which data may be handled. In summary we rely on four grounds. First, contract: when you begin a purchase or a sourcing engagement, some data is needed so that order can be fulfilled. Second, consent: when you send a message through the form or email the desk, you choose to share the facts necessary for us to reply. Third, legitimate interest: we have a fair interest in protecting the web site, in answering genuine trade enquiries and in keeping honest records of completed shipments. Fourth, legal obligation: customs, tax and audit law may require us to hold certain documents for fixed periods. Where we rely on consent, you may withdraw it at any time by writing to the data office, and doing so does not affect the lawfulness of work already finished on that consent. Where we rely on a legitimate interest, you may object, and we will weigh your objection against the need to run a lawful trading floor.
We work with a small set of service providers so that the site stays up and shipments reach the gate. The web site is hosted by an infrastructure firm whose servers store the pages and the access logs. A mailing or booking helper may process the messages the contact form produces, though we prefer a direct reply to the address the client gives us. Freight and customs brokers may hold shipping documents. An auditor appointed under a compliance rule may see business records that contain contact lines. Every provider that touches personal data signs a written contract that limits the provider to acting on our instructions, forbids the provider from using the data for its own marketing and requires the provider to protect the data with reasonable safeguards. If a provider needs to see data from outside its own country, the transfer follows the rules described in the transfers section of this policy.
The trading floor serves retail buyers in many countries, so a reply or a shipment document may cross a border. Our home office and servers sit in China, while a buyer may live in a market elsewhere. When we send a quotation or documents to you, we are sending data outward to you by your own request, which is the ordinary course of answering you. When a subcontracted host or broker stores data in another country, we choose a provider that offers a recognised lawful route for the data and we record the reason in our internal register. We do not transfer data to a country merely because the price is low; we check that a defender of rights exists or that the transfer is protected by a standard clause approved for that purpose. You may ask for details of the safeguards in place for any single transfer by writing to the data office, and we will send a plain summary of what protects your data on the journey.
Security here has to survive a busy shipping season. Access to the trading system is limited to named staff who each hold an individual account, and each account records the actions it takes. The web site is served over an encrypted connection so a message travels to us in a form that cannot be read while in transit by an ordinary intercept. Files that hold signed documents are kept behind a second layer of control, and only the desk that owns the shipment can open them. Our staff are trained at least once a year on the simple failures that cause most leaks: a reused password, a forwarded attachment, a desk left unlocked. When a shipment is finished, the extra copies are removed. No system is risk free, and this policy does not promise that, but we match the controls to the sensitivity of the data: the more sensitive the record, the narrower the circle that may touch it.
We do not keep data forever just because it costs little to store. A routine enquiry that never becomes an order is reviewed and the correspondence is removed after two years from the last contact, unless a legal hold applies. A completed order keeps its documents for the period set by customs, tax and audit rules for the market concerned, which is commonly five years and never longer than the legal maximum we may lawfully keep. Access logs are held for the shorter window needed to protect the site, usually a few months, and then erased. A supplier qualification certificate is current for ninety days and the supporting visit notes are kept for two years so a later audit can trace the renewal history. When a retention period ends, the record is deleted or anonymised so that it can no longer identify a person, and the deletion is logged so we can show that the task was actually done.
Whatever law sits behind you, we honour a practical set of rights. You may ask for a copy of the personal data we hold about you and for a note of where it came from. You may ask us to correct a mistake such as a wrong email address or a misspelt company name. You may ask us to delete data where no law requires us to keep it. You may ask for a machine readable copy of data you gave us so you can move it to another provider. You may object to a use you consider unfair, and we will review the objection and reply with our reasoning. You may withdraw any consent you gave. To exercise any right, write to the data office at the email given below; a staff member answers within one month, or within the longer period your local law allows, and we mark the calendar so the reply is never forgotten. We will confirm your identity before handing over data, and a request costs you nothing unless you repeat it to the point of waste.
