Home News & Blog Get started
EN
English 简体中文

Privacy Policy

Last updated September 21, 2026

This policy explains what CHB Mate (the “Service”), operated from chbmate.com, collects about you, why it is collected, who else receives it and how long it is kept. It is part of the Terms of Service and uses the same words in the same way.

The short version. We keep what the Service needs to sign you in, charge the subscription you authorized and enforce the usage limits. We do not sell your account, billing or lookup information, and no advertiser ever sees the codes you look up. We do measure how the site is used, with Google Analytics, and we may advertise the Service using tags of the same kind. Both stop before they load for a browser that asks not to be tracked.

1. Who we are and how to reach us

CHB Mate is operated at chbmate.com. Email is how you reach us: [email protected]. Send privacy questions, access and deletion requests, and complaints to that address.

The Service is operated from the United States, for people classifying goods entering the United States, and your information is handled there under this policy and United States law. It is not directed to and is not offered in the European Economic Area, the United Kingdom or Switzerland: we do not aim the Service at those markets, and the consent banner their rules call for is not shown here. Cookies are set as section 7 describes; that section also says how to refuse them, wherever you are reading from.

2. What we collect, and why

An account is an email address and a password, and most of what we hold follows from that. The rest is the technical record any website keeps of a request.

  • Account information — the email address you registered with, a one-way cryptographic hash of your password (we cannot read the password back), a record that your address was verified, and a record that you accepted the terms. When you ask to reset your password, a short-lived record that a code was issued — the code itself, like the verification link's token, is stored only as a hash. We ask for no name, no profile and nothing else about you.
  • Subscription and payment information — your plan, what has been charged and when, and the identifiers PayPal gives us so that a renewal can be taken. Card and bank numbers never reach the Service — you enter them at PayPal, and PayPal holds them.
  • Your use of the Service — a record of the lookups you run, including the codes you look up, and of what happened on your account.
  • Technical records — the ordinary records a website and its network provider keep about requests, used for security and troubleshooting.

We collect this to sign you in, to run and bill your subscription, to answer your support questions, to enforce the usage limits and fair-use rules in the terms, and to investigate suspected abuse. None of it is collected for advertising. Advertising, if we run it, works from the tags described in sections 4 and 7 — which see the pages visited on this website and nothing else — and never from your account, your billing history or the codes you look up. We do not buy information about you from anyone.

3. The codes you look up

When you are signed in, we keep a record of the lookups you run, including the codes searched. We read it to answer support questions and to look into suspected scraping or account sharing — nothing else, and never to advertise to you. We do not sell it and do not share it for advertising (section 4).

If your lookups involve information your own clients treat as confidential, be aware that a record is kept as described here, and satisfy yourself that this is compatible with your obligations to them.

4. Who else receives your information

  • PayPal — takes the payments. It holds your card or bank details; we hold only its identifiers and your permission to charge.
  • Mailgun — delivers our service and billing email, including the account-verification link and password-reset codes, and so receives your email address and the contents of those messages, for that purpose and no other. Those messages never include your lookup activity, and we do not use open or click tracking in them.
  • Cloudflare — sits in front of the site as its DNS and network provider, so requests to chbmate.com pass through it.
  • Google — measures how the site is used, through Google Analytics. On every public page a tag reports the page you opened and the ordinary technical details a browser sends, including your IP address, from which Google derives an approximate location. It never receives your name, your email address, your billing history or the codes you look up.
    Advertising. We may also advertise the Service, through Google or a comparable network. An advertising tag works the same way as the measurement one: it sees which pages of this website a browser visited, so that an advertisement for the Service can be shown to that browser elsewhere, and the network may combine it with what it already knows. It is described here now so that this page does not have to change when it happens, and the limit above holds either way — an advertising network sees pages visited on this site, never the account behind them and never a code that was looked up. Sections 7 and 8 say how to switch both off.
  • Our hosting provider — runs the server the Service and its database sit on.

Each of those handles your information under its own terms and privacy policy. Beyond them, we may disclose information where the law requires it or to protect our rights, and may transfer it as part of a merger, acquisition or sale of assets. We do not sell your personal information and we do not share it for cross-context behavioral advertising.

