CrossMeet respects and is committed to protecting user privacy. This policy explains how we collect, use, and safeguard your data.
0. Data Controllers
CrossMeet is operated by two independent legal entities. Each acts as the data controller for users in its respective region:
| Your region | Data controller | Applicable law |
|---|---|---|
| China mainland | [CN_COMPANY_NAME] (Unified Social Credit Code [USCC], registered in [CN_CITY], address [CN_REGISTERED_ADDRESS]) |
Personal Information Protection Law (PIPL), Data Security Law, Cybersecurity Law of the People's Republic of China |
| Outside China mainland (including Hong Kong, international) | [HK_COMPANY_NAME] (BRN [BRN], CR [CR], registered in Hong Kong SAR, address [HK_REGISTERED_ADDRESS]) |
Hong Kong Personal Data (Privacy) Ordinance, EU GDPR, UK-GDPR, California CCPA / CPRA |
The two entities are compliance-independent, settlement-independent, and invoice-independent. User data is segregated by region and never flows between the two entities.
1. Data we collect
1.1 Account information
- Email address, username (provided at registration)
- Encrypted password hash (irreversible bcrypt)
- Registration time, last login time, login IP (for fraud prevention)
1.2 Payment information
- Payments are processed by Stripe / Alipay / WeChat Pay / PayPal / Wire Transfer. We do not store credit card or bank card numbers. We retain only: transaction ID, amount, currency, timestamp, subscription status, and receiving entity.
- Invoice data (company name, tax ID) — saved only when explicitly submitted by customers requesting an invoice.
1.3 Device information (license binding)
- Device hardware fingerprint (HWID): an irreversible hash derived from CPU + motherboard + MAC. Contains no personally identifying information.
- Device activation time, last heartbeat time, device name (user-customizable)
1.4 Usage logs
- Crash reports (automatic): only stack traces uploaded on crash (no user input content)
- Error logs: stored locally at
%APPDATA%/CrossMeet/logs.db. Not uploaded by default. Only attached if you submit feedback.
1.5 What we do NOT collect (important)
- ❌ ASR audio content is NOT uploaded to our servers. Cloud ASR (e.g., OpenAI Whisper, Aliyun) uses your own API key — audio goes directly to that cloud service, never through CrossMeet servers
- ❌ Translation content and conversation history are NOT uploaded. Stored locally at
%APPDATA%/CrossMeet/crossmeet.db - ❌ We do NOT collect microphone, screen, or filesystem listing data
2. Data storage & security
Storage is segregated by data controller:
| Data controller | Storage location | Cross-border transfer |
|---|---|---|
[CN_COMPANY_NAME] (China mainland users) |
Aliyun East China nodes (within China mainland) | None — data does not leave China mainland |
[HK_COMPANY_NAME] (international users) |
AWS Hong Kong / North America | Only under GDPR / UK-GDPR Standard Contractual Clauses (SCCs) where applicable |
Technical controls (identical across both entities):
- Transport encryption: HTTPS (TLS 1.3)
- Storage encryption: at-rest AES-256 database encryption
- Environment isolation: dev / staging / prod strictly separated
- Access control: role-based least-privilege (RBAC); audit logs record every data access
3. Data retention
- Account data: retained while account exists; permanently deleted within 30 days of voluntary account closure
- Device records: retained while license is valid; cleared 90 days after expiry
- Email send logs: 90 days
- Crash reports: aggregated stats kept; raw data cleared after 6 months
- Payment records: retained per local tax law (10 years for China, 7 years for Hong Kong), then destroyed
4. Cookies
- Session cookie (required): keeps you logged in, expires when browser closes
- CSRF token: prevents cross-site request forgery
- No third-party tracking cookies (no Google Analytics, no Facebook Pixel)
5. Third-party services
| Service | Purpose | Data shared | Used by entity |
|---|---|---|---|
| Stripe | International payments | Credit card data (never touches our servers) | [HK_COMPANY_NAME] |
| PayPal | International payments | Payment information | [HK_COMPANY_NAME] |
| Alipay / WeChat Pay | China mainland payments | Order ID + amount only | [CN_COMPANY_NAME] |
| Resend | Email delivery (registration, password reset) | Email address + email content | Both entities |
| Cloudflare | CDN + DDoS protection | Visitor IP (aggregated) | Both entities |
Cloud ASR / TTS / LLM (OpenAI, Aliyun, Claude, etc.) used inside the desktop app run with your own API keys — they never touch our servers and are outside the scope of this privacy policy.
6. Your rights
Under China PIPL, EU GDPR, UK-GDPR, and California CCPA / CPRA, you have the right to:
- Access: request all data we hold about you
- Rectification: correct inaccurate personal information
- Erasure / Right to be Forgotten: request complete deletion of your account and related data
- Data Portability: download your account data as JSON / CSV
- Restriction of Processing: pause processing of certain data categories
- Object: object to automated processing based on legitimate interest
- Withdraw Consent: withdraw any previously given consent at any time
To exercise these rights, contact the data controller responsible for your region:
- China mainland users: privacy-cn@crossmeet.com ·
[CN_COMPANY_NAME] - International users: dpo@crossmeet.com · Data Protection Officer at
[HK_COMPANY_NAME]
We respond within 30 calendar days (GDPR / CCPA compliant).
7. Policy changes
If we make material changes, we will email all registered users and post a notice on the site at least 7 days in advance. The effective date is reflected in the last_updated frontmatter field.
8. Contact
- China data requests: privacy-cn@crossmeet.com ·
[CN_COMPANY_NAME]·[CN_REGISTERED_ADDRESS] - International data requests (GDPR / CCPA): dpo@crossmeet.com ·
[HK_COMPANY_NAME]·[HK_REGISTERED_ADDRESS], Hong Kong SAR - General support: support@crossmeet.com