Last updated: 9 September 2026

Privacy Policy

Xingwang International Limited ("Xingwang", "we", "us", "our") operates the website xingwangcs.com and mobile management applications published on the Apple App Store and Google Play. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have. It applies to both the website and our mobile apps.

Contents
  1. 1. Who we are
  2. 2. Information we collect
  3. 3. How we use your information
  4. 4. Mobile app data & ad SDKs
  5. 5. Ad formats in our apps
  6. 6. Legal bases (GDPR)
  7. 7. International data transfers
  8. 8. Data retention
  9. 9. Your rights
  10. 10. Children's privacy
  11. 11. Do Not Track & global privacy controls
  12. 12. Security
  13. 13. App store compliance
  14. 14. Third-party links
  15. 15. Changes to this policy
  16. 16. Contact us

1. Who we are

The data controller is Xingwang International Limited, a Hong Kong incorporated company with its registered office at RM 11, 9/F, THE CLOUD, 111 TUNG CHAU ST, Hong Kong. You can reach our data protection contact at privacy@xingwangcs.com.

2. Information we collect

2.1 Information you give us

  • Contact form: name, work email, company, country, message contents.
  • Trade inquiries: commercial information you share with our trade desk (e.g. product categories, target markets, shipment volumes).
  • App accounts: if you create an account in one of our apps, your name, email, hashed password, organization, and role.
  • Support correspondence: emails, call recordings (where permitted and announced), chat transcripts, attachments.

2.2 Information collected automatically on the website

  • IP address, approximate location (country/city), browser type and version, operating system, referrer, pages visited, time on page.
  • Cookies and similar identifiers (see our cookie banner for categories).

2.3 Information collected automatically in the apps

  • Device identifiers: Identifier for Advertisers (IDFA) on iOS and Google Advertising ID (GAID) on Android, where permitted by the platform.
  • Device model, OS version, app version, locale, timezone, screen size, network type, crash logs, and in-app events (sessions, screens viewed, actions taken).
  • Push notification tokens, if you grant permission.

2.4 Information from third parties

  • App stores (Apple, Google) for app distribution, crash diagnostics, and aggregate download statistics.
  • Ad networks and mediation partners (see section 4) for ad delivery, measurement, and fraud prevention.
  • Analytics providers for aggregated usage reporting.
  • Payment processors when you purchase services (they receive only what is needed to process the transaction).

2.5 Cookies and similar technologies

We use a minimal set of cookies: a session cookie to keep the site working, a preference cookie to remember your cookie choice, and (only if you accept) an analytics cookie to count visits. We do not sell cookie data and we do not use third-party advertising cookies on this website.

3. How we use your information

PurposeExamplesLawful basis (GDPR)
Provide and operate the website and appsAuthenticate app users, render pages, route requestsContract / Legitimate interests
Respond to inquiries and provide supportReply to contact form, troubleshoot an app issueContract / Pre-contractual steps
Provide B2B servicesQuote, plan, ship, invoice, deliver, support a trade engagementContract
Improve our productsAggregate analytics, A/B test UX changes, fix bugsLegitimate interests
Marketing communicationsSend the newsletter, share event invitationsConsent (opt-out in every email)
Legal compliance and dispute resolutionTax records, sanctions screening, fraud preventionLegal obligation / Legitimate interests
SecurityDetect abuse, protect accounts, log security eventsLegitimate interests

4. Mobile app data & ad SDKs

Our mobile management apps integrate the following advertising and monetization platforms, typically via a mediation layer. For each, the table below lists the provider, categories of data collected, the purpose, a link to the provider's own privacy documentation, and the opt-out mechanism available to users. We require all of these partners to contractually limit their use of data to providing their services to us.

