Captcha v4

Compliance and Privacy

Privacy notice for Captcha v4 data processing across Web/H5, iOS, and Android

This Product Privacy Notice applies when a customer integrates Geelab Captcha v4 into its website, H5 page, iOS application, or Android application. It supplements the Geelab Privacy Policy for this product.

Captcha v4 is a security service used to identify genuine user interactions and defend against automated attacks, mass registration, credential stuffing, interface abuse, malicious scripts, and other abusive behavior.

1. Processing Role

On customer websites or applications, the customer usually determines whether to integrate Captcha v4, the integration scenarios, verification trigger conditions, and how verification results are used in the customer's business. Therefore, for end user data, the customer is usually the controller or business, and Geelab usually provides verification services as the customer's processor, service provider, or contractor.

Geelab does not directly decide whether a customer allows end users to register, log in, place orders, post content, or continue access. The customer shall make final decisions based on its own business rules.

Geelab will not use customer end user data for advertising targeting, cross-site tracking for non-security purposes, user profiling for other customers, or make raw data that identifies a single customer or end user available to other customers.

2. Supported Platforms

Geelab Captcha v4 currently supports:

  • Web/H5
  • iOS
  • Android

3. Processing Purposes

Geelab may process Captcha v4 data for the following purposes:

  • Providing captcha loading, display, interaction, verification, and result