Legal · Privacy

Privacy Policy.

Controller: CHENGTUZHI TRADING CO., LIMITED · Registered office: Rm A19(H19) 12/F WING TAI CTR 12 HING YIP ST, Kwun Tong, HK · Last updated: 23 September 2026 · Language: English only.

Contents:
  1. Introduction & scope
  2. Information we collect
  3. How we use personal data
  4. Cookies & similar technologies
  5. Mobile app — data and ad SDKs
  6. Advertising and ad-platform compliance
  7. International data transfers
  8. Regional privacy rights
  9. Children's privacy
  10. Data retention
  11. Security measures
  12. Third-party processors
  13. Changes to this policy
  14. Contact us
  15. App-store compliance references

P1 Introduction & scope

This Privacy Policy describes how CHENGTUZHI TRADING CO., LIMITED (the "Company", "we", "us" or "our") collects, uses, discloses and protects personal data when you:

  • Visit or interact with our website at chengtuzhi.com and any sub-domain we operate;
  • Install and use our mobile management applications (the "Apps") published on Google Play and Apple App Store;
  • Communicate with us by email, contact form or other channels referenced on this website.

The controller of your personal data is CHENGTUZHI TRADING CO., LIMITED, registered in Hong Kong at Rm A19(H19) 12/F WING TAI CTR 12 HING YIP ST, Kwun Tong, HK. Where the European GDPR or the UK GDPR applies, the Company acts as the data controller; where the LGPD applies, the Company acts as the controller ("controlador"); where the CCPA/CPRA applies, the Company acts as the "business".

This policy does not cover third-party sites we link to. If you click a link to a third-party site (for example, a Google Play or App Store page), that site's own privacy policy will apply.

P2 Information we collect

We collect the categories of personal data described below. We do not knowingly collect biometric data, sensitive government identifiers or precise location data unless you explicitly opt in.

P2.1 Website data

  • IP address (truncated where feasible);
  • User-agent string, referrer, pages visited, timestamps;
  • Server logs from the hosting environment (GitHub Pages + Pages CDN).

P2.2 Voluntary data

  • Name, email, message body, company and any other information you choose to share with us via the contact form or email links.

P2.3 App data

  • Device identifiers (IDFA on iOS, GAID on Android, hashed where feasible);
  • OS version, app version, locale, in-app events, crash logs;
  • Opt-in / opt-out status for analytics and personalised advertising;
  • Account-related identifiers if you create an in-app account (email address, hashed password, role).

P2.4 Do-not-collect list

We do not collect biometric identifiers, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, health data or sex-life / sexual orientation data. We do not collect precise location unless you opt in.

P3 How we use personal data

We use personal data for the following purposes, with the lawful basis identified under GDPR Article 6.

Purposes, lawful bases, and our retention rationale
Purpose Categories of data Lawful basis (GDPR Art. 6)
Provide and operate the website and AppsWebsite data; App dataArt. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interest
Respond to inquiries submitted via contact form or emailVoluntary dataArt. 6(1)(b) — pre-contractual steps; Art. 6(1)(a) — consent
Provide in-app features (orders, inventory, brand assets)App data; Account identifiersArt. 6(1)(b) — performance of a contract
Fraud prevention and securityDevice identifiers; IP address; logsArt. 6(1)(f) — legitimate interest
Legal compliance and record-keepingServer logs; account recordsArt. 6(1)(c) — legal obligation
Serve advertising in the Apps (subject to consent where required)Device identifiers; event data; coarse location (if granted)Art. 6(1)(a) — consent (personalised ads); Art. 6(1)(f) — legitimate interest (non-personalised ads)

We do not use personal data for automated decision-making that produces legal effects or similarly significantly affects you (Art. 22 GDPR). Ad-targeting decisions are not "solely" automated decisions with legal effect within the meaning of Art. 22.

P4 Cookies & similar technologies

The website uses a consent management platform (CMP) that blocks non-essential cookies for EEA, UK and Swiss visitors until consent is granted. We classify cookies and similar trackers as follows:

Cookie categories used on chengtuzhi.com
Name / category Purpose Provider Retention Strictly necessary?
consentStores your cookie preferencesCHENGTUZHI (first-party)12 monthsYes
sessionMaintains session integrityCHENGTUZHI (first-party)SessionYes
analyticsAggregated, anonymous usage statisticsFirst-party (no third-party trackers loaded)6 monthsNo (opt-in)
marketingMarketing attribution and re-engagementNot used on the static siten/aNo (opt-in)

We do not load third-party advertising trackers on chengtuzhi.com. Advertising trackers appear in our Apps only, and only after explicit in-app consent where required (see P5).

