Legal

Privacy Policy

A complete statement of how Vision Retail Display (Hong Kong) Co., Limited ("we", "us", "our") collects, uses, discloses, and protects personal data across our website, services, and the Vision Retail OS mobile app (the "App"), distributed on the Apple App Store and Google Play.

Last updated: 1 March 2026 · Effective: 1 March 2026

Plain-English summary. We collect the minimum data needed to run our business and our App. We do not sell your personal data. You can ask us to access, correct, port, restrict, or delete your data at any time. Our free App is supported by ads served through Google AdMob and other listed partners; you can opt out of personalised ads and upgrade to a Pro subscription to remove ads entirely.

Table of contents

  1. Scope and who we are
  2. Definitions
  3. Data we collect
  4. How we use your data and legal bases
  5. Cookies, SDKs and similar technologies
  6. Advertising, AdMob, and ad mediation partners
  7. App store distribution (Apple & Google) compliance
  8. Sharing and disclosure
  9. International data transfers
  10. Retention
  11. Security
  12. Children, age-gate and parental consent
  13. Your rights and how to exercise them
  14. Regional rights (GDPR, UK GDPR, CCPA/CPRA, PIPEDA, LGPD, PIPL, PDPA, etc.)
  15. Changes to this policy
  16. Contact us & DPO

1. Scope and who we are

This Privacy Policy applies to (a) this website at weishengretail.com and any subdomain, (b) the Vision Retail OS mobile application for iOS and Android (the "App"), and (c) the related services, customer support, sales, marketing, and consulting activities of Vision Retail Display (Hong Kong) Co., Limited.

Data controller: Vision Retail Display (Hong Kong) Co., Limited, registered office at Rm 704, 7/F, New Mandarin Plaza Tower A, 14 Science Museum Road, Tsim Sha Tsui East, Hong Kong. We are the data controller for the personal data described in this policy. Where we process data on behalf of a business customer as part of our services, we act as a data processor under their written instructions.

2. Definitions

Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data. Profiling means automated processing to evaluate certain personal aspects. Consent means a freely given, specific, informed, and unambiguous indication of the data subject's wishes.

3. Data we collect

We collect the following categories of personal data, depending on how you interact with us:

3.1 Data you give us directly

  • Identity & contact: name, email address, phone number, postal address, company name, job title.
  • Account: username, hashed password, profile photo, language preference, time zone.
  • Communications: messages you send us via forms, email, in-app chat, support tickets, surveys.
  • Billing (for Pro tier): billing name, billing address, VAT/tax ID, last four digits of payment card (the full card is held by our PCI-DSS-compliant payment processor, never by us).
  • Content you upload to the App: store photos, planogram screenshots, merchandising checklists, voice notes, and notes attached to tasks.

3.2 Data collected automatically when you use our services

  • Device & connection: IP address, device model, operating system version, browser type and version, screen resolution, locale, time zone, mobile carrier, network type.
  • Identifiers: advertising identifiers (IDFA on iOS, GAID on Android), vendor identifiers, app-set identifiers, and our own randomly-rotated user IDs.
  • Usage: pages viewed, links clicked, features used, buttons tapped, sessions and timestamps, referrer URL, in-app events, crash logs and performance diagnostics.
  • Location: with your consent, precise (GPS) or coarse (city/country) location derived from IP, Wi-Fi, or device sensors. We use this for store-finder features, regional pricing, and aggregated analytics. You can disable precise location at any time in your device settings.
  • Cookies and similar: see §5.

3.3 Data from third parties

  • App stores: anonymised install, update, and crash data from Apple App Store Connect and Google Play Console.
  • Advertising partners: ad attribution events (e.g. install referrer, SKAdNetwork postbacks).
  • Analytics & support: aggregated behaviour from Google Analytics, Firebase, Sentry, and our CRM (HubSpot).
  • Social: if you choose to log in via Apple, Google, or Facebook, we receive the public profile and verified email address you authorise.

