Privacy Policy.
P1 Introduction & scope
This Privacy Policy describes how CHENGTUZHI TRADING CO., LIMITED (the "Company", "we", "us" or "our") collects, uses, discloses and protects personal data when you:
- Visit or interact with our website at chengtuzhi.com and any sub-domain we operate;
- Install and use our mobile management applications (the "Apps") published on Google Play and Apple App Store;
- Communicate with us by email, contact form or other channels referenced on this website.
The controller of your personal data is CHENGTUZHI TRADING CO., LIMITED, registered in Hong Kong at Rm A19(H19) 12/F WING TAI CTR 12 HING YIP ST, Kwun Tong, HK. Where the European GDPR or the UK GDPR applies, the Company acts as the data controller; where the LGPD applies, the Company acts as the controller ("controlador"); where the CCPA/CPRA applies, the Company acts as the "business".
This policy does not cover third-party sites we link to. If you click a link to a third-party site (for example, a Google Play or App Store page), that site's own privacy policy will apply.
P2 Information we collect
We collect the categories of personal data described below. We do not knowingly collect biometric data, sensitive government identifiers or precise location data unless you explicitly opt in.
P2.1 Website data
- IP address (truncated where feasible);
- User-agent string, referrer, pages visited, timestamps;
- Server logs from the hosting environment (GitHub Pages + Pages CDN).
P2.2 Voluntary data
- Name, email, message body, company and any other information you choose to share with us via the contact form or email links.
P2.3 App data
- Device identifiers (IDFA on iOS, GAID on Android, hashed where feasible);
- OS version, app version, locale, in-app events, crash logs;
- Opt-in / opt-out status for analytics and personalised advertising;
- Account-related identifiers if you create an in-app account (email address, hashed password, role).
P2.4 Do-not-collect list
We do not collect biometric identifiers, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, health data or sex-life / sexual orientation data. We do not collect precise location unless you opt in.
P3 How we use personal data
We use personal data for the following purposes, with the lawful basis identified under GDPR Article 6.
| Purpose | Categories of data | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Provide and operate the website and Apps | Website data; App data | Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interest |
| Respond to inquiries submitted via contact form or email | Voluntary data | Art. 6(1)(b) — pre-contractual steps; Art. 6(1)(a) — consent |
| Provide in-app features (orders, inventory, brand assets) | App data; Account identifiers | Art. 6(1)(b) — performance of a contract |
| Fraud prevention and security | Device identifiers; IP address; logs | Art. 6(1)(f) — legitimate interest |
| Legal compliance and record-keeping | Server logs; account records | Art. 6(1)(c) — legal obligation |
| Serve advertising in the Apps (subject to consent where required) | Device identifiers; event data; coarse location (if granted) | Art. 6(1)(a) — consent (personalised ads); Art. 6(1)(f) — legitimate interest (non-personalised ads) |
We do not use personal data for automated decision-making that produces legal effects or similarly significantly affects you (Art. 22 GDPR). Ad-targeting decisions are not "solely" automated decisions with legal effect within the meaning of Art. 22.
P4 Cookies & similar technologies
The website uses a consent management platform (CMP) that blocks non-essential cookies for EEA, UK and Swiss visitors until consent is granted. We classify cookies and similar trackers as follows:
| Name / category | Purpose | Provider | Retention | Strictly necessary? |
|---|---|---|---|---|
| consent | Stores your cookie preferences | CHENGTUZHI (first-party) | 12 months | Yes |
| session | Maintains session integrity | CHENGTUZHI (first-party) | Session | Yes |
| analytics | Aggregated, anonymous usage statistics | First-party (no third-party trackers loaded) | 6 months | No (opt-in) |
| marketing | Marketing attribution and re-engagement | Not used on the static site | n/a | No (opt-in) |
We do not load third-party advertising trackers on chengtuzhi.com. Advertising trackers appear in our Apps only, and only after explicit in-app consent where required (see P5).
P5 Mobile app — data and ad SDKs
Our Apps integrate advertising SDKs as well as first-party analytics and crash-reporting components. The Apps are not aimed at children. The four ad formats used in the Apps are described below; the catalogue of all 19 ad platforms we integrate (or may integrate) is set out in P6.
