1. Scope & Controller
This Privacy Policy applies to quanqiusb.com and any website, mobile application, or service operated by Global Association of Master and Doctor Co., Limited ("GAMD", "we", "us", "our"), including the GAMD mobile management application published on Google Play and the Apple App Store.
The data controller is:
Global Association of Master and Doctor Co., Limited
Rm 101A 1/F GENPLAS INDL BLDG, 56 HOI YUEN RD, Kwun Tong, Hong Kong
Email: support@quanqiusb.com
Where required by law (e.g. for users in the European Economic Area, the United Kingdom, or California), we also identify or appoint local representatives — see Regional Compliance for details.
2. Information We Collect
We collect information in three ways: (a) you give it to us directly, (b) we collect it automatically when you use our services, and (c) we receive it from third parties (such as app stores and advertising partners).
2.1 Information you provide
- Account information: name, email, password (hashed), profile photo, role, organization, country.
- Application / event information: research abstracts, biography, project descriptions, files you upload.
- Communications: messages you send us via forms, email, or in-app chat; survey responses.
- Payment information (where applicable): handled by our payment processor (e.g. Stripe, Apple Pay, Google Pay); we do not store full card numbers on our servers.
2.2 Information collected automatically
- Device & connection: IP address, device type, operating system version, device identifiers (IDFA, GAID, IDFV), browser type, language, time zone, mobile carrier.
- Usage: pages viewed, buttons tapped, in-app screens visited, features used, session duration, referrer and exit URLs, crash logs and diagnostic data.
- Approximate location: country, region, city derived from IP (not precise GPS unless you explicitly grant permission).
- Advertising identifiers and signals: Apple's Identifier for Advertising (IDFA) only after you grant App Tracking Transparency permission; Google Advertising ID (GAID) with opt-out respected; limit ad tracking signals.
- Cookies and similar technologies: see Cookies & Tracking.
2.3 Information from third parties
- App store receipts and basic profile when you sign in with Apple, Google, Facebook, or similar.
- Aggregated demographic and interest data from advertising partners (only with your consent where required).
- Partner organizations that sponsor your participation in events.
- Service providers that help us run our business (hosting, analytics, support, email).
3. How We Use Information
We use personal data for the following purposes:
- Provide and operate our services — create accounts, deliver content, process registrations, host events, support forum participation.
- Personalize your experience — recommend events, content, and partners likely to interest you.
- Communicate with you — service announcements, security alerts, account messages, and (with consent where required) marketing.
- Improve our services — analytics, research, A/B testing, debugging, and product development.
- Show advertising — in our free mobile apps we display advertising through carefully selected ad partners; see Ad Monetization Platforms.
- Safety, security, and legal compliance — fraud prevention, enforcing our terms, complying with applicable law, responding to lawful requests.
- Research cooperation and academic services — matching members, facilitating collaborations, and producing aggregated research insights (using de-identified data where possible).
We rely on the following legal bases under the GDPR / UK GDPR: performance of a contract, our legitimate interests in running a safe and useful service, your consent (for non-essential cookies, marketing, and personalized advertising), compliance with legal obligations, and in some cases vital or public-interest grounds.
4. App Store Compliance
Our mobile applications are published on Google Play and the Apple App Store. We comply with each platform's privacy and data-handling requirements in full.
4.1 Google Play — Data Safety
Our Data Safety form is fully populated and matches our practices. We share or collect only what is strictly necessary. Specifically:
- Data shared with third parties: limited to advertising identifiers, device info, and usage signals shared with our advertising partners (see Ad Monetization Platforms). Users can opt out at any time via their device settings and in-app controls.
- Data collected: account info, app activity, device identifiers, and approximate location (derived from IP).
- Security practices: data is encrypted in transit (TLS 1.2+), at-rest encryption in our databases, and we follow Google's Play Families Policy where relevant.
- User controls: in-app privacy settings let you reset your advertising ID, opt out of personalized ads, request data export, or delete your account.
- Compliance with Families Policy: if our app is designed for or may appeal to children, we comply fully with the Google Play Families Policy, including required disclosures and disabling personalized advertising for known child users.
- User Messaging Policy: we serve only messages necessary for compliance (e.g. GDPR consent) and avoid any disallowed interstitial messaging on first launch.
4.2 Apple App Store — Privacy Labels & Tracking
Our App Privacy Labels accurately describe the data we collect. Concretely:
- Privacy Labels: every data category declared in App Store Connect — Contact Info (name, email), User Content (uploads), Identifiers (device and user IDs), Usage Data & Diagnostics, and Advertising Data — is declared with the correct purpose (App Functionality, Analytics, Product Personalization, Third-Party Advertising) and whether it is linked to the user identity.
