运营主体:【四川省荥小省互联网科技有限责任公司】
住所地:【四川省雅安市荥经县严道街道若水东二路5号】
欢迎您使用塔塔屋应用(以下简称“本应用”或“我们”)。我们深知个人信息对您的重要性,并始终致力于本着“最小必要、安全可控”的原则保护您的个人隐私。本《隐私政策》(以下简称“本政策”)旨在向您透明地说明我们在您使用塔塔屋应用时,如何收集、使用、存储、共享及保护您的个人信息,以及您管理自身个人信息的方式。
【特别提示】请您在首次启动本应用时仔细阅读本政策。本应用会在首次启动时通过醒目的弹窗形式展示本政策,您点击同意并勾选条款,即视作认可并接受本政策的全部条款;若您点击拒绝,您将无法进入并使用本应用的全部服务。
我们仅会出于本政策所述的业务功能和卡牌工具服务,依法收集您的个人信息。我们承诺绝不利用收集的信息发送任何商业广告、营销短信或进行营销骚扰。
1. 基础登录与身份验证功能
验证码登录:当您使用手机号验证码登录时,我们会收集您的手机号码。该手机号码仅用于账号安全核验、身份验证及找回账号,我们承诺绝不外泄,亦绝不用于任何商业营销推送。
第三方快捷登录:当您使用 Apple ID 或微信快捷登录时,我们会收集第三方平台向我们提供的您的唯一标识符(OpenID/UID)、微信昵称、微信头像。收集这些信息是为了将第三方账号与您的塔塔屋账号进行绑定,以便您实现跨设备快捷登录。
2. 核心业务与内购记录功能
卡牌矩阵创建(UGC)与权责:当您自由创建自定义卡牌矩阵时,我们会收集并存储您输入的矩阵简介文本、矩阵名称及描述。用户知悉并同意,您自主创建的卡牌矩阵图文内容,其著作权归您(发布者)个人所有;您严禁发布任何违反法律法规、低俗、侵害他人知识产权或违背社会主义核心价值观的内容。平台设有内容审查机制,有权对涉及违规的内容直接进行下架、删除等处置。因您发布违规内容引发的所有法律纠纷、侵权索赔,全部法律责任由发布用户自行承担。本应用不提供任何形式的预测或结论性解读,上述文本仅作为工具内的用户自主备注与展示。
消费与内购记录:当您花费对应资金购买单次创建卡牌矩阵功能服务时,我们会记录您的订单生成时间、交易金额、交易状态及购买的工具功能标识。用户知悉并同意,该功能服务属于虚拟数字商品,除适用法律另有强制性规定(如消费者保护相关法律要求)或产品本身存在技术故障外,虚拟功能服务售出后不支持无理由退款。在账号注销或度过恢复期后,相关虚拟权益同步失效,不支持任何形式的退费或折现。
3. 技术维护与运行优化功能
网络状态检查:本应用集成了网络检测功能,会读取您的网络连接类型(如 Wi-Fi、蜂窝网络状态、是否断网)。该功能仅用于获取联网状态以优化沙盒内卡牌图片资产、音乐文件的加载体验,或在断网时向您展示友好的错误提示,我们绝不抓取您的网页浏览记录,亦不会私自获取 IP 以外的网络路由、局域网设备信息。
为了实现特定的卡牌工具互动功能,本应用会在必要时向手机系统申请调取以下底层权限:
1. 摄像头(Camera)权限:当您扫描二维码与实体卡牌产生数字联动时调用。该权限仅在您主动扫码的场景下临时调用,我们绝不进行后台常驻调取,亦不截取、不存储、不上传您的任何镜头画面或影像素材,同时我们绝不索取您的系统相册访问权限。
2. 网络权限(Internet):用于基础的登录校验、数据同步、核心资源(如卡牌图文、音频)的在线加载,除此之外无任何额外的数据采集行为。
3. 设备传感器与反馈权限:在您进行卡牌置换、查看卡牌细节、摇晃触发互动或体验特定物理动效时,调用手机的加速度传感器(用于检测设备运动姿态)及系统振动反馈。上述传感器原始数据仅在设备本地用于实时计算界面动效与触觉反馈,应用不会对此类传感器数据进行任何信息上报、统计、持久化存储或采集。
【权限撤回说明】您知悉并同意,您可随时在手机系统设置(权限管理)中,手动自主关闭摄像头、网络、震动等系统权限的授权。一旦您关闭对应权限,本应用将不会再调取相关能力与数据,但对应的特定业务功能也将无法继续使用。
本应用不使用网页 Cookie:本应用作为移动端原生应用程序,不调取、不使用任何针对网页的 Cookie 技术,无任何跨设备追踪行为。
同类本地存储技术与清理权限:为了保证应用的正常运行、避免您重复登录,我们会利用系统本地存储技术(包括 Shared Preferences、Flutter Secure Storage 等),在您的设备本地隔离存储您的登录 Token(安全令牌)、卡牌图片缓存、以及内置背景音乐(MP3)。用户知悉并同意,您可以在手机系统的应用设置内随时手动清除本应用的缓存数据。清除缓存后,仅本地图片、音频等临时缓存文件会被彻底删除销毁,您的账号核心数据(如内购资产、已创建的矩阵)仍安全保存在服务器中。
1. 除本政策已明确披露的第三方 SDK(如微信、Apple)以及法律法规另有规定的情形外,我们不会向任何第三方共享、转让您的个人信息。
2. 第三方 SDK 集成明示与免责边界:为了实现快捷登录与内购支付,本应用集成了必要的第三方 SDK。这些第三方 SDK 仅服务于其对应的特定业务,不会跨业务混用或跨业务采集数据。我方服务器既不读取、亦不留存、不备份第三方返回的任何设备唯一标识数据:
所有第三方 SDK 的数据收集行为均受其自身隐私政策约束。
【 SDK 名称 】 微信 Open SDK
【 提供方 】 深圳市腾讯计算机系统有限公司
【 业务场景 】 实现微信快捷登录、微信支付、分享,及处理从微信跳回本应用时的跨应用跳转参数恢复与安全校验
【 收集信息 】
1. 剪切板信息(仅用于读取微信分享口令,以及作为跨应用跳转通信失败时的安全校验与口令中转机制);
2. 软件安装列表 / 应用安装状态(仅用于校验当前设备是否安装微信客户端,以保障相关功能正常唤起);
3. 设备标识符(包含设备MAC地址、Android ID、OAID、设备序列号/Serial;iOS:IDFV,用于风控、防作弊校验);
4. 设备硬件信息(设备型号、操作系统版本,用于环境校验);
5. 网络基础信息(IP地址、WLAN接入点、Wi-Fi状态,用于保障通信安全);
6. 支付相关信息(如订单金额、支付状态、交易单号等,用于完成交易与结果校验);
【 数据共享与传输 】 上述信息将传输至微信服务器进行处理;数据处理行为受《微信隐私保护指引》约束;除实现本政策所述功能外,不会将您的数据用于其他目的。
