Skip to main content
BBossAI
SolutionsProductsCasesCompanyResourcesContact
Request Demo中文
Privacy

Privacy Policy

This policy explains how the BossAI website, BossAI OS-governed products and capabilities, BossAI Cloud, controlled software delivery, and related payment and support workflows handle information. Last updated: September 6, 2026.

1. Scope and controller

BossAI is a brand operated by Daxinglian Cross-Border E-Commerce Co., Ltd. “We,” “us,” and “our” refer to Daxinglian Cross-Border E-Commerce Co., Ltd. unless a transaction identifies another responsible entity. This policy applies to the official website, the authorization cloud service, Desktop delivery, product support, and related order records. Third-party model providers and payment providers apply their own terms and privacy notices when you use their services.

2. Website access data, local storage, and external assets

The website currently has no user registration and does not intentionally use advertising trackers. The web server may record basic access logs such as IP address, access time, requested path, browser type, referrer, and error information for availability and security.

The website uses browser local storage only to remember a light or dark theme preference under the key bossai-theme. This preference stays in the browser until the user clears it and is not used for advertising or cross-site tracking. The current website does not intentionally set advertising cookies.

Product screenshots and other static website assets are currently served directly from the official BossAI website rather than GitHub Raw or another external content-hosting path. The browser connects to a third-party service only when the page explicitly enables a necessary third-party function, such as payment processing; that provider may receive ordinary network information such as IP address, user agent, referrer, and request time under its own privacy practices.

When you contact us through the website form or another support channel that BossAI expressly provides to you, we process the name, email address, company or team details, product interest, device or team scale, current AI setup, message, and attachments you choose to send. The contact form first submits through the same-origin website API and uses an email delivery service to forward the request. If the API is unavailable, the page preserves the request content for copying and retry; an email draft is offered only when a governed public support recipient is explicitly configured.

The contact API does not write the complete form submission into the BossAI customer, order, or license database and does not record the full message body in application logs. Minimal operational records such as submission time, request type, the bounded product-interest enum, and response status may be retained for abuse prevention and troubleshooting.

3. Data handled by BossAI Cloud

  • Customer name, email address, and status;
  • Order reference, product, amount, currency, payment status, and transaction time;
  • License plan, device limit, expiry, validation state, and offline grace period;
  • Device name, platform, app version, activation time, and last validation time;
  • Release records, administrative audit records, and necessary server security logs.

License codes and device identifiers are stored as hashes. The complete activation code is shown only once when issued.

4. Product data and AI credential boundary

The BossAI website and contact form do not require and should not receive complete AI credentials. Storage location for project materials, professional files, assets, and outputs depends on the product and deployment model; some project and work files in a controlled Desktop build may remain on the user's device.

Where an enterprise deployment uses customer-owned AI credentials, raw credentials should enter only the approved BossAI OS / AI Gateway configuration boundary and should not be placed in project content, prompts, chat, screenshots, or support requests. BossAI Cloud does not currently store complete customer AI credentials as ordinary customer, order, or license records.

We receive diagnostic material only when the user actively exports and sends it for support. Remove unrelated sensitive information before sending it.

5. Purposes

We use relevant information only to create customer and order records; issue, activate, validate, suspend, restore, or revoke licenses; control devices; provide release checks and download verification; deliver support; prevent abuse; maintain security; and meet transaction or legal obligations.

6. Overseas hosting and cross-border transfer

The BossAI website and BossAI Cloud are currently hosted primarily on servers in the United States. Necessary customer, order, license, device, and audit information submitted to Cloud, as well as contact information submitted through the website API, is transferred to overseas infrastructure and handled by the relevant services.

If you submit another person's personal information on behalf of a business or team, you are responsible for confirming a lawful basis and completing any notice, authorization, consent, or cross-border procedure required by applicable law.

See the Deployment, filing and data notice for more detail.

7. Third-party services

When a BossAI product or customer-authorized enterprise deployment invokes a third-party AI service, relevant inputs may be processed under that third party's terms and privacy policy. BossAI does not control third-party availability, processing region, or policy changes; the actual data flow depends on the enabled product, configuration, and enterprise agreement.

The website contact form may use a third-party email delivery provider, currently configurable as Resend, to forward contact requests. That provider processes the information required for delivery under its own terms and privacy policy.

