Privacy Policy

Last updated: September 16, 2026

This Privacy Policy describes how Claims Copilot, Inc., a Delaware corporation trading as "Lightsail Sourcing" ("Lightsail Sourcing", "we", "us" or "our"), collects, uses, discloses and otherwise processes information in connection with our business, our website and our services. Please read this Privacy Policy carefully. By accessing or using our website or services, you acknowledge that you have read and understood this Privacy Policy.

1. Who We Are and How to Reach Us

1.1. Claims Copilot, Inc. (trading as "Lightsail Sourcing") is the entity responsible for the information described in this Privacy Policy. Depending on the applicable law and the context of the processing, we may act as a "business", "controller", "service provider", "processor", or in an equivalent role.

1.2. Our business provides sourcing and procurement, quality control, inspection and testing, and product development services to United States companies that purchase goods from suppliers located in China and elsewhere.

1.3. You can reach us regarding this Privacy Policy or your information using the following contact details:

  • (a) by email at support@lightsail.global;
  • (b) by mail at Claims Copilot, Inc., Attn: Privacy, 2627 Hanover St, Palo Alto, CA 94304, United States.

1.4. Privacy Officer. For the purposes of Canadian privacy law (including the Personal Information Protection and Electronic Documents Act and Quebec's Law 25), our designated privacy officer with responsibility for our compliance is:

  • (a) Name / Title: Bruce Tan;
  • (b) Email: bruce@lightsail.global;
  • (c) Mailing address: as set out in Clause 1.3(b).

2. Scope and What This Policy Covers

2.1. This Privacy Policy applies to information we process in connection with:

  • (a) our website, web pages, portals and any online forms operated by us (collectively, the "Website");
  • (b) our sourcing, procurement, quality control, inspection, testing and product development services (collectively, the "Services"); and
  • (c) our marketing, sales and business development activities.

2.2. This Privacy Policy does not apply to:

  • (a) the information practices of our clients, suppliers, or any third party, including any third party whose website, platform or service you may access through a link or integration; or
  • (b) information that is not regulated as personal information under applicable law, including information that has been aggregated, de-identified or anonymized.

2.3. Where we process information on behalf of and under the instructions of a client (for example, information about that client's own customers or personnel provided to us to perform the Services), we generally do so as a service provider or processor, and the client's own privacy policy governs that information as against the relevant individuals. In such cases, this Privacy Policy describes our practices to the extent we determine the purposes and means of processing.

2.4. Nothing in this Privacy Policy is intended to grant any individual rights beyond those expressly required by applicable law.

3. Categories of Information We Collect

3.1. We collect the following categories of information, depending on how you interact with us. Not all categories apply to every individual.

3.2. Website and marketing data. When you visit the Website, contact us, request information, subscribe to communications, or otherwise engage with our marketing:

  • (a) identifiers and contact details, such as name, business email address, telephone number, employer, job title and mailing address;
  • (b) communications content, such as the contents of inquiries, requests, and correspondence;
  • (c) internet and network activity information, such as IP address, device and browser type, operating system, referring pages, pages viewed, and interactions with the Website; and
  • (d) marketing and lead data, such as your interests, the source through which you reached us, and your engagement with our communications.

3.3. Client personnel and representative data. In the course of providing the Services and managing our client relationships, we collect business contact and identifying information about our clients' employees, officers, agents and representatives, such as name, business contact details, job title, and the content of business communications.

3.4. Client confidential and business information. To perform the Services, we receive and process client business information, which may include product specifications, designs, drawings, samples, pricing, cost data, sourcing strategies, supplier information, product roadmaps, and other confidential or proprietary business information.

3.5. End-user personal data. Where a client provides us with, or instructs us to process, personal information relating to that client's own customers or end users (for example, in connection with product development, fulfilment, or quality-related matters), we may process that information solely as necessary to perform the Services.

3.6. Product development, quality control and testing data. In connection with sourcing, inspection, testing, and product development activities, we collect and generate data such as inspection results, test measurements and reports, defect and non-conformance records, supplier and factory performance data, photographs and images of goods and facilities, and related technical and operational records. This data may incidentally include information relating to individuals (such as the identity of personnel involved in an inspection).

