C
Cloubay
Privacy Policy

ClouBay Privacy Policy

Cloubay is operated by Shenzhen Yunye Tech Co. Ltd. This Policy explains how we collect, use, store, share, and protect your personal information while delivering build / hosting / cross-border / managed-ops services, and your rights under China's Personal Information Protection Law (PIPL) and related regulations.

Last updated2026-05-12
01

1. Scope

This Policy applies to all natural persons ("you") who visit cloubay.com and its subdomains, register a customer portal account, submit an inquiry form, subscribe to emails, use our API endpoints, or sign a service contract with us. This Policy does not cover third-party services we deliver to you (e.g. domain registrars, payment channels, cloud providers) — those have their own privacy policies.
02

2. Personal information we collect

We collect only what is necessary to deliver the Service:
  • Account & contact: name, phone, email, company, city, WeChat ID (optional)
  • Identity verification: legal-rep ID, business license, KYC documents (only for cross-border payments / incorporation / KYC services)
  • Service delivery: requirements, design preferences, brand assets, domain / server credentials (when in custody)
  • Payment: invoice title, tax ID, corporate bank account info (we do NOT store full card numbers or CVV)
  • Technical: IP, device type, browser version, access timestamps, page dwell (for security and product improvement)
  • Cookies & similar technologies: login session, language preference, analytics identifiers
03

3. How we use your information

We use your personal information for:
  • Delivering the products / services you ordered or inquired about — build, launch, renewal, ops, reporting
  • Identity verification and KYC compliance (legally required for financial and cross-border services)
  • Processing payments, issuing invoices, reconciling accounts, tax filing
  • Customer support, technical support, ticket handling, incident alerts
  • Improving the product through anonymized analytics and A/B tests
  • Complying with law, regulation, or lawful requests by competent authorities
05

5. Sharing, transfer, and disclosure

We share your information with third parties only in these circumstances, and only the minimum necessary: 1) With your explicit consent or at your request (e.g. delegating us to apply for an Apple Developer account on your behalf); 2) With subcontractors / processors who help deliver the Service (Aliyun / Tencent Cloud as storage processors, Stripe / banks as payment processors), subject to legally-binding data processing agreements; 3) When required by law or regulation (e.g. ICP filing to MIIT); 4) In M&A, reorganization, or insolvency proceedings as part of assets transferred — we will notify you and ensure the assignee continues to honor this Policy. We do not sell your personal information to any third party.
06

6. Storage & cross-border transfer

Your personal information is stored by default on servers within China (Aliyun / Tencent Cloud, East / South China regions). When cross-border services require it (incorporation, cross-border payments, AI top-up), we may transfer relevant information to overseas recipients (Stripe / overseas banks / Apple Inc.). We comply with PIPL Article 38 requirements including impact assessment and separate consent. Retention: We retain basic account information for the lifetime of your account; data is deleted or anonymized within 6 months of account closure. Where law requires longer retention (e.g. 10 years for electronic invoices and contracts), we retain accordingly.
07

7. Your rights

Under PIPL, you have the following rights regarding your personal information. Submit requests via the contact below or your customer portal; we respond within 15 business days:
  • Access and copy your personal information
  • Correct or supplement inaccurate or incomplete information
  • Delete your information in qualifying circumstances
  • Withdraw previously-given consent (withdrawal does not affect prior processing)
  • Request data portability in qualifying circumstances
  • Receive an explanation of automated decisions and object to fully-automated decisions that materially affect you
  • Close your Cloubay account
  • File a complaint about our handling of your personal information
08

8. Information security

We apply industry-standard safeguards: full-site HTTPS / TLS 1.2+ in transit, AES-256 at rest for sensitive fields, tiered server access with 12-month audit logs, dual-control for critical operations (e.g. KYC document export). No measure can guarantee 100% security. If a personal information breach occurs, we will notify you within 72 hours via portal message, email, or phone — including incident details, possible impact, and remediation steps — and report to the regulator.
09

9. Minors

The Service is intended for business operators and natural persons aged 18 or older. We do not knowingly collect personal information from minors under 14. If we discover such data was collected, we will delete it promptly. Minors aged 14-18 may use the Service only with written guardian consent.
10

10. Policy updates

This Policy may be updated as our business, the law, or technology evolves. Material changes will be announced 30 days in advance via prominent site notice, email, or SMS. Continued use of the Service after the update means you accept the updated Policy. If you disagree, you may stop using the Service and request account closure.

Concerns about your personal information? Let us know.

We have appointed a dedicated data protection contact responsible for handling your requests around collection, use, deletion, and portability. We respond within 15 business days; suspected breach incidents are responded to within 72 hours. [email protected]