Privacy Policy
HK BAUSHUN TRADE LIMITED — baotongshun.com and our iOS & Android mobile management app.
1. Interpretation & Definitions
This Privacy Policy (“Policy”) applies to the website baotongshun.com and the iOS and Android mobile management application published by HK BAUSHUN TRADE LIMITED under the same brand (together, the “Services”). It explains what personal data we collect, how we use it, who we share it with, and the rights you have over it.
Definitions used in this Policy:
- “We”, “us”, “our” — HK BAUSHUN TRADE LIMITED, the data controller for the Services.
- “You”, “your”, “user” — any natural person using the Services, including visitors of baotongshun.com and end users of the mobile app.
- “Personal data” — any information relating to an identified or identifiable natural person.
- “Processing” — any operation performed on personal data, including collection, storage, use, disclosure, and erasure.
- “SDK” — a third-party software development kit embedded in the mobile app that processes data on its own or our behalf.
- “Ad identifier” — the Apple Identifier for Advertisers (IDFA) or the Google Advertising ID (GAID) used for ad selection and attribution.
- “App-store-receipt ID” — the transaction identifier returned by Apple App Store or Google Play after a purchase or restoration.
- “Restricted transfer” — a transfer of personal data to a country outside the European Economic Area, the United Kingdom, or other jurisdiction deemed adequate by the relevant regulator.
2. Data Controller & Contact
The data controller responsible for the processing of your personal data is:
HK BAUSHUN TRADE LIMITEDRm 1339, 13/F, FOOK CHEONG BLDG,
63 HOI YUEN RD, Kwun Tong, Hong Kong
General support: support@baotongshun.com
Data Protection Officer: dpo@baotongshun.com
Key-account enquiries: yuchengkang@baotongshun.com
For data-subject requests, please use the DPO mailbox in the first instance. Postal correspondence to the Hong Kong office is also accepted. We aim to acknowledge every request within five (5) business days and to respond substantively within thirty (30) calendar days.
3. Personal Data We Collect
We collect the following categories of personal data. We do not currently collect biometric data, genetic data, or special-category data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, or sexual orientation.
3.1 Account data
Full name, email address, mobile number, hashed password, country of residence, preferred language, account role (customer, partner, staff), account status, and account creation timestamp.
3.2 Identity data
Government-issued ID number, tax identifier, or business registration number, collected only when required to fulfil anti-money-laundering, sanctions-screening, customs-declaration, or invoicing obligations.
3.3 Contact data
Billing address, shipping address, company name, job title, and any alternative contact details you provide.
3.4 Payment-token data
Last four digits of payment cards, card brand, card expiry month and year, payment-token identifiers returned by our PCI-DSS compliant payment processor, billing currency, and transaction timestamps. Full card numbers are never stored on our servers.
3.5 Device & connection data
IP address, user-agent string, operating system and version, device model, screen resolution, browser type and version, language setting, time zone, crash logs, and diagnostic identifiers.
3.6 Usage data
Pages visited, features used, in-app events, session duration, clickstream, referral source, search queries inside the Services, and purchase history.
3.7 Location data
Coarse location derived from IP address (country and city level) and, only with your explicit consent, precise location from device GPS. We do not collect precise location by default.
3.8 Cookie & similar data
First- and third-party cookies, local-storage items, web beacons, and pixels. See Section 6 for the full register.
3.9 App-store receipt data
App Store and Google Play transaction identifiers and receipts, used to validate entitlements, process refunds, and prevent fraud. We do not receive your Apple ID or Google account password.
3.10 Advertising identifiers
Apple IDFA (after ATT prompt consent) and Google GAID, used by ad partners listed in Section 7 for ad selection, frequency capping, and attribution. You can reset or revoke these identifiers in your device settings at any time.
4. How We Use Personal Data
We process personal data for the following purposes:
- Service delivery — to operate the website and app, authenticate users, fulfil orders, deliver digital products, and provide customer support.
- Customer support — to respond to enquiries, troubleshoot issues, investigate abuse, and keep a record of interactions.
