This policy explains how Runlume handles personal information. Browsing, registration, purchases, and third-party services involve different data. Processing is limited to what each service requires; reading this policy does not constitute blanket consent.
01Scope and responsible entity
Runlume is developed and operated by Shenzhen TreeDeep Computer Systems Co., Ltd. (“we”). This policy covers personal information we process for the website, accounts, purchases, enquiries, and platform services. Independent apps and third-party providers may also have their own privacy policies.
Organizations remain responsible for customer, employee, and other business data they process in independent systems. We handle such data only within the authorization needed to provide a service or act as a processor. Integration does not automatically give us access to all business data.
02Information we collect
Accounts: depending on the registration, sign-in, or linking method, we record your phone number, email, verification results, account identifier, and the name or company details you provide. These support account creation, authentication, recovery, and necessary notices. Not every service requires both phone and email.
Access and security: we record IP addresses, access times, requested pages, browser or device types, activity and error logs, and network locations such as country, region, or city inferred from IP. These support operation, troubleshooting, risk detection, and security audits. IP-based location is not precise positioning; browsing alone does not request device GPS.
Transactions: we retain purchased items, order references, amounts, payment channels, transaction references or status, refunds, invoicing, and delivery records for confirmation, reconciliation, support, disputes, and statutory retention. Payment credentials are handled by payment providers under their rules; do not send them through enquiry channels.
Enquiries and partnerships: we process names, contact details, requirements, correspondence, and providers’ identity, qualification, and contact documents that are submitted for enquiries, eligibility checks, coordination, and service delivery. Do not submit unrelated sensitive information or other people’s data without authorization.
03Purposes and processing rules
We rely on applicable lawful grounds, including consent, necessity for a contract with you, and legal obligations, and limit processing to defined purposes and necessary data. Changes requiring renewed consent will be explained and consent obtained before the changed processing begins.
Service notices and marketing are handled separately. Marketing uses consent where required and provides an opt-out. Declining optional processing does not prevent use of basic services that do not require that data.
06Retention and storage
Account data is retained as needed for account services. Enquiry and partnership data is retained for the relevant purpose and necessary follow-up. Other data is kept for the shortest necessary period. Closure, withdrawal, or completion triggers deletion or anonymization where applicable, without overriding statutory retention.
Where e-commerce platform retention rules apply, product, service, and transaction information is retained for at least three years after completion. Network logs, payment vouchers, accounting, and tax records follow their applicable statutory periods. Required retention is restricted to necessary storage, protection, and lawful uses.
Storage locations, hosting providers, and access arrangements are described for the relevant product or deployment. Before using services involving overseas processing, we provide required recipient and processing details, complete applicable procedures, and obtain separate consent where required. This policy is not blanket authorization for cross-border transfers.
07Security and private deployment
We apply risk-appropriate access controls, transmission and storage protection, activity records, and staff controls. Actual or suspected loss, alteration, or disclosure is addressed with remediation and legally required notices. Internet systems cannot offer an absolute security guarantee.
Private deployment allows business systems and data to run in a customer-designated environment. Integration does not mean uploading the entire business database, but authentication, authorized calls, subscriptions, and transactions may still involve platform processing. Remote support, backups, external models, and data leaving the environment must be defined in the deployment plan, authorizations, and agreement.
08Your rights and contact channels
You may request access, copies, correction, completion, deletion, account closure, withdrawal of consent-based permissions, and an explanation of processing rules. Contact us using the email or phone below. We handle requests promptly as required by law after necessary identity checks and explain any refusal. Avoid sending unrelated sensitive documents.
Withdrawal does not invalidate prior processing and may affect dependent features, but not unrelated ones. Legally retained data is subject to processing restrictions. You may also complain to the competent personal information protection authority.
09Minors and policy updates
Runlume primarily serves businesses and users with appropriate legal capacity. Information about children under fourteen is sensitive personal information; any necessary processing requires guardian consent and specific safeguards as required by law. Contact us about unnecessary collection involving minors.
Updates are dated on this page. Material changes to purposes, data categories, sharing, or individual rights are clearly communicated through appropriate channels, with renewed consent where required. Silent updates do not replace notice or authorization.
Questions? Get in touch
For questions about personal information, transactions, contracts, or your rights:
Shenzhen TreeDeep Computer Systems Co., Ltd.深圳市树深计算机系统有限公司[email protected]+86 131 6991 9969Visit our contact page