【 数据存储期限 】 所涉及的个人信息存储期限不超过实现相关业务功能所必需的时间;法律法规另有规定的,从其规定;支付相关数据将按国家金融与税务法规要求留存。
【 隐私政策 】 点击查看《微信隐私保护指引》
【 SDK 名称 】 Sign in with Apple 及 Apple 应用内购买 SDK
【 提供方 】 Apple Inc. (苹果公司)
【 业务场景 】 iOS端安全授权登录、提供 App Store 应用内购买(内购支付)及订单凭证校验服务
【 收集信息 】
1. 苹果用户唯一标识符(Apple ID 关联的匿名用户标识)、设备风控参数;
2. 交易流水分单信息(当您发起 iOS 内购时,收集并向服务器传输【App Store 交易标识符/Transaction ID、购买商品 ID、支付凭证/Receipt Data】以验证并下发虚拟权益)。
【 数据共享与传输 】 上述信息将传输至 Apple 服务器进行处理;数据处理行为受《Apple隐私政策》约束;除实现本政策所述功能外,不会将您的数据用于其他目的。
【 数据存储期限 】 所涉及的个人信息存储期限不超过实现相关业务功能所必需的时间;法律法规另有规定的,从其规定;内购凭证数据将按苹果官方开发者权责及相关法规要求持续留存,以便您随时恢复购买权益。
【 隐私政策 】 点击查看《Apple隐私政策》
【免责边界声明】上述第三方 SDK 收集的数据完全由其技术初始化触发,用于其自身风控与支付安全。因第三方 SDK 自身漏洞、违规收集或其独立处理行为引发的任何个人信息泄露与纠纷,将由该第三方提供方在其责任范围内依法承担相应的法律责任。我方将积极协助您向第三方维护合法权益,并严格依据国家法律法规的规定,在各自法律责任范围内承担相应的损害赔偿或法律责任。
数据留存时长界定:我们仅在为实现本政策所述目的所必需的最短时限内保留您的个人信息:
- 账号基础数据(手机号、第三方唯一标识等):在您的账号存续期间持续留存,一旦账号彻底注销,该数据将被立刻彻底删除销毁。
- 订单交易数据(内购记录、流水编号):为了符合《电子商务法》的要求,该数据将依法强制留存 3 年以备国家相关部门核查,留存期间不对外进行任何商业化利用。
- 本地缓存数据:由用户在手机设置中自行清理,或在满足系统过期机制后自动清理。
异常账号数据处置规则:若您的账号因严重违反用户协议或法律法规被平台强制永久封禁,平台可依规留存该账号的必要操作记录与违规证据用于司法核查;在账号封禁期间,该账号暂不支持行使信息导出等个人权利操作。
本应用收集的个人信息主要存储于中华人民共和国境内的服务器。为实现微信快捷登录、Apple 登录及内购支付等功能,部分必要信息(如 OpenID、交易凭证、设备风控参数等)将依照第三方 SDK 提供方的隐私政策,传输至微信(腾讯)及 Apple Inc. 的服务器进行处理,具体请参见本政策第四节第三方 SDK 说明。除上述情形外,我们不会擅自将您的个人信息传输至境外。
按照中国相关法律法规,我们保障您对自己的个人信息行使以下主体权利:
查询、访问与个人信息复制导出权:
您有权查看应用内您的账号绑定状态及历史内购记录。您可以通过本政策公布的官方邮箱与我们联系,申请导出您自身账号名下的基础个人信息及创作矩阵数据,我们在收到申请并核验您身份无误后的 7 个工作日内,为您推送导出的结构化数据。
更正、修改与自主删除权:
当您需要变更个人绑定信息,或需要删除您个人发布的卡牌矩阵内容时,您可以通过本政策公布的官方邮箱(228273847@qq.com)联系我们进行后台人工处理。同时,您可以通过系统功能自主退出或移除您所加入的他人的卡牌矩阵,一旦您在客户端选择退出或移除,客户端界面将不再展示该矩阵,服务器将同步解除您的账号与该矩阵的关联绑定关系。
账号注销与约束规则:
您可以随时申请注销您的账户。为了向您提供便捷的自助注销渠道,我们已在应用程序内内置了线上注销功能。具体的注销路径指引如下:您可以通过进入本应用后,点击我的页面右上角的【齿轮/设置】图标按钮进入【设置】界面,随后在列表中点击【注销账号】选项,即可提交账户自助注销申请。
【注销处理与恢复期】我们将在收到您的申请后立即响应并处理您的注销请求。为了防止用户误操作导致资产丢失,本应用为您提供 15 天的账号恢复期。在提交注销申请后的 15 天内,若您重新登录该账号,即可随时撤销注销流程并重新激活账户。
一旦度过 15 天恢复期,您的账号注销将最终生效。所有的第三方及手机号绑定关系将自动解除,您的个人信息及账号数据将被彻底删除或不可逆匿名化处理(但依据相关法律法规要求必须留存的交易流水等合规记录除外),您将无法再次恢复该账号内的任何内购资产。
禁止注册年龄线:本应用作为卡牌创意交互工具,本应用主要面向年满 16 周岁的用户提供完整服务。如发现 16 周岁以下儿童未经监护人同意注册使用,平台将采取限制功能或封禁账号等措施。
监护人申诉核验:若 16 周岁以上、未满 18 周岁的限制民事行为能力人在法定监护人未同意的情况下进行了内购消费,监护人申请退费申诉时,必须向我们的联系邮箱提供监护人有效身份证明、未成年人身份证明、账户所属权凭证及消费流水记录。经平台核验材料真实合规、且符合法定退款条件的,我们将依法处理。
隐私保护兜底安全技术:我们采取了符合业界标准的安全防护措施保护您的个人信息。并且使用加密存储技术(HTTPS传输加密、安全哈希算法Token存储)、严格的访问权限管控机制,将敏感个人信息隔离在受保护的服务器环境中,最大程度降低数据被泄露、毁损、篡改或违规授予的风险。
政策的更新与微小修订提示:如果本政策发生关乎收集目的、类型改变等重大变更,我们会在您打开应用时通过重新触发弹窗的形式再次展示,您需要重新勾选同意方能继续使用全部服务。对于字词修正、排版优化等不实质性削弱您权利的非重大条款微调,我们将通过应用内公告、系统通知进行公示,不再触发二次弹窗同意,请您注意定期查阅应用内公告。
法律适用与管辖:本隐私政策的订立、效力、解释、履行及争议解决,首先适用中华人民共和国大陆地区法律。对于中华人民共和国香港特别行政区、澳门特别行政区、台湾地区,以及新加坡、马来西亚等其他司法管辖区的用户,本政策同时遵循该地区适用的个人资料隐私相关法规(包括但不限于香港《个人资料(隐私)条例》、新加坡《个人数据保护法案》PDPA 等)中关于个人信息保护之强制性规定。如因本政策产生任何争议,双方应友好协商解决;协商不成的,任何一方可向本公司住所地有管辖权的人民法院提起诉讼。