- Marketing — with your consent, to send newsletters, product updates, and promotional offers by email or in-app message, and to measure campaign performance.
- Analytics — to understand how the Services are used, prioritise engineering work, detect anomalies, and improve usability.
- Security — to detect and prevent fraud, abuse, unauthorised access, and other unlawful activity, and to enforce our Terms of Service.
- Legal compliance — to comply with applicable laws, regulations, court orders, and binding requests from competent authorities, and to establish, exercise, or defend legal claims.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you, except for fraud-risk scoring in checkout, which you can contest by contacting our DPO.
5. Legal Bases
Where the General Data Protection Regulation (EU) 2016/679 (“GDPR”) or the United Kingdom GDPR applies, we rely on the following Article 6 bases:
- Performance of a contract (Art. 6(1)(b)) — for service delivery, account management, and customer support.
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, basic analytics, and product improvement, balanced against your rights and freedoms.
- Compliance with legal obligations (Art. 6(1)(c)) — for tax, accounting, customs, sanctions-screening, and law-enforcement requests.
- Consent (Art. 6(1)(a)) — for non-essential cookies, marketing email, precise location, and personalised advertising. You can withdraw consent at any time without affecting the lawfulness of prior processing.
Where the Personal Information Protection and Electronic Documents Act (Canada, “PIPEDA”) applies, we rely on the corresponding consent, necessity, and legitimate-business justifications.
Where the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”) applies, we collect and use personal information only for the disclosed purposes at or before collection, and honour the right to opt out of sale or sharing.
Where the Lei Geral de Proteção de Dados (Brazil, “LGPD”) applies, we observe the ten lawful bases in Art. 7 and the legitimate-interest regime in Art. 10.
Where the Personal Information Protection Law of the People’s Republic of China (“PIPL”) applies, we rely on consent, contract necessity, legal obligation, and the other bases set out in PIPL Art. 13.
6. Cookies & Similar Technologies
We use cookies and similar technologies on baotongshun.com. The categories are:
- Essential cookies — required for the site to function, including session, authentication, security, and load-balancing cookies. These are always on and do not require consent under GDPR Recital 32.
- Analytics cookies — first-party aggregated analytics, plus Google Analytics 4 in default (cookieless measurement) mode where deployed. We do not currently use Google Analytics advertising features.
- Advertising cookies — only on the mobile app through the SDKs listed in Section 7, not on the marketing website.
How to refuse: open the cookie banner, choose “Reject all”, and essential cookies will remain the only category set. You can also clear cookies in your browser at any time, and use your device’s “Limit Ad Tracking” (iOS) or “Opt out of Ads Personalisation” (Android) controls. Refusing non-essential cookies does not affect your access to the Services.
7. Advertising Platforms in Our Mobile App
The mobile app integrates the following advertising SDKs. Each SDK acts as a joint or independent controller of the data it processes; we have listed the partner’s privacy page for your reference. The SDK list reflects the version of the app published on the effective date of this Policy; see Section 15 for SDK versions.
7.1 Google AdMob
AdMob may collect device identifiers (GAID), IP address, coarse location, app-instance ID, ad impressions and clicks, and crash data, to serve and measure ads and to detect fraud. Privacy: https://policies.google.com/privacy.
7.2 Meta Audience Network
Meta Audience Network may collect device identifiers, coarse location, ad-event data (impressions, clicks, installs), and event timestamps to deliver and personalise ads inside the app. Privacy: https://www.facebook.com/policy.php.
7.3 AppLovin MAX / Unity Ads / ironSource
AppLovin may collect device identifiers, IP address, advertising events, session length, and SDK diagnostics to bid, serve, and attribute ads across the MAX mediation stack (which wraps Unity Ads and ironSource). Privacy: https://www.applovin.com/privacy/.
7.4 Unity Ads
Unity Ads may collect device identifiers, IP-derived coarse location, session events, and ad-interaction data to deliver ads, frequency-cap them, and prevent fraud. Privacy: https://unity.com/legal/game-player-and-app-user-privacy-policy.