- App Tracking Transparency (ATT): we present the ATT prompt the first time we need to access the IDFA. If you decline, we use only contextual advertising and do not share device-level identifiers with advertising partners for tracking.
- Data minimization: we never request data we do not need, and we periodically review categories against the App Store's Required Reason API guidance.
- Ad Network Attribution: we follow Apple's Ad Network Attribution rules and Apple's SKAdNetwork for install attribution when applicable.
- Kids Category: if we offer an app version under the Kids Category, we do not include behavioral advertising or third-party analytics in that version.
5. Ad Monetization Platforms
Our free mobile applications display advertising through a curated set of ad networks and mediation partners. Each partner processes limited device and usage data to deliver, measure, and improve ads, and to detect fraud. Below is the full list, with one paragraph per partner describing what they do, the data they receive, and how to opt out.
5.1 Google AdMob
AdMob is Google's mobile ad platform. It uses device advertising identifiers (IDFA / GAID), device info, and coarse location to deliver and measure ads. AdMob is part of Google's broader ad system, which uses the data to personalize ads, frequency-cap them, and fight fraud. Users can opt out of personalized ads at any time via Settings > Privacy > Ads on iOS and Settings > Google > Ads on Android, and through our in-app privacy controls.
5.2 Meta Audience Network
Meta Audience Network serves ads from Meta (Facebook) advertisers inside our apps. It receives the device identifier, IP-derived location, and event data (e.g. ad view, click). Meta combines this with your activity on Facebook and Instagram to personalize ads unless you opt out. You can opt out of Audience Network ads at facebook.com/help/568137493302217, and through the in-app controls described above.
5.3 Unity Ads
Unity Ads serves in-game and in-app video and display ads. It uses device and usage data (including the advertising ID, IP, device model, OS version, and ad events) to select, deliver, and measure ads. Unity participates in the IAB Europe Transparency & Consent Framework. Opt out via the in-app "Privacy" menu or through platform-level ad personalization controls.
5.4 AppLovin MAX
AppLovin MAX is a mediation platform that auctions ad inventory to multiple networks in real time. AppLovin processes device identifiers, coarse location, app activity, and ad-interaction events to optimize yield, target ads, and detect fraud. Opt out via the in-app privacy settings or via AppLovin's opt-out page.
5.5 ironSource (now part of Unity)
ironSource is a mobile ad mediation and monetization platform. It collects device identifiers, coarse location, app session info, and ad events to deliver and measure ads. Opt out is available through the in-app "Privacy" menu and through platform-level "Limit Ad Tracking" controls.
5.6 Vungle (Liftoff)
Vungle, now part of Liftoff, serves rewarded video, interstitial, and native ads. It uses device identifiers, IP, coarse location, and ad interaction events to deliver, measure, and improve ads and to detect fraud. Opt out via the in-app controls or the device-level ad personalization settings.
5.7 Chartboost
Chartboost is a mobile ad network and programmatic exchange for in-app advertising. It uses device identifiers, IP, and ad events to deliver and measure ads, to perform frequency capping, and to detect invalid traffic. Opt out via the in-app "Privacy" menu or platform-level ad controls.
5.8 Pangle (ByteDance)
Pangle is ByteDance's mobile ad platform. It uses device identifiers, device info, and ad events to deliver and measure ads. Pangle participates in regional compliance programs such as China's PIPL and the EU's TCF. Opt out via the in-app "Privacy" menu or platform-level ad personalization settings.
5.9 Mintegral
Mintegral serves programmatic in-app ads, including playable and rewarded formats. It uses device identifiers, IP-derived location, and ad events for delivery, measurement, and fraud detection. Mintegral participates in industry frameworks including the IAB Tech Lab's ads.txt / app-ads.txt. Opt out via the in-app "Privacy" menu and platform-level controls.
5.10 InMobi
InMobi is a global mobile ad network. It uses device identifiers, coarse location, and usage data to deliver and personalize ads. InMobi offers its own opt-out via inmobi.com/page/opt-out in addition to the platform-level controls.
5.11 StartApp
StartApp is a mobile ad network serving rewarded, interstitial, and native ads. It uses device identifiers, IP, and ad-interaction events for delivery, measurement, and fraud prevention. Opt out is available via the in-app privacy menu.
