Update Date: 2024-07-17
Effective Date: 2024-07-24
Shanghai SUNMI Technology Co., Ltd. and its affiliates (registered office: Room 505, No. 388, Songhu Road, Yangpu District, Shanghai, Tel.: 400-6666-509, “SUNMI” or “We”) are the providers of registration and use services for SUNMI account. We attach great importance to the protection of personal information and privacy of our users (“You”). When you log in and use your SUNMI account and its relevant products or services (“SUNMI Account Services”), we will collect, use, store, and share your personal information. In order to make you informed of our processing of your personal information, we have prepared the SUNMI Account Privacy Policy (“Privacy Policy”) and promise to process your personal information in strict accordance herewith.
This Policy applies to the SUNMI account and its related products or services that we provide to you through the website and the new forms that appear with the development of technology. If the SUNMI account and its related products or services provided by us are used in our and our affiliates’ products or services, such products or services also apply to this Policy. This Policy does not apply to other services provided by other third parties, except the related information collection and use activities as described herein.
Before you begin to use our products and services, please be sure to read and understand this Policy carefully. In particular, you shall focus on the terms marked in bold/underlined by us to ensure that you have fully understood and agreed to such terms before using our products and services. When you click “Agree”, it shall be deemed that you have agreed with this Policy. If you do not agree with the terms of this Policy or have doubts about any content, please immediately stop using your SUNMI account and refrain from providing any personal information without contacting us.
This Privacy Policy will tell you:
I. Personal information We May Process & How We Use Your information
II. How We Retain Your Personal Information
III. How We Entrust Others for Processing, Share, Transfer and Publicly Disclose Your Personal Information
IV. How We Protect Your Personal Information
V. How to Manage Your Personal Information
VI. How We Process the Personal Information of Minors
VII. How this Policy is Updated
VIII. How to Contact Us
I. Personal information We May Process & How We Use Your information
When you use our products/services, we need/may need to collect and use your personal information as follows:
1. The necessary information that you shall authorize us to collect and use to provide the basic functions of our products and/or services. If you refuse to provide the relevant information, you will not be able to use our products and/or services normally;
2. The information that you may choose to individually agree or disagree to be collected and used by us in order to provide the extended functions of our products and/or services. If you refuse to provide such information, you will not be able to normally use the relevant extended functions or achieve the functional effect we plan to achieve, and your use of the basic functions of our products and/or services will not be affected.
We will explain in detail the type and purpose of processing your personal information. In addition, for users resident in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, it also identifies the legal basis under which we process your data.
(I) Basic Functions
1. Register or login
If you choose to register or log in to your account by email or mobile phone number, we need to collect your login email or mobile phone number and password to help you complete the registration or account login. We collect the above information to provide you with account registration and login services. If you refuse to provide the above information, you will not be able to complete the account login or registration, which will lead to your inability to use the SUNMI Account Services.
For users in the EEA, the United Kingdom, or Switzerland, you may register or log in to your account with an E-mail only, and the legal basis for us to process your personal information is necessary to perform our contract with you to provide you with the SUNMI Account Services.
2. Real-name authentication
In view of the particularity of SUNMI Services, according to the Cybersecurity Law, the Law on Combating Telecom and Online Fraud, the Interim Provisions on the Administration of the Pre-Installation and Distribution of Application Software for Smart Mobile Terminals, if you want to use the products or services of SUNMI MALL, and other laws and relations, if you need to use the products or services of SUNMI Mall, SUNMI Partners Platform and SUNMI Developer Center, you shall first complete the real-name authentication. Otherwise, you will not be able to use the aforesaid products or services.
If you are an individual, when you carry out real-name authentication, we need to collect the information on the country/region where you are domiciled, your ID card photos, mobile phone number, SMS verification code, team name/brand name, business region and business address to assist you to complete the real name authentication. We collect your above information to identify and verify your identity as a partner, and help you manage the SUNMI device, application software and App Store through the Partners Platform. If you refuse to provide such information, we will not be able to provide the SUNMI Partners Platform services to you.
If you are an enterprise, when you carry out real-name authentication, we need to collect the information on the country where you are domiciled, your business license, the company's alias and abbreviation, business address and business region to assist you to complete the real name authentication. We collect your above information to identify and verify your identity as a partner, and help you manage the SUNMI device, application software and App Store through the Partners Platform. If you refuse to provide such information, we will not be able to provide the SUNMI Partners Platform services to you.