P5 Mobile app — data and ad SDKs

Our Apps integrate advertising SDKs as well as first-party analytics and crash-reporting components. The Apps are not aimed at children. The four ad formats used in the Apps are described below; the catalogue of all 19 ad platforms we integrate (or may integrate) is set out in P6.

P5.1 Ad formats

The four ad formats supported by our Apps
Format How it appears User controls SDKs that may serve it
Open-screen / splash Static or short video that appears when the app first launches each session; dismissible. Skip / close button (after a few seconds), OS-level ad-personalisation toggle. AdMob, Ad Manager, AppLovin, ironSource, Pangle, Mintegral, Start.io, Appodeal.
Rewarded video User-initiated: the user taps a clearly-labelled "Watch an ad" button to receive an in-app reward. Always user-initiated (no auto-play); reward terms disclosed in context; OS-level toggle. AdMob, Unity Ads, AppLovin, ironSource, Pangle, Vungle, Chartboost, Tapjoy, Mintegral, Liftoff, Start.io, Appodeal.
Interstitial Full-screen ad at natural transition points; never covers an active form field. Visible close button; frequency capped; OS-level toggle. AdMob, Ad Manager, Meta Audience Network, Unity Ads, AppLovin, ironSource, Pangle, Vungle, Chartboost, InMobi, Tapjoy, Mintegral, Digital Turbine, Liftoff, Moloco, Yahoo, Smaato, Start.io, Appodeal.
Banner Persistent strip rendered at the top or bottom of a screen; refreshes periodically. Clearly labelled as advertising; OS-level toggle. AdMob, Ad Manager, Meta Audience Network, AppLovin, ironSource, Pangle, InMobi, Digital Turbine, Moloco, Yahoo, Smaato, Start.io, Appodeal.

P5.2 Data each SDK category collects

  • Device identifiers (IDFA/GAID, hashed where feasible);
  • IP address, coarse location (if the user has granted location permission);
  • Event timestamps and ad-interaction events (impression, click, completion);
  • App version, OS version, locale, free disk space, network type.

P5.3 Opt-out

You can opt out of personalised advertising through:

  • iOS: Settings → Privacy & Security → Apple Advertising → toggle "Limit Ad Tracking".
  • Android: Settings → Google → Ads → toggle "Opt out of Ads Personalisation".
  • In-app settings (where supported by the SDK): Settings → Privacy → "Opt out of interest-based ads".

P6 Advertising and ad-platform compliance

This section enumerates every advertising platform whose SDK is integrated (or may be integrated in the future) into our Apps. For each platform we state the SDK behaviour, the data collected, the lawful basis, the opt-out mechanism and a link to the platform's privacy page.

P6.1 Your ad choices (global opt-out links)

  • Digital Advertising Alliance (DAA) — youradchoices.com/choices;
  • European Interactive Digital Advertising Alliance (EDAA) — youronlinechoices.eu;
  • Network Advertising Initiative (NAI) — optout.networkadvertising.org;
  • Google Ads Settings — adssettings.google.com.

