PP Love Privacy Policy
Effective Date: February 27, 2026
I. Privacy Protection Statement
As an application focused on the social communication field, PP Love always places the privacy and security of users' personal information at the core. We deeply understand that your trust in us is the fundamental premise for the sustainable development of the platform.
To this end, we have specially built a comprehensive and rigorous information security management system that is fully adapted to the characteristics of real-time communication services. This system can fully ensure the confidentiality, integrity and availability of your personal information, allowing you to enjoy a smooth, safe and reliable communication experience in the digital environment created by PP Love.
II. Scope of Collection and Purpose of Use of Personal Information
To ensure the stable operation of PP Love's core communication services and provide you with a personalized and high-quality user experience, we will collect and use your personal information in strict accordance with the principles of "legality, necessity and minimum scope". The specific scope of collection and purpose of use are as follows:
(I) Core Communication-Related Information
Such information is the basis for us to provide you with core services such as real-time calls, voice chats, and video communications, and will be collected when you register an account and use core functions:
• Communication Behavior Information: When you use call, voice or video communication functions, the system will automatically record necessary communication logs, including call time, call duration, communication object and call quality data.
• This information is only used to optimize communication quality and troubleshoot call failures (such as stuttering, disconnection, etc.) to ensure the smooth progress of communication services. Without your explicit consent, we will never use it for any other purposes unrelated to communication services.
(II) Device and Environment Information
To ensure the compatibility of the application with your device and guarantee the security of your account and communication process, during your use of PP Love services, the system will automatically collect and record relevant device and environment information. Such information alone cannot directly identify your personal identity, and specifically includes:
• Basic Device Parameters: Device model, brand, operating system type and version, hardware configuration (such as processor, memory, camera, microphone parameters), unique device identifiers (such as International Mobile Equipment Identity (IMEI), Android Advertising ID) and device status (such as battery level, network connection status).
• These parameters help us adapt to different device configurations, solve compatibility issues (such as interface adaptation, function activation failure, etc.), and improve the stability of application operation.
• Network Environment Information: IP address, Internet Service Provider (ISP) information, mobile operator information, network connection type (such as Wi-Fi, 4G, 5G, etc.) and network signal strength.
• Collecting such information is mainly to locate network faults (such as regional network access restrictions, poor signal leading to reduced call quality, etc.), optimize network resource allocation, and ensure the fluency of real-time communication.
(III) Service Optimization and Analysis Data
To continuously improve the quality of PP Love's services and push you personalized function recommendations that are more in line with your needs, we will collect and analyze your service usage logs and relevant diagnostic data. The specific content and purpose of use are as follows:
• Usage Behavior Logs: Record your interaction behavior with the application, including functions used (such as one-on-one calls, voice messages, video messages, etc.), usage frequency of each function, single usage duration, pages browsed and operation paths.
• Such data will be used to analyze user usage habits, optimize the layout of application functions, adjust function modules with poor usability, and thereby improve the overall user experience.
• Diagnostic Data: When the application has abnormal phenomena such as crashes, stutters or function failures, the system will automatically collect diagnostic data, including crash reports, error logs, hardware setting information and application running status data.
• Such data is only used to quickly locate and solve technical problems and improve application stability, and does not involve any of your private communication content.
• Personalized Analysis (Requiring Explicit Consent): With your prior explicit consent, we may use your device identifier and advertising identifier for data analysis.
• Specific application scenarios include evaluating the effect of marketing activities (to avoid ineffective promotion), optimizing service operation efficiency, and pushing personalized function recommendations or promotional information that may be of interest to you. You can withdraw this consent at any time through the application settings.
(IV) Necessary Permission Applications and Detailed Instructions
In the process of providing communication services, PP Love needs to apply for some necessary permissions from your device to ensure the complete realization of core functions and the best user experience. All permission applications follow the principle of "necessity and minimum scope" and are only activated with your explicit consent.
You can independently manage, enable or disable all the following permissions in the device settings at any time. The specific permissions and application scenario instructions are as follows:
• Camera Access Permission: This permission is required when you use video calls, record video messages or take avatars. We only activate the camera when you actively trigger the corresponding functions, and will never collect images or videos through the camera without permission.
• If you refuse this permission, you will not be able to use video-related functions, but basic functions such as voice calls will not be affected.
• Microphone Access Permission: This permission is a necessary condition for using functions such as voice calls and recording voice messages. We only collect audio data through the microphone when you actively use communication functions that require audio input, and will not perform background audio collection.
• Refusing this permission will affect the use of voice-related core functions, but text interaction functions (if any) can be used normally.
• Album Access Permission: When you need to upload photos from the album to set an avatar, share photos in the chat interface or attach photos to message content, we will apply for this permission.
• This permission only allows us to read the photos you actively select, and will not automatically access, read or upload all photos in the album. Refusing this permission only affects the function of uploading photos from the album, and does not affect other core communication functions.
