1. Introduction and Scope
This Privacy Policy applies to all websites operated by HZXingyuTrade, including hzxingyutrade.com and subdomains, and all mobile applications published on the Apple App Store, Google Play Store, Huawei AppGallery, Samsung Galaxy Store, Amazon Appstore, and other distribution platforms (collectively, our Services).
HZXingyuTrade is a research and development team headquartered at Sheffield Science Park, United Kingdom. We are committed to protecting your privacy and handling your data with transparency, integrity, and care. This Policy complies with global privacy regulations including GDPR (EU and UK), CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), LGPD (Brazil), PIPL (China), PIPEDA (Canada), Privacy Act (Australia), APPI (Japan), PIPA (South Korea), DPDPA (India), COPPA (US Childrens Privacy), and the UK Age-Appropriate Design Code.
2. Definitions
- Personal Data means information relating to an identified or identifiable natural person.
- Processing means any operation performed on Personal Data.
- Controller means the entity determining purposes and means of processing. HZXingyuTrade is the Controller.
- Advertising Identifier means the Apple IDFA or Google AAID.
- SDK means a software development kit integrated into our Apps.
We follow data minimization. Categories of information:
3.1 Information You Provide Directly
- Contact Information: When you contact us via email (contact@hzxingyutrade.com or support@hzxingyutrade.com), we collect name, email, subject, and message.
- User Content: Content you create in our Apps (audio, photos, notes, lists) is stored locally on your device by default.
- Feedback: Bug reports and support tickets you submit.
3.2 Information Collected Automatically
- Device Info: Device type, OS version, model, language, timezone, device identifiers.
- Usage Data: Features used, screens viewed, session duration, crash logs, performance data. Anonymized where possible.
- Log Data: Truncated IP address, browser type, pages visited, timestamps, referring URLs.
- Advertising IDs: IDFA/AAID only with consent via ATT framework or equivalent.
4. How We Use Information
- Service Delivery: To provide, maintain, improve, and personalize our Services.
- Communication: To respond to inquiries and provide support.
- Analytics: To understand usage patterns and improve UX.
- Advertising: To display ads through integrated platforms (see Section 6).
- Security: To detect and prevent fraud, abuse, and technical issues.
- Legal Compliance: To comply with applicable laws.
- R&D: To develop new products and features.
5. Legal Basis for Processing (GDPR)
For EEA/UK/Switzerland users, we process Personal Data under:
- Consent (Art 6(1)(a)): Non-essential cookies, personalized ads, optional communications.
- Contract (Art 6(1)(b)): To fulfill our contractual obligations.
- Legitimate Interests (Art 6(1)(f)): Analytics, security, fraud prevention, service improvement.
- Legal Obligation (Art 6(1)(c)): To comply with applicable laws.
6. Advertising Platforms and Ad Networks
Our mobile applications may display advertisements through integrated third-party advertising platforms (Ad Networks). We work with multiple Ad Networks to support free access to our Apps while maintaining user privacy. Each Ad Network has its own data practices, governed by their respective privacy policies.
6.1 General Advertising Principles
- We display non-personalized ads by default, where supported by the Ad Network.
- We do not use your data for personalized ad targeting unless you provide explicit consent.
- We comply with Apples App Tracking Transparency (ATT) framework on iOS 14.5+ and Googles User Messaging Platform (UMP) on Android.
- We implement Googles Family Policy and Designed for Families standards where applicable.
- We honor user opt-outs from personalized advertising at the device level (Limit Ad Tracking on iOS, Opt out of Ads Personalization on Android).
- We do not serve behavioral advertising to users under 18 (see Age Restrictions section).
- Frequency capping is applied to limit ad repetition (typically 3 impressions per user per hour per ad unit).
6.2 Ad Network Compliance
All Ad Networks we integrate must:
- Comply with GDPR, CCPA, COPPA, and applicable local privacy laws.
- Honor user consent and opt-out signals.
- Provide transparent privacy notices.
- Implement appropriate security measures.
- Refrain from collecting sensitive personal information.
- Support child-directed treatment flags where applicable.
7. Google AdMob Integration
Our mobile applications integrate Google AdMob, a mobile advertising platform provided by Google LLC (and Google Ireland Limited for EEA users). AdMob is our main monetization partner for free apps.
7.1 What AdMob Collects
When you use our Apps with AdMob enabled, Google may collect:
- Device Identifiers: Advertising ID (IDFA on iOS, AAID on Android), device fingerprint (hashed), Android ID (if AAID unavailable).