P6.2 The 19 ad platforms

The 19 advertising platforms whose SDKs are integrated (or may be integrated) into our Apps
# Platform SDK behaviour Data collected Lawful basis Opt-out & platform privacy
1 Google AdMob Initialises at app start; requests ads; renders banner / interstitial / rewarded / native. Device ID, IP, app version, coarse location (if granted), event data. Legitimate interest (non-personalised) / consent (personalised). adssettings.google.com · policies.google.com/privacy
2 Google Ad Manager Ad-server SDK; serves banner / interstitial from Ad Manager line items. Device ID, IP, app version, event data. Legitimate interest / consent. adssettings.google.com · policies.google.com/privacy
3 Meta Audience Network Serves banner, interstitial, rewarded video and native ads. Device ID, coarse location, event data, conversion events. Consent (personalised). facebook.com/adpreferences · facebook.com/policy.php
4 Unity Ads Serves video, playable and banner ads. Device ID, IP, advertising ID, event data. Consent (personalised). OS-level toggle · unity.com/legal/privacy-policy
5 AppLovin Serves banner, interstitial, rewarded video and native ads. Device ID, IP, advertising ID, session data. Consent (personalised). OS-level toggle · applovin.com/privacy
6 ironSource (Unity LevelPlay) Serves video, rewarded video, interstitial and banner ads through the LevelPlay mediation layer. Device ID, IP, event data. Consent (personalised). OS-level toggle · is.com/legal/privacy-policy
7 Pangle (ByteDance) Serves native, splash, interstitial, rewarded video and banner ads. Device ID, IP, event data, coarse location (if granted). Consent (personalised). OS-level toggle · pangleglobal.com/privacy/en
8 Vungle Serves rewarded video, interstitial, banner and native ads. Device ID, IP, event data. Consent (personalised). OS-level toggle · vungle.com/privacy
9 Chartboost Serves banner, interstitial, rewarded video and native ads. Device ID, IP, event data. Consent (personalised). OS-level toggle · chartboost.com/privacy
10 InMobi Serves banner, interstitial, rewarded video and native ads. Device ID, IP, GPS / coarse location (if granted), event data. Consent (personalised). OS-level toggle · inmobi.com/privacy-policy
11 Tapjoy Primarily serves rewarded ads (offerwalls) plus interstitials. Device ID, IP, event data, conversion events. Consent (personalised). OS-level toggle · tapjoy.com/legal/privacy-policy
12 Mintegral Serves banner, interstitial, rewarded video and native ads. Device ID, IP, event data. Consent (personalised). OS-level toggle · mintegral.com/en/privacy
13 Digital Turbine Serves install / app-ads and in-app ads. Device ID, IP, event data. Consent (personalised). OS-level toggle · digitalturbine.com/privacy-policy
14 Liftoff Operates ad-serving and measurement tools (Vungle post-acquisition). Device ID, IP, event data. Consent (personalised). OS-level toggle · liftoff.io/privacy-policy
15 Moloco Operates programmatic ad-serving. Device ID, IP, event data, coarse location (if granted). Consent (personalised). OS-level toggle · moloco.com/privacy-policy
16 Yahoo (Verizon Media) Native and display ads. Device ID, IP, event data. Consent (personalised). Yahoo Ad Interest Manager · OS-level toggle.
17 Smaato Mobile ad exchange. Device ID, IP, event data. Consent (personalised). OS-level toggle · smaato.com/privacy-policy
18 Start.io Serves banner, interstitial, rewarded video, native and splash ads. Device ID, IP, event data. Consent (personalised). OS-level toggle · start.io/privacy-policy
19 Appodeal Mediation platform; integrates the SDKs above. Device ID, IP, mediation event data. Consent (personalised). OS-level toggle · appodeal.com/privacy-policy

We periodically audit this list. Region-specific addenda (for example, the Pangle EEA addendum and the Meta Audience Network EU addendum) are reflected in the platform's own opt-out and consent flow, which is presented inside each App before any personalised ad request.

P7 International data transfers

The Company is based in Hong Kong SAR. Where personal data is transferred out of Hong Kong — for example, to the EEA, UK, US, Canada, Australia, Singapore or Japan — we rely on the transfer mechanisms identified below.

Transfer mechanisms by destination
Destination Mechanism(s) used Notes
European Economic Area (EEA)EU Standard Contractual Clauses (SCCs) 2021/914; supplementary measures.Where personal data is transferred to a recipient outside the EEA.
United Kingdom (UK)UK International Data Transfer Addendum (IDTA) to the SCCs; UK SCCs.Where personal data is transferred to a recipient outside the UK.
United States (US)SCCs; vendor diligence; data-processing addenda.No adequacy decision for Hong Kong → US transfers; safeguards described in our DPA.
CanadaSCC-equivalent contractual safeguards.Personal Information Protection and Electronic Documents Act (PIPEDA) consent model.
AustraliaAPP 8 cross-border transfer requirements; contractual safeguards.APP 8 requires reasonable steps to ensure overseas recipient compliance.
SingaporePDPA transfer-limitation obligations; contractual safeguards.PDPC notification requirements where applicable.
JapanAPPI rules on cross-border transfer; consent or equivalent basis.PPC confirmation of adequacy where applicable.
BrazilSCC-equivalent ("cláusulas-padrão") where adopted by ANPD; contractual safeguards.LGPD Art. 33–36 transfer framework.

