Privacy Policy
Xingwang International Limited ("Xingwang", "we", "us", "our") operates the website xingwangcs.com and mobile management applications published on the Apple App Store and Google Play. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have. It applies to both the website and our mobile apps.
- 1. Who we are
- 2. Information we collect
- 3. How we use your information
- 4. Mobile app data & ad SDKs
- 5. Ad formats in our apps
- 6. Legal bases (GDPR)
- 7. International data transfers
- 8. Data retention
- 9. Your rights
- 10. Children's privacy
- 11. Do Not Track & global privacy controls
- 12. Security
- 13. App store compliance
- 14. Third-party links
- 15. Changes to this policy
- 16. Contact us
1. Who we are
The data controller is Xingwang International Limited, a Hong Kong incorporated company with its registered office at RM 11, 9/F, THE CLOUD, 111 TUNG CHAU ST, Hong Kong. You can reach our data protection contact at privacy@xingwangcs.com.
2. Information we collect
2.1 Information you give us
- Contact form: name, work email, company, country, message contents.
- Trade inquiries: commercial information you share with our trade desk (e.g. product categories, target markets, shipment volumes).
- App accounts: if you create an account in one of our apps, your name, email, hashed password, organization, and role.
- Support correspondence: emails, call recordings (where permitted and announced), chat transcripts, attachments.
2.2 Information collected automatically on the website
- IP address, approximate location (country/city), browser type and version, operating system, referrer, pages visited, time on page.
- Cookies and similar identifiers (see our cookie banner for categories).
2.3 Information collected automatically in the apps
- Device identifiers: Identifier for Advertisers (IDFA) on iOS and Google Advertising ID (GAID) on Android, where permitted by the platform.
- Device model, OS version, app version, locale, timezone, screen size, network type, crash logs, and in-app events (sessions, screens viewed, actions taken).
- Push notification tokens, if you grant permission.
2.4 Information from third parties
- App stores (Apple, Google) for app distribution, crash diagnostics, and aggregate download statistics.
- Ad networks and mediation partners (see section 4) for ad delivery, measurement, and fraud prevention.
- Analytics providers for aggregated usage reporting.
- Payment processors when you purchase services (they receive only what is needed to process the transaction).
2.5 Cookies and similar technologies
We use a minimal set of cookies: a session cookie to keep the site working, a preference cookie to remember your cookie choice, and (only if you accept) an analytics cookie to count visits. We do not sell cookie data and we do not use third-party advertising cookies on this website.
3. How we use your information
| Purpose | Examples | Lawful basis (GDPR) |
|---|---|---|
| Provide and operate the website and apps | Authenticate app users, render pages, route requests | Contract / Legitimate interests |
| Respond to inquiries and provide support | Reply to contact form, troubleshoot an app issue | Contract / Pre-contractual steps |
| Provide B2B services | Quote, plan, ship, invoice, deliver, support a trade engagement | Contract |
| Improve our products | Aggregate analytics, A/B test UX changes, fix bugs | Legitimate interests |
| Marketing communications | Send the newsletter, share event invitations | Consent (opt-out in every email) |
| Legal compliance and dispute resolution | Tax records, sanctions screening, fraud prevention | Legal obligation / Legitimate interests |
| Security | Detect abuse, protect accounts, log security events | Legitimate interests |
4. Mobile app data & ad SDKs
Our mobile management apps integrate the following advertising and monetization platforms, typically via a mediation layer. For each, the table below lists the provider, categories of data collected, the purpose, a link to the provider's own privacy documentation, and the opt-out mechanism available to users. We require all of these partners to contractually limit their use of data to providing their services to us.