- Device Information: Device model, OS version, language, screen size, carrier, network type.
- App Information: App version, session duration, in-app actions.
- Ad Interaction Data: Ad impressions, clicks, conversions, view-through conversions.
- Location Data: Coarse location derived from IP address (city/country level only, unless user consents to precise location).
- Crash Logs and Diagnostics: For SDK stability.
7.2 How AdMob Uses Data
Google uses this data to:
- Select and serve relevant ads (subject to your consent).
- Measure ad performance and prevent fraud.
- Improve AdMob and other Google services.
- Comply with legal obligations.
7.3 AdMob Privacy Controls
You can control AdMob data collection through:
- iOS Settings > Privacy > Tracking: Toggle "Allow Apps to Request to Track" off.
- iOS Settings > Privacy > Apple Advertising: Toggle "Personalized Ads" off.
- Android Settings > Google > Ads: Toggle "Opt out of Ads Personalization" on.
- Google Ads Settings: Visit adssettings.google.com to manage ad personalization.
- My Account > Ad Choices: Within our Apps, navigate to Settings > Privacy > Ad Choices.
7.4 AdMob SDK Initialization
Our Apps initialize the AdMob SDK only after:
- You have granted ATT permission (iOS), OR
- You have provided consent via Googles UMP consent dialog (Android/EEA), OR
- Non-personalized ads are explicitly enabled for users who decline consent.
The SDK does not collect advertising identifiers before user consent is determined.
7.5 AdMob for Children
For Apps designated as "Designed for Families" or "Made for Kids":
- We serve only contextually appropriate, non-personalized ads.
- AdMob Tag For Child-Directed Treatment (TFCDT) flag is set to true.
- No advertising identifiers are collected or used.
- AdMob disables interest-based advertising and remarketing.
- We do not use third-party SDKs that collect personal information from children.
8. Ad Formats and Frequency
Our Apps may display the following ad formats, depending on the specific App and platform:
| Ad Format | Description | Frequency |
|---|
| Banner Ads | Standard rectangular ads at top or bottom of screen. Sizes include 320x50, 300x250, and adaptive banner. | Always visible when present; refreshed every 30-60 seconds |
| Interstitial Ads | Full-screen ads at natural transition points. Skippable after 5 seconds. | Max once per 4 minutes; never more than 3 per session |
| Rewarded Video Ads | User-initiated video ads offering in-app rewards upon completion. | User-initiated; 60-second cooldown between rewards |
| Native Ads | Ads designed to match visual design of App, integrated into content feeds. | 1 per 5 content items in feed views |
| App Open Ads | Full-screen ads displayed when users open or return to App. | Max once per session; suppressed if user recently dismissed |
| Rewarded Interstitial Ads | Hybrid format offering rewards for viewing full-screen interstitial. | User-initiated with 60-second cooldown |
| MREC Ads | 300x250 medium rectangle ads in scrollable content. | Refreshed every 45 seconds |
Frequency Caps:
- Maximum 3 impressions per user per hour (combined).
- No two interstitial ads within 4 minutes.
- App open ads suppressed after user dismissal for 4 hours.
- Rewarded ads require explicit user action.
9. Third-Party Advertising Partners
In addition to Google AdMob, our Apps may integrate the following advertising partners. Each partner is independently responsible for its own data practices:
9.1 Meta Audience Network (Facebook)
Provided by Meta Platforms, Inc. Governed by Meta Privacy Policy. Used for banner, interstitial, and rewarded video ads. Supports ATT and GDPR consent.
9.2 Unity Ads
Provided by Unity Technologies. Governed by Unity Privacy Policy. Used primarily for rewarded video ads in gaming-adjacent contexts.
9.3 AppLovin MAX
Provided by AppLovin Corporation. Governed by AppLovin Privacy Policy. Used for mediation between multiple ad networks including AdMob.
9.4 ironSource (now Unity)
Provided by ironSource. Supports rewarded video, interstitial, and banner formats.
9.5 Vungle
Provided by Vungle (a Lionsgate company). Used primarily for rewarded video ads.
9.6 Chartboost
Provided by Chartboost, Inc. Used for in-app programmatic advertising mediation.
9.7 Tapjoy
Provided by Tapjoy, Inc. Specializes in rewarded video and offerwall formats.
9.8 Pangle (by ByteDance)
Provided by ByteDance. Used primarily in Asian markets.
