As a buyer using TokoAI, the data that matters most is yours — your identity and what you want to source. This page explains, plainly, how we keep that private, where supplier data comes from, and what control you have over your information.

1. Your identity and contact stay private

The core of our model: your identity and contact stay private until you authorize sharing. What you want to source is shared with suppliers so they can judge fit — but they don't learn who you are or how to reach you until you authorize us to share your contact. Until then, they can see your sourcing request, not your identity.

This is deliberate. It keeps you in control of who reaches you, and it means a supplier can't learn your identity or contact you outside the channel before you're ready.

2. Where supplier data comes from

The suppliers we match are drawn from public web information — customs import records, global trade-show exhibitor lists, government procurement awardees, and public company contact pages. Sources are cross-validated, each with a traceable origin, and the supplier base is one we build and maintain ourselves. We reach those suppliers over email and collect their responses; you never handle their raw contact files.

3. We send from our own domain — your mailbox stays isolated

All outreach to suppliers is sent through our own sending domain and infrastructure. We never use your mailbox or domain to send. Your inbox and sender reputation stay fully isolated from any sending activity, so your own email is never exposed to the suppliers we contact.

4. You control your data: opt-out and deletion

You can step away at any time:

5. Lawful basis and traceability

Supplier contact data is collected from public sources on a legitimate-interest basis (GDPR Art. 6.1(f)), with a clear opt-out on every send. Personal-data handling follows the same standard we apply to any identifiable individual: lawful basis, traceable origin, opt-out, and deletion on request. We do not claim a personal email is "not personal data."

In one sentence

TokoAI's privacy principle for buyers: your identity and contact stay private until you authorize sharing; suppliers see your sourcing request but not your identity; supplier data comes from public sources; we send from our own domain so your mailbox stays isolated; you can opt out or request deletion at any time. That is the foundation of how we handle your data.

This page describes our data-handling practice and does not constitute legal advice. For jurisdiction-specific questions (e.g. GDPR in the EU), consult legal counsel.

Related: About · Service · How we verify suppliers

Questions about your data or privacy? Email us and we'll explain how your information is handled.

toko@51toko.com

For human assistance, email 18049700567@163.com

FAQ

Is the email outreach compliant? Will we get complaints?

We follow GDPR and anti-spam (CAN-SPAM) requirements: ① every send identifies the real sender and includes an unsubscribe that takes effect immediately; ② data comes only from public information and legally authorized channels; ③ outreach cadence is restrained — no blast-style mass sending; ④ people who explicitly opt out are never contacted again. Compliance is the floor of the service, not optional.

How do you verify a supplier's contact before reaching out?

We only use contact points collected from public sources — a company's own website, trade-show directory, or public business registry — never guessed or machine-constructed addresses. Each address is checked for a real, reachable path before we send on your behalf, and the source is recorded so it can be traced. When a supplier we found responds, it comes from a real, checkable source you can verify yourself.

Total visits