4. How we use your data and legal bases

PurposeCategories of dataLegal basis (GDPR / UK GDPR)
Provide and operate the website and AppIdentity, account, device, usageContract (Art. 6(1)(b))
Process orders, payments, refundsIdentity, billingContract (Art. 6(1)(b)) · Legal obligation (Art. 6(1)(c))
Customer supportIdentity, communications, accountContract (Art. 6(1)(b))
Send transactional emails (order, security)Identity, contactContract (Art. 6(1)(b))
Send marketing emails / newslettersIdentity, contactConsent (Art. 6(1)(a))
Personalise ads in the free App tierIdentifiers, usage, locationConsent (Art. 6(1)(a))
Measure ad performance & attributionIdentifiers, usageConsent (Art. 6(1)(a))
Analytics & product improvementAggregated usageLegitimate interests (Art. 6(1)(f))
Security, fraud prevention, abuseDevice, IP, usageLegitimate interests (Art. 6(1)(f)) · Legal obligation
Comply with law & enforce termsAs relevantLegal obligation (Art. 6(1)(c))

5. Cookies, SDKs and similar technologies

We use cookies and similar tracking technologies on the website, and SDKs in the App. You can manage cookies via our cookie banner or your browser settings. You can reset your advertising identifier or enable "Limit Ad Tracking" / "Opt out of Ads Personalisation" in your device settings to opt out of personalised ads in the App.

Categories used on the website

  • Strictly necessary: session, security, load balancing.
  • Functional: language, region, last-viewed page.
  • Analytics: anonymised page views via Google Analytics 4 (with IP anonymisation enabled).
  • Marketing: only with consent — used to measure campaign effectiveness.

SDKs used in the App

Depending on the App build, version, and region, the following SDKs may be active. You can review the full list in the App's "Privacy" settings.

  • Google AdMob / Google Mobile Ads SDK — banner, interstitial, rewarded video, native, and app open ads. Google Privacy Policy.
  • Google Firebase (Analytics, Crashlytics, Cloud Messaging, Remote Config, Authentication) — Firebase Privacy.
  • Meta Audience Network — banner, interstitial, rewarded video, native. Meta Privacy Policy.
  • Unity Ads — banner, interstitial, rewarded video. Unity Privacy Policy.
  • AppLovin MAX — banner, interstitial, rewarded video, native, MREC. AppLovin Privacy.
  • ironSource (now Unity LevelPlay) — banner, interstitial, rewarded video. ironSource Privacy.
  • Vungle (now part of Liftoff) — interstitial, rewarded video, native. Vungle Privacy.
  • Pangle (ByteDance / TikTok) — banner, interstitial, rewarded video, native. Pangle Privacy.
  • InMobi — banner, interstitial, rewarded video, native. InMobi Privacy.
  • Chartboost (now part of Digital Turbine) — interstitial, rewarded video. Chartboost Privacy.
  • Digital Turbine (Exchange / Fyber) — banner, interstitial, rewarded video. Digital Turbine Privacy.
  • Tapjoy — offerwall, rewarded video, interstitial. Tapjoy Privacy.
  • Mintegral — banner, interstitial, rewarded video, native. Mintegral Privacy.
  • Liftoff (Vungle + AerServ) — banner, interstitial, rewarded video, native. Liftoff Privacy.
  • Smaato (now part of Verve Group) — banner, interstitial, native. Smaato Privacy.
  • Start.io (StartApp) — banner, interstitial, native. Start.io Privacy.
  • Yahoo / Verizon Media (OneSearch Advertising) — banner, native. Yahoo Privacy.
  • Amazon Publisher Services (APS) / Ad Server & Header Bidding — banner, native. Amazon APS Privacy.
  • Criteo — banner, native, retargeting. Criteo Privacy.
  • Ogury — banner, interstitial, rewarded video. Ogury Privacy.
  • AdColony (now part of Digital Turbine) — interstitial, rewarded video. AdColony Privacy.
  • MyTarget (VK / Mail.ru Group) — banner, native. myTarget Privacy.
  • Yandex Advertising Network — banner, native (only on builds served to Yandex-compliant regions).
  • Microsoft Advertising (Bing / Xandr / AppNexus) — banner, native. Microsoft Privacy.
  • Sentry — error & crash reporting, no advertising. Sentry Privacy.
  • Mixpanel / Amplitude (optional, region-dependent) — product analytics, no advertising. Mixpanel Privacy.
  • Adjust / AppsFlyer / Branch (optional) — mobile attribution & deep linking. Adjust Privacy.

