Privacy Policy
Last updated: August 28, 2026
This Privacy Policy applies to the independent Reach2Sell website, customer console, and the marketing automation services we provide, including integrations with merchant-operated websites, third-party commerce platforms such as Shopify, SHOPLINE, and Shoplazza, communications channels, and related systems (collectively, the “Services”). Reach2Sell is operated by Universal touch (Hong Kong) Limited and Lanchi Telecom (Hangzhou) Co., Ltd. within the scope described in this Policy (collectively, “we”, “us”, or “our”).
We respect the privacy of merchants and their customers. This Policy explains what information we process, why we process it, how we share and transfer it, how long we retain it, and how individuals can exercise their privacy rights. We process personal data only as necessary to provide the Services, follow merchant instructions, protect the Services, and comply with law.
1. Scope and our roles
Universal touch (Hong Kong) Limited provides Reach2Sell Services to entities outside mainland China and is the developer of the Reach2Sell app under the SHOPLINE developer account. Lanchi Telecom (Hangzhou) Co., Ltd. provides the Services to mainland-China entities. The applicable service provider is determined by the merchant’s verified region, contracting entity, and payment entity.
When a merchant connects a merchant-operated website or a third-party platform such as Shopify, SHOPLINE, or Shoplazza through an API, OAuth, webhook, file import, or another method, and imports or synchronizes customer data, the merchant generally determines the purposes and means of processing, and we act on the merchant’s instructions as a processor or service provider. Merchants must provide appropriate notices and obtain any consent or other lawful basis required for marketing, profiling, tracking, and international transfers.
For Reach2Sell account administration, business verification, subscriptions and billing, security logs, support communications, and our own legal obligations, we may act as an independent controller. The legal terminology may differ by jurisdiction, but the limits on our use of data described in this Policy remain the same.
2. Information we process
Depending on the features a merchant enables and the platform permissions the merchant grants, we process the following categories of information:
- Account and merchant information: name, business email, phone number, company or team information, store name and domain, language and region, login and verification information, subscription and billing status, support communications, and information submitted by the merchant. Full payment card credentials are normally processed directly by payment providers and are not intended to be stored in Reach2Sell.
- Website, platform, and store information: store identifiers, domains, basic settings, granted access scopes, API credentials or OAuth tokens for merchant-operated websites or integrated platforms such as Shopify, SHOPLINE, and Shoplazza, and the product, customer, order, checkout, fulfillment, refund, and related event data that the platform actually provides and the merchant authorizes us to read.
- Merchant customer information: platform customer identifiers, names, email addresses, phone numbers, addresses or regions, languages, tags, subscription and opt-out status, order and product details, transaction status, discounts, source and marketing attribution, and customer records lawfully imported by the merchant.
- Marketing configuration and content: segments, templates, email or SMS content, automation flows, sender settings, audiences, schedules, A/B assignments, and other configurations created in the Services.
- Delivery and engagement data: email addresses or phone numbers used as destinations; accepted, sent, delivered, failed, and unsubscribe status; and email opens, link clicks, redirect destinations, timestamps, IP addresses, browser or device information used to provide campaign analytics to the merchant.
- Technical and security data: access times, IP addresses, browser and device types, request and error logs, security events, session identifiers, and abuse-prevention data. We use cookies or local storage that are necessary for login, security, language, and core functionality. If we introduce non-essential analytics or marketing tracking, we will provide additional notice and obtain consent where required.
3. Sources of information
- Merchants, merchant staff, or authorized users when they register, complete business verification, import customers, create marketing content, or contact support.
- Merchant-operated websites and integrated platforms such as Shopify, SHOPLINE, and Shoplazza, including their APIs, webhooks, authorization, and app installation flows, after the merchant grants access.
- Merchant customers when they receive marketing messages, click links, unsubscribe, or interact with a merchant’s store.
- Communications, cloud infrastructure, security, logging, payment, and support providers when they perform services for us.
4. Purposes and legal bases
We use personal data only for the purposes described in this Policy and based on performance of a contract, consent, our legitimate interests, a merchant’s lawful instructions, or compliance with applicable law. These purposes include:
- Creating and maintaining accounts, connecting stores, synchronizing authorized data, and providing customer management, templates, campaigns, automation, delivery records, and analytics.
- Sending email, SMS, or other enabled communications as configured by the merchant, and performing segmentation, RFM analysis, A/B assignment, automated triggers, and attribution.
- Maintaining subscription, unsubscribe, and suppression status to prevent messages from being sent to recipients who should not be contacted.
- Providing customer support, troubleshooting, service notices, and subscription and billing administration.
- Protecting accounts and the Services, verifying platform signatures, preventing fraud, abuse, and unauthorized access, and conducting audits and incident response.
- Responding to data access and deletion requests, complying with regulatory, tax, accounting, and other legal obligations, and establishing, exercising, or defending legal claims.
5. Marketing consent, opt-outs, and tracking
Merchants are responsible for ensuring that customer data they collect, import, or use for marketing is covered by the notice, consent, or other lawful basis required by applicable law. Merchants must respect channel preferences, opt-outs, and choices not to sell or share data. Reach2Sell uses platform-provided or merchant-maintained email and SMS subscription and suppression status to limit sending.