7.5 ironSource
ironSource may collect device identifiers, session events, in-app placement IDs, and ad-interaction data to deliver, measure, and optimise ads. Privacy: https://www.is.com/privacy-policy/.
7.6 Pangle / ByteDance
Pangle may collect device identifiers, IP address, coarse location, ad-event data, and frequency-cap state to deliver ads, including in non-EU markets where the TikTok for Business auction runs. Privacy: https://www.pangleglobal.com/privacy.
7.7 TikTok Audience
TikTok Audience may collect device identifiers, IP address, coarse location, and ad-event data to deliver and measure ads in regions where Pangle and TikTok Audience operate. Privacy: https://www.tiktok.com/legal/privacy-policy.
7.8 Mintegral
Mintegral may collect device identifiers, IP address, coarse location, ad-event data, and SDK diagnostics to bid and serve ads and to detect click-injection and other invalid-traffic patterns. Privacy: https://www.mintegral.com/en/privacy.
7.9 InMobi
InMobi may collect device identifiers, IP-derived coarse location, interaction data, and inferred interests to deliver and personalise ads and to run brand-survey research. Privacy: https://www.inmobi.com/privacy-policy.
7.10 Vungle
Vungle may collect device identifiers, IP address, ad-event data, and session length to deliver rewarded video and other ad formats, and to attribute installs. Privacy: https://vungle.com/privacy/.
7.11 Chartboost
Chartboost may collect device identifiers, IP address, in-app event data, and ad-interaction data to serve ads, run cross-promotion between apps, and measure campaign performance. Privacy: https://www.chartboost.com/privacy/.
7.12 Digital Turbine / Fyber
Fyber may collect device identifiers, IP address, ad-event data, and SDK diagnostics to deliver ads, manage yield, and detect invalid traffic. Privacy: https://www.digitalturbine.com/privacy-policy/.
7.13 Start.io
Start.io may collect device identifiers, IP address, coarse location, and ad-event data to serve ads and build aggregated interest segments. Privacy: https://www.start.io/policy/privacy-policy/.
7.14 Smaato
Smaato may collect device identifiers, IP address, ad-event data, and frequency-cap state to run real-time bidding and serve ads across its exchange. Privacy: https://www.smaato.com/privacy/.
7.15 AdColony
AdColony may collect device identifiers, IP address, coarse location, and ad-event data to deliver interactive and high-definition video ads and to detect fraud. Privacy: https://www.adcolony.com/privacy/.
7.16 Tapjoy
Tapjoy may collect device identifiers, IP address, in-app event data, and reward-completion data to deliver rewarded ads, including offerwall engagement. Privacy: https://www.tapjoy.com/legal/advertisers/privacy-policy/.
7.17 Verizon Media / Yahoo
Verizon Media (formerly Yahoo Flurry) may collect device identifiers, IP address, session events, and ad-event data to serve ads and to provide aggregated analytics. Privacy: https://www.verizonmedia.com/policies/us/en/verizonmedia/privacy/index.html.
7.18 Mobfox
Mobfox may collect device identifiers, IP address, coarse location, and ad-event data to bid and serve ads across its mobile exchange. Privacy: https://www.mobfox.com/privacy-policy/.
7.19 Ogury
Ogury may collect device identifiers, coarse location, ad-event data, and declared user interests to deliver personified ads and to measure campaign performance. Privacy: https://ogury.com/privacy-policy/.
8. Ad Types in the App
The app uses six ad formats. Each format’s frequency cap and your controls are described below. Frequency caps are enforced client-side by the SDKs where supported; where a cap is not supported by a partner, we do not currently enable that placement.
8.1 Splash / app-open
Shown on cold start, capped at one impression per session per user. Capped placements are not personalised. You can disable splash ads by enabling the in-app “Reduce motion and ads” toggle in Settings → Privacy.
