ThinkingData SDK privacy statement
Release date of this Privacy Statement: December 23, 2025
Effective date of this Privacy Statement: December 23, 2025
Preface
数数信息科技(上海)有限公司 (hereinafter "we") has always attached great importance to personal information protection. When developers use the SDKs and other data import tools we provide, we will collect, use, store, share, transfer, and publicly disclose the personal information of developers' end users within the People's Republic of China (for the purposes of this Privacy Statement, excluding the Hong Kong and Macao Special Administrative Regions and Taiwan) in accordance with this ThinkingData SDK Privacy Statement (hereinafter "this Privacy Statement") and the relevant provisions of other related legal documents.
This Privacy Statement is closely related to how developers (hereinafter "you") and end users use our services. We recommend that you read, and require your end users to read, the entire content of this Privacy Statement carefully, and in particular make sure that you fully know and understand the meaning and legal consequences of the content in bold, so that you and your end users can make the choices you consider appropriate on that basis. If you choose to use our services, you shall agree to this Privacy Statement and ensure that your users have also agreed to it. We will adhere to the following principles to protect the personal information of your end users: the principles of lawfulness, legitimacy, necessity, and good faith; having specific and reasonable purposes; clear and reasonable purposes directly related to the processing; minimum necessity; openness and transparency; quality assurance; and accountability and security of personal information. We also strive to use plain, concise language, and mark in bold the terms of this Privacy Statement that are of material significance to the rights and interests of your end users, to draw their attention. If your end users have any questions, comments, or suggestions about this Privacy Statement, they can contact us through the contact information provided in this Privacy Statement.
This Privacy Statement will help you understand the following:
1. How we collect and use your end users' personal information;
2. How we use cookies and similar technologies;
3. How we share, transfer, and publicly disclose your end users' personal information;
4. How we store and protect your end users' personal information;
5. Your end users' rights;
6. Provisions on minors' personal information;
7. How this Privacy Statement is updated;
8. How to contact us.
1. How we collect and use your end users' personal information
Personal Information refers to all kinds of information, recorded electronically or by other means, relating to an identified or identifiable natural person, excluding information that has been anonymized.
Sensitive personal information is personal information that, once leaked or illegally used, can easily lead to infringement of the personal dignity of a natural person or harm to their personal or property safety, including information on biometrics, religious beliefs, specific identities, medical health, financial accounts, and whereabouts, as well as the personal information of minors under the age of fourteen.
When you use products and/or services that integrate the ThinkingData SDK, we will, in accordance with the principles of lawfulness, legitimacy, necessity, and good faith, collect the following information in the ways described below: information generated by your end users' use of the services, information your end users actively provide when using the services, and personal information lawfully collected from third parties in accordance with laws and regulations or with your end users' consent. We use this information to understand the performance and usage of your app on different devices, platforms, or app distribution channels, and to provide you with analysis services and analysis results. Details are as follows:
| SDK name: ThinkingData SDK | |||||||
| Feature type | Business function | Overview | Personal information type | Personal Information fields and content | Purpose of processing personal information | Optional | Sensitive permissions involved |
| Basic functions | Statistical analysis | Collects client logs as events and user properties, providing capabilities such as DAU statistics, usage duration statistics, and retention behavior analysis. | Device information | Android ID (Android), IDFV (iOS), browser type (Web), OS version, device manufacturer, operating system, screen resolution, device model, APP version, network status, network carrier, app install time, system language | User identification | Optional | Device information permission |
| Location information | Location information resolved from the IP address, including the country, country code, province, and city | User behavior analysis | Optional | None | |||
| Unique application number | AndroidID, OAID, IDFA, IDFV, app name and app version number (Android and iOS only) | User behavior analysis | Optional | None | |||
| Extended functions | Statistical analysis | Collects device-related information to provide customers with attribution capabilities. | Device information | IMEI (Android), OAID (Android), IDFA (iOS) | User identification | Optional | Device information permission |
You can disable or turn off the collection of some personal information with switches. If you do so, we will no longer collect the corresponding personal information. In addition, in on-premises deployment mode, the above personal information of end users is collected and used by you through data tools, and we have no access to such information. You shall bear full responsibility for the collection, use, storage, and other processing of such information.
You shall disclose the above collection of your end users' personal information in your app's privacy statement and ensure that you have obtained your end users' consent in compliance with the law. For the avoidance of doubt, such consent includes the end users' consent to our collection and use of their personal information to provide you with products and/or services that integrate the ThinkingData SDK.
-
How we use your end users' personal information
To comply with national laws, regulations, and regulatory requirements, provide features and services to your end users, and improve the quality of features and services, we will use your end users' information in the following cases:
a. To achieve the purposes described in "How we collect your end users' personal information" in this Privacy Statement;
b. To report to the relevant authorities in accordance with laws, regulations, or regulatory requirements.
