diff --git a/CONTRIBUTORS.toml b/CONTRIBUTORS.toml index 23f0662a..76f2c5f4 100644 --- a/CONTRIBUTORS.toml +++ b/CONTRIBUTORS.toml @@ -223,3 +223,9 @@ github = "maximbelyakov" [Anon-sec] github = "Anon-sec" + +[filex] +name = "FileX" +website = "https://codeberg.org/FileX" + +[makai] diff --git a/icons/line-yahoo.png b/icons/line-yahoo.png new file mode 100644 index 00000000..8256ebaf Binary files /dev/null and b/icons/line-yahoo.png differ diff --git a/icons/matrix-org.png b/icons/matrix-org.png new file mode 100644 index 00000000..7011f224 Binary files /dev/null and b/icons/matrix-org.png differ diff --git a/products/google.toml b/products/google.toml index 6e9d6f2b..c8a2e17d 100644 --- a/products/google.toml +++ b/products/google.toml @@ -3,36 +3,30 @@ description = "Google is an American technology and advertising company known fo slug = "google" hostnames = [ "google.com", "youtube.com", "google", "googleapis.com" ] sources = [ "https://policies.google.com/privacy" ] -contributors = [ "ibarakaiev" ] +contributors = [ "ibarakaiev", "filex" ] [rubric.behavioral-marketing] value = "yes-opt-out" citations = [ - "\"We use the information we collect to customize our services for you, including providing recommendations, personalized content, and customized search results.\"" + "\"We use the information we collect to customize our services for you, including providing recommendations, personalized content, and customized search results.\n[...] You can control what information we use to show you ads by visiting your ad settings in My Ad Center.\"" ] [rubric.security] value = "yes-audits" citations = [ - "\"We work hard to protect you and Google from unauthorized access, alteration, disclosure, or destruction of information we hold, including:\n\n- We use encryption to keep your data private while in transit\n- We offer a range of security features, like Safe Browsing, Security Checkup, and 2 Step Verification to help you protect your account\n- We review our information collection, storage, and processing practices, including physical security measures, to prevent unauthorized access to our systems\n- We restrict access to personal information to Google employees, contractors, and agents who need that information in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.\"" -] - -[rubric.third-party-collection] -value = "yes" -citations = [ - "\"In some circumstances, Google also collects information about you from publicly accessible sources. For example, if your name appears in your local newspaper, Google’s Search engine may index that article and display it to other people if they search for your name. We may also collect information about you from trusted partners, including marketing partners who provide us with information about potential customers of our business services, and security partners who provide us with information to protect against abuse. We also receive information from advertisers to provide advertising and research services on their behalf.\n\nWe use various technologies to collect and store information, including cookies, pixel tags, local storage, such as browser web storage or application data caches, databases, and server logs.\"" + "\"We work hard to protect you and Google from unauthorized access, alteration, disclosure, or destruction of information we hold, including: \n- We use encryption to keep your data private while in transit \n- We offer a range of security features, like Safe Browsing, Security Checkup, and 2 Step Verification to help you protect your account \n- We review our information collection, storage, and processing practices, including physical security measures, to prevent unauthorized access to our systems \n- We restrict access to personal information to Google employees, contractors, and agents who need that information in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.\"" ] [rubric.history] value = "yes" citations = [ - "\"We change this Privacy Policy from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We always indicate the date the last changes were published and we offer access to archived versions for your review. If changes are significant, we’ll provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).\"" + "\"[...] we offer access to archived versions for your review.\"" ] [rubric.data-deletion] value = "yes-automated" citations = [ - "\"You can export a copy of content in your Google Account if you want to back it up or use it with a service outside of Google.\"\n\n\"To delete your information, you can:\n- Delete your content from specific Google services\n- Search for and then delete specific items from your account using My Activity\n- Delete specific Google products, including your information associated with those products\n- Delete your entire Google Account\"" + "\"You can export a copy of content in your Google Account if you want to back it up or use it with a service outside of Google.\n\nTo delete your information, you can:\n- Delete your content from specific Google services\n- Search for and then delete specific items from your account using My Activity\n- Delete specific Google products, including your information associated with those products\n- Delete your entire Google Account\"" ] [rubric.data-breaches] @@ -44,35 +38,41 @@ citations = [ [rubric.third-party-access] value = "yes-unspecified" citations = [ - "\"We provide personal information to our affiliates and other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures. For example, we use service providers to help us with customer support.