Privacy policy
How we process personal information
This policy covers browsing and contact forms on dataflowforever.com, plus Meta Ads connection, authorization, and Conversions API features provided by Hangzhou DataFlowForever Technology Co., Ltd. A client data-processing agreement controls where it provides more specific terms.
Controller: Hangzhou DataFlowForever Technology Co., Ltd. · Contact: wusu@dataflowforever.com
Last updated: July 12, 2026
1. Scope and our role
For website inquiries, business contact, and our own Meta connection records, we generally determine the purpose and means of processing as the controller or personal information processor.
When we transmit a merchant's customer events through Meta Conversions API under the merchant's instructions, the merchant is generally the controller and we act as its processor or entrusted party within the agreement and configuration.
2. Information we may process
The categories depend on the feature you use. Browsing this site alone does not grant us access to your advertising accounts.
- Website inquiries: company, name, email, WeChat, site, offer intent, selected services, problem description, source page, referrer, UTM values, consent, and processing status.
- Technical and security data: hosting, security, and abuse-prevention systems may temporarily process IP address, browser, device, time, and request logs; the lead record does not store the raw IP address.
- Meta connections: Meta app-scoped user ID, authorized Business, Page, ad-account or pixel identifiers, permissions, token and expiry information, connection status, and necessary audit records.
- Conversions API: merchant-configured event name, time, source, page or transaction context, and normalized or hashed matching identifiers. The exact fields are set by merchant configuration and contract.
3. Purposes and legal bases
We process information to answer inquiries, assess fit, provide requested features, maintain authorized connections, transmit merchant-configured events, secure the service, prevent duplicate or abusive activity, perform contracts, and comply with law.
Depending on the context, the legal basis may be consent, steps requested before a contract, performance of a contract, legal obligation, or legitimate operational and security interests where permitted. We obtain separate or written consent when applicable law requires it.
4. Cookies and website tracking
This website currently does not deploy Meta Pixel, third-party advertising cookies, or cross-site behavioral profiling. Your language choice may be stored locally in the browser to preserve the selected version.
If we add non-essential analytics, advertising, or behavioral tracking, we will update this policy first and provide consent controls where required.
5. Sharing, processors, and sale
We share or entrust information only as needed to cloud hosting, database, email notification, security, and platform providers, with contractual, access, and security limits. Meta features interact with Meta Platforms under your authorization or the merchant's instructions.
We do not sell personal information or provide client and lead data to third parties for their independent advertising profiles or public-model training. We may disclose necessary information when legally required or to resolve disputes and protect lawful interests.
6. International processing
Platforms and providers used in cross-border commerce may operate in different countries or regions. We identify the actual data flow, location, and applicable requirements before using contracts, assessments, certifications, separate consent, or other required safeguards.
Where a client project involves transfers beyond this general notice, project documents or a separate notice will identify the recipient, purpose, data categories, and rights channel as required.
7. Retention
Website inquiries that do not become a client relationship are generally retained for 24 months after the last substantive interaction. Client records are retained as needed for contract, tax, dispute, and legal obligations.
Verified Meta deletion or disconnect requests are generally completed within 30 days. Restricted backups may remain for up to 90 days after active-system deletion and are removed through backup rotation. Security logs and legally required records are kept for the shortest necessary period.
8. Your rights
Subject to applicable law, you may request notice, access, a copy, correction, completion, restriction or objection, withdrawal of consent, deletion, Meta disconnection, explanation, or complaint. Withdrawing consent does not affect prior lawful processing.
We verify identity and scope before responding. For merchant customer events, requests should normally begin with the merchant that collected the information; we assist that merchant with its obligations.
9. Security, children, and updates
We use access controls, tenant isolation, transport protection, audit records, key management, and appropriate masking, but no networked system can guarantee absolute security. We handle and notify relevant incidents as required by law.
The site and services are for business users and are not directed to children under 18. We may update this policy as features, providers, or laws change, with the date shown here and additional notice for material changes where appropriate.
Access, correction, deletion, or disconnection
Use the public data-request workflow or contact us by email. For Meta authorization, disconnection also attempts to revoke the related permissions and stop future synchronization.
Open data deletion and rights requests