For users in the EEA, the United Kingdom, or Switzerland, you can only carry out real-name authentication in the name of the enterprise. The legal basis for us to process your personal information is necessary to fulfill the contract we have entered into with you to provide you with SUNMI Account Services.
3. Complete account information
You can choose to complete your user information, fill in or modify your user nickname and country/region on your initiative, and you can also choose to connect with your email account or mobile phone number and upload an avatar for your account. We collect the above information to help you complete your account information. If you refuse to provide such information, it will not affect your use of any other services.
For users in the EEA, the United Kingdom, or Switzerland, you cannot connect with a mobile phone number to your account or upload a profile picture for your account. The legal basis for us to process your personal information is necessary to perform our contract with you to provide you with the SUNMI Account Services.
4. Ensure the network security
To fulfill the obligations related to network security, ensure the security of your account and the security of services we provide for you, and improve the quality of products and services, we will use system tools to automatically collect your device name and model, unique device identifier, IP address, access date and time, service log information, the software version of your SUNMI account, and operation logs. We collect the above information to maintain and ensure the security of the network and services. If you refuse to provide such information, it may affect the security of your use of the network and services.
For users in the EEA, the United Kingdom, or Switzerland, the legal basis for us to process your personal information is to ensure the security of our services, which is in line with our legitimate rights and interests and is necessary to perform our contract with you to provide you with the SUNMI Account Services.
(II) Add-on Business Functions
1. Use of cookies and similar technical services
(1) In order to ensure the proper operation of the website, your better visit experience, we may store small data files called cookies on your computer. Cookies usually consist of identifiers, site names, numbers, and characters. Cookies allow us to collect your preferences and related data.
(2) We will not use the cookies for any purpose other than those described herein. You may enable or disable the cookies by following the relevant instructions in your browser settings, provided that your browser or browser add-on service allows it. For more details, please visit https://www.aboutcookies.org/. However, if the cookies are disabled, some functions of our website may not work properly.
(III) How We Use Your Personal Information
1. We will only collect and use your personal information in accordance with the purpose and scope specified herein. When we use your personal information for other purposes not specified herein, we will seek your consent in advance or have other legal reasons.
2. The sensitive personal information collected by us has been displayed in this Privacy Policy through prominent flags. Once your sensitive personal information is leaked, altered or illegally used, it will damage your personal or property safety. In order to prevent your sensitive personal information from being leaked or illegally used, we have taken appropriate technical and organizational protection measures to ensure the security of your information.
3. If the information you provide contains the personal information of other users, you need to ensure that you have been legally authorized before providing such personal information to us. If the personal information of a child is involved, you shall obtain the consent from guardian of the corresponding child before posting it. Under the above circumstances, the guardian has the right to contact us through the channels specified herein to request correcting or deleting the content involving the child's personal information.
4. Please note that the personal information you provide when using our services will continue to be authorized to be used by us during your use of our services unless you delete it or refuse us to collect it through system Settings.
5. We will collect statistics on the use of our services and may provide such statistics to the public or third parties for product development, service optimization, and security assurance. However, such statistics do not contain any identifying information about you.
6. We will desensitize your personal information before display according to the actual business functions, including masking, shielding, and other de-identification technologies, to protect your information security.
(IV) Other Circumstances in Which Personal Information is Collected or Used
In accordance with relevant laws and regulations, we may collect and use your personal information without your prior consent under the following circumstances:
(1) Necessary for the conclusion and performance of the contract to which you are a party;
(2) Necessary for fulfilling legal obligations;
(3) Necessary for dealing with public health emergencies or protecting the life, health, and property safety of natural persons in emergencies;
(4) Collecting personal information within a reasonable range through news report and public opinion supervision for public interests;
(5) Collecting the personal information that has been disclosed by yourself or other personal information that has been legally disclosed within a reasonable scope in accordance with the provisions of this Policy;
(6) Other circumstances as provided for by laws and administrative regulations.