• Bluetooth Access Permission: When you need to connect external audio devices (such as Bluetooth headsets, Bluetooth speakers) to use PP Love's audio communication services, we will apply for this permission to achieve fast pairing and stable connection between the device and external audio devices, and improve the audio quality and communication experience during your use.
• If you refuse this permission, you can still use the device's built-in audio devices for communication.
• External Storage Access Permission: This permission is divided into read and write permissions, which will be applied for on demand according to different service scenarios:
○ Read Permission: Used to retrieve files stored in the external storage of your device, such as uploading photos, videos or documents from external storage to the PP Love application to complete sharing or avatar setting operations.
○ Write Permission: Used to save content generated or obtained in the PP Love application (such as downloaded chat files, recorded voice/video messages, exported call records, etc.) to the external storage of the device, facilitating your subsequent offline viewing and management.
• Push Notification Permission: When you need to receive timely friend message notifications, call invitation reminders, in-app activity announcements and other information, we will apply for this permission.
• We only push important information related to the service to you, and you can enable, disable or customize push content (such as message type, reminder method, etc.) through "Settings - Notifications" or device system settings at any time. If you refuse this permission, you will not be able to receive relevant notifications in a timely manner, but the use of core communication functions will not be affected.
• Advertising Identifier Access Permission: To improve the accuracy and effectiveness of marketing activities and reduce the interference of irrelevant advertisements on you, we may collect your device's advertising identifier.
• This identifier is used to analyze the effect of marketing activities, optimize the direction of advertising delivery, and avoid repeated delivery of the same advertising content. You can turn off the collection of advertising identifiers through device settings or application privacy settings.
It should be emphasized that PP Love will never use the obtained permissions for any purposes unrelated to the service, nor will it force you to authorize non-necessary permissions. If you refuse to authorize non-core permissions, it may affect the use of corresponding auxiliary functions, but will not affect the normal operation of basic communication services.
III. Protection of Minors' Personal Information
PP Love services are directed at users over 18 years of age. We attach great importance to the protection of minors' personal information, strictly abide by the relevant laws and regulations on the protection of minors' information in various countries and regions, and formulate a special mechanism for the protection of minors' information to ensure that the legitimate rights and interests of minors are not infringed.
(I) Core Protection Principles
We adhere to the principle of "not actively collecting" personal information of minors under the age of 18. To prevent minors from using the service without authorization, for users suspected of being minors, we will further conduct real-name information verification (which may require the consent of a guardian) to restrict minors' access to the platform.
If personal information of minors is inadvertently collected under special circumstances, we will immediately stop the collection behavior and completely delete the relevant information within the shortest possible time (no more than 7 working days) after verification.
(II) Restrictions on Minors' Use
Minors under the age of 18 are not allowed to use PP Love services independently. We remind minors that when using the Internet and related communication tools, they should do so under the guidance and supervision of their parents or legal guardians, correctly recognize the risks of network communication, and not arbitrarily disclose personal information (such as name, school, home address, contact information, etc.) to strangers to avoid information leakage and potential safety hazards.
(III) Guardian's Responsibilities
If you are the parent or legal guardian of a minor and find that your child has registered a PP Love account or provided us with personal information without your consent, please contact us immediately through the official channels specified in this policy.
After you provide the necessary certification materials (such as guardian's identity certificate, minor's identity certificate, guardianship relationship certificate) and we verify the relevant information, we will immediately take measures to delete the minor's account and all stored personal information, and use technical means to prevent the minor from using the relevant information to register and use the service again.
(IV) Application for Deletion of Minors' Data
If you have reason to believe that PP Love has collected personal information of minors, please contact us as soon as possible through the official service email and explain the specific situation. After receiving your valid application and verifying the relevant information, we will immediately conduct a review and handling, complete the deletion of the relevant data within 15 working days, and feedback the handling result through the contact information you provided.
IV. Sharing, Transfer and Disclosure of Personal Information
PP Love attaches great importance to the security of your personal information and will never share, transfer or disclose your personal information to third parties without authorization. Except as required by laws and regulations or with your explicit consent, we will strictly limit the scope of personal information sharing and take adequate security protection measures.
(I) Data Sharing
• Based on Explicit Consent: Before sharing your personal information with any third party (except authorized partners providing auxiliary services), we will clearly inform you of the third party's name, the scope and type of shared information, the purpose and duration of use and other key information, and will only carry out the sharing behavior after obtaining your clear and explicit consent. You have the right to refuse such sharing requests.
• Fulfillment of Legal Obligations: When facing mandatory legal requirements such as legal investigations, court subpoenas, and administrative orders, we may disclose your personal information within the scope specified by law.
