DocuConsist (docuconsist.com) is a document-consistency and freight-check tool for China cross-border sellers. This policy explains how we handle your data. Version / last updated: 2026-08-05.
1. What we store
We only keep analysis results after you sign in, to power cross-session cumulative features. What we store is structured fields and aggregated results, not the original files:
- Account: email (for sign-in and notices). Passwords are stored as scrypt hashes; the server never holds plaintext.
- Bill batches (bills): carrier name, bill number, bill period, source file name, total orders, total deviation (base-currency basis), base currency, analysis mode, status, full aggregated result (JSONB), created / completed time.
- Bill line items (bill_items): tracking no. (tokenized, no plaintext PII), platform order id, channel, destination port, actual weight, original currency, freight (original / base basis), deviation amount, is abnormal.
- Consent record: the policy version you accepted, the time, and the IP at acceptance.
2. What we do not store
- Your uploaded original PDF / image / Excel is never written to our storage; it is processed in memory / temp and deleted as soon as results are produced, and temp directories are cleaned periodically.
- Personally identifiable info such as tracking numbers is stored as a token, never in recoverable plaintext.
3. Why we store it
To provide cumulative features such as "total overcharged across carriers" and "trend" (L2) that need data across multiple analyses. You can export or delete it anytime from your account page.
4. How long we keep it
Rolling 24-month deletion: bill data older than 24 months is cleaned automatically per settings.retention_months (cascading to line items / exchange rates / summaries). You can also delete manually at any time.
5. Redaction
- You can redact sensitive fields in the browser before upload; redaction happens locally, so the original never enters the analysis result.
- Your own identifiers (company / address / consignee, etc.) can be tokenized; the carrier name is kept in plaintext — because a finding like "worst carrier" is only actionable if the counterparty name is known; otherwise it loses its value.
6. Third-party services
In rare cases (only when local parsing fails) we call a cloud OCR fallback service to recover the text from a scan. That result is used purely to read characters and never to make any call; we do not name the specific vendor. Apart from that, we do not share your data with any third party.
7. Your rights
- Export: one-click export of all your structured data (JSON) from your account page.
- Delete: request deletion of all your bill data from your account page (with a second confirmation). Deletion excludes the account and orders (financial records) and the consent record (needed as evidence).
- Withdraw consent: deleting your account is treated as withdrawal; existing analysis data follows the deletion flow above.
- Contact: privacy@docuconsist.com
8. Cross-border & compliance
- Data location: currently Alibaba Cloud (Hangzhou, China) Function Compute + PostgreSQL.
- EU users (GDPR): you have the right to access / rectify / erase / restrict / port your data; cross-border transfer relies on Standard Contractual Clauses. Contact dpo@docuconsist.com.