Privacy notice

This notice explains how CNC Compass handles information submitted with a sourcing inquiry.

Information we collect

When you submit an inquiry, we collect your name, work email, company, part requirements, quantity, material, process, tolerance, finish, the supplier or guide that led to the request, and when you accepted this notice and whether you allowed forwarding to suppliers. Drawing upload is not currently enabled.

When you use the agent chat, we process the briefs and messages you type so the agent can search the published supplier records and answer. The thread is kept on our server under an anonymous identifier, or under your account when you sign in, so you can reopen it. The text you type is also sent to the model service that reads it; where that service is operated by a third party, it is named here before general availability.

When you sign in with Google on the chat page, Google sends us your account identifier, email address, name, and profile picture. We use the identifier to attach your threads to your account and show your email so you can see which account is signed in. We do not post to or read anything else from your Google account.

Cookies and local storage

CNC Compass sets one cookie, and only after you choose to sign in on the chat page: a session cookie that keeps you signed in for 30 days. It is marked HttpOnly, is not readable by scripts, and carries no tracking identifier. Signing out removes it.

The chat page keeps the current thread in your browser's session storage so it survives a reload in the same tab. This storage is cleared when the tab closes and is never sent to a third party.

Google's sign-in script is loaded only after you select "Sign in with Google". From that point Google may set its own cookies under Google's privacy policy. Until then, no third-party script runs on this site.

We do not use analytics cookies, advertising cookies, or tracking pixels, so no cookie consent is requested. If that changes, consent will be asked for before any such cookie is set.

How we use it

We use the information only to review the sourcing requirement, identify potentially suitable suppliers, respond to you, prevent abuse, and maintain an operational record of the request. We do not sell inquiry contact information.

We share your requirement and contact details with suppliers only when you tick the separate forwarding box on the inquiry form. We then send them to no more than three suppliers we select, through the inquiry form on each supplier's Made-in-China.com storefront. We submit that form as a guest in your name, with your name, company, and email, so the supplier replies to you directly. Made-in-China.com does not create an account for you, but it may send marketing email to that address; you can unsubscribe from it there. If your email already has a Made-in-China.com account, the site asks for that account's login; we never log in as you, and send the same message from the CNC Compass account instead, with your contact details in the text. From that point the supplier and Made-in-China.com handle those details under their own privacy policies. We tell you by email which suppliers received your inquiry. Without the forwarding box ticked, your contact details stay with CNC Compass and we only reply with the suppliers that fit.

Storage and access

Inquiry data is sent through a server-side endpoint and stored in the private CMS. It is not exposed through the public content API. Access should be limited to people operating CNC Compass and service providers needed to host the system or deliver an explicitly configured notification.

Retention

Unsuccessful or inactive inquiries should be deleted after 12 months unless a longer period is required for an active commercial discussion, security investigation, or legal obligation. Chat threads are kept for 12 months after their last message, or deleted earlier when you ask.

Your choices

You may ask CNC Compass to correct or delete inquiry information by writing to [email protected] or by replying to the response you receive.

Security and international processing

No internet service can guarantee absolute security. Hosting and notification providers may process information in other countries. Production deployment must use HTTPS, restricted service tokens, access logging, rate limits, and encrypted platform secrets.

Last updated 2026-09-26. This pilot notice must be reviewed against the final operator identity, hosting region, and notification providers before public launch.