Effective Date: February 4, 2025
Last Updated: February 4, 2025
Welcome to our SaaS subscription and license management service ("the Service", "we", "us"). We value your privacy and have established this policy to explain how we collect, use, and protect your personal information.
By using the Service, you agree to the terms of this Privacy Policy.
Payments are processed via Stripe. We do not store your full credit card number or CVV. We only store order history and Stripe customer IDs.
We use the collected information solely for the following purposes:
We will NOT use your information for:
We share necessary information with the following third-party service providers:
Stripe (Payment Processing)
AWS (Cloud Services)
Email Service (AWS SES or other SMTP providers)
We may disclose your information in the following circumstances:
If we undergo a merger, acquisition, or asset sale, your information may be transferred as part of our business assets. We will notify you before the transfer and ensure the new entity complies with this Privacy Policy.
Clear Commitments:
We implement the following security measures to protect your information:
Please Note: While we take reasonable security measures, no system is completely secure. If you discover any security issues, please contact us immediately.
We use the following essential cookies to provide the Service:
| Cookie Name | Purpose | Expiry | Type |
|---|---|---|---|
| session-id | Session management and authentication | 7 days | HttpOnly, Secure, SameSite |
| csrf-token | Prevent cross-site request forgery attacks | Session | Secure, SameSite |
These cookies are necessary for the Service to function and cannot be disabled.
Stripe: During the payment process, Stripe may set cookies for fraud detection and payment processing. These cookies are governed by Stripe's privacy policy.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account | Provide service |
| Session Data | Auto-expires after 7 days | Security management |
| Order Records | 7 years | Tax and legal requirements |
| Audit Logs | 3 years | Compliance requirements |
| Email Logs | 30 days | Troubleshooting |
We may create encrypted backups of our database to prevent data loss. Backup data is rotated and deleted within a maximum of 90 days according to our backup policy.
Where legal and compliance requirements permit, we may anonymize or de-identify data that needs to be retained long-term (e.g., order records, audit logs) to minimize privacy impact.
When you delete your account:
We automatically clean up:
Under applicable data protection laws (such as GDPR and CCPA), you have the following rights:
You have the right to access the personal information we hold about you.
How to Exercise: Log into your account to view your personal information, or contact us to request a complete data copy.
You have the right to correct inaccurate or incomplete information.
How to Exercise: Update your information in your account settings, or contact us for assistance.
You have the right to request deletion of your personal information.
How to Exercise: Contact us to request account deletion. Please note that certain information may need to be retained for legal requirements.
You have the right to receive your data in a structured, commonly used format.
How to Exercise: Contact us to request data export. We will provide a JSON format data file within 30 days.
You have the right to object to our processing of your information for specific purposes.
How to Exercise: Contact us with your objection reasons.
You have the right to request restriction of processing your information.
How to Exercise: Contact us with the reasons for restriction.
If we process information based on your consent, you have the right to withdraw consent at any time.
How to Exercise: Contact us to withdraw consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with a data protection authority.
EU Users: Contact the data protection authority in your country
California Users: Contact the California Privacy Protection Agency
We do not use automated decision-making (including profiling) that produces legal effects or similarly significantly affects you.
The Service is not directed to children under 16 years of age (or the higher legal age in your jurisdiction). We do not knowingly collect personal information from such individuals.
If you are a parent or guardian and discover that your child has provided us with personal information, please contact us. We will delete the information promptly upon verification.
Your data is stored in AWS data centers (specific location to be determined based on deployment).
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred outside these regions. We implement the following safeguards:
While the EU-U.S. Privacy Shield framework is no longer valid, we ensure lawful data transfers through Standard Contractual Clauses and other legitimate mechanisms.
If you are a California resident, you have the following additional rights:
You have the right to know the categories and specific pieces of personal information we collect.
You have the right to request deletion of personal information we have collected (subject to certain exceptions).
We do NOT sell your personal information. We have never sold, and will never sell, your personal information.
We will not discriminate against you for exercising your CCPA rights (e.g., denying service, charging different prices).
You may designate an authorized agent to exercise your CCPA rights on your behalf.
How to Exercise CCPA Rights: Email us at support@chengrouter.com. We will respond to your request within 45 days.
If you are an EU resident, we act as the data controller for your personal information.
We process your information based on the following legal grounds:
For GDPR-related questions, please contact our Data Protection Officer:
Email: dpo@chengrouter.com
In the event of a data breach, we will notify the relevant supervisory authority within 72 hours, and notify affected users when necessary.
The Service may contain links to third-party websites (such as the Stripe payment page). We are not responsible for the privacy practices of these third-party websites.
Please review their privacy policies when visiting third-party websites.
We may update this Privacy Policy from time to time. For material changes, we will notify you through:
The updated Privacy Policy will become effective 30 days after publication. Continued use of the Service indicates your acceptance of the updated policy.
You may request previous versions of this Privacy Policy by contacting us.
If you have any privacy-related questions, comments, or requests, please contact us through the following methods:
Email: support@chengrouter.com
Mailing Address: [Your Company Address]
Data Protection Officer (DPO): dpo@chengrouter.com (GDPR-related questions only)
Response Time: We will respond to your request within 30 days (45 days for CCPA requests).
If you believe our data processing violates applicable data protection laws, you have the right to lodge a complaint with the relevant data protection supervisory authority.
Last Updated: February 4, 2025
Version: 1.0
Thank you for trusting our Service. Protecting your privacy is our top priority.