• In such cases, we will strictly follow the principle of minimum necessity, only disclose the information absolutely necessary to fulfill legal obligations, and actively verify the legality and validity of relevant legal documents; at the same time, unless prohibited by laws and regulations, we will try our best to notify you of the relevant situation in advance.
• Cooperation with Authorized Partners: To better provide you with stable and high-quality communication services, we may entrust some authorized third-party partners to complete specific auxiliary service links. These partners include but are not limited to technical infrastructure service providers, communication quality optimization service providers, payment processing service providers (if there are paid functions), customer service outsourcing agencies, etc.
• When sharing information with these partners, we will strictly review their qualifications, sign formal data processing agreements, clarify the rights, obligations and liability for breach of both parties, and only provide them with the minimum scope of information necessary to perform their duties; at the same time, we will regularly supervise and inspect their information processing activities (including on-site inspections, data security audits, etc.) to ensure that they will not use the shared information for any purposes other than those agreed in the agreement.
(II) Specific Scenarios of Third-Party Cooperation and Information Protection
In the daily operation of PP Love, the scenarios of cooperation with third parties and the corresponding information sharing rules are as follows:
• Technical Infrastructure Cooperation: We may cooperate with cloud service providers to store non-sensitive operation data (such as application running logs, device parameters that cannot identify identity). The shared data will be desensitized in advance, and cloud service providers will be required to take the same level of security protection measures as us.
• Marketing and Effect Evaluation: We may share anonymized user behavior data that cannot identify identity with professional marketing analysis institutions (such as Appsflyer) to carry out marketing attribution analysis and optimize the effect of promotion activities. Such data does not involve any information that can identify your personal identity.
• Payment Processing (if applicable): If you use the paid functions in PP Love, we will share necessary transaction information (such as order number, transaction amount) with payment service providers to complete payment processing. Payment service providers will strictly abide by relevant financial regulations and data protection laws to ensure the security of your transaction information.
All the above cooperative third parties are required to sign strict data protection agreements with us. The agreements clearly stipulate that they must process personal information in accordance with our requirements, this privacy policy and the relevant laws and regulations of various countries/regions. Those who cause information leakage or improper use due to their own reasons shall bear corresponding compensation liabilities.
V. Personal Information Security Protection Measures
In view of the characteristics of real-time communication services, PP Love has built an end-to-end, multi-level personal information security protection system that integrates advanced technical measures and strict management systems to fully ensure the security of your personal information and prevent risks such as information leakage, tampering and loss.
(I) Technical Protection Measures
• Data Encryption Technology: End-to-end encryption technology is adopted for your real-time communication content (voice, video, text messages) to ensure that only you and the communication object can decrypt and view the content, and we ourselves cannot obtain the original communication content;
• At the same time, SSL/TLS encryption technology is adopted for data transmission, and AES-256 encryption technology is adopted for data storage to ensure the security of data transmission and storage processes.
• Security Defense System: Deploy advanced security protection systems, including firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), etc., to resist malicious network attacks such as hacker attacks, virus intrusions, and Distributed Denial of Service (DDoS) attacks;
• Regularly conduct security vulnerability scans and penetration tests on applications and server systems to timely discover and fix potential security risks.
• Data Desensitization and Anonymization: For data that does not need to be displayed in its original form (such as device information, usage logs), desensitization or anonymization processing is adopted (such as masking part of the device identifier, removing personal identifiers in logs) to reduce the risk of information leakage after accidental data leakage.
• Access Control Mechanism: Implement a strict access control mechanism based on the principle of least privilege. Only employees who truly need to access sensitive information (such as customer service, technical maintenance personnel) can obtain corresponding access rights after multi-level identity verification (such as account password + dynamic verification code + work certificate verification);
• At the same time, all access behaviors to sensitive information are recorded for traceability.
(II) Management Protection Measures
• Strict Internal Management System: Formulate a complete set of personal information security management systems, including data classification and grading management specifications, employee information security codes of conduct, data processing operation processes, etc., to standardize the behavior of internal employees in processing personal information.
• Regular Security Training and Assessment: Regularly carry out privacy and information security training for all internal employees, covering data protection laws and regulations, security protection skills, risk identification and response, etc.;
• At the same time, conduct regular assessments to ensure that each employee has sufficient information security awareness and abides by relevant operation processes.
• Security Incident Response Plan: Formulate a complete security incident response plan, clarifying the processing process, division of responsibilities and response measures for information security incidents (such as data leakage, system intrusion).
• When a security incident occurs, immediately activate the emergency response mechanism, investigate the cause of the incident, take measures to control the scope of the incident, and notify the relevant competent authorities and affected users in accordance with legal requirements.
