VIP Privacy Policy
- Last updated:
- Effective date:
VIP (the “App,” “we,” or “us”) respects and protects your personal information. This Policy explains how we collect, use, store, share, and protect personal information when we provide account services, identity verification, tasks and orders, chat and audio or video calls, location services, wallets, payments, withdrawals, and notifications, as well as how you may exercise your related rights.
Please note: On first launch, the App presents this Policy and the Terms of Service in a separate dialog (you can switch language). We initialize third-party SDKs such as JPush and Mi Push only after you actively select “Agree and continue.” If you select “Decline and exit,” those SDKs will not be initialized. Merely viewing this Policy, opening an agreement page, or remaining silent does not constitute consent.
Before you consent, we will not request non-essential system permissions or use a third-party SDK to collect or upload personal information. You may decline non-essential permissions. Apart from the corresponding feature being unavailable, doing so will not affect other basic features.
1. Scope and operator
This Policy applies to the VIP Android app and the websites and services directly associated with it. The operator and app filing information for the officially released version are identified by the notice above and the results in the filing system of the Ministry of Industry and Information Technology. Services that a third party provides through its own page or app are governed by that third party’s separately published privacy policy.
2. Information we collect and use
We process information only as necessary to provide clearly identified features, in accordance with the principles of lawfulness, fairness, necessity, and good faith. A feature page will explain the information it needs before collection. We process that information only after you enter, upload, or authorize it.
| Service scenario | Information that may be processed | Purpose | How it is provided |
|---|---|---|---|
| Registration, sign-in, and account security | Mobile number, SMS verification code, SMS consent and delivery records, CAPTCHA challenge and verification data, nickname, avatar, email address and email verification codes (when you sign up or sign in with email), sign-in credentials, and account status | Create and identify an account, send and verify one-time authentication codes, recover or change account information, prevent automated abuse and account theft, and troubleshoot message delivery | You submit the mobile number and verification code and actively request the message; the system generates the code, CAPTCHA challenge, delivery result, and security record |
| Identity verification | Name, identity-document type and number, verification materials, and verification result submitted on the verification page | Meet legal, transaction-security, order acceptance, payment-receipt, or withdrawal requirements | Collected only when you initiate identity verification; the fields shown on the page control |
| Tasks, products, services, and orders | Task or order details, service address and contact, transaction amount, order and fulfillment times, order status, after-sales information, and dispute records | Display and match services, fulfill orders, arrange delivery or on-site services, provide after-sales support, resolve disputes, and manage security risks | You submit the information, or it is generated when you use the relevant feature |
| Chat, audio or video calls, and content publishing | Chat text, images, video, voice, call status, locations you actively send, task content, reports, and feedback | Enable communication, message delivery, calls, content display, report handling, and community-safety management | You send the information, or it is generated when you use the relevant feature |
| Wallet, payment, and withdrawal | Order number, payment channel, amount, payment or refund status, wallet balance and transaction history, top-up and withdrawal records, and receiving-account information needed for a withdrawal | Initiate payment, verify transaction results, keep accounts, issue refunds, settle funds, process withdrawals, reconcile accounts, and control risk | You submit the information, or it is generated during a transaction. Payment institutions directly process sensitive credentials such as payment passwords; we do not obtain them |
| Location and nearby services | Latitude and longitude, approximate or precise location, and locations or addresses you select | Show nearby services, fill in your current location, select a point on a map, or send a location in chat | Obtained only after you use the relevant feature and authorize foreground location access. The App does not request background location access |
| Operation, security, and notifications | Device brand and model, operating system and app version, IP address, network type and status, Android ID, OAID, push Registration ID, crash and operation logs, and push-delivery and click records | Keep the App stable, protect accounts and transactions, diagnose faults, and, after you consent, send service notifications about orders, chats, or calls | Automatically generated or obtained within the necessary scope by the App or the push SDKs described below after you consent to this Policy |
Except where consent is not legally required—for example, when processing is necessary to enter into or perform a contract to which you are a party, fulfill a legal obligation, respond to a public-health emergency, or protect life, health, or property in an emergency—we will not process information beyond the purposes described in this Policy. If a purpose changes materially, we will notify you again and obtain renewed consent where required by law.
