2026-08-27
中文版本:隐私政策 · Related: Terms of Service · Refund Policy · Acceptable Use Policy
Effective date: 27 August 2026 Last updated: 27 August 2026
This policy explains how the operator of KnowUV — Wuhan Zhizhizhi Trading Co., Ltd. (武汉市知之智商贸有限公司), Wuhan, Hubei Province, People's Republic of China — handles personal data.
Contact for anything in this policy: cjh@knowuv.com.
1. Two kinds of people, two different roles
KnowUV is a link service, so personal data reaches us on two distinct paths. Which one you are on decides who is legally responsible for your data.
| Customers | Visitors | |
|---|---|---|
| Who | People with a KnowUV account who create links | People who click or scan a link a Customer made |
| Our role | Controller — we decide why and how | Processor — the Customer decides why and how |
| Ask questions to | Us, at cjh@knowuv.com | The Customer whose link you followed; we will help you reach them |
If you clicked a KnowUV link and want your data erased, the fastest route is the organisation whose link you followed. If you cannot identify them, write to us and we will either forward your request or identify the account holder for you, as the law requires.
2. What we collect from Customers
Account data. Username, email address, phone number, display name, avatar, and a salted hash of your password (we never store the password itself).
Third-party sign-in identifiers. If you sign in with Google, the identifier and basic profile in the Google ID token. If you connect a WeChat Official Account, the WeChat openid, unionid, nickname and avatar for your account.
Verification data. One-time SMS codes and the phone number they were sent to, held briefly (see section 6) to prove a number belongs to you.
Content you create. Destination URLs, link settings and plugin configuration, landing-page content, form definitions, uploaded images and files.
Billing data. Your credit balance and a ledger of every top-up and deduction (amount, resulting balance, reason, reference); order records; and, where you pay us directly, the payment channel and transaction reference. We never receive or store your full card number — card data goes directly to the payment provider.
Technical and usage data. IP address, browser and device information, pages you view in the dashboard, API token usage, and server logs.
Support correspondence. What you write to us and what we write back.
3. What we collect from Visitors
When someone opens a short link or scans a dynamic QR code, we record a visit on behalf of the Customer who owns it:
- The link opened, the time, and the referring page
- IP address, and the approximate location derived from it (country, region, city — not a precise location)
- Browser, operating system, device type, user agent, and the in-app browser identifier (
X-Requested-With) - A pseudonymous visitor identifier stored in a cookie, used to keep a visitor on the same destination across visits
Two further items are collected only when the Customer has switched on the corresponding feature, and only then:
- Verified phone number — where the Customer has enabled the SMS phone-verification gate, the visitor must verify a phone number by SMS before reaching the destination, and that number is attached to the visit record. Customers who enable this gate must tell their visitors why, and have a lawful basis for it.
- WeChat
openid— where the Customer has enabled the WeChat routing feature, the visitor'sopenidfor that Official Account.
Gated links record nothing until the gate is passed. If a visitor is shown a password prompt or a phone-verification page and leaves, no visit record is created.
We do not use this data to build cross-customer advertising profiles, and we do not sell it.
4. Why we use it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service — resolving links, applying your settings, running your dashboard | Account, content, technical | Contract |
| Metering and billing | Billing, usage | Contract |
| Authentication and account security | Account, verification, technical | Contract; legitimate interests |
| Reviewing destinations for abuse (see section 5) | Destination URL and its rendered content | Legitimate interests — preventing phishing, malware and fraud; legal obligation |
| Rate limiting, fraud and bot prevention | Technical, usage | Legitimate interests |
| Analytics reporting to the Customer who owns the link | Visit records | Processor, on the Customer's instructions |
| Service emails, and marketing email you can unsubscribe from | Account | Contract; consent |
| Complying with the law, and responding to lawful requests | As required | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights, and you may object — see section 8.
5. Automated destination review
Because URL shorteners are a well-known vehicle for phishing and malware, every destination that is not already trusted is reviewed before the link resolves for anyone. That review is automated: an isolated browser loads the destination, follows redirects, decodes any QR code it finds, and captures the page's text and a screenshot. Those two artefacts are passed to a content-classification model that returns a risk score and a short reason. Links assessed as violating are disabled.
Three things worth being explicit about:
- The destination page is fetched from our infrastructure, not from a visitor's device. No visitor data is involved in review.
- The captured text and screenshot are sent to a third-party model provider for classification. They are used for that classification only, and we contract against their use for model training.
- The decision can be appealed to a human. Write to cjh@knowuv.com with the short code. Where a decision meaningfully affects you, you have the right to human review, to state your case, and to contest the outcome.
Full detail is in the Acceptable Use Policy.
6. How long we keep things
| Data | Retention |
|---|---|
| Account data | While the account is open, then 90 days after closure |
| Link definitions and settings | While the account is open, then 90 days after closure |
| Visit records | 720 days (about 24 months) from when the record is written, then automatically deleted by the database |
| Verified phone numbers on visit records | Deleted with the visit record they belong to |
| One-time SMS codes | 5 minutes, then automatically discarded |
| Billing ledger, orders and invoices | 10 years — required by PRC accounting and tax law |
| Abuse reports and review decisions | 24 months, to detect repeat offenders |
| Server logs | 90 days |
| Support correspondence | 24 months after the ticket closes |
Backups are overwritten on a rolling cycle and cleared within 90 days. Where the law requires us to keep something longer, we keep only that, and only for that reason.
