Release Date: April 7, 2026
Effective Date: April 7, 2026
Last Updated: July 1, 2026
Developer: Tianjin Hezhong Tinghui Agriculture Development Co., Ltd.
Email: rita@thintlgroup.com

Thplus values your privacy and personal information security. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Thplus mobile application, website, and related services. Please read this policy carefully before using our services. If you do not agree with this policy, please stop using Thplus services.

I. How We Collect and Use Your Personal Information

When you use Thplus services, we follow the principles of lawfulness, legitimacy, necessity, and data minimization. We collect information provided by you or generated through your use of the services only for the purposes described below.

Type of Personal Information Specific Fields Purpose of Collection Method of Collection Scope of Use Triggering Scenarios and Frequency
Account and Contact Information Name, nickname, phone number, email address, account ID, login token Account registration, login, password retrieval, customer service, account security, order notification, and service communication User voluntarily provides or generated by account system Used within Thplus account, order, customer service, and security systems Triggered when you register, log in, manage your account, retrieve password, contact customer service, or use account-related services
Delivery and Address Information Recipient name, phone number, email address, country, state, city, postal code, detailed address, selected address coordinates Address management, order delivery, warehouse matching, delivery-related services, and customer support User voluntarily provides, selects on map, or generated through address services with permission Used for order fulfillment, delivery, warehouse services, and support Triggered when you add or edit addresses, place orders, select addresses, or use delivery-related services
Order, Payment, and Transaction Information Order number, cart items, product information, payment method, payment status, transaction amount, balance records, top-up records, refund or after-sales records, offline payment voucher records Order creation, payment processing, payment confirmation, delivery, after-sales service, dispute handling, accounting, and compliance Generated when you use cart, checkout, payment, balance, refund, or after-sales features Used for transaction fulfillment, account balance management, support, security, and compliance Triggered when you browse products, add to cart, place orders, pay, upload vouchers, request refunds, or request after-sales services
User Content and Uploaded Images Avatar images, payment voucher or bank slip images, feedback images, support images, images selected for image search, related file metadata Avatar management, payment confirmation, image search, customer support, feedback, and other image upload features you actively use User actively selects, captures, or uploads Used only for the feature you choose to use and related service processing Triggered only when you actively choose images, take photos, upload files, submit feedback, upload payment vouchers, or use image search
Location Information Approximate location, precise location, latitude, longitude, selected address coordinates Nearby warehouse display, address selection, delivery-related services, localized product or service display Collected through system location API after your authorization or generated when you select an address Used only for location-related features and order delivery scenarios Triggered when you use location, map, warehouse, address selection, or delivery-related features; not continuously tracked in the background
Device, App, and Log Information Device model, operating system version, app version, language, region, network status, IP address, timestamps, app-generated device identifier, runtime logs, error logs, crash logs, performance logs App operation, login security, fraud prevention, troubleshooting, diagnostics, analytics, performance improvement, and service security Automatically generated during app operation or when errors occur Used for security, diagnostics, analytics, and service improvement Collected during app operation, login, error reporting, security checks, analytics events, or troubleshooting
Push Notification Information Push registration ID, device push token, notification delivery status, notification interaction data Sending order updates, service notices, logistics updates, account alerts, and permitted promotional notifications Generated by push notification service after push service initialization Used for notification delivery and push service diagnostics Triggered when push service is initialized, notifications are sent, delivered, or interacted with
Usage and Analytics Information App launch, page views, clicks, search activity, feature usage, order flow events, daily active events, error events Service analytics, product improvement, troubleshooting, user experience optimization, and security Generated when you use the app Used for analytics, app improvement, security, and diagnostics Generated during app usage or when relevant app events occur
Voice Input Information Voice input and converted text Converting voice input into search text or command text when you actively use voice input features Collected through microphone after your authorization and active operation Used only for the voice input feature you choose to use Triggered only when you actively use voice search or voice input

Special Note: We do not collect your call logs, SMS content, calendar data, full contacts list, or phone state information for core app functionality. If you refuse to provide certain information or permissions, you may not be able to use the corresponding feature, but this will not affect your use of unrelated basic browsing features.

