SimDock 隐私政策
上海英纵网络科技有限公司(以下简称“我们”)是 SimDock 服务的运营者与个人信息处理者。 本政策适用于 SimDock 在中国大陆及海外地区提供的移动应用、网站与相关服务。
1. 我们处理的信息
- 账号信息:电子邮箱、验证码、昵称(如有)、账号状态,以及登录和身份验证所需的安全数据。密码仅以不可逆的安全摘要保存。
- 号卡资产信息:由你手工录入的 ICCID、号码、号卡名称、运营商、国家或地区、到期日期、提醒设置,以及该号码已开通的平台名称、账号标识和备注。请勿在账号记录中填写密码、验证码、Token、恢复码或安全问题答案。SimDock 不从设备自动读取 ICCID。
- 设备信息:已绑定设备的标识符、设备名称、平台、系统版本、能力开关、最近在线时间及用于同步的必要状态。
- 消息信息:当你在支持消息采集的来源设备上主动开启对应能力后,我们处理用于多设备同步的消息类型、时间、来源等必要元数据,以及在设备端以 AES-256-GCM 加密后的标题和正文。服务端不持有解密消息正文所需的密钥。
- 安全与运行信息:IP 地址、浏览器或设备环境、请求时间、错误与审计日志,以及 CAP 人机验证所需的挑战和验证结果。
- 沟通信息:你向我们发送的邮件、反馈及解决问题所需的相关内容。
2. 设备权限与功能边界
支持消息采集的来源设备会将相关能力默认关闭,并由你逐项选择是否开启;SimDock 不读取历史短信数据库。 你可以随时在 SimDock 或系统设置中撤回相关权限。仅用于查看同步数据的设备不会采集本机消息。
3. 我们为何使用这些信息
我们仅在提供和改进 SimDock 所必需的范围内处理信息,包括:
- 创建和保护账号,完成登录、找回密码与人机验证;
- 提供号卡资产管理、到期提醒、设备绑定和加密消息同步;
- 发送验证码、安全通知、号卡到期提醒和必要的服务邮件;
- 防止欺诈、暴力破解、滥用和其他危害服务安全的行为;
- 排查故障、回应你的请求并履行适用法律义务。
4. 受托处理与对外提供
我们不会出售你的个人信息。为提供服务,我们可能在必要范围内使用以下服务提供方:
- CAP 人机验证:通过
cap.yinzon.com提供注册、登录、找回密码等场景的防自动化验证; - 阿里云 DirectMail:用于发送验证码、账号安全通知和号卡到期提醒等交易类邮件;
- 基础设施服务:用于托管 API、数据库、缓存、日志与网站。
这些服务方仅可按我们的指示、为约定目的处理必要信息,并应采取适当的安全保护措施。法律要求、保护用户或服务安全所必需时,我们也可能依法提供相关信息。
5. 存储地点、跨境与保留期限
SimDock 的主要服务数据存储在中国大陆。海外地区用户使用服务时,相关数据可能传输至中国大陆进行处理; 我们将依据适用法律采取告知、同意、合同或其他必要的跨境保护措施。
我们仅在实现本政策所述目的所需的最短期限内保留信息。你永久注销账号后,账号将立即停用, 号卡、已开通账号记录、设备、消息密文及其他业务数据将立即删除;仅保留不含原始邮箱、IP 等直接识别信息的去标识化安全审计记录 30 天, 用于防滥用与安全追溯,期满后自动删除。法律另有强制要求的,从其规定。
6. 安全措施与加密边界
我们采用传输加密、访问控制、登录防暴力破解和安全审计等措施。消息标题和正文使用 AES-256-GCM 在设备端加密, 密钥仅保存在设备的系统安全存储中,服务端只保存密文与密钥标识。 如果本地密钥被删除且没有其他可用设备,相关历史消息可能无法恢复或解密。
7. 你的权利与选择
在适用法律允许的范围内,你可以访问、更正、复制或删除个人信息,撤回可选权限或同意,反对或限制特定处理, 并可在应用内永久注销账号。具体注销路径与结果见《账号注销说明》。 我们可能在处理请求前合理核验你的身份。
8. 未成年人
SimDock 不面向未满 14 周岁的儿童提供服务。若你所在地区规定了更高的数字服务同意年龄, 你应达到该年龄或在监护人同意与指导下使用服务。若我们发现误收集了儿童信息,将依法尽快删除。
9. 政策更新
我们可能因功能、技术或法律要求变化而更新本政策。发生重大变化时,我们会通过应用内提示、网站或邮件等合理方式通知你, 并在需要时再次征得同意。
10. 联系我们
运营主体:上海英纵网络科技有限公司
隐私联系人:yc.zhao@yinzon.com
我们通常会在收到请求并完成必要身份核验后,于适用法律规定的期限内回复。
SimDock Privacy Policy
Shanghai Yinzon Network Technology Co., Ltd. ("we", "us", or "our") operates SimDock and is the controller of personal data processed through the service. This policy applies to the SimDock mobile applications, website, and related services offered in mainland China and other regions.