7. Who we share it with
We do not sell personal data. We share it with these categories of recipient, each under a contract limiting them to our instructions:
| Recipient | What for | Where |
|---|---|---|
| Alibaba Cloud | Hosting, CDN, object storage, SMS delivery | China; CDN edges worldwide |
| Paddle.com Market Ltd | Merchant of record for international sales — checkout, tax, invoicing, refunds | UK / EU |
| Alipay (Ant Group), WeChat Pay (Tencent) | Payment processing for purchases in mainland China | China |
| Tencent / WeChat | Official Account features, openid resolution | China |
| Google LLC | Google Sign-In; website analytics | US |
| IP geolocation provider | Turning an IP address into a country/region/city | — |
| Content-classification model provider | Destination review (section 5) | — |
We also disclose data where we are legally required to, to establish or defend legal claims, or to protect the rights and safety of users and the public — including passing evidence to law enforcement, platform trust-and-safety teams and anti-phishing bodies in response to abuse.
If the business is sold or merged, data may transfer to the acquirer; we will tell you before that happens and it remains subject to this policy.
8. Your rights
Depending on where you live you may have the right to: access your data; correct it; delete it; restrict or object to processing; portability; withdraw consent at any time (without affecting past processing); and not to be subject to a solely automated decision with legal or similarly significant effect.
Exercise any of them at cjh@knowuv.com, with PRIVACY at the start of the subject line. We reply within 30 days, and will tell you if we need longer. We will ask you to verify your identity first. We do not charge for this and we will not treat you differently for asking.
If you are in the EEA or UK you may also complain to your local supervisory authority. In mainland China, your rights under the Personal Information Protection Law (PIPL) — including the right to request an explanation of our processing rules and to have a deceased relative's data handled by their next of kin — apply in full.
If you are a Visitor, the Customer who owns the link is the controller: send erasure and access requests to them. We will assist, and will identify them to you where the law requires.
9. International transfers
We operate primarily from mainland China, and our infrastructure is mainly in China. Some recipients in section 7 are outside it.
- Transfers out of the EEA/UK rely on the European Commission's Standard Contractual Clauses (or the UK Addendum), with a transfer risk assessment where required.
- Transfers out of mainland China are made on the basis of the PIPL standard contract, with separate consent obtained where PIPL requires it.
Ask us at cjh@knowuv.com for a copy of the safeguards for a specific transfer.
10. Cookies and similar technologies
We use a small number of cookies, and no third-party advertising cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session / auth | Keeps you signed in | Session, or until sign-out |
| Locale preference | Remembers your language | 12 months |
SlV2<code> | Keeps a visitor on the same destination for a given link | Per link |
SlOtp<code> | Remembers that a visitor already passed phone verification, so they are not sent a second SMS. HttpOnly. | Up to 5 minutes |
| Google Analytics | Aggregate website statistics | Up to 24 months |
Session, locale and the two Sl* cookies are strictly necessary for the features they support. You can block cookies in your browser, but link gating and sign-in will stop working. Where consent is required for analytics, we ask for it before setting those cookies.
11. Security
We use TLS in transit, encryption at rest for sensitive fields, salted password hashing, scoped API tokens you can revoke, least-privilege access for staff, and audit logging of administrative actions. Phone verification credentials are held in an HttpOnly cookie and re-checked against the server on every use — the cookie itself grants nothing.
No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.
Found a vulnerability? Report it to cjh@knowuv.com with SECURITY at the start of the subject line. We will not pursue legal action against good-faith research that respects user privacy and does not degrade the Service.
12. Children
The Service is not directed at children under 14, and we do not knowingly collect their personal data. If you believe a child has given us data, write to cjh@knowuv.com and we will delete it. Customers must not use the phone-verification gate, forms or landing pages to collect data from children.
13. Changes
We will update this policy as the Service changes. For material changes we will give notice by email or in-product at least 30 days before they take effect, and we will update the "Last updated" date. The current version always lives at this URL.
14. Contact
All enquiries go to one mailbox: cjh@knowuv.com
We are a small team, so a single address reaches us fastest. To help us triage, start your subject line with one of these tags:
| Tag | Use it for |
|---|---|
ABUSE | Phishing, malware, spam or another abusive link — triaged first |
SECURITY | Vulnerability reports |
PRIVACY | Data access, correction, deletion and other privacy rights |
REFUND | Refund requests and billing questions |
APPEAL | A link or account you believe we disabled in error |
SUPPORT | Everything else |
Staffed 08:00–22:00 China Standard Time (UTC+8), Monday to Friday. Reports tagged ABUSE are triaged outside those hours.
Postal: Wuhan Zhizhizhi Trading Co., Ltd., Wuhan, Hubei Province, People's Republic of China.