P5.1 Ad formats
| Format | How it appears | User controls | SDKs that may serve it |
|---|---|---|---|
| Open-screen / splash | Static or short video that appears when the app first launches each session; dismissible. | Skip / close button (after a few seconds), OS-level ad-personalisation toggle. | AdMob, Ad Manager, AppLovin, ironSource, Pangle, Mintegral, Start.io, Appodeal. |
| Rewarded video | User-initiated: the user taps a clearly-labelled "Watch an ad" button to receive an in-app reward. | Always user-initiated (no auto-play); reward terms disclosed in context; OS-level toggle. | AdMob, Unity Ads, AppLovin, ironSource, Pangle, Vungle, Chartboost, Tapjoy, Mintegral, Liftoff, Start.io, Appodeal. |
| Interstitial | Full-screen ad at natural transition points; never covers an active form field. | Visible close button; frequency capped; OS-level toggle. | AdMob, Ad Manager, Meta Audience Network, Unity Ads, AppLovin, ironSource, Pangle, Vungle, Chartboost, InMobi, Tapjoy, Mintegral, Digital Turbine, Liftoff, Moloco, Yahoo, Smaato, Start.io, Appodeal. |
| Banner | Persistent strip rendered at the top or bottom of a screen; refreshes periodically. | Clearly labelled as advertising; OS-level toggle. | AdMob, Ad Manager, Meta Audience Network, AppLovin, ironSource, Pangle, InMobi, Digital Turbine, Moloco, Yahoo, Smaato, Start.io, Appodeal. |
P5.2 Data each SDK category collects
- Device identifiers (IDFA/GAID, hashed where feasible);
- IP address, coarse location (if the user has granted location permission);
- Event timestamps and ad-interaction events (impression, click, completion);
- App version, OS version, locale, free disk space, network type.
P5.3 Opt-out
You can opt out of personalised advertising through:
- iOS: Settings → Privacy & Security → Apple Advertising → toggle "Limit Ad Tracking".
- Android: Settings → Google → Ads → toggle "Opt out of Ads Personalisation".
- In-app settings (where supported by the SDK): Settings → Privacy → "Opt out of interest-based ads".
P6 Advertising and ad-platform compliance
This section enumerates every advertising platform whose SDK is integrated (or may be integrated in the future) into our Apps. For each platform we state the SDK behaviour, the data collected, the lawful basis, the opt-out mechanism and a link to the platform's privacy page.
P6.1 Your ad choices (global opt-out links)
- Digital Advertising Alliance (DAA) — youradchoices.com/choices;
- European Interactive Digital Advertising Alliance (EDAA) — youronlinechoices.eu;
- Network Advertising Initiative (NAI) — optout.networkadvertising.org;
- Google Ads Settings — adssettings.google.com.
P6.2 The 19 ad platforms
| # | Platform | SDK behaviour | Data collected | Lawful basis | Opt-out & platform privacy |
|---|---|---|---|---|---|
| 1 | Google AdMob | Initialises at app start; requests ads; renders banner / interstitial / rewarded / native. | Device ID, IP, app version, coarse location (if granted), event data. | Legitimate interest (non-personalised) / consent (personalised). | adssettings.google.com · policies.google.com/privacy |
| 2 | Google Ad Manager | Ad-server SDK; serves banner / interstitial from Ad Manager line items. | Device ID, IP, app version, event data. | Legitimate interest / consent. | adssettings.google.com · policies.google.com/privacy |
| 3 | Meta Audience Network | Serves banner, interstitial, rewarded video and native ads. | Device ID, coarse location, event data, conversion events. | Consent (personalised). | facebook.com/adpreferences · facebook.com/policy.php |
| 4 | Unity Ads | Serves video, playable and banner ads. | Device ID, IP, advertising ID, event data. | Consent (personalised). | OS-level toggle · unity.com/legal/privacy-policy |
| 5 | AppLovin | Serves banner, interstitial, rewarded video and native ads. | Device ID, IP, advertising ID, session data. | Consent (personalised). | OS-level toggle · applovin.com/privacy |
| 6 | ironSource (Unity LevelPlay) | Serves video, rewarded video, interstitial and banner ads through the LevelPlay mediation layer. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · is.com/legal/privacy-policy |
