隐私政策
最后更新:2025年12月16日
生效日期:立即生效
运营主体:arkvol.com域名持有者(个人开发者)
1. 信息收集范围
我们收集的最小化信息:
账户信息(必需):
- 邮箱地址(用于登录、通知、邀请码发送)
- 用户名(昵称,可自定义)
- 密码加密存储(使用bcrypt,无法查看或还原)
捐赠信息(如适用):
- Buy Me a Coffee平台传递的捐赠金额(不存储支付详情)
- 邮箱地址(用于发送邀请码)
技术日志(自动收集):
- IP地址(用于安全审计、地域限制)
- 浏览器User-Agent(用于兼容性优化)
- 访问时间戳、页面URL(用于匿名化分析)
我们坚决不收集:
- ❌ 任何第三方应用的持仓数据(股票、基金具体持有)
- ❌ 交易记录(个人买卖历史)
- ❌ 金融资产信息(账户余额、净资产)
- ❌ 身份证、护照等实名信息
- ❌ 手机号码(除非您主动提供)
2. 信息使用目的
严格限定用途:
- ✅ 账户认证:验证身份、发送登录通知
- ✅ 邀请码发放:捐赠后发送邀请码邮件
- ✅ 服务通知:功能更新、服务变更(极少发送,可退订)
- ✅ 安全审计:检测异常登录、防止滥用
- ✅ 服务改进:基于匿名日志分析使用习惯
我们不会:
- ❌ 向任何第三方出售您的信息
- ❌ 使用您的信息做商业营销
- ❌ 将您的邮箱用于非本项目相关的推广
- ❌ 分析或查看您的具体使用行为(如查看了哪些股票)
3. 信息共享与披露
严格保密原则:
可能共享给:
- ✅ 邮件服务商(如SendGrid):仅用于发送验证邮件和通知
- ✅ 服务器提供商(如Vultr/AWS):仅用于托管网站和数据库
- ✅ CDN服务商(如Cloudflare):仅用于加速和防护
绝不共享给:
- ❌ 广告商或数据分析公司
- ❌ 数据经纪人
- ❌ 任何金融机构
- ❌ 未授权的第三方
法律强制披露:
仅在收到有效法院传票或执法机构正式要求时,才可能披露必要信息。我们将尽可能保护您的隐私。
4. 数据存储与安全
存储位置:
- 主服务器:美国纽约(Vultr/AWS)
- 数据库:PostgreSQL,独立服务器
- 备份:加密备份至AWS S3(每日1次)
安全措施:
- ✅ 传输加密:全站强制HTTPS(TLS 1.3)
- ✅ 密码加密:bcrypt算法,加盐存储
- ✅ 数据库加密:静态数据加密(AES-256)
- ✅ 访问控制:严格限制服务器和数据库访问权限
- ✅ 日志保留:访问日志保留30天后自动删除
安全承诺:
作为个人开发者,我们尽力采取行业标准安全措施,但无法保证100%安全。互联网传输和存储存在固有风险。
5. 您的权利与控制
您拥有以下权利:
- ✅ 查看权:登录账户后可查看您的注册邮箱和用户名
- ✅ 更正权:可在账户设置修改用户名(邮箱修改需验证)
- ✅ 删除权:可永久删除账户,所有数据将在30天内清除
- ✅ 导出权:可请求导出您的账户数据(JSON格式,72小时内发送)
- ✅ 退订权:可退订所有非必要的邮件通知
行使权利方式:
- 登录后访问"账户设置"页面
- 或发送邮件至 legal@arkvol.com(响应时间3个工作日)
账户删除:
- 删除后无法恢复,邀请码失效
- 捐赠记录不删除(需保留财务记录),但会匿名化
6. Cookie与追踪技术
我们使用的Cookie:
必要Cookie(无法禁用):
- 会话ID:维持登录状态
- CSRF Token:防止跨站请求伪造
- 语言偏好:保存您的语言设置
分析Cookie(可选,默认关闭):
- 使用Cloudflare Web Analytics(隐私优先,不收集个人标识)
- 如未来启用Google Analytics,将使用IP匿名化和无Cookie模式
您可控制:
- 浏览器设置可禁用非必要Cookie
- 但禁用可能导致部分功能不可用(如保持登录)
请勿追踪(DNT):
我们尊重浏览器的DNT设置,不追踪您的跨站行为。
7. 儿童隐私保护
年龄限制:
- 本服务不向13岁以下儿童提供
- 我们不会故意收集儿童信息
家长权利:
- 如发现子女注册,请立即联系 legal@arkvol.com
- 我们将在24小时内删除账户并清除所有数据
8. 数据保留期限
账户活跃期间:
- 保留账户信息、捐赠记录、邀请码记录
- 保留30天内的访问日志(用于安全审计)
账户删除后:
- 账户信息:30天内永久删除
- 捐赠记录:保留但匿名化(财务合规)
- 技术日志:30天后自动删除
匿名化数据:
匿名化统计数据可长期保留用于服务改进
9. 国际数据传输
跨境传输说明:
- 服务器在美国,数据会跨境传输
- 如您在欧洲经济区(EEA),数据将传输至美国
- 我们不依赖欧盟-美国隐私盾,而是采用标准合同条款和最小化数据原则保护您的隐私
10. 政策更新通知
更新方式:
- 重大更新(影响您的权利)将邮件通知(提前7天)
- 一般更新将在网站发布公告
- 更新后立即生效
查看历史版本:
本页面底部提供历史版本链接
不同意更新:
- 您可发送邮件至 legal@arkvol.com 申请账户删除
- 继续使用视为接受更新
11. 联系我们
隐私官:arkvol.com运营者
联系邮箱:legal@arkvol.com
响应时间:3个工作日内(个人开发者,请理解)
特别说明:
本项目无专职客服团队,隐私相关请求将通过邮件处理。
12. 法律管辖
适用法律:香港特别行政区法律(以对运营者更有利方式解释)
争议解决:任何争议须提交香港国际仲裁中心(HKIAC)按其现行规则仲裁,您放弃集体诉讼权利。
- 仲裁地:香港
- 仲裁语言:中文或英文(由运营者选择)
- 仲裁裁决为终局,对双方有约束力
管辖地:香港国际仲裁中心所在地
放弃集体诉讼:
您明确放弃参与集体诉讼权利,同意以个人仲裁方式解决纠纷。
重要声明
生效日期:2025年12月16日
版本:个人开发者版1.0
运营者信息:
运营主体:arkvol.com个人持有者