-
Device permission usage
If end users need to turn off a permission enabled for certain features above (such as the device information permission or the location permission), most mobile devices support this. For details, refer to or contact the service provider or manufacturer of the mobile device. End users should note that enabling any permission means authorizing us to collect and use the related information to provide the corresponding service. Once an end user turns off a permission, the authorization is canceled, and we will no longer collect or use the related information based on that permission, nor can we provide the service that corresponds to that permission.
Android SDK permission description
To support customer data collection, the Android SDK needs the following system permissions:
| Permissions | Purpose | Required |
|---|---|---|
| INTERNET | Allows the app to send statistical data | Required. The SDK needs this permission to send tracking data |
| ACCESS_NETWORK_STATE | Allows the app to detect the network status | Required. The SDK decides whether to send data based on the network status |
| READ_PHONE_STATE | Allows the app to get the device IMEI and MEID | Optional. Used for in-app promotion and for collecting the $carrier property |
iOS SDK permission description
To support customer data collection, the iOS SDK needs the following system permissions:
| Permissions | Purpose | Required |
|---|---|---|
| Network (Chinese mainland only) | Allows the app to send data | Required. The SDK needs this permission to send tracking data |
IDFA | Allows the app to get the IDFA | Optional. Used for in-app promotion |
HarmonyOS SDK permission description
To support customer data collection, the HarmonyOS SDK needs the following system permissions:
| Permissions | Purpose | Required |
|---|---|---|
| INTERNET | Allows access to the Internet | Required. The SDK needs this permission to send tracking data |
GET_NETWORK_INFO | Allows the app to get network information | Required. The SDK decides whether to send data based on the network status |
| STORE_PERSISTENT_DATA | Allows the app to store persistent data | Required. Stores data that must stay unchanged after the app is uninstalled |
-
Exceptions to obtaining consent
In accordance with relevant laws and regulations, we may lawfully collect and use your end users' personal information without their consent in the following cases:
- Where it is related to the performance of obligations under laws and regulations;
- Where it is directly related to national security or national defense security;
- Where it is directly related to public safety, public health, or major public interests;
- Where it is directly related to criminal investigation, prosecution, trial, enforcement of judgments, and the like;
- Where it is for the purpose of protecting the life, property, or other major legitimate rights and interests of you, your end users, or other individuals, but it is difficult to obtain the consent of the person concerned;
- Where the personal information involved has been made public by you or your end users;
- Where it is necessary for entering into and performing a contract at the request of you or your end users;
- Where your or your end users' personal information is collected from lawfully and publicly disclosed information, such as legitimate news reports and government information disclosure;
- Other cases stipulated by laws and regulations.
-
Changes to the purposes of collecting and using personal information
As our business develops, our features and services may be adjusted. In principle, when a new feature or service is related to the features or services we currently provide, the personal information collected and used will be related to the original processing purposes. If we collect or use your end users' personal information in a scenario unrelated to the original processing purposes, we will notify you again and obtain your consent, and you shall inform your end users and obtain their consent.
2. How we use cookies and similar technologies
-
Cookie
To ensure that our websites run properly, we store small data files called cookies on your end users' computers or mobile devices. Cookies usually contain an identifier, the site name, and some numbers and characters. With cookies, websites can store data such as your end users' preferences or the features or services they use. We will not use cookies for any purpose other than those described in this Privacy Statement. Your end users can manage or delete cookies according to their preferences. Your end users can clear all cookies saved on their computers, and most web browsers have a feature to block cookies. However, if your end users do so, they will need to change the settings themselves each time they visit our websites.
-
Do Not Track
Many web browsers have a Do Not Track feature that sends Do Not Track requests to websites. Currently, major internet standards organizations have not established policies on how websites should respond to such requests. However, if Do Not Track is enabled in your end users' browsers, all of our websites will respect their choice.
3. How we share, transfer, and publicly disclose your end users' personal information
When end users use products and/or services that integrate the ThinkingData SDK, all information collected through the ThinkingData SDK is stored in the ThinkingAI cluster purchased by the developer (including on-premises deployment and SaaS editions). We have no right to access users' personal data, and no sharing, transfer, or public disclosure of end users' personal information is involved.
4. How we store and protect your end users' personal information
-
Storage of personal information
a. The personal information of end users collected by developers is stored in the ThinkingAI cluster they purchased and its associated servers. Developers shall store personal information in strict accordance with laws and regulations (for example, personal information collected within China shall be stored within China).
b. When end users use products and/or services that integrate the ThinkingData SDK, the ThinkingAI cluster purchased by the developer and its associated servers are responsible for storing the end users' personal information. Developers shall retain information in accordance with laws and regulations, and shall make sure that end users' personal information is deleted or anonymized after the retention period expires.