VI. Your Rights to Manage Personal Information
In accordance with the relevant data protection laws and regulations of various countries and regions, as the subject of personal information, you have the right to inquire, access, correct, delete, restrict the processing of your personal information, and withdraw consent to the processing of personal information. We provide convenient channels for you to exercise these rights, and the specific ways to exercise them are as follows:
(I) Inquiry and Access to Personal Information
• Self-service Inquiry and Access: You can log in to your PP Love account, enter the "My" page, view and inquire about your personal data (nickname, avatar), call records, chat records (locally or cloud-stored) and other relevant content; you can also modify editable information (such as nickname, avatar) through this channel.
• Consult Customer Service: If you encounter technical difficulties or cannot find the required information when inquiring and accessing information through self-service channels, you can contact our customer service team through the in-app customer service function or official service email.
• After identity verification (to ensure your information security), we will assist you in inquiring and accessing relevant information and respond to your request within 15 working days.
• Application for Access to Other Information: For personal information generated during the use of the service that cannot be accessed through self-service channels (such as information shared with third parties, historical operation logs), you can submit an access application to us through the official service email.
• We will review your application in accordance with relevant processes and agreements, and provide you with accessible information in a safe and appropriate manner within a reasonable time (no more than 30 working days).
• Obtaining Data Copies: If you need a copy of your personal information held by us, you can submit a copy application to the customer service team through the official service email.
• After identity verification, we will provide you with a structured, common and machine-readable format (such as PDF, CSV) data copy through a secure method (such as encrypted email). There is no charge for providing data copies, unless the request is obviously excessive or repetitive.
(II) Correction and Deletion of Personal Information
• Information Correction: If you find that the personal information about you held by us is inaccurate or incomplete (such as incorrect bound mobile phone number, outdated avatar information), you can correct it through the self-service channel in (I) 1 above; if you cannot correct it yourself, you can submit a correction application through customer service.
• After we verify the accuracy of the information, we will complete the correction within 10 working days.
• Information Deletion: You have the right to legally require us to delete your personal information. The way to apply for deletion is the same as the way of inquiry and access mentioned above.
• In addition, in the following circumstances, you can take the initiative to require us to delete personal information, and we will complete the deletion or anonymization processing within the specified time after verification:
○ Our collection, use or processing of your personal information violates relevant laws and regulations or the agreement of this privacy policy;
○ Processing your personal information without your prior explicit consent and without other legal processing basis;
○ The purpose of collecting and using your personal information has been achieved, and there is no requirement for retaining information in laws, regulations or service agreements;
○ You decide to terminate the use of PP Love services and apply for account cancellation;
○ We have permanently stopped providing you with all or part of the services, and the stored personal information is no longer necessary for providing services.
It should be noted that if deleting information will affect the performance of legal obligations (such as retaining transaction records in accordance with tax regulations) or the handling of ongoing legal disputes, we may not be able to delete the relevant information immediately, but we will stop using the information for any other purposes unrelated to legal obligations or disputes, and delete it immediately after the relevant obligations or disputes are resolved.
(III) Exercise of Other Rights
• Right to Restrict Processing: If you have objections to the accuracy of your personal information held by us, or believe that our information processing behavior is illegal but do not want to delete the information, you can require us to restrict the processing of your personal information (such as suspending the use of the information for marketing purposes). After verification, we will take corresponding restrictive measures within 15 working days.
• Right to Data Portability: You have the right to require us to provide your personal information in a structured, common and machine-readable format, and have the right to transfer the information to another data controller designated by you (the party must meet the corresponding data security requirements). You can submit an application to exercise this right through the official service email.
• Right to Object: If we process your personal information based on legitimate interests or public interests, you have the right to object to such processing behavior. After receiving the objection, we will re-examine the necessity of the processing; if we cannot prove that there is a mandatory legal reason that takes precedence over your interests, we will stop the relevant processing behavior.
• Right to Withdraw Consent: If the data processing activity is carried out based on your consent (such as personalized marketing), you have the right to withdraw your consent at any time. Withdrawal of consent can be completed through "Privacy Settings" in the application or by contacting customer service. The withdrawal of consent does not affect the legality of data processing activities carried out before the withdrawal.
(IV) Right to Opt-Out of Data Sale/Sharing ("Do Not Sell or Share My Personal Information")
For the "right to opt-out of data sale/sharing" required by data protection laws in different regions, you have the right to direct us not to sell or share your personal information at any time. You can exercise this right through the following unified channels:
• Email Application: You can submit an application through the official service email, using the subject line "Do Not Sell or Share My Personal Information" and indicating your account information. We will complete the processing within the time limit required by applicable laws and feedback the result to you.
VII. Data Retention Period and Processing Rules
PP Love strictly abides by the privacy laws and regulations of various countries and regions, formulates scientific and reasonable data retention rules, ensures that your personal information is only retained for the period necessary to achieve the purpose of collection, and does not carry out indefinite retention. The specific retention framework is as follows:
(I) Determination of Retention Period
The retention period of your personal information is determined by us based on three core factors: the purpose of data collection and use, the type of data and the requirements of legal obligations. After the retention period expires, we will take the initiative to delete or anonymize the relevant data. The specific retention periods for different types of data are as follows:
• Basic Account Information: Retained during the active period of your account; after you apply for account cancellation and complete identity verification, we will delete or anonymize all your basic account information within 30 days, unless otherwise required by laws and regulations (such as retaining relevant information for handling potential disputes).
