Who we are
Eating in China is provided by ZAOPIN LIMITED. Contact service@zaopincollect.com about privacy, access, correction or deletion of your information. This policy covers the Eating in China app and website.
Accounts and your library
If you sign in, we process your email address, Apple or Google account identifier, sign-in verification data and session tokens to authenticate you. We do not receive your Apple or Google password. We store the profile information you choose to provide, saved and tried items, trips and private experience notes to provide account features and synchronize your devices. Guest library data stays on your device until you choose to copy it to an account.
Comments and safety
When you choose to share a comment or reply, its text and selected public profile information may be shown to other users. We process reports, blocks and internal moderation records to protect the community. Private experience notes and private trip details are not published as comments. Please do not include sensitive personal information in public text.
Purchases
Apple or Google processes your payment. We receive purchase identifiers, verification results and purchase or refund notifications to grant and restore access and prevent fraudulent use. We do not receive your full payment card details. Deleting an Eating in China account does not delete the store's transaction records or automatically refund a purchase.
Optional usage analytics
Analytics is off until you choose to enable it in the app or website. If enabled, we collect a random installation or browser identifier, session identifier, screen and action events, item identifiers, language, platform, app version and timestamps. On the website, this also includes broad referral and campaign categories and clicks to app stores. We do not store full referral URLs or arbitrary campaign text. These records are not linked to your Eating in China account. We do not include search text, email, comment text or private trip details in analytics. You can turn analytics off at any time; this stops new collection and resets the local analytics identifier. Analytics reports use the most recent 90 UTC dates. Older raw events are excluded from reports immediately and removed by an hourly cleanup job; restricted backups expire separately.
Location and device storage
If you use the current-region feature, the app requests location permission to suggest a region. Precise coordinates are processed through your device and its operating-system geocoding service; they are not sent to our API or stored by us. You can choose a region manually instead. Downloaded guide content and preferences are stored on your device; you can manage downloads or remove local data through the app or device settings.
Service providers and security
Our services use Amazon Web Services for hosting, storage, content delivery, backups and transactional email. Apple and Google provide sign-in and purchase services when you choose them. Network providers receive information such as your IP address to deliver requests. We process limited technical and security records to operate and protect the service. Data may be processed outside your country, including Hong Kong and Singapore. We restrict database access, use encrypted network connections and limit staff access by role. We do not sell personal information, run advertising or use analytics for cross-app advertising tracking.
Retention and deletion
Account data is retained while needed to provide your account. You can delete your account from Me > Settings > Delete account, or request deletion by emailing service@zaopincollect.com. We verify ownership before deleting account data. Deletion removes the active account, profile, synchronized library, private experiences and associated comments and replies. To prevent deleted sessions from being reused, hashed session identifiers remain until their expiry plus 30 days and are removed by subsequent account-deletion housekeeping. Purchase verification and refund records are retained separately to support restoration and prevent reuse of invalid purchases; they currently have no automatic deletion deadline. Operational logs are configured for 14 days. Daily backups expire after 7 days and weekly backups after 28 days; older backup object versions expire separately after 7 days, and storage-provider deletion can take additional time. Retained records are not used to recreate a deleted account during ordinary use. Guest data and downloaded content remaining on your device can be removed locally. Contact us to request review of retained records or assistance.
Changes
We will update this policy when our data practices change. The document version is shown below. If your local law gives you additional data rights, contact us to exercise them.