如果您对本政策有任何疑问、投诉、举报,或需要行使您的信息导出、删除、未成年人退款申诉等权利,请通过以下专属官方渠道与我们取得联系:
官方电子邮箱:228273847@qq.com
为了保障您的合法权益,我们在收到您的来信、并核全相关证明材料后的 15 个工作日内 完成核验、处理并向您反馈结果。若因案情复杂逾期未收到回复的,您可以再次发送邮件问询。
四川省荥小省互联网科技有限责任公司
營運主體:【四川省滎小省互聯網科技有限責任公司】
註冊地址:【四川省雅安市滎經縣嚴道街道若水東二路5號】
歡迎您使用塔塔屋應用程式(以下簡稱「本應用」或「我們」)。我們深知個人資料對您的重要性,並始終致力於本著「最小必要、安全可控」的原則保護您的個人隱私。本《隱私權政策》(以下簡稱「本政策」)旨在向您透明地說明我們在您使用塔塔屋應用程式時,如何蒐集、使用、儲存、分享及保護您的個人資料,以及您管理自身個人資料的方式。
【特別提示】請您在首次啟動本應用時仔細閱讀本政策。本應用會在首次啟動時透過醒目的彈跳視窗形式展示本政策,您點擊同意並勾選條款,即視作認可並接受本政策的全部條款;若您點擊拒絕,您將無法進入並使用本應用的全部服務。
我們僅會出於本政策所述的業務功能和卡牌工具服務,依法蒐集您的個人資料。我們承諾絕不利用蒐集的資訊發送任何商業廣告、行銷簡訊或進行行銷騷擾。
1. 基礎登入與身份驗證功能
驗證碼登入:當您使用手機號碼驗證碼登入時,我們會蒐集您的手機號碼。該手機號碼僅用於帳號安全核驗、身份驗證及找回帳號,我們承諾絕不外洩,亦絕不用於任何商業行銷推播。
第三方快捷登入:當您使用 Apple ID 或微信快捷登入時,我們會蒐集第三方平台向我們提供的您的唯一識別碼(OpenID/UID)、微信暱稱、微信頭像。蒐集這些資訊是為了將第三方帳號與您的塔塔屋帳號進行綁定,以便您實現跨設備快捷登入。
2. 核心業務與內購記錄功能
卡牌矩陣創建(UGC)與權責:當您自由創建自訂卡牌矩陣時,我們會蒐集並儲存您輸入的矩陣簡介文本、矩陣名稱及描述。用戶知悉並同意,您自主創建的卡牌矩陣圖文內容,其著作權歸您(發布者)個人所有;您嚴禁發布任何違反法律法規、低俗、侵害他人智慧財產權或違背社會善良風俗的內容。平台設有內容審查機制,有權對涉及違規的內容直接進行下架、刪除等處置。因您發布違規內容引發的所有法律糾紛、侵權索賠,全部法律責任由發布用戶自行承擔。本應用不提供任何形式的預測或結論性解讀,上述文本僅作為工具內的用戶自主備註與展示。
消費與內購記錄:當您花費對應資金購買單次創建卡牌矩陣功能服務時,我們會記錄您的訂單生成時間、交易金額、交易狀態及購買的工具功能標識。用戶知悉並同意,該功能服務屬於虛擬數位商品,除適用法律另有強制性規定(如消費者保護相關法律要求)或產品本身存在技術故障外,虛擬功能服務售出後不支援無理由退款。在帳號註銷或度過恢復期後,相關虛擬權益同步失效,不支援任何形式的退費或折現。
3. 技術維護與運行優化功能
網路狀態檢查:本應用整合了網路檢測功能,會讀取您的網路連接類型(如 Wi-Fi、行動網路狀態、是否斷網)。該功能僅用於獲取連網狀態以優化沙盒內卡牌圖片資產、音樂檔案的載入體驗,或在斷網時向您展示友好的錯誤提示,我們絕不抓取您的網頁瀏覽記錄,亦不會私自獲取 IP 以外的網路路由、區域網路設備資訊。
為了實現特定的卡牌工具互動功能,本應用會在必要時向手機系統申請調取以下底層權限:
1. 相機(Camera)權限:當您掃描 QR Code 與實體卡牌產生數位聯動時調用。該權限僅在您主動掃碼的場景下臨時調用,我們絕不進行後台常駐調取,亦不截取、不儲存、不上傳您的任何鏡頭畫面或影像素材,同時我們絕不索取您的系統相簿訪問權限。
2. 網路權限(Internet):用於基礎的登入校驗、資料同步、核心資源(如卡牌圖文、音訊)的線上載入,除此之外無任何額外的資料採集行為。
3. 裝置感應器與反饋權限:在您進行卡牌置換、查看卡牌細節、搖晃觸發互動或體驗特定物理動效時,調用手機的加速度感應器(用於檢測裝置運動姿態)及系統震動反饋。上述感應器原始數據僅在裝置本機用於即時計算介面動效與觸覺反饋,應用程式不會對此類感應器數據進行任何資訊回報、統計、持久化儲存或採集行為。
【權限撤回說明】您知悉並同意,您可隨時在手機系統設定(權限管理)中,手動自主關閉相機、網路、震動等系統權限的授權。一旦您關閉對應權限,本應用將不會再調取相關能力與資料,但對應的特定業務功能也將無法繼續使用。
本應用不使用網頁 Cookie:本應用作為行動端原生應用程式,不調取、不使用任何針對網頁的 Cookie 技術,無任何跨設備追蹤行為。
同類本地儲存技術與清理權限:為了保證應用的正常運行、避免您重複登入,我們會利用系統本地儲存技術(包括 Shared Preferences、Flutter Secure Storage 等),在您的設備本地隔離儲存您的登入 Token(安全權杖)、卡牌圖片快取、以及內建背景音樂(MP3)。用戶知悉並同意,您可以在手機系統的應用設定內隨時手動清除本應用的快取資料。清除快取後,僅本地圖片、音訊等臨時快取檔案會被徹底刪除銷毀,您的帳號核心資料(如內購資產、已創建的矩陣)仍安全保存在伺服器中。
1. 除本政策已明確揭露的第三方 SDK(如微信、Apple)以及法律法規另有規定的情形外,我們不會向任何第三方分享、轉讓您的個人資料。
2. 第三方 SDK 整合明示與免責邊界:為了實現快捷登入與內購支付,本應用整合了必要的第三方 SDK。這些第三方 SDK 僅服務於其對應的特定業務,不會跨業務混用或跨業務採集資料。我方伺服器既不讀取、亦不留存、不備份第三方返回的任何設備唯一識別資料:
所有第三方 SDK 的資料蒐集行為均受其自身隱私權政策約束。
【 SDK 名稱 】 微信 Open SDK
【 提供方 】 深圳市騰訊計算機系統有限公司
【 業務場景 】 實現微信快捷登入、微信支付、分享,及處理從微信跳回本應用時的跨應用跳轉參數恢復與安全校驗
【 蒐集資訊 】
1. 剪貼簿資訊(僅用於讀取微信分享口令,以及作為跨應用跳轉通信失敗時的安全校驗與口令中轉機制);
2. 軟體安裝列表 / 應用安裝狀態(僅用於校驗當前設備是否安裝微信客戶端,以保障相關功能正常喚起);
3. 設備識別碼(包含設備MAC地址、Android ID、OAID、設備序號/Serial;iOS:IDFV,用於風控、防作弊校驗);
4. 設備硬體資訊(設備型號、作業系統版本,用於環境校驗);