Where a purchase is processed through Paddle, Paddle acts as the authorised reseller and Merchant of Record and independently processes payment, tax, billing, cancellation, fraud-prevention, and refund information under its own buyer terms and privacy notice. BossAI does not receive or store full payment-card details from Paddle checkout.

We do not sell personal information to advertisers and do not allow advertisers to access the BossAI Cloud customer, order, or license database.

7A. Planned Amazon Selling Partner API data boundary

BossAI does not currently access live Amazon Selling Partner API (SP-API) data. If the relevant application and roles are approved by Amazon and an eligible seller separately authorizes BossAI Commerce, access is intended to remain limited to the minimum data necessary for the approved, seller-authorized business purpose.

The currently stated application scope is read-only commerce analysis for catalog and listing facts, pricing, inventory and sales-performance information, and Brand Analytics only where separately approved. The stated scope excludes buyer personally identifiable information, Orders, buyer messaging, refunds, payments and seller-account control, and it does not perform Amazon write actions.

Amazon information will not be sold, rented, used for advertising, or used for unrelated purposes. A live connection must remain disabled until the operating entity has verified and published the applicable retention/deletion schedule, incident-management contact, and any processor or subprocessor that would handle Amazon data. Sellers and authorized users may use the privacy request form for access, correction, deletion, or data-protection questions.

8. Retention

Data is retained only as long as needed to provide the service, evidence transactions, handle support and disputes, maintain security, and meet applicable legal duties. After a license ends or a valid deletion request is accepted, data will be deleted or anonymized where this does not conflict with transaction, accounting, security, or legal record obligations.

9. Security

  • Production traffic uses HTTPS;
  • The signing private key remains on the cloud server;
  • Desktop contains only the public key;
  • Database and admin access are controlled;
  • Important administrative actions are audited;
  • License codes and device identifiers are hashed.

No system can guarantee absolute security. We will take reasonable containment, remediation, evidence-preservation, and notification steps if a security incident may affect user rights.

10. General privacy rights

Subject to applicable law, you may ask what data we process about you; request access, correction, supplementation, deletion, or a portable copy; ask for an explanation of order, license, or device records; or raise a privacy complaint. We may verify the associated email, order, license, or other information reasonably necessary to protect the account and data.

11. United States state privacy rights and notice at collection

Where an applicable United States state privacy law grants you additional rights, you may request confirmation of processing, access, correction, deletion, or data portability; opt out of a sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying profiling; appeal a denied request where required; and exercise your rights without unlawful discrimination.

Our current website and product-delivery practices do not sell personal information, do not share personal information for cross-context behavioral advertising, and do not use personal information for targeted advertising or high-impact automated decision profiling. If these practices change, we will update this policy and provide any legally required opt-out method, including recognition of qualifying browser-based opt-out signals where applicable.

At or before collection, the contact form identifies the categories requested—identifiers and contact information, organization details, product or device information, current AI-setup categories, and the message you choose to provide—and links to this policy. We use that information for responding to the request, product delivery, security, fraud prevention, support, and legal or transaction records. We do not collect full payment-card details through the BossAI website.

Submit a United States state privacy request through the privacy request form. An authorized agent may submit a request where permitted by law, subject to reasonable proof of authorization and identity verification. We will respond within the period required by the applicable law and explain any denial or available appeal process.

12. Children

BossAI is a general-audience business product intended for adult professional users and is not directed to children under 13. We do not knowingly collect personal information online from children under 13. If we learn that such information was collected without legally sufficient parental authorization, we will take reasonable steps to delete it. Do not submit a child's voice, likeness, or other personal information without a lawful basis and any required parent or guardian consent.

13. Language, contact, and updates

The English version of this Privacy Policy is the primary and legally binding version. Any Chinese translation is provided for convenience only. Mandatory law prevails where it does not permit this language rule.

Privacy, access, correction, or deletion requests:

BossAI Privacy Request Center · bossai.support@gmail.com

We will update this policy if the product architecture, payment relationship, hosting region, or data scope materially changes.

BossAI · Enterprise AI Work Systems
About · Solutions · Products · Demo · Cases · Contact Us
Company · Pilot Program · ROI · Security · Resources: Pricing · Product Access · Resource Center · AI Access Boundary · Responsible AI · Changelog
Legal: Privacy · Terms · Refunds · Accessibility · 中文
© 2026 Daxinglian Cross-Border E-Commerce Co., Ltd.