6. Advertising, AdMob, and ad mediation partners

The free tier of the App is supported by advertising. Ad formats we use include:

  • App Open Ads (splash, shown on cold start and resume from background).
  • Banner Ads (standard 320×50 / 300×250 / 728×90 / adaptive banner).
  • Interstitial Ads (full-screen, shown at natural transition points).
  • Rewarded Video Ads (user-initiated; in exchange for an in-app reward such as a feature unlock, extra storage, or a coupon).
  • Native Ads (matched to the App's visual design).
  • MREC / Medium Rectangle Ads (300×250 in-feed).
  • Playable Ads (interactive preview, where supported by the network).

6.1 Data used for advertising

Our ad partners may process the following data to deliver, measure, and personalise ads:

  • Advertising identifiers (IDFA, GAID), reset on user request.
  • Device make/model, OS version, language, time zone, screen size, network type.
  • IP address (used for coarse geo, not for precise location).
  • App events (e.g. "level_completed", "ad_shown", "reward_granted", "purchase") — only those relevant to ad delivery and frequency capping.
  • Coarse location (city / country) derived from IP.
  • Crash and performance diagnostics tied to an ad response.

6.2 Frequency capping & user control

We and our partners apply frequency caps to limit how often you see a given ad. You can reset your advertising identifier at any time from your device settings. On iOS, enable "Limit Ad Tracking" in Settings > Privacy & Security > Tracking. On Android, enable "Opt out of Ads Personalisation" in Settings > Google > Ads.

6.3 "Sale" and "sharing" of personal information (US jurisdictions)

Under the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), we do not "sell" or "share" (as those terms are defined) personal information for monetary or other valuable consideration. However, the use of advertising SDKs in our App may be considered "sharing" for cross-context behavioural advertising. California residents may opt out at any time — see §14.

6.4 EU/UK consent

For users in the European Economic Area, the United Kingdom, and Switzerland, we request consent before (a) storing or reading non-essential cookies, (b) processing personal data for personalised advertising, and (c) any cross-border transfer to a country not covered by an adequacy decision. You can withdraw consent at any time in the App's privacy settings.

6.5 Children

Our App is not directed to children. We do not serve personalised advertising to known children. See §12.

6.6 Ad fraud, malware, and brand safety

We and our partners use industry-standard techniques (device attestation, signature verification, anti-fraud signals) to detect and block invalid traffic, malware, and ad fraud. We do not knowingly serve ads that violate applicable laws.

7. App store distribution (Apple & Google) compliance

7.1 Apple App Store

The App is distributed via Apple App Store. We comply with the Apple App Store Review Guidelines, including but not limited to:

  • Guideline 1.4.1 (Physical harm): not applicable.
  • Guideline 2.1 (App Completeness): the App is fully functional at submission.
  • Guideline 2.3 (Accurate Metadata): all metadata is accurate.
  • Guideline 3.2.1 (Acceptable Payments): in-app purchases go through Apple's IAP system. Physical goods and services outside the App are processed separately and not through IAP.
  • Guideline 5.1.1 (Privacy — Data Collection): we request App Tracking Transparency (ATT) consent before accessing IDFA, in line with Apple's policy. Users in supported regions see the ATT prompt and may decline.
  • Guideline 5.1.2 (Data Use & Sharing): we use data only for the purposes described in this policy and Apple's "Privacy Nutrition Labels". We do not share data with third parties for tracking purposes without user consent.
  • Guideline 5.3 / Kids Category: the App is not in the Kids category and is not designed for children.

