fzkaipeng.com
Home Services Advantages Updates Contact
fzkaipeng.com  /  Legal

Privacy Policy

Last updated: 1 August 2025 Effective: 1 August 2025 Version: 4.2
On this page
Introduction Definitions Scope & Applicability Data Controller Information We Collect How We Use Information Legal Basis App Store Compliance Ad Platforms Ad Formats Children's Privacy (COPPA) International Transfers Regional Compliance Data Retention Your Rights Cookies Security Measures Third-Party Links Changes Contact

§1Introduction

fzkaipeng.com ("we", "us", "our", "the Studio") is a research-driven software studio registered in the United Kingdom at Sheffield Science Park, Sheffield, United Kingdom. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website fzkaipeng.com, when you use any of our mobile, desktop, or web applications published under the "fzkaipeng" brand name (collectively, the "Services"), and when you contact us by email or other channels.

We have built our products around the principle that your data stays on your device by default. Most of our applications do not require an account, do not upload personal data to our servers, and do not contain third-party tracking. Where this is not the case, this policy explains exactly what is collected, why, and how you can exercise control.

This policy is designed to satisfy the disclosure requirements of the United Kingdom General Data Protection Regulation ("UK-GDPR"), the European Union General Data Protection Regulation ("EU-GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana state privacy laws, Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act 1988, Singapore's PDPA, Hong Kong's PDPO, Japan's APPI, South Korea's PIPA, India's DPDPA, the United States Children's Online Privacy Protection Act ("COPPA"), the UK Age-Appropriate Design Code, the EU Digital Services Act ("DSA"), the EU Digital Markets Act ("DMA"), the Apple App Store Review Guidelines (notably 5.1.1, 5.1.2, and 5.1.3), the Google Play Developer Policy, the Microsoft Store Policy, and the Amazon Appstore Developer Guidelines.

By downloading, installing, or using our Services, or by visiting our website, you confirm that you have read and understood this Privacy Policy. If you do not agree, please discontinue use and contact us at contact@fzkaipeng.com.

§2Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data.
  • "Controller" means the entity that determines the purposes and means of processing — that is fzkaipeng.com.
  • "Processor" means a third party that processes Personal Data on our behalf.
  • "User", "you", "your" means any individual who installs or uses the Services.
  • "Device" means any hardware used to access the Services.
  • "SDK" means a software development kit integrated into an Application by a third party.
  • "Child" means any individual under 13 (COPPA), under 16 in the EEA/UK (UK-GDPR / AADC), or under the age defined as a minor by applicable local law.

§3Scope & Applicability

This policy applies to fzkaipeng.com and all subdomains; all mobile, desktop, and web applications published by fzkaipeng.com; and all communications with the Studio. It does not apply to third-party websites or platforms.

§4Data Controller Information

  • Data Controller: fzkaipeng.com
  • Address: Sheffield Science Park, Sheffield, United Kingdom
  • Privacy: contact@fzkaipeng.com
  • Support: support@fzkaipeng.com

We have not appointed a Data Protection Officer because we do not engage in large-scale systematic monitoring or process special categories of data.

§5Information We Collect

We collect the minimum information required to operate the Services.

5.1 Information you provide directly

  • Account information: None — our applications do not require account creation.
  • Contact form submissions: Name, email, company, inquiry type, optional budget, and message body. Stored in our ticketing system.
  • Support emails: Anything you send to support@fzkaipeng.com.
  • Newsletter opt-ins: Email address only.

5.2 Information collected automatically by our website

  • Server logs: IP address, user agent, referrer, URL, response code, timestamp. Retained 30 days for security and debugging, then aggregated.
  • Theme preference: Local-storage key "fzk-theme" only. Never leaves your browser.

We do not use Google Analytics, Meta Pixel, Hotjar, Mixpanel, Amplitude, Segment, or FullStory on our website.

5.3 Information collected automatically by our applications

  • Crash logs: Anonymised stack traces if you opt in to share diagnostic data. Off by default.
  • App-store receipt metadata: Transaction ID and product identifier returned by Apple/Google. Not linked to you as a person.
  • On-device content you create: Audio, photos, notes, inventories. Stored locally; only uploaded if you explicitly enable sync.