II. Permissions We Request and Their Purposes

To provide specific features, we may request the following system permissions. You can disable these permissions at any time in your device settings. After disabling a permission, the related feature may not be available.

III. Google Play Data Safety and Android Photo Picker Notice

For Android users, we collect and use personal information only when it is necessary to provide Thplus services, including account management, order processing, delivery address management, payment confirmation, customer support, push notifications, security, analytics, and app performance improvement.

Photos and Videos: When you choose images for features such as avatar upload, payment voucher upload, support request, feedback, or image search, we access only the images you actively select or capture. On Android, where available, we use the system Photo Picker for image selection. We do not request broad access to your photo or video library for one-time image selection, and we do not continuously scan or read your media files in the background.

Device Identifiers: We may use an app-generated identifier, system-provided app instance information, push notification registration ID, app version, device model, operating system version, language, region, network status, and diagnostic logs for login security, push notifications, analytics, troubleshooting, fraud prevention, and service improvement. We do not request Android phone state permission to collect IMEI, IMSI, phone number, SIM serial number, or call state information.

Permissions We Do Not Request for Core App Functionality: We do not request permissions to read call logs, SMS messages, calendar data, full contacts list, or phone state. If future features require additional permissions, we will update this policy and request your authorization before using the related feature.

Data Transmission and Deletion: We use reasonable security measures, including encrypted transmission where applicable, to protect your information. You may request account deletion in the Thplus App through [My] - [Settings] - [Delete Account]. After deletion, we will delete or anonymize your personal information unless retention is required by law, transaction records, dispute resolution, security, tax, accounting, or compliance obligations.

IV. App Store Privacy and Tracking Notice

For iOS users, the information we collect may correspond to the following App Store privacy categories, depending on the features you use:

App Store Data Category Examples Purpose Linked to User Used for Tracking
Contact Information Name, nickname, phone number, email address, delivery contact information Account registration, login, order processing, delivery, customer support, account security Yes No
Location Approximate or precise location, selected address coordinates Nearby warehouse display, address selection, delivery-related services Yes, when associated with your account or order No
User Content Avatar images, payment voucher images, support or feedback images, images selected for image search Avatar management, payment confirmation, support, feedback, image search Yes, when uploaded under your account No
Purchases and Transaction Information Orders, cart items, payment method, payment status, balance records, voucher records Order fulfillment, payment confirmation, after-sales service, dispute handling, compliance Yes No
Identifiers User ID, app-generated device identifier, push registration ID, login token Account management, push notifications, security, fraud prevention, analytics Yes No
Usage Data App launch, page views, clicks, search activity, order flow events, feature usage Analytics, service improvement, troubleshooting, user experience optimization Yes, where associated with your account or device No
Diagnostics Crash logs, error logs, performance logs, device and app runtime information Bug fixing, stability improvement, security, performance monitoring May be linked to user or device No

Tracking and IDFA: We do not use Apple IDFA for cross-app or cross-website tracking. We do not track you across apps or websites owned by other companies for targeted advertising. If we introduce tracking activities in the future, we will update this policy and request your permission through Apple's App Tracking Transparency framework where required.

Sign in with Apple and Third-Party Login: If you choose to sign in with Apple, Google, Facebook, or another supported third-party login provider, we may receive account authentication information such as user identifier, token, email address, or nickname, depending on the information you authorize the provider to share.

V. Third-Party SDKs and Service Providers

To provide app functionality, stability, security, payment, login, push notifications, map/address services, analytics, diagnostics, file storage, and customer support, we may integrate third-party SDKs or service providers. These providers may process necessary information only for the corresponding service scenarios.