8.2 Rewarded video
User-initiated. Capped at six completions per user per day, twelve per week. Reward is granted only after the SDK reports a valid completion event. You can decline to watch a rewarded video at any time; the feature the reward unlocks simply remains locked.
8.3 Interstitial
Full-screen ads shown at natural transition points. Capped at one impression per user per two minutes, six per session. You can dismiss an interstitial by tapping the close control as soon as it is visible.
8.4 Banner
Persistent strip at the bottom of selected screens. Capped at one visible banner per screen. You can hide all banners by purchasing the in-app “ad-free” entitlement where offered.
8.5 Native
Card-style ad unit rendered in-stream with editorial cards. Capped at one native slot per scroll depth, refreshed every forty-five seconds. Disclosure of sponsored content is shown by an “Ad” label on every native unit.
8.6 MREC (Medium Rectangle)
300×250 inline unit embedded in app screens where supported by the layout. Capped at one visible MREC per screen, refreshed every sixty seconds. Hide controls are provided wherever an MREC is rendered.
9. Children’s Privacy
The Services are not directed to children. The age thresholds we apply are:
- 13 — the United States Children’s Online Privacy Protection Act (“COPPA”).
- 16 — the default under the EU and UK GDPR; member states may raise the threshold to a higher age but not lower it.
- 14 — the People’s Republic of China under PIPL Art. 31.
- 18 — Brazil under LGPD Art. 18 (“criança”) and Art. 18-A (“adolescente”).
- 14 — Australia under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
We do not knowingly collect personal data from anyone below these ages. If we identify that we have collected data from a child below the applicable threshold, we delete the data within thirty (30) days. Specifically:
- Ad personalisation is disabled in our mediation stack for any account flagged as under-age.
- Ad-attribution identifiers (IDFA / GAID) are not requested from devices where the registered user’s age is below the applicable threshold.
- Analytics events from under-age accounts are stored in aggregate-only mode and stripped of any persistent identifiers within seven (7) days.
A parent or guardian who believes a child has provided personal data may email dpo@baotongshun.com to request deletion. We will verify the request, delete the data, and confirm completion within thirty (30) days.
10. International Transfers
We are headquartered in Hong Kong and engage processors and ad partners in the European Union, the United Kingdom, the United States, Singapore, India, China, and other jurisdictions. Where personal data leaves a country, we use the following transfer mechanisms:
- EU Standard Contractual Clauses — Commission Implementing Decision (EU) 2021/914, Module 1 (controller to controller) and Module 2 (controller to processor), as appropriate.
- UK International Data Transfer Agreement — the IDTA, or the EU SCCs as approved by the UK ICO under the UK GDPR international-transfer regime.
- Hong Kong PDPO — Section 33 cross-border transfer principles, including the data user’s accountability for the recipient’s protection.
- China PIPL standard contract — the Standard Contract for Cross-Border Transfer of Personal Information (Cyberspace Administration of China, 2023) where data leaves mainland China.
- Transfer impact assessment — a written assessment of destination-jurisdiction law and practice, refreshed annually and on material change.
- Supplementary measures — encryption in transit (TLS 1.2 or higher) and at rest (AES-256), pseudonymisation where feasible, contractual audit rights, and notice to you of any government-access request that affects your data.
You can request a copy of the transfer mechanism and the transfer impact assessment relevant to your data by emailing dpo@baotongshun.com.
11. Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy or as required by law. The schedule below is current as of the effective date of this Policy and is reviewed at least annually.
| Category | Retention period | Basis |
|---|---|---|
| Account data | 7 years after account closure | Tax, AML, legal-claims limitation |
| Identity-verification data | 5 years after last interaction | AML / KYC obligations |
| Support-ticket data | 3 years after ticket closure | Service-quality, dispute defence |
| Analytics (aggregated) | 26 months from collection | Product-improvement legitimate interest |
| Analytics (per-user) | 13 months from collection | Product-improvement legitimate interest |
| Ad-attribution data | 13 months from impression | Industry-standard attribution window |
| Marketing data | 24 months from last engagement | Consent and suppression-list maintenance |
| Accounting and tax records | 7 years from period end | Inland Revenue (HK) and equivalents |
| Server access logs | 90 days from event | Security and incident response |
| Backups (encrypted) | 35 days rolling, then overwrite | Disaster-recovery continuity |
At the end of the retention period, personal data is either deleted, anonymised (so it can no longer be associated with you), or archived in a form that prevents further processing, whichever is appropriate.