II. How We Retain Your Personal Information
(I) Storage Location
Currently, SUNMI has data centers in China, Germany, and the United States. For the purposes described in this privacy policy, your personal information may be transferred to these data centers in accordance with applicable laws:
1. Personal information collected and generated during our operations in the People’s Republic of China (PRC) will be stored in China. Under the following circumstances, we will provide your personal information to overseas entities after fulfilling our legal obligations:
(1) Stipulated in the governing law;
(2) Obtaining your express authorization; or
(3) Your cross-border transactions and other personal initiatives through the Internet.
2. For users registered through the European Union site operated by SUNMI (domain: *.eu.sunmi.com), your personal information will be stored on Amazon servers located in Germany.
3. For users registered through the North American site operated by SUNMI (domain: *.us.sunmi.com), your personal information will be stored on Amazon servers located in the United States.
4. For users outside of China who do not register through the EU or North American sites, your personal information will be stored in China.
(II) Retention period
1. We only keep your personal information for the shortest period as provided for by laws and regulations, and for the shortest period necessary to achieve the purpose stated herein. We will delete or anonymize the personal information that has exceeded the storage period. Please see the following table for the details of the storage period of your relevant personal information:
Number |
Data type |
Retention period |
1 |
Registration and login data, and account information data |
Your registration and login data will not be deleted or anonymized until your account is canceled |
2 |
Real-name authentication |
Your registration and login data will not be deleted or anonymized until your account is canceled |
3 |
Network operation security data |
Your network operation security data will be retained as provided for by the law (for example, it shall be retained for 6 months in China). |
2. If we terminate the services or operation, we will notify you at least 30 days in advance, and delete or anonymize your personal information upon termination of the services or operation.
(III) How Personal Information is Transferred Around the World
There are SUNMI’s clients all over the world, which means that SUNMI may process personal information in your countries or regions, or be aceessed from these countries/regions. Data protection laws may vary in these countries/regions. In such cases, SUNMI will take steps to ensure that the data we collect is processed in accordance with the requirements of this statement and applicable laws.
III. How We Entrust Others for Processing, Share, Transfer and Publicly Disclose Your Personal Information
(I) Entrust Others for Processing
We may entrust authorized affiliates or partners to process your personal information in order to provide you with corresponding products or services. However, provided that, we will only entrust authorized partners to process your personal information for legal, legitimate, necessary, specific, and explicit purposes, and will only provide personal information necessary for using our products or services. Our partners will not use your personal information for purposes not entrusted by us before your consent.
If we entrust our partners to process your personal information, we will sign a Data Protection Agreement with them, requiring them to process your personal information in accordance with the Agreement, this Privacy Policy, and relevant laws and regulations.
(II) Sharing
We will only provide your personal information in the following circumstances:
1. Upon your consent or your request
Sharing with Business partners: We may share the relevant information with business partners, such as developers, to run our business smoothly and serve you better. We will only share your personal information for legal, legitimate, necessary, specific, and explicit purposes, and will only share personal information necessary for providing our products or services:
(1) After the third-party application provides your explicit authorization, we will share the following personal information with it according to your instructions for the following business purposes:
l Sharing your openid for assisting you to use a third-party application through SUNMI account;
l Sharing your mobile phone number to provide convenience for you to quickly log in and register a third-party account;
Our business partners do not have any right to use your relevant personal information for any other purpose; If they want to change the purpose of personal information processing, they shall obtain your authorization separately.
In addition to the above circumstances, if you agree or request us to provide your personal information to a third party, we will inform you of the name and contact information of the party who receives your personal information in an appropriate manner on the corresponding page for the purpose agreed by you. If you use the information-sharing service, we will provide the name of the third-party sharing platform on the page. Please refer to the privacy policy of the third party for specific contact information.
2. Necessary for fulfilling legal obligations
We may provide your information to the public as required by law to process dispute resolution, to respond to requests made by state organs under the law, and for other purposes necessary to fulfill our legal obligations. Unless otherwise provided by law, if we provide your personal information to a third party to fulfill our legal obligations, we will inform you of the name and contact information of the party who receives your personal information on the corresponding page or by other feasible means.
3. Necessary for dealing with public health emergencies or protecting your life, health, and property safety in emergencies;
Where we provide your personal information to a third party to deal with public health emergencies or to protect your life, health and property safety in an emergency, we will inform you of the relevant information at an appropriate time (such as after the emergency is eliminated).