• Communication-Related Information: Call records and cloud-stored chat records are retained for 1 year from the date of generation, except for content manually saved by you (manually saved content is retained until you take the initiative to delete it or cancel your account).
• The purpose of retention is to facilitate your inquiry of historical communication records, which will be automatically deleted after the retention period expires.
• Transaction Records (if applicable): To meet the requirements of legal obligations such as tax declaration and audit, transaction records related to you (such as order information, payment records) are retained for a maximum of 7 years from the date of transaction completion.
• After the retention period expires, the transaction records will be anonymized (personal identity information will be removed) so that they can no longer be associated with your personal identity.
• Customer Service Records: Records generated during your consultation and communication with customer service (including consultation content, processing process, processing results, etc.) are retained for a maximum of 2 years from the date of completion of processing.
• The purpose of retention is to facilitate the handling of potential subsequent disputes or repeated consultations, which will be automatically deleted after the period expires.
• Marketing-Related Data: If you agree to receive marketing information (such as promotional activities, new function recommendations), the relevant data used for marketing will be retained until the date you withdraw your consent; after you withdraw your consent, we will delete the relevant marketing data within 6 months.
• System Operation and Diagnostic Logs: Logs related to system operation (such as access logs, login logs) and diagnostic logs (such as crash reports, error logs) are retained for a maximum of 90 days.
• Such logs are mainly used to ensure system security, troubleshoot technical problems and optimize service performance, and will be automatically cleaned up after the period expires.
(II) Standards for Data Deletion and Anonymization
When your personal information no longer needs to be retained (that is, the retention period expires or the purpose of collection is achieved), we will delete the relevant data in accordance with internal data processing specifications. Deletion methods include permanently deleting from the server, overwriting the data storage area, and destroying physical storage media (if applicable).
For data that cannot be completely deleted due to technical reasons (such as backup data in offline storage systems), we will take strict anonymization measures to remove all identifiers that can directly or indirectly identify you (such as device identifiers, account information), so that it can no longer be associated with a specific individual.
Anonymized data is no longer regarded as personal information and can be used for legitimate business purposes such as data analysis and service optimization without further consent.
(III) Retention Requirements for Fulfilling Legal Obligations
In special cases, even if the original retention period expires, we may continue to retain your personal information to meet legal, regulatory or contractual obligations. Such cases mainly include:
• Meeting the requirements of relevant regulations such as tax declaration, financial audit and accounting standards;
• Handling ongoing legal disputes, responding to judicial or administrative inquiries, and assisting law enforcement agencies in investigating illegal acts;
• Complying with industry norms or special provisions of regional data protection laws and regulations.
In such cases, we only retain the information necessary to fulfill the obligations, and immediately stop retaining and deleting it after the relevant obligations or disputes are resolved.
(IV) Response to User Requests Related to Retention
You have the right to inquire about the retention period, retention purpose and storage location of your personal information held by us. If you believe that we have retained your personal information beyond the necessary period, you can submit a request to shorten the retention period or delete the data through the official service email.
We will review your request in accordance with legal provisions and actual business conditions and give a clear reply within 30 days of receiving the request; if your request is reasonable and compliant, we will take corresponding measures to adjust the retention period or delete the data.
VIII. Legal Basis for Data Processing and Your Core Rights
When processing your personal information, PP Love strictly abides by the relevant international and regional data protection laws and regulations of various countries to ensure that each data processing activity has a legal basis. The main legal bases for us to process your personal information are as follows:
• Consent: For data processing activities that are not necessary for providing basic communication services (such as personalized marketing, data analysis for non-service optimization purposes), we will obtain your explicit consent in advance. You have the right to withdraw your consent at any time, and the withdrawal of consent does not affect the legality of data processing activities carried out before the withdrawal.
• Performance of Contract: When it is necessary to process your personal information to perform the service agreement signed with you (such as providing account registration services, completing real-time communication, processing transaction payments for paid functions, etc.), we will process the data based on the needs of contract performance. This is a necessary basis for us to provide you with core services.
• Legitimate Interests: When processing your personal information is necessary to safeguard our legitimate business interests (such as optimizing communication quality, improving user experience, preventing account theft and fraud, ensuring system security, etc.) and does not violate your legitimate rights and interests and public order and good customs, we will process the data based on legitimate interests.
• A balance of interests assessment will be conducted before processing to ensure that our legitimate interests do not take precedence over your rights and interests.