5.12 Tapjoy
Tapjoy specializes in rewarded and offerwall ads. It uses device identifiers and ad-interaction events to deliver offers and credit rewards. Opt out via the in-app privacy menu and platform-level ad controls.
5.13 Digital Turbine (AdColony, Fyber)
Digital Turbine (which includes AdColony and Fyber) serves video and rich-media ads. It uses device identifiers, IP, and ad-interaction events for delivery, measurement, and fraud prevention. Opt out via the in-app privacy menu and platform-level ad controls.
5.14 Liftoff (Vungle)
Liftoff, the parent company of Vungle, operates a unified monetization stack. It uses device identifiers, IP, and ad-interaction events for delivery, measurement, and optimization. Opt out via the in-app privacy menu and platform-level ad controls.
5.15 Smaato
Smaato operates a real-time ad exchange for mobile. It uses device identifiers, IP-derived location, and ad-interaction events to deliver, measure, and optimize ads. Smaato is a member of industry self-regulatory programs. Opt out via the in-app privacy menu and platform-level ad controls.
5.16 AdColony (Titanium)
AdColony (now part of Digital Turbine, with its Titanium SDK) serves video ads, especially high-quality HD video. It uses device identifiers, IP, and ad-interaction events for delivery, measurement, and fraud detection. Opt out via the in-app privacy menu and platform-level ad controls.
5.17 Ad Mediation & Bidding Partners
In addition to the networks above, our apps use the following mediation/bidding infrastructure: Google Ad Manager, AppLovin MAX (which includes bidding adapters for AdMob, Meta Audience Network, Vungle, Unity Ads, ironSource, Pangle, and others), and DT Exchange. These mediation partners do not use your data for their own advertising outside the auction that occurs in our app at the moment of an ad request, except as described in their own privacy policies above.
5.18 Children & Sensitive Audiences
For users we identify as children (see Children's Privacy), we disable interest-based advertising and configure our mediation stack to request only contextual ads from COPPA-compliant networks.
6. Ad Formats Used
Our apps may display the following ad formats. Each format has specific design, frequency, and disclosure requirements.
- Splash ads — full-screen ads shown at app launch or transition. Skip / dismiss control is provided; we comply with platform rules on splash duration and dismissibility.
- Rewarded video ads — full-screen video ads users choose to watch in exchange for an in-app reward. Always user-initiated; we never auto-play rewarded video.
- Interstitial ads — full-screen ads shown at natural transition points (e.g. between screens). We never serve more than the platform-allowed frequency and never immediately on app open.
- Banner ads — small rectangular ads placed in a designated area of the screen. Clearly marked "Ad" or "Sponsored".
- Native ads — ads designed to match the look-and-feel of surrounding content but always clearly labelled "Ad" or "Sponsored".
- MREC (Medium Rectangle) ads — 300×250 (or similar) in-app display ads. Always clearly labelled as advertising.
All ad creatives are reviewed for compliance with each network's creative policy and applicable law (e.g. no advertising of restricted product categories to minors, no deceptive creatives, clear disclosure of sponsored content).
7. Cookies & Tracking
We use cookies and similar technologies (local storage, pixels, SDKs) on our website. We classify them as follows:
- Strictly necessary — required for the site to function (session, security, load balancing). Always on.
- Functional — remember your preferences (language, region). On by default but you can disable via cookie banner.
- Analytics — aggregated, de-identified analytics (e.g. Google Analytics 4, with IP anonymization). Off until you consent in regions where consent is required.
- Marketing — used to measure and improve marketing campaigns. Off until you consent.
You can withdraw your consent at any time via the in-page "Cookie settings" link (where available) or by clearing cookies in your browser. We honor Global Privacy Control (GPC) and similar opt-out signals where required.
8. Regional Compliance
8.1 GDPR & UK GDPR (EEA & UK)
For users in the European Economic Area and the United Kingdom, we comply with the General Data Protection Regulation and the UK GDPR. We process your data on the legal bases described in Section 3. You have the rights described in Section 12. Where required, we have appointed a local representative; contact details are available on request.
8.2 CCPA & CPRA (California, USA)
For California residents, we comply with the California Consumer Privacy Act and the California Privacy Rights Act. We do not "sell" or "share" personal information as those terms are defined under California law. You have the right to know, delete, correct, and limit use of sensitive personal information. You may exercise these rights via the methods in Section 12 and through the in-app controls.
8.3 LGPD (Brazil)
For users in Brazil, we comply with the Lei Geral de Proteção de Dados. You have the rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing. Our Data Protection Officer (where appointed) is reachable via the contact in Section 15.
