Privacy Policy
Contents
- Scope & Controller
- Definitions
- Data We Collect
- Data We Do Not Collect
- Legal Basis for Processing
- How We Use Data
- App Store & Google Play Disclosure
- Advertising, AdMob & Mediation Partners
- Ad Formats: Open-screens, Rewarded, Interstitial, Banner
- Third-Party SDKs & Vendors
- Data Sharing & Sale
- International Transfers
- Retention
- Security
- Your Rights
- Age Restrictions & Children
- Regional Rights (GDPR / CCPA / LGPD / PIPL)
- Cookies & Similar Tech
- Changes to this Policy
- Contact & DPO
This Privacy Policy describes how csshichuang.com ("csshichuang", "we", "our", "us") collects, uses, discloses, and safeguards information when you use our websites, mobile applications, and related services (collectively, the "Services"). It applies to users worldwide, including the European Economic Area, the United Kingdom, the United States, Brazil, Mainland China, Canada, Australia, Singapore, India, Japan, South Korea, the United Arab Emirates, and any other jurisdiction in which we make the Services available.
By installing, accessing, or using the Services, you confirm that you have read and understood this Policy. If you do not agree, please discontinue use and uninstall any of our applications.
Scope & Controller
The data controller for the Services is csshichuang.com, a private R&D studio registered and operating from the Sheffield Digital Campus, Technology Park, Sheffield, United Kingdom. For users in the European Economic Area and the United Kingdom, the controller is also the entity responsible under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR / Data Protection Act 2018.
This Policy covers our corporate website at csshichuang.com and every mobile application published by csshichuang on the Apple App Store and Google Play, including (without limitation): the Multi-track Offline Audio Editor, Ingredient Freshness Tracker, Self-drive Trajectory Logger, Credentials & Expiry Notifier, Personal Goal Decomposer, and Jewellery & Collection Ledger.
Definitions
For the purposes of this Policy:
- Personal Data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on Personal Data (collection, storage, use, disclosure, erasure).
- Sensitive Data means special categories of data under Article 9 GDPR (health, biometric, etc.).
- Service Data means content the user creates inside our apps (audio recordings, fresh-produce entries, route logs, credential entries, goals, collection items).
- Device Data means technical metadata emitted by the operating system, such as OS version and locale.
Data We Collect
We practice data minimisation. The categories of Personal Data we may process, in connection with the Services, are:
| Category | Examples | Where stored |
|---|---|---|
| Account Data (optional, opt-in only) | Display name, email address, profile photo | On-device encrypted vault or our EU-based server |
| Service Data | Audio recordings, fresh-produce entries, route logs, credential entries, goals, collection items | On-device, encrypted at rest (NSFileProtectionComplete / EncryptedSharedPreferences) |
| Device Data | OS version, locale, device model | Anonymous, used only for crash diagnostics when you opt in |
| Purchase Data | Receipt validation tokens, subscription status | Apple / Google servers; we see only anonymised receipts |
| Support Data | Messages and attachments you send us | Encrypted email and our EU-based ticketing system |
| Advertising Data | See the AdMob section below; only present in free-tier builds of selected apps | Handled by our advertising partners under their own policies |
Data We Do Not Collect
We do not, and will not, collect the following categories of data from our users. This list is exhaustive at the time of writing and is part of our public commitment:
- Government identification numbers, social security numbers, or national ID numbers.
- Financial account numbers, credit or debit card numbers, or bank routing information.
- Authentication credentials for any third-party service (we never ask for them).
- Health or medical information, biometric identifiers for identification purposes, or genetic data.
- Precise location data, beyond what is required for the in-app feature (e.g. route logging, which is opt-in and on-device).
- Contacts, photos library, microphone, or camera access, except where the user explicitly grants a single-feature permission.
- Browsing history, advertising IDs (IDFA / GAID), or cross-app tracking signals, in paid versions of the Services.
