4. Information That May Be Processed
Compliance and Privacy: 4. Information That May Be Processed
Geelab Device Fingerprint performs identification based on multi-dimensional weak features and security signals. By default, it does not require end users to provide names, government-issued identification numbers, bank card numbers, account passwords, contacts, SMS messages, photos, audio, video, or raw biometric data.
The Geelab Device Fingerprint SDK should not read customer page form content, password fields, SMS verification codes, payment credentials, or user-entered business content unless the customer separately and actively submits such information and has completed necessary notice and authorization.
The information actually processed depends on endpoint platform, SDK version, customer configuration, system permissions, browser or operating system restrictions, and end user authorization status. Geelab processes relevant information only to the extent necessary for device fingerprint generation, device risk identification, server-side query, troubleshooting, security audit, and technical support.
This Notice discloses data categories, processing purposes, recipient categories, retention periods or criteria, cross-border transfers, and rights channels. Geelab will not disclose complete algorithms, risk rules, weights, thresholds, model feature combinations, or details that could be used to circumvent risk-control measures.
| Data category | Representative examples | Primary purposes |
|---|---|---|
| Device and system information | Device model, brand, system platform, system version, system language, screen parameters, device type, memory, system properties | Device identification, device environment risk identification, abnormal device detection |
| Browser and runtime environment information | User agent, browser information, browser language, time zone, resolution, plugin information, storage capability, cookie-enabled status | Web/H5 device fingerprint generation, automated environment and abnormal browser detection |
| Network information | IP address, network type, network generation, carrier-related information | Regional routing, risk identification, security audit, troubleshooting |
| Local technical identifiers and SDK tokens | Cookies, local storage, session storage, cache, Keychain, SharedPreferences, SDK tokens, device-related technical identifiers | Token generation, device continuity identification, server-side query, and risk judgment |
| Risk results and server-side query results | fp,risk_code,risk_label,client_ip,client_type,access_list | Returning device fingerprints, risk labels, risk codes, and list-hit results to customers |
| Logs and request context | Request time, access logs, error logs, security logs, necessary request context | Service monitoring, troubleshooting, security response, compliance audit |
| Necessary business context submitted by customers | Application ID, scene identifier, business serial number, order number, or other context configured by customers | Helping customers make risk judgments within business scenarios. Customers are responsible for ensuring submitted content is lawful, necessary, and disclosed |