Privacy Policy
This policy explains what personal data IsItAFactory collects, why we collect it, who else processes it, and what you can ask us to do with it. It describes what this website actually does: there is no advertising on it and no behavioural tracking. Statistics come in two parts and are described in section 3 — aggregate counting done by our own server, and Google Analytics, which loads only in jurisdictions that require prior consent (the EU, the EEA, the UK and Switzerland) and only after you have accepted.
1. Who we are
IsItAFactory is an independent research service operated by an individual based in mainland China. We prepare written reports that summarise information taken from official Chinese public records. For the purposes of the EU and UK General Data Protection Regulation, that individual is the data controller.
You can reach us at our contact form or by replying to any email we have sent you.
2. What we collect
We collect only what we need to produce a report, get it to you and answer your questions.
When you place an order
- your email address, so we can deliver the report and send order updates;
- the name of the Chinese company you want checked, plus any registration number (USCC) or website or shop link you give us;
- the package and any optional add-ons you selected, and the total price;
- whatever you write in the free-text field describing your concern;
- your preferred report language, and the site language you were using;
- the country the request came from: a two-letter code worked out from your connection, plus, if you fill in the country field yourself, the wording you used. Section 3 explains how that code is derived;
- the order number, its status and timestamps;
- payment status, the method used, PayPal order and capture identifiers, the amount paid, and the email address on the PayPal account.
When you use the contact form
- your salutation and name (both optional) and your email address;
- your own company and country, and the type of customer you select (all optional);
- the website or shop link you give us. If you give one, we may open it once to see whether it loads and whether the company name matches, before we quote you;
- the Chinese company you are asking about, its registration number (USCC) and its website or shop link, as far as you give them;
- the free text you write, including the details listed above the send button.
When you subscribe to our emails
- your email address, the site language you were using, and where on the site you subscribed;
- whether and when you confirmed the subscription and, if applicable, when you unsubscribed.
Placing an order also creates a record in our mailing list, so that we can send you a follow-up about the report we delivered and so that we can honour an unsubscribe request.
What we do not collect
We do not run advertising, heat-mapping or session-recording scripts. Statistics are covered in section 3 and there are two parts to them. We do not ask for your card number or bank details: card data is entered on PayPal's own site and never reaches our servers. We do not ask for identity documents.
3. IP addresses and statistics
We look at the IP address of requests to the order form, the contact form, the subscribe form and the order-tracking page to stop automated abuse of forms that send email. Those IP addresses are held in the server's memory for at most one hour and are not written to our database.
We also use the IP address of a page request to work out which country the visit came from, so that we can see which languages and markets are worth investing in. For our visit statistics only the two-letter country code is kept, and only as a daily total (for example Germany, 12 page views). If you place an order, that code is also stored with the order, as listed in section 2. The IP address itself is never stored, and it is not sent to any third-party geolocation service. A country is not a personal identifier — millions of different people are counted under the same code, and the total tells us nothing about any one of them.
For the same statistics we also keep three more things about the first page of a visit, each as a daily total next to the country code: the domain of the page that referred you (for example google.com, never the full address), the search term if the referring page passed one on, and the page you landed on. When you arrive from a Google search the search term is usually not passed on at all, and then nothing is recorded for it. We keep these totals because they are the only way to learn which questions bring people here. None of them identifies you: a domain and a country are shared by millions of people, and a search term is stored only as a normalised word.
If a city-level database is configured on the server, the statistics also record the city derived from the IP address, again only as a daily total. Like the country code, a city is a coarse place rather than a location, and it is stored next to no identifier.
Our application log records IP addresses only in truncated form (for example
203.0.113.x.x), which is enough to see that a network range is misbehaving but not
enough to identify an individual. Our web server keeps standard access logs for security and
troubleshooting; those contain full IP addresses and are rotated by the hosting configuration.
Counting done by our own server
The items above — the country code, the referring domain, the search term, the landing page and the city — are received by our own server and totalled per day. There is no cookie, the data does not leave our server, and it is not shared with anyone else.
Google Analytics
In addition to that, this site uses Google Analytics (provided by Google LLC, a company in the
United States) to see which pages are visited and where visitors come from. It writes two cookies
in your browser (_ga and _ga_<container id>), records a randomly
generated client identifier, and sends the pages you viewed, the referring source and those
identifiers to Google. It does not receive the email address, company name or order details you
enter on this site.
Google Analytics is not loaded, and none of its cookies are written, until you click "Accept". You can accept or decline in the banner at the bottom of the page; declining does not affect any feature, and you can change your mind at any time through "Cookie settings" in the footer. Where we cannot determine your country, we treat it as requiring consent, so we ask first.