1. Information we process
- Account data: email address, verification codes, optional display name, account status, and security data needed for authentication. Passwords are stored only as non-reversible secure hashes.
- SIM card asset data: ICCID, phone number, label, carrier, country or region, expiration date, and reminder settings that you enter manually. SimDock does not automatically read an ICCID from your device.
- Device data: identifiers, device names, platforms, operating system versions, enabled capabilities, last-seen time, and other status needed for synchronization.
- Message data: after you explicitly enable a capability on a supported message-source device, we process necessary metadata such as message type, time, and source, together with titles and bodies encrypted on the device using AES-256-GCM. Our servers do not possess the key required to decrypt message content.
- Security and operational data: IP address, browser or device environment, request time, error and audit logs, and CAP challenge and verification results.
- Communications: emails, feedback, and related information you provide when requesting support.
2. Device permissions and capability boundaries
Collection capabilities on supported message-source devices are off by default and must be enabled individually by you. SimDock does not read the historical SMS database. You can withdraw optional permissions in SimDock or your system settings at any time. Devices used only to view synchronized data do not collect local messages.
3. Why we use information
- To create and protect accounts and support sign-in, password recovery, and anti-bot checks;
- To provide SIM card asset management, expiration reminders, device binding, and encrypted message synchronization;
- To send verification codes, security notices, expiration reminders, and essential service emails;
- To prevent fraud, brute-force attacks, abuse, and other threats to the service;
- To troubleshoot issues, respond to requests, and meet applicable legal obligations.
4. Service providers and disclosures
We do not sell personal data. We may use the following providers only as necessary to operate SimDock:
- CAP: anti-automation challenges served through
cap.yinzon.comfor registration, sign-in, and password recovery; - Alibaba Cloud DirectMail: transactional emails such as verification codes, security notices, and SIM expiration reminders;
- Infrastructure providers: hosting for APIs, databases, cache, logs, and the website.
Providers may process only necessary data for the agreed purpose, under our instructions and appropriate safeguards. We may also disclose information when required by law or when necessary to protect users or service security.
5. Location, international transfers, and retention
SimDock's primary service data is stored in mainland China. When users outside mainland China use the service, their data may be transferred to and processed in mainland China. We use notices, consent, contractual protections, or other measures required by applicable law for such transfers.
We retain information only for the shortest period necessary for the purposes described here. When you permanently delete your account, access is disabled immediately and account, SIM card, device, encrypted message, and other business data is deleted immediately. Only pseudonymized security audit records that do not store raw email addresses, IP addresses, or other directly identifying values are retained for 30 days for abuse prevention and security traceability, then automatically deleted, unless a mandatory law requires otherwise.
6. Security and encryption boundaries
We use encrypted transport, access controls, brute-force protection, and security auditing. Message titles and bodies are encrypted on the device with AES-256-GCM. Keys remain in the operating system's secure storage; the server stores only ciphertext and a key identifier. If local keys are deleted and no other usable device remains, historical messages may be unrecoverable.
7. Your rights and choices
Subject to applicable law, you may access, correct, copy, or delete personal data; withdraw optional permissions or consent; object to or restrict certain processing; and permanently delete your account in the app. See the Account Deletion Guide for the process and effects. We may reasonably verify your identity before acting on a request.
8. Children
SimDock is not directed to children under 14. If your region sets a higher age of digital consent, you must meet that age or use the service with authorization and guidance from a parent or guardian. If we learn that we collected a child's information unintentionally, we will delete it as required by law.
9. Changes to this policy
We may update this policy as features, technology, or legal requirements change. We will provide reasonable notice of material changes through the app, website, or email and request renewed consent when required.
10. Contact us
Operator and controller: Shanghai Yinzon Network Technology Co., Ltd.
Privacy contact: yc.zhao@yinzon.com
We normally respond after receiving a request and completing necessary identity verification, within the period required by applicable law.