-
Personal information protection measures
a. We have adopted industry-standard security measures to protect your end users' personal information and prevent unauthorized access, public disclosure, use, modification, damage, or loss of data. We will take all reasonable and practicable measures to protect your end users' personal information. For example, we use encryption to keep data confidential, use trusted protection mechanisms to prevent malicious attacks on data, and deploy access control mechanisms to ensure that only authorized personnel can access personal information.
b. Our data security capabilities: We have used industry-standard security measures to protect your end users' personal information and do our best to prevent unauthorized access, public disclosure, use, modification, damage, or loss of data. We will take all reasonable and practicable measures to protect your end users' personal information.
c. The internet is not an absolutely secure environment, and we will do our best to ensure the security of any information you send to us. You and your end users should also keep your accounts, login passwords, and other identity credentials safe.
d. In the unfortunate event of a personal information security incident, we will, in accordance with laws and regulations, promptly inform you of the incident by email, letter, phone call, push notification, or other means, or issue an announcement in a reasonable and effective way. If we inform you of the incident, you shall promptly inform your end users. We will also report how the personal information security incident was handled in accordance with laws and regulations.
5. Your rights
As our customer, you have a direct contractual relationship with us, which is different from the indirect relationship between us and your end users. You shall undertake to provide your end users with an easy-to-use mechanism for exercising their rights and to explain to your users how to exercise their statutory rights over personal information. Depending on the relationship, and in accordance with relevant Chinese laws and regulations, we will take different measures as far as possible to safeguard your end users' rights to manage their information, as follows:
(1) Customers who directly use our products or services
Since developers are directly obligated to respond to users' requests regarding personal information, developers shall, based on how they have integrated the ThinkingData SDK, provide users with clear features and channels to access, copy, modify, and delete personal information, withdraw consent, transfer personal information, restrict the processing of personal information, obtain a copy of personal information, and cancel their accounts.
(2) Users of apps that use our products or services
Since end users are not our direct users and have no direct interactive interface with the ThinkingData SDK, we have required third-party developers to undertake to provide easy-to-use features and channels for users to exercise their rights, so that your rights can be exercised. If you need to access, copy, modify, or delete your personal information, withdraw consent, restrict the processing of personal information, obtain a copy of personal information, or cancel your account, you can do so through the features provided by the third-party developer.
6. Provisions on minors' personal information
We attach great importance to the protection of minors' personal information. ThinkingData SDK products and/or services are mainly intended for enterprises and adults. We have asked developers to ensure that their products and/or services are used by people aged 18 or over. If you are a minor under the age of 18, make sure that your guardian reads and agrees to this Statement with you before you use products and/or services that integrate the ThinkingData SDK and provide your personal information.
If your app provides services to minors under the age of 14 (hereinafter "children"), you shall, in accordance with laws and regulations, inform the children's parents or guardians of how children's personal information is processed and obtain the consent of the parents or guardians.
If you find that we have processed children's personal information without our knowledge or without verifiable prior consent from their parents or other guardians, you can contact us promptly, and we will try to delete it promptly after we become aware of it. If we discover such a situation ourselves, we will also delete the information promptly, unless otherwise provided by laws and regulations.
7. How this Privacy Statement is updated
- We may revise this Privacy Statement in part or in whole in accordance with national laws and regulations and the needs of providing features and services and business operations. However, we will not reduce the rights your end users are entitled to under this Privacy Statement without your explicit consent. We will notify you of the revised content through push notifications, pop-ups, announcements on our official website, or other appropriate means.
- We will notify you in an appropriate manner when any of the following changes:
- Our name and contact information;
- The purposes and methods of processing personal information, and the types and retention periods of the personal information processed;
- The ways and procedures for you to exercise your statutory rights;
- Other matters that must be disclosed under laws and administrative regulations.
- You have the right to choose whether to continue authorizing us to collect, process, and use your personal information. Make the choice you consider appropriate after fully understanding our revised Privacy Statement. If you do not agree to the revised Privacy Statement, you have the right to, and shall, stop using our services immediately.
Example of a privacy policy consent pop-up:
Example of a sensitive personal information consent pop-up:
8. How to contact us
If you have any questions, comments, or suggestions about this Privacy Statement, you can contact us in the following ways:
Address: 上海市长宁区凯旋路1388号T1幢501-506室
Email: compliance@thinkingdata.cn
In general, we will accept and process your questions, comments, or suggestions within 15 working days.
If you are not satisfied with our response, especially if our processing of personal information has harmed your legitimate rights and interests, you can report it to the relevant government authorities.