\"" + "\"We provide personal information to our affiliates and other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures. For example, we use service providers to help operate our data centers, deliver our products and services, improve our internal business processes, and offer additional support to customers and users. We also use service providers to help review YouTube video content for public safety and analyze and listen to samples of saved user audio to help improve Google’s audio recognition technologies.\"" ] [rubric.data-collection-reasoning] -value = "mostly" +value = "yes" citations = [ - "\"If you use our services to make and receive calls or send and receive messages, we may collect telephony log information like your phone number, calling-party number, receiving-party number, forwarding numbers, time and date of calls and messages, duration of calls, routing information, and types of calls.\"" + "\"We use the information we collect from all our services for the following purposes: \n Provide our services \nMaintain & improve our services \nDevelop new services \nProvide personalized services, including content and ads \nMeasure performance \nCommunicate with you \nProtect Google, our users, and the public\"" ] [rubric.noncritical-purposes] value = "opt-out-all" citations = [ - "\"This section describes key controls for managing your privacy across our services. You can also visit the [Privacy Checkup](https://myaccount.google.com/privacycheckup), which provides an opportunity to review and adjust important privacy settings. In addition to these tools, we also offer specific privacy settings in our products.\"" + "\"You can also visit the Privacy Checkup, which provides an opportunity to review and adjust important privacy settings. In addition to these tools, we also offer specific privacy settings in our products [...].\"" ] [rubric.law-enforcement] value = "reasonable" citations = [ - "\"We will share personal information outside of Google if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to:\n\n...\n- Meet any applicable law, regulation, legal process, or enforceable governmental request. We share information about the number and type of requests we receive from governments in our Transparency Report.\"" + "\"We will share personal information outside of Google if we have a good-faith belief that disclosure of the information is reasonably necessary to: \n- Respond to any applicable law, regulation,legal process, or enforceable governmental request. \n[...]\"" ] [rubric.list-collected] value = "generally" citations = [ - "\"The activity information we collect may **include**: ...\"\n\n\"The information we collect **includes**: ...\"\n\n\"If you’re using an Android device with Google apps, your device periodically contacts Google servers to provide information about your device and connection to our services. This information **includes** things like your device type, carrier name, crash reports, and which apps you've installed.\"" + "\"Things you create or provide to us [...] \nYour apps, browsers & devices [...] \nYour activity [...] \nYour location information [...]\"" ] [rubric.revision-notify] value = "yes" citations = [ - "\"We change this Privacy Policy from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We always indicate the date the last changes were published and we offer access to archived versions for your review. If changes are significant, we’ll provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).\"" + "\"If changes are significant, we’ll provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).\"" +] + +[rubric.third-party-collection] +value = "yes" +citations = [ + "\"In some circumstances, Google also collects information about you from publicly accessible sources. For example, if your name appears in your local newspaper, Google’s Search engine may index that article and display it to other people if they search for your name. We may also collect information about you from trusted partners, such as directory services who provide us with business information to be displayed on Google’s services, marketing partners who provide us with information about potential customers of our business services, and security partners who provide us with information to protect against abuse. We also receive information from partners to provide advertising and research services on their behalf.\"" ] diff --git a/products/line.toml b/products/line.toml new file mode 100644 index 00000000..75d5a6c8 --- /dev/null +++ b/products/line.toml @@ -0,0 +1,78 @@ +name = "Line" +description = "Line is a Messenger mainly used in Japan." +slug = "line-yahoo" +hostnames = ["line.me"] +sources = ["https://www.lycorp.co.jp/en/company/privacypolicy/"] +contributors = ["filex", "makai"] + +[rubric.behavioral-marketing] +value = "yes" +citations = [ + "\"We will utilize Personal Data for providing recommended contents, including ads, to each user.\"" +] + +[rubric.data-breaches] +value = "no" +citations = [ + "\"Also, please notify us in the event you suspect any unauthorized use of your account or any other breach of security via our Contact Form.