BIMENT Workplace Privacy Policy
Anhui Baimeng Technology Co., Ltd. ("BIMENT", "we", or "us") values the security of personal information and company business data. This policy applies to the BIMENT Workplace iOS app (Bundle ID: cn.biment.workplace), which is available only to employees authorized by BIMENT. Workplace accounts are created, authorized, suspended, and revoked by company administrators. The app does not offer public account registration.
You can read this policy before signing in and from My → About Workplace. If you do not agree, do not sign in or use the app and contact your company administrator.
1. Data controller
- Data controller: Anhui Baimeng Technology Co., Ltd.
- Registered and contact address: No. 948 Fuyang North Road, Luyang District, Hefei, Anhui, China
- Privacy, support, complaint, and report email: service@biment.cn
- Website: https://www.biment.cn
- Service hours: 9:00–17:00 China Standard Time
2. Scope and principles
We process information as necessary to authenticate employees, enforce permissions, manage customers and orders, handle inventory and after-sales work, support finance operations and content management, maintain security audit trails, and diagnose failures. We do not sell personal information, display third-party advertising, perform cross-app or cross-site tracking, or create advertising profiles from Workplace data.
Customer, order, payment, inventory, repair, content, and report data shown in Workplace is company business information. Employees may access and process it only within their assigned permissions and for authorized work.
3. Information we process
3.1 Employee accounts and authentication
We may process the employee's name, account, verified phone number or email address, verification-code status, session identifier, employee ID, assigned permissions, account status, and sign-in time. Passwords are submitted to BIMENT servers for verification and are never stored in plaintext in the app. Sign-in tokens are stored in the iOS Keychain.
If an employee enables Face ID, iOS returns only whether local authentication succeeded. BIMENT does not receive, store, or upload facial features. Face ID unlocks the local interface and does not replace an expired or revoked server session.
3.2 Devices, notifications, and security logs
To maintain device sessions, deliver business notifications, prevent unauthorized access, and troubleshoot failures, we may process an installation identifier, APNs push token, device name, iOS and app versions, notification preferences, recent activity time, IP address, request time, endpoint and result, error information, and security audit records. We do not read an advertising identifier or use this information for advertising.
Employees can disable business notifications and review or revoke device sessions from My → Sign-in Protection. System notification permission can also be disabled in iOS Settings. In-app messages and tasks remain available when push notifications are disabled.
3.3 Customers, orders, delivery, and after-sales work
When employees perform authorized work, Workplace may process customer names, contacts, phone numbers, customer type and source, tags, assigned salesperson, recipient name, phone number, province/city/district and street address, together with product, SKU, price, quantity, promotion, order number, note, warehouse, shipment, delivery, return, refund, and after-sales status. When an employee uses address recognition, the original pasted text is parsed only on the device and is not stored. After employee review, only formal business fields such as recipient, phone number, region, and street address are submitted to BIMENT servers with the customer or order.
3.4 Payments, receivables, and invoices
To generate a Mini Program payment code, record company transfer or cash receipts, review payment evidence, and track refunds, receivables, and invoice applications, Workplace may process order amount, payment method and status, transaction identifier, company receipt account, proof image, refund result, invoice title, tax number, email, and invoice file. A payment start or client response is not treated as settlement; final status relies on a trusted provider result and server verification.
3.5 Products, inventory, serial numbers, and repair data
To manage products, inbound and outbound inventory, transfers, warranties, and repairs, Workplace may process product and SKU information, product images, barcodes, warehouse and quantity, serial numbers, inventory movements, linked customer and order data, problem descriptions, service conclusions, shipping information, and photos actively selected by employees.
When an employee scans a product code, barcode, or serial number, the camera frame is recognized on the device and no scanning video or photograph is saved or uploaded. The app uses the iOS system photo picker and reads only images actively selected for the relevant task.
3.6 Content operations and business analytics
Authorized employees may review community content and edit news or FAQ material. Workplace may process public author information, text, images, comments, reports, moderation reasons, versions, and publication status. Dashboards and reports may display order, customer, product, salesperson, receipt, receivable, inventory, and profit data within server-enforced permissions.
3.7 Local storage
The app stores sign-in tokens in the iOS Keychain and stores the Face ID setting, interface preferences, and necessary business drafts in app-specific storage. Drafts are separated by employee account and service environment. Signing out clears business drafts and revokes the current device session. Deleting the app clears local data but does not automatically delete business records that BIMENT must retain for legal, accounting, security, or operational purposes.