Legal Basis for Processing
Under GDPR, we rely on the following legal bases:
- Consent (Art. 6(1)(a)) for any optional analytics, advertising, or non-essential cookie in the website or the free-tier apps.
- Contract (Art. 6(1)(b)) to deliver the core features of the Services the user has installed or subscribed to.
- Legal obligation (Art. 6(1)(c)) to comply with applicable law (tax, accounting, anti-fraud, lawful government requests).
- Legitimate interest (Art. 6(1)(f)) only for narrowly defined security and anti-abuse purposes, and only when balanced against your rights and freedoms.
How We Use Data
We use Personal Data only for the following purposes:
- To provide, maintain, and improve the core features of the Services.
- To authenticate the user, where authentication is required (e.g. iCloud or Google sign-in for backup opt-in).
- To process subscriptions, in-app purchases, and refunds.
- To respond to support enquiries, when you contact us.
- To detect, prevent, and address fraud, security incidents, and abuse.
- To comply with legal obligations and to respond to lawful government requests.
- To send service-critical notifications (security alerts, terms changes) - never marketing without consent.
We do not use Personal Data for automated decision-making that produces legal or similarly significant effects, except in narrowly defined anti-fraud contexts where you have a right to human review.
App Store & Google Play Disclosure
Every csshichuang mobile application published on Apple's App Store or Google Play is accompanied by an accurate, complete, and up-to-date privacy declaration. We treat the App Store "App Privacy" nutrition labels and the Google Play "Data safety" form as a binding public commitment, and we review the labels on every release.
Categories of data declared in our labels
- Data Not Collected - the default state of every paid tier of our applications. Where the app is fully paid, no data is collected, no data is used for tracking, and no data is linked to the user's identity.
- Data Not Linked to You - aggregate crash and performance data that cannot reasonably be used to identify the user, used only with explicit opt-in, and stored on-device unless the user chooses to share it.
- Data Linked to You - only ever the categories required to fulfil a feature the user has explicitly requested (e.g. an iCloud backup that the user has enabled).
Tracking
We do not participate in the App Tracking Transparency ("ATT") framework for cross-app tracking, and we do not fingerprint devices. In free-tier builds of selected apps that include advertising, we request ATT permission before showing any personalised advertising, and we honour the user's choice immediately. If the user declines, only non-personalised contextual advertising is served.
Advertising, AdMob & Mediation Partners
Selected free-tier builds of our applications are monetised through advertising. The advertising layer is always opt-in, always disclosed in the in-app first-run flow, and always separable from the core features of the application. Users on paid tiers never see advertising of any kind.
Our primary advertising platform is Google AdMob, with the following mediation partners and demand sources integrated through Google AdMob Mediation:
| Partner | Role | SDK privacy policy |
|---|---|---|
| Google AdMob (Google LLC) | Primary ad platform, mediation host | https://policies.google.com/privacy |
| Google Ad Manager (Google LLC) | Backfill demand for AdMob | https://policies.google.com/privacy |
| Meta Audience Network (Meta Platforms Ireland Ltd) | Mediated demand source | https://www.facebook.com/policy.php |
| Unity Ads (Unity Technologies) | Mediated demand source | https://unity.com/legal/privacy-policy |
| AppLovin MAX (AppLovin Corporation) | Mediated demand source | https://www.applovin.com/privacy/ |
| Pangle / ByteDance (Pangle) | Mediated demand source (APAC) | https://www.pangleglobal.com/privacy |
| ironSource (ironSource Ltd) | Mediated demand source | https://www.is.com/ironSource/privacy-policy/ |
| Vungle (Liftoff Mobile) | Mediated demand source | https://vungle.com/privacy/ |
| Chartboost (Chartboost Inc.) | Mediated demand source | https://www.chartboost.com/legal/privacy-policy/ |
| Tapjoy (Tapjoy Inc.) | Mediated demand source | https://www.tapjoy.com/legal/privacy-policy/ |
| InMobi (InMobi Technology Services) | Mediated demand source | https://www.inmobi.com/privacy-policy |
| Mintegral (Mobvista) | Mediated demand source | https://www.mintegral.com/en/privacy |
| Digital Turbine (Digital Turbine Inc.) | Mediated demand source | https://www.digitalturbine.com/privacy-policy/ |
| AdColony (Digital Turbine) | Mediated demand source | https://www.adcolony.com/privacy-policy/ |
| Liftoff (Liftoff Mobile) | Mediated demand source | https://liftoff.io/privacy-policy/ |
Each partner processes the data described in its own privacy policy. We have configured every mediated SDK to disable personalised advertising by default, to suppress the device-wide advertising identifier (IDFA / GAID) from being passed unless the user has explicitly granted ATT / ad-tracking consent, and to honour the Global Privacy Platform (GPP) and the IAB Europe Transparency & Consent Framework (TCF v2.2) where applicable.