3.7. Sensitive information. We do not seek to collect sensitive or special categories of personal information in the ordinary course of our business. Where any such information is provided to us, we process it only as necessary and as permitted by applicable law.

4. How We Collect Information

4.1. We collect information:

  • (a) directly from you, when you contact us, complete a form, correspond with us, or otherwise provide information to us;
  • (b) from our clients and their personnel, in connection with establishing and performing the Services;
  • (c) from suppliers, factories, laboratories, and other participants in the supply chain, in connection with sourcing, inspection, testing and product development;
  • (d) automatically, through cookies and similar tracking technologies when you use the Website (see Clause 9); and
  • (e) from third-party sources, such as business information providers, marketing partners, publicly available sources, and analytics providers.

4.2. We may combine information we collect from these different sources.

5. How and Why We Use Information

5.1. We use information for the following purposes:

  • (a) to provide, operate, perform, maintain and improve the Services;
  • (b) to communicate with you, respond to inquiries, and manage our client and business relationships;
  • (c) to operate, secure, personalize and improve the Website;
  • (d) for marketing, advertising, sales and business development, including sending communications about our Services (subject to your rights and choices);
  • (e) to conduct research, analysis, product development, quality assurance and testing;
  • (f) to protect our rights, property and safety and those of our clients and others, to prevent, detect and investigate fraud, security incidents and misuse, and to enforce our agreements;
  • (g) to comply with applicable law, legal process, and regulatory, customs, trade compliance and similar obligations; and
  • (h) for any other purpose disclosed to you at the time of collection or with your consent where required.

5.2. Aggregation, de-identification and derived data. To the maximum extent permitted by applicable law, we may aggregate, de-identify, anonymize and otherwise process information to create statistical, analytical, benchmarking, and derived data, insights and models. We may use, retain, disclose and commercialize such aggregated, de-identified and derived data for any lawful business purpose, including improving and developing our Services, without restriction and indefinitely, provided that we maintain such data in a form that does not reasonably identify an individual and do not attempt to re-identify it except as permitted by law.

5.3. Legal bases (where applicable). Where our processing is governed by a law requiring a legal basis, we rely, as applicable, on the necessity of the processing to perform or manage a contract, our legitimate business interests, compliance with legal obligations, and your consent where required. Where we rely on consent, you may withdraw it at any time, without affecting processing carried out before withdrawal.

6. How We Disclose and Share Information

6.1. We may disclose information as follows:

  • (a) Service providers and sub-processors. To vendors, contractors and service providers that perform functions on our behalf (such as hosting, IT, analytics, communications, professional advisers, inspection and testing partners, and payment and logistics providers), who are permitted to use the information only to provide services to us.
  • (b) Clients. To the client on whose behalf we perform the Services, and to other participants in a transaction or supply chain as necessary to perform the Services.
  • (c) Suppliers and supply-chain participants. To factories, suppliers, laboratories and logistics providers as necessary to source, inspect, test, develop or deliver goods.
  • (d) Legal, compliance and safety. To courts, regulators, customs and government authorities, and other third parties where we believe disclosure is necessary or appropriate to comply with applicable law or legal process, to respond to lawful requests, or to protect the rights, property or safety of Lightsail Sourcing, our clients, or others.
  • (e) Business transfers. In connection with, or during negotiations of, any merger, acquisition, financing, reorganization, sale of assets, or other corporate transaction, in which case information may be transferred to the counterparty and its advisers as part of the transaction.
  • (f) With consent or direction. To any other party with your consent or at your direction.

6.2. We do not sell personal information in exchange for money in the traditional sense. Certain disclosures for cross-context behavioral advertising or analytics may, however, be treated as a "sale" or "sharing" under some laws. See Clause 8 for the rights available to you and how to exercise them.

6.3. We may disclose aggregated, de-identified and derived data (as described in Clause 5.2) to any third party for any lawful purpose.

7. Cross-Border Data Transfers

7.1. We are based in the United States, and our clients are primarily located in the United States. Our sourcing, inspection, testing and product development activities involve suppliers, factories, laboratories and personnel located in China and other countries.

7.2. As a result, information may be collected in, transferred to, stored in, accessed from, and processed in the United States, Canada, China, and other jurisdictions whose data protection laws may differ from, and may be less protective than, the laws of the jurisdiction in which you are located.