| 7 | Pangle (ByteDance) | Serves native, splash, interstitial, rewarded video and banner ads. | Device ID, IP, event data, coarse location (if granted). | Consent (personalised). | OS-level toggle · pangleglobal.com/privacy/en |
| 8 | Vungle | Serves rewarded video, interstitial, banner and native ads. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · vungle.com/privacy |
| 9 | Chartboost | Serves banner, interstitial, rewarded video and native ads. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · chartboost.com/privacy |
| 10 | InMobi | Serves banner, interstitial, rewarded video and native ads. | Device ID, IP, GPS / coarse location (if granted), event data. | Consent (personalised). | OS-level toggle · inmobi.com/privacy-policy |
| 11 | Tapjoy | Primarily serves rewarded ads (offerwalls) plus interstitials. | Device ID, IP, event data, conversion events. | Consent (personalised). | OS-level toggle · tapjoy.com/legal/privacy-policy |
| 12 | Mintegral | Serves banner, interstitial, rewarded video and native ads. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · mintegral.com/en/privacy |
| 13 | Digital Turbine | Serves install / app-ads and in-app ads. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · digitalturbine.com/privacy-policy |
| 14 | Liftoff | Operates ad-serving and measurement tools (Vungle post-acquisition). | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · liftoff.io/privacy-policy |
| 15 | Moloco | Operates programmatic ad-serving. | Device ID, IP, event data, coarse location (if granted). | Consent (personalised). | OS-level toggle · moloco.com/privacy-policy |
| 16 | Yahoo (Verizon Media) | Native and display ads. | Device ID, IP, event data. | Consent (personalised). | Yahoo Ad Interest Manager · OS-level toggle. |
| 17 | Smaato | Mobile ad exchange. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · smaato.com/privacy-policy |
| 18 | Start.io | Serves banner, interstitial, rewarded video, native and splash ads. | Device ID, IP, event data. | Consent (personalised). | OS-level toggle · start.io/privacy-policy |
| 19 | Appodeal | Mediation platform; integrates the SDKs above. | Device ID, IP, mediation event data. | Consent (personalised). | OS-level toggle · appodeal.com/privacy-policy |
We periodically audit this list. Region-specific addenda (for example, the Pangle EEA addendum and the Meta Audience Network EU addendum) are reflected in the platform's own opt-out and consent flow, which is presented inside each App before any personalised ad request.
P7 International data transfers
The Company is based in Hong Kong SAR. Where personal data is transferred out of Hong Kong — for example, to the EEA, UK, US, Canada, Australia, Singapore or Japan — we rely on the transfer mechanisms identified below.
| Destination | Mechanism(s) used | Notes |
|---|---|---|
| European Economic Area (EEA) | EU Standard Contractual Clauses (SCCs) 2021/914; supplementary measures. | Where personal data is transferred to a recipient outside the EEA. |
| United Kingdom (UK) | UK International Data Transfer Addendum (IDTA) to the SCCs; UK SCCs. | Where personal data is transferred to a recipient outside the UK. |
| United States (US) | SCCs; vendor diligence; data-processing addenda. | No adequacy decision for Hong Kong → US transfers; safeguards described in our DPA. |
| Canada | SCC-equivalent contractual safeguards. | Personal Information Protection and Electronic Documents Act (PIPEDA) consent model. |
| Australia | APP 8 cross-border transfer requirements; contractual safeguards. | APP 8 requires reasonable steps to ensure overseas recipient compliance. |
| Singapore | PDPA transfer-limitation obligations; contractual safeguards. | PDPC notification requirements where applicable. |
| Japan | APPI rules on cross-border transfer; consent or equivalent basis. | PPC confirmation of adequacy where applicable. |
| Brazil | SCC-equivalent ("cláusulas-padrão") where adopted by ANPD; contractual safeguards. | LGPD Art. 33–36 transfer framework. |
P8 Regional privacy rights
Depending on where you live, you may have rights under the following laws. For each region we identify the applicable law, the rights you enjoy and the contact route.
