3. Processing Purposes
Compliance and Privacy: 3. Processing Purposes
Geelab may process Device Fingerprint data for the following purposes:
- Generating or assisting in generating stable device identifiers
- Identifying same-device reuse, multi-account association, abnormal access sources, and device reuse risks within the customer's own business scope
- Identifying emulators, cloud phones, virtual machines, Root, jailbreak, Hook, code injection, debugging, automated environments, environment spoofing, browser private mode, or other high-risk runtime states
- Returning results such as
fp,risk_code,risk_label,client_ip,client_type, andaccess_list - Helping customers conduct risk control in registration, login, transaction, marketing anti-cheating, content interaction, and game security scenarios
- Preventing fraud, automated attacks, mass registration, credential stuffing, account abuse, fake transactions, activity cheating, fake traffic or reviews, and interface abuse
- Providing service monitoring, troubleshooting, log audit, security response, and technical support
- Using aggregated, anonymized, or de-identified data to improve device risk identification capabilities, model accuracy, service stability, and security
- Fulfilling legal, regulatory, judicial, or compliance obligations
Geelab will not use customer end user data for advertising targeting, cross-context behavioral advertising, cross-site profiling for non-security purposes, single-user identification for other customers, or commercial marketing unrelated to device risk identification and security protection.
3.1 EEA/UK Processing Legal Bases
Where the GDPR, UK GDPR, or other data processing laws apply, the customer is usually responsible for determining the legal basis for using the Device Fingerprint service, such as legitimate interests, consent, performance of a contract, legal obligation, or another applicable basis. The customer shall complete necessary assessments before integration and explain the legal basis in its privacy notice.
When Geelab acts as the customer's processor, it usually processes customer end user data according to customer instructions, the service agreement, and the data processing agreement. When Geelab independently processes customer contact and account data for Console accounts, customer support, billing, contracts, security operations, service improvement, or legal obligations, Geelab may act as a controller or independent responsible party, as described in the Geelab Privacy Policy.
3.2 U.S. State Privacy Law Disclosures
Where the CCPA/CPRA or other U.S. state privacy laws apply, the Geelab Device Fingerprint service is used for security and integrity, fraud prevention, service provision, debugging, quality assurance, internal operations, attack detection, and risk assistance purposes. Geelab does not sell customer end user data and will not share customer end user data for cross-context behavioral advertising.
Customers should still confirm, based on their own business, whether they have obligations relating to sale, sharing, targeted advertising, use of sensitive personal information, automated decision-making, consumer requests, authorized agents, appeals, or global privacy control signals.