9.9 InMobi
Provided by InMobi Technology Services. Global mobile ad network.
9.10 Amazon Publisher Services
Provided by Amazon.com, Inc. Unified auction-based advertising.
9.11 Yahoo Gemini / Verizon Media
Native advertising and search advertising. Subject to Verizon Media Privacy Policy.
9.12 Criteo
Retargeting and personalized advertising. Governed by Criteo Privacy Policy.
9.13 Smaato
Real-time advertising exchange for mobile apps.
9.14 Digital Turbine (AdColony)
Provided by Digital Turbine. Used for video and interactive ads.
Each of these partners has been vetted for compliance with GDPR, CCPA, COPPA, and applicable regional privacy laws. You can opt out of personalized advertising from any partner through your device settings or by contacting us.
10. App Store Specific Policies
10.1 Apple App Store
Our Apps published on the Apple App Store comply with:
- Apple Developer Program License Agreement.
- App Store Review Guidelines, including Sections 5.1.1 (Privacy) and 5.1.2 (Data Use and Sharing).
- App Tracking Transparency (ATT) framework requirements.
- Privacy Nutrition Labels disclosing data collection practices.
- App Privacy Report showing all sensor, hardware, and data accesses.
- Apple Privacy Policy (in addition to this Policy).
- Apple-designed standard EULA where applicable.
10.2 Google Play Store
Our Apps published on Google Play comply with:
- Google Play Developer Distribution Agreement.
- Google Play Developer Policy, including User Data policies.
- Google Play Families Policy for child-directed content.
- Data Safety Form disclosures.
- User Messaging Platform (UMP) consent requirements.
- Google Play Console privacy disclosures.
10.3 Huawei AppGallery
For Apps published on Huawei AppGallery, we comply with Huawei Developer terms, HMS Core privacy requirements, and applicable Chinese privacy laws including PIPL.
10.4 Samsung Galaxy Store
For Apps published on Samsung Galaxy Store, we comply with Samsung Developer terms and Galaxy Store privacy requirements.
10.5 Amazon Appstore
For Apps published on Amazon Appstore, we comply with Amazon Developer Services Agreement and Amazon privacy requirements.
11. Data Sharing and Disclosure
We do not sell your Personal Data. Period. We share data only in the following limited circumstances:
11.1 Service Providers
We share data with vetted service providers who perform services on our behalf, including:
- Cloud hosting providers (where applicable).
- Analytics providers (anonymized data only).
- Customer support platforms.
- Email service providers.
- Advertising networks (with your consent).
All service providers are bound by confidentiality and data processing agreements.
11.2 Legal Requirements
We may disclose data when required by law, including:
- To comply with court orders, subpoenas, or legal process.
- To cooperate with law enforcement investigations.
- To respond to lawful government requests.
- To enforce our Terms of Service.
- To protect our rights, privacy, safety, or property.
11.3 Business Transfers
If HZXingyuTrade is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. You will be notified via email and/or prominent notice on of our Services.
11.4 Aggregated/Anonymized Data
We may share aggregated or fully anonymized data with third parties for research, analytics, or marketing purposes. Such data cannot be used to identify you.
12. International Data Transfers
HZXingyuTrade is based in the United Kingdom, but our service providers and partners may be located worldwide. When we transfer your data outside your country of residence, we ensure appropriate safeguards:
- EEA/UK Transfers: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and UK ICO, the UK International Data Transfer Agreement (IDTA), and adequacy decisions.
- US-EU Data Privacy Framework: For transfers to US partners certified under the EU-US Data Privacy Framework, UK Extension, or Swiss-US Data Privacy Framework.
- APEC Cross-Border Privacy Rules (CBPR): For transfers among APEC economies.
- Binding Corporate Rules (BCRs): Where applicable.
For users in China, India, Russia, and other countries with data localization requirements, we ensure data is stored in compliance with local laws.
13. Data Retention
We retain Personal Data only as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specific retention periods:
- Contact Inquiries: Retained for 2 years from last interaction.
- Support Tickets: Retained for 3 years for quality assurance.
- Analytics Data: Aggregated data retained indefinitely; raw logs purged after 14 months.
- User-Generated Content: Retained on your device until you delete it or uninstall the App.
- Account Data: Retained until you delete your account, plus 30 days grace period.
- Advertising Data: Subject to Ad Network retention policies (typically 13-18 months for Google).
Upon termination of services or upon your valid deletion request, we will delete or anonymize your Personal Data within 30 days, except where retention is required by law.
