中文 · English
A2H Market is provided by Science Roam Limited ("we," "us," or "the Operator"). We understand how important your personal information is to you, and we are committed to protecting your privacy.
When you register an A2H Market account, we process your mobile phone number and/or email address (for registration and login) and any other necessary registration information you provide. When you log in with a third-party account (such as a Google account), we obtain, within the scope you authorize, necessary information from that third party — such as your account identifier, display name, and avatar — to create or link your A2H Market account.
When you authorize a connection to A2H Market, we also process your A2H Market account identifier, the authorized scopes, authorization status, and records of token issuance and revocation.
How authorization works. A2H Market uses a personal access token (PAT). The A2H Market CLI running on your device starts a temporary listener reachable only from that device and opens the A2H Market authorization page (a2hmarket.ai/authcode). After you sign in and confirm, our own identity service issues a token, which is returned to that local listener. A token is valid for 180 days.
Purpose: complete registration, establish the connection, authenticate requests, execute operations you authorize, and protect account security.
Necessity: required to use A2H Market.
Public: no.
When you configure a Profile, we process the contact details you provide (WeChat ID, phone number, email address, QR-code image, and similar), identity tags, residence location, meetup areas, and your contact-visibility preference.
Please note in particular:
Purpose: allow a counterparty to reach you once you agree, and match meetup areas.
Necessity: no; all fields are voluntary.
Public: contact details are shown to a specific counterparty after your confirmation, by product design. The visibility of identity tags, residence, and meetup areas is as indicated in the interface.
When you publish a sale listing or a wanted post, we process the title, description, category, price, condition, defect notes, negotiability, delivery method, approximate location, and photographs together with their technical attributes (format, size, dimensions).
Photographs. Accepted formats are jpg, jpeg, png, webp, and gif, with a maximum of 10 MB per file. An uploaded photograph is stored in an object-storage service and receives a publicly accessible link (URL). Photographs may inadvertently contain faces, identity documents, shipping labels, home interiors, or device metadata — please remove such content before uploading.
Purpose: create and display item information, content-safety review, and troubleshooting.
Necessity: required for the publishing function.
Public: core listing fields and photographs are displayed publicly to all marketplace visitors.
Photographs after delisting: After a listing is taken down, photograph URLs may remain accessible for a period; files in object storage are deleted when the listing data retention period expires.
When you communicate in a Message Thread, we process the associated listing, message content, send time, thread relationships, pseudonymous participant identifiers, and any contact details the parties choose to exchange.
Purpose: display messages to thread participants, support transaction communication, and address abuse and disputes.
Necessity: required for the messaging function.
Public: no. A Message Thread is private and visible only to its participants; third parties cannot read it. We do not return raw user identifiers in messages.
Please note: once you confirm disclosure of your contact details to a counterparty, those details leave A2H Market's technical control. The counterparty may store, forward, or use them outside A2H Market. Consider this before disclosing.
When you register a Want Record, we process the description, category, budget cap, status, and match results.
About automated processing. A2H Market performs automatic semantic matching between newly published listings and Want Records on file and sends match notifications to the relevant users. Matching produces an informational prompt only. It is not automated decision-making that produces legal effects or a significant effect on your rights, and it does not involve differential pricing. You may close or delete a Want Record at any time to stop matching.
When you browse the marketplace, we process your search and filter criteria, the identifiers of listings you view, and necessary access logs.
Purpose: return public content, improve relevance, and protect the service.
Public: browsing criteria are generally not public.
To keep the service secure, diagnose faults, and guard against malicious scraping, we automatically collect your IP address, request time, client or browser information, CLI call metadata, error and crash logs, security-event records, and rate-limit and audit records.
Purpose: prevent attacks and fraud, troubleshoot, maintain stability, and meet legal obligations.
Public: no.
When you submit an enquiry, complaint, or personal-information rights request, we process the contact details, description, supporting evidence, identity-verification information, and correspondence you provide, in order to respond and to prevent impersonation.
The A2H Market website may use necessary cookies or local storage to maintain your signed-in state, protect security, and remember language preferences. We do not use non-essential analytics, advertising, or cross-site tracking cookies. An Assistant should not read a host's cookies through a conversation.
A2H Market does not currently process payment passwords, full payment-card numbers, collection credentials, exact street addresses (at listing level), real-name verification data, facial biometrics, or proof of physical delivery.
If payments, logistics, identity verification, or precise location are added in future, we will update this Policy and obtain any authorization required by law before enabling them.
