Legal
CardGuy Privacy Policy
This Privacy Policy explains how CardGuy collects, uses, shares, retains, and protects personal and sensitive user data when you use the CardGuy mobile application, website, APIs, customer support channels, and related services.
1. Scope and operator
CardGuy (the “App”) and its related services (collectively, the “Services”) are operated by Wuhan Yunjing E-commerce Technology Co., Ltd. (“CardGuy,” “we,” “us,” or “our”). Our registered or principal business address is Room 9, 13th Floor, Building 12, Changhang Lanjing International, No. 116 Gaoxin Avenue, Guanshan Subdistrict, Hongshan District, Wuhan, Hubei Province, China.
This Policy applies to the CardGuy App for Android, iOS, and HarmonyOS; our website and APIs hosted under https://api.cardguy.vip; account registration; gift card redemption; wallet and withdrawal functions; coupons and referrals; customer support; feedback; account deletion; and other pages or services that link to this Policy.
CardGuy is distributed through Google Play in all supported countries or regions except Mainland China. If you access the Services from a country or region where the App is not distributed, this Policy still applies to information we collect from you.
By creating an account or using the Services, you acknowledge that you have read this Policy. Where applicable law requires consent, we request consent through a separate affirmative action before beginning the relevant optional processing.
2. Information we collect
2.1 Account and profile information
- Email address, account ID, password hash, authentication tokens, and verification codes used for registration, login, password reset, and account security.
- Nickname, profile photo, optional WhatsApp or mobile phone number, sex or gender selection, and date of birth.
- Invitation code and referral relationship information when you participate in a referral program.
- Account deletion request information, including an optional deletion reason and information needed to verify the request.
We do not store your password in plain text.
2.2 Gift card redemption and transaction information
- Gift card category, country, card type, submitted value, card number, expiry date, PIN, uploaded card images, review information, order status, and credited amount.
- Wallet balance, redemption history, withdrawal amount, withdrawal status, payout account or bank account details, and related transaction records.
- Coupon issue, claim, selection, validity, and usage information.
- Referral count, referral relationship, referral contribution, referral earnings, and settlement records.
2.3 Customer support, feedback, and user content
- Messages, images, and other content sent through Platform Support or customer service chat.
- Feedback category, feedback description, attachments, optional contact information, and feedback history.
- Other information you voluntarily provide when contacting us or resolving a dispute.
2.4 Device, app, and technical information
- Device model, operating system and version, App version, language, platform, and basic runtime information.
- Device or app identifiers used for captcha security, fraud prevention, and service operation, which may include a device UUID, system-provided device ID, or an App-generated identifier.
- Push notification identifiers, such as a UniPush client ID, push channel token, Firebase Cloud Messaging token, and related App identifier, when push services are enabled.
- Access time, API request records, feature interactions, error logs, crash or diagnostic information, network connection information, and security events generated by the App, our servers, or integrated service providers.
2.5 Local information stored on your device
The App may store authentication state, preferences, cached content, and generated App identifiers locally on your device. Information processed only on your device and not transmitted off-device is not treated as collected by us. You may clear local cache through the App settings; clearing cache does not delete your account or server-side records.
2.6 Information from service providers and partners
We may receive delivery status from notification providers, upload results from object storage providers, customer service delivery information from messaging providers, redemption review results, payout status, and security or fraud signals from providers that support the Services.
3. Permissions and device access
We request device permissions only when they are needed for the feature you choose to use.
| Permission or access | Purpose | When requested |
|---|---|---|
| Camera | Take gift card photos, profile photos, feedback attachments, or customer service images. | When you choose a camera action. |
| Selected photos | Select specific gift card images, profile images, feedback attachments, or customer service images. On supported Android versions, the App must use the system photo picker rather than broad photo-library access. | When you choose an upload-from-album action. |
| Add to photo library | Save a share poster or image that you request to save. | When you select “Save the picture to the album.” |
| Notifications | Deliver service messages, order updates, customer support messages, platform announcements, and security notices. | After an in-App explanation and when notification functionality is enabled. |
You can deny or withdraw permissions in your device settings. Denying a permission prevents the related feature from accessing that device capability but should not block unrelated App functions.
Implementation requirement: the released Android App must remove broad READ_MEDIA_IMAGES access unless Google Play has approved a qualifying core use case. This Policy does not authorize permissions that the App is not permitted to request.
4. How we use information
We use information for the following purposes:
- Create and manage accounts, authenticate users, keep users signed in, and provide account security.
- Generate and validate captchas, detect suspicious activity, prevent fraud, investigate abuse, and enforce our agreements.
- Process gift card redemption submissions, review card details and images, determine results, calculate credited value, and display order status.
- Operate wallet balance, payout account binding, withdrawals, coupons, referral programs, and transaction history.
- Upload and display profile photos and other images you choose to submit.
- Provide customer support, deliver chat messages, respond to feedback, and resolve disputes.
- Register push identifiers and deliver service-related notifications after the applicable disclosure, consent, and permission requirements are met.
- Maintain, troubleshoot, secure, and improve the Services.
- Comply with applicable laws, financial recordkeeping requirements, lawful authority requests, audits, and dispute resolution obligations.
- Process account and data deletion requests.
We do not sell personal or sensitive user data.
4.1 Sensitive user data and consent
CardGuy treats the following as sensitive user data within the meaning of Google Play policy: government identifier information used only as your login account (email address), financial information (gift card card number and PIN, wallet balance, withdrawal records, payout account details), and precise or coarse device identifiers used for fraud prevention and security.
Sensitive data is collected and used only for the specific purpose for which it was provided, is not shared with advertising, analytics, or unrelated third parties, and is handled under the retention rules in Section 6. Before a first camera or photo-library access, a first push notification registration, or any other action that requires in-App disclosure under applicable law, CardGuy presents a clear in-App notice and obtains your affirmative choice.