\"" +] + +[rubric.data-collection-reasoning] +value = "yes" +citations = [ + "\"We will use the collected Personal Data (including Personal Data collected from when you use our Services and all Personal Data collected from third parties) for the following purposes: \n\n- Provision and maintenance of our Services; \n- Development and improvement of our Services; \n- Security and prevention of unauthorized use; and/or \n- Provision of Services optimized for you. \n\nWe use Personal Data to provide our Services to users, for utilization in research and development to provide safer and better services, and to provide services that are strongly linked to users, including ads.\"" +] + +[rubric.data-deletion] +value = "yes-contact" +citations = [ + "\"If you no longer wish to use our Services or if you withdraw your consent to our processing of your Personal Data which is necessary for us to provide our Services, you may choose to delete your entire account. However, the withdrawal of your consent will not in any way affect the lawfulness of our processing of your Personal Data based on your consent that was given before the foregoing withdrawal.\"" +] + +[rubric.history] +value = "yes" +citations = [ + "\"10.b.iii.Archived versions of Privacy Policy\"" +] + +[rubric.law-enforcement] +value = "strict" +citations = [ + "\"If we receive a request pursuant to legal proceedings such as a warrant, or if there is imminent danger to someone’s life or property such as a suicide threat or a bomb threat, we may disclose Personal Data to third parties including law enforcement agencies such as the police, or the court, pursuant to Applicable Laws. For details regarding the disclosure of Personal Data to public agencies, please refer to our Transparency Report.\"" +] + +[rubric.list-collected] +value = "exhaustively" +citations = [ + "\"3.a.Examples of Personal Data to be provided by you [...] \n3.b.Examples of Personal Data related to your use of our Services \n 3.b.i.Status of use of our Services\n 3.b.ii.Location information\n 3.b.iii.Apps, browsers, devices and network information\n3.c.Examples of Personal Data collected from third parties\n 3.c.i.Personal Data collected from group companies\n 3.c.ii.Personal Data collected from Partners\n 3.c.iii.Personal Data uploaded by other users\n3.d.Other Examples\n 3.d.i.Personal Data that is directly collected in third-party services\n 3.d.ii.Collection of Personal Data from public information\"" +] + +[rubric.noncritical-purposes] +value = "opt-out-some" +citations = [ + "\"If you do not provide certain types of information which need to be registered for using our Services, you may not be able to use all or a part of our Services.\"" +] + +[rubric.revision-notify] +value = "yes" +citations = [ + "\"When we make any material changes to this Policy, we will notify you on our Services, or by other reasonable means.\"" +] + +[rubric.security] +value = "yes-audits" +citations = [ + "\"For example, we are taking the following measures. \n\n- Provision of encryption feature of messages \n- Strict access control based on a need-to-know basis \n- 24/7 security monitoring \n- External authentication for objectively evaluating our security measures \n- R&D of new security technologies \nFurthermore, we will never provide any means for fraudulently accessing Personal Data to a third party.\n For details regarding our security measures, please also read “Safety Management Measures for Personal Data.” \nHowever, because no method of electronic transmission or method of data storage is perfect or impenetrable, we cannot guarantee that your Personal Data will be absolutely safe from intrusion during transmission or while stored in our systems.\"" +] + +[rubric.third-party-access] +value = "yes-specified-critical" +citations = [ + "\"We may subcontract certain services required for providing our Services (e.g.: building, operation and development of infrastructure, settlement, shipping, customer support, etc.) to a third party. In connection with this, we entrust all or a part of the Personal Data to the subcontractor, including companies located in the following countries or regions. [...] \n\n5.c.Sharing of Personal Data among group companies\nYou can confirm our group companies to share Personal Data in [“List of Group Companies”](https://privacy.lycorp.co.jp/en/connection/group.html).\"" +] + +[rubric.third-party-collection] +value = "yes" +citations = [ + "\"3.c.ii.Personal Data collected from Partners\n\nWe may collect your Personal Data from our Partners.\nThere are cases where we collect Personal Data from a Partner operating its own service, and from a Partner operating a service that is linked to our Services such as the LINE official account or LINE login.\"" +] diff --git a/products/matrix-org.toml b/products/matrix-org.toml new file mode 100644 index 00000000..f5b7759d --- /dev/null +++ b/products/matrix-org.toml @@ -0,0 +1,80 @@ +name = "Matrix.org" +description = "An open network for secure, decentralised communication." +slug = "matrix-org" +hostnames = ["matrix.org"] +sources = ["https://matrix.org/legal/privacy-notice/"] +contributors = ["filex"] + +[rubric.behavioral-marketing] +value = "no" +notes = [ + "\"Nothing written about it.