PRIVACY POLICY
Privacy Policy
This Policy explains how Tongping Pro processes personal data while providing account, device, remote-collaboration, and commerce features. We apply purpose limitation, data minimization, and appropriate safeguards.
1. Data we process
- Account: username, one-way password hash, account status, and security settings.
- Device: device ID, user-provided device name, binding slot, status, and binding time. The account page does not invent system or network fields that the server does not record.
- Security and operations: digests of session identifiers, IP address, browser or client identifier, timestamps, errors, and necessary audit records.
- Transactions: orders, amounts, plan snapshots, payment-provider order identifiers, balance entries, refund requests, and invoice details. Payment providers such as WeChat Pay and Alipay handle bank details and payment passwords; this portal does not collect them.
- Remote collaboration: sessions, leases, and routing data needed for a connection initiated by a user and authorized for the remote device. Screen or file content is transferred only when the user uses the relevant feature.
2. Why we process it
We use data to create and protect accounts, enforce device allowances, establish remote connections, process orders and invoices, verify payments and refunds, troubleshoot, prevent abuse, and comply with law. We do not sell personal data.
3. Cookies and sessions
The account portal uses a necessary session cookie and CSRF security token to maintain sign-in and stop forged requests. They are not used for cross-site advertising. Sessions end after sign-out, expiry, or a password change.
4. Sharing and processors
We provide the minimum necessary data to infrastructure, payment, or invoicing services needed to deliver a feature, or respond to a legally authorized request. A payment callback changes an order or balance only after provider verification.
5. Retention
Service data is kept while an account exists; sessions expire under security limits; orders, balance entries, invoices, refunds, and security audits are retained as needed for disputes, tax, and compliance. Data is then deleted or de-identified unless law requires longer retention.
6. Security
Measures include password hashing, access control, session expiry, CSRF checks, payment-signature verification, minimized public fields, and operational audit trails. No internet transmission is perfectly secure; we take reasonable containment, repair, and notification steps when risk is identified.
7. Your choices and rights
The account center lets you view key account, device, order, balance, and invoice data, remove devices, and change your password. Requests for correction, deletion, closure, a copy, or a complaint may be submitted through the contact page and will be handled after identity verification.
8. Children
The service is intended for capable users and organizations and is not directed to children. A guardian who believes a child supplied data without consent may contact us.
9. Contact and changes
For privacy questions, sign in and submit an in-account support ticket. Material changes will be posted prominently with a new effective date.