P8.1 European Union — GDPR (Regulation (EU) 2016/679)
If you are in the EU, the General Data Protection Regulation applies. Lawful bases are set out in Art. 6 and detailed in P3. Data-subject rights include:
- Right of access (Art. 15);
- Right to rectification (Art. 16);
- Right to erasure / right to be forgotten (Art. 17);
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20);
- Right to object (Art. 21);
- Right to withdraw consent (Art. 7(3));
- Right to lodge a complaint with a supervisory authority (Art. 77).
We are not required to appoint a Data Protection Officer (DPO) given the nature, scope and purposes of our processing. We are not required to appoint an EU representative. To exercise your rights, contact support@chengtuzhi.com.
P8.2 United Kingdom — UK GDPR & Data Protection Act 2018
If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply. The rights mirror those under the EU GDPR (Arts. 15–22) and you may complain to the Information Commissioner's Office (ICO) at ico.org.uk. We are not required to appoint a UK representative. Contact support@chengtuzhi.com.
P8.3 California, United States — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) applies. You have the right to:
- Notice at collection — what we collect, why and with whom we share it (this section).
- Right to know what personal information we have collected about you.
- Right to delete personal information we have collected from you.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information (we do not collect sensitive PI within the meaning of CPRA).
- Right to opt out of sale or sharing — we do not sell personal information for monetary or other valuable consideration; cross-context behavioural advertising may constitute "sharing" under CPRA, which you may opt out of via the in-app toggle or by emailing support@chengtuzhi.com.
- Non-discrimination for exercising any CCPA/CPRA right.
P8.4 Brazil — LGPD (Lei nº 13.709/2018)
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. Legal bases are set out in Art. 7 and include consent, performance of a contract, legitimate interest and legal obligation. Data-subject rights under Art. 18 include confirmation of existence, access, correction, anonymisation, portability, deletion and information about sharing. The data protection authority is the Autoridade Nacional de Proteção de Dados (ANPD). Contact support@chengtuzhi.com.
P8.5 Canada — PIPEDA & provincial laws (e.g., Quebec Law 25)
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, supplemented by applicable provincial laws (for example, Quebec's Law 25). You have the right of access, the right to challenge accuracy, and the right to withdraw consent. The Office of the Privacy Commissioner of Canada (OPC) is the federal supervisory authority. Contact support@chengtuzhi.com.
P8.6 Australia — Privacy Act 1988 (Cth) & Australian Privacy Principles (APPs)
If you are in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. APP 8 governs cross-border transfers of personal information and requires us to take reasonable steps to ensure that an overseas recipient does not breach the APPs. The Office of the Australian Information Commissioner (OAIC) is the supervisory authority. Contact support@chengtuzhi.com.
P8.7 Singapore — PDPA (Personal Data Protection Act 2012)
If you are in Singapore, the Personal Data Protection Act 2012 (PDPA) applies. The PDPC oversees compliance. We will obtain consent (or rely on another legitimate basis under the PDPA), notify you of the purpose, and cease retention when the purpose is exhausted. Contact support@chengtuzhi.com.
P8.8 Japan — APPI (Act on the Protection of Personal Information)
If you are in Japan, the Act on the Protection of Personal Information (APPI) applies. We use personal information within the stated purpose and apply the APPI's rules on cross-border transfer. The Personal Information Protection Commission (PPC) is the supervisory authority. Contact support@chengtuzhi.com.
| Region | Law | Key rights | Supervisory authority | Contact |
|---|---|---|---|---|
| European Union | GDPR (Regulation (EU) 2016/679) | Access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge complaint | Local DPA (each Member State) | support@chengtuzhi.com |
| United Kingdom | UK GDPR + Data Protection Act 2018 | Same as EU GDPR | ICO (ico.org.uk) | support@chengtuzhi.com |
| California, US | CCPA / CPRA | Know, delete, correct, limit, opt-out of sale/sharing, non-discrimination | California AG / CPPA | support@chengtuzhi.com |
| Brazil | LGPD (Lei nº 13.709/2018) | Confirmation, access, anonymisation, portability, deletion, sharing info | ANPD | support@chengtuzhi.com |
| Canada | PIPEDA + provincial laws (e.g., Quebec Law 25) | Access, challenge accuracy, withdraw consent | OPC / CAI (Quebec) | support@chengtuzhi.com |
| Australia | Privacy Act 1988 (Cth) + APPs | Access, correction, complaint, APP 8 safeguards | OAIC | support@chengtuzhi.com |
| Singapore | PDPA (2012) | Access, correction, withdraw consent | PDPC | support@chengtuzhi.com |
| Japan | APPI | Access, correction, cease use | PPC | support@chengtuzhi.com |
P9 Children's privacy
Our Apps are not aimed at children. We do not knowingly target advertising at children and we honour OS-level ad personalisation flags (Limit Ad Tracking on iOS, Opt out of Ads Personalisation on Android).