\"" +] + +[rubric.data-breaches] +value = "no" +citations = [ + "\"If you become aware of any unauthorised use of your account or any other breach of security, you must notify Element immediately by sending an email to security@matrix.org. Suspicious devices can be deleted using the User Settings management tools in a Matrix client such as https://element.io/app, and users should manage good password hygiene (e.g. using a password manager) and change their password if they believe their account is compromised.\"" +] + +[rubric.data-collection-reasoning] +value = "mostly" +citations = [ + "\"Matrix.org processes your data under a performance of contract basis of processing, to provide our Service to you in an efficient and secure manner and to ensure the legal compliance and proper administration of our business. [...] \nWe process your information for the purposes of providing our decentralised, openly-federated and end-to-end encrypted communication Service, getting in touch with you, responding to your requests, working with our suppliers to deliver the Service and enabling its features, ensuring the security of our Service, developing, fixing and improving our Service, administering our business and complying with the law.\"" +] + +[rubric.data-deletion] +value = "yes-automated" +citations = [ + "\"You can request that we forget your copy of messages and files by instructing us to deactivate your account (using a Matrix client such as the Element chat app) and selecting the option instructing us to forget your messages.\"" +] + +[rubric.history] +value = "yes" +citations = [ + "\"Document History [...]\"" +] + +[rubric.law-enforcement] +value = "strict" +citations = [ + "\"In exceptional circumstances, we may share information about you with a third party if we believe that sharing is reasonably necessary to\n\n- (a) comply with any applicable law, regulation, legal process or governmental request,\n- (b) protect the security or integrity of our products and services (e.g. for a security audit),\n- (c) protect Element and our users from harm or illegal activities, or\n- (d) respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing the serious bodily harm of any person.\n\nDetails on how we share data with Law Enforcement agencies can be found in our Law Enforcement Guidelines.\"" +] + +[rubric.list-collected] +value = "exhaustively" +citations = [ + "\"The information we collect is purely for the purpose of providing your communication service via Matrix. We do not profile users or their data on the Service. [...]\nWe collect information about you when you input it into the Service or otherwise provide it directly to us. [...]\nWe collect information about you when you register for an account. This information is kept to a minimum on purpose, and is restricted to:\n\n- Username\n- Password hash\n- Display Name (if you choose to provide one)\n- Your email address (if you choose to provide it)\n- Your verified telephone number (if you choose to provide it)\n- Your username and password is used to authenticate your access to the Service and to uniquely identify you within the Service.\n- Your password hash is stored until your account is deactivated (see 2.6 for details on how passwords are handled securely). Your username is stored indefinitely to avoid account recycling.\n- When you've registered your account and what SSO links you might have (i.e. 'Facebook ID', 'Google ID', etc.)\n- Type of account (i.e. free or paid)\n\nAdditionally, we collect data associated with each of your sessions, specifically:\n\n- When it was created\n- When it finished (so we retain 'finished' sessions)\n- When it was last active\n- The last seen IP for it\n- the user agent we saw when it got created\n- which client you used\n\nYour email address and/or telephone number, if you choose to provide them, are used so that other users can look up your Matrix ID from these identifiers via the Matrix.org Identity Server. We will also use your email address to let you reset your password if you forget it, and to send you notifications about missed messages from users trying to contact you on Matrix if you enable the option. We may also send you infrequent urgent messages about platform updates. [...]\nWe store and distribute the messages and files you share using the Service (and across the wider Matrix ecosystem via federation) as described by the Matrix protocol and according to the access rules configured within the system. Storing and sharing this content is the reason the Service exists.\n\nThis content includes any information about yourself that you choose to share.\n2.2.1.3 Information you provide through purchases in the Matrix.org Foundation shop\"" +] + +[rubric.noncritical-purposes] +value = "na" +notes = [ + "" +] + +[rubric.revision-notify] +value = "yes" +citations = [ + "\"We will likely improve this document over time and we will take steps to inform our users about any updates.\"" +] + +[rubric.security] +value = "yes" +citations = [ + "\"We never store password data in plain text; instead they are stored hashed (with at least 4096 rounds of bcrypt, including both a salt and a server-side pepper secret). Passwords sent to the server are encrypted using SSL.\n\nIt is your sole responsibility to keep your user name, password and other sensitive information confidential. Actions taken using your credentials shall be deemed to be actions taken by you, with all consequences including service termination, civil and criminal penalties.