Device Fingerprint
Compliance and Privacy

12. Customer Notice Obligations

Compliance and Privacy: 12. Customer Notice Obligations

Customers shall explain their integration of the Geelab Device Fingerprint service in a privacy policy, Cookie/SDK list, application permission notice, or other appropriate location, and explain processing purposes, data categories, service provider, collection methods, data sharing, retention period, user rights channels, and contact details.

Customers are advised to use layered notices:

  • Disclose the Geelab Device Fingerprint service, processing purposes, personal data categories, recipient categories, retention periods or criteria, cross-border transfers, user rights, and contact details in the main privacy policy
  • Disclose cookies, local storage, SDK tokens, local technical identifiers, whether they are necessary or security technologies, storage duration, and management method in the Cookie, Tracker, or SDK list
  • Explain in iOS, Android permission notices or App Store or Google Play data safety disclosures whether optional capabilities such as IDFA, advertising ID, location, Wi-Fi, and device status are enabled, their trigger timing, and their purposes
  • Maintain more detailed technical signal lists and integration instructions in developer documentation, while avoiding public disclosure of complete algorithms, model weights, risk thresholds, hit rules, or bypass detection details

When integrating the Geelab Device Fingerprint service, customers shall comply with the following requirements:

  • Before initializing or calling the Geelab SDK, display a clear and easily accessible privacy notice to end users and, where required by applicable law, obtain consent or ensure another lawful processing basis
  • List in the notice text the Geelab Device Fingerprint service, service provider GEELAB PTE. LTD., the Geelab Device Fingerprint product Privacy Notice, processing purposes, possible data categories, local storage or SDK identifiers, data region, and user-rights exercise method
  • For IDFA, location, Wi-Fi, device status, advertising identifiers, or other optional capabilities controlled by system permissions, the customer shall separately display permission notices according to platform rules and enable relevant capabilities only after end user authorization
  • Without necessary notice or authorization to end users, the customer shall not initialize or call the Geelab Device Fingerprint service during first app launch, before the privacy pop-up is displayed, in unrelated background scenarios, or in scenarios unrelated to device risk identification
  • The customer shall provide rights channels for access, correction, deletion, restriction, objection, data portability, and consent withdrawal, and serve as the primary respondent to end user requests
  • If the customer receives an end user request related to the Geelab Device Fingerprint service, the customer may contact Geelab where necessary. Geelab will assist in locating, exporting, deleting, or restricting relevant data within commercially reasonable efforts. The customer shall bear the reasonable costs incurred by Geelab in providing assistance, including labor and technical implementation costs. Geelab may require the customer to prepay reasonable costs before providing assistance
  • If the customer uses device fingerprint results in high-impact scenarios, the customer shall provide reasonable review, appeal, or correction mechanisms and avoid making decisions that have significant effects on natural persons based solely on a single device risk result
  • If the customer changes the use purpose, trigger scenario, data category, retention period, or sharing arrangement for the Device Fingerprint service, the customer shall promptly update its privacy notice and, where required by applicable law, re-obtain consent or confirm the lawful processing basis

Reference Notice Text

To protect account security, transaction security, fairness of marketing activities, and service stability, we have integrated the Geelab Device Fingerprint service provided by GEELAB PTE. LTD. This service may process your device and system information, browser or application runtime environment information, network information, necessary local technical identifiers, SDK tokens, device fingerprint results, risk codes, risk labels, client IP, client type, and list-hit information through SDKs, local storage, network requests, and server-side queries, for identifying abnormal devices, automated environments, emulators, Root or jailbreak, Hook, debugging, environment spoofing, device reuse, multi-account association, mass registration, credential stuffing, fake transactions, activity cheating, and other security risks. Geelab will process relevant information according to our instructions and will not use such information for cross-context behavioral advertising or sale. You may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the channels listed in our privacy policy.

Reference Disclosure Example

Disclosure itemExample content
Third-party service nameGeelab Device Fingerprint service
Service providerGEELAB PTE. LTD.
Purpose of useAccount security, transaction security, marketing anti-cheating, anti-fraud, anti-automation attacks, device environment risk identification, abnormal access identification, service security audit, and troubleshooting
Use scenariosUser registration, login, transaction, activity participation, content interaction, interface access, risk request verification, or other scenarios requiring device risk identification
Information that may be processedDevice information, system information, browser or application runtime environment information, network information, log information, local technical identifiers, SDK tokens, device fingerprint results, risk codes, risk labels, client IP, client type, and list-hit information
Processing methodCollection, transmission, computation, identification, result return, logging, deletion, anonymization, or aggregation analysis through SDKs, local storage, network requests, and server-side queries
Data sharing and roleGeelab processes relevant information according to our instructions and returns device fingerprints and device risk identification results to us. Geelab will not use relevant information for cross-context behavioral advertising or sale
User rightsYou may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the contact details or rights request channels listed in this privacy policy
Third-party privacy policyGeelab Device Fingerprint product Privacy Notice