5. How long we keep it

We keep what is described above for as long as your account is open, and afterwards for as long as we need it to support you, protect the Service against abuse, resolve disputes and meet our tax and legal obligations.

Payment records are kept indefinitely, including after an account is erased. They are the evidence of what was charged, when and why; disputes and chargebacks are raised long after the payment itself, and there are tax records to keep. A record deleted or edited would be no use to either of us at that point.

6. Access, correction and erasure

Email [email protected] from the address on your account to ask for a copy of what we hold about you, to have something corrected, or to have your account erased. We respond within 30 days.

Erasure closes your account and removes the identifiers we are able to remove. Records we need to keep stay with us for the reasons in section 5 — payment records above all. Asking us to erase your account is not a refund request and does not by itself stop a subscription — use Cancel plan on your subscription page to do that.

7. Cookies

The Service sets two cookies of its own. chbmid holds a session identifier and nothing else, is marked Secure and HttpOnly with SameSite Lax, and is not kept after your session ends; without it you cannot stay signed in. chblang remembers whether you are reading the site in English or Chinese, and holds nothing else. Cloudflare, which sits in front of the site (section 4), may set its own cookies to tell real visitors from bots; those carry no advertising purpose and nothing here reads them.

Google Analytics sets its own cookies, so that a return visit counts as the same visit rather than a new one. If we advertise the Service, the advertising tag described in section 4 sets cookies of the same kind, which is what lets an advertisement be shown to a browser that has been here before. Nothing on this site reads either set, and neither carries anything about your account.

There is no cookie banner. The Service is not offered in the markets whose rules require one (section 1), and asking a question we would ignore the answer to would be worse than not asking it. What we offer instead works without being clicked: a browser sending a Do Not Track or Global Privacy Control signal gets no analytics tag and no advertising tag at all — they stop before they load, on every page, for everyone (section 8). Blocking cookies for this site, or Google's own opt-out add-on, does the same thing from the other end.

8. Do Not Track

We honor both signals, and honoring them is the whole of our answer to the question a cookie banner asks. When your browser sends a Do Not Track or Global Privacy Control signal, the tags described in sections 4 and 7 stop before they load: no measurement is reported for your visit, and no advertising tag runs. It is done in the page itself rather than by asking Google to respect the signal, and it applies to every page of this site, whether you are signed in or not. Nothing else here follows you across other websites.

Under California law a Global Privacy Control signal is also an opt-out request, and this is how we act on it — automatically, for everyone, without your having to write to us (section 9).

9. California residents

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you may ask what personal information we have collected about you, ask for a copy of it, ask us to correct it, and ask us to delete it — the same requests as section 6, made the same way, answered within 30 days. We will not treat you differently for making one.

We do not sell your personal information for money, and we never have. California law also treats handing a browser's activity to an advertising network as “sharing for cross-context behavioral advertising”, and the advertising described in section 4 would be that if we run it. You can opt out of it three ways, none of which needs an account: send a Global Privacy Control signal from your browser, which we honor automatically on every page (section 8); block cookies for this site; or write to [email protected] and we will action it. We will not treat you differently for opting out. The categories we collect, why we collect them and how long we keep them are listed in sections 2 to 5.

10. Children

The Service is offered to trade professionals in the course of business and is not directed to children. You must be at least 18 to use it. We do not knowingly collect information from anyone under 13; if you believe a child has given us information, email [email protected] and we will delete it.

11. Security

The site is served over HTTPS only. Card and bank details never touch it. Passwords and reset codes are stored only as salted one-way hashes — there is no readable password to steal — and the session cookie is Secure and HttpOnly. Values that look like a secret are stripped before anything is written to our records. No system is perfectly secure, and we do not promise that one is.

12. Changes to this policy

We may update this policy. The date at the top of the page changes when we do, and the update applies from that date. Where an update also changes the terms, the terms carry their own last-updated date and take effect the same way — section 18 of the Terms of Service says how. Practices this page already describes as things we may do — the advertising in section 4 is the one — are not a change when they begin: they are written here in advance so that you can read them before they happen, and so that nothing has to be re-papered afterwards.

© 2026 CHB Mate Terms of Service Privacy [email protected]
Not legal or customs advice — verify against the official HTSUS.