P8 Regional privacy rights

Depending on where you live, you may have rights under the following laws. For each region we identify the applicable law, the rights you enjoy and the contact route.

P8.1 European Union — GDPR (Regulation (EU) 2016/679)

If you are in the EU, the General Data Protection Regulation applies. Lawful bases are set out in Art. 6 and detailed in P3. Data-subject rights include:

  • Right of access (Art. 15);
  • Right to rectification (Art. 16);
  • Right to erasure / right to be forgotten (Art. 17);
  • Right to restriction of processing (Art. 18);
  • Right to data portability (Art. 20);
  • Right to object (Art. 21);
  • Right to withdraw consent (Art. 7(3));
  • Right to lodge a complaint with a supervisory authority (Art. 77).

We are not required to appoint a Data Protection Officer (DPO) given the nature, scope and purposes of our processing. We are not required to appoint an EU representative. To exercise your rights, contact support@chengtuzhi.com.

P8.2 United Kingdom — UK GDPR & Data Protection Act 2018

If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply. The rights mirror those under the EU GDPR (Arts. 15–22) and you may complain to the Information Commissioner's Office (ICO) at ico.org.uk. We are not required to appoint a UK representative. Contact support@chengtuzhi.com.

P8.3 California, United States — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) applies. You have the right to:

  • Notice at collection — what we collect, why and with whom we share it (this section).
  • Right to know what personal information we have collected about you.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to limit use of sensitive personal information (we do not collect sensitive PI within the meaning of CPRA).
  • Right to opt out of sale or sharing — we do not sell personal information for monetary or other valuable consideration; cross-context behavioural advertising may constitute "sharing" under CPRA, which you may opt out of via the in-app toggle or by emailing support@chengtuzhi.com.
  • Non-discrimination for exercising any CCPA/CPRA right.

P8.4 Brazil — LGPD (Lei nº 13.709/2018)

If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. Legal bases are set out in Art. 7 and include consent, performance of a contract, legitimate interest and legal obligation. Data-subject rights under Art. 18 include confirmation of existence, access, correction, anonymisation, portability, deletion and information about sharing. The data protection authority is the Autoridade Nacional de Proteção de Dados (ANPD). Contact support@chengtuzhi.com.

P8.5 Canada — PIPEDA & provincial laws (e.g., Quebec Law 25)

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, supplemented by applicable provincial laws (for example, Quebec's Law 25). You have the right of access, the right to challenge accuracy, and the right to withdraw consent. The Office of the Privacy Commissioner of Canada (OPC) is the federal supervisory authority. Contact support@chengtuzhi.com.

P8.6 Australia — Privacy Act 1988 (Cth) & Australian Privacy Principles (APPs)

If you are in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. APP 8 governs cross-border transfers of personal information and requires us to take reasonable steps to ensure that an overseas recipient does not breach the APPs. The Office of the Australian Information Commissioner (OAIC) is the supervisory authority. Contact support@chengtuzhi.com.

P8.7 Singapore — PDPA (Personal Data Protection Act 2012)

If you are in Singapore, the Personal Data Protection Act 2012 (PDPA) applies. The PDPC oversees compliance. We will obtain consent (or rely on another legitimate basis under the PDPA), notify you of the purpose, and cease retention when the purpose is exhausted. Contact support@chengtuzhi.com.

P8.8 Japan — APPI (Act on the Protection of Personal Information)

If you are in Japan, the Act on the Protection of Personal Information (APPI) applies. We use personal information within the stated purpose and apply the APPI's rules on cross-border transfer. The Personal Information Protection Commission (PPC) is the supervisory authority. Contact support@chengtuzhi.com.