7.3. By providing information to us or using the Services, you acknowledge that your information may be transferred to and processed in these jurisdictions, including the United States and China. Where required by applicable law, we take steps intended to provide an appropriate level of protection for information transferred across borders, and, where required, we will provide notice of, or obtain consent for, such transfers.

7.4. For individuals in Quebec, we will, before communicating personal information outside Quebec, conduct any privacy assessment required by applicable law and take reasonably appropriate measures in the circumstances.

8. Your Privacy Rights

8.1. This Clause 8 describes rights that may be available to you depending on where you are located and the applicable law. We will honor rights to the extent, and only to the extent, required by applicable law. Verifiable requests may be made using the contact details in Clause 1.3 or as described in Clause 16.

United States — California (CCPA/CPRA)

8.3. Notice at collection. We collect the categories of personal information described in Clause 3 for the purposes described in Clause 5. We retain personal information as described in Clause 10.

8.4. Categories collected, disclosed, and sold or shared. In the preceding twelve (12) months, we have collected the categories of personal information identified in Clause 3. We have disclosed personal information to the categories of recipients identified in Clause 6 for business purposes. To the extent any of our analytics or advertising practices constitute "selling" or "sharing" of personal information as defined under California law, the categories that may be involved are identifiers and internet or network activity information. We do not knowingly sell or share the personal information of consumers under 16 years of age.

8.5. Consumer rights. If you are a California resident, subject to the limitations and exceptions in the law, you may have the right to:

  • (a) know and access the specific pieces and categories of personal information we have collected about you, the sources, the purposes, and the categories of recipients;
  • (b) delete personal information we have collected from you;
  • (c) correct inaccurate personal information;
  • (d) opt out of the "sale" or "sharing" of personal information and of targeted or cross-context behavioral advertising;
  • (e) limit the use and disclosure of sensitive personal information; and
  • (f) not receive discriminatory treatment for exercising your rights.

8.6. How to exercise. You may exercise these rights using the contact details in Clause 1.3 or as described in Clause 16. We will verify your request as required by law and may decline requests where an exception applies.

8.7. Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may require you to verify your identity directly with us or confirm that you have authorized the agent.

8.8. Appeals. Where required by applicable law, you may appeal a decision we make regarding your request by contacting us using the details in Clause 1.3.

Canada — PIPEDA and Quebec (Law 25)

8.10. Accountability. We are responsible for personal information under our control and have designated the privacy officer identified in Clause 1.4 to oversee our compliance.

8.11. Consent and purposes. We identify the purposes for which personal information is collected at or before the time of collection, and we collect, use and disclose personal information for those purposes and as otherwise permitted or required by law. Where consent is required, we obtain it, and you may withdraw consent subject to legal and contractual restrictions and reasonable notice.

8.12. Access and correction. Subject to the exceptions permitted or required by law, you may request access to the personal information we hold about you and request correction of inaccurate or incomplete personal information.

8.13. Cross-border transfers. As described in Clause 7, personal information may be transferred to and processed outside Canada, including in the United States and China, where it may be accessible to courts, law enforcement and authorities under the laws of those jurisdictions.

8.14. Quebec (Law 25). If you are in Quebec, additional rights and protections may apply, including the right to be informed of the use of automated decision-making and of cross-border transfers, and rights concerning the de-indexing and portability of personal information to the extent required by law. Requests and complaints may be directed to our privacy officer identified in Clause 1.4.

8.15. Safeguards and breach handling. We maintain safeguards as described in Clause 11 and will handle any breach of security safeguards, including any notification to affected individuals and regulators, in accordance with applicable law.

9. Cookies and Tracking Technologies

9.1. We and our service providers use cookies, pixels, tags, software development kits, and similar tracking technologies (collectively, "Cookies") on the Website to enable functionality, remember your preferences, measure and analyze traffic and usage, and support our marketing.

9.2. We use the following general categories of Cookies:

  • (a) strictly necessary Cookies, which are required for the Website to function;
  • (b) analytics and performance Cookies, which help us understand how the Website is used; and
  • (c) functionality and marketing Cookies, which support personalization and advertising.

9.3. Your choices. You can manage Cookies through your browser settings and, where offered, through any cookie preferences tool made available on the Website. Some browsers offer a "Do Not Track" or a Global Privacy Control signal; where required by applicable law, we will treat a recognized opt-out preference signal as a valid request to opt out of "sale" or "sharing". Disabling certain Cookies may affect the functionality of the Website.