For the personal information we share, please refer to the Personal Information Share List:
Type of the Receiving Party |
Type of Personal Information |
Purposes of Share |
Mode of Share |
Third-party application developer |
Open_id |
Using a third-party application through a SUNMI account; |
API transmission |
Mobile phone number |
Quickly signing up and logging in to third-party software |
API transmission |
(III) Transfer
We will not transfer your personal information to any company, organization or individual, provided that, in the case of merger, acquisition or bankruptcy liquidation, if personal information is transferred, we will inform you about the situation (including the name and contact information of the receiving party) and require the new company or organization holding your personal information to continue to be bound by this Policy, otherwise we will require the company or organization to obtain your authorization again.
(IV) Public Disclosure
In principle, we will not publicly disclose your personal information. If it is indeed necessary to publicly disclose your personal information, we will obtain your separate consent or meet other conditions as provided for by laws.
(V) How Third-Party Service Providers Obtain Your Personal Information
SUNMI account also has access to also third-party services. Please note that a third-party service provider’s processing of your personal information will be governed by the privacy policy of the third-party service. Please click on the List of Third-party Services That SUNMI Account Has Access To for details of the authorized partners to which we have access.
If you are a user in China, the third-party services we access are as follows:
Number |
Third-Party Services |
Purpose |
Providers |
Collected Information |
Privacy Policies/Official Websites of the Providers |
1 |
Qichacha |
Realizing real-name authentication of enterprises |
Qichacha Tec Co., Ltd. |
Country where the company is located, business license, company alias abbreviation, business address and business area |
https://www.qcc.com/web/cms/cm_15 |
2 |
Tianyancha |
Realizing real-name authentication of enterprises |
Beijing Jindi Technology Co., Ltd. |
Country where the company is located, business license, company alias abbreviation, business address and business area |
https://www.tianyancha.com/property/3 |
3 |
Yunmatong |
Realizing real-name authentication of individuals |
Yunmatong Data Operation Co., Ltd. |
Name, ID card number, and mobile phone number |
http://www.ymtdata.com/#/Service |
4 |
Alibaba Cloud DirectMail |
Sending you emails according to your needs, such as verification code. |
Alibaba Cloud Computing Co., Ltd. |
E-mail and E-mail verification code |
https://help.aliyun.com/document_detail/29420.html |
5 |
SUBMAIL |
SMS verification |
Shanghai SUBMAIL Technology Co., Ltd. |
Mobile phone number and SMS verification code |
https://www.mysubmail.com/documents/ibW2A2 |
6 |
Monternet |
SMS verification |
China Mobile Communications Group Co., Ltd. |
Mobile phone number and SMS verification code |
http://gx.10086.cn/educloud/html/yinsi/web/index.html |
7 |
Baidu Statistics |
Buried point statistics |
Baidu Online Network Technology (Beijing) Co., Ltd. |
Number of views, clicks, web pages visited, access time, number of visitors, number of IP addresses, geographical distribution, browser, network device type, screen resolution, screen color, flash version, language environment, and network provider |
https://tongji.baidu.com/web/help/article?id=330&type=0/ |
8 |
Alibaba Cloud |
Behavior verification |
Alibaba Cloud Computing Co., Ltd. |
IP, Cookie |
https://help.aliyun.com/document_detail/121893.html |
If you are a user outside China, the third-party services we access are as follows:
Number |
Third-Party Services |
Purpose |
Providers |
Collected Information |
Privacy Policies/Official Websites of the Providers |
|
1 |
AWS |
Sending E-mails |
Amazon Web Services, Inc. |
E-mail and E-mail verification code |
https://aws.amazon.com/privacy/?nc1=h_ls |
IV. How We Protect Your Personal Information
(I) Data Security Management and Technical Measures
We have taken security measures that meet industry standards to protect your personal information and prevent unauthorized access, public disclosure, use, modification, damage, or loss of your data. We will continue to make every effort to take all reasonably practicable measures to protect your personal information. For example, the data exchange between your browser and the server is protected by the Secure Socket Layer (SSL) protocol encryption; We use encryption to improve the security of your personal information; We use trusted protection mechanisms to prevent malicious attacks on your personal information; We deploy access control mechanisms to ensure that only authorized personnel have access to your personal information; And we organize security and privacy training courses to enhance employees’ awareness of the importance of protecting your personal information. At present, our important information system has been filed and evaluated in network security level protection.
