LEGAL
Privacy Policy
This Policy explains how the Rolife website collects, uses, shares, retains, and protects personal data, and how you can exercise your rights.
Draft for legal review only; not legal advice. Bracketed items must be confirmed by the operator, legal counsel, or compliance owner before publication.
1. Scope and controller
This Policy applies to the Rolife global brand website, member center, event registration, store locator, search, and other online services that link to it (together, the “Services”).
The controller is [Legal review required: full legal entity name], registered at [address to be confirmed]. Contact: [privacy email to be confirmed]. Regional operating entities must be listed in an applicable regional addendum.
2. Data we collect
- Account and membership data: name, email, verification code, securely stored password credentials, member ID, points, coupons, tier, preferences, and store-source identifier.
- Event registration data: name, phone number, email, verification status, selected event, submission time, status, and necessary operational notes.
- Device and usage data: IP address, browser and device type, language, page requests, error logs, and security audit data. The current release does not deploy advertising or behavioral analytics SDKs.
- Search and local storage data: recent searches, member session state, store identifier, and consent preferences.
- Store and map data: country, city, or postal code entered by you and requests needed to display maps. Maps load only after Functional consent.
- Other data you provide through support, privacy requests, feedback, or event participation.
3. Purposes and legal bases
- Contract and service delivery: create accounts, authenticate users, provide member benefits, register events, and deliver store and content features.
- Consent: enable non-essential maps, optional marketing, and processing that requires separate consent under applicable law.
- Legitimate interests: secure, debug, and improve the Services, subject to balancing tests and objection rights where required.
- Legal obligations: maintain required records, respond to authorities, and process data-subject requests.
4. Sharing and processors
We do not sell personal data. We disclose data only where necessary to hosting, email/verification, mapping, support, security, and professional service providers under appropriate contracts and safeguards.
The currently identified map provider is Google Maps. Loading it may disclose an IP address, device data, and map interactions to Google. The production vendor register, hosting regions, purposes, and retention periods must be completed before launch.
5. International transfers
A global service may transfer data outside your country. We will use recognized safeguards such as standard contractual clauses, assessments, certifications, separate consent, or other lawful mechanisms.
[Legal review required: actual data flows, recipients, storage locations, and transfer mechanisms for Mainland China, the EEA, the UK, California, and other launch regions.]
6. Retention
- Account data: while the account is active and for the minimum period needed after closure for disputes and legal duties.
- Event registration: [retention period to be confirmed] after the event, unless law or disputes require longer.
- Consent records: while valid and afterward as reasonably needed to demonstrate compliance.
- Security and technical logs: generally no longer than [period to be confirmed], subject to incident requirements.
- Search history: on your device until cleared by you or through a site control.
7. Your rights
Depending on applicable law, you may have rights to notice, access, correction, deletion, restriction, objection, withdrawal of consent, portability, review of automated decisions, account closure, and regulatory complaint.
Submit a request through the Member Center privacy-request entry or [privacy email to be confirmed]. We may verify identity and will respond within the applicable deadline. Withdrawal does not affect processing already lawfully performed.
8. Children
Rolife products may appeal to children, but account and event features are not intended to collect children's data without valid parental authorization. If you are below the age at which you can independently consent in your region, a parent or guardian must review and authorize use.
[Legal review required: target audience, minimum account age, parental consent flow, and whether COPPA or other child-data rules apply.] We will delete or regularize data found to have been collected without valid authorization.
9. Security
We use reasonable access controls, transport encryption, secure credential storage, least privilege, audit logging, backups, and incident response. No online service is absolutely secure; legally required incident notices will be provided.
10. Updates and contact
Material changes will be communicated by prominent notice, renewed consent, or another legally required method. Each page displays its version, effective date, and update date.
Privacy and rights: [privacy email]; general support: [support email]; postal address: [address to be confirmed].