Privacy Agreement
Effective Date: 2026-05-14
This Privacy Agreement applies to all websites, mobile applications, software modules, APIs, digital services, and related online experiences provided by Xihua County Pillar Network Technology Co., Ltd ("XHZHUZI", "we", "us", or "our"). This agreement covers both direct products and solutions operated for clients where we act as a controller, processor, or service provider under applicable laws.
1. Controller and Contact Details
Company Name: Xihua County Pillar Network Technology Co., Ltd
Office Address: No. 132, North Section of Education Avenue West, Xihua County, Henan, 466600, China
Website: xhzhuzi.com
Business Support: support@xhzhuzi.com
Key Accounts: zhangjinzhu@xhzhuzi.com
2. Scope of Data Processing
We process personal data in connection with:
- Network technology services, technology development, consulting, exchange, transfer, and promotion.
- Software development and information technology consulting services.
- Information system integration services.
- Graphic design, image and text production, advertising design, and advertising agency operations.
- Marketing strategy, corporate identity planning, ecommerce consulting, and internet sales support.
- Sales operations related to daily goods, home products, apparel, footwear, office supplies, and electronics support systems.
- Mobile management applications published on Google Play, Apple App Store, and similar distribution channels.
3. Categories of Personal Data
- Identity data: name, username, organization name, role, and account identifiers.
- Contact data: email address, support request details, communication preferences.
- Device and technical data: IP address, device identifiers, operating system, app version, browser metadata, crash logs, performance diagnostics.
- Usage data: page views, event logs, feature interactions, session duration, conversion actions, campaign attribution signals.
- Commerce and transaction data: order records, fulfillment metadata, and invoice references where applicable.
- Support and ticketing data: issue descriptions, attachments, and communication history.
- Advertising and consent data: ad request metadata, consent status, opt-in and opt-out signals, and ad-frequency controls.
4. Sources of Data
- Directly from users, enterprise clients, and authorized representatives.
- Automatically from websites, SDKs, applications, and telemetry services.
- From app stores, analytics providers, advertising platforms, and integration partners.
- From public and legally available business records when relevant to service delivery.
5. Purpose and Legal Basis
We process personal data for contractual, legitimate, legal, and consent-based purposes, including:
- Delivering, maintaining, securing, and improving products and services.
- Managing app publishing, updates, and compliance submissions to app stores.
- Providing customer support, incident handling, and fraud prevention.
- Conducting analytics, service quality optimization, and product planning.
- Operating advertising monetization while respecting consent and age restrictions.
- Complying with legal, regulatory, tax, and law-enforcement obligations.
6. App Store and Distribution Platform Compliance
For applications distributed through app stores and similar channels, we align processing and disclosures with platform requirements, including:
- Google Play Developer Program Policies and Data Safety requirements.
- Apple App Store Review Guidelines and Apple privacy nutrition label disclosures.
- Requirements for accurate age ratings, content disclosures, and permission transparency.
- Clear presentation of data collection categories, data sharing, and data usage purposes.
- Submission updates when SDK behavior, permissions, or privacy practices materially change.
7. Advertising, Ad Monetization, and SDK Compliance
Our mobile applications and client-operated applications may include advertising and monetization integrations. Common ad formats include splash ads, rewarded video ads, interstitial ads, and banner ads. Optional formats may include native ads, app-open ads, and playable ads.
Ad platforms and monetization services may include, subject to product requirements and regional legality:
- Google AdMob and Google Ad Manager
- AppLovin MAX and AppLovin Exchange
- Meta Audience Network
- Unity Ads
- ironSource
- Liftoff Monetize (Vungle)
- Chartboost
- InMobi
- Pangle
- Mintegral
- Smaato
- Start.io
- Yandex Ads, Moloco, and additional approved demand partners where lawful
For ad-related processing we apply the following controls:
- Consent collection and signaling (for example, IAB TCF where applicable, Google UMP or equivalent compliant flows).
- Region-aware ad request behavior, including non-personalized ads where consent is not granted.
- Age screening and child-directed treatment controls where required.
- Data minimization, SDK governance, and regular partner compliance review.
- User-facing controls for ad personalization where required by law.
8. Age Policy and Child Protection
Our services are generally intended for business and general audience users unless explicitly designated otherwise. We do not knowingly collect personal data from children in violation of applicable law. Where age-restricted processing applies, we implement age gates, child-directed handling flags, consent requirements, and restricted data processing modes.
- United States: COPPA compliance for child-directed contexts.
- European Economic Area and United Kingdom: child consent and parental authorization standards under GDPR and UK GDPR.
- App store age rating obligations and sensitive category restrictions.
9. International and National Policy Adaptation
We design privacy operations to support major country and regional legal frameworks, including but not limited to:
- European Union and EEA: GDPR and ePrivacy requirements.