#Provider / SDKData collectedPurposeProvider privacy & opt-out
1 Google AdMob (Google LLC) Advertising ID (IDFA/GAID), IP address, device info, ad interaction events Serve and measure in-app ads (splash, rewarded video, interstitial, banner) Policy · Ad settings · Reset Advertising ID in OS settings
2 Google Ad Manager (Google LLC) Advertising ID, IP address, device info, contextual ad signals Direct-sold and programmatic in-app ads, header bidding Policy · Ad settings · Reset Advertising ID in OS settings
3 Meta Audience Network (Meta Platforms, Inc.) Advertising ID, device info, ad events, coarse location Serve and measure in-app ads via Meta mediation Policy · Ad preferences · iOS App Tracking Transparency prompt
4 Unity Ads (Unity Technologies) Advertising ID, device info, IP, gameplay/app events Rewarded video and interstitial ad serving Policy · Opt-out
5 AppLovin (AppLovin Corporation) Advertising ID, device info, IP, ad events In-app bidding, rewarded, interstitial, banner Policy · Opt-out
6 ironSource / Unity LevelPlay Advertising ID, device info, IP, ad interaction events Mediation, rewarded video, interstitial, banner Policy · Opt-out
7 Pangle (ByteDance Pte. Ltd.) Advertising ID, device info, IP, coarse location In-app video and native ads, especially in APAC Policy · In-app opt-out + OS Advertising ID reset
8 Vungle (Liftoff Mobile, Inc.) Advertising ID, device info, IP, ad events Rewarded video and interstitial ads Policy · Opt-out
9 Chartboost (Zynga Inc., a Take-Two company) Advertising ID, device info, IP, ad events In-app programmatic ads and mediation Policy · OS Advertising ID reset / ATT prompt
10 InMobi (InMobi Technology Services Pvt. Ltd.) Advertising ID, device info, IP, coarse location, ad events Programmatic in-app ads Policy · Opt-out
11 Tapjoy (Tapjoy, Inc.) Advertising ID, device info, IP, reward events Rewarded offerwall and in-app ads Policy · Opt-out
12 Mintegral (Mintegral International S.A.) Advertising ID, device info, IP, ad events Programmatic video and playable ads Policy · Opt-out
13 Digital Turbine (Digital Turbine, Inc.) Advertising ID, device info, IP, ad events Mediation, in-app bidding Policy · OS Advertising ID reset / ATT prompt
14 Liftoff (Liftoff Mobile, Inc.) Advertising ID, device info, IP, ad events Programmatic user acquisition and monetization Policy · OS Advertising ID reset / ATT prompt
15 Moloco (Moloco, Inc.) Advertising ID, device info, IP, ad events Programmatic in-app bidding Policy · OS Advertising ID reset / ATT prompt
16 Yahoo / Verizon Media (Yahoo Inc.) Advertising ID, device info, IP, contextual signals Native and video in-app ads Policy · Opt-out
17 Smaato (Smaato, Inc.) Advertising ID, device info, IP, ad events In-app header bidding Policy · OS Advertising ID reset / ATT prompt
18 Start.io (Start.io Inc., formerly StartApp) Advertising ID, device info, IP, ad events In-app programmatic ads Policy · Opt-out
19 Appodeal (Appodeal Ltd.) Advertising ID, device info, IP, ad events Mediation and in-app bidding Policy · OS Advertising ID reset / ATT prompt
20 Amazon Publisher Services (Amazon.com, Inc.) Advertising ID, device info, IP, ad events Header bidding for in-app inventory Policy · Ad preferences

5. Ad formats in our apps

The ad networks above may deliver any of the following formats inside our mobile apps. We describe each in plain English so you know what to expect.

  • Splash / open-screen ads. A full-screen static or short video shown at the moment the app is launched. Typically lasts 3 to 8 seconds, with a clear "skip" or close control where required. Used to keep the free tier of the app free.
  • Rewarded video ads. The user voluntarily opts in to watch a short video (typically 15 to 30 seconds) in exchange for an in-app reward such as a premium feature unlock, an extended report, or a credit. The ad network records only that the user completed the video.
  • Interstitial ads. Full-screen ads shown at natural transition points — between screens, after a long-running action completes, or when a feature is locked. Users can dismiss them with a visible close control.
  • Banner ads. Small persistent banners that appear at the top or bottom of a screen. They refresh automatically and are clearly labeled as advertisements.

Ad placements never overlay safety-critical UI (such as emergency contact actions) and never appear during data-entry flows where a mis-click would be costly.

6. Legal bases for processing (GDPR Article 6)

Where the GDPR applies, we rely on the following legal bases:

  • Consent (Art. 6(1)(a)) — for non-essential cookies, marketing emails, and the use of advertising identifiers for personalized ads. You can withdraw consent at any time without affecting prior lawful processing.
  • Contract (Art. 6(1)(b)) — to provide the services and apps you have asked us to provide.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, customs, sanctions, and other legal requirements.
  • Vital interests (Art. 6(1)(d)) — to protect your life or someone else's in an emergency.
  • Public task (Art. 6(1)(e)) — where we perform a task in the public interest (rare for our business).
  • Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, product analytics, and basic service improvement, balanced against your rights and freedoms.

7. International data transfers

Because we operate across borders, your data may be transferred to and processed in countries other than your own, including Hong Kong, Singapore, the United States, the United Kingdom, and the European Economic Area. Where we transfer personal data out of the EEA, the UK, mainland China, or other jurisdictions that require safeguards, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other approved mechanisms, plus supplementary technical and organizational measures. For transfers out of mainland China involving personal information, we comply with the PIPL, including separate consent and security assessments where required.

