Last updated: August 2026
When you create an account: your name, company and country, so we know who we are dealing with. Subscribers are also asked, once, about the size of their company and what they intend to use the data for. We also ask, optionally, how you heard about us, and we record the website that referred you if there was one — the site name only, such as "google.com", never the page or the search you came from. Both are used to understand which channels bring people to us, and neither is shared.
When you buy a report or subscribe: your name, email address and order details. Payment card details are collected and processed by Stripe on Stripe's own secure checkout page — they never reach our servers, and we do not store them. Stripe returns to us only the billing name and country shown on your account, plus identifiers for your subscription.
When you browse: our hosting provider's standard server logs (pages requested, approximate location, device type). Our public pages also carry Google's advertising tag, which sets cookies used to measure how our own advertising performs. It is deliberately absent from the search results, company profile, declaration and sign-in pages, so what you look up inside the service is never sent to Google. The tag is further configured to report only the page address itself, with the query stripped out, so no search term, email address or return link can leave in a URL. If you are in the EU, the UK or Switzerland, we send Google a "consent denied" signal by default and no advertising cookies are set for you at all. We run no other third-party analytics.
When you create an account, we send a single conversion event to Google Ads so we can measure whether our advertising led to the signup. The event contains no personal information — no name, no email address, and no search activity.
When you follow a link from an email we sent you: we record that the link was followed, and the country the request came from — the country only, never a town or an address. It tells us whether a message reached a person or was opened by an automated security scanner, which is the difference between a reply worth waiting for and a machine. We do not store your IP address.
When you send us a message: the details you enter on the contact form — name, email, and any company details you choose to give — kept so we can answer you and refer back to the conversation. To keep the form free of automated spam we also store a one-way hash of your IP address, which cannot be turned back into the address itself, and use Cloudflare Turnstile to distinguish people from bots.
We don't sell your personal information, and we don't share it except with the service providers needed to operate the Service, each bound by their own privacy obligations: Stripe (payment processing), Brevo (email delivery), Supabase (database and sign-in), Vercel (hosting), Cloudflare (domain and bot protection) and Google (advertising measurement on our public pages only).
Our primary application database and application hosting are configured in Australia. Some service providers operate internationally, so certain information may also be processed or stored outside Australia.
The trade data in our database relates to companies and commercial shipments and is compiled from official Korean trade records.
Account and order data is kept while your account is active and as required for tax and legal purposes. You can request a copy of, correction of, or deletion of your personal information at any time.