| Region | Instrument | Threshold we apply |
|---|---|---|
| United States | COPPA (Children's Online Privacy Protection Act) | <13 requires verifiable parental consent; our Apps are 13+. |
| European Union | GDPR Art. 8 ("GDPR-K") | Default <16; member-state variants can lower to 13 (NL, DK, SE, FI, AT, IT, ES, LV, LT, PT, PL). We apply the strictest applicable threshold across the EEA — 16 — to the entire EEA. |
| United Kingdom | Age-Appropriate Design Code (AADC) | Default protections for all users; DPIA where children likely to access; data minimisation; default-off settings. |
| Other regions | Local equivalents | Where local law sets a higher age of digital consent, we apply that age. |
If we learn that we have collected personal data from a child under the applicable threshold without verifiable parental consent, we will delete that data on notice. Please contact support@chengtuzhi.com if you believe this has happened.
P10 Data retention
| Category | Retention period | Rationale |
|---|---|---|
| Contact-form submissions | 24 months from last interaction | Partnership follow-up and record-keeping. |
| Server logs (hosting) | 30 days | Security and abuse prevention. |
| App analytics events | 13 months | Product improvement and trend analysis. |
| Ad events (impression, completion) | 13 months | Attribution, fraud prevention and audit. |
| Account records (in-app accounts) | Life of account + 24 months | Contract performance; legal record-keeping. |
| Backups | 30 days rolling | Disaster recovery. |
P11 Security measures
We apply technical and organisational measures designed to protect personal data, including:
- TLS in transit for the website and Apps (HTTPS enforced);
- Role-based access control for staff with access to personal data;
- Vendor due diligence for every processor that handles personal data;
- Encrypted storage of credentials and account identifiers;
- A documented breach-response procedure with notification timelines consistent with GDPR Art. 33 / 34 and equivalent regional laws.
P12 Third-party processors
| Purpose | Provider | Provider policy |
|---|---|---|
| Hosting & CDN | GitHub Pages (GitHub, Inc.) | GitHub Privacy Statement |
| Email delivery (mailto links) | User's local mail client | Handled client-side; no third-party email service for the contact form. |
| Ad serving | The 19 ad platforms listed in P6 | See each platform's privacy page. |
| Crash reporting | Native platform crash reporters (Apple, Google) and SDK crash reporters as configured per app. | Subject to platform and SDK privacy policies. |
P13 Changes to this policy
We may revise this policy from time to time. The "Last updated" header at the top of this page reflects the current version. Material changes will be notified by an in-app banner or a website notice, and (where required by law) by re-prompting for consent.
P14 Contact us
For any privacy question, request, or complaint, contact us via one of the following routes:
- General privacy questions: support@chengtuzhi.com
- Key-account / contract-related privacy questions: liuqiumeng@chengtuzhi.com
- Postal address: Rm A19(H19) 12/F WING TAI CTR 12 HING YIP ST, Kwun Tong, HK
We will respond within the timeframes required by applicable law (typically within 30 days for GDPR / UK GDPR access requests).
P15 App-store compliance references
Our Apps and this policy are designed to comply with the latest published versions of:
- Apple App Store Review Guidelines — developer.apple.com/app-store/review/guidelines/
- Google Play Developer Program Policy — support.google.com/googleplay/android-developer/topic/9871336
Where an App Store requirement imposes a stricter rule than this policy (for example, around children's data, advertising identifiers or "Data Used to Track You" disclosures), the App Store rule governs the in-App experience.
End of Privacy Policy. Companion document: Terms of Service.