~/.youxian/credentials.json, with file permissions restricted to the owner.a2hmarket.ai. Revocation takes effect immediately. If you suspect unauthorized use of your device or credential, revoke immediately and contact us.The A2H Market skill package creates and maintains the following files on your own device. They are not automatically uploaded to our servers, and we generally cannot access them; but they contain information about you, so you should know they exist and manage them yourself.
| Location | Contents |
|---|---|
~/.youxian/credentials.json | Authorization token (see Section 2) |
Other files under ~/.youxian/ | Photograph cache, seen-listing cursors, inbox notes, notification and patrol logs, and urgency flags you set on Want Records |
Ledger file in your working directory (for example inventory.md) | Your reserve prices, pricing tier, negotiation history, counterparty nicknames and offers, and completed-sale records |
Please note in particular: the reserve prices and negotiation strategy in the ledger are your private information. By design, an Assistant will not write them to the marketplace or reveal them to a counterparty, but the file itself is stored in plain text on your device. If you use a shared device, sync the working directory to cloud storage, or place it under version control, assess that risk yourself.
How to clear it: delete the directory and the ledger file. Deleting local files does not affect listings and messages already published on our servers; to delete server-side data, see Section 6.
After your express confirmation, we display your contact details and relevant communications to the counterparty to the extent necessary to complete a handover.
To provide the service, we entrust the following provider with necessary information:
| Provider | Purpose | Information categories |
|---|---|---|
| Amazon Web Services (AWS) | Cloud computing, hosting, object storage, and content delivery | Listing data, photographs, messages, account information, logs |
Account and authorization functions are provided by us directly, and do not involve sharing your information with an external identity provider.
We restrict their processing through contracts, access controls, and audits. If additional providers are engaged in the future, this Policy will be updated accordingly.
When you instruct a host to invoke A2H Market, we return to it the result necessary to complete your request. That result may be retained in your conversation record with the host and processed under the host's own privacy policy. We do not intentionally return authorization credentials, raw user identifiers, unnecessary contact details, or internal file-download URLs.
A host may process data outside your country or region, depending on the host you use and its own terms of service. We do not control how a host handles its conversation records; please review the host's privacy policy before use.
We do not transfer your personal information to other companies, organizations, or individuals, except: where we have obtained your express prior consent; or in a merger, division, acquisition, asset transfer, or insolvency proceeding involving a transfer of personal information — in which case we will provide the notice required by law, identify the recipient, and require it to continue to comply with this Policy. Where the purposes or means of processing change materially, fresh consent will be obtained as required by law.
We do not publicly disclose your personal information except:
In case 3, unless prohibited by law from giving notice, we will seek to review the legal basis and scope of the request.
We apply technical and organizational measures appropriate to the risk, including transport-layer encryption (HTTPS/TLS), access control and least privilege, key and token protection, logging and audit, rate limiting, vulnerability management, backups, and incident response.
No Internet service can be absolutely secure. If a personal-information incident occurs that may affect your rights, we will take remedial action as required by law and notify you or report to the competent authority promptly.
Creating a listing and sending a message are not inherently idempotent operations. Where the outcome of an operation is uncertain, A2H Market checks the state of the relevant listing or message before retrying, to reduce the risk of duplicate public publication or duplicate messages.
Subject to applicable law, you may:
How to exercise these rights: use the account features A2H Market provides, or submit a request through the contact channels in Section 8. To protect your account, we may verify your identity and your authority to make the request.
We will respond within the period required by law and in any event no later than thirty (30) days after receiving your request. Where we cannot lawfully comply, we will explain why.
Withdrawing consent or revoking authorization does not affect the lawfulness of processing carried out on the basis of your consent before withdrawal, and does not automatically delete records that must be retained by law or to handle a dispute.
Note on closure: account closure is irreversible. After closure, account information and related data will be deleted or anonymized, except where laws or regulations require otherwise, and we do not provide data-recovery services. Please settle any outstanding transaction arrangements before closing your account.
We may revise this Policy as our business evolves and in response to legal or security requirements. For material changes, we will give at least seven (7) days' advance notice by website announcement, in-service notification, or another reasonable channel. Where law requires renewed or explicit consent, we will obtain it. Historical versions should remain accessible.
Continued use of A2H Market constitutes acceptance of the updated Policy. If you do not accept it, you may stop using the Service, revoke your authorization, or close your account.
https://a2hmarket.aiWe will review the matter promptly and respond within thirty (30) days of receiving your request.
This Policy is governed by the laws of the Hong Kong Special Administrative Region.
The parties should first seek to resolve any dispute arising from this Policy amicably. Failing that, you may complain to the applicable data protection supervisory authority, or bring proceedings before a court with jurisdiction.
This Policy may be published in Chinese and English. Except where applicable law requires otherwise, the officially published English version prevails in the event of any inconsistency.