5. 網路基礎資訊(IP地址、WLAN接入點、Wi-Fi狀態,用於保障通信安全);
6. 支付相關資訊(如訂單金額、支付狀態、交易單號等,用於完成交易與結果校驗);
【 資料分享與傳輸 】 上述資訊將傳輸至微信伺服器進行處理;資料處理行為受《微信隱私保護指引》約束;除實現本政策所述功能外,不會將您的資料用於其他目的。
【 資料儲存期限 】 所涉及的個人資料儲存期限不超過實現相關業務功能所必需的時間;法律法規另有規定的,從其規定;支付相關資料將按國家金融與稅務法規要求留存。
【 隱私權政策 】 點擊查看《微信隱私保護指引》
【 SDK 名稱 】 Sign in with Apple 及 Apple 應用內購買 SDK
【 提供方 】 Apple Inc. (蘋果公司)
【 業務場景 】 iOS端安全授權登入、提供 App Store 應用內購買(內購支付)及訂單憑證校驗服務
【 蒐集資訊 】
1. 蘋果用戶唯一識別碼(Apple ID 關聯的匿名用戶標識)、設備風控參數;
2. 交易流水分單資訊(當您發起 iOS 內購時,蒐集並向伺服器傳輸【App Store 交易標識符/Transaction ID、購買商品 ID、支付憑證/Receipt Data】以驗證並下發虛擬權益)。
【 資料分享與傳輸 】 上述資訊將傳輸至 Apple 伺服器進行處理;資料處理行為受《Apple隱私權政策》約束;除實現本政策所述功能外,不會將您的資料用於其他目的。
【 資料儲存期限 】 所涉及的個人資料儲存期限不超過實現相關業務功能所必需的時間;法律法規另有規定的,從其規定;內購憑證資料將按蘋果官方開發者權責及相關法規要求持續留存,以便您隨時恢復購買權益。
【 隱私權政策 】 點擊查看《Apple隱私權政策》
【免責邊界聲明】上述第三方 SDK 蒐集的資料完全由其技術初始化觸發,用於其自身風控與支付安全。因第三方 SDK 自身漏洞、違規蒐集或其獨立處理行為引發的任何個人資料洩露與糾紛,將由該第三方提供方在其責任範圍內依法承擔相應的法律責任。我方將積極協助您向第三方維護合法權益,並嚴格依據國家法律法規的規定,在各自法律責任範圍內承擔相應的損害賠償或法律責任。
資料留存時長界定:我們僅在為實現本政策所述目的所必需的最短時限內保留您的個人資料:
- 帳號基礎資料(手機號碼、第三方唯一識別等):在您的帳號存續期間持續留存,一旦帳號徹底註銷,該資料將被立刻徹底刪除銷毀。
- 訂單交易資料(內購記錄、流水編號):為了符合相關電子商務法律的要求,該資料將依法強制留存 3 年以備國家相關部門核查,留存期間不對外進行任何商業化利用。
- 本地快取資料:由用戶在手機設定中自行清理,或在滿足系統過期機制後自動清理。
異常帳號資料處置規則:若您的帳號因嚴重違反用戶協議或法律法規被平台強制永久封禁,平台可依規留存該帳號的必要操作記錄與違規證據用於司法核查;在帳號封禁期間,該帳號暫不支援行使資訊匯出等個人權利操作。
本應用蒐集的個人資料主要儲存於中華人民共和國境內的伺服器。為實現微信快捷登入、Apple 登入及內購支付等功能,部分必要資訊(如 OpenID、交易憑證、設備風控參數等)將依照第三方 SDK 提供方的隱私權政策,傳輸至微信(騰訊)及 Apple Inc. 的伺服器進行處理,具體請參見本政策第四節第三方 SDK 說明。除上述情形外,我們不會擅自將您的個人資料傳輸至境外。
按照相關法律法規,我們保障您對自己的個人資料行使以下主體權利:
查詢、訪問與個人資料複製匯出權:
您有權查看應用內您的帳號綁定狀態及歷史內購記錄。您可以透過本政策公布的官方信箱與我們聯繫,申請匯出您自身帳號名下的基礎個人資料及創作矩陣資料,我們在收到申請並核驗您身份無誤後的 7 個工作日內,為您推播匯出的結構化資料。
更正、修改與自主刪除權:
當您需要變更個人綁定資訊,或需要刪除您個人發布的卡牌矩陣內容時,您可以透過本政策公布的官方信箱(228273847@qq.com)聯繫我們進行後台人工處理。同時,您可以透過系統功能自主退出或移除您所加入的他人的卡牌矩陣,一旦您在客戶端選擇退出或移除,客戶端介面將不再展示該矩陣,伺服器將同步解除您的帳號與該矩陣的關聯綁定關係。
帳號註銷與約束規則:
您可以隨時申請註銷您的帳戶。為了向您提供便捷的自助註銷管道,我們已在應用程式內內建了線上註銷功能。具體的註銷路徑指引如下:您可以透過進入本應用後,點擊我的頁面右上角的【齒輪/設定】圖示按鈕進入【設定】介面,隨後在列表中點擊【註銷帳號】選項,即可提交帳戶自助註銷申請。
【註銷處理與恢復期】我們將在收到您的申請後立即響應並處理您的註銷請求。為了防止用戶誤操作導致資產丟失,本應用為您提供 15 天的帳號恢復期。在提交註銷申請後的 15 天內,若您重新登入該帳號,即可隨時撤銷註銷流程並重新啟用帳戶。
一旦度過 15 天恢復期,您的帳號註銷將最終生效。所有的第三方及手機號碼綁定關係將自動解除,您的個人資料及帳號資料將被徹底刪除或不可逆匿名化處理(但依據相關法律法規要求必須留存的交易流水等合規記錄除外),您將無法再次恢復該帳號內的任何內購資產。
禁止註冊年齡線:本應用作為卡牌創意互動工具,本應用主要面向年滿 16 週歲的用戶提供完整服務。如發現 16 週歲以下兒童未經監護人同意註冊使用,平台將採取限制功能或封禁帳號等措施。
監護人申訴核驗:若 16 週歲以上、未滿 18 週歲的限制民事行為能力人在法定監護人未同意的情況下進行了內購消費,監護人申請退費申訴時,必須向我們的聯繫信箱提供監護人有效身份證明、未成年人身份證明、帳戶所屬權憑證及消費流水記錄。經平台核驗材料真實合規、且符合法定退款條件的,我們將依法處理。
隱私保護兜底安全技術:我們採取了符合業界標準的安全防護措施保護您的個人資料。並且使用加密儲存技術(HTTPS傳輸加密、安全雜湊演算法Token儲存)、嚴格的訪問權限管控機制,將敏感個人資料隔離在受保護的伺服器環境中,最大程度降低資料被洩露、毀損、篡改或違規授予的風險。
政策的更新與微小修訂提示:如果本政策發生關乎蒐集目的、類型改變等重大變更,我們會在您打開應用時透過重新觸發彈跳視窗的形式再次展示,您需要重新勾選同意方能繼續使用全部服務。對於字詞修正、排版優化等不實質性削弱您權利的非重大條款微調,我們將透過應用內公告、系統通知進行公示,不再觸發二次彈跳視窗同意,請您注意定期查閱應用內公告。
