1. Who we are
ReachPilot is operated by Sun Mellon Trading Ltd., a Canadian company. ReachPilot is the public name of the creator-operations system also known as JianLian. This policy covers personal information processed through our website and product, including existing internal operations as we prepare our public service and platform integrations.
Contact our privacy team at sunmellon@gmail.com.
Business teams determine the purposes of their creator campaigns. We provide and maintain their workspace and process information needed to operate and support it.
2. Information and purposes
We receive information from business teams, creators, imported files, public profiles and service providers. Product use also generates activity records. We process:
- Account details, roles and access records to manage access and protect the service.
- Creator names, handles, profile links, contact details, categories, locations, available metrics and notes to organize and evaluate potential collaborators.
- Drafts, recorded replies, review decisions, contact preferences and collaboration history to coordinate communication and follow-up.
- Sample recipient names, phone numbers, addresses, products and shipping details to arrange samples and track fulfilment.
- Source files, search results, uploaded business materials, reports and activity history to preserve context, support users and review outcomes.
Public profile information can still be personal information. Teams should supply only information they are entitled to use and avoid unnecessary sensitive information.
3. Providers and sharing
| Recipient | Purpose and information |
|---|---|
| Alibaba Cloud | Hosting the website, application and database; infrastructure and backup services. |
| DeepSeek | Optional AI assistance using selected brand, product and cooperation text, creator category/platform, search prompts and filters. Inputs can contain personal information. |
| FastMoss | Receiving search criteria when its discovery service is used and returning creator profiles and performance information for review and reuse. |
| Google/Gmail | Handling messages, sender details and attachments sent to our contact and privacy mailbox. |
| Cloudflare | Domain-name resolution for this website, whose content is served directly by our hosting provider. |
| Authorized teams and fulfilment recipients | Access to relevant collaboration records; necessary recipient and product information shared with warehouses or carriers to arrange samples. |
Do not include unnecessary or sensitive personal information in AI prompts. Providers handle information under their applicable terms. Information may also be disclosed when required by law or to investigate misuse.
4. Platform data and authorization
We process data obtained through official TikTok or other platform connections only after the necessary platform approval and user authorization, and only for the permitted service purposes. We do not claim official partner status or API approval.
Imported profiles and third-party discovery results are distinct from officially authorized platform data. Authorization does not permit unrelated advertising, data resale or model training. You may revoke an authorized connection through the platform’s permission controls and contact us about information already received.
5. International processing
Our primary servers and database are in Hong Kong, China. Operations and administrative access involve mainland China and Canada. Remote access is processing in the country where the operator works. DeepSeek also involves processing in mainland China.
Google and other providers use international infrastructure. Provider services, operational access and controlled copies can involve cross-border processing. Canadian registration does not mean data stays in Canada, and we do not offer exclusive Canada/Hong Kong residency. Contact us about any location restriction before providing affected information. Data processed abroad may be subject to local laws and lawful access requirements.
6. Retention and deletion
We retain personal information only for as long as needed to provide services, manage collaborations, maintain security or meet applicable retention obligations. Retention depends on the purpose, the relationship, valid requests and applicable obligations; there is no single period for all records.
Following a valid deletion request or the end of a customer relationship, we will delete or return customer data in accordance with applicable agreements and law. Our process will cover relevant business records, source files, exports and controlled copies, and coordinate deletion with service providers processing data on our behalf. Manual processing and verification may be used.
Limited information that must be retained by law will be restricted in access and use, and deleted when the obligation ends. Backup copies will be handled through a controlled removal process; restoring a backup must not reintroduce data scheduled for deletion. We do not specify an unverified fixed backup-expiry period.
These are service commitments. Before opening the public service or receiving officially authorized platform data, we will establish and verify the procedures needed to fulfil them. Removing a profile from view does not by itself complete this process.
7. Your requests
Email sunmellon@gmail.com to request access, correction, deletion, restrictions on use or an end to outreach. Include enough context to locate your information. We may verify your identity or authority and coordinate with the responsible business team. We will assist with valid requests under applicable requirements and explain any lawful limitations.
The workspace records do-not-contact preferences. Withdrawing platform authorization stops the authorized connection; requests concerning information already received are handled through our privacy contact. Rights and response requirements depend on applicable law.
8. Website visits
This public website has no registration form, payment function, analytics tracker, advertising pixel or marketing cookie. Routine access logging is disabled. Hosting, error and security records may still include IP addresses, requested pages and timestamps. The product separately records authentication and account activity.
9. Security and updates
Current safeguards include HTTPS, authenticated access, role-based permissions, separation of business records between workspaces and restricted administrative access.
Our organizational security requirements cover access control, encryption of sensitive data in transit and at rest, endpoint protection, incident response and vulnerability management. Requirements not yet verified will be implemented and checked before officially authorized platform data is received. These requirements are not a claim that every control is already operational or independently certified.
We will update this policy when processing changes and show the revised date here. Questions can be sent to sunmellon@gmail.com.