12. Your Rights
Subject to the law that applies to you, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete personal data.
- Erasure (“right to be forgotten”) — request deletion of your personal data where the legal grounds apply.
- Restriction — ask us to suspend processing of your personal data while a dispute is resolved.
- Portability — receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Objection — object to processing based on legitimate interest, including profiling.
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Opt out of sale or sharing — under CCPA/CPRA, and equivalent rights in other US states.
- Limit use of sensitive personal information — under CCPA/CPRA, where applicable.
- Opt out of automated decision-making — including profiling that produces legal or similarly significant effects.
Where local law provides additional rights — for example, the right to data portability under PIPL, the right to confirmation of existence under LGPD, or the right to nominate a representative under the Indian DPDP Act — those rights are preserved and exercised through the same channel.
13. How to Exercise Rights & DPO Contact
To exercise any of the rights set out in Section 12, contact our Data Protection Officer:
Data Protection Officer — HK BAUSHUN TRADE LIMITEDEmail: dpo@baotongshun.com
Postal: Rm 1339, 13/F, FOOK CHEONG BLDG, 63 HOI YUEN RD, Kwun Tong, Hong Kong
Please include enough information for us to verify your identity (name, account email, and a recent transaction reference, where applicable). Where the request is made by an authorised agent, we will require proof of authorisation. We will not charge a fee for responding to a verifiable request, unless the request is manifestly unfounded or excessive.
Response window. We acknowledge requests within five (5) business days and respond substantively within thirty (30) calendar days. If we need more time, we will tell you why and when you can expect a full answer, up to a maximum of ninety (90) days in aggregate (sixty (60) days under the UK GDPR, fifteen (15) days under PIPL).
You also have the right to lodge a complaint with a supervisory authority. Examples include the Office of the Privacy Commissioner for Personal Data (Hong Kong), the European Data Protection Board (via your national authority), the Information Commissioner’s Office (United Kingdom), the Office of the Privacy Commissioner of Canada, the Autoridade Nacional de Proteção de Dados (Brazil), the Cyberspace Administration of China, and the California Privacy Protection Agency.
14. Security Measures
We apply technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These include:
- Transport encryption — TLS 1.2 or higher on all client-facing endpoints; HSTS preload; modern cipher suites only.
- Storage encryption — AES-256 at rest for relational databases, object storage, and backups; envelope encryption with key rotation at least every twelve (12) months.
- Access control — role-based access control, least-privilege grants, and quarterly access reviews for all production systems.
- Staff authentication — mandatory multi-factor authentication for all staff with production access; hardware-key MFA for administrators.
- Vendor due diligence — security and privacy questionnaires, contractual data-processing terms, and audit rights for every sub-processor that handles personal data.
- Incident response — a documented incident response plan, tabletop exercises twice a year, and a personal-data breach notification clock that triggers supervisory-authority notice within seventy-two (72) hours of awareness under GDPR Art. 33, and equivalent clocks under PIPL and the HK PDPO.
No security measure is perfect. If we determine that a personal-data breach has occurred and that it is likely to result in a risk to your rights and freedoms, we will notify you without undue delay.
15. Third-Party Links & SDKs
The Services may contain links to third-party websites and resources we do not control (for example, business partners, logistics carriers, payment processors, and trade-data services). This Policy does not apply to those sites. Review each site’s privacy notice before providing personal data.
The mobile app integrates the SDKs listed in Section 7. We are not responsible for the independent practices of those SDK providers, although we require each provider by contract to maintain a published privacy notice, to honour your opt-out signals, and to comply with applicable data-protection law.