Google's servers are in the United States, so this is a transfer of personal data abroad. The legal basis is your consent, described in section 4; retention on Google's side is governed by Google's own policies.
4. Why we use your data
- To perform our contract with you — producing and delivering the report you ordered, taking payment, and handling questions about that order.
- Our legitimate interests — preventing abuse of our forms, keeping the records we need for accounting and tax purposes, and sending one follow-up about a report we have already delivered to you.
- Your consent — sending you our newsletter, and loading Google Analytics in the jurisdictions that require it. You may withdraw either consent at any time, and we then stop.
Every newsletter and follow-up email contains a one-click unsubscribe link that works without logging in. We do not make automated decisions about you and we do not build profiles.
5. Who else processes your data
We use a small number of service providers, each of which processes data only on our instructions:
- PayPal — payment processing. PayPal collects and controls its own data; see PayPal's privacy statement for what it holds.
- Resend — delivery of our transactional email: order confirmations, status updates, replies to your message, and newsletters. Your email address and the content of the message pass through them.
- Cloudflare — DNS, content delivery and email routing for our domain. Like any content delivery network, it sees the IP addresses of visitors.
- Google — provides Google Analytics. It processes data according to our configuration and stores the resulting statistics on its own servers; see Google's privacy policy for how it handles them. This happens only in the jurisdictions that require it, and only after you have accepted.
- Our hosting provider — operates the virtual server on which this site and its database run.
Some of these providers are located outside your country, including in the United States. Where a transfer requires a safeguard, it relies on the provider's standard contractual clauses or an equivalent mechanism.
We do not sell, rent or trade your personal data. We do not share it with anyone else except where the law requires it, or where it is necessary to establish, exercise or defend a legal claim.
6. Data about the company you ask us to check
A report is built from official public registers. It does not contain personal data that is not already public in those registers. We do not publish reports, and we do not tell the company you asked about that you asked. The report is delivered to you alone.
7. How long we keep it
- Order records, including your email address and the company you asked about: three years after delivery, so that we can answer questions about the report and meet accounting and tax obligations.
- Contact form messages: twelve months.
- Newsletter subscriptions: until you unsubscribe. After that we keep your address only in a suppression list, so that we do not email you again by mistake.
- Rate-limiting IP addresses: at most one hour, in memory only.
8. Cookies
The only strictly necessary cookie we set ourselves is a session cookie, and it is required for the site to work. It does three things:
- protects our forms against cross-site request forgery;
- remembers which orders this browser has just placed, so that the order-tracking page does not ask you for your email address again;
- remembers the site language you were last browsing in, so that a bare address such as
/pricingcan send you to the language version you expect.
If you sign in to the administration area, the same cookie keeps you signed in there. It holds no advertising or analytics identifier, and we do not use it to recognise you on other sites.
It is deleted when you close your browser. The only exception is signing in to the administration area, where it lasts up to twelve hours.
Two further kinds of cookie can appear. Neither is strictly necessary, and both are described below:
- Your consent choice — set by us, named
consent_choice, kept for up to six months. It records only whether you clicked "Accept" or "Decline" in the consent banner. It contains no identifier and is used for nothing else; without it we cannot honour your choice. Clear it and we will ask again on your next visit. - Visit statistics — set by Google, named
_gaand_ga_<container id>, kept for up to two years. These appear only after you click "Accept". If you decline, or make no choice, they are never written. See section 3.
That is why visitors in the EU, the EEA, the UK and Switzerland see a consent banner. Until you make a choice, no cookie other than the strictly necessary session cookie above is written, and no request is made to any third party.
9. Your rights
Depending on where you live, you may have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete your data, where we are not obliged to keep it;
- ask us to restrict how we use it, or object to our use of it;
- receive your data in a portable format;
- withdraw consent for newsletter email at any time;
- complain to your national data protection authority.
To exercise any of these, write to us through the contact form. We answer within 30 days. We may ask you to confirm that you control the email address in question before we act.
One limitation worth stating plainly: a report is a record of what official registers said at a particular moment, and it is evidence that a transaction happened. If you ask us to delete your personal data we will do so, but we may have to keep the fact that a report was produced in order to satisfy accounting requirements.
10. Security
Traffic to this site is encrypted with HTTPS. Access to the order database requires credentials held only by the operator. Payment credentials are never stored on our servers. No system is perfectly secure, so we cannot promise absolute security; we limit what we collect in order to limit the consequences if something does go wrong.
11. Children
This is a business research service and is not directed at children. We do not knowingly collect data from anyone under 18.
12. Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects how we use your data, we will also note it on the site.