3. When and why we request system permissions
System permissions are off by default. We explain the purpose and request a permission when you actively use the corresponding feature. Agreeing to this Policy does not cause us to request all permissions at once.
| System permission | When and why it is requested | Effect of declining |
|---|---|---|
| Camera | Requested when you photograph an avatar, chat image, or verification material, so the App can take and upload the image. | You cannot take a photo directly, but features that do not depend on the camera remain available. |
| Photos, videos, or storage | Requested when you select, send, upload, or save an image or video. On supported Android versions, we prefer the system photo picker or selected-photos access. | You cannot select or save local media. Text chat and other features remain available. |
| Microphone | Requested when you record a voice message or start an audio or video call, to capture audio for that session. | You cannot record or send audio from your device. Other features remain available. |
| Foreground location (approximate or precise) | Requested when you look for nearby services, use your current location, select a point on a map, or send a location. We do not request background location access. | Your current location cannot be obtained automatically, but you can still enter or select an address manually. |
| Notifications | Requested when you want service alerts for chats, order status, or calls, including standard notifications, incoming-call alerts, sound, and vibration. | You can still view information in the App, but may not receive timely alerts after leaving it. |
You can change permissions at any time in Android under Settings → Apps → VIP → Permissions / Notifications. Withdrawing authorization does not affect processing already completed on the basis of that authorization.
4. Third-party SDKs and services
To provide push notifications, payments, international SMS verification, and abuse-prevention CAPTCHA, the App and associated websites may use the providers described in this section, Twilio Verify for approved international verification routes, and Alibaba Cloud-branded services for CAPTCHA and other separately identified functions. When you request an international verification text, the approved SMS service may process the mobile number, one-time verification message, routing parameters, and necessary request metadata. The approved CAPTCHA service may process challenge and verification parameters together with the IP address and browser, device, network, and risk data needed to determine whether a request is automated or abusive. The services may return message identifiers, delivery status, error details, and CAPTCHA verification results. We use this information only to deliver and verify authentication texts, prevent fraud and abuse, troubleshoot delivery, and meet carrier or regulatory requirements. A service brand is not treated as the legal identity of an overseas recipient. Before a United States verification text can be requested, the page must load a versioned feature notice that identifies every overseas recipient by legal name and contact details and provides the other transfer information described in Section 6. If that complete notice is unavailable, United States SMS verification remains unavailable. We perform necessary security assessments and require providers to process information only for agreed purposes.
4.1 JPush (JPush Android SDK 6.1.0)
- Provider: Shenzhen Hexun Huagu Information Technology Co., Ltd.
- Purpose: Generate a push identifier, deliver order, chat, call, and other service notifications, measure delivery, and diagnose push failures.
- Information that may be processed: Device brand, model, and operating system; app version; Android ID; OAID; network type and status; IP address; JPush Registration ID; push logs; and notification-delivery and click records.
- When enabled: Initialized only after you actively consent to this Policy; the JPush SDK is not called if you decline. In the current version, optional collection and features for IMEI, IMSI, MAC address, SSID, BSSID, Wi-Fi scanning, base stations, geofencing, intelligent push, user insights, linked wake-up, and app-active-time statistics are disabled. JPush is not used for personalized marketing messages.
- Policy: JPush Privacy Policy.
4.2 Mi Push
- Provider: Beijing Xiaomi Mobile Software Co., Ltd.
- Purpose: Improve delivery of order, chat, call, and other service notifications on Xiaomi devices.
- Information that may be processed: Device identifiers such as OAID and Android ID, device brand and model, system and SDK versions, carrier and network type, IP address, push content, notification settings, and push-delivery and click logs.
- When enabled: Enabled through the JPush channel after you consent to this Policy. If you do not allow notifications, messages remain available in the App.
- Policy: Mi Push Privacy Policy.
4.3 WeChat Pay
- Provider: Shenzhen Tencent Computer Systems Co., Ltd. and the licensed payment institution that actually provides payment and settlement services.
- Purpose: Open WeChat, when you actively choose WeChat Pay, to complete payment or a refund and verify the transaction result.
- Information that may be processed: Order number, transaction amount, merchant and app information, basic device and network information, and payment status. WeChat Pay directly processes sensitive credentials such as the payment password you enter in WeChat; we do not obtain them.
- When enabled: Called only when you actively choose WeChat Pay.
- Policy: WeChat Privacy Protection Guidelines.
4.4 Alipay
- Provider: Alipay (China) Network Technology Co., Ltd.
- Purpose: Open Alipay, when you actively choose Alipay, to complete payment or a refund and verify the transaction result.
- Information that may be processed: Order number, transaction amount, merchant and app information, basic device and network information, and payment status. Alipay directly processes sensitive credentials such as the payment password you enter in Alipay; we do not obtain them.
- When enabled: Called only when you actively choose Alipay.
- Policy: Alipay Privacy Policy.
AMap map SDK disclosure — AMap Android 3D Map/Location/Search combined SDK
The provider is Beijing Gaode Tuqiang Technology Co., Ltd. The SDK displays maps in VIP and lets you select a point on a map.
Depending on device state and feature use, the AMap Android Map SDK may process latitude and longitude, IP address, network and Wi-Fi status and parameters, OAID, app information, device and operating-system information, sensor data, runtime and diagnostic logs, and other information necessary to provide and secure the map service.
Collection method: automatically collected through the SDK program interface while it is enabled.