SDK versions present in the most recent app release (build dated 2026-09-09):
| SDK | Purpose | Version |
|---|---|---|
| Google Mobile Ads SDK (AdMob) | Ads | 23.5.0 |
| Meta Audience Network SDK | Ads | 6.17.0 |
| AppLovin MAX SDK | Mediation / ads | 12.4.1 |
| Unity Ads SDK | Ads | 4.12.2 |
| ironSource SDK | Ads | 7.6.1 |
| Pangle SDK (ByteDance) | Ads | 5.8.0.3 |
| TikTok Audience SDK | Ads | 1.4.0 |
| Mintegral SDK | Ads | 16.5.41 |
| InMobi SDK | Ads | 10.6.0 |
| Vungle SDK | Ads | 7.1.0 |
| Chartboost SDK | Ads | 9.7.0 |
| Fyber SDK (Digital Turbine) | Ads | 8.3.2 |
| Start.io SDK | Ads | 4.8.4 |
| Smaato SDK | Ads | 22.7.0 |
| AdColony SDK | Ads | 4.8.2 |
| Tapjoy SDK | Ads | 13.2.0 |
| Verizon Media SDK (Yahoo) | Ads / analytics | 1.13.0 |
| Mobfox SDK | Ads | 5.8.0 |
| Ogury SDK | Ads | 5.6.0 |
| Firebase Crashlytics | Crash diagnostics | 11.4.0 |
| Google Analytics for Firebase | Analytics | 11.3.0 |
16. Changes to This Policy
We review this Policy at least annually and update it when our processing, the Services, or the law changes. For any material change — meaning a change that broadens the categories of personal data we collect, the purposes for which we use it, the parties with whom we share it, or your rights — we will give you at least thirty (30) days’ notice by:
- email to the address associated with your account, and
- a banner in the mobile app and a banner on baotongshun.com.
Non-material changes (for example, contact-detail updates, typographical corrections, or new sub-processors for the same purpose) are reflected in the version history below without separate notice.
16.1 Version history
| Version | Effective date | Summary of change |
|---|---|---|
| 1.0.0 | 2026-09-09 | Initial publication; full SDK disclosure; country addenda for 12 jurisdictions. |
17. Country-Specific Addenda
The following provisions apply in addition to the rest of this Policy where you are located in, or where the relevant law otherwise applies to your personal data. If a provision conflicts with another part of this Policy, the country-specific provision controls for that jurisdiction.
17.1 United States — CCPA / CPRA
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, the following categories of personal information may be collected and processed as set out in this Policy: identifiers (name, email, phone, IP, account ID), commercial information (purchase history), internet activity (browsing and usage data), geolocation (coarse), audio or visual information (none collected), professional or employment-related information (job title, company), and inferences drawn from the above. We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age. California residents may exercise the right to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information by following the steps in Section 13. The Notice at Collection is this Policy together with the categories listed above and the purposes set out in Section 4.
17.2 European Union & United Kingdom
Where the GDPR or the UK GDPR applies, our representative in the European Union can be reached at eu-rep@baotongshun.com pending the appointment of a formal Art. 27 representative (the team will wire up this mailbox and update the entry to list the appointed representative). For the United Kingdom, the Information Commissioner’s Office is the supervisory authority. We rely on the legal bases set out in Section 5 and the international-transfer mechanisms set out in Section 10.
17.3 Canada — PIPEDA & Quebec Law 25
We comply with the Personal Information Protection and Electronic Documents Act and, where applicable, the Act respecting the protection of personal information in the private sector (Québec) as amended by Law 25, including the requirements for a privacy officer (the DPO listed in Section 2), incident-response planning, and prior privacy impact assessments for high-risk processing. Consent under PIPEDA may be express or implied depending on sensitivity and context.
17.4 Brazil — LGPD
We comply with the Lei Geral de Proteção de Dados. The data-subject rights set out in Section 12 mirror LGPD Art. 18. The Autoridade Nacional de Proteção de Dados (ANPD) is the supervisory authority. Where the LGPD’s international-transfer rules apply, we use the standard contractual clauses or other lawful mechanisms recognised by the ANPD.