14. Security Measures
We implement industry-standard security measures to protect your Personal Data, including:
- Encryption in Transit: TLS 1.3 for all data transmissions.
- Encryption at Rest: AES-256 for stored data; iOS Data Protection and Android Keystore for credential storage.
- Access Controls: Role-based access, multi-factor authentication, principle of least privilege.
- Regular Audits: Internal security audits and third-party penetration testing.
- Secure Development: OWASP Mobile Top 10 compliance, code reviews, automated security scanning.
- Incident Response: 24/7 monitoring, documented breach response procedures, regulatory notification within 72 hours (GDPR).
- Vendor Management: Security assessments of all service providers.
- Employee Training: Regular privacy and security awareness training.
Despite our efforts, no security measure is 100% perfect. If you discover a security vulnerability, please contact us at security@hzxingyutrade.com.
15. Your Rights and Choices
Depending on your jurisdiction, you have the following rights regarding your Personal Data:
15.1 Universal Rights
- Right to Know: What data we collect, how we use it, and who we share it with.
- Right to Access: Request a copy of your Personal Data.
- Right to Correct: Request correction of inaccurate or incomplete data.
- Right to Delete: Request deletion of your Personal Data (subject to legal exceptions).
- Right to Withdraw Consent: Withdraw previously granted consent at any time.
15.2 GDPR Rights (EEA/UK/Switzerland)
In addition to universal rights, EEA/UK/Switzerland users have:
- Right to Data Portability: Receive data in a structured, commonly used, machine-readable format.
- Right to Restrict Processing: Request limitation of processing in certain circumstances.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Lodge Not: Lodge a complaint with your supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany).
- Right Not to Be Subject to Automated Decision-Making: Including profiling, with legal or similarly significant effects.
15.3 CCPA/CPRA Rights (California)
California residents have additional rights under CCPA/CPRA:
- Right to Know: Specific pieces of Personal Data collected, categories, sources, and business purposes.
- Right to Delete: Personal Data collected from you (with exceptions).
- Right to Correct: Inaccurate Personal Data.
- Right to Opt-Out of Sale or Sharing: We do not sell Personal Data; you may opt out of sharing for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: To only what is necessary to provide services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Designate an Authorized Agent: To make a request on your behalf.
To exercise these rights, California residents may email privacy@hzxingyutrade.com or call our toll-free number (where required).
15.4 Exercising Your Rights
To exercise any of these rights, contact us at contact@hzxingyutrade.com or support@hzxingyutrade.com. We will respond within 30 days (or such shorter period as required by law). We may need to verify your identity before processing your request to protect against fraud.
16. Childrens Privacy (COPPA, GDPR-K, AADC)
We are committed to protecting childrens privacy. Our practices comply with:
- COPPA (US): Childrens Online Privacy Protection Act for users under 13.
- GDPR Article 8: For users under 16 (or as defined by member state law).
- UK AADC: Age-Appropriate Design Code for all users under 18.
- India DPDPA Section 9: For users under 18.
16.1 Our Children-Focused Practices
- We do not knowingly collect Personal Data from children under 13 (or under 16 in the EEA/UK) without verifiable parental consent.
- For Apps targeted at children, we use only contextually appropriate, non-personalized advertising.
- We do not use behavioral advertising or remarketing to known children.
- We do not collect precise location data from children.
- We disable all third-party tracking SDKs in child-directed sections of our Apps.
- We provide age screens to verify appropriate user age.
- We honor parental requests to delete childrens data promptly.
16.2 Parental Rights
Parents and guardians may:
- Review Personal Data collected from their child.
- Request deletion of their childs Personal Data.
- Refuse to permit further collection of their childs data.
To exercise these rights, parents may contact us at contact@hzxingyutrade.com.
17. Age Restrictions by Jurisdiction
The minimum age to use our Services varies depending on your jurisdiction:
| Jurisdiction | Minimum Age | Legal Basis |
|---|
| United States | 13 | COPPA |
| California | 13 | CCPA / COPPA |
| European Union | 16 (default; 13 in some member states) | GDPR Article 8 |
| United Kingdom | 13 | UK GDPR / AADC |
| Switzerland | 16 | FADP |
| Canada | 13 (varies by province) | PIPEDA / Provincial laws |
| Australia | 15 (or under parental supervision) | Privacy Act 1988 |
| Japan | 18 (for consent to information handling) | APPI |
| South Korea | 14 | PIPA |
| China | 14 | PIPL |
| India | 18 | DPDPA |
| Brazil | 12 (with parental consent) or 16 | LGPD |
| Russia | 18 (for personal data consent) | Federal Law 152-FZ |
| Singapore | 13 | PDPA |
If you are under the minimum applicable age, you may only use our Services with verifiable parental or guardian consent. We do not knowingly allow users under the applicable age to use our Services without such consent.