8.4 PIPEDA (Canada)
For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act. We obtain meaningful consent, limit collection, and honor access and correction requests.
8.5 Australian Privacy Principles (Privacy Act 1988)
For Australian users, we comply with the Australian Privacy Principles. We manage personal information in accordance with the APPs and notify the Office of the Australian Information Commissioner of any eligible data breaches.
8.6 POPIA (South Africa)
For users in South Africa, we comply with the Protection of Personal Information Act. You have the rights of access, correction, and objection; contact us to exercise them.
8.7 PIPL (People's Republic of China)
For users in the PRC, we comply with the Personal Information Protection Law. We obtain separate consent for sensitive personal information and cross-border transfers, and we provide the rights described in PIPL. Where our services are not available to PRC users, this section is informational.
8.8 Other Jurisdictions
We extend GDPR-equivalent rights to all users regardless of location, except where local law provides a different (and not less protective) standard. We do not knowingly direct our services at, or collect personal data from, individuals in jurisdictions where such activity is prohibited.
9. Children's Privacy
Our services are not directed at children under 13. The minimum age to use our services is 13, or such higher age as may be required by local law (e.g. 14 in some EU member states, 16 in some others, 18 in certain regions).
- COPPA (US): we do not knowingly collect personal information from children under 13. If we learn we have, we delete it promptly.
- GDPR-K (EU): where local law sets a higher age (up to 16), we require verifiable parental consent for users under that age.
- UK Age-Appropriate Design Code (AADC): we apply the AADC's standards — privacy by default, no detrimental use of data, no profiling of children — to all users we identify as under 18.
- India DPDPA: verifiable parental consent is required before processing personal data of children under 18.
- Behavioral advertising: we never serve personalized or behavioral ads to users we identify as children. Only contextual ads from COPPA / GDPR-K / AADC-compliant networks are eligible in child-directed contexts.
Parents and guardians may review, request deletion of, or refuse further collection of their child's information by contacting us at support@quanqiusb.com.
10. International Data Transfers
We are a global organization with users, partners, and infrastructure across regions. When we transfer personal data across borders, we use appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers out of the EEA / UK.
- Reliance on adequacy decisions where they exist.
- Data Processing Agreements (DPAs) with every service provider that processes personal data on our behalf.
- Regional data residency where required (e.g. PRC PIPL cross-border transfer mechanisms).
Our principal hosting is in secure, ISO 27001-certified data centers operated by reputable cloud providers. A current list of sub-processors is available on request.
11. Data Retention
We retain personal data for as long as necessary to provide our services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account data: while your account is active, plus up to 24 months after closure for legal and audit purposes.
- Event / forum participation records: up to 5 years for academic and tax records.
- Support communications: up to 3 years from last contact.
- Analytics data: aggregated / de-identified data may be retained indefinitely; raw event data up to 14 months.
- Advertising data: per the retention windows of the respective ad partners (typically up to 13–18 months for measurement; see partner policies).
- Backups: encrypted backups are retained for up to 90 days, then deleted in rotation.
12. Your Rights
Subject to your jurisdiction, you have some or all of the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete your personal data (the "right to be forgotten").
- Restriction — ask us to limit the processing of your data in certain circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests, including profiling.
- Opt-out of "sale" or "sharing" (CCPA / CPRA): we do not sell or share personal information as defined under those laws, but you may still exercise this right.
- Opt-out of automated decision-making — we do not subject you to decisions based solely on automated processing that produce legal or similarly significant effects.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data protection authority.
To exercise these rights, contact us at support@quanqiusb.com. We respond within the timeframes required by applicable law (typically 30 days; 45 days under CCPA; 1 month under GDPR).
13. Security
We protect personal data with administrative, technical, and physical safeguards designed for the sensitivity of the data, including: encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege principles, multi-factor authentication for staff, regular security reviews, vulnerability management, and incident response planning. No system is perfectly secure; if a security incident affects you, we will notify you and applicable regulators as required by law.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we revise the "Last updated" date above. For material changes, we provide additional notice (e.g. an in-app banner or email) and, where required, request your renewed consent. The previous version(s) of this Policy are available on request.
15. Privacy Contact
For any privacy-related question, complaint, or rights request:
Global Association of Master and Doctor Co., Limited
Attn: Privacy Office
Rm 101A 1/F GENPLAS INDL BLDG, 56 HOI YUEN RD, Kwun Tong, Hong Kong
Email: support@quanqiusb.com
For our EEA / UK representative and other regional contacts, please email us; we will provide details in our response.