Legal
Privacy Policy
This Policy explains how Muleverse Digital handles personal information across the software, websites, subscriptions, downloadable products, online libraries, and other digital services that link to it.
Muleverse Digital respects your privacy. This Privacy Policy (“Policy”) describes what personal information we collect, why we use it, how long we keep it, when we share it, and the choices and rights available to you. It applies to our websites, applications, software-as-a-service products, downloadable materials, member content, support, and related services that link to this Policy (collectively, the “Services”).
Our Terms of Service contain additional rules for using the Services. We may update this Policy as described in Section 13.
1. Data controller and business-customer roles
1.1 Data controller
The controller responsible for account, purchase, website, marketing, support, and direct-customer information is:
- Legal entity: 深圳市木乐宇宙贸易有限公司
- Trading brand: Muleverse Digital
- Registered address: Kingdee Software Park, No. 2 Keji South 12th Road, Nanshan District, Shenzhen, Guangdong, China 521000
- Privacy contact: privacy@muleversedigital.com
- Data Protection Officer: Not appointed; privacy requests are handled through the privacy contact above.
1.2 Data submitted by business customers
Some business Services allow customers to upload or enter information about their employees, contractors, clients, contacts, accounts, projects, payroll, documents, or other records (“Customer Data”). For Customer Data, the business customer generally determines the purposes and means of processing and acts as controller or business; we generally act as its processor or service provider. The customer is responsible for providing required notices, obtaining permissions, responding to individuals, and configuring access and retention. Requests about Customer Data should normally be directed to the customer that supplied it; we will assist that customer as required by contract and law.
2. Personal information we collect
2.1 Information you provide
- Account and profile data: name, email address, password credential in hashed form, organization, workspace, role, and preferences.
- Purchase and billing data: product, plan, transaction identifier, amount, currency, tax information, billing status, subscription status, and limited billing details received from our payment provider. We do not store full payment-card numbers.
- Customer Data and files: information, documents, spreadsheets, PDFs, images, templates, project records, payroll or wage records, client document requests, and other content you choose to submit to a Service. The exact fields depend on the product.
- Communications: support messages, refund or cancellation requests, survey responses, feedback, and related correspondence.
- Integration data: identifiers, authorization tokens, folder or file metadata, and content needed to provide an integration you choose to connect. We use integration data only to provide and secure the requested connection.
2.2 Information collected automatically
- Device and network data: IP address, browser type, device and operating-system information, language, time zone, and approximate region inferred from IP.
- Usage and event data: pages viewed, feature interactions, referring page, timestamps, session activity, download and access events, and subscription or checkout events.
- Security and operational logs: authentication events, audit records, request metadata, error logs, performance data, fraud indicators, and malware or file-validation results where a Service accepts uploads.
- Cookies and local storage: identifiers needed for authentication, security, checkout, preferences, and permitted analytics as described in Section 4.
We do not intentionally collect precise geolocation, biometric identifiers, or information from consumer data brokers. A particular business Service may process sensitive Customer Data only when a customer submits it for that Service; applicable product instructions may prohibit specific data, such as full Social Security numbers.
3. How and why we use personal information
| Purpose | Examples | Legal basis where required |
|---|---|---|
| Provide the Services | Create accounts, deliver downloads, host workspaces, process Customer Data, and provide requested integrations. | Performance of a contract |
| Billing and orders | Complete checkout, manage subscriptions, maintain transaction records, and process refunds. | Performance of a contract; legal obligation |
| Support and communications | Answer requests and send essential account, security, billing, policy, or service notices. | Performance of a contract; legitimate interests |
| Security and abuse prevention | Authenticate users, keep audit trails, scan permitted uploads, detect fraud, and investigate incidents. | Legitimate interests; legal obligation |
| Operate and improve | Debug errors, monitor reliability, understand aggregate usage, and improve product design. | Legitimate interests; consent where required |
| Legal compliance | Maintain tax or accounting records, respond to lawful requests, and enforce agreements. | Legal obligation; legitimate interests |
| Optional marketing | Send product news or offers only where you have opted in or applicable law otherwise permits. | Consent; legitimate interests where permitted |
We may create aggregated or de-identified information for analytics, security, and product improvement. We will not attempt to re-identify information maintained in de-identified form.