法律適用與管轄:本隱私權政策的訂立、效力、解釋、履行及爭議解決,首先適用中華人民共和國大陸地區法律。對於香港特別行政區、澳門特別行政區、台灣地區,以及新加坡、馬來西亞等其他司法管轄區的用戶,本政策同時遵循該地區適用的個人資料隱私相關法規(包括但不限於香港《個人資料(私隱)條例》、新加坡《個人資料保護法》PDPA 等)中關於個人資料保護之強制性規定。如因本政策產生任何爭議,雙方應友好協商解決;協商不成的,任何一方可向本公司註冊地址有管轄權的法院提起訴訟。
如果您對本政策有任何疑問、投訴、檢舉,或需要行使您的資訊匯出、刪除、未成年人退款申訴等權利,請透過以下專屬官方管道與我們取得聯繫:
官方電子信箱:228273847@qq.com
為了保障您的合法權益,我們在收到您的來信、並核全相關證明材料後的 15 個工作日內完成核驗、處理並向您反饋結果。若因案情複雜逾期未收到回覆的,您可以再次發送郵件詢問。
四川省滎小省互聯網科技有限責任公司
Operating Entity: [Sichuan Yingxiaosheng Internet Technology Co., Ltd.]
Registered Address: [No. 5, Ruoshui East 2nd Road, Yandao Street, Yingjing County, Ya'an City, Sichuan Province]
Welcome to the Tata House Application (hereinafter referred to as "this Application" or "we"). We understand the importance of personal information to you and are committed to protecting your personal privacy under the principles of "minimum necessity and secure control". This "Privacy Policy" (hereinafter referred to as "this Policy") is designed to transparently explain to you how we collect, use, store, share, and protect your personal information when you use the Tata House Application, as well as the ways you can manage your personal information.
[Special Notice] Please read this Policy carefully upon the first launch of this Application. This Application will display this Policy in a prominent pop-up window upon the first launch. By clicking agree and checking the terms, you are deemed to have recognized and accepted all terms of this Policy; if you click reject, you will not be able to enter and use all services of this Application.
We will only collect your personal information in accordance with the law for the business functions and card tool services described in this Policy. We promise never to use the collected information to send any commercial advertisements, marketing text messages, or conduct marketing harassment.
1.1 Basic Login and Authentication Functions
Verification Code Login: When you log in using a mobile phone verification code, we will collect your mobile phone number. This mobile phone number is only used for account security verification, identity authentication, and account recovery. We promise not to leak it or use it for any commercial marketing pushes.
Third-Party Quick Login: When you use Apple ID or WeChat quick login, we will collect the unique identifier (OpenID/UID), WeChat nickname, and WeChat avatar provided to us by the third-party platform. Collecting this information is to bind the third-party account with your Tata House account to enable cross-device quick login.
1.2 Core Business and In-App Purchase Record Functions