| # | Provider / SDK | Data collected | Purpose | Provider privacy & opt-out |
|---|---|---|---|---|
| 1 | Google AdMob (Google LLC) | Advertising ID (IDFA/GAID), IP address, device info, ad interaction events | Serve and measure in-app ads (splash, rewarded video, interstitial, banner) | Policy · Ad settings · Reset Advertising ID in OS settings |
| 2 | Google Ad Manager (Google LLC) | Advertising ID, IP address, device info, contextual ad signals | Direct-sold and programmatic in-app ads, header bidding | Policy · Ad settings · Reset Advertising ID in OS settings |
| 3 | Meta Audience Network (Meta Platforms, Inc.) | Advertising ID, device info, ad events, coarse location | Serve and measure in-app ads via Meta mediation | Policy · Ad preferences · iOS App Tracking Transparency prompt |
| 4 | Unity Ads (Unity Technologies) | Advertising ID, device info, IP, gameplay/app events | Rewarded video and interstitial ad serving | Policy · Opt-out |
| 5 | AppLovin (AppLovin Corporation) | Advertising ID, device info, IP, ad events | In-app bidding, rewarded, interstitial, banner | Policy · Opt-out |
| 6 | ironSource / Unity LevelPlay | Advertising ID, device info, IP, ad interaction events | Mediation, rewarded video, interstitial, banner | Policy · Opt-out |
| 7 | Pangle (ByteDance Pte. Ltd.) | Advertising ID, device info, IP, coarse location | In-app video and native ads, especially in APAC | Policy · In-app opt-out + OS Advertising ID reset |
| 8 | Vungle (Liftoff Mobile, Inc.) | Advertising ID, device info, IP, ad events | Rewarded video and interstitial ads | Policy · Opt-out |
| 9 | Chartboost (Zynga Inc., a Take-Two company) | Advertising ID, device info, IP, ad events | In-app programmatic ads and mediation | Policy · OS Advertising ID reset / ATT prompt |
| 10 | InMobi (InMobi Technology Services Pvt. Ltd.) | Advertising ID, device info, IP, coarse location, ad events | Programmatic in-app ads | Policy · Opt-out |
| 11 | Tapjoy (Tapjoy, Inc.) | Advertising ID, device info, IP, reward events | Rewarded offerwall and in-app ads | Policy · Opt-out |
| 12 | Mintegral (Mintegral International S.A.) | Advertising ID, device info, IP, ad events | Programmatic video and playable ads | Policy · Opt-out |
| 13 | Digital Turbine (Digital Turbine, Inc.) | Advertising ID, device info, IP, ad events | Mediation, in-app bidding | Policy · OS Advertising ID reset / ATT prompt |
| 14 | Liftoff (Liftoff Mobile, Inc.) | Advertising ID, device info, IP, ad events | Programmatic user acquisition and monetization | Policy · OS Advertising ID reset / ATT prompt |
| 15 | Moloco (Moloco, Inc.) | Advertising ID, device info, IP, ad events | Programmatic in-app bidding | Policy · OS Advertising ID reset / ATT prompt |
| 16 | Yahoo / Verizon Media (Yahoo Inc.) | Advertising ID, device info, IP, contextual signals | Native and video in-app ads | Policy · Opt-out |
| 17 | Smaato (Smaato, Inc.) | Advertising ID, device info, IP, ad events | In-app header bidding | Policy · OS Advertising ID reset / ATT prompt |
| 18 | Start.io (Start.io Inc., formerly StartApp) | Advertising ID, device info, IP, ad events | In-app programmatic ads | Policy · Opt-out |
| 19 | Appodeal (Appodeal Ltd.) | Advertising ID, device info, IP, ad events | Mediation and in-app bidding | Policy · OS Advertising ID reset / ATT prompt |
| 20 | Amazon Publisher Services (Amazon.com, Inc.) | Advertising ID, device info, IP, ad events | Header bidding for in-app inventory | Policy · Ad preferences |
5. Ad formats in our apps
The ad networks above may deliver any of the following formats inside our mobile apps. We describe each in plain English so you know what to expect.
- Splash / open-screen ads. A full-screen static or short video shown at the moment the app is launched. Typically lasts 3 to 8 seconds, with a clear "skip" or close control where required. Used to keep the free tier of the app free.
- Rewarded video ads. The user voluntarily opts in to watch a short video (typically 15 to 30 seconds) in exchange for an in-app reward such as a premium feature unlock, an extended report, or a credit. The ad network records only that the user completed the video.
- Interstitial ads. Full-screen ads shown at natural transition points — between screens, after a long-running action completes, or when a feature is locked. Users can dismiss them with a visible close control.
- Banner ads. Small persistent banners that appear at the top or bottom of a screen. They refresh automatically and are clearly labeled as advertisements.
Ad placements never overlay safety-critical UI (such as emergency contact actions) and never appear during data-entry flows where a mis-click would be costly.
6. Legal bases for processing (GDPR Article 6)
Where the GDPR applies, we rely on the following legal bases:
- Consent (Art. 6(1)(a)) — for non-essential cookies, marketing emails, and the use of advertising identifiers for personalized ads. You can withdraw consent at any time without affecting prior lawful processing.
- Contract (Art. 6(1)(b)) — to provide the services and apps you have asked us to provide.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, customs, sanctions, and other legal requirements.
- Vital interests (Art. 6(1)(d)) — to protect your life or someone else's in an emergency.
- Public task (Art. 6(1)(e)) — where we perform a task in the public interest (rare for our business).
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, product analytics, and basic service improvement, balanced against your rights and freedoms.
7. International data transfers
Because we operate across borders, your data may be transferred to and processed in countries other than your own, including Hong Kong, Singapore, the United States, the United Kingdom, and the European Economic Area. Where we transfer personal data out of the EEA, the UK, mainland China, or other jurisdictions that require safeguards, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other approved mechanisms, plus supplementary technical and organizational measures. For transfers out of mainland China involving personal information, we comply with the PIPL, including separate consent and security assessments where required.