It is enabled only after you expressly agree to this Privacy Policy. When you actively search for a trip pickup or destination, the place keyword and search-center latitude/longitude are sent to the AMap Map/Search SDK to return nearby candidates; when you actively open the map, the SDK displays it and supports point selection. Merely starting the App does not initialize the SDK.
This app includes the AMap combined 3D Map/Location/Search package, but it does not call AMap's location capability to obtain your current location. Current location is obtained only when needed through the device system's foreground location service; you may deny location permission and select a point manually.
Alipay facial real-name verification disclosure
This feature is available only for Chinese mainland resident identity cards. Alipay provides the facial real-name verification service.
It starts only after you make a separate, express choice that is not preselected and actively request verification; merely opening VIP does not start it.
VIP sends your legal name and identity-card number to Alipay. Alipay processes facial images or video, liveness signals, and device risk-control information to complete and protect the verification.
VIP does not receive or store facial images or video. We retain only an irreversible identity-document digest, the Alipay verification identifier and result, and consent audit records needed for security, duplicate-account prevention, and compliance.
You may decline or stop verification. Features that legally or operationally require real-name verification will then remain unavailable. You may contact VIP support to appeal or ask about a result.
Personal information in merchant verification
This section applies when you apply to become, or remain, a restaurant, hotel or homestay merchant on VIP. We process the information below only after you submit a merchant verification application yourself.
What we collect: a photo of your business licence, the company name and unified social credit code; the legal representative's name and ID card number; the result of the legal representative's (or owner's) face verification; a letter of authorisation if a store manager applies; photos and the number, issuing authority, expiry date, holder and address of your food business licence, special industry licence or homestay filing certificate; a property certificate or lease for homestays; the store name, phone number, address, map location and photos; and the version and time at which you accepted the Food Safety Agreement. ID card numbers are sensitive personal information: we keep only a partly masked number and an irreversible digest, and we do not keep face images.
Purpose and legal basis: under Article 27 of the E-Commerce Law, Article 62 of the Food Safety Law, Article 8 of the online catering food safety measures and related rules, we use this information to verify merchant identity and licences, register and file merchants, re-check them every six months, show licences on the store page (with numbers partly masked), handle complaints and cooperate with regulators. Processing is necessary to meet these legal obligations. Before processing sensitive personal information we ask for your separate consent on the merchant verification page.
Processor: for merchants in mainland China, identity and company details are verified by Alibaba Cloud Computing Co., Ltd. (Aliyun real-person verification and enterprise element verification) on our behalf, to complete face verification and match the national enterprise registry. Alibaba Cloud may process the information only as we instruct. The information is stored and processed in mainland China and is not transferred abroad.
Retention: merchant identity information, review records and agreement acceptance records are kept for at least three years after you leave the platform (Article 31 of the Measures for the Supervision and Administration of Online Transactions), or longer where other laws require. We then delete or anonymise them. If you delete your account, these legally required records are kept until the period ends and are used only to meet legal obligations.
Your rights: on the Merchant verification page you can view and correct the information you submitted, withdraw your application or stop trading. Records we must keep by law are restricted during the retention period and deleted afterwards. To exercise other rights or to complain, contact support@vip.world. We reply within 15 working days.
If you do not provide this information, you cannot become a restaurant, hotel or homestay merchant, but you can still use the rest of VIP.
5. Sharing, transfer, and public disclosure
- Except for the service providers identified in this Policy, the exact overseas recipients identified in the separate feature notice you accept, counterparties necessary to fulfill an order you select, or as otherwise required by law, we do not share your personal information with another company, organization, or individual.
- We do not sell personal information. If personal information is transferred because of a merger, division, restructuring, asset transfer, or similar transaction, we will identify the recipient and require it to remain bound by this Policy. If the purpose or method of processing changes, we will obtain renewed consent as required by law.
- As a rule, we do not publicly disclose personal information. If disclosure becomes necessary, we will explain its purpose, type, and scope and obtain separate consent as required by law, unless the law provides otherwise.
6. Storage, retention, and security
- We retain personal information only for the shortest period necessary for the purposes described in this Policy. Information that laws or regulations require us to retain—such as orders, payments, settlements, tax and accounting records, and security logs—is kept for the legally required period. When a retention period expires, we delete or anonymize the information unless the law provides otherwise.
- After account deletion, we stop providing services and delete or anonymize account-related information within the period required by law. Transaction or compliance records that must legally be retained are isolated and no longer used for ordinary business.
- We use safeguards including HTTPS encryption in transit, access controls, identity authentication, log auditing, backups, and security-incident response to prevent unauthorized access, disclosure, alteration, or loss.
- If a security incident may harm your rights or interests, we will, as required by law, explain the incident, its possible effects, and measures taken or recommended, and report it to the appropriate regulator.
