Privacy Policy
Effective 2026-09-08 · Only the data handling that actually happens is listed here.
In the event of any discrepancy between the English and Chinese versions, the Chinese version shall prevail.
What we collect
(1) your phone number or email address (for signing up, signing in and service notices: by default a 6-digit code goes to your phone; the email-and-password route is kept for existing accounts); (2) the photos you upload — products, the workshop, shipments or trade shows (used to generate your pages), together with any product catalogue, spec sheet or brochure you upload (PDF, Word, Excel, PPT: we read the specifications out of them so you have fewer questions to answer), along with the product and capability information you fill in and confirm in the questionnaire; (3) the WhatsApp number and email address you choose to enter (shown on your pages so buyers can contact you directly — inquiries do not pass through us, and we do not keep buyers' details); (4) visit counts and inquiry-button click counts on your pages (no personal information about visitors: there is no form and nothing is captured).
The original photos sit in our private storage (the addresses are not public). You can delete any of them at any time before the site is built; deleting the whole account and site is covered under “Export and deletion” below.
Your photos are only used to build your own site. Your site is public, so the product and workshop photos you upload will appear on those pages — that is exactly what they are for. Beyond that we do not use them for anything else: not on our case-study pages, not in marketing material, not in any outward display, and not given to third parties.
What we do not collect
We do not collect personally identifying information about visitors to your pages (there is no lead-capture form; visits and clicks are counted only); we never touch your bank card details (see Stripe below); and we do not sell data to anyone.
Third-party services
The AI model provider (OpenRouter): the photos and documents you upload, and the information you fill in, are sent there to be processed — to work out what you sell, to read the specifications out of your documents, to turn your records into pages, and to place your product images into a usage scene. This is an unavoidable step in generating your pages. Also: an SMS provider (to send the code when you sign in with a phone number — only the number and the code are sent), email delivery (Resend), payments (Stripe: card details go only to Stripe, we never touch them), infrastructure (Railway / Cloudflare), search data (Google Search Console), the optional Google one-click sign-in and the Cloudflare human check (Turnstile) at sign-in, and the visit statistics and ad-performance measurement on our own website (Google Analytics, Google Ads, X).
That last group runs only on edanic.com, our own website, and never reaches your pages. The pages we generate for you are published by a separate system and carry none of our statistics or advertising code — your visitors are not tracked by us or by an ad platform because you use us.
Export and deletion
You can export all of your data yourself as JSON at any time on the Billing page, or submit a request there to delete your account and data — after you submit it there is a grace period during which you can withdraw the request, and the page lists item by item what will be deleted and what will be kept. You can also email support@edanic.com and we will handle and confirm it within a reasonable time.
What we still keep after deletion: the payment and usage ledger (account id, site id, amount and period only — no personal information), which we need for tax and reconciliation; the audit trail of what we did to that account; the record of this deletion request itself (it is the evidence that we did delete, and when); the site headstone (site id and teardown time only); and one record of whether this phone number has used its free allowance — it stores only an irreversible hash of the number: it can tell whether the number has been used but cannot be turned back into the number itself. It is kept for one purpose only: a free site is one per number. The account row itself is anonymised: all personal information is cleared (including the phone number), leaving an empty shell for the ledgers above to point at. This list is shown to you item by item when you submit the deletion request on the billing page.
Accounts and sign-in
By default it is a phone number plus a 6-digit code: signing up and signing in are the same action — if the code is right and there is no account yet, one is created on the spot. Codes are stored as a salted hash, never in the clear. The email-and-password route is still there (Google one-click sign-in also works): passwords are stored as an irreversible hash, we cannot see your original password, and forgotten passwords go through an emailed reset link.
Cookies and local storage
A sign-in session cookie (HttpOnly, 30 days); arriving from the “Built by Edanic” line in a customer site's footer writes a first-party referral cookie (e2_ref, 30 days, used only to know where you came from); and browser local storage remembers your sign-in email, the referral marker, the interface language, and the draft number of the site you have not finished building (the draft content lives on our servers; only a number is stored locally, so you can come back and carry on) — all of it so you have to fill in less next time.
On edanic.com, our own website, there are also cookies written by Google Analytics and by ad-conversion measurement (Google Ads, X), used to know which channel a sign-up came from and whether the ad spend worked. These are on our own website only; there are none on your pages — your visitors are unaffected. If you would rather not be counted, your browser's tracking protection or an ad blocker works on them just as well, and it does not affect your use of Edanic.