# Privacy policy

Understand account, access, transaction, and partnership data, cookies, third-party analytics, and your privacy rights.

Last updated: 2026-09-08

Original page: https://runlume.app/en/privacy

This policy explains how Runlume handles personal information. Browsing, registration, purchases, and third-party services involve different data. Processing is limited to what each service requires; reading this policy does not constitute blanket consent.

## 1. Scope and responsible entity

Runlume is developed and operated by Shenzhen TreeDeep Computer Systems Co., Ltd. (“we”). This policy covers personal information we process for the website, accounts, purchases, enquiries, and platform services. Independent apps and third-party providers may also have their own privacy policies.

Organizations remain responsible for customer, employee, and other business data they process in independent systems. We handle such data only within the authorization needed to provide a service or act as a processor. Integration does not automatically give us access to all business data.

## 2. Information we collect

Accounts: depending on the registration, sign-in, or linking method, we record your phone number, email, verification results, account identifier, and the name or company details you provide. These support account creation, authentication, recovery, and necessary notices. Not every service requires both phone and email.

Access and security: we record IP addresses, access times, requested pages, browser or device types, activity and error logs, and network locations such as country, region, or city inferred from IP. These support operation, troubleshooting, risk detection, and security audits. IP-based location is not precise positioning; browsing alone does not request device GPS.

Transactions: we retain purchased items, order references, amounts, payment channels, transaction references or status, refunds, invoicing, and delivery records for confirmation, reconciliation, support, disputes, and statutory retention. Payment credentials are handled by payment providers under their rules; do not send them through enquiry channels.

Enquiries and partnerships: we process names, contact details, requirements, correspondence, and providers’ identity, qualification, and contact documents that are submitted for enquiries, eligibility checks, coordination, and service delivery. Do not submit unrelated sensitive information or other people’s data without authorization.

## 3. Purposes and processing rules

We rely on applicable lawful grounds, including consent, necessity for a contract with you, and legal obligations, and limit processing to defined purposes and necessary data. Changes requiring renewed consent will be explained and consent obtained before the changed processing begins.

Service notices and marketing are handled separately. Marketing uses consent where required and provides an opt-out. Declining optional processing does not prevent use of basic services that do not require that data.

## 4. Cookies and analytics

Where cookies or similar technologies support sign-in, security, or necessary preferences, their use is limited to those purposes. Optional analytics, advertising, or third-party tracking requires information about the provider, purpose, and scope and any legally required consent; it is not bundled with basic services.

Analytics helps us understand page traffic, referral sources, and content usage to improve the website. Use of Google Analytics or GoatCounter follows the disclosures below and any required consent. Continued browsing is not default authorization for optional analytics.

The bottom Cookie notice keeps necessary storage on and offers Google Analytics and GoatCounter separately, both off by default. The localStorage key runlume.cookie-consent stores only choices, version, and confirmation time—not phone, email, or IP. Granted choices persist until site data is cleared or you withdraw them. Necessary-only or closing the initial notice suppresses reminders for six months; a later visit can prompt again.

Language switching uses local storage under runlume.language to remember your manual Simplified Chinese, Traditional Chinese, or English selection until site data is cleared. Without a saved choice, the homepage uses your browser language preferences. If no supported language matches, it reads the network region from a same-origin Cloudflare endpoint to choose a language; the site does not separately store or forward IP information from that response. This setting only controls display language and does not enable optional analytics.

This website loads Google Analytics and GoatCounter scripts only after you authorize each service. Page addresses sent by the website omit query strings and fragments, referrer fields are cleared, and booking or inquiry form contents are not sent. Withdrawal stops the corresponding analytics and clears Google Analytics cookies that this site can remove; it does not automatically erase previously collected server-side data.

Use Cookie settings in the footer at any time to change or withdraw optional permissions. Clearing site data, changing browsers, or private browsing affects persistence. New purposes or material changes requiring renewed consent are prompted separately. Declining analytics does not affect browsing, necessary security, or lawful transaction duties.

Google Analytics (GA4, provided by Google) can process pages, referrers, timestamps, interactions, browser and device details, approximate IP-derived location, and user or session identifiers. Common first-party cookies, _ga and _ga_<container-id>, have a documented default lifetime of two years, subject to site configuration and browser limits. Cookie lifetimes differ from server retention. GA4 can send data without cookies, so blocking cookies alone does not stop all analytics requests.

Google’s IP processing varies by region and settings; it should not be described as never processing IP addresses. Analytics may involve overseas processing under Google’s applicable terms and privacy rules. Advertising integrations and cross-site profiling require additional disclosure and authorization where applicable, separate from basic analytics.

