Privacy Policy
position:Home>Privacy Policy
Privacy Policy

This statement follows the complete data lifecycle — Collection → Storage → Use → Sharing → Deletion — to systematically explain how your personal information is handled at each stage. Through full transparency across the entire process, we want you to clearly understand the complete journey of your data and your rights at every step.


Stage 1: Data Collection

1.1 Collection Principles

We adhere to four fundamental principles: lawfulness, fairness, necessity, and integrity. We collect information only to the minimum extent necessary to deliver our services.

1.2 Collection Categories

CategorySpecific Data ItemsCollection TimingCollection Method
Account Identity DataPhone number, email, password, user IDRegistration/LoginUser input
Profile DataNickname, avatar, gender, birthday, bioUser fills inUser submission
Usage Behavior DataPage paths, click positions, dwell time, search queriesDuring service useSystem log recording
Device DataDevice model, OS version, screen resolution, browser UAEach visitAutomatic collection
Network DataIP address, ISP, network type (WiFi/4G/5G)Each connectionAutomatic collection
Permission-based DataGPS location, gallery images, camera footage, microphone audioUser triggers a featureCollected with authorization
Transaction & Payment DataOrders, amounts, payment methods, shipping addressesOrdering/PaymentUser submission + system generation

1.3 Special Notes on Sensitive Data

  • Biometric data (e.g., fingerprint, facial features): We do not collect;

  • Precise location data: Obtained only with your explicit authorization; you may disable it anytime;

  • Contact list data: Obtained only when you proactively import; we do not upload it to servers (processed locally).


Stage 2: Data Storage

2.1 Storage Architecture

TierDescription
Cache Tier (Memory)Temporary session data; auto-cleared when you log out
Database Tier (Disk)Persistent structured data; stored encrypted
File Storage Tier (Cloud)Unstructured files like images and videos; supports CDN acceleration
Backup Tier (Disaster Recovery)Encrypted backups for disaster recovery; strictly limited access

2.2 Storage Location

  • Primary Storage: Within the territory of China;

  • Backup Storage: If applicable, all within China-based compliant data centers;

  • Cross-Border Transfers: Not proactively transferred overseas. If business requires, we will conduct security assessments and obtain your separate consent.

2.3 Retention Periods

Data TypeDefault Retention PeriodLegal/Business Basis
Core Account InformationAccount duration + 3 years after cancellationCybersecurity Law
Transaction Records5 years after transaction completionE-Commerce Law
Usage Behavior LogsMost recent 12 monthsService optimization & security
User-Generated ContentUntil user proactively deletesUser's decision
Device & Network LogsMost recent 6 monthsSecurity auditing
Location DataMost recent 30 days (unless otherwise authorized)Privacy-friendly default

After expiry, data is automatically deleted or irreversibly anonymized.


Stage 3: Data Use

3.1 Use Purpose Matrix

Use ScenarioData Categories UsedProcessing MethodLegal Basis
Account Registration/LoginAccount identity dataIdentity verification, account creationContractual performance
Core Service FunctionsAccount identity + Profile + Usage behaviorContent display, request processingContractual performance
Personalized RecommendationsUsage behavior + Device dataAlgorithmic analysis, interest modelingLegitimate interest / Consent
Service SecurityNetwork + Device + Usage behaviorAnomaly detection, risk identificationLegitimate interest
Product Iteration & OptimizationUsage behavior + Device + NetworkAggregation, A/B testingLegitimate interest
Compliance & AuditingAll categories (as needed)Retention, cooperation with investigationsLegal obligation
User CommunicationAccount identity dataNotifications, inquiry responsesContractual / Legal obligation

3.2 Data Use Red Lines

We commit not to use your data for:

  • Discriminatory decisions or price discrimination ("big data price gouging");

  • Unsolicited commercial marketing (spam);

  • Infringement on your dignity or legitimate rights;

  • Any illegal or unlawful activities.


Stage 4: Data Sharing

4.1 Sharing Principles

All external data sharing is subject to the following prerequisites:

  1. Necessity Review: Essential for service delivery;

  2. Minimization Provision: Only the minimum data fields necessary are shared;

  3. Contractual Constraints: All recipients sign data processing agreements with security standards no lower than ours;

  4. User Notification: Prior notice and consent are obtained for major sharing scenarios.

4.2 Sharing Scenario List

Recipient TypeData SharedPurposeControl Measures
Payment ProcessorsOrder amount, payment method, payment resultTransaction settlementEncrypted transmission; no storage of sensitive payment data
Push Service ProvidersDevice ID, push tokenMessage notificationsUsed only for push, no other purposes
Cloud Service ProvidersUser-uploaded files (images/videos)Content storage & distributionData encryption, access restrictions
Analytics ProvidersAggregated/anonymized behavioral dataProduct optimizationOnly aggregated data; no individual identification
Regulatory/Judicial AuthoritiesData as legally requiredLegal complianceReview legal documentation; limit disclosure scope
Other Third PartiesData with your separate consentPurpose you agreed toStrictly follow authorized scope

4.3 Prohibited Activities

  • We do not sell your personal information;

  • We do not transfer your personal information (except in mergers/acquisitions where the successor continues to uphold this statement);

  • We do not publicly disclose your personal information (except with your separate consent or as legally required).


Stage 5: Data Deletion

5.1 Deletion Triggers

Trigger ScenarioDescription
You request account cancellationDeletion process begins after identity verification
Retention period expiresSystem automatically triggers deletion or anonymization
You request specific data deletione.g., delete a single comment, clear history
Withdrawal of consentProcessing based on that consent ceases and data is deleted
Legal or regulatory requirementDelete in compliance with lawful instructions

5.2 Deletion Levels

LevelActionTimeline
Content-Level DeletionDelete a single item or record (e.g., comment, search history)Immediate (cache cleared within 1 hour)
Category-Level DeletionDelete an entire category (e.g., all location records)Immediate
Account-Level DeletionCancel account and delete all associated dataWithin 7 business days after confirmation
Complete PurgeOverwrite from physical storage mediaPerformed quarterly

5.3 Deletion Exceptions

Data may be retained temporarily in the following cases:

  • Legal retention periods have not yet expired;

  • Pending legal disputes or litigation;

  • Reasonably necessary to prevent fraud or abuse.


Stage 6: Your End-to-End Control Rights

You may exercise your rights at every stage of the data lifecycle:

StageWhat You Can Do
CollectionChoose whether to fill optional fields, grant sensitive permissions
StorageKnow where data is stored and for how long
UseDisable personalized recommendations, turn off targeted ads
SharingKnow who data is shared with and what is shared
DeletionProactively delete data, request account cancellation

Stage 7: Security Technology Assurance

We implement the following technical measures to protect data throughout its lifecycle:

Security LayerTechnical Measures
Transmission SecurityTLS 1.3 encryption, certificate mutual authentication
Storage SecurityAES-256 encryption, tiered key management, HSM protection
Access SecurityLeast-privilege principle, multi-factor authentication, auto-logout on session timeout
Operational SecurityFull operation logging, real-time anomaly alerts, regular penetration testing
Personnel SecurityBackground checks, confidentiality agreements, privacy training
Incident ResponseData breach response plan, 24-hour escalation, legal reporting obligations


home phone E-mail