PRIVACY POLICY
I. Introduction
Bonbon Team ("we," "us," or "the Service") is committed to safeguarding user privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant regulations. This Privacy Policy outlines how we collect, use, store, and protect your personal information when you interact with our services, applications, or platforms. By using our services, you consent to the practices described herein.
II. Data Controller and Contact Information
- Data Controller: Bonbon Team
- Contact Email: zouqi0202@gmail.com
III. Data We Collect
1. User-Provided Data
- Account Registration: Email address, username (optional), password. Optional profile information (e.g., nickname, avatar, gender, birthdate).
- Content Creation: Text, images, videos, or audio uploaded by users (e.g., profile banners, posts).
- Service Interactions: Feedback, support requests, or participation in community forums.
2. Automatically Collected Data
- Device Information: Device type, operating system, browser type, IP address, device identifiers (e.g., Android ID, IDFA).
- Usage Data: Session duration, feature interactions (e.g., clicks, page views), login/logout times.
- Technical Data: Cookies, local storage, and tracking technologies (e.g., Google Analytics, Firebase).
3. Third-Party Data
- Social Media Integration: Information from linked accounts (e.g., Facebook, Google) with user consent (e.g., profile picture, friend lists).
- Advertising Partners: Anonymous identifiers (e.g., Google AAID) for personalized ads.
IV. Purposes and Legal Bases for Data Processing
We process personal data for the following purposes under the legal bases provided:
Purpose | Legal Basis | Data Types |
---|---|---|
Service delivery and account management | Performance of a contract (GDPR Art. 6(1)(b)) | Account credentials, profile data |
Fraud prevention and security | Legitimate interests (GDPR Art. 6(1)(f)) | Device info, login attempts, IP address |
Service improvement | Performance of a contract (GDPR Art. 6(1)(b)) | Usage analytics, feature feedback |
Marketing (with consent) | User consent (GDPR Art. 6(1)(a)) | Email, device tokens for ads |
Legal compliance | Legal obligation (GDPR Art. 6(1)(c)) | Law enforcement requests, regulatory data |
V. Data Sharing and Cross-Border Transfers
1. Third-Party Sharing
- Service Providers: Hosting, analytics (e.g., Google Analytics), and customer support tools. Data shared is anonymized or pseudonymized where possible.
- Advertising Partners: Non-identifiable user behavior data for ad targeting (e.g., interest-based ads).
2. Cross-Border Transfers
- Data transferred outside your jurisdiction (e.g., to servers in the EU or US) will use:
- Standard Contractual Clauses (SCCs) for GDPR compliance.
- Privacy Shield Framework (if applicable).
VI. User Rights Under GDPR/CCPA
You may exercise the following rights:
Right | Action | How to Exercise |
---|---|---|
Access | Request a copy of your data. | Email zouqi0202@gmail.com |
Rectification | Correct inaccurate data. | Submit updated info via account settings |
Erasure | Delete your account and associated data. | "Delete Account" option in settings |
Restrict Processing | Limit how we use your data (e.g., suspend account). | Contact support |
Data Portability | Receive data in a machine-readable format (e.g., CSV). | Submit a formal request |
Object to Processing | Opt out of non-essential processing (e.g., marketing). | Unsubscribe links, account settings |
CCPA Right to Know/Sell | Opt out of data sales (if applicable). | "Do Not Sell My Info" link |
Response Timeline: We aim to respond within 30 days of your request.
VII. Data Retention and Security
1. Retention Period
- Active Accounts: Data retained for as long as your account is active.
- Inactive Accounts: Deleted after 6 months of inactivity.
- Legal Requirements: Retained longer if required by law (e.g., tax records for 7 years).
2. Security Measures
- Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest.
- Access Controls: Role-based permissions and multi-factor authentication (MFA).
- Audits: Quarterly third-party security assessments.
VIII. Cookies and Tracking Technologies
- Cookies:
- Essential: Session management (e.g., login persistence).
- Analytics: Track usage patterns (opt-out via browser settings).
- Advertising: Interest-based targeting (opt-out via AdChoices).
- Pixel Tags: Monitor email campaign engagement (user-controlled via unsubscribe links).
IX. Children's Privacy
- Age Restriction: Services are not directed at users under 18 years old.
- Parental Consent: Required for minors to create accounts.
X. Updates to This Privacy Policy
- Changes will be communicated via email or in-app notifications.
- Review this policy periodically for updates.
XI. Contact Us
For inquiries or rights requests: zouqi0202@gmail.com