The web site sells wholesale merchandise to retail groups and not consumer toys to children, so we do not design any part of the site for children and we do not knowingly collect data from a child. A child who has reached the age at which its own consent is valid in its country may of course read the public pages, but we ask a parent or guardian to send any request on its behalf. If a parent discovers that a child left details in a message by mistake, the parent should write to the data office and we will delete the record as soon as we confirm who the child is. We do not run games, contests or chat rooms aimed at young people, and we do not use personal details of a young visitor for any purpose at all. Where a stricter local rule lowers or raises the age of consent, that local rule governs the child who lives under it.
This web site may carry a link to a standard of a regulator, to a map service or to a carrier that runs a reciprocal page. When you click such a link, you leave our site and this policy no longer applies to what that other site does. The other site has its own owner, its own privacy notice and its own cookies, over which we have no control. We add a link only where we believe the destination is honest, but we cannot answer for a change made there later. Before you type personal details on a site that we merely point to, read that site own privacy notice and decide for yourself. If a third party web site that you visited from ours sends us a note that mentions your visit, we treat that note as correspondence about our own service and keep it only as long as the correspondence rule allows.
We do not make decisions about you by an algorithm alone. A purchase, a credit line and a shipping route are each reviewed by a named human before anything is confirmed, because a wholesale floor depends on judgement about quality and trust. Our systems do draw automatic reminders, such as a note that a supplier certificate is due for renewal or that a quote has not received an answer, but those reminders only prompt a person to act; they do not create a legal effect against you. We do not build a profile that ranks you as a customer for someone else to buy. If we ever introduce a tool that delivers a fully automatic decision with a significant effect on you, we will stop, tell you in clear words what the tool does and give you the right to a human review of that outcome.
If a mishandling of personal data is discovered, we act quickly and honestly. The desk that finds the problem tells the data office the same day. The data office decides whether real harm is likely to a living person, rather than a purely technical event that touched nobody. Where a risk to a person is serious, we notify the affected people directly and we notify the relevant regulator within the window its law sets. The notice describes what happened in plain language, what data was involved so far as we know, what protection we have already applied and what steps the person can take to guard against misuse. We keep a record of every breach, serious or not, with the cause and the fix, so the same failure is not repeated. Telling a customer a difficult truth early is cheaper than letting it leak from somewhere else later.
The web site and the trading floor will grow, so this policy may change. When it does, the date on the second line of this page is refreshed and a short summary of what changed is added at the top of the document so a regular reader can see the difference without rereading every line. A change that narrows your rights, or that adds a new use of your data, is highlighted before it takes effect, and for a new use that rests on consent we ask for that consent fresh rather than treating old agreement as silence. For a material change we will post the notice on the home page for a reasonable period. If you keep using the web site after a change, the refreshed policy governs your next use, but earlier action is measured against the policy that stood at the time the action was taken.
The data office is best reached by email at assist@cubaitrade.buzz and by telephone at +15407307653. You may also write to the postal office at the full address of the company, which is Room 1603 Building C, No. 14 Jinlong Road, Nanning Area of China (Guangxi) Pilot Free Trade Zone, Nanning - 530000, China (CN). When you write about your data, please give the name of the company you buy for and the best way to reach you, because the office must confirm your identity before it releases anything. The office answers ordinary data requests within one month of a complete request. If you phone, the counter will ask the nature of your call and route a data matter to the person who holds that file. Keep the reference number the office gives you in its first reply, because it speeds every later question about the same case.
If you believe your data was handled wrongly, please raise it with the data office first, giving the matter a fair chance to be corrected in an ordinary working day. If the office answer does not satisfy you, or if you prefer a route outside the company, you may complain to the data protection authority that has power over your own country. For a person in China the relevant regulator is the Cyberspace Administration of China as that law names the authority for such matters. For a person in the European Union, the complaint goes to the supervisory authority of the member state where you live. We will not punish or penalise you for raising a concern, and no buyer loses a lot or a quotation because it made a privacy complaint. A record of a complaint and its outcome is kept for two years so a pattern of the same fault would become visible to the office.