• Fulfillment of Legal Obligations: When it is necessary to process your personal information to comply with the provisions of laws and regulations (such as responding to legal inquiries, fulfilling tax obligations, reporting security incidents in accordance with regulations, etc.), we will process the data based on the needs of fulfilling legal obligations.
• Public Interest: When carrying out public interest activities (such as responding to public health emergencies, assisting public security prevention and control, etc.) and not violating your legitimate rights and interests, we will process the data based on public interest.
As a data subject, under the data protection legal framework, you enjoy a series of core rights related to the protection of personal information. These rights are designed to ensure that you can effectively control your own personal information. In addition to the rights mentioned in Chapter VI, the specific core rights also include:
• Right to Complain: If you believe that our processing of your personal information violates relevant data protection laws and regulations, you have the right to complain to the local data protection supervisory authority (such as the Office of the Privacy Commissioner for Personal Data of Hong Kong, China, the Information Commissioner's Office of the United Kingdom, etc.).
• Right to Know the Legal Basis: You have the right to require us to inform you of the specific legal basis for processing your personal information and the reasoning process for determining the legal basis.
We attach great importance to the protection of your core rights. If you need to exercise the above rights, you can contact us through the official channels specified in this policy. We will review your request in accordance with legal procedures and relevant regulations and respond in a timely manner. Your trust is the foundation of our development, and we will always follow the highest standards of data protection requirements to protect your legitimate rights and interests.
IX. Privacy Rights Under Major International and Regional Data Protection Laws
PP Love is committed to complying with major international and regional data protection laws and regulations around the world to protect the privacy rights of users in different regions. The main laws and regulations we comply with include the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) of the United States, the Brazilian General Data Protection Law (LGPD) and the Virginia Consumer Data Protection Act (VCDPA) of the United States. The specific rights you enjoy under these laws and the ways to exercise them are detailed as follows:
(I) Rights Under the General Data Protection Regulation (GDPR) (For EU Users)
If you are located in the European Union (EU) or the European Economic Area (EEA), you enjoy the following rights in accordance with GDPR:
• Right of Access: You may request access to your personal data held by us and obtain detailed information on data processing, including the purpose of processing, the category of personal data, the data recipient (including third parties in third countries), the retention period and the source of the data (if not collected from you).
• Right to Rectification: You may request us to rectify inaccurate or incomplete personal data without undue delay; if necessary, you may request to supplement incomplete data.
• Right to Erasure (Right to Be Forgotten): You may request the erasure of your personal data, especially when the data is no longer necessary for the purpose of collection, you withdraw your consent and there is no other legal basis for processing, you object to the processing and there is no overriding legitimate reason for continuing the processing, or the data processing is illegal.
• Right to Restriction of Processing: You may request the restriction of the processing of your personal data, especially when you have objections to the accuracy of the data (during verification), the processing is illegal but you do not want the data to be deleted, we no longer need the data but you need it for legal claims, or you have filed an objection (during the objection review period).
• Right to Data Portability: You may request to receive your personal data in a structured, common and machine-readable format and have the right to transmit it unhindered to another data controller; if technically feasible, you may request us to transmit the data directly to another data controller designated by you.
• Right to Object: You may object at any time to the processing of your personal data based on legitimate interests or public interests; for processing for direct marketing purposes, you have an absolute right to object, and we will immediately stop the relevant processing after receiving the objection.
• Right to Withdraw Consent: You may withdraw the authorization for data processing based on consent at any time, and the withdrawal does not affect the legality of processing before the withdrawal; the way of withdrawal shall be as simple as the way of giving consent.
• Right to Complain: If you believe that your data rights have been infringed, you may complain to the data protection authority of the EU member state where you reside, work or where the alleged infringement occurred.
(II) Rights Under the California Consumer Privacy Act (CCPA) (For California Residents of the United States)
If you are a resident of California, USA, you enjoy the following rights in accordance with CCPA (including the California Privacy Rights Act (CPRA)):
• Right to Know Personal Information: You may request us to disclose details of the collection, use, sharing or sale of your personal information in the past 12 months, including the specific categories of personal information collected, the specific content of your personal information held by us, the specific purposes of collecting, using, sharing or selling your personal information, and the specific categories of third parties with whom we have shared or sold your personal information. You may submit two "right to know" requests per year free of charge.
• Disclosure of Data Sale and Sharing in the Past 12 Months: Under the CCPA/CPRA, "sell" and "share" are defined very broadly. We do not sell your personal information for monetary compensation. However, to evaluate marketing efforts, we may share anonymized user behavior data or device identifiers with professional marketing analysis institutions (such as Appsflyer). Under California law, this activity may be considered a "sale" or "sharing" of personal information for cross-context behavioral advertising. You have the absolute right to opt-out of this at any time.
