Menu

Privacy policy

Author: RosaryBase Release time: 2026-04-16 09:29:13 View number: 13061

1Scope & Effective Date

This Privacy Policy ("Policy") is issued by the operator of this website ("we," "us," or "our") and applies to all services provided through this website (including mobile versions, H5 pages, and API integrations).

This Policy is designed to comply with:

  • 🇨🇳 China: Personal Information Protection Law (PIPL, 2021), Cybersecurity Law, and Data Security Law
  • 🇪🇺 EU: General Data Protection Regulation (GDPR, 2018)
  • 🇺🇸 US: California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
  • 🇬🇧 UK: UK GDPR and Data Protection Act 2018
  • 🇦🇺 Australia: Privacy Act 1988 and Australian Privacy Principles (APPs)

This Policy is effective as of the "Last Updated" date shown at the top of this page.

2Information We Collect

2.1 Information You Provide Directly

  • Registration details: username, email address, password (stored encrypted)
  • Profile information: name, avatar, contact details (optional)
  • Transaction data: shipping address, payment method (full card numbers are not stored)
  • User-generated content: reviews, feedback, uploaded files
  • Customer support correspondence

2.2 Information Collected Automatically

  • Log data: IP address, access timestamp, page path, HTTP status codes
  • Device information: browser type, operating system, device identifiers
  • Approximate location: country/region level only (not precise GPS coordinates)
  • Cookies and similar technologies (see Section 6)

2.3 Information from Third Parties

  • When you log in via a third-party account (WeChat, Google, Apple, etc.), we receive only the profile information you have authorized for sharing
  • Aggregated, anonymized analytics data from advertising partners
Data Minimization: We collect only the personal information necessary to provide our services and will not collect information beyond what is strictly required.

3Legal Basis for Processing

Under applicable law, we process your personal information on the following legal bases:

Account creation and service delivery
Performance of a contract / Your consent
Security and fraud prevention
Legitimate interests / Legal obligation
Marketing and personalized recommendations
Your explicit consent (withdrawable at any time)
Analytics and service improvement
Legitimate interests (after anonymization)
Compliance with regulatory requirements
Legal obligation
Payment processing
Performance of a contract

For EU/UK users, we identify the specific legal basis under GDPR Article 6 for each processing activity.

4How We Use Your Information

  • Service delivery: Creating accounts, processing transactions, providing customer support
  • Service improvement: Analyzing usage patterns, optimizing UI and features
  • Security: Detecting and preventing fraud, abuse, and security vulnerabilities
  • Legal compliance: Fulfilling legal obligations, responding to lawful requests from courts or government authorities
  • Communications: Sending service notifications and security alerts (these cannot be opted out of)
  • Marketing: Sending promotional messages only with your explicit consent (opt-out available at any time)
Purpose Limitation: We will not use your personal information for purposes not described in this Policy. If we need to use your information for a new purpose, we will obtain your fresh consent.

5Sharing, Transfer & Disclosure

We do not sell your personal information. We may share it only in the following circumstances:

5.1 With Service Providers

We engage third-party service providers (e.g., cloud hosting, payment gateways, email services) who process data on our behalf under strict data processing agreements that prohibit use for any other purpose.

5.2 Legal Disclosure

We may disclose your information when required by law, court order, or governmental authority. We will notify you to the extent permitted by law.

5.3 Business Transfers

In the event of a merger, acquisition, or asset sale, we will ensure that any successor party honors this Policy and provide you with advance notice of any change in control.

5.4 Protection of Rights

We may disclose information as necessary to protect the rights, safety, or security of our company, users, or the public (e.g., reporting fraud).

Do Not Sell (CCPA): We do not sell, rent, or commercially share your personal information with third parties for their independent marketing purposes. California residents may exercise their right to opt out by contacting us as described in Section 15.

6Cookies & Similar Technologies

You can manage your cookie preferences through your browser settings. Refusing non-essential cookies will not affect core functionality. Where required, we will obtain your consent for non-essential cookies through a consent banner on your first visit.

7Data Security

We implement industry-standard technical and organizational measures to protect your information, including:

  • Transport encryption: TLS/SSL — the entire site operates over HTTPS
  • Storage encryption: AES-256 encryption for sensitive fields at rest
  • Access controls: Internal access based on least-privilege principles
  • Regular security audits and penetration testing
  • Incident response and data breach notification procedures
Limitation of Liability: No method of Internet transmission is 100% secure. To the fullest extent permitted by applicable law, we shall not be liable for data breaches caused by: (a) your own actions (e.g., disclosing your password, using public networks); or (b) events beyond our reasonable control, including but not limited to cyberattacks, natural disasters, or governmental actions. In the event of a breach, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law (72 hours under GDPR Article 33; applicable timelines under China PIPL Article 57).