Service or SDK Developer / Provider Information Processed Purpose Triggering Scenario
DCloud / uni-app / 5+ Runtime DCloud and related runtime service providers Device model, operating system version, app version, network status, runtime logs, diagnostic information, app-generated identifiers App runtime capability, native capability support, diagnostics, security, and performance improvement During app operation, native feature invocation, diagnostics, and error reporting
EngageLab / MTPush EngageLab Push registration ID, device push token, app version, device model, operating system information, notification delivery and interaction data Push notification delivery, order notices, service notices, account alerts, and push diagnostics When push service is initialized, notifications are sent, delivered, or interacted with
Google services Google Authentication token, third-party user identifier, email address or nickname authorized by you, map/address information, device and network information necessary for Google services Google login, map/address services, push-related services where applicable When you choose Google login or use Google map/address related services
Apple Sign In Apple Apple user identifier, authentication token, email address or name authorized by you Apple account login and account binding When you choose Sign in with Apple
Facebook Login Meta / Facebook Facebook user identifier, authentication token, email address or nickname authorized by you Facebook account login and account binding When you choose Facebook login
Payment service providers Stripe, Alipay, WeChat Pay, or other supported payment partners Order number, transaction amount, payment method, payment status, transaction verification information Payment processing, payment confirmation, refund handling, transaction security When you initiate payment, confirm payment, request refund, or use balance/payment-related services
Map, geolocation, and address service providers Google Maps or other supported map/address providers Location coordinates, address keywords, selected address information, device and network information necessary for map services Address selection, nearby warehouse display, map display, delivery-related services When you use location, map, address search, or address selection features
Cloud storage or file hosting providers Cloud storage and file hosting service providers used by Thplus Images and files you upload, such as avatars, payment vouchers, support images, feedback images, and related file metadata Image/file upload, storage, display, order or support processing When you actively upload or save files through app features
Speech recognition service providers Speech recognition service providers used by Thplus Voice input, converted text, device and network information necessary for speech recognition Converting voice input into search text When you actively use voice search or voice input

VI. Sharing of Personal Information

We do not sell your personal information. We only share necessary information with third parties in the following limited circumstances and only for the purposes described in this Privacy Policy.

Recipient Type Information Shared Purpose Triggering Scenario
Push notification service providers, such as EngageLab / MTPush Push registration ID, device push token, app version, device model, operating system information, notification delivery or interaction data Sending order updates, service notices, account alerts, logistics updates, and permitted promotional notifications When push notification service is initialized or when notifications are sent or interacted with
Login service providers, such as Apple, Google, and Facebook Authentication token, third-party user identifier, email address, nickname, or other information you authorize Third-party account login and account binding When you choose to sign in using a third-party login method
Payment service providers Order number, transaction amount, payment method, payment status, transaction verification information Payment processing, payment confirmation, refund handling, transaction security When you initiate payment, confirm payment, request refund, or use balance/payment-related services
Map, geolocation, and address service providers Location coordinates, address keywords, selected address information, device and network information necessary for map services Address selection, nearby warehouse display, map display, delivery-related services When you use location, map, address search, or address selection features
Cloud storage or file hosting providers Images and files you upload, such as avatars, payment vouchers, support images, feedback images, and related file metadata Image/file upload, storage, display, order or support processing When you actively upload or save files through app features
Speech recognition service providers Voice input and converted text, device and network information necessary for speech recognition Converting voice input into search text When you actively use voice search or voice input
Technical service providers, such as app framework, analytics, diagnostics, and security service providers Device model, operating system version, app version, network status, app runtime logs, crash logs, usage events, app-generated identifiers App operation, security, troubleshooting, analytics, performance improvement, fraud prevention During app operation, error reporting, analytics, security checks, or troubleshooting
Logistics, warehouse, customer support, and business service providers Order information, recipient name, phone number, delivery address, service request details Order fulfillment, delivery, warehouse services, after-sales service, customer support When you place orders, request delivery, contact support, or request after-sales services

We require third-party service providers to process personal information only for the purposes described above and to take appropriate security measures. We may also disclose information when required by law, regulation, legal process, government request, dispute resolution, protection of rights and safety, fraud prevention, or enforcement of our agreements.