§6How We Use Information

  • To respond to your enquiries and provide support.
  • To deliver, maintain, and improve the Services (including optional diagnostics).
  • To verify in-app purchases and restore entitlements across devices.
  • To detect, prevent, and address fraud, abuse, and security incidents.
  • To comply with legal obligations and respond to lawful authority requests.
  • To send critical service announcements (security alerts, breaking changes).

We do not sell Personal Data, and we do not use Personal Data for automated profiling that produces legal or similarly significant effects.

§7Legal Basis for Processing (UK-GDPR / EU-GDPR)

  • Performance of a contract — paid subscriptions and engagement enquiries.
  • Legitimate interests — security, fraud prevention, and product analytics that do not override your rights.
  • Consent — optional features (crash reporting, cloud sync, newsletter). Withdrawable at any time.
  • Legal obligation — tax, accounting, lawful disclosure duties.

§8App Store Compliance

Our applications are reviewed and distributed through the platforms listed below. Each platform has its own privacy and content rules that supplement this policy.

8.1 Apple App Store

Our applications comply with the Apple App Store Review Guidelines, including Guidelines 1.4.1, 2.1, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.2, 5.3, and 6.5. We do not engage in tracking as defined by Apple, and we publish accurate Privacy labels describing the data collected and linked to the user for each app.

8.2 Google Play Store

Our Android applications comply with the Google Play Developer Policy, including the User Data Policy, the Families Policy, and the Ads Policy. We provide accurate Data Safety declarations for each app. We respect the "Designed for Families" requirements where applicable.

8.3 Amazon Appstore, Microsoft Store, Huawei AppGallery, Samsung Galaxy Store, Snap Store

Our applications comply with each platform's developer and privacy policies. Apps targeting children under 13 follow each platform's kids-category rules.

§9Ad Platforms and Advertising

Where we display advertising, we use industry-standard ad mediation platforms. The following lists the networks, mediation platforms, and attribution providers that may be integrated. Each platform operates its own privacy policy.

9.1 Ad Networks and Mediation

  • Google AdMob — policies.google.com/privacy.
  • Google Ad Manager (DFP) — direct and programmatic ads.
  • Google AdSense — web surface ads.
  • Meta Audience Network — facebook.com/privacy/policy.
  • Unity Ads — unity.com/legal/privacy-policy.
  • AppLovin MAX — applovin.com/privacy.
  • ironSource — is.com/privacy-policy.
  • Vungle — vungle.com/privacy.
  • Tapjoy — tapjoy.com/legal/privacy-policy.
  • AdColony — adcolony.com/privacy-policy.
  • Chartboost — chartboost.com/legal/privacy-policy.
  • Pangle — pangleglobal.com/privacy.
  • InMobi — inmobi.com/privacy-policy.
  • Mintegral — mintegral.com/en/privacy.
  • Liftoff — liftoff.io/privacy-policy.
  • Digital Turbine (Fyber) — digitalturbine.com/privacy-policy.
  • Smaato — smaato.com/privacy.
  • PubMatic — pubmatic.com/legal/privacy-policy.
  • OpenX — openx.com/legal/privacy-policy.
  • Index Exchange — indexexchange.com/privacy.
  • Criteo — criteo.com/privacy.
  • Taboola — taboola.com/privacy-policy.
  • Outbrain — outbrain.com/legal/privacy.

9.2 Attribution & Analytics Providers

  • AppsFlyer — appsflyer.com/legal/privacy-policy.
  • Adjust — adjust.com/privacy-policy.
  • Branch — branch.io/privacy.
  • Kochava — kochava.com/privacy-policy.
  • Singular — singular.net/privacy-policy.
  • Tenjin — tenjin.com/privacy-policy.
  • Firebase Analytics / GA4F — anonymised event analytics.
  • Mixpanel — mixpanel.com/legal/privacy-policy.
  • Amplitude — amplitude.com/privacy.
  • Sentry — sentry.io/privacy.
  • Bugsnag — bugsnag.com/privacy.
  • Crashlytics — Firebase crash reporting.

9.3 How ad networks use your data

Networks may collect identifiers (Apple IDFA, Google Advertising ID, Android ID, IP), coarse location, device characteristics, app interaction events, and contextual information to select and serve ads, measure performance, detect fraud, and build aggregated audience segments. We do not allow behavioural targeting for users under 16 in the EEA/UK or under 13 anywhere.