7.2 Google Play

The App is distributed via Google Play. We comply with the Google Play Developer Program Policies and the Google Play Developer Distribution Agreement, including but not limited to:

  • User Data Policy: we disclose all data collected in the Play Console Data safety form, including data shared with third parties, and the purposes of use.
  • Families Policy: the App is not designed for or primarily marketed to children. We do not use age bands under 13 as a target audience.
  • Personal and Sensitive Information Policy: we collect only data needed to provide the service.
  • Ad Policy: all ads in the App comply with Google Play Ad Policy, including restrictions on tracking, sensitive categories, and ads that interfere with system functionality.
  • Payments Policy: subscriptions and in-app purchases are processed via Google Play Billing.
  • Permissions Policy: we request only the runtime permissions we need (camera for store photos, location for store finder with consent, notifications for store tasks, etc.).

7.3 app-ads.txt and sellers.json

We publish an app-ads.txt file at the root of this website to declare authorised advertising sellers, and we use a corresponding sellers.json file for buyer transparency. You can review it at weishengretail.com/app-ads.txt.

8. Sharing and disclosure

We do not sell personal data. We share personal data only as follows:

  • Service providers / processors: cloud hosting (AWS, GCP), email (Postmark/SendGrid), support (Zendesk), analytics (Google Analytics, Firebase), payments (Apple, Google, Stripe, PayPal), ad networks (as listed in §5), attribution (Adjust, AppsFlyer, Branch), CRM (HubSpot).
  • App stores: aggregated, non-personally-identifiable install and crash data via App Store Connect and Play Console.
  • Business customers: where you use the App on behalf of an employer, your activity may be visible to that employer's administrator (e.g. store managers, HQ users). The employer is the data controller for the underlying store data and acts on its own privacy notice.
  • Legal: when we believe in good faith that disclosure is necessary to comply with a law, court order, or valid legal process; to protect the safety of any person; to protect the security of the App or our services; or to defend our legal rights.
  • Corporate transactions: in connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of our business, in which case we will notify affected users.
  • With your consent: in any other case where you have given us permission.

9. International data transfers

We are headquartered in Hong Kong and use cloud infrastructure in multiple regions. When personal data is transferred outside the country of origin, we rely on appropriate safeguards:

  • EU/UK → third country: European Commission Standard Contractual Clauses (SCCs) 2021/914 (Module 1 / Module 2 as applicable), the UK International Data Transfer Addendum, and where applicable the EU–US Data Privacy Framework (EU–US DPF), UK Extension, and Swiss–US DPF for certified recipients.
  • Transfer Impact Assessments (TIA): we have conducted and maintain TIAs for transfers from the EEA, UK, and Switzerland to jurisdictions not covered by an adequacy decision.
  • Supplementary measures: encryption in transit and at rest, least-privilege access, contractual audit rights, and transparent sub-processor lists.
  • Other regions: PIPL (China), LGPD (Brazil), PDPA (Singapore, Thailand), and other local transfer rules are addressed in our sub-processor agreement and via specific consent where required.

10. Retention

We keep personal data only as long as necessary for the purposes set out in this policy, then delete or anonymise it. Specific retention periods:

  • Account data: for as long as your account is active; deleted within 30 days of account closure (some data may remain in backups for up to 90 days).
  • Customer support records: 24 months from last interaction.
  • Billing records: 7 years (legal / tax requirement).
  • Server logs: 90 days, then aggregated or deleted.
  • Crash reports: 24 months, then aggregated.
  • Ad-related data: per partner's retention windows, typically 13–18 months (Google AdMob: up to 18 months).
  • Backups: encrypted, retained for 35 days, then overwritten.

11. Security

We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, mandatory MFA for staff, regular vulnerability scanning, annual third-party penetration tests, and an incident response plan with a 72-hour breach notification target where required by law. No system is 100% secure; we cannot guarantee absolute security.