- United Kingdom: UK GDPR and Data Protection Act 2018.
- Switzerland: revised FADP.
- United States federal and state regimes: FTC Act principles; California CCPA and CPRA; Virginia VCDPA; Colorado CPA; Connecticut CTDPA; Utah UCPA and other enacted state privacy laws where applicable.
- Canada: PIPEDA and provincial private-sector privacy obligations where relevant.
- Brazil: LGPD where services or users fall within legal scope.
- Australia and New Zealand privacy frameworks where market operations require.
When local law grants stronger rights than this agreement, we apply the higher standard where legally required.
10. Cookies, SDKs, and Tracking Technologies
We use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, analytics, performance, attribution, and advertising. Depending on jurisdiction, we provide consent banners, granular choices, and withdrawal options.
11. Data Sharing and Disclosure
We may share personal data only where lawful and necessary with:
- Hosting, cloud, analytics, communications, and security vendors acting under contract.
- Advertising and mediation partners for monetization and campaign delivery.
- Payment, commerce, and fulfillment service providers where relevant.
- Professional advisors, auditors, and legal counsel under confidentiality obligations.
- Authorities and regulators when required by legal process.
We do not sell personal data in ways prohibited by law and provide rights mechanisms where sale or sharing definitions apply under local law.
12. International Data Transfers
When cross-border transfers occur, we apply recognized safeguards such as standard contractual clauses, transfer impact assessments, supplementary technical controls, and contractual data protection obligations.
13. Data Security
We maintain administrative, technical, and physical safeguards, including:
- Access control and least-privilege models.
- Encryption in transit and protective controls at rest where feasible.
- Secure development lifecycle, vulnerability management, and patch processes.
- Monitoring, incident response procedures, and periodic security reviews.
14. Retention
Personal data is retained only as long as required for service delivery, legal obligations, dispute resolution, and legitimate business records. Retention periods vary by data type, region, and legal requirements.
15. User Privacy Rights
Depending on jurisdiction, users may have rights to access, correction, deletion, portability, restriction, objection, and consent withdrawal.
United States users may also have rights related to targeted advertising and profiling under applicable state law.
Users can submit requests through support@xhzhuzi.com. We may verify identity before fulfilling requests.
16. Do Not Track and Global Privacy Signals
We evaluate browser-level and platform-level preference signals where required by law and support recognized opt-out mechanisms for relevant jurisdictions.
17. Third-Party Links and Services
Our services may link to third-party websites, stores, and services. Their privacy practices are governed by their own notices and agreements.
18. Breach Notification
In the event of a personal data breach, we follow applicable notification obligations, including timing and content requirements defined by relevant laws and regulations.
19. Changes to This Agreement
We may update this Privacy Agreement to reflect legal, operational, or technical changes. Material updates will be posted with a revised effective date and, where required, additional notice or consent collection.
20. Contact and Supervisory Rights
Questions and requests: support@xhzhuzi.com. Users in applicable regions may also lodge complaints with competent supervisory authorities.
21. Interpretation and Language
This English version is the governing publication for this website. Supplemental translations, if provided, are for convenience only unless local law requires otherwise.
22. Data Subject Request Procedure
To exercise rights, users may submit requests to support@xhzhuzi.com with sufficient details for identity and request verification.
- Request categories include access, correction, deletion, portability, restriction, objection, and withdrawal of consent.
- Where legally required, we respond within jurisdiction-specific timelines and may extend with lawful notice for complex requests.
- Authorized agents may submit requests where local law permits and proper authorization is provided.
23. Sensitive Data and Restricted Processing
We avoid processing sensitive personal data unless strictly necessary and legally justified. Where sensitive processing is required, we apply enhanced safeguards, role-based access controls, minimization procedures, and legal basis validation.
24. Automated Decision-Making and Profiling
We may use automated systems for analytics, fraud screening, ad relevance controls, and service optimization. Where law provides rights related to automated decisions, users can request review through support@xhzhuzi.com.
25. Policy Appendix: Region-Specific Notice Summary
- EEA and UK: legal basis transparency, transfer safeguards, data subject rights, and supervisory authority complaint pathways.
- United States: notice at collection, opt-out rights where applicable, and non-discrimination protections under relevant state laws.
- Canada: accountability, purpose limitation, and access/correction rights under applicable federal and provincial frameworks.
- Brazil and other applicable jurisdictions: lawful basis, rights management, and controller accountability standards.
26. Advertising Compliance Appendix
For ad-enabled applications, we maintain partner due diligence, SDK inventory records, consent-logic review, child-directed flags, and periodic policy checks for ad monetization components including splash, rewarded video, interstitial, and banner units.