9.4 Ad choices and opt-outs

  • iOS: Settings → Privacy & Security → Tracking → toggle off "Allow Apps to Request to Track".
  • Android: Settings → Privacy → Ads → "Opt out of Ads Personalisation".
  • Reset Advertising Identifier: limits how networks link activity across apps.
  • Network opt-outs: youradchoices.com, youronlinechoices.eu, or the DAA AppChoices app.

9.5 Consent management (EU/UK EEA)

For users in the EEA, UK, or Switzerland, we display a consent banner managed by a certified CMP (Usercentrics, Cookiebot, OneTrust, Iubenda, or Quantcast Choice) collecting consent per the ePrivacy Directive, UK PECR, and EU DSA.

§10Ad Formats

Our applications may display banner, interstitial, rewarded video, native, splash/open, and offerwall ads. Each is described in detail below; the data each format collects is summarised in the table that follows.

10.1 Banner Ads

Static or animated image ads at the top or bottom of a screen. Per Apple Guideline 6.5, we do not display banner ads in the bottom one-third on iPhone, and never on iPad or Apple Watch. Served via Google AdMob, AppLovin, Meta Audience Network, Unity Ads, or direct deals.

10.2 Interstitial Ads

Full-screen ads shown at natural transition points. Include a clear close/skip button. Never interrupt user-initiated tasks. Served via any of the mediation networks listed in §9.

10.3 Rewarded Video Ads

Users opt in to watch a short video in exchange for an in-app reward. Rewards are clearly labelled before opt-in. Served via AdMob, Unity Ads, AppLovin, Vungle, ironSource, AdColony, Chartboost, Tapjoy, Pangle, InMobi, or Mintegral.

10.4 Native Ads

Ads styled to match surrounding content. Clearly labelled "Sponsored" or "Ad". Served by AdMob Native, Meta Native, or direct partners.

10.5 Splash / Open Ads

Full-screen ads shown at app launch. Closed automatically after a few seconds or on tap. Served via Google AdMob Open Ads.

10.6 Offerwall Ads

A list of actions earning in-app rewards. Served by Tapjoy or Fyber Offerwall.

10.7 Data collected by ad formats

FormatIdentifierCoarse locationInteraction eventsDevice info
BannerIDFA / AAIDDerivedImpression, clickModel, OS version
InterstitialIDFA / AAIDDerivedImpression, click, dismissModel, OS version
Rewarded videoIDFA / AAIDDerivedImpression, completion, claimModel, OS version
NativeIDFA / AAIDDerivedImpression, clickModel, OS version
SplashIDFA / AAIDDerivedImpression, skipModel, OS version
OfferwallIDFA / AAIDDerivedImpression, click, conversionModel, OS version

§11Children's Privacy (COPPA / AADC / Google Families)

We design our products around the strictest applicable child-protection standard.

11.1 Age thresholds

  • Under 13 (COPPA, US): We do not knowingly collect, use, or disclose Personal Data outside categories permitted by COPPA.
  • Under 16 (UK-GDPR / EU-GDPR / AADC): Higher standard; users under 16 receive additional protection.
  • Under 14 (Spain, France, Netherlands, Italy, etc.): Local age of digital consent applies.

11.2 Age screening

A neutral age gate asks the user to confirm they are at least 13 (or the local minimum). Users below the threshold enter a restricted mode that disables optional cloud sync, advertising identifiers, analytics, and the contact form.

11.3 Kids Category compliance

Apps designed for children are tagged "Designed for Families" on Google Play and may be placed in the Kids Category on Apple App Store. In kids-category builds:

  • All third-party advertising SDKs must be certified for child-directed traffic.
  • Behavioural targeting is disabled.
  • Contextual ads only.
  • No persistent identifiers beyond what is strictly necessary.
  • No outlinks (per Apple Guideline 1.4.1).
  • Parental gates on external links or purchases.

11.4 Verifiable parental consent

Where verifiable parental consent is required (e.g., for in-app purchases in kids-category apps), we use platform-provided parental gates or knowledge-based authentication. No additional Personal Data is collected beyond what is necessary.