邮箱:legal@arkvol.com
项目性质:个人技术实践项目
重要提示:本项目由个人开发者利用业余时间运营,数据保护措施尽力但非商业级。使用本服务即代表您理解并接受相关隐私风险。
Privacy Policy
Last Updated: December 16, 2025
Effective Date: Immediately
Operating Entity: arkvol.com Domain Holder (Individual Developer)
1. Data Collection Scope
We collect minimal information necessary for operation:
Account Information (Required):
- Email address (for login, notifications, and invitation codes)
- Username (Display name, customizable)
- Encrypted Passwords (Stored using bcrypt; cannot be viewed or reversed)
Donation Information (If applicable):
- Donation Amount transmitted via Buy Me a Coffee (payment details are not stored)
- Email address (used to send invitation codes)
Technical Logs (Automatically collected):
- IP Address (for security auditing and geographic restrictions)
- Browser User-Agent (for compatibility optimization)
- Timestamps and Page URLs (for anonymized usage analysis)
Information we STRICTLY DO NOT collect:
- ❌ Portfolio data from third-party apps (stocks, funds held)
- ❌ Transaction history (personal buy/sell records)
- ❌ Financial asset info (account balances, net worth)
- ❌ Government identification (ID, Passport, etc.)
- ❌ Phone numbers (unless proactively provided)
2. Use of Information
Restricted Use Policy:
- ✅ Account Authentication: Verifying identity and sending login alerts
- ✅ Invitation Code Issuance: Sending automated emails after donations
- ✅ Service Notifications: Rare updates or policy changes (opt-out available)
- ✅ Security Auditing: Detecting unusual activity and preventing abuse
- ✅ Service Improvement: Analyzing anonymized logs to improve UI/UX
We WILL NOT:
- ❌ Sell your personal information to third parties
- ❌ Use your information for commercial marketing
- ❌ Use your email for non-project related promotions
- ❌ Analyze your specific market behavior (e.g., tracking specific stocks viewed)
3. Information Sharing & Disclosure
Strict Confidentiality:
We may share data with:
- ✅ Email Providers (e.g., SendGrid): Strictly for verification and notification emails
- ✅ Server Providers (e.g., Vultr/AWS): For hosting the website and database
- ✅ CDN Providers (e.g., Cloudflare): For acceleration and DDoS protection
We NEVER share data with:
- ❌ Advertisers or data analytics firms
- ❌ Data brokers
- ❌ Financial institutions
- ❌ Unauthorized third parties
Mandatory Disclosure:
Information will only be disclosed if required by a valid court order or formal law enforcement request. We will advocate for your privacy to the fullest extent possible.