For users in the European Economic Area, the United Kingdom, and Switzerland, we surface a consent management platform (CMP) certified against the TCF v2.2 before any advertising request is made. No personalisation or measurement cookies are set without prior, granular, freely-given consent.
Ad Formats: Open-screens, Rewarded, Interstitial, Banner
Our free-tier applications use the following ad formats, each configured to comply with the App Store Guidelines (in particular, 5.1.1(iv) and the Human Interface Guidelines on advertising), Google Play's Ad policy, and the user's consent state:
Splash / open-screen ads (App Open)
App open ads are shown at the natural cold-start of the application, after the user has completed the first-run consent flow. We display a clear "Ad" label as required by App Store Guideline 5.1.1(iv). The user can dismiss the ad after five seconds, in line with current guidance. We do not show a splash ad to a user who has purchased the paid tier, removed ads via the in-app purchase, or otherwise opted out of personalised advertising.
Rewarded video ads
Rewarded video ads are offered to the user in exchange for an in-app benefit (extra lives, premium features for a session, etc.). The reward is only granted after the user has watched the ad in full or to a clearly marked skip point. We never auto-play rewarded ads. We never grant the reward unless the SDK reports a verified reward event.
Interstitial ads
Interstitial ads are shown at natural transition points in the application flow (between levels, after a save action, after a completed recording). We enforce a minimum interval between interstitial impressions and never show an interstitial immediately after the user closes another interstitial. The user can dismiss the ad at any time via the close button. We never show an interstitial on first-launch, during a paid action, or in a context that would surprise the user.
Banner ads
Banner ads are placed in non-intrusive, clearly marked locations at the bottom or top of the screen. We do not place banner ads adjacent to navigation controls, primary action buttons, or scrolling content. The user can dismiss a banner via the in-app "Remove ads" purchase, which removes all ad formats in a single transaction.
Frequency caps and user controls
We enforce a maximum impression frequency per user per day, configurable per app. The user can at any time revoke advertising consent from the in-app privacy settings, which immediately stops all personalised advertising and falls back to contextual advertising only. Users in the EU/UK can also object to legitimate-interest-based processing at any time, with effect from the next session.
Third-Party SDKs & Vendors
In addition to the advertising partners listed above, we use the following categories of vendor. Each has been selected for its data-handling standards, its GDPR / UK-GDPR compliance posture, and its geographic footprint.
| Category | Vendor(s) | Data shared | Region |
|---|---|---|---|
| Cloud hosting & data residency | OVHcloud, Hetzner, AWS (eu-central-1) | Server logs, encrypted backups (opt-in) | EU |
| Email & ticketing | Fastmail, Help Scout | Support messages | EU / US (SCCs) |
| Crash & performance (opt-in only) | Self-hosted Sentry, Telemetry Deck | Stack traces, anonymised device metadata | EU |
| Receipt & subscription validation | Apple App Store, Google Play | Anonymised receipt tokens | US (SCCs) |
| Payments (web commissions only) | Stripe Payments Europe Ltd. | Payment metadata, billing address | EU / US (SCCs) |
| Analytics (website, opt-in) | Plausio / Plausible (self-hosted) | Cookieless page views, country level | EU |
| Transactional email | Postmark (ActiveCampaign) | Email address, name | US (SCCs) |
All vendors are bound by a Data Processing Agreement ("DPA") consistent with Article 28 GDPR, and transfers to vendors outside the EEA / UK are governed by the European Commission's 2021 Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework where the recipient is certified.