4. System permissions
| Permission | Purpose | Effect if denied | | --- | --- | --- | | Face ID | Unlock the local Workplace interface after the employee enables it | The employee can continue to sign in with account credentials and verification codes | | Camera | Scan product codes, barcodes, or serial numbers | Codes can be entered manually | | Selected photos | Upload repair, serial-number, or business-evidence images selected by the employee | The related image cannot be submitted; other functions remain available | | Notifications | Receive order, task, after-sales, and business reminders | Messages and tasks remain available inside the app | | Network | Access BIMENT business services and synchronize authorized data | Online business functions are unavailable |
Workplace currently does not request location, contacts, SMS reading, call history, microphone, Bluetooth, or advertising-tracking permission.
5. Service providers and disclosures
The iOS client uses Apple system frameworks and contains no advertising, analytics, or social-platform SDK. We may use these service providers to deliver the authorized business functions:
| Provider | Purpose | Information that may be processed | | --- | --- | --- | | Apple / APNs | Deliver business notifications to employee devices | Push token, app identifier, notification content, and delivery result; see https://www.apple.com/legal/privacy/ | | Alibaba Cloud / ECS, SMS, and email | Host BIMENT services and deliver verification or security messages | Employee account, phone or email, notification content, business data, uploaded files, and necessary logs; see https://terms.aliyun.com/legal-agreement/terms/suit_bu1_ali_cloud/suit_bu1_ali_cloud202107091605_49213.html | | WeChat Pay and other payment providers | Generate customer payment access and query payment or refund results | Order identifier, amount, payment or refund state, and necessary transaction information | | Logistics, banking, and invoice-service providers | Complete shipment, receipt verification, or invoicing requested by an employee | Information necessary for the relevant order, recipient, shipment, payment, or invoice |
We do not disclose personal information to other parties except to complete an authorized task, meet a legal obligation, protect lawful rights, or as otherwise permitted by law. We will assess material changes to providers, purposes, or data scope and update this policy before applying them.
6. Storage location and retention
Workplace business data is generally processed and stored in mainland China. Employee account and permission information is retained until the employment or cooperation relationship and necessary settlement or audit matters are complete. Transaction, payment, delivery, return, invoice, and after-sales records are retained as required by applicable law and company accounting rules. Network and security logs are generally retained for at least six months. Verification codes usually expire within five minutes. Backups are deleted on a rolling schedule.
When a retention period ends, we delete or anonymize personal information. If law, auditing, dispute handling, or technical constraints require longer retention, we restrict processing to necessary storage and protection.
7. Security and access control
We use HTTPS, the iOS Keychain, server-side session validation, least-privilege access, role authorization, review of sensitive actions, device-session revocation, idempotent operations, audit records, log redaction, backups, and recovery measures. Employees must promptly contact an administrator when leaving the company, changing roles, losing a device, or detecting abnormal access.
8. Access, correction, and account administration
Employees can view their account and permissions in My and correct authorized business data in the relevant workflow. Workplace accounts are not created inside the app and are not public consumer accounts that employees can delete themselves. Company administrators and HR processes handle account suspension, permission revocation, and employee-record correction.
Employees can select “Withdraw Local Privacy Consent” from My → About Workplace to sign out immediately and clear the local session, drafts, and device preferences. The policy must be accepted again on the next launch.
Employees, customers, partners, and other individuals may contact service@biment.cn to request access, a copy, correction, supplementation, or deletion of personal information, an explanation of our rules, or complaint handling. We verify identity and respond within the period required by applicable law.
9. Children
Workplace is available only to authorized employees and does not provide registration or consumer services to children. Employees must not enter children's personal information unless it is necessary for an authorized business task and lawfully handled.
10. Updates
If functions, permissions, providers, or processing rules materially change, we will update this policy and notify employees through the app, company channels, or another appropriate method. We will provide any additional notice or obtain consent required by law before new processing begins.
11. Contact us
- Data controller: Anhui Baimeng Technology Co., Ltd.
- Address: No. 948 Fuyang North Road, Luyang District, Hefei, Anhui, China
- Privacy, support, complaint, and report email: service@biment.cn
- Service hours: 9:00–17:00 China Standard Time