\"" +] + +[rubric.third-party-access] +value = "yes-specified-noncritical" +citations = [ + "\"Big Cartel\nDonorbox\nPretix\nPretalx\nWe need to collect additional information on your account to manage paid plans. This is essentially a flag to identify your account as being on a free or paid plan. Payment details are processed by Stripe. Additionally, we use Xero to automate our tax obligations. [...]\n\nWe may share your information when working with our suppliers in order to provide the Service.\n\nIn addition, the Matrix.org homeserver is a decentralised and open service. This means that, to support communication between users on different homeservers or different messaging platforms, your username, display name and messages and files are sometimes shared with other services that are connected with the Matrix.org homeserver.\"" +] + +[rubric.third-party-collection] +value = "no" +notes = [ + "Nothing written about it." +] + + diff --git a/products/tiktok.toml b/products/tiktok.toml index df352499..46d54e87 100644 --- a/products/tiktok.toml +++ b/products/tiktok.toml @@ -3,85 +3,79 @@ description = "TikTok is a social media app where users upload short videos, typ slug = "tiktok" hostnames = [ "tiktok.com" ] sources = [ "https://www.tiktok.com/legal/privacy-policy" ] -contributors = [ "bumbleben" ] +contributors = [ "bumbleben", "filex", "makai" ] [rubric.behavioral-marketing] -value = "yes" +value = "yes-opt-out" citations = [ - "As explained below, we use your information to fulfill and enforce our Terms of Service, to improve and administer the Platform, and to allow you to use its functionalities. We may also use your information to, among other things, show you suggestions, promote the Platform, and customize your ad experience.\n\nWe generally use the information we collect: ...\n\n... to customize the content you see when you use the Platform. For example, we may provide you with services based on the country settings you have chosen or show you content that is similar to content that you liked or interacted with ...\n\n... to make suggestions and provide a customized ad experience." + "\"We may also use your information to, among other things, show you suggestions, promote the Platform, and customize your ad experience.\"", + "\"We ask for your consent to access or use your information for specific purposes. If we do, you’ll always be able to revoke your consent through your device permissions or in-app settings.\"" ] -[rubric.security] -value = "somewhat" -citations = [ - "We use reasonable measures to help protect information from loss, theft, misuse and unauthorized access, disclosure, alteration, and destruction. You should understand that no data storage system or transmission of data over the Internet or any other public network can be guaranteed to be 100 percent secure. Please note that information collected by third parties may not have the same security protections as information you submit to us, and we are not responsible for protecting the security of such information." +[rubric.data-breaches] +value = "no" +notes = [ + "\"Not in policy.\"" ] -[rubric.third-party-collection] +[rubric.data-collection-reasoning] value = "yes" citations = [ - "We may receive the information described in this Privacy Policy from other sources, such as:\n\nSocial Media. if you choose to link or sign up using your social network (such as Facebook, Twitter, Instagram, or Google), we may collect information from these social media services, including your contact lists for these services and information relating to your use of the Platform in relation to these services.\n\nThird-Party Services. We may collect information about you from third-party services, such as advertising partners and analytics providers.\n\nOthers Users of the Platform. Sometimes other users of the Platform may provide us information about you, including through customer service inquiries. \n\nOther Sources. We may collect information about you from other publicly available sources. " -] - -[rubric.history] -value = "last-modified" -citations = [ - "(If you are a US resident)\nLast update: January 1, 2020.\n\n(If you are a user having your usual residence in the EU)\nLast updated: October 2019\n\n(If your residence is in another country, and not the US or EU)\nLast updated: February 2019" + "\"As explained below, we use your information to improve, support and administer the Platform, to allow you to use its functionalities, and to fulfill and enforce our Terms of Service. We may also use your information to, among other things, show you suggestions, promote the Platform, and customize your ad experience.\"" ] [rubric.data-deletion] -value = "yes-contact" +value = "yes-automated" citations = [ - "You may submit a request to access or delete the information we have collected about you by sending your request to us at the email or physical address provided in the Contact section at the bottom of this policy. We will respond to your request consistent with applicable law and subject to proper verification. And we do not discriminate based on the exercise of any privacy rights that you might have." + "\"[...] delete your account by following the instructions [here](https://support.tiktok.com/en/account-and-privacy/deleting-an-account/deleting-an-account).