10. Data Retention

10.1. We retain information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including to provide the Services, maintain business and transaction records, comply with our legal, tax, accounting, trade-compliance and regulatory obligations, resolve disputes, and enforce our agreements.

10.2. Retention periods vary depending on the type of information and the applicable requirements. When information is no longer required, we will delete, destroy or de-identify it in accordance with our retention practices and applicable law.

10.3. Nothing in this Clause 10 limits our right to retain and use aggregated, de-identified and derived data as described in Clause 5.2.

11. Security

11.1. We maintain administrative, technical and physical safeguards designed to protect information against unauthorized access, use, disclosure, alteration and destruction, taking into account the nature of the information and the risks involved.

11.2. No method of transmission or storage is completely secure, and we cannot and do not guarantee the absolute security of information. To the maximum extent permitted by applicable law, we are not responsible for any unauthorized access to, or loss, alteration or misuse of, information that occurs despite our reasonable safeguards or as a result of factors beyond our reasonable control. You are responsible for maintaining the confidentiality of any credentials used to access the Website or the Services.

12. Children's Privacy

12.1. The Website and the Services are directed to businesses and are not intended for, or directed to, children. We do not knowingly collect personal information from children as defined under applicable law. If we become aware that we have collected personal information from a child in a manner inconsistent with applicable law, we will take steps to delete it.

13. Third-Party Links and Services

13.1. The Website and the Services may contain links to, or integrations with, websites, platforms and services operated by third parties. We do not control and are not responsible for the privacy practices or content of any third party.

13.2. The inclusion of any link or integration does not imply endorsement. Your use of any third-party website or service is at your own risk and is governed by that third party's terms and privacy policy. To the maximum extent permitted by applicable law, we disclaim all responsibility and liability arising out of or relating to any third-party website, platform or service.

14. Limitation of Liability and Disclaimers

14.1. To the maximum extent permitted by applicable law, the Website and the information made available through it are provided on an "as is" and "as available" basis, without warranties of any kind, whether express, implied or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.

14.2. To the maximum extent permitted by applicable law, in no event will Lightsail Sourcing or its affiliates, or their respective officers, directors, employees, agents, or service providers, be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for any loss of profits, revenue, data, goodwill or business opportunity, arising out of or relating to this Privacy Policy, the Website, or our privacy practices, whether based in contract, tort (including negligence), strict liability or any other theory, even if advised of the possibility of such damages.

14.3. To the maximum extent permitted by applicable law, the total aggregate liability of Lightsail Sourcing and the parties described in Clause 14.2 arising out of or relating to this Privacy Policy or our privacy practices will not exceed one hundred U.S. dollars (US$100).

14.4. Nothing in this Privacy Policy excludes or limits any liability or right that cannot be excluded or limited under applicable law, and nothing in this Clause 14 is intended to limit any privacy rights that applicable law grants to you and that cannot be waived.

15. Changes to This Policy

15.1. We may update this Privacy Policy at any time and in our sole discretion. When we make changes, we will revise the "Last Updated" date above and, where required by applicable law, provide additional notice.

15.2. Each version of this Privacy Policy is identified by its effective date and version number. The version in effect at the time of the relevant processing governs that processing. Your continued use of the Website or the Services after an update takes effect constitutes your acknowledgment of the updated Privacy Policy, to the extent permitted by applicable law.

16. How to Contact Us and Submit a Request

16.1. If you have questions, concerns or requests regarding this Privacy Policy or your information, you may contact us:

  • (a) by email at support@lightsail.global;
  • (b) by mail at Claims Copilot, Inc., Attn: Privacy, 2627 Hanover St, Palo Alto, CA 94304, United States; and
  • (c) for Canadian and Quebec matters, by contacting our privacy officer identified in Clause 1.4.

16.2. To help us respond, please provide sufficient detail to allow us to understand and verify your request. We will respond within the timeframes and to the extent required by applicable law. Where permitted by law, we may decline a request or charge a reasonable fee for manifestly unfounded, excessive or repetitive requests.

16.3. If you are in Canada and are not satisfied with our response, you may have the right to contact the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.