Legal

Privacy Policy

Version 1.0 · Effective and last updated August 31, 2026

This Policy explains how Muleverse Digital handles personal information across the software, websites, subscriptions, downloadable products, online libraries, and other digital services that link to it.

Muleverse Digital respects your privacy. This Privacy Policy (“Policy”) describes what personal information we collect, why we use it, how long we keep it, when we share it, and the choices and rights available to you. It applies to our websites, applications, software-as-a-service products, downloadable materials, member content, support, and related services that link to this Policy (collectively, the “Services”).

Our Terms of Service contain additional rules for using the Services. We may update this Policy as described in Section 13.

1. Data controller and business-customer roles

1.1 Data controller

The controller responsible for account, purchase, website, marketing, support, and direct-customer information is:

1.2 Data submitted by business customers

Some business Services allow customers to upload or enter information about their employees, contractors, clients, contacts, accounts, projects, payroll, documents, or other records (“Customer Data”). For Customer Data, the business customer generally determines the purposes and means of processing and acts as controller or business; we generally act as its processor or service provider. The customer is responsible for providing required notices, obtaining permissions, responding to individuals, and configuring access and retention. Requests about Customer Data should normally be directed to the customer that supplied it; we will assist that customer as required by contract and law.

2. Personal information we collect

2.1 Information you provide

2.2 Information collected automatically

We do not intentionally collect precise geolocation, biometric identifiers, or information from consumer data brokers. A particular business Service may process sensitive Customer Data only when a customer submits it for that Service; applicable product instructions may prohibit specific data, such as full Social Security numbers.

3. How and why we use personal information

PurposeExamplesLegal basis where required
Provide the ServicesCreate accounts, deliver downloads, host workspaces, process Customer Data, and provide requested integrations.Performance of a contract
Billing and ordersComplete checkout, manage subscriptions, maintain transaction records, and process refunds.Performance of a contract; legal obligation
Support and communicationsAnswer requests and send essential account, security, billing, policy, or service notices.Performance of a contract; legitimate interests
Security and abuse preventionAuthenticate users, keep audit trails, scan permitted uploads, detect fraud, and investigate incidents.Legitimate interests; legal obligation
Operate and improveDebug errors, monitor reliability, understand aggregate usage, and improve product design.Legitimate interests; consent where required
Legal complianceMaintain tax or accounting records, respond to lawful requests, and enforce agreements.Legal obligation; legitimate interests
Optional marketingSend product news or offers only where you have opted in or applicable law otherwise permits.Consent; legitimate interests where permitted

We may create aggregated or de-identified information for analytics, security, and product improvement. We will not attempt to re-identify information maintained in de-identified form.

4. Cookies and similar technologies

CategoryPurposeCan be disabled?
Strictly necessaryAuthentication, security, session continuity, checkout, fraud prevention, and core functions.Not through a consent control; blocking them may break the Service.
FunctionalRemember language, display, and product preferences.Yes, through browser or available preference controls.
AnalyticsMeasure aggregate traffic, errors, and feature use where a Service has enabled analytics.Yes where consent is required.

We do not use advertising cookies or behavioral-advertising pixels unless a product-specific notice and any legally required consent control state otherwise. The particular cookies and analytics provider, if any, should be identified in that Service’s cookie notice. You can also control cookies through your browser, although disabling necessary storage may prevent login or checkout.

5. Sharing and disclosure

We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. We disclose information only as needed for the following purposes:

We require service providers to use personal information only for contracted purposes and to apply appropriate confidentiality and security protections.

6. Security

We use safeguards designed for the nature of the information and Service, including HTTPS/TLS in transit; hashed passwords; access controls and authorization checks; private storage for customer files; audit logging; credential and secret management; file-type validation and security scanning where supported; backups; and dependency, vulnerability, and incident-response practices.

No system is completely secure. You must protect credentials, use appropriate permissions, and avoid submitting information prohibited by the relevant Service. If we become aware of a breach requiring notice, we will notify affected users and regulators within the period required by applicable law. Where the GDPR applies, we aim to notify the competent authority within 72 hours after becoming aware of a reportable breach.

7. Retention

InformationRetention periodEnd-of-period action
Account and profile dataWhile the account is active, then 90 days after closure.Delete or de-identify, except records subject to another period below.
Customer Data and filesAccording to the Service or workspace retention setting; otherwise no more than 90 days after account termination.Delete from active systems, subject to legal hold and backup expiry.
Transactions, invoices, tax and accounting recordsSeven years after the transaction or longer if local law requires.Securely archive, then delete or de-identify.
Support and dispute recordsTwo years after the request closes; chargeback evidence may follow the transaction period.Delete or de-identify.
Security and audit logs12 months unless needed for an investigation, dispute, or legal obligation.Delete or aggregate.
BackupsUp to 35 days after deletion from active systems.Expire through the backup rotation.
Marketing preferencesUntil consent is withdrawn; minimal suppression records may be retained to honor opt-outs.Delete nonessential marketing data and retain the opt-out signal.

We may retain information longer where necessary for a legal claim, fraud investigation, tax or accounting obligation, enforceable customer instruction, or legal hold. When no longer required, we delete, de-identify, or securely isolate it.

8. Your privacy rights

Depending on your location and our role, you may have the right to:

Submit a request to [email protected]. Describe the Service and account involved. We may verify your identity and authority before acting. We aim to respond within 30 calendar days, or within another period required by applicable law. If Customer Data was provided by an organization, contact that organization first; we will assist it as appropriate.

You may also complain to your local data-protection or privacy authority. We will not discriminate against you for exercising a privacy right.

9. Marketing communications

Where required, we send marketing only with your consent. You can opt out using the unsubscribe link in a marketing email or by contacting [email protected]. Opting out of marketing does not stop essential transactional communications such as receipts, subscription notices, security alerts, service messages, or policy updates.

10. International transfers

We are based in China and may use service providers or infrastructure in China, the United States, the European Economic Area, and other locations where our providers operate. Your information may therefore be processed outside your country, where privacy laws may differ.

Where required, we use recognized transfer safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or another lawful mechanism, together with contractual, organizational, and technical protections.

11. Children

The Services are intended for adults and business users aged 18 or older. We do not knowingly collect personal information directly from anyone under 18. If you believe a minor has provided personal information without appropriate authorization, contact [email protected] so we can investigate and delete it where required.

12. Third-party services and links

The Services may link to or integrate with independent websites and services. Their handling of information is governed by their own policies. Review those policies before directing us to send data to an integration or leaving our Services. This Policy does not apply to information an independent third party collects for its own purposes.

13. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. We will post the revised Policy and update the date above. For material changes, we will provide at least 15 days’ advance notice through email, an in-product message, or a prominent website notice, unless law, security, or urgent circumstances require otherwise. We will retain version records sufficient to identify the policy that applied at a given time.

14. Contact us

Brand: Muleverse Digital

Legal entity and controller: 深圳市木乐宇宙贸易有限公司

Registered and mailing address: Kingdee Software Park, No. 2 Keji South 12th Road, Nanshan District, Shenzhen, Guangdong, China 521000

Privacy and rights requests: [email protected]

Customer support: [email protected]

Support hours: Monday–Friday, 09:00–18:00 China Standard Time (UTC+8), excluding public holidays