17.5 China — PIPL, DSL, CSL, CAC Standard Contract
We comply with the Personal Information Protection Law, the Data Security Law, and the Cybersecurity Law. For cross-border transfers out of mainland China, we use the CAC Standard Contract for Cross-Border Transfer of Personal Information, supplemented by a personal-information protection impact assessment, security assessment, or certification as required by the volume and sensitivity of the data and the nature of the recipient.
17.6 Australia — Privacy Act 1988 (Cth)
We comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Notifiable Data Breaches scheme as amended by the Privacy and Other Legislation Amendment Act 2024. The Office of the Australian Information Commissioner (OAIC) is the supervisory authority. We will notify the OAIC and affected individuals of any eligible data breach in accordance with the statutory statement-notification framework.
17.7 Singapore — PDPA
We comply with the Personal Data Protection Act 2012 as amended by the Personal Data Protection (Amendment) Act 2021, including the mandatory data-breach notification, the consent-and-purpose-limitation obligations, and the transfer-limitation arrangements (the standard contractual clauses or binding corporate rules prescribed by the PDPC).
17.8 Japan — APPI
We comply with the Act on the Protection of Personal Information, including its 2022 amendments on opt-in consent for sensitive personal information and the anonymous-processed-information framework, and the cross-border-transfer rules (whitelist or standard contract).
17.9 South Korea — PIPA
We comply with the Personal Information Protection Act, including the resident-registration-number handling rules, the cross-border-transfer consent and disclosure requirements, and the data-breach notification rules administered by the Personal Information Protection Commission.
17.10 Hong Kong — PDPO
We comply with the Personal Data (Privacy) Ordinance (Cap. 486), the six data-protection principles, and the cross-border-transfer requirements in Section 33. The Office of the Privacy Commissioner for Personal Data is the supervisory authority.
17.11 India — DPDP Act 2023
We comply with the Digital Personal Data Protection Act 2023, including notice-and-consent requirements, the right of data principals to access, correction, erasure, and grievance redressal, and the cross-border-transfer restrictions on data of data principals located outside notified countries. The Data Protection Board of India is the adjudicatory body.
17.12 South Africa — POPIA
We comply with the Protection of Personal Information Act, including the lawful-processing grounds in Section 11, the information-handler obligations, and the cross-border-transfer rules in Section 72. The Information Regulator is the supervisory authority.
17.13 New Zealand — Privacy Act 2020
We comply with the Privacy Act 2020, including the IPPs, the cross-border-disclosure rules (IPP 12), the notifiable-privacy-breach regime, and the requirements to appoint a privacy officer and to comply with directions issued by the Office of the Privacy Commissioner.
18. App Store Specifics
18.1 Google Play
The app is published on Google Play and aligns with the Google Play User Data Policy, including the requirement to disclose data collection and to honour the “Data safety” form. The form currently declares the following mappings: data collected (account data, device data, app activity, in-app purchase history, app-store-receipt IDs, advertising IDs, optional precise location); data shared with the 19 ad partners listed in Section 7 for ad personalisation; data used to track users across apps and websites; data linked to your identity (account, purchases, in-app events); data not linked to your identity (aggregated crash and analytics).
18.2 Apple App Store
The app is published on the Apple App Store and aligns with Apple App Store Review Guidelines 5.1.1 (privacy) and 5.1.2 (data use and sharing). The App Privacy labels declare the same mappings as the Google Play Data Safety form above. On iOS, the app triggers the App Tracking Transparency (ATT) prompt on first launch of any ad-supported screen; the prompt is required before IDFA is read. You can change your ATT answer at any time in iOS Settings → Privacy & Security → Tracking.
18.3 Families & age rating
The app is rated 4+ on the App Store and Everyone on Google Play. The app does not include user-generated content, in-app chat, or open social features that would change the age rating. See Section 9 for our children’s-privacy commitments.