Privacy Policy

Last updated: November 18, 2025

1. Introduction

FusionTech Exports ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

2. Information We Collect

2.1 Account Information

When you create an account or sign in, we collect:

  • Email address
  • Display name and username (if provided)
  • Profile picture/avatar URL
  • Authentication provider information (Google, Twitter, or manual email/password)

2.2 OAuth Provider Information

When you sign in using Google or Twitter OAuth:

  • We receive your email address, display name, and profile picture from the OAuth provider
  • We store a provider ID to link your account to the OAuth provider
  • We do not store your OAuth access tokens or passwords
  • We do not access any additional information beyond what you authorize during the OAuth flow

2.3 Usage Information

We automatically collect:

  • Login count and last login timestamp
  • IP address and browser information
  • Pages visited and actions taken on our platform

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your user account
  • Authenticate your identity when you sign in
  • Provide access to our services and features
  • Display your profile information (name, avatar) in the platform
  • Track your login activity for security purposes
  • Assign and manage user roles (admin, author, user)
  • Improve our services and user experience
  • Respond to your inquiries and provide customer support

4. Data Storage and Security

Your information is stored securely in our database:

  • User account data is stored in PostgreSQL database
  • OAuth provider links are stored separately in the user_providers table
  • Passwords (for manual accounts) are hashed using industry-standard encryption
  • We use secure authentication tokens (JWT) for session management
  • Refresh tokens are stored as httpOnly cookies for enhanced security

5. Third-Party Services

We use the following third-party OAuth providers:

  • Google OAuth: When you sign in with Google, your authentication is handled by Google. We only receive the information you authorize Google to share with us.
  • Twitter OAuth: When you sign in with Twitter, your authentication is handled by Twitter. We only receive the information you authorize Twitter to share with us.

Please review the privacy policies of these providers to understand how they handle your data.

6. Your Rights

You have the right to:

  • Access your personal information
  • Update or correct your account information
  • Delete your account (contact us to request account deletion)
  • Opt-out of certain data collection practices
  • Request a copy of your data

7. Cookies

We use cookies to:

  • Store authentication refresh tokens (httpOnly cookies for security)
  • Remember your preferences
  • Analyze site usage and improve our services

For more details, please see our Cookies Policy.

8. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at our contact page.