18. Cookies and Tracking Technologies
18.1 Cookies We Use
Our website uses the following cookies:
- Strictly Necessary Cookies: Required for core website functionality (session management, security). Cannot be disabled.
- Preference Cookies: Remember your preferences (language, theme). Optional.
- Analytics Cookies: Anonymized usage analytics. Optional.
- Marketing Cookies: Not used on our website.
18.2 Local Storage and Similar Technologies
Our Apps use:
- Local Storage: For app preferences, user-generated content.
- Keychain (iOS): For secure credential storage.
- EncryptedSharedPreferences (Android): For secure preferences.
- NSUserDefaults: For non-sensitive preferences on iOS.
18.3 Cookie Consent Management
For EEA/UK users, we display a cookie consent banner on first visit. You can change your preferences at any time via the Cookie Settings link in our footer.
19. Regional Privacy Rights
19.1 European Economic Area (EEA) and United Kingdom
If you are in the EEA or UK, you have the rights described in Section 15.2. Our Data Protection Officer can be contacted at dpo@hzxingyutrade.com. Our EU representative under GDPR Article 27 can be contacted at eu-representative@hzxingyutrade.com. Our UK representative can be contacted at uk-representative@hzxingyutrade.com.
19.2 California (CCPA/CPRA)
California residents have the rights described in Section 15.3. We do not sell or share Personal Data as defined under CCPA/CPRA. California residents may submit requests via privacy@hzxingyutrade.com or our toll-free number.
19.3 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA)
Residents of these US states have rights similar to CCPA/CPRA, including access, correction, deletion, portability, and opt-out of targeted advertising and profiling.
19.4 Nevada (NRS 603A)
Nevada residents may opt out of the sale of their covered information by contacting privacy@hzxingyutrade.com. We do not sell covered information.
19.5 Brazil (LGPD)
Brazilian residents have rights similar to GDPR under the Lei Geral de Proteção de Dados. Our Brazilian representative can be contacted at br-representative@hzxingyutrade.com.
19.6 China (PIPL)
For users in Mainland China, we comply with the Personal Information Protection Law. Sensitive personal information requires separate consent. Cross-border data transfers require security assessment by CAC or use of standard contracts.
19.7 South Korea (PIPA)
Korean users have rights under the Personal Information Protection Act. Cross-border transfers require consent and PIPC approval where applicable.
19.8 Japan (APPI)
Japanese users have rights under the Act on the Protection of Personal Information, including access, correction, and cessation of use.
19.9 India (DPDPA)
For Indian residents, we comply with the Digital Personal Data Protection Act 2023. Consent-based processing; rights to access, correction, erasure, grievance redressal.
19.10 Other Jurisdictions
We extend privacy rights to users in all jurisdictions, applying the highest standard of protection available under the relevant law.
20. Changes to This Policy
We may update this Policy from time to time. When we make changes, we will:
- Update the "Last updated" date at the top of this Policy.
- Notify you via email (for material changes) where you have provided contact details.
- Display a prominent notice on our website and within our Apps.
- For changes that require renewed consent (e.g., new data processing purposes, new Ad Network integrations), we will request your explicit consent before the changes take effect.
Material changes are those that affect your rights, the types of data we collect, how we use it, or with whom we share it. Non-material changes (such as clarifications or organizational updates) will be effective immediately upon posting.
We encourage you to review this Policy periodically to stay informed about how we protect your data.
If you have any questions, concerns, or requests regarding this Policy or our data practices, please contact us:
HZXingyuTrade Privacy Team
Email (General): contact@hzxingyutrade.com
Email (Support): support@hzxingyutrade.com
Address: Sheffield Science Park, United Kingdom
For data subject requests, please email contact@hzxingyutrade.com with the subject line "Privacy Request" and include sufficient information to verify your identity.
Data Protection Officer: dpo@hzxingyutrade.com
EU Representative: eu-representative@hzxingyutrade.com
UK Representative: uk-representative@hzxingyutrade.com
We aim to respond to all privacy requests within 30 days. For complex requests, we may extend the response time by up to 60 days and will notify you of any extension.