Skip to content
SSPARKDATA

LEGAL · PERSONAL INFORMATION

SparkData Privacy Policy

This Policy explains how Hangzhou Zhiyuan Xinghuo Technology Co., Ltd. processes personal information when providing SparkData sign-up, sign-in, console, and API services.

1. Information we collect

  • Sign-in identities: email address, phone number, identifiers returned by WeChat Open Platform, and basic profile information you authorize. Verification codes are used only for the current verification.
  • Account and tenant data: user identifier, tenant membership and role, API-key name and prefix, status, permissions, rate limits, and creation or revocation records. The server stores only API-key hashes; a complete key is displayed once at creation.
  • Security and operations data: sign-in and request time, IP address, basic device or browser information, request identifier, API path, response status, and security audit events. Complete API keys are not recorded in ordinary logs.
  • Support data: messages, contact details, and materials you voluntarily provide when requesting help.

2. Why we use it

  • Create and maintain accounts and complete email, phone, or WeChat sign-in.
  • Provide tenants, API keys, quotas, permissions, and market-data services.
  • Prevent fraud, credential exposure, attacks, and abuse; diagnose faults and maintain stability.
  • Answer support, deletion, and rights requests and meet legal, regulatory, and audit obligations.

3. Processors, sharing, and third parties

We may use WeChat Open Platform, SMS providers, and email-delivery providers for your chosen sign-in method, and cloud, database, cache, logging, and security providers to operate the service. We provide only information necessary for the function and constrain processing through contracts, access controls, and security measures.

We do not sell personal information or disclose it to unrelated third parties unless you separately consent, law requires it, vital lawful interests must be protected, or a legally permitted corporate transaction occurs. If cross-border processing occurs, we will complete legally required notice, consent, or other compliance procedures.

4. Cookies, sessions, and security

After sign-in, a secure cookie maintains your session with attributes such as HttpOnly, Secure, and SameSite. The server stores only a hash of the session token. Sessions last up to 30 days by default and may end earlier when you sign out, delete the account, or we revoke them for security.

We use access control, encryption in transit, credential hashing, least privilege, and auditing. No internet service is absolutely secure; contact us immediately if you detect suspicious activity.

5. Retention

Verification challenges normally expire after five minutes. Account data is kept while needed to provide service and process deletion. Security, transaction, and audit records are retained according to risk-control, contractual, and legal requirements, then deleted, anonymized, or isolated as required by law.

6. Your rights

Through the console or by contacting us, you may request access, correction, supplementation, copying, or deletion of personal information; withdraw consent where withdrawal is available; unlink sign-in identities; delete the account; or request an explanation of processing rules. We verify identity before acting unless law provides otherwise.

7. Children

SparkData is intended for developers and organizations with the necessary legal capacity. Children under 14 should not register independently. If we learn that relevant information was collected without guardian consent, we will address it promptly as required by law.

8. Updates and contact

We may update this Policy when features, providers, or laws change. Material changes will be highlighted. Contact us using the details at the bottom of this page with questions about this Policy or personal-information processing.