Card Matrix Creation (UGC) and Responsibilities: When you freely create a custom card matrix, we will collect and store the matrix introduction text, matrix name, and description you input. The user acknowledges and agrees that the copyright of the card matrix graphics and text created by you independently belongs to you (the publisher); you are strictly prohibited from publishing any content that violates laws and regulations, is vulgar, infringes on the intellectual property rights of others, or violates core social values. The platform has a content review mechanism and has the right to directly take down or delete content that involves violations. All legal disputes and infringement claims arising from your publication of illegal content shall be solely borne by the publishing user. This Application does not provide any form of prediction or conclusive interpretation; the above text serves merely as the user's independent notes and display within the tool.
Consumption and In-App Purchase Records: When you spend corresponding funds to purchase single card matrix creation function services, we will record your order generation time, transaction amount, transaction status, and the tool function identifier purchased. The user acknowledges and agrees that this function service belongs to virtual digital goods. Except as otherwise mandated by applicable laws (such as consumer protection laws) or technical failures of the product itself, virtual function services are not eligible for unjustified refunds once sold. After account deletion or after the recovery period has passed, the relevant virtual rights and interests will concurrently become invalid, and no form of refund or cash conversion is supported.
1.3 Technical Maintenance and Operation Optimization Functions
Network Status Check: This Application integrates a network detection function that will read your network connection type (such as Wi-Fi, cellular network status, network disconnection). This function is only used to obtain the network status to optimize the loading experience of card image assets and music files within the sandbox, or to show you friendly error prompts when disconnected. We will never crawl your web browsing history, nor will we privately obtain network routing or LAN device information other than the IP address.
To achieve specific card tool interactive functions, this Application will apply to call the following underlying permissions from the mobile phone system when necessary:
1. Camera Permission: Called when you scan a QR code to generate a digital linkage with an entity card. This permission is only temporarily called in the scenario where you actively scan a code. We will never perform background resident calls, nor will we intercept, store, or upload any of your camera lenses or video materials. At the same time, we will never ask for your system album access permission.