- For United States SMS verification, immediately before CAPTCHA and message delivery, we present a fixed-English, versioned feature notice that identifies each overseas recipient’s legal name, country or region, role, postal address, privacy email and telephone number, processing purpose and method, personal-information categories, retention period, and procedure for exercising your rights. The SMS receipt consent and cross-border transfer consent are separate, unchecked choices. We bind an acceptance to the displayed disclosure version, contract hash, recipient-list version, and recipient-list hash. We do not offer the United States SMS route when any required notice field or integrity value is missing. You may decline the transfer by leaving either choice unchecked and not requesting the verification text.
7. Your personal-information rights
As provided by law, you may access, copy, correct, supplement, or delete personal information; withdraw authorization; turn off system permissions; delete your account; and ask us to explain our personal-information processing rules. You may do so as follows:
- Change your nickname, avatar, mobile number, email address, and other account information in the App.
- Turn off camera, photos, microphone, location, or notification access in Android settings.
- Account-deletion path: after signing in, open the bottom Me page, select the Security Center icon in the upper-right corner, choose “Delete account” under “Account security,” and follow the confirmation prompts.
- Email support@vip.world to request access, correction, deletion, a copy, withdrawal of consent, suppression of future authentication texts, or account deletion. For routes that accept inbound replies, you may also reply STOP to opt out or HELP for assistance. Withdrawing consent does not affect processing already completed before withdrawal.
To protect account security, we may first verify your identity. After receiving a complete and verifiable request, we will handle it promptly and respond or complete processing no later than 15 business days afterward. If laws or regulations provide otherwise, or if an unsettled order, dispute, or statutory retention duty exists, we will explain the reason and expected handling.
8. Protection of minors
VIP is intended only for adults aged 18 and over. We do not knowingly allow anyone under 18 to create an account or knowingly collect their personal information. If we learn that a user is under 18, we will close the account and delete the information as required by law. If you believe a minor is using VIP, contact support@vip.world.
9. Policy updates
We may update this Policy to reflect changes in our business, technology, laws, or regulations. If a significant change affects the purpose or method of processing, categories of information, or your rights, we will notify you through a prominent in-app notice, dialog, or website announcement. Where renewed consent is legally required, we will obtain your active consent before the change takes effect.
10. Contact us
For questions, comments, complaints, or requests concerning this Policy, personal-information protection, or account deletion, email support@vip.world. After verifying your identity, we will handle the matter promptly and respond no later than 15 business days afterward.
Voice and translation features
When you turn a voice message into text, when a voice message in another language is played to you in your app language, or when you use the Live Translator, the audio or text is sent to Alibaba Cloud Model Studio (DashScope) for speech recognition, machine translation and speech synthesis. Translated speech is read aloud by an AI-generated voice. Our brand voices were designed from text descriptions and are not the voice of any real person. We never clone your voice or create a voiceprint. Live Translator recordings are deleted after processing; we keep no Live Translator audio, text or location on our servers. To suggest a local language, the Live Translator may use your device's approximate location, which is converted to a country on your device and never sent to us. Translation is off until you turn it on. Generated audio for ordinary voice messages is stored privately like other voice messages, is deleted when the message is revoked or after 30 days without playback, and is not used to train AI models. Burn-after-read voice messages are never processed.
AI analysis and AI learning
AI analysis (optional). If you start an AI analysis, the conversations you select, including text, images, sampled video frames and speech transcripts, and including messages sent by the other people in those conversations, are processed on our servers and our dedicated processing machine to answer your question. Temporary files are deleted after use and task memory expires after at most 30 minutes. You can report an inappropriate AI answer from the result screen.
AI learning (optional, off by default). If you turn on AI learning consent, the content types you choose (chats, in-app behaviour, photos, videos) may be used to improve our AI features. You can withdraw consent at any time in Me > AI learning consent; after withdrawal we stop using new data and remove your data from future training sets.
Cross-border processing
When you use email sign-up or other features that require Alibaba Cloud CAPTCHA 2.0, challenge and risk data may be processed by Alibaba Cloud in Singapore. When international SMS verification via Twilio Verify is enabled for a country, the mobile number and one-time verification message may be processed in the United States. These are cross-border transfers under the Personal Information Protection Law of the People’s Republic of China. Where required, we will obtain your separate consent, complete a security assessment, certification or standard contract, and identify the overseas recipient, purpose, method, categories of information and how you may exercise your rights, before the transfer takes place. You may decline a transfer by not using the feature that requires it.
Child safety and account deletion
VIP has zero tolerance for child sexual abuse and exploitation. Such content is removed, offending accounts are banned and we report it to NCMEC and the competent authorities. Report it in the app with the reason "Child safety" or email support@vip.world. Read our Child Safety Standards.
You can delete your account and data at any time in the app under Me, then Security Center, then Delete account, or by email. See Delete your account and data for what is deleted and what the law requires us to keep.