\"" ] -[rubric.data-breaches] -value = "no" -notes = [ - "Neither the Privacy Policy nor Terms of Service specify a data breach protocol." +[rubric.history] +value = "last-modified" +citations = [ + "\"When we update the Privacy Policy, we will notify you by updating the “Last Updated” date at the top of the new Privacy Policy [...]\"" ] -[rubric.third-party-access] -value = "yes-unspecified" +[rubric.law-enforcement] +value = "reasonable" citations = [ - "We are committed to maintaining your trust, and while TikTok does not sell personal information to third parties, we want you to understand when and with whom we may share the information we collect for business purposes. \n\nService Providers and Business Partners\nWe share the categories of personal information listed above with service providers and business partners to help us perform business operations and for business purposes, including research, payment processing and transaction fulfillment, database maintenance, administering contests and special offers, technology services, deliveries, email deployment, advertising, analytics, measurement, data storage and hosting, disaster recovery, search engine optimization, marketing, and data processing. \n\nWithin Our Corporate Group\nWe may share your information with a parent, subsidiary, or other affiliate of our corporate group.\n\nIn Connection with a Sale, Merger, or Other Business Transfer\nWe may share your information in connection with a substantial corporate transaction, such as the sale of a website, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy.\n\nFor Legal Reasons\nWe may disclose your information to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims, or government inquiries, and to protect and defend the rights, interests, safety, and security of TikTok Inc., the Platform, our affiliates, users, or the public. We may also share your information to enforce any terms applicable to the Platform, to exercise or defend any legal claims, and comply with any applicable law. \n\nWith Your Consent\nWe may share information for other purposes pursuant to your consent or with your further direction.\n\nIf you access third-party services, such as Facebook, Google, or Twitter, to login to the Platform or to share information about your usage on the Platform with others, these third-party services may be able to collect information about you, including information about your activity on the Platform, and they may notify your connections on the third-party services about your use of the Platform, in accordance with their privacy policies.\n\nIf you choose to engage in public activities on the Platform, you should be aware that any information you share may be read, collected, or used by other users. You should use caution in disclosing personal information while engaging. We are not responsible for the information you choose to submit." -] -notes = [ - "ByteDance, which owns TikTok, allegedly works closely with the Communist Party of China to monitor and censor the content on its platforms, including TikTok." + "\"We may disclose any of the Information We Collect to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims, or government inquiries, and to protect and defend the rights, interests, safety, and security of the Platform, our affiliates, users, or the public.\"" ] -[rubric.data-collection-reasoning] -value = "mostly" +[rubric.list-collected] +value = "generally" citations = [ - "We generally use the information we collect:\n\nto fulfill requests for products, services, Platform functionality, support and information for internal operations, including troubleshooting, data analysis, testing, research, statistical, and survey purposes and to solicit your feedback\n\nto customize the content you see when you use the Platform. For example, we may provide you with services based on the country settings you have chosen or show you content that is similar to content that you liked or interacted with\n\nto send promotional materials from us or on behalf of our affiliates and trusted third parties\n\nto improve and develop our Platform and conduct product development\n\nto measure and understand the effectiveness of the advertising we serve to you and others and to deliver targeted advertising\n\nto make suggestions and provide a customized ad experience\n\nto support the social functions of the Platform, including to permit you and other users to connect with each other through the Platform and for you and other users to share, download, and otherwise interact with User Content posted through the Platform\n\nto use User Content as part of our advertising and marketing campaigns to promote the Platform\n\nto understand how you use the Platform, including across your devices\n\nto infer additional information about you, such as your age, gender, and interests\n\nto help us detect abuse, fraud, and illegal activity on the Platform\n\nto ensure that you are old enough to use the Platform (as required by law)\n\nto communicate with you, including to notify you about changes in our services\n\nto announce you as a winner of our contest, sweepstakes, or promotions if permitted by the promotion rule, and to send you any applicable prizes\n\nto enforce our terms, conditions, and policies\n\nconsistent with your permissions, to provide you with location-based services, such as advertising and other personalized content\n\nto inform our algorithms\n\nto combine all the information we collect or receive about you for any of the foregoing purposes\n\nfor any other purposes disclosed to you at the time we collect your information or pursuant to your consent." + "\"Information You Provide [...] \nInformation From Other Sources [...] \nAutomatically Collected Information [...]