2. Network (Internet) Permission: Used for basic login verification, data synchronization, and online loading of core resources (such as card graphics, audio), without any additional data collection behavior.
3. Device Sensors and Feedback Permissions: When you perform card replacements, view card details, shake to trigger interactions, or experience specific physical visual effects, the App accesses the device's accelerometer (used to detect device motion and orientation) and system vibration feedback. The aforementioned raw sensor data is only used locally on your device for real-time UI dynamic effects and interactive feedback, with no information reporting, statistical analysis, persistent storage, or data collection behaviors.
[Permission Withdrawal Note] You acknowledge and agree that you can manually turn off the authorization of camera, network, vibration, and other system permissions at any time in the mobile phone system settings (Permission Management). Once you turn off the corresponding permissions, this Application will no longer call the relevant capabilities and data, but the corresponding specific business functions will also be unusable.
This Application Does Not Use Web Cookies: As a mobile native application, this Application does not call or use any Cookie technologies targeted at webpages and has no cross-device tracking behavior.
Similar Local Storage Technologies and Cleaning Permissions: To ensure the normal operation of the application and prevent repeated logins, we use system local storage technologies (including Shared Preferences, Flutter Secure Storage, etc.) to isolate and store your Login Token, card image caches, and built-in background music (MP3) locally on your device. Users acknowledge and agree that you can manually clear the cache data of this Application at any time within the application settings of the mobile phone system. After clearing the cache, only temporary cache files such as local images and audio will be completely deleted and destroyed. Your account core data (such as in-app purchase assets, created matrices) will still be safely stored on the server.
1. Except for third-party SDKs (such as WeChat, Apple) already clearly disclosed in this Policy and situations otherwise required by laws and regulations, we will not share or transfer your personal information to any third parties.
2. Third-Party SDK Integration Express and Exemption Boundaries: To achieve quick login and in-app purchase payments, this Application integrates necessary third-party SDKs. These third-party SDKs only serve their corresponding specific businesses and will not mix across businesses or collect data across businesses. Our servers neither read, retain, nor back up any device unique identification data returned by third parties:
All data collection behaviors of third-party SDKs are subject to their own privacy policies.
[SDK Name] WeChat Open SDK
[Provider] Shenzhen Tencent Computer Systems Company Limited
[Business Scenario] Implement WeChat quick login, WeChat payment, sharing, and handle cross-application jump parameter recovery and security verification when jumping back to this Application from WeChat.
[Information Collected]
1. Clipboard information (only used to read WeChat sharing passwords, and as a security verification and password relay mechanism when cross-app jump communication fails);
2. Software installation list/app installation status (only used to verify whether the WeChat client is installed on the current device to ensure related functions are launched normally);
3. Device identifiers (including device MAC address, Android ID, OAID, device serial number/Serial; iOS: IDFV, used for risk control, anti-cheating verification);
4. Device hardware information (device model, operating system version, used for environmental verification);
5. Network basic information (IP address, WLAN access point, Wi-Fi status, used to ensure communication security);
6. Payment-related information (such as order amount, payment status, transaction number, etc., used to complete the transaction and verify the result);
[Data Sharing and Transfer] The above information will be transmitted to WeChat servers for processing; data processing behavior is subject to the "WeChat Privacy Protection Guidelines"; except to achieve the functions described in this Policy, your data will not be used for other purposes.
[Data Storage Period] The retention period of the personal information involved will not exceed the time necessary to achieve the relevant business functions; if laws and regulations stipulate otherwise, such provisions shall prevail; payment-related data will be retained in accordance with national financial and tax regulations.
[Privacy Policy] Click to view "WeChat Privacy Protection Guidelines"
[SDK Name] Sign in with Apple and Apple In-App Purchase SDK
[Provider] Apple Inc.
[Business Scenario] iOS secure authorization login, providing App Store In-App Purchase (IAP) and order receipt verification services.
[Information Collected]
1. Apple user unique identifier (anonymous user identifier associated with Apple ID), device risk control parameters;
2. Transaction flow sub-order information (when you initiate an iOS IAP, collect and transmit [App Store Transaction Identifier/Transaction ID, Product ID, Receipt Data] to the server to verify and issue virtual rights).
[Data Sharing and Transfer] The above information will be transmitted to Apple servers for processing; data processing behavior is subject to the "Apple Privacy Policy"; except to achieve the functions described in this Policy, your data will not be used for other purposes.
[Data Storage Period] The retention period of the personal information involved will not exceed the time necessary to achieve the relevant business functions; if laws and regulations stipulate otherwise, such provisions shall prevail; IAP receipt data will be continuously retained in accordance with Apple's official developer rights and responsibilities and relevant regulatory requirements so that you can restore your purchase rights at any time.
[Privacy Policy] Click to view "Apple Privacy Policy"
[Disclaimer of Liability Boundary] The data collected by the above third-party SDKs is entirely triggered by their technical initialization and used for their own risk control and payment security. Any leakage of personal information and disputes caused by third-party SDK's own vulnerabilities, illegal collection, or its independent processing behavior shall be borne by the third-party provider in accordance with the law within its scope of responsibility. We will actively assist you in safeguarding your legitimate rights and interests against third parties and strictly bear corresponding damages or legal responsibilities within our respective legal liability scopes in accordance with national laws and regulations.
Definition of Data Retention Duration: We retain your personal information only for the minimum period necessary to achieve the purposes stated in this Policy:
- Basic Account Data (mobile phone number, third-party unique identifiers, etc.): Retained continuously during the existence of your account. Once the account is completely deleted, this data will be permanently and immediately destroyed.
- Order Transaction Data (IAP records, serial numbers): To comply with the requirements of the "E-Commerce Law," this data will be mandatorily retained according to law for 3 years for inspection by relevant national authorities, and will not be commercially utilized during the retention period.
- Local Cache Data: Cleaned up by the user manually in the phone settings or automatically cleaned after meeting the system expiration mechanism.
Abnormal Account Data Handling Rules: If your account is permanently banned by the platform due to serious violations of the User Agreement or laws and regulations, the platform may retain the necessary operation records and violation evidence of the account for judicial verification according to regulations; during the account ban period, operations related to personal rights such as information export and account deletion will be temporarily suspended.
The personal information collected by this application is primarily stored on servers located within the mainland of the People's Republic of China. To facilitate functions such as WeChat quick login, Apple Sign-in, and in-app purchases, some necessary information (such as OpenID, transaction receipts, and device risk control parameters) will be transmitted to the servers of WeChat (Tencent) and Apple Inc. in accordance with the privacy policies of the third-party SDK providers. For details, please refer to Section 4 on Third-Party SDKs in this Policy. Except for the above circumstances, we will not transmit your personal information abroad without authorization.
In accordance with relevant laws and regulations, we guarantee your ability to exercise the following subject rights over your personal information:
Right of Access and Copy/Export of Personal Information:
You have the right to view your account binding status and historical in-app purchase records within the application. You can contact us via the official email address published in this Policy to request the export of your basic personal information and creation matrix data under your account. We will push the exported structured data to you within 7 working days after receiving the application and verifying your identity correctly.
Right to Rectification and Independent Deletion:
When you need to change your personal binding information, or need to delete the card matrix content published by you, you can contact us via the official email (228273847@qq.com) published in this Policy for manual processing in the background. At the same time, you can independently exit or remove card matrices created by others that you have joined via system functions. Once you choose to exit or remove in the client, the client interface will no longer display the matrix, and the server will synchronously dissolve the binding relationship between your account and the matrix.
Account Deletion and Restriction Rules:
You can apply to delete your account at any time. To provide you with a convenient self-service cancellation channel, we have built an online cancellation function within the application. The specific cancellation path guide is as follows: After entering the application, click the [Gear/Settings] icon button in the upper right corner of the 'My' page to enter the [Settings] interface, then click the [Delete Account] option in the list to submit your account cancellation request.
[Deletion Processing and Grace Period] We will respond to and process your deletion request immediately upon receipt. To prevent users from losing assets due to operational mistakes, this Application provides you with a 15-day account recovery grace period. Within 15 days of submitting the cancellation application, if you log into the account again, you can revoke the cancellation process and reactivate the account at any time.
Once the 15-day grace period has passed, your account deletion will become final. All third-party and mobile phone number binding relationships will be automatically dissolved, and your personal information and account data will be permanently deleted or irreversibly anonymized (except for compliance records such as transaction flows that must be retained in accordance with relevant laws and regulations). You will not be able to restore any in-app purchase assets within the account again.
Prohibited Registration Age Limit: As a card creative interactive tool, this Application is primarily aimed at providing full services to users aged 16 and above. If it is found that children under the age of 16 register and use without the consent of their guardians, the platform will take measures such as restricting functions or banning accounts.
Guardian Appeal Verification: If a person with limited civil capacity over the age of 16 but under the age of 18 makes an in-app purchase without the consent of the legal guardian, when the guardian applies for a refund appeal, they must provide our contact email with the guardian's valid identity proof, the minor's identity proof, the account ownership voucher, and the consumption flow record. After the platform verifies that the materials are authentic and compliant, and meet the statutory refund conditions, we will process them in accordance with the law.
Privacy Protection Security Technologies: We have adopted security protection measures that comply with industry standards to protect your personal information. We use encrypted storage technology (HTTPS transmission encryption, secure Hash Algorithm Token storage) and a strict access privilege control mechanism to isolate sensitive personal information in a protected server environment, maximizing the reduction of risks of data leakage, damage, tampering, or unauthorized access.
Policy Updates and Minor Revision Notices: If there is a material change to this Policy concerning collection purposes, type changes, etc., we will display it again through a triggered pop-up window when you open the application, and you will need to check agree again to continue using all services. For minor clause adjustments that do not materially weaken your rights, such as word corrections and layout optimization, we will publish them through in-app announcements and system notifications without triggering a secondary pop-up consent. Please pay attention to periodically reviewing in-app announcements.
Governing Law and Jurisdiction: The conclusion, validity, interpretation, performance, and dispute resolution of this Privacy Policy shall initially be governed by the laws of mainland People's Republic of China. For users in the Hong Kong Special Administrative Region, Macao Special Administrative Region, Taiwan Region, as well as Singapore, Malaysia, and other jurisdictions, this Policy simultaneously complies with the mandatory provisions regarding personal data protection in the applicable personal data privacy laws of those regions (including but not limited to the Hong Kong "Personal Data (Privacy) Ordinance", Singapore's "Personal Data Protection Act" (PDPA), etc.). If any dispute arises from this Policy, both parties shall attempt to resolve it through friendly negotiation; if negotiation fails, either party may file a lawsuit with a competent court in the location where our company is registered.
If you have any questions, complaints, reports regarding this Policy, or need to exercise your rights to export data, delete data, or appeal for minor refunds, please contact us through the following exclusive official channel:
Official Email: 228273847@qq.com
To protect your legitimate rights and interests, we will complete the verification, processing, and feed back the results to you within 15 working days after receiving your letter and verifying all relevant certification materials. If the case is complex and you have not received a reply within the time limit, you may send another email to inquire.
Sichuan Yingxiaosheng Internet Technology Co., Ltd.