(II) Responding to Data Security Incidents
After an unfortunate occurrence of any personal information security incident, we will inform you, in accordance with the requirements of laws and regulations, of the basic situation of the security incident and the possible impacts, the disposal measures we have taken or will take, the advice on your own risk prevention and mitigation, the remedial measures for you, etc. We will inform you about the incident by email, letter, telephone, push notification, and other means. If it is difficult to inform you one by one, we will make announcements in a reasonable and effective way. In addition, we will also actively report the disposal of the personal information security incident in accordance with the requirements of the regulatory authorities.
V. How to Manage Your Personal Information
You have the right to know and decide your personal information. During your use of our services, you may contact us by means of the prompts on the corresponding page or as set forth herein to inquire, copy, transfer, refuse, or limit the processing of, correct, supplement or delete your personal information, and exercise the right to change the scope of your consent. In addition, we have set up complaint-reporting channels, and your opinions will be dealt with in time.
1. Right of access
You may access your personal information in the following ways:
(1) Your user login information: You may access your user login information (nickname, country and region, E-mail address, and password) by clicking on the avatar in the upper right corner and then clicking on the “Personal Center”.
(2) If your personal information cannot be accessed in the aforesaid ways, you may contact us through the contact information stated herein.
2. Right to data portability
If you want to transfer your personal information to other personal information processors designated by you, and your request meets the conditions stipulated by applicable legal, we will assist you in the transfer. You may contact us in the way stated herein to exercise the above rights.
3. Right to object to automated decision making
We do not involve the use of automated decision-making in the products and services we provide to you.
4. Change the scope of your consent
(1) You may withdraw your authorization by: deleting some personal information in your SUNMI account; Or contacting us in the way stated herein.
(2) Please understand that the business functions of the SUNMI account may be materialized only after partial permissions are enabled and necessary personal information is collected. When you withdraw your consent, we will no longer be able to provide you with the services corresponding to the consent withdrawn, provided that it will not affect the personal information processing services previously carried out based on your authorization.
(3) If you do not want to accept commercial advertisements sent by us, you may unsubscribe by the means indicated in the commercial advertisements, or by contacting us directly by the means stated herein.
5. Right to rectification
When you find that there is a mistake in your personal information processed by us, you have the right to request us to rectify your personal information. You may rectify your personal information in the following ways:
(1) Your user login information: You may rectify your user login information (nickname, country and region, E-mail address, and password) by clicking on the avatar in the upper right corner and then clicking on the “Personal Center”;
(2) If your personal information cannot be rectified in the aforesaid ways, you may contact us through the contact information stated herein.
6. Right to erasure
You may request us to delete your personal information if:
(1) The processing purpose stated herein has been achieved, cannot be achieved, or is no longer necessary to be achieved;
(2) You withdraw your consent on which processing your personal information is based;
(3) The storage term of personal information has expired;
(4) We collect, use, store, share, or publicly disclose your personal information in violation of laws and administrative regulations or the agreement with you;
(5) You are no longer using our products or services;
(6) We stop providing products or services;
(7) Other circumstances as stipulated by laws and regulations.
We will, upon receipt of your deletion request and verification of your identity, handle the request and give a reply as soon as possible. If we decide to respond to your request for deletion, we will also notify the entities that have obtained your personal information from us and ask them to delete such information in time, unless otherwise stipulated by laws and regulations or these entities have obtained your independent authorization.
When you delete information from our services, we may not immediately delete the corresponding information from the backup system, provided that we will delete the information when updating the backup. We will not deal with the personal information whose storage term prescribed by laws and administrative regulations has not expired, or that is difficult to delete technically, except by storing and taking necessary security protection measures.
7. Canceling Account
1. You may cancel your account in the following ways:
(1) You may click on the avatar in the upper right corner, and then the “Personal Center”, select “Cancel Account” and fill in the reasons for cancellation and your contact information.
(2) You may contact our customer service representatives for cancellation through the contact information stated herein.
2. Upon the cancellation of your account, we will stop providing products or services for you. All contents, information, data and records of our products and services that you used through this account will be deleted or anonymized.
