This statement follows the complete data lifecycle — Collection → Storage → Use → Sharing → Deletion — to systematically explain how your personal information is handled at each stage. Through full transparency across the entire process, we want you to clearly understand the complete journey of your data and your rights at every step.
1.1 Collection Principles
We adhere to four fundamental principles: lawfulness, fairness, necessity, and integrity. We collect information only to the minimum extent necessary to deliver our services.
1.2 Collection Categories
| Category | Specific Data Items | Collection Timing | Collection Method |
|---|---|---|---|
| Account Identity Data | Phone number, email, password, user ID | Registration/Login | User input |
| Profile Data | Nickname, avatar, gender, birthday, bio | User fills in | User submission |
| Usage Behavior Data | Page paths, click positions, dwell time, search queries | During service use | System log recording |
| Device Data | Device model, OS version, screen resolution, browser UA | Each visit | Automatic collection |
| Network Data | IP address, ISP, network type (WiFi/4G/5G) | Each connection | Automatic collection |
| Permission-based Data | GPS location, gallery images, camera footage, microphone audio | User triggers a feature | Collected with authorization |
| Transaction & Payment Data | Orders, amounts, payment methods, shipping addresses | Ordering/Payment | User submission + system generation |
1.3 Special Notes on Sensitive Data
Biometric data (e.g., fingerprint, facial features): We do not collect;
Precise location data: Obtained only with your explicit authorization; you may disable it anytime;
Contact list data: Obtained only when you proactively import; we do not upload it to servers (processed locally).
2.1 Storage Architecture
| Tier | Description |
|---|---|
| Cache Tier (Memory) | Temporary session data; auto-cleared when you log out |
| Database Tier (Disk) | Persistent structured data; stored encrypted |
| File Storage Tier (Cloud) | Unstructured files like images and videos; supports CDN acceleration |
| Backup Tier (Disaster Recovery) | Encrypted backups for disaster recovery; strictly limited access |
2.2 Storage Location
Primary Storage: Within the territory of China;
Backup Storage: If applicable, all within China-based compliant data centers;
Cross-Border Transfers: Not proactively transferred overseas. If business requires, we will conduct security assessments and obtain your separate consent.
2.3 Retention Periods
| Data Type | Default Retention Period | Legal/Business Basis |
|---|---|---|
| Core Account Information | Account duration + 3 years after cancellation | Cybersecurity Law |
| Transaction Records | 5 years after transaction completion | E-Commerce Law |
| Usage Behavior Logs | Most recent 12 months | Service optimization & security |
| User-Generated Content | Until user proactively deletes | User's decision |
| Device & Network Logs | Most recent 6 months | Security auditing |
| Location Data | Most recent 30 days (unless otherwise authorized) | Privacy-friendly default |
After expiry, data is automatically deleted or irreversibly anonymized.
3.1 Use Purpose Matrix
| Use Scenario | Data Categories Used | Processing Method | Legal Basis |
|---|---|---|---|
| Account Registration/Login | Account identity data | Identity verification, account creation | Contractual performance |
| Core Service Functions | Account identity + Profile + Usage behavior | Content display, request processing | Contractual performance |
| Personalized Recommendations | Usage behavior + Device data | Algorithmic analysis, interest modeling | Legitimate interest / Consent |
| Service Security | Network + Device + Usage behavior | Anomaly detection, risk identification | Legitimate interest |
| Product Iteration & Optimization | Usage behavior + Device + Network | Aggregation, A/B testing | Legitimate interest |
| Compliance & Auditing | All categories (as needed) | Retention, cooperation with investigations | Legal obligation |
| User Communication | Account identity data | Notifications, inquiry responses | Contractual / Legal obligation |
3.2 Data Use Red Lines
We commit not to use your data for:
Discriminatory decisions or price discrimination ("big data price gouging");
Unsolicited commercial marketing (spam);
Infringement on your dignity or legitimate rights;
Any illegal or unlawful activities.
4.1 Sharing Principles
All external data sharing is subject to the following prerequisites:
Necessity Review: Essential for service delivery;
Minimization Provision: Only the minimum data fields necessary are shared;
Contractual Constraints: All recipients sign data processing agreements with security standards no lower than ours;
User Notification: Prior notice and consent are obtained for major sharing scenarios.
4.2 Sharing Scenario List
| Recipient Type | Data Shared | Purpose | Control Measures |
|---|---|---|---|
| Payment Processors | Order amount, payment method, payment result | Transaction settlement | Encrypted transmission; no storage of sensitive payment data |
| Push Service Providers | Device ID, push token | Message notifications | Used only for push, no other purposes |
| Cloud Service Providers | User-uploaded files (images/videos) | Content storage & distribution | Data encryption, access restrictions |
| Analytics Providers | Aggregated/anonymized behavioral data | Product optimization | Only aggregated data; no individual identification |
| Regulatory/Judicial Authorities | Data as legally required | Legal compliance | Review legal documentation; limit disclosure scope |
| Other Third Parties | Data with your separate consent | Purpose you agreed to | Strictly follow authorized scope |
4.3 Prohibited Activities
We do not sell your personal information;
We do not transfer your personal information (except in mergers/acquisitions where the successor continues to uphold this statement);
We do not publicly disclose your personal information (except with your separate consent or as legally required).
5.1 Deletion Triggers
| Trigger Scenario | Description |
|---|---|
| You request account cancellation | Deletion process begins after identity verification |
| Retention period expires | System automatically triggers deletion or anonymization |
| You request specific data deletion | e.g., delete a single comment, clear history |
| Withdrawal of consent | Processing based on that consent ceases and data is deleted |
| Legal or regulatory requirement | Delete in compliance with lawful instructions |
5.2 Deletion Levels
| Level | Action | Timeline |
|---|---|---|
| Content-Level Deletion | Delete a single item or record (e.g., comment, search history) | Immediate (cache cleared within 1 hour) |
| Category-Level Deletion | Delete an entire category (e.g., all location records) | Immediate |
| Account-Level Deletion | Cancel account and delete all associated data | Within 7 business days after confirmation |
| Complete Purge | Overwrite from physical storage media | Performed quarterly |
5.3 Deletion Exceptions
Data may be retained temporarily in the following cases:
Legal retention periods have not yet expired;
Pending legal disputes or litigation;
Reasonably necessary to prevent fraud or abuse.
You may exercise your rights at every stage of the data lifecycle:
| Stage | What You Can Do |
|---|---|
| Collection | Choose whether to fill optional fields, grant sensitive permissions |
| Storage | Know where data is stored and for how long |
| Use | Disable personalized recommendations, turn off targeted ads |
| Sharing | Know who data is shared with and what is shared |
| Deletion | Proactively delete data, request account cancellation |
We implement the following technical measures to protect data throughout its lifecycle:
| Security Layer | Technical Measures |
|---|---|
| Transmission Security | TLS 1.3 encryption, certificate mutual authentication |
| Storage Security | AES-256 encryption, tiered key management, HSM protection |
| Access Security | Least-privilege principle, multi-factor authentication, auto-logout on session timeout |
| Operational Security | Full operation logging, real-time anomaly alerts, regular penetration testing |
| Personnel Security | Background checks, confidentiality agreements, privacy training |
| Incident Response | Data breach response plan, 24-hour escalation, legal reporting obligations |
Copyright © 2010 MIDDIA ceramic knife set ceramic knife set XML| Top