Data Sharing & Sale
We do not sell Personal Data. We do not share Personal Data with third parties for cross-context behavioural advertising. The only categories of data we share with third parties are:
- Anonymised, aggregated crash and performance data, only with your opt-in.
- Anonymised receipt tokens with Apple and Google for the purpose of subscription validation.
- Advertising requests (without device-identifying information, by default) with the partners listed above.
- Data with vendors, only as required to deliver the Services and bound by a DPA.
- Data with law enforcement, only in response to a valid legal process reviewed by counsel.
International Transfers
Our primary data infrastructure is hosted in the European Union. Where Personal Data is transferred outside the EEA, the UK, or an adequacy-decision country, we rely on one of the following safeguards:
- The European Commission's 2021 Standard Contractual Clauses (Module 1, 2, or 3 as appropriate).
- The UK International Data Transfer Addendum (where the transfer is from the UK).
- The EU-US Data Privacy Framework, the UK Extension thereto, or the Swiss-US Data Privacy Framework, where the recipient is certified.
- Derogations under Article 49 GDPR (e.g. explicit consent, contract performance) for narrow, documented cases.
You can request a copy of the transfer safeguards that apply to your data by emailing contact@csshichuang.com.
Retention
We retain Personal Data only for as long as necessary for the purposes for which it was collected, and thereafter delete or irreversibly anonymise it. The specific retention windows are:
| Category | Retention | Basis |
|---|---|---|
| Service Data (user content) | Until the user deletes it, or 24 months of inactivity | Contract, user control |
| Account Data | Until account deletion + 30 days | Contract |
| Support messages | 36 months from last contact | Legitimate interest |
| Server logs | 30 days | Legitimate interest, security |
| Invoices (commission work) | 7 years (UK / EU statutory) | Legal obligation |
| Advertising data (mediation) | As defined by partner policy; we set shortest reasonable | Consent |
Security
We employ administrative, technical, and physical safeguards designed to protect Personal Data, including: encryption in transit (TLS 1.3) and at rest (AES-256), per-row key management via the iOS Secure Enclave / Android Keystore, hardware-bound biometric gating, two-factor authentication on every staff account, least-privilege access policies, and an annual third-party security review. In the event of a personal data breach, we will notify affected users and the competent supervisory authority within the timeframes required by GDPR (72 hours) and other applicable law.
Your Rights
Depending on where you live, you have some or all of the following rights with respect to your Personal Data. We will respond to a verified request within 30 days (or sooner where required by local law, e.g. 45 days under CCPA):
- Access - to obtain a copy of the Personal Data we hold about you.
- Rectification - to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") - to delete your data, subject to legal exceptions.
- Restriction - to limit how we process your data while a complaint is investigated.
- Portability - to receive your data in a structured, machine-readable format.
- Objection - to object to processing based on legitimate interest or for direct marketing.
- Withdraw consent - at any time, with effect for future processing.
- Opt-out of sale or sharing - though we do not sell or share, you can confirm this at any time.
- Non-discrimination - we will not penalise you for exercising a right.
- Lodge a complaint - with your local data protection authority.
To exercise any right, email contact@csshichuang.com. We will need to verify your identity before acting on the request, and we will explain any delay if the request is complex.
Age Restrictions & Children
Our Services are not directed at children under the age of 13, and we do not knowingly collect Personal Data from children under 13. We do not direct advertising to children, and we configure our mediation partners to suppress personalised advertising for users we have reason to believe are under 18.