12. Children, age-gate and parental consent

The App and our services are not directed to children under 13 (or under 16 in the EEA/UK, under 14 in mainland China and Spain, under 18 in any other jurisdiction with a higher local age of digital consent). We do not knowingly collect personal data from children. We use an age-gate on account creation. If we learn that we have collected personal data from a child without verifiable parental consent, we will delete it as soon as possible.

COPPA (US), the UK Age-Appropriate Design Code (AADC), GDPR-K (EU/UK), PIPL (China), and equivalent laws require us to:

  • Disable behavioural advertising and profiling for known children.
  • Set high-privacy defaults.
  • Avoid dark patterns and nudge techniques that encourage children to provide more data.
  • Use clear, age-appropriate language in our privacy notice for child users.
  • Provide a contact channel for parents to review, delete, or restrict their child's data.

Parents and guardians can exercise these rights via privacy@weishengretail.com.

13. Your rights and how to exercise them

You have the following rights (subject to local law):

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): ask us to delete your data, subject to legal exceptions.
  • Restriction: limit how we process your data while a complaint is investigated.
  • Portability: receive your data in a machine-readable format (JSON / CSV).
  • Objection: object to processing based on legitimate interests, including profiling.
  • Withdraw consent: where processing is based on consent, withdraw at any time without affecting prior processing.
  • Opt out of sale or sharing (US).
  • Opt out of automated decision-making, including profiling.
  • Lodge a complaint with a supervisory authority (EU/UK), data protection authority, or equivalent local regulator.

To exercise any right, email privacy@weishengretail.com. We respond within 30 days (or sooner as required by local law). We may need to verify your identity before fulfilling the request.

14. Regional rights

14.1 EU / EEA (GDPR) and UK (UK GDPR)

The GDPR and the UK GDPR apply when we process personal data of individuals in the EEA or the UK. Our lawful bases are set out in §4. Our EU and UK representatives are available on request. You may lodge a complaint with your local data protection authority.

14.2 California (CCPA / CPRA)

California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of sale or sharing. We do not sell or share personal information for monetary or other valuable consideration. We honour Global Privacy Control (GPC) signals. To exercise these rights, email privacy@weishengretail.com or call our toll-free California line listed in §15.

14.3 Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, etc.)

Residents of these states have similar rights to opt out of sale, targeted advertising, and profiling, and to access, delete, and correct personal data.

14.4 Canada (PIPEDA & Quebec Law 25)

Canadian residents have rights of access and correction. To make a request, contact our privacy team; we will respond within 30 days.

14.5 Brazil (LGPD)

Brazilian residents have rights of access, correction, anonymisation, portability, deletion, and information about sharing. The ANPD is the supervisory authority.

14.6 China (PIPL)

For users in the People's Republic of China, we process personal data in accordance with the Personal Information Protection Law. Cross-border transfers are subject to standard contract or security assessment as required. We honour rights of access, correction, deletion, portability, and withdrawal of consent.

14.7 Singapore (PDPA), Thailand (PDPA), and other APAC

Residents of Singapore, Thailand, Malaysia, and other APAC jurisdictions have rights of access and correction under their respective personal data protection laws.

14.8 Australia (Privacy Act 1988)

Australian residents can request access to and correction of their personal data, and may complain to the Office of the Australian Information Commissioner (OAIC).

14.9 Other regions

If you are in a region not listed above, you may still have rights under local law. Contact us and we will assist.

15. Changes to this policy

We will update this policy when our practices change. We will post the updated policy on this page with a new "Last updated" date. If changes are material, we will notify you via email (if you have an account) or via an in-app banner. Your continued use of our services after the effective date constitutes acceptance of the updated policy, except where further consent is required by law.

16. Contact us & DPO

For any questions about this policy, to exercise your rights, or to contact our Data Protection Officer:

By using our website or the App, you acknowledge that you have read and understood this Privacy Policy. Read the Terms of Service · Contact us · View app-ads.txt