11.5 Parental rights

Parents may, at any time, request to review, delete, or stop further collection of their child's Personal Data by contacting contact@fzkaipeng.com. We respond to verifiable requests within 30 days.

§12International Data Transfers

Where Personal Data is transferred outside the UK or EEA, we rely on adequacy decisions, Standard Contractual Clauses (SCCs) with the UK Addendum, Binding Corporate Rules, or explicit consent where permitted. Our primary infrastructure is hosted in the EU and UK.

§13Regional Compliance

13.1 EEA & UK

EU-GDPR, UK-GDPR, ePrivacy Directive, UK PECR, UK Age-Appropriate Design Code, EU Digital Services Act. Supervisory authority complaints supported.

13.2 California, USA

CCPA/CPRA, CalOPPA, Shine the Light. California residents have the right to know, delete, correct, and opt out of sale or sharing. We do not sell Personal Data. We honour the Global Privacy Control (GPC).

13.3 Other US States

VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, and equivalent state laws.

13.4 Canada

PIPEDA and Quebec's Law 25.

13.5 Brazil

LGPD (Lei nº 13.709/2018).

13.6 Other jurisdictions

Singapore PDPA, Hong Kong PDPO, Japan APPI, South Korea PIPA, India DPDPA, Australia Privacy Act 1988, New Zealand Privacy Act 2020, South Africa POPIA, and equivalents. Where local law provides higher protection, it prevails.

§14Data Retention

  • Server logs: 30 days, then aggregated.
  • Contact form submissions: 24 months from last contact.
  • Support emails: 24 months from resolution.
  • Newsletter subscriptions: until you unsubscribe.
  • Crash reports (opt-in): 90 days.
  • On-device user content: retained until you delete it or uninstall the app.
  • In-app purchase records: as required by tax and accounting law.

§15Your Rights

Access, rectification, erasure, restriction of processing, data portability, objection, opt-out of sale or sharing, non-discrimination, withdrawal of consent, and the right to lodge a complaint with a supervisory authority. To exercise, contact contact@fzkaipeng.com. We respond within statutory deadlines.

§16Cookies and Similar Technologies

NameTypePurposeLifetime
fzk-themelocalStorageRemembers your light/dark theme choice.Persistent (until cleared)
__sessionServer cookieSession integrity; CSRF prevention.Session

We do not use third-party analytics cookies, advertising cookies, or social-media cookies.

§17Security Measures

  • TLS 1.3 in transit (HSTS preload, modern cipher suites).
  • AES-256 at rest for persisted server data.
  • Per-app sandboxing and platform secure enclave / Keystore for sensitive material.
  • Two-factor authentication for all studio accounts.
  • Annual third-party penetration testing by a CREST-accredited firm.
  • Bug bounty programme (HackerOne, Bugcrowd, or Intigriti).
  • Continuous dependency scanning and SBOM generation.
  • Secure SDLC aligned with OWASP MASVS, SAMM, and NIST SSDF.

Report vulnerabilities to security@fzkaipeng.com for responsible disclosure.

§18Third-Party Links

Our Services may link to third-party websites or services. We are not responsible for their privacy practices.

§19Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top indicates when revised. Material changes are communicated via in-app notice, email, or a website banner. Continued use after a change indicates acceptance.

§20Contact Us

  • Privacy & Data Protection: contact@fzkaipeng.com
  • Customer Support: support@fzkaipeng.com
  • Security Disclosures: security@fzkaipeng.com
  • Postal: fzkaipeng.com, Sheffield Science Park, Sheffield, United Kingdom

You may lodge a complaint with the UK ICO (ico.org.uk), the relevant European supervisory authority, the California Attorney General, or your local data-protection authority.

fzkaipeng.com

An R&D studio in Sheffield building privacy-first, local-native applications with procedural craft and minimalist soul.

Sheffield · United Kingdom
Navigate
  • Home
  • Services
  • Advantages
  • Updates
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Notice
  • Children's Privacy
  • DMCA
Contact
  • support@fzkaipeng.com
  • contact@fzkaipeng.com
  • Sheffield Science Park
    United Kingdom
© 2025 fzkaipeng.com — All rights reserved. Built with care · No tracking · Local-first