8. Other rights to personal information
Under the condition of complying with relevant laws and regulations, your next of kin may exercise the above-mentioned right of access, right to rectification, right to erasure, and other rights to your relevant personal information, unless otherwise arranged by you.
9. Explanation of this Policy
In case of any doubts about the contents of this Policy, you have the right to request us to explain the relevant contents of this Policy at any time through the contact information disclosed herein.
10. Response to your above request
1. For security purposes, you may be required to provide a written request or otherwise prove your identity. We may ask you to verify your identity before processing your request. We will respond to your request within 15 days or within the time limit as provided for by laws.
2. In principle, no fee will be charged for reasonable requests. However, for requests that are repeated for several times and exceed reasonable limits, we will charge a fee as appropriate. We may reject requests that are repeated for no reason, require excessive technology (for example, new systems are required to be developed or existing practices are required to be fundamentally changed), put the legal rights of others at risk, or are highly impractical (for example, information stored in the backup tapes is involved).
11. Response exceptions
We will not be able to respond to your request if:
(1) It is related to the fulfillment of our obligations under the laws and regulations;
(2) It is directly related to national security and national defense security;
(3) It is directly related to public safety, public health, and major public interests;
(4) It is directly related to criminal investigation, prosecution, trial and sentence enforcement;
(5) We have sufficient evidence of subjective malice or abuse of rights by you;
(6) It is related to protection of your or other individuals’ lives, properties, and other significant legitimate rights and interests, but it is difficult to obtain your or such person’s consent.
(7) A response to your request will result in serious damage to your, or other individuals’ or organizations’ legitimate rights and interests;
(8) It involves trade secrets;
(9) Other circumstances as stipulated by laws and regulations.
If we decide not to respond to your request, we will inform you of the reasons for the decision; If you have any objection to the reasons, you may contact us through the contact information disclosed herein.
12. Application of special jurisdictions
Please note that if you are a user in the EEA, the United Kingdom, or Switzerland, in addition to the rights listed above, you also have the right to object. If we use your information for our legitimate interests or use your personal information in marketing scenarios, you may object to our use of your personal information.
VI. How We Process the Personal Information of Minors
1. The products provided by the SUNMI account for you are of commercial nature, and in principle we do not provide services to minors.
2. In the case of any personal information collected from minors with the consent of their parents or legal guardians, we will use or publicly disclose this information only as permitted by law, with the express consent of the parents or guardians, or as necessary to protect the minors.
3. If any facts prove that we have collected personal information from minors without prior consent of verifiable parents or legal guardians, you may contact us via the contact information set forth herein and we will attempt to delete the relevant information as soon as we are aware of it.
VII. How the Privacy Policy is Updated
1. In case of any change in our products or services, our Privacy Policy will be adjusted accordingly. We will not reduce your rights under this Policy without your express consent. We will post any changes hereto on this page. We will also provide more prominent notices of material changes (including, for some services, we will send notices by E-mail to explain the specific changes in the Privacy Policy).
2. Material changes referred to herein include but are not limited to:
(1) Our service model has undergone material changes, such as the purpose for processing personal information, the types of personal information processed, and the ways of using personal information.
(2) We have undergone material changes in ownership structure and organizational structure, such as owner change caused by business adjustment, bankruptcy, merger, and acquisition.
(3) The main object of personal information sharing, transfer or public disclosure has changed;
(4) Your right to participate in personal information processing and the way in which it is exercised have changed significantly;
(5) Our department responsible for processing personal information security, contact information and complaint channels have changed;
(6) Personal information security impact assessment report indicates that there is a high risk.
3. We will also keep an older version of this Policy on file for your review.
VIII. How to Contact Us
If you have any questions about this Privacy Policy or the protection of personal information, please contact us through:
Customer Service Hotline: 400-6666-509
Contact information of the person in charge of personal information protection: privacy@sunmi.com
In general, we will reply to you within 15 days or within the time limit as provided for by laws. If you are not satisfied with our reply, especially if you think our personal information processing behaviors have harmed your legitimate rights and interests, you can also make a complaint or report to the regulatory departments of cyberspace information, industrial information, public security, and industry and commerce, or seek a solution by bringing a lawsuit to the court with jurisdiction in the defendant’s domicile.
Please note that if you are a user in the EEA, the United Kingdom, or Switzerland, you have the right to complain with the data protection agency in your country.