Email open and click tracking provides campaign performance information to merchants and may involve pixels, redirect links, IP addresses, and device data. Merchants must disclose this tracking in their customer-facing notices and obtain consent where required. Standard store events do not by themselves establish consent to marketing or tracking.
6. Automation, segmentation, and artificial intelligence
Reach2Sell can help merchants create customer segments, scores, and automated journeys based on purchase recency, frequency, value, engagement, tags, and store events. These features support marketing operations and are not used by us to make decisions that have legal or similarly significant effects on individuals. Merchants remain responsible for reviewing and deciding how to use the results.
We do not use merchant or customer data from merchant-operated websites or integrated platforms such as Shopify, SHOPLINE, and Shoplazza to train, fine-tune, or improve general-purpose artificial intelligence or machine-learning models for other customers without explicit merchant authorization and, where required by applicable platform terms, prior platform approval.
7. Sharing and service providers
We do not sell or rent merchant or merchant-customer personal data, and we do not permit third parties to use it for independent marketing unrelated to the Reach2Sell Services. We share information only as necessary in the following circumstances:
- With merchants and their authorized users so they can view, export, and manage their own store, customer, and marketing data.
- With merchant-authorized integrated platforms such as Shopify, SHOPLINE, and Shoplazza to support app authorization, webhooks, privacy requests, and integration functionality.
- With email, SMS, and other communications providers to deliver messages, return delivery status, and process unsubscribes.
- With contractually bound cloud hosting, database, storage, content delivery, security, logging and monitoring, payment, and customer-support providers as necessary to provide the Services. We require them to process data on our instructions and apply appropriate confidentiality and security measures.
- With authorities or professional advisers where required by law, regulation, or court order, or to protect users, the public, and our lawful rights.
- With relevant parties to a merger, acquisition, reorganization, or asset transfer, subject to appropriate confidentiality and continuing protection obligations.
8. International transfers
Reach2Sell’s principal operating entities are not established in the European Economic Area. To serve cross-border merchants, information may be processed in Singapore and in other countries or regions where we or our service providers operate. Data protection rules in those locations may differ from those at the place of origin.
Where required by applicable law, we use an appropriate transfer mechanism, such as an adequacy decision, standard contractual clauses, contractual and organizational safeguards, and supplementary security measures proportionate to the risk. Merchants remain responsible for ensuring that they have a lawful basis to provide or authorize the transfer of customer data to Reach2Sell.
9. Retention, uninstall, and deletion
We retain information while an account or store integration is active and for as long as necessary for the purposes described in this Policy. The specific period depends on the data type, merchant configuration, contract, dispute handling, security, tax, accounting, and other legal requirements. When information is no longer needed, we delete it, anonymize it, or retain it in a restricted form.
For valid customer-deletion and store-deletion requests submitted directly or forwarded by integrated platforms such as Shopify, SHOPLINE, and Shoplazza, we verify the request and delete or de-identify relevant personal data within the period required by applicable law or the platform, generally within 30 days after receipt. Some integrated platforms send a store-deletion request approximately 48 hours after an app is uninstalled. Limited records that law requires us to retain may be kept with restricted use and access.
Residual copies in backups are removed through backup rotation and disaster-recovery procedures and remain isolated and protected until removal. Uninstalling the app does not override incomplete legal, billing, security, or dispute-related retention obligations.
10. Individual rights and request process
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or object to processing of their personal data; request portability; withdraw consent; or complain to a supervisory authority. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
A merchant customer should normally contact the merchant with whom they transact because the merchant controls its website and store data. Merchants can forward a verified request directly to us or use a privacy-request process provided by an integrated platform such as Shopify, SHOPLINE, or Shoplazza. Merchants or individuals may also contact us using the details below. We may request information necessary to verify identity, website or store ownership, authority, and the scope of the request.
11. Data security and incident response
We use technical and organizational measures proportionate to the risk, including data minimization, access and tenant boundaries, protection in transit, encryption of sensitive credentials, platform webhook signature verification, access and security logging, backups, monitoring, and confidentiality obligations for staff and providers.
No method of internet transmission or storage is completely secure. If a personal-data security incident occurs, we take steps to contain, investigate, and remediate it and notify affected merchants, individuals, relevant integrated platforms (such as Shopify, SHOPLINE, or Shoplazza), or authorities as required by applicable law and relevant contracts.
12. Children’s data
Reach2Sell provides services to merchants and is not directed to children. Merchants must not knowingly provide personal data about children who do not meet the applicable age requirement. If we identify such data, we will take appropriate steps to restrict or delete it.
13. Changes to this Policy
We may update this Policy to reflect changes to the Services, platform rules, or law. We will post the revised version on this page and update the date above. If a change materially affects individual rights or data use, we will notify merchants through the Services, email, or another appropriate channel and obtain renewed consent where required.
14. Contact us
For questions or complaints about this Policy, our data practices, or a privacy request, email the shared privacy contact for Universal touch (Hong Kong) Limited and Lanchi Telecom (Hangzhou) Co., Ltd. Include the relevant website or store domain, integrated platform, and request type in your message. We will respond after verifying identity and authority and within the period required by applicable law.
Privacy and data protection: operations@uni-interconnection.com