6. Data retention
We retain each category of information only for the period necessary for its stated purpose and any applicable legal obligations.
| Data category | Retention rule |
|---|---|
| Account and profile information | While the account is active, then deleted or irreversibly anonymized within 15 days after a verified deletion request, except for data identified below as lawfully retained. |
| Gift card, wallet, withdrawal, payout, coupon, referral, and transaction records | Retained while the account is active; deleted with the account on a verified deletion request. Backups expire within 90 days. Mandatory financial recordkeeping may apply where required by law. |
| Customer service and feedback records | Retained for up to 12 months while the account is active, then deleted with the account, unless needed longer for an unresolved dispute, security investigation, or legal obligation. |
| Security, access, API, error, and diagnostic logs | 6 months, unless a specific event requires longer preservation for security or legal proceedings. |
| Uploaded images | Profile images: while the account is active; gift card, feedback, and customer service images: up to 12 months for redemption review, dispute handling, and support, according to the related profile, redemption, feedback, or customer support purpose. |
| Backups | Deleted data is removed from active systems first and expires from protected backups within 90 days, unless preservation is legally required. |
When we retain limited information after account deletion for accounting, regulatory compliance, fraud prevention, security, dispute resolution, or enforcement, we restrict it from ordinary product use and delete or anonymize it when the applicable retention requirement ends.
7. Account and data deletion
7.1 Request deletion in the App
A signed-in user can initiate account deletion through Settings > Cancel account. A cancellation reason must be optional and must not prevent submission of a deletion request.
7.2 Request deletion outside the App
If you have uninstalled the App or cannot access your account, submit a request through our public deletion page: https://api.cardguy.vip/h5/account-deletion.html. The deletion page must allow you to initiate a request without reinstalling the App.
7.3 Verification and processing
We may ask for information reasonably necessary to verify account ownership and protect accounts from unauthorized deletion. We will confirm receipt and complete a valid request within 15 days, unless a longer period is required or permitted by applicable law. If pending withdrawals, disputes, fraud investigations, or mandatory financial recordkeeping prevent immediate completion, we will explain the applicable restriction.
7.4 Effect of deletion
Upon completion, the account can no longer be used. We delete or irreversibly anonymize account credentials, profile information, active authentication tokens, device-to-account push associations, and other account-linked data that is not required to be retained. We also instruct processors to delete applicable data under our control. Data that must be retained is handled according to Section 6 and is not treated as an active account.
Temporary account suspension, disabling, or freezing does not constitute account deletion.
8. Data security
We use administrative, technical, and organizational measures designed to protect personal and sensitive data. Measures include HTTPS encryption in transit, password hashing, authentication and authorization controls, restricted administrative access, service-provider access limitations, monitoring, and protected storage practices. Financial and gift card information is accessible only to personnel and systems that need it for the relevant business purpose.
No Internet transmission or storage system is completely secure. You are responsible for keeping your account credentials confidential and notifying us promptly if you suspect unauthorized access.
9. Your rights and choices
Subject to applicable law, you may have the right to:
- Access, review, and update profile information through the App.
- Request correction of inaccurate personal information.
- Request account and associated data deletion as described in Section 7.
- Request information about our collection, use, disclosure, and retention of your data.
- Withdraw consent for optional processing where consent is the applicable basis.
- Manage camera, selected-photo, photo-library, and notification permissions through device settings.
- Clear local App cache through Settings.
- Contact us or lodge a complaint with a competent data protection authority where available.
Withdrawing an optional permission or consent does not affect processing already lawfully completed. Some Services cannot operate without information that is strictly necessary for account security, redemption, payout, or legal compliance.
10. Children's privacy
The Services are intended only for individuals aged 18 or older, or the higher minimum age required to enter into the relevant transactions in their jurisdiction. We do not knowingly permit children to create accounts or knowingly collect personal information from children. If you believe a child has provided information to us, contact us using Section 13 so that we can investigate and delete it where required.
11. International processing
You may access the Services from different countries or regions. Your information may be processed in countries where we or our service providers operate. Where applicable law requires safeguards for cross-border transfers, we use appropriate contractual, organizational, or legal measures. For information about the locations used for primary hosting and processing, contact our privacy contact.
Primary hosting, processing, and storage for the Services are located in Singapore and the Hong Kong Special Administrative Region, with backups stored in the same regions. Service-provider locations used for push, customer support chat, email delivery, and image storage are listed in Section 5.
12. Changes to this Policy
We may update this Policy to reflect changes to the Services, data practices, third-party providers, or legal requirements. We will publish the revised Policy at this URL and update the “Last updated” date. Where required, we will provide an in-App notice and request renewed consent before materially different processing begins. Continued use alone will not replace consent where applicable law requires an affirmative choice.
13. Contact us
For privacy questions, rights requests, or complaints, contact:
Operator: Wuhan Yunjing E-commerce Technology Co., Ltd.
Privacy email: luog377@gmail.com
Customer support phone: +852 98669874
Official website: https://cardguy.vip/guanwang/index.html
Business address: Room 9, 13th Floor, Building 12, Changhang Lanjing International, No. 116 Gaoxin Avenue, Guanshan Subdistrict, Hongshan District, Wuhan, Hubei Province, China
Account deletion page: https://api.cardguy.vip/h5/account-deletion.html
In-App: Settings > Feedback, or Platform Support
The privacy email and deletion page must remain accessible to users who are not signed in and users who have uninstalled the App.
This Policy is the single source of truth for CardGuy data practices. The Google Play Data safety form, the in-App disclosures, and this document must describe the same practices. If a conflict is identified, update the inconsistent source rather than adding fallback language.