4. Data Storage & Security
Storage Locations:
- Main Server: New York, USA (Vultr/AWS)
- Database: PostgreSQL on an independent server
- Backups: Encrypted daily backups to AWS S3
Security Measures:
- ✅ Transmission Encryption: Site-wide HTTPS forced (TLS 1.3)
- ✅ Password Encryption: Salted bcrypt hashing
- ✅ Database Encryption: Encryption-at-rest (AES-256)
- ✅ Access Control: Strictly limited permissions for server/DB access
- ✅ Log Retention: Access logs are automatically deleted after 30 days
Security Commitment:
As an individual developer, we implement industry-standard security measures, but cannot guarantee 100% security. Online transmission and storage involve inherent risks.
5. Your Rights & Control
You have the following rights:
- ✅ Right to Access: View your registered email and username after login
- ✅ Right to Rectify: Modify your username in account settings (email change requires verification)
- ✅ Right to Erasure: Permanently delete your account; all data cleared within 30 days
- ✅ Right to Portability: Request account data export (JSON format, sent within 72 hours)
- ✅ Right to Opt-out: Unsubscribe from all non-essential notifications
Exercising Your Rights:
- Visit the "Account Settings" page after logging in
- Or email legal@arkvol.com (Response time: 3 business days)
Account Deletion:
- Deletion is irreversible and invitation codes become void
- Donation records are retained but anonymized for financial compliance
6. Cookies & Tracking
Cookies we use:
Essential Cookies (Cannot be disabled):
- Session ID: To maintain login status
- CSRF Token: To prevent Cross-Site Request Forgery
- Language Preference: To store your UI settings
Analytics Cookies (Optional, disabled by default):
- Cloudflare Web Analytics: Privacy-first analytics without individual identifiers
- Any future use of Google Analytics will employ IP Anonymization and Cookieless Mode
Your Control:
- You may disable non-essential cookies via browser settings
- Note: Disabling essential cookies may break core site functionality
Do Not Track (DNT):
We respect browser DNT settings and do not track your cross-site behavior.
7. Children's Privacy
Age Restrictions:
- This service is not intended for children under 13
- We do not knowingly collect information from children
Parental Rights:
- If you discover your child has registered, contact legal@arkvol.com immediately
- We will delete the account and clear all data within 24 hours
8. Data Retention
While Account is Active:
- Account info, donation history, and invitation code logs are retained
- Access logs are kept for 30 days for security auditing
After Account Deletion:
- Account Info: Permanently deleted within 30 days
- Donation Records: Retained but anonymized for compliance
- Technical Logs: Deleted automatically after 30 days
Anonymized Data:
Aggregated, anonymized statistics may be kept indefinitely for service improvement
9. International Data Transfers
Cross-border Transfer Notice:
- Servers are located in the USA; data will be transferred across borders
- If you are in the European Economic Area (EEA), your data will be transferred to the USA
- We rely on Standard Contractual Clauses (SCCs) and Data Minimization principles to protect your privacy
10. Policy Updates
Notification Methods:
- Major updates (affecting your rights) via email (7-day notice)
- General updates via site announcements
- Updates are effective immediately upon posting
Historical Versions:
Archive links are provided at the bottom of this page
Disagreement:
- You may request account deletion via legal@arkvol.com
- Continued use constitutes acceptance of updated policies
11. Contact Information
Privacy Officer: arkvol.com Operator
Email: legal@arkvol.com
Response Time: Within 3 business days
Note: There is no dedicated support team; privacy requests are handled via email by the developer.
12. Governing Law
Applicable Law: Laws of the Hong Kong Special Administrative Region (interpreted in favor of the operator).
Dispute Resolution: Disputes shall be submitted to the Hong Kong International Arbitration Centre (HKIAC) under its current rules. You waive any right to class action.
- Place of Arbitration: Hong Kong
- Language: Chinese or English (at the operator's discretion)
- Awards are final and binding
Class Action Waiver:
You explicitly waive the right to participate in class actions and agree to individual arbitration.
Important Declaration
Effective Date: December 16, 2025
Version: Individual Developer Edition 1.0
Operator Info:
Owner: arkvol.com Individual Holder
Email: legal@arkvol.com
Nature: Personal Technical Practice Project
Crucial Note: This project is operated by an individual in their spare time. Security measures are best-effort and not commercial-grade. Use of the service constitutes acceptance of associated privacy risks.