Privacy Policy
Effective date: 23 August 2026
1. Who we are
LED Proposal is a SaaS platform for LED display professionals, operated by Bemazone Ltd, a limited liability company registered in Hong Kong, trading as LED Proposal. In this policy "we", "us" and "our" mean Bemazone Ltd, and "the Service" means the platform at led-proposal.com.
We are the data controller for the personal data described here. For any privacy question, or to exercise the rights in section 9, contact [email protected].
2. Accounts and organisations
The Service is used by organisations. Your account belongs to the organisation that created it, and administrators of that organisation can see your account details, the proposals you create, and your sign-in history. They can also change your permissions, reset your password, or deactivate your account.
This matters for your privacy: if your employer provides your account, your use of the Service is visible to them. We cannot restrict an organisation's access to its own users' activity.
3. What we collect
Information you give us
| Data | Why |
|---|---|
| Username and email address | To identify you, sign you in, and let you recover access |
| Password | Stored only as a salted one-way hash. We cannot read it |
| Company name, English name, Chinese name | Shown on the proposals and exports you generate |
| Phone, WhatsApp number, WeChat ID | Optional. Included as seller contact details on proposals |
| Company logo | Optional. Used to brand your proposals. Treated as a private account asset |
| Proposal content | Client names, project details, screen specifications and pricing you enter |
Information collected automatically
- IP address and browser type, recorded with sign-in attempts for security and abuse prevention.
- Timestamps of sign-ins, proposal generation and exports, used for rate limiting and usage statistics.
If you sign in with Google
Where Google sign-in is enabled, we receive your email address and basic profile information from Google to create or match your account. We do not receive your Google password, and we do not access your Gmail, Drive or contacts.
4. Cookies
We use strictly necessary cookies only. We do not use advertising or tracking cookies, and we do not embed third-party trackers, analytics scripts or advertising pixels of any kind. Because these cookies are required to operate the Service, they are set without asking for consent; you cannot sign in without them.
This is separate from the aggregated usage analysis described in section 6, which we perform ourselves on our own servers and which sets no cookies.
| Cookie | Purpose |
|---|---|
authToken | Keeps you signed in. HTTP-only, so page scripts cannot read it |
sessionId | Identifies your session so it can be ended |
| Session cookie | Server-side session, extended while you stay active |
_resetCtx, _verifyCtx | Short-lived. Carry you through password reset and email verification |
| Sign-in flow cookie | Short-lived. Protects the Google sign-in exchange |
led_cookie_notice | Remembers that you dismissed the cookie notice. Contains no identifier |
You can clear cookies in your browser at any time. Doing so signs you out.
5. How we use your data
- To provide the Service: authenticating you, generating proposals, producing Excel and PDF exports.
- To secure the Service: detecting failed sign-ins, applying rate limits, investigating abuse.
- To contact you about your account: verification, password resets, and notices about changes that affect you. These are transactional messages, not marketing.
- To keep the Service working: diagnosing errors and monitoring capacity.
- To understand how the Service is used, in aggregate — see section 6.
We do not sell your data, we do not use it for advertising, and we do not send SMS marketing.
6. Aggregated usage analytics
We may aggregate and anonymise usage data — including geographic region, screen dimensions, pixel pitch selections, cabinet brands, sending card preferences, and other configuration patterns — to produce industry insights, internal reports, and product improvements. Aggregated data does not identify any individual user, end customer, or specific project. Aggregations are constructed so that no fewer than five users contribute to any single output, which means individual configurations cannot be re-identified.
Free plan. By using the free plan, you grant us a non-exclusive, royalty-free right to include your anonymised configuration data in these aggregates.
Paid plans. Your individual configurations and project data are excluded from these aggregates. We use paid users' data only to operate the Service for you and as required by law. You may request further restrictions at any time.
Never included, on any plan: names, email addresses, company names, end-customer names, and contact details.
7. Who else processes your data
We use a small number of providers, each acting only on our instructions:
| Provider | Role |
|---|---|
| Supabase (PostgreSQL) | Hosts the database holding accounts and proposals |
| Hostinger | Hosts the application server |
| Brevo / SendGrid | Deliver account emails such as verification and password reset |
| Cloudflare | DNS and traffic delivery |
| Only if you choose to sign in with Google |
These providers may store or process data outside your country. Where that happens we rely on the safeguards our providers maintain for international transfers, including Standard Contractual Clauses where they apply.
8. How long we keep it
- Account data is kept while your account is active.
- Deactivated accounts are marked as deleted and can no longer sign in, but the underlying record is retained so that proposals remain correctly attributed. Ask us for full erasure using the address in section 1.
- Proposals are kept until you or your organisation's administrator deletes them.
- Security logs are kept only as long as they are needed for security and abuse prevention, and are deleted once they are not.
- Aggregated, anonymised data may be kept indefinitely, because it is no longer personal data.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, request deletion, object to or restrict processing, and receive a copy in a portable format. You can change most of your own details in Account Settings. For anything else, contact [email protected] and we will respond within 30 days.
If your account was created by your employer, some requests may need to go through them, since they control the account.
If you are in the EEA or UK and believe we have not handled your data properly, you may also complain to your local data protection authority.
10. How we protect your data
- Passwords are stored only as salted one-way hashes.
- Session cookies are HTTP-only, so scripts running in the page cannot read them.
- Traffic is encrypted in transit using HTTPS.
- Each organisation's data is isolated, and access is checked on the server for every request.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any relevant regulator where the law requires it.
11. Children
The Service is a business tool for working professionals. You must be at least 18 to hold an account, and we do not knowingly collect data from anyone under 13.
12. Changes to this policy
We may update this policy as the Service changes. The effective date at the top always reflects the current version, and we will tell you about significant changes before they take effect.
13. Contact
Bemazone Ltd, trading as LED Proposal
led-proposal.com
Hong Kong
Email: [email protected]