• Right to Request Deletion of Personal Information: You may request us to delete your personal information collected or stored. However, in the following cases, we may not be able to legally meet the deletion request:
○ Completing the transaction initiated by you or providing the service explicitly requested by you;
○ Detecting security incidents, preventing malicious or illegal activities or prosecuting the responsible persons;
○ Complying with legal obligations or exercising legal rights (such as tax declaration or responding to legal requests);
○ Ensuring the integrity and security of our services.
• Disclosure of Data Sale and Sharing in the Past 12 Months: Under the CCPA/CPRA, "sell" and "share" are defined very broadly. We have not sold your personal information for monetary compensation in the preceding 12 months. However, to evaluate marketing efforts, we may share anonymized user behavior data or device identifiers with professional marketing analysis institutions (such as Appsflyer). Under California law, this activity may be considered a "sale" or "sharing" of personal information for cross-context behavioral advertising. You have the absolute right to opt-out of this at any time.
• Right to Opt Out of Sale or Sharing: You may request us not to sell or share your personal data to third parties. "Sale" under CCPA refers to the exchange of personal data for money or other valuable consideration, and "sharing" refers to disclosing personal information for targeted advertising. After you opt out, we will immediately stop selling or sharing your data unless you explicitly agree to resume it.
• Right to Opt Out of Targeted Advertising: You may request us not to use your personal data for targeted advertising. That is, we will not use your data to push you advertisements customized according to your interests or behaviors on different websites, applications or services.
• Right to Non-Discrimination: When exercising your privacy rights, you have the right to be free from discrimination. We will not refuse to provide you with goods or services, charge you different prices or rates, or provide you with services of different levels or quality solely because you exercise your rights under CCPA.
• Right to Correct Inaccurate Personal Information: You may request us to correct your inaccurate personal information. After receiving the request and verifying your identity, we will review and correct the information within a reasonable time.
• Right to Know Data Sale Status: You have the right to know whether we have sold your personal data, as well as the categories of personal data sold and the categories of buyers. You may submit a "data sale information request" through the contact information specified in Chapter XI of this policy, and we will disclose the relevant information of the past 12 months within 15 working days.
• Ways to Exercise the Right to Opt Out ("Do Not Sell or Share My Personal Information"): You may exercise the right to opt out of data sale and sharing through the following ways
○ Email Application: Send a specific request titled "Do Not Sell or Share My Personal Information" to our official service email and provide account information for identity verification. After receiving the request, we will complete the operation within 10 working days and feedback the result to you.
(III) Rights Under the Brazilian General Data Protection Law (LGPD)
If you are located in Brazil, you enjoy the following rights in accordance with LGPD:
• Right of Access: You may request to obtain information about your personal data held by us, including the purpose of processing, the category of data, the data recipient, the retention period and the source of the data.
• Right to Rectification: If your data is inaccurate, incomplete or outdated, you may request to correct, update or supplement it to ensure the accuracy and completeness of the data.
• Right to Deletion: You may request us to delete your personal data from the system (within the scope permitted by law), which applies when the data is no longer necessary for the purpose of collection, you withdraw your consent, the processing is illegal, or you object to the processing and there is no overriding legitimate reason.
• Right to Information: You may inquire about which institutions we have shared your data with, the reasons for sharing and the scope of sharing, and we will provide you with clear and detailed information about the sharing behavior.
• Right to Revoke Consent: You may withdraw your consent to specific data processing activities at any time, and the withdrawal does not affect the legality of processing before the withdrawal; we will provide a simple way to revoke consent.
• Right to Object: If data processing is based on legitimate interests, public interests or the performance of public duties, you may object to the processing; unless we can prove that there is a mandatory legal reason that takes precedence over your interests, rights and freedoms, we will stop the processing.
• Right to Data Transmission: You may request us to transmit your personal data to you or a third party designated by you in a structured, common and machine-readable format; if technically feasible, we will assist in completing the transmission.
• Right to Complain: If you believe that your data protection rights have been infringed, you may complain to the Brazilian National Data Protection Authority (ANPD).
(IV) Rights Under the Virginia Consumer Data Protection Act (VCDPA) (For Virginia Residents of the United States)
If you are a resident of Virginia, USA, you enjoy the following rights in accordance with VCDPA:
• Right to Opt Out of Targeted Advertising: You may opt out of the use of your personal data for targeted advertising, including displaying advertisements to you based on your personal data collected on non-affiliated websites or applications.
• Right to Opt Out of Sale: You may opt out of the sale of your personal data to third parties. "Sale" under VCDPA refers to the exchange of personal data for money or other valuable consideration, and we will promptly respond to your opt-out request.
• Right to Opt Out of Profiling: You may opt out of profiling that supports decisions with legal or similar significant effects on you. Profiling refers to the evaluation, analysis or prediction of your behavior, preferences, health status or credit status through automated processing of personal data.