8. Data retention
| Category | Retention | Why |
|---|---|---|
| Contact form submissions | 24 months from last interaction | Reasonable business follow-up window |
| App account data | For the life of the account + 24 months | Service continuity, audit trail |
| Trade engagement records | 7 years (HK) / 10 years (PRC, where applicable) | Tax, customs, commercial law |
| Server access logs | 90 days | Security, incident response |
| Analytics aggregates | 26 months | Trend analysis |
| App advertising data | Per partner policy (typically 13–18 months) | Frequency capping, fraud prevention |
9. Your rights
Depending on where you live, you have some or all of the following rights. We will respond within one month (extendable to two months for complex requests) and will never charge a fee for exercising a right.
- EEA, UK, Switzerland (GDPR / UK GDPR): access, rectification, erasure, restriction of processing, data portability, object to processing, withdraw consent, lodge a complaint with your local supervisory authority.
- California, USA (CCPA / CPRA): right to know, right to delete, right to correct, right to opt out of sale or sharing, right to limit the use of sensitive personal information, right to non-discrimination.
- Brazil (LGPD): confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, right to revoke consent, right to complain to the ANPD.
- Canada (PIPEDA): access and correction, with limited exceptions.
- Australia (Privacy Act 1988): access and correction through the OAIC process.
- Singapore (PDPA): access and correction through the PDPC process.
- Mainland China (PIPL):知情决定权 (knowledge and decision), 查询复制 (query and copy), 更正补充 (correct and supplement), 删除 (delete), 撤回同意 (withdraw consent), 解释说明 (explanation), and the right to lodge a complaint.
To exercise any right, email privacy@xingwangcs.com from the email address you want us to verify. We may need to confirm your identity before acting on a request.
10. Children's privacy
Our services are designed for business users and adult consumers. We do not knowingly collect personal data from children.
- COPPA (US, under 13): our apps and website are not directed to children under 13, and we do not knowingly collect personal data from them. Where the relevant SDKs support it, we pass tag_for_child_directed_treatment or equivalent child-directed flags in line with Google's Families Policy and Meta's audience signals.
- GDPR-K (EEA, under 16 by default, or as set by member state): same approach. We rely on consent from a parent or guardian where applicable.
- UK Age-Appropriate Design Code: our apps are not marketed to children and do not use behavioural advertising toward users we know to be under 18.
- China (PIPL) and Hong Kong (PDPO): processing of personal data of minors under 14 requires separate guardian consent.
If you believe a child has provided us personal data, contact privacy@xingwangcs.com and we will delete it within 7 days.
11. Do Not Track & global privacy controls
We respect the following signals, where technically possible:
- Browser "Do Not Track" (DNT) and "Global Privacy Control" (GPC) headers on the website.
- iOS App Tracking Transparency (ATT) opt-out on iOS apps.
- Android Advertising ID reset / opt-out of "Ad personalization" in Google Settings.
- App-level privacy controls exposed in the app's settings screen.
12. Security
We protect personal data with technical and organizational measures appropriate to the risk, including TLS in transit, encryption at rest, role-based access control, multi-factor authentication for staff, vendor due diligence, regular patching, and incident response drills. No method of transmission or storage is 100% secure; we notify affected users and regulators of material breaches as required by law.
13. App store compliance
13.1 Apple App Store
- App Review Guidelines: 1.4 (Safety), 2.1 (App Completeness), 4.0 (Design), and especially 5.1.1 / 5.1.2 (Privacy).
- App Tracking Transparency (ATT): on iOS 14.5+ we display the ATT prompt before any SDK accesses the IDFA for tracking. The prompt clearly states the purpose and lets users decline.
- Privacy nutrition labels: the labels on our App Store listing are kept in sync with this policy and the data actually collected.
- Children's category: our apps are not in the Kids category; we do not target children.
- Apple EULA: use of our iOS apps is also subject to Apple's standard Licensed Application End User License Agreement, which is incorporated by reference.
13.2 Google Play
- Developer Program Policy: User Data, Permissions, Mobile Unwanted Software, Families Policy, and Ads Policy are all observed.
- Data Safety form: the Data Safety answers on our Play listing match the data flows described in this policy.
- Ads policy: no interest-based advertising to users we know to be children; ads are clearly distinguishable from app content; ad behavior matches the rules for each format.
- Families Policy: not used; we do not target children.
14. Third-party links
Our website and apps may link to third-party sites (such as Apple, Google, or trade-event pages). We are not responsible for their privacy practices. Please read their policies.
15. Changes to this policy
We will post material changes on this page and, for material changes, in-app. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of our services after a material change constitutes acceptance of the updated policy.
16. Contact us
For privacy questions, requests, or complaints:
- Data protection contact: privacy@xingwangcs.com
- Customer support: support@xingwangcs.com
- Key accounts: yangshiwei@xingwangcs.com
- Postal address: RM 11, 9/F, THE CLOUD, 111 TUNG CHAU ST, Hong Kong
Effective date: 9 September 2026.