\"" ] [rubric.noncritical-purposes] value = "opt-out-some" citations = [ - "You may be able to refuse or disable Cookies by adjusting your browser settings. Because each browser is different, please consult the instructions provided by your browser. Please note that you may need to take additional steps to refuse or disable certain types of Cookies. For example, due to differences in how browsers and mobile apps function, you may need to take different steps to disable Cookies used for targeted advertising in a browser and to disable targeted advertising for a mobile application, which you may control through your device settings or mobile app permissions. In addition, your choice to disable cookies is specific to the particular browser or device that you are using when you disable cookies, so you may need to separately disable cookies for each type of browser or device. If you choose to refuse, disable, or delete Cookies, some of the functionality of the Platform may no longer be available to you. Without this information, we are not able to provide you with all the requested services, and any differences in services are related to your information.\n\nYou can manage third-party advertising preferences for some of the third parties we work with to serve advertising across the Internet by clicking here and by utilizing the choices available at www.networkadvertising.org/managing/opt_out.asp and www.aboutads.info/choices.\n\nYour mobile device may include a feature that allows you to opt out of some types of targeted advertising (\"Limit Ad Tracking\" on iOS and \"Opt out of Interest-Based Ads\" on Android).\n\nYou can opt out of marketing or advertising emails by utilizing the “unsubscribe” link or mechanism noted in marketing or advertising emails.\n\nYou can switch off GPS location information functionality on your mobile device if you do not wish to share GPS information.\n\nIf you have registered for an account you may access, review, and update certain personal information that you have provided to us by logging into your account and using available features and functionalities.\n\nSome browsers transmit \"do-not-track\" signals to websites. Because of differences in how browsers incorporate and activate this feature, it is not always clear whether users intend for these signals to be transmitted, or whether they even are aware of them. We currently do not take action in response to these signals." + "\"- You may be able to control some of the Information We Collect through your device browser settings to refuse or disable Cookies. Because each browser is different, please consult the instructions provided by your browser. Please note that you may need to take additional steps to refuse or disable certain types of Cookies. In addition, your choice to disable Cookies is specific to the particular browser or device that you are using when you disable Cookies, so you may need to separately disable Cookies for each type of browser or device. If you choose to refuse, disable, or delete Cookies, some of the functionality of the Platform may no longer be available to you. Without this information, we are not able to provide you with all of the requested services. \n- You can navigate to \"Ads\" in your in-app settings to opt-out of targeted advertising based on personal information about your activity on nonaffiliated apps and websites. \n- You may be able to manage third-party advertising preferences for some of the third parties we work with to serve advertising across the Internet by using the choices available at https://www.networkadvertising.org/managing/opt_out.asp and https://www.aboutads.info/choices. \n- Your device may have controls that determine what Information We Collect. For example, you can control whether we can collect your mobile advertising identifier for advertising through settings on your Apple and Android devices. \n- You can opt out of marketing or advertising emails by using the “unsubscribe” link or mechanism noted in marketing or advertising emails. \n- Current versions of the app do not collect precise or approximate GPS information from U.S. users. If you are still using an older version that allowed for collection of precise or approximate GPS information (last release in August 2020) and you granted us permission to do so, you can prevent your device from sharing such information with the Platform at any time through your device’s operating system settings. \n- If you have registered for an account, you may access, review, and update certain personal information that you have provided to us by logging into your account and using available features and functionalities. \n- Some browsers transmit “do-not-track” signals to websites. Because of differences in how browsers incorporate and activate this feature, we currently do not take action in response to these signals.