8Data Storage & International Transfers

Our servers are located in China. When we transfer your data internationally, we ensure adequate safeguards as follows:

  • China users: We comply with PIPL Articles 38–40, including completing security assessments or signing standard contracts (SCCs) approved by the Cyberspace Administration of China (CAC);
  • EU/UK users: We rely on Standard Contractual Clauses (SCCs) under GDPR Article 46 or other approved transfer mechanisms;
  • California users: We ensure that recipients provide a level of protection equivalent to CCPA requirements.

9Data Retention

Account information
Duration of active account + 5 years after closure (as required by law)
Transaction records
5 years (E-Commerce Law & tax regulations)
Log data
6 months
Marketing consent records
3 years after consent is withdrawn
Customer support records
3 years

Upon expiry of the applicable retention period, we will securely delete or anonymize your personal information.

10Your Rights

Depending on your jurisdiction, you may have some or all of the following rights:

Right to Know
Understand how we process your data
🌍 Global
Right of Access
Obtain a copy of personal information we hold about you
🇨🇳 China / 🇪🇺 EU / 🇺🇸 California / 🇬🇧 UK / 🇦🇺 AU
Right to Rectification
Correct inaccurate personal information
🇨🇳 China / 🇪🇺 EU / 🇺🇸 California / 🇬🇧 UK / 🇦🇺 AU
Right to Erasure
Request deletion of your personal information (subject to conditions)
🇨🇳 China / 🇪🇺 EU / 🇺🇸 California / 🇬🇧 UK
Right to Data Portability
Export your data in a structured, machine-readable format
🇪🇺 EU / 🇬🇧 UK
Right to Object
Object to processing based on legitimate interests
🇪🇺 EU / 🇬🇧 UK
Right to Restrict
Restrict processing in certain circumstances
🇪🇺 EU / 🇬🇧 UK
Right to Withdraw Consent
Withdraw consent at any time (without affecting prior lawful processing)
🌍 Global
Right to Opt Out of Sale
Opt out of the sale of your personal information
🇺🇸 California (CCPA)
Right to Non-Discrimination
Not be discriminated against for exercising privacy rights
🇺🇸 California (CCPA)
Automated Decision-Making
Not be subject to decisions based solely on automated processing with significant effects
🇪🇺 EU / 🇬🇧 UK / 🇨🇳 China

To exercise any of these rights, please contact us using the details in Section 15. We will respond within the timeframe required by applicable law (generally within 30 days). We may need to verify your identity before processing your request.

Note: Certain rights are subject to exceptions (e.g., where we must retain data to comply with a legal obligation). If we refuse a request, we will explain why and inform you of your right to complain to a supervisory authority.

11Children's Privacy

Our services are not directed to children under 14 years old (China)16 years old (EU), or 13 years old (United States). We do not knowingly collect personal information from children below these age thresholds.

If we discover that we have inadvertently collected personal information from a child without appropriate consent, we will delete it promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us via Section 15.

Users aged 14–18 must have parental or guardian consent to use our services. Parents and guardians are responsible for supervising minors' use of this website.

12Third-Party Links Disclaimer

This website may contain links to third-party websites, services, or content. Those third parties' privacy practices are beyond the scope of this Policy.

Disclaimer: We are not responsible for the content, privacy policies, or data practices of any third-party websites. You access third-party websites at your own risk. We strongly encourage you to review the applicable privacy policy of every website you visit before submitting any personal information.

13Limitation of Liability

To the fullest extent permitted by applicable law:

  • Any loss arising from your own breach of this Policy or our Terms of Service is your sole responsibility;
  • We shall not be liable for data breaches or service interruptions caused by force majeure events, including but not limited to natural disasters, war, acts of government, cyberattacks, or network failures;
  • We shall not be liable for losses caused by your own disclosure of account credentials or use of insecure networks;
  • We exclude liability for indirect, incidental, consequential, special, or punitive damages, including loss of profits or loss of data;
  • Our total aggregate liability to you shall not exceed the fees you have actually paid to us in the 12 months preceding the claim.

The above limitations do not apply to liability arising from our gross negligence or willful misconduct, nor to any liability that cannot be excluded by applicable law (including mandatory consumer protection laws).

14Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will:

  • Post a prominent notice on our website;
  • Send you an email notification to your registered address (where applicable);
  • Update the "Last Updated" date at the top of this page.

Your continued use of our website after changes take effect constitutes your acceptance of the updated Policy. If you do not accept the changes, please stop using the website and you may request deletion of your account.

Nginx server needs to configure pseudo-static rules