• Right to Access, Correct and Delete: You may request access to your personal data held by us (including the category of collected data, the purpose of processing and the third party with whom the data is shared); may request correction of inaccurate or incomplete data; may request deletion of your personal data (except as required by laws, regulations or legitimate business purposes).
• Right to Appeal: If we refuse your request to exercise the above rights, you have the right to appeal our decision. After receiving the appeal, we will review and issue a written reply within 60 days; if the appeal is still rejected, we will inform you of the reasons and the way to complain to the Attorney General of Virginia.
• Ways to Exercise the Right to Opt Out of Data Sharing/Sale: You may exercise the right to opt out of personal data sharing or sale through the following ways:
○ Opt out of "Targeted Advertising, Data Sale and Automated Decision Analysis": Opt out of the above functions through the relevant switch in the application's privacy settings;
○ Email Application: Send an "opt out of data sharing/sale" request to the official service email, clearly stating the specific items to opt out. After receiving the request, we will complete the operation within 20 working days and feedback the result to you.
(V) Ways to Exercise Rights Under the Above Laws
To exercise any of the above rights, please contact us through the official service email. When submitting a request, please clearly state the right to be exercised, the specific content of the request, and provide the necessary identity verification materials (to ensure that the request is made by you).
We will respond to your request within the time limit required by applicable laws (usually 30 to 45 days). If the processing time needs to be extended due to the complexity of the request or the need to collect more information, we will notify you in writing within the initial response time limit, explaining the reason for the extension and the expected processing time.
There is no charge for processing your reasonable request, but a reasonable fee may be charged for obviously excessive, repetitive or unfounded requests.
X. Updates to the Privacy Policy
We reserve the right to modify or update this privacy policy from time to time to reflect changes in relevant laws and regulations, adjustments to service functions or optimization of data processing practices. Any update to this privacy policy follows the principle of "not reducing your legitimate rights and interests without your explicit consent."
For minor changes that do not affect your core rights and interests, after the update takes effect, we will announce the updated content through PP Love's in-app (such as the "Notification" module) or official website (if any);
For changes that may have a significant impact on your rights and interests (such as expanding the scope of personal information collection, changing the purpose of data processing, adjusting the way of information sharing, etc.), we will give prominent notice through in-app pop-ups, push notifications or sending emails to your registered email at least 7 days before the change takes effect, and remind you to carefully read the updated privacy policy.
After the updated privacy policy takes effect, your continued use of PP Love services will be deemed as acceptance of the updated content; if you do not accept it, you have the right to terminate the use of our services and apply for account cancellation.
You can view the latest version of this privacy policy through the "Privacy Policy" module in the PP Love application at any time. We will also retain historical versions of the privacy policy for your reference, and you can apply to view the historical versions through customer service channels.
XI. Contact Us and Data Controller Instructions
If you have any questions about the content of this privacy policy or matters related to personal information processing, or need to exercise privacy-related rights (such as inquiring, correcting, deleting personal information, etc.), you can contact us through the following official channels. The information of the data controller and relevant responsible entities of your personal information in this application is as follows for your understanding and communication:
I. Core Contact Information
Official Service Email: partheniaterbush3@gmail.com
Email Communication Instructions: When sending an email, please be sure to indicate the type of specific matter in the subject line (such as "Application for Access to Personal Information", "Consultation on Privacy Policy", "Request for Data Deletion", etc.), and attach your account information and valid contact information to facilitate us to quickly verify your identity, accurately handle your needs and feedback the results in a timely manner.
II. Data Protection Officer (DPO) Consultation Channel
If you have professional questions in the field of data protection (such as consultation on data processing compliance, questions about the privacy protection system, etc.), you can directly contact our Data Protection Officer:
Name: Olivia Wilson
Contact Email: partheniaterbush3@gmail.com (same as the official service email, facilitating the centralized handling of your professional needs)
III. Data Controller Information
The data controller of your personal information in this application is: EMERALD VALLEY ENTERPRISES INC
Registered Address: 636 Hathburn Dr, Rockwood, TN 37854, Roane County, USA
Responsibility Statement: As the responsible subject for personal information processing, the data controller is responsible for determining the purpose and method of personal information processing, and bears the primary responsibility for the full-process security of the collection, use, storage and protection of personal information. If you need to directly communicate with the data controller on core matters related to personal information processing, you can submit a communication request through the above official service email.
IV. Feedback Processing Timeframe
We attach great importance to each of your feedbacks. Upon receiving your valid consultation (with complete information and verifiable identity), we will complete the review and provide a response within 15 working days.
If your consultation involves complex issues (e.g., cross-regional data processing disputes, inquiries about information related to large-value transactions), which require an extension of processing time, we will inform you of the specific reasons and expected progress during the initial communication. This ensures you are kept timely updated on the status of your request.
Your feedback serves as a crucial foundation for us to optimize privacy protection efforts. We will continuously enhance the efficiency of communication responses and the quality of problem resolution.