6. Security
We use safeguards designed for the nature of the information and Service, including HTTPS/TLS in transit; hashed passwords; access controls and authorization checks; private storage for customer files; audit logging; credential and secret management; file-type validation and security scanning where supported; backups; and dependency, vulnerability, and incident-response practices.
No system is completely secure. You must protect credentials, use appropriate permissions, and avoid submitting information prohibited by the relevant Service. If we become aware of a breach requiring notice, we will notify affected users and regulators within the period required by applicable law. Where the GDPR applies, we aim to notify the competent authority within 72 hours after becoming aware of a reportable breach.
7. Retention
| Information | Retention period | End-of-period action |
|---|---|---|
| Account and profile data | While the account is active, then 90 days after closure. | Delete or de-identify, except records subject to another period below. |
| Customer Data and files | According to the Service or workspace retention setting; otherwise no more than 90 days after account termination. | Delete from active systems, subject to legal hold and backup expiry. |
| Transactions, invoices, tax and accounting records | Seven years after the transaction or longer if local law requires. | Securely archive, then delete or de-identify. |
| Support and dispute records | Two years after the request closes; chargeback evidence may follow the transaction period. | Delete or de-identify. |
| Security and audit logs | 12 months unless needed for an investigation, dispute, or legal obligation. | Delete or aggregate. |
| Backups | Up to 35 days after deletion from active systems. | Expire through the backup rotation. |
| Marketing preferences | Until consent is withdrawn; minimal suppression records may be retained to honor opt-outs. | Delete nonessential marketing data and retain the opt-out signal. |
We may retain information longer where necessary for a legal claim, fraud investigation, tax or accounting obligation, enforceable customer instruction, or legal hold. When no longer required, we delete, de-identify, or securely isolate it.
8. Your privacy rights
Depending on your location and our role, you may have the right to:
- know whether and how we process your personal information;
- access and receive a copy of it;
- correct inaccurate or incomplete information;
- request deletion in applicable circumstances;
- restrict or object to certain processing;
- receive portable information in a structured, commonly used format;
- withdraw consent without affecting prior lawful processing;
- opt out of marketing, sale, sharing, or targeted advertising where applicable; and
- appeal a denied request where applicable law provides that right.
Submit a request to privacy@muleversedigital.com. Describe the Service and account involved. We may verify your identity and authority before acting. We aim to respond within 30 calendar days, or within another period required by applicable law. If Customer Data was provided by an organization, contact that organization first; we will assist it as appropriate.
You may also complain to your local data-protection or privacy authority. We will not discriminate against you for exercising a privacy right.
9. Marketing communications
Where required, we send marketing only with your consent. You can opt out using the unsubscribe link in a marketing email or by contacting support@muleversedigital.com. Opting out of marketing does not stop essential transactional communications such as receipts, subscription notices, security alerts, service messages, or policy updates.
10. International transfers
We are based in China and may use service providers or infrastructure in China, the United States, the European Economic Area, and other locations where our providers operate. Your information may therefore be processed outside your country, where privacy laws may differ.
Where required, we use recognized transfer safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or another lawful mechanism, together with contractual, organizational, and technical protections.
11. Children
The Services are intended for adults and business users aged 18 or older. We do not knowingly collect personal information directly from anyone under 18. If you believe a minor has provided personal information without appropriate authorization, contact privacy@muleversedigital.com so we can investigate and delete it where required.
12. Third-party services and links
The Services may link to or integrate with independent websites and services. Their handling of information is governed by their own policies. Review those policies before directing us to send data to an integration or leaving our Services. This Policy does not apply to information an independent third party collects for its own purposes.
13. Changes to this Policy
We may update this Policy to reflect product, legal, or operational changes. We will post the revised Policy and update the date above. For material changes, we will provide at least 15 days’ advance notice through email, an in-product message, or a prominent website notice, unless law, security, or urgent circumstances require otherwise. We will retain version records sufficient to identify the policy that applied at a given time.
14. Contact us
Brand: Muleverse Digital
Legal entity and controller: 深圳市木乐宇宙贸易有限公司
Registered and mailing address: Kingdee Software Park, No. 2 Keji South 12th Road, Nanshan District, Shenzhen, Guangdong, China 521000
Privacy and rights requests: privacy@muleversedigital.com
Customer support: support@muleversedigital.com
Support hours: Monday–Friday, 09:00–18:00 China Standard Time (UTC+8), excluding public holidays