GoatCounter summarizes traffic and referrers. Standard visitor analytics writes no tracking cookies or localStorage. Depending on configuration it processes browser, system, language, screen width, and IP-derived location. Its documentation describes in-memory use of site, IP, and User-Agent for up to eight hours to distinguish repeat visits, without storing raw IP in the analytics database. Cookieless does not mean no network-data processing. The hosted service is operated by Martin Tournoij in Ireland, with storage in Finland and Germany; self-hosted storage follows the deployment arrangement.

We do not send registered phone numbers, email addresses, enquiry content, payment credentials, or identifiable order data as analytics fields, and avoid including them in URLs, query strings, or event labels. Recipients, retention settings, storage locations, and cross-border arrangements must be defined before activation and remain consistent with this policy and authorization.

You can manage cookies and site data in your browser and use Google’s Analytics opt-out add-on in supported browsers. Contact us below to object to analytics, withdraw consent, or request action on related data. Clearing cookies does not automatically delete previously collected data or block cookieless analytics; restricting necessary cookies may affect sign-in.

[Google privacy policy](https://policies.google.com/privacy)

[GA4 cookie documentation](https://support.google.com/analytics/answer/11397207)

[Google Analytics opt-out](https://tools.google.com/dlpage/gaoptout)

[GoatCounter privacy documentation](https://www.goatcounter.com/help/privacy)

## 5. Processors, sharing, and third-party services

We do not sell personal information. Where hosting, communications, payments, maintenance, or other services involve processing on our behalf, we define the purpose, duration, scope, and safeguards and oversee processing within those limits.

Before providing information to an independent third party, we identify the recipient and its contact details, purposes, processing methods, and data categories and obtain separate consent where legally required. Data you provide directly to a provider is governed by your agreement and its privacy rules.

Cross-system calls are limited to authorized tenants, apps, tasks, and data. Before using an agent, skill, or external model, check the destination and necessary input. Do not provide customer data, trade secrets, or sensitive personal information without authority.

Disclosure to authorities and transfers arising from mergers or reorganizations follow applicable legal conditions, notification requirements, safeguards, and assistance obligations.

## 6. Retention and storage

Account data is retained as needed for account services. Enquiry and partnership data is retained for the relevant purpose and necessary follow-up. Other data is kept for the shortest necessary period. Closure, withdrawal, or completion triggers deletion or anonymization where applicable, without overriding statutory retention.

Where e-commerce platform retention rules apply, product, service, and transaction information is retained for at least three years after completion. Network logs, payment vouchers, accounting, and tax records follow their applicable statutory periods. Required retention is restricted to necessary storage, protection, and lawful uses.

Storage locations, hosting providers, and access arrangements are described for the relevant product or deployment. Before using services involving overseas processing, we provide required recipient and processing details, complete applicable procedures, and obtain separate consent where required. This policy is not blanket authorization for cross-border transfers.

## 7. Security and private deployment

We apply risk-appropriate access controls, transmission and storage protection, activity records, and staff controls. Actual or suspected loss, alteration, or disclosure is addressed with remediation and legally required notices. Internet systems cannot offer an absolute security guarantee.

Private deployment allows business systems and data to run in a customer-designated environment. Integration does not mean uploading the entire business database, but authentication, authorized calls, subscriptions, and transactions may still involve platform processing. Remote support, backups, external models, and data leaving the environment must be defined in the deployment plan, authorizations, and agreement.

## 8. Your rights and contact channels

You may request access, copies, correction, completion, deletion, account closure, withdrawal of consent-based permissions, and an explanation of processing rules. Contact us using the email or phone below. We handle requests promptly as required by law after necessary identity checks and explain any refusal. Avoid sending unrelated sensitive documents.

Withdrawal does not invalidate prior processing and may affect dependent features, but not unrelated ones. Legally retained data is subject to processing restrictions. You may also complain to the competent personal information protection authority.

## 9. Minors and policy updates

Runlume primarily serves businesses and users with appropriate legal capacity. Information about children under fourteen is sensitive personal information; any necessary processing requires guardian consent and specific safeguards as required by law. Contact us about unnecessary collection involving minors.

Updates are dated on this page. Material changes to purposes, data categories, sharing, or individual rights are clearly communicated through appropriate channels, with renewed consent where required. Silent updates do not replace notice or authorization.

## Contact us

Shenzhen TreeDeep Computer Systems Co., Ltd.

[shushen@treedeep.cn](mailto:shushen@treedeep.cn)

[+86 131 6991 9969](tel:+8613169919969)

[Terms of service](https://runlume.app/en/terms)

[Disclaimer](https://runlume.app/en/disclaimer)