Specific age thresholds we observe:
- COPPA (United States, children under 13): we do not knowingly collect or process Personal Data from children under 13. Our applications are not listed in the Apple "Kids" category and we do not enable the Designed for Families track on Google Play.
- GDPR (EEA & UK, children under 16, or under 13 in some member states): where consent is the legal basis (e.g. for advertising or non-essential cookies), we obtain verifiable parental consent for users below the relevant age threshold.
- CCPA / CPRA (California): we do not sell or share the Personal Data of consumers under 16 without affirmative opt-in.
- India DPDP Act (children under 18): verifiable parental consent is required before processing, which is technically enforced in the first-run consent flow.
- China PIPL (minors): we obtain verifiable parental consent for minors and apply heightened safeguards to their data.
- Australia / Singapore / South Korea / Japan / UAE / Brazil: we observe the highest applicable age threshold (18, or as otherwise defined by the local regulator for consent purposes).
If you believe we have inadvertently collected Personal Data from a child below the applicable age threshold, please email contact@csshichuang.com and we will delete the data within 7 days.
Regional Rights (GDPR / CCPA / LGPD / PIPL)
European Economic Area, United Kingdom, Switzerland (GDPR & UK GDPR)
The supervisory authority for the United Kingdom is the Information Commissioner's Office (ICO), Wilmslow, Cheshire. For users in the EEA, the lead supervisory authority is the data protection authority of the user's habitual residence. You can find your national authority at edpb.europa.eu.
California, United States (CCPA / CPRA)
Under the California Consumer Privacy Act (as amended by the California Privacy Rights Act), California residents have the right to know, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to non-discrimination. We do not sell or share Personal Data. You can exercise these rights by emailing contact@csshichuang.com or by using the in-app privacy controls.
Other US states
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other US states with comprehensive privacy laws have analogous rights. We extend the rights described in this Policy to all US residents regardless of state of residence.
Brazil (LGPD - Lei Geral de Protecao de Dados)
Brazilian users have the rights of confirmation, access, correction, anonymisation, portability, deletion, and information about sharing, as set out in the LGPD. The Brazilian National Data Protection Authority (ANPD) oversees enforcement.
Mainland China (PIPL - Personal Information Protection Law)
For users in Mainland China, we act as a personal information processor, observe the consent, notification, and minimum-necessary principles, and provide a separate method for the exercise of PIPL rights via contact@csshichuang.com. Where required, we engage a local representative; details on request.
Other regions
Canada (PIPEDA, Quebec Law 25), Australia (Privacy Act 1988), Singapore (PDPA), South Korea (PIPA), Japan (APPI), India (DPDP Act 2023), and any other region with applicable law - we extend equivalent rights to all users worldwide and respond to verifiable requests within the timeframes required by local law.
Cookies & Similar Technologies
The csshichuang.com website uses a strictly minimum set of cookies and only the categories strictly necessary for the site to function. We do not use third-party analytics cookies, third-party advertising cookies, or social media pixels. The cookies and similar technologies we use are:
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
| css_theme | Stores the user's dark/light theme preference | 12 months | First-party, functional, no consent required |
| (none) | We do not use analytics cookies | n/a | n/a |
| (none) | We do not use advertising cookies on the website | n/a | n/a |
For users in the EEA / UK, we do not deploy a cookie consent banner because the only cookies set are strictly necessary for the operation of the site. If we introduce optional cookies in the future, we will deploy a certified CMP and obtain granular consent before any non-essential cookie is set.
Changes to this Policy
We may update this Policy from time to time. The "Effective" date at the top of this page reflects the current version. For material changes, we will notify users in-app and, where required by law, request renewed consent. The previous versions of this Policy are archived and available on request.
Contact & Data Protection Officer
For any question, complaint, or right-exercise request, please contact us at:
csshichuang.com
Sheffield Digital Campus, Technology Park
Sheffield, United Kingdom
Email: contact@csshichuang.com
We aim to acknowledge every enquiry within 2 working days and to resolve every request within 30 days (sooner where required by law). If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.