VII. Data Storage, Security, and Retention

We use reasonable administrative, technical, and organizational measures to protect your personal information, including access control and encrypted transmission where applicable. However, no network transmission or storage system can be guaranteed to be completely secure.

We retain your information only for as long as necessary to provide services, maintain your account, fulfill orders, comply with legal obligations, resolve disputes, prevent fraud, and enforce agreements. Order, payment, transaction, and after-sales records may be retained as required for transaction, tax, accounting, compliance, and dispute resolution purposes.

VIII. Your Rights and Choices

You may access, correct, or delete certain account information in the app. You may disable permissions such as camera, microphone, photos, location, and notifications in your device settings. If you disable a permission, related features may not be available.

If you have questions or requests regarding your personal information, you may contact us using the contact information listed in this policy.

IX. User Account Deletion

We respect and guarantee your control over your own account. If you no longer wish to use Thplus services, you may apply to delete your account. Account deletion is an irreversible operation. Upon deletion, data under that account will be deleted or anonymized, except as otherwise required by law, transaction records, dispute resolution, security, tax, accounting, or compliance obligations.

Deletion Method and Path: Log in to the Thplus App, go to [My] - [Settings] - [Delete Account].

Consequences of Deletion and Data Processing: After account deletion, you will permanently lose the right to use that account, and it cannot be recovered. This includes but is not limited to:

X. Children’s Privacy (COPPA Compliance for the United States)

Our Services are intended for general audiences and are NOT targeted to children under 13 years of age in the United States, in compliance with the Children’s Online Privacy Protection Act (COPPA).

We do not knowingly collect, solicit or store any personal identifiable information from users under 13 without verifiable parental consent.

If we become aware that we have inadvertently obtained personal information from a child under 13 without proper parental approval, we will immediately take all reasonable steps to permanently delete such data from our servers.

If you are a parent or guardian and believe your child has provided us personal data, please contact us via rita@thintlgroup.com to request data removal.

XI. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app, website, or other appropriate means. Your continued use of Thplus services after the update takes effect means that you have read and accepted the updated policy.

XII. Contact Us

If you have questions, requests, or complaints about this Privacy Policy or your personal information, please contact us:

Developer: Tianjin Hezhong Tinghui Agriculture Development Co., Ltd.
Email: rita@thintlgroup.com

XIII. Supplementary Privacy Rights for California Residents (CCPA/CPRA)

If you are a resident of the State of California, you are entitled to the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  1. Right to Know: You may request us to disclose what categories of personal information we have collected about you, the sources of such information, the business or commercial purpose for collecting the information, the categories of third parties with whom we share personal information, and the specific pieces of personal information we have collected about you.
  2. Right to Delete: You may request us to delete the personal information we have collected from you, subject to certain exceptions permitted by California law (such as retaining transaction records for tax, accounting, dispute resolution and legal compliance purposes).
  3. Right to Opt Out of Sale/Sharing: We do NOT sell any of your personal information to third parties for monetary consideration. We only share necessary data with service providers strictly to deliver our service as stated in this policy, so no opt-out sale request is required.
  4. Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA privacy rights. We will not deny you goods or services, charge you different prices or rates, provide a different level or quality of services, or penalize your account because you submit a data access or deletion request.

How to Submit a CCPA Request:

You may submit your request for access or deletion by sending an email to rita@thintlgroup.com with the subject line "California Privacy Request - Your Account ID". We will verify your identity to confirm the request belongs to the account holder and respond to your valid request within 45 calendar days.

An authorized agent may also submit a request on your behalf with a written signed permission from you.

XIV. Other Terms

If Thplus discovers or receives reports or complaints that a user has violated applicable agreements, platform rules, laws, or regulations, Thplus may review and process relevant content and accounts according to the severity of the violation, including but not limited to warnings, account restrictions, function restrictions, or other measures permitted by law and agreement. Users may contact Thplus regarding related processing results. Users shall bear legal liability for their own violations of laws, regulations, or agreements.