Summary. The table below summarises regional rights and contact routes.
Regional rights matrix
Region Law Key rights Supervisory authority Contact
European UnionGDPR (Regulation (EU) 2016/679)Access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge complaintLocal DPA (each Member State)support@chengtuzhi.com
United KingdomUK GDPR + Data Protection Act 2018Same as EU GDPRICO (ico.org.uk)support@chengtuzhi.com
California, USCCPA / CPRAKnow, delete, correct, limit, opt-out of sale/sharing, non-discriminationCalifornia AG / CPPAsupport@chengtuzhi.com
BrazilLGPD (Lei nº 13.709/2018)Confirmation, access, anonymisation, portability, deletion, sharing infoANPDsupport@chengtuzhi.com
CanadaPIPEDA + provincial laws (e.g., Quebec Law 25)Access, challenge accuracy, withdraw consentOPC / CAI (Quebec)support@chengtuzhi.com
AustraliaPrivacy Act 1988 (Cth) + APPsAccess, correction, complaint, APP 8 safeguardsOAICsupport@chengtuzhi.com
SingaporePDPA (2012)Access, correction, withdraw consentPDPCsupport@chengtuzhi.com
JapanAPPIAccess, correction, cease usePPCsupport@chengtuzhi.com

P9 Children's privacy

Our Apps are not aimed at children. We do not knowingly target advertising at children and we honour OS-level ad personalisation flags (Limit Ad Tracking on iOS, Opt out of Ads Personalisation on Android).

Age thresholds by region
Region Instrument Threshold we apply
United StatesCOPPA (Children's Online Privacy Protection Act)<13 requires verifiable parental consent; our Apps are 13+.
European UnionGDPR Art. 8 ("GDPR-K")Default <16; member-state variants can lower to 13 (NL, DK, SE, FI, AT, IT, ES, LV, LT, PT, PL). We apply the strictest applicable threshold across the EEA — 16 — to the entire EEA.
United KingdomAge-Appropriate Design Code (AADC)Default protections for all users; DPIA where children likely to access; data minimisation; default-off settings.
Other regionsLocal equivalentsWhere local law sets a higher age of digital consent, we apply that age.

If we learn that we have collected personal data from a child under the applicable threshold without verifiable parental consent, we will delete that data on notice. Please contact support@chengtuzhi.com if you believe this has happened.

P10 Data retention

Retention periods by data category
Category Retention period Rationale
Contact-form submissions24 months from last interactionPartnership follow-up and record-keeping.
Server logs (hosting)30 daysSecurity and abuse prevention.
App analytics events13 monthsProduct improvement and trend analysis.
Ad events (impression, completion)13 monthsAttribution, fraud prevention and audit.
Account records (in-app accounts)Life of account + 24 monthsContract performance; legal record-keeping.
Backups30 days rollingDisaster recovery.

P11 Security measures

We apply technical and organisational measures designed to protect personal data, including:

  • TLS in transit for the website and Apps (HTTPS enforced);
  • Role-based access control for staff with access to personal data;
  • Vendor due diligence for every processor that handles personal data;
  • Encrypted storage of credentials and account identifiers;
  • A documented breach-response procedure with notification timelines consistent with GDPR Art. 33 / 34 and equivalent regional laws.

P12 Third-party processors

Third-party processors we engage
Purpose Provider Provider policy
Hosting & CDNGitHub Pages (GitHub, Inc.)GitHub Privacy Statement
Email delivery (mailto links)User's local mail clientHandled client-side; no third-party email service for the contact form.
Ad servingThe 19 ad platforms listed in P6See each platform's privacy page.
Crash reportingNative platform crash reporters (Apple, Google) and SDK crash reporters as configured per app.Subject to platform and SDK privacy policies.

P13 Changes to this policy

We may revise this policy from time to time. The "Last updated" header at the top of this page reflects the current version. Material changes will be notified by an in-app banner or a website notice, and (where required by law) by re-prompting for consent.

P14 Contact us

For any privacy question, request, or complaint, contact us via one of the following routes:

  • General privacy questions: support@chengtuzhi.com
  • Key-account / contract-related privacy questions: liuqiumeng@chengtuzhi.com
  • Postal address: Rm A19(H19) 12/F WING TAI CTR 12 HING YIP ST, Kwun Tong, HK

We will respond within the timeframes required by applicable law (typically within 30 days for GDPR / UK GDPR access requests).

P15 App-store compliance references

Our Apps and this policy are designed to comply with the latest published versions of:

  • Apple App Store Review Guidelines — developer.apple.com/app-store/review/guidelines/
  • Google Play Developer Program Policy — support.google.com/googleplay/android-developer/topic/9871336

Where an App Store requirement imposes a stricter rule than this policy (for example, around children's data, advertising identifiers or "Data Used to Track You" disclosures), the App Store rule governs the in-App experience.


End of Privacy Policy. Companion document: Terms of Service.