Privacy Statement
1. Introduction
Haozhi Information Technology Co., Ltd. (hereinafter referred to as "Haozhi Company," "the Company," "we," or "us") understands the importance of privacy to our customers. Therefore, we outline in this statement the measures we take to handle information and ensure privacy protection.
We place a high priority on protecting the privacy rights of users (including natural persons, legal entities, and other organizations who access or use our products through various lawful means, hereinafter referred to as "users" or "you"). Before using our products or services, please carefully read and fully understand the provisions and limitations of this Privacy Statement (hereinafter referred to as "the Statement"). This Statement is independent and comprehensive. By choosing to use our products, you confirm that you fully understand and agree to all the terms of this Statement and voluntarily assume all responsibilities and risks associated with using our products or services.
If you have any questions about this Privacy Policy or related matters, please contact us at [email protected], and we will respond promptly.
2. Scope of this Privacy Statement
This Privacy Statement applies to your use of any products and services provided by our Company, regardless of whether the specific product or service includes its own privacy terms or whether you are a browsing user (visitor) or a registered user.
Please note that this Privacy Statement does not apply to the following:
- Information collected through third-party services (including any third-party websites) that are accessed via our services
- If, as a user of our services, you provide services to your users using our technology services, the data generated belongs to you, and you should separately establish a privacy policy with your users
3. Information We Collect
3.1 Information You Provide to Us
- Personal information you provide when registering an account or using our services, such as your name, ID number, user password, phone number, mobile number, photos, and IP address
3.2 Information Generated When Using Our Services
- Log information: Technical data that the system may automatically collect through cookies or other methods when you use our services
- Device information: Includes IMEI, MEID, Android ID, IMSI, GUID, MAC address, hardware serial number, IP address, Bluetooth, and configuration information provided by the page browser or other programs used to access our services
- Metadata in content shared through our services, such as the date, time, or location of shared photos or videos you upload
3.3 Permissions You May Grant Us
- Storage: For reading and writing external storage on your device, e.g., saving application-generated documents
- Album: For uploading and updating profile photos
- Camera: For taking or updating profile photos
- Device Information or Phone Permissions: For device compatibility, smooth content browsing, and security assurance
3.4 Information Collected by Third-Party SDKs and Plugins
Getui SDK: For improving user experience through analysis; collects Google Advertising ID (GAID). Provider: Google.
4. How We Store, Use, and Protect Your Information
4.1 Storage of Personal Information
Location: Personal information is stored in the United States (New York, DigitalOcean Space). By using our services, you acknowledge and consent to the transfer of your personal information to the United States, which may have different data protection laws than your country of residence.
Cross-Border Data Transfer:
- We may transfer your personal information to countries other than your country of residence
- When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions by relevant authorities
- Binding Corporate Rules (BCRs) where applicable
- Technical and organizational measures to ensure data security
- You can request information about the specific safeguards we use for international transfers
Duration: We retain your personal information for the duration necessary to fulfill the purposes outlined in this Statement or as required by law.
4.2 Usage Purposes
- Data analysis to improve service quality
- Identity verification, customer support, fraud detection, and security purposes
- Development of new services and improvement of existing ones
- Personalizing services to meet your needs
- Software authentication or updates
- Anonymous data analysis and commercialization
4.3 Protection Measures
- SSL/TLS encryption for secure data transmission
- Industry-standard encryption for data at rest
- Regular security audits and penetration testing
- Strict access controls and authentication mechanisms
- Regular security training for staff
- Comprehensive data backup and disaster recovery procedures
- Compliance with SOC 2 Type II security standards
- Regular vulnerability assessments and security updates
5. Your Rights
5.1 Rights Under GDPR (For EU Users)
If you are located in the European Economic Area (EEA), you have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
5.2 Rights Under CCPA (For California Residents)
If you are a California resident, you have the following rights:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access your personal information
- Right to equal service and price
- Right to request deletion of your personal information
To exercise these rights, please contact us at [email protected].
6. Information Sharing
We do not share your personal information with third parties without your consent, except in the following cases:
- With affiliates, partners, or service providers (e.g., for SMS notifications or push messages)
- To comply with laws, court orders, or regulatory requirements
- To protect the rights, safety, or property of our users, company, or partners
7. Security Incidents and Notifications
In the event of a data security incident:
- We will notify affected users within 72 hours of becoming aware of the breach (as required by GDPR)
- For California residents, we will notify within 45 days of discovery (as required by CCPA)
- Notifications will include:
- Nature of the breach
- Categories of affected data
- Likely consequences
- Measures taken to address the breach
- Contact information for further inquiries
- We will also notify relevant supervisory authorities as required by law
- We maintain an incident response plan and regularly test our response procedures
8. Use of Cookies and Similar Technologies
8.1 Purpose
We use cookies and similar tracking technologies to:
- Maintain your session and preferences
- Analyze website usage and performance
- Improve our services and user experience
- Provide personalized content
8.2 Types of Cookies
- Essential Cookies: Required for basic website functionality
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how visitors use our website
- Marketing Cookies: Used for targeted advertising
8.3 Cookie Management
- You can control cookies through your browser settings
- Essential cookies cannot be disabled as they are necessary for website functionality
- Disabling certain cookies may limit your ability to use some features
- We respect Do Not Track (DNT) signals and Global Privacy Control (GPC) signals
8.4 Cookie Retention
- Session cookies are deleted when you close your browser
- Persistent cookies remain until they expire or are deleted
- Analytics cookies are typically retained for 26 months
- Marketing cookies are typically retained for 13 months
9. Updates and Dispute Resolution
We may update this Statement from time to time. Your continued use of our services signifies your acceptance of these updates.
For any disputes arising from or in connection with this Privacy Statement:
- Both parties shall first attempt to resolve the dispute through friendly consultation
- If consultation fails, either party may submit the dispute to the competent court in New York, United States
- This Privacy Statement shall be governed by and construed in accordance with the laws of the State of New York and applicable United States federal law
- The prevailing party in any legal action shall be entitled to recover reasonable attorney's fees and costs
- Any dispute resolution process shall be conducted in English
10. Contact Us
For questions, comments, or suggestions regarding this Privacy Statement, please contact us at: Email: [email protected]