\"" ] -[rubric.law-enforcement] -value = "reasonable" +[rubric.revision-notify] +value = "yes" citations = [ - "TikTok is committed to assisting law enforcement while respecting the privacy and rights of its users. To obtain non-public user information, law enforcement must provide the appropriate legal documents required for the type of information being sought, such as a subpoena, court order, or warrant, or submit an emergency request." -] -notes = [ - "ByteDance, which owns TikTok, is legally required to provide any data requested by the Communist Party of China under Chinese internet laws. " + "\"When we update the Privacy Policy, we will notify you by updating the “Last Updated” date at the top of the new Privacy Policy, posting the new Privacy Policy, or providing any other notice required by applicable law.\"" ] -[rubric.list-collected] -value = "generally" +[rubric.security] +value = "somewhat" citations = [ - "We collect information when you create an account and use the Platform. We also collect information you share with us from third-party social network providers, and technical and behavioral information about your use of the Platform. We also collect information contained in the messages you send through our Platform and information from your phone book, if you grant us access to your phone book on your mobile device. More information about the categories and sources of information is provided below. " + "\"We use reasonable measures to help protect information from loss, theft, misuse, unauthorized access, disclosure, alteration, or destruction.\"" ] -notes = [ - "TikTok uses vague language in a long bulleted list of information that users may voluntarily provide, may unintentionally provide, may be automatically collected, or may be collected from third parties." + +[rubric.third-party-access] +value = "yes-unspecified" +citations = [ + "\"Service Providers and Business Partners [...]\nWithin Our Corporate Group [...] \nIn Connection with a Sale, Merger, or Other Business Transfer [...] \nFor Legal Reasons [...] \nWith Your Consent [...]\"" ] -[rubric.revision-notify] -value = "no" +[rubric.third-party-collection] +value = "yes" citations = [ - "We may update this Privacy Policy from time to time. When we update the Privacy Policy, we will notify you by updating the “Last Updated” date at the top of this policy and posting the new Privacy Policy and providing any other notice required by applicable law. We recommend that you review the Privacy Policy each time you visit the Platform to stay informed of our privacy practices." + "\"Information From Other Sources\n\nAdvertising, Measurement and Other Partners. Advertisers, measurement and other partners share information with us about you and the actions you have taken outside of the Platform, such as your activities on other websites and apps or in stores, including the products or services you purchased, online or in person. These partners also share information with us, such as mobile identifiers for advertising, hashed email addresses and phone numbers, and cookie identifiers, which we use to help match you and your actions outside of the Platform with your TikTok account. Some of our advertisers and other partners enable us to collect similar information directly from their website or app by integrating our TikTok Advertiser Tools (such as TikTok Pixel). These partners are required to have the necessary rights and permissions to share your information with us before doing so. We process certain information that we receive from these partners as a joint controller with them. Learn more about our arrangements with these partners.\nSellers, Payment and Transaction Fulfillment Providers. We receive information about you from sellers as well as payment and transaction fulfillment providers, such as payment confirmation details, and information about the delivery of products you have purchased through our shopping features.\nThird Party Platforms and Partners. Third party platforms provide us with information (such as your email address, authentication ID, and public profile) when you choose to sign up for or log in to the Platform using sign-in features provided by those third parties. We may also receive contact information that you hold or is held about you when contact information is synced with our Platform by you or another user. When you interact with any third party service (such as third party apps, websites or products) that integrate TikTok Developer Tools, we will receive the information necessary to provide you with features like cross-service authentication or cross-posting. For example, this will happen if you log in to another platform with your TikTok account or if you use TikTok’s “share” button on a third party platform to share content from there to the Platform. We may also receive information from third party providers which we use for safety purposes, including to protect users on the Platform and for content moderation.\nAdditional Sources. We may collect or receive information about you from organisations, businesses, people, and others, including, for example, publicly available sources, government authorities, professional organisations, and charity groups. We also collect information about you where you are included or mentioned in User Content, Messages, in a complaint, appeal, request or feedback submitted by a user or third party, or if your contact information is provided to us by a user.\"" ] + +