8. Data retention

CategoryRetentionWhy
Contact form submissions24 months from last interactionReasonable business follow-up window
App account dataFor the life of the account + 24 monthsService continuity, audit trail
Trade engagement records7 years (HK) / 10 years (PRC, where applicable)Tax, customs, commercial law
Server access logs90 daysSecurity, incident response
Analytics aggregates26 monthsTrend analysis
App advertising dataPer partner policy (typically 13–18 months)Frequency capping, fraud prevention

9. Your rights

Depending on where you live, you have some or all of the following rights. We will respond within one month (extendable to two months for complex requests) and will never charge a fee for exercising a right.

  • EEA, UK, Switzerland (GDPR / UK GDPR): access, rectification, erasure, restriction of processing, data portability, object to processing, withdraw consent, lodge a complaint with your local supervisory authority.
  • California, USA (CCPA / CPRA): right to know, right to delete, right to correct, right to opt out of sale or sharing, right to limit the use of sensitive personal information, right to non-discrimination.
  • Brazil (LGPD): confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, right to revoke consent, right to complain to the ANPD.
  • Canada (PIPEDA): access and correction, with limited exceptions.
  • Australia (Privacy Act 1988): access and correction through the OAIC process.
  • Singapore (PDPA): access and correction through the PDPC process.
  • Mainland China (PIPL):知情决定权 (knowledge and decision), 查询复制 (query and copy), 更正补充 (correct and supplement), 删除 (delete), 撤回同意 (withdraw consent), 解释说明 (explanation), and the right to lodge a complaint.

To exercise any right, email privacy@xingwangcs.com from the email address you want us to verify. We may need to confirm your identity before acting on a request.

10. Children's privacy

Our services are designed for business users and adult consumers. We do not knowingly collect personal data from children.

  • COPPA (US, under 13): our apps and website are not directed to children under 13, and we do not knowingly collect personal data from them. Where the relevant SDKs support it, we pass tag_for_child_directed_treatment or equivalent child-directed flags in line with Google's Families Policy and Meta's audience signals.
  • GDPR-K (EEA, under 16 by default, or as set by member state): same approach. We rely on consent from a parent or guardian where applicable.
  • UK Age-Appropriate Design Code: our apps are not marketed to children and do not use behavioural advertising toward users we know to be under 18.
  • China (PIPL) and Hong Kong (PDPO): processing of personal data of minors under 14 requires separate guardian consent.

If you believe a child has provided us personal data, contact privacy@xingwangcs.com and we will delete it within 7 days.

11. Do Not Track & global privacy controls

We respect the following signals, where technically possible:

  • Browser "Do Not Track" (DNT) and "Global Privacy Control" (GPC) headers on the website.
  • iOS App Tracking Transparency (ATT) opt-out on iOS apps.
  • Android Advertising ID reset / opt-out of "Ad personalization" in Google Settings.
  • App-level privacy controls exposed in the app's settings screen.

12. Security

We protect personal data with technical and organizational measures appropriate to the risk, including TLS in transit, encryption at rest, role-based access control, multi-factor authentication for staff, vendor due diligence, regular patching, and incident response drills. No method of transmission or storage is 100% secure; we notify affected users and regulators of material breaches as required by law.

13. App store compliance

13.1 Apple App Store

  • App Review Guidelines: 1.4 (Safety), 2.1 (App Completeness), 4.0 (Design), and especially 5.1.1 / 5.1.2 (Privacy).
  • App Tracking Transparency (ATT): on iOS 14.5+ we display the ATT prompt before any SDK accesses the IDFA for tracking. The prompt clearly states the purpose and lets users decline.
  • Privacy nutrition labels: the labels on our App Store listing are kept in sync with this policy and the data actually collected.
  • Children's category: our apps are not in the Kids category; we do not target children.
  • Apple EULA: use of our iOS apps is also subject to Apple's standard Licensed Application End User License Agreement, which is incorporated by reference.

13.2 Google Play

  • Developer Program Policy: User Data, Permissions, Mobile Unwanted Software, Families Policy, and Ads Policy are all observed.
  • Data Safety form: the Data Safety answers on our Play listing match the data flows described in this policy.
  • Ads policy: no interest-based advertising to users we know to be children; ads are clearly distinguishable from app content; ad behavior matches the rules for each format.
  • Families Policy: not used; we do not target children.

14. Third-party links

Our website and apps may link to third-party sites (such as Apple, Google, or trade-event pages). We are not responsible for their privacy practices. Please read their policies.

15. Changes to this policy

We will post material changes on this page and, for material changes, in-app. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of our services after a material change constitutes acceptance of the updated policy.

16. Contact us

For privacy questions, requests, or complaints:

  • Data protection contact: privacy@xingwangcs.com
  • Customer support: support@xingwangcs.com
  • Key accounts: yangshiwei@xingwangcs.com
  • Postal address: RM 11, 9/F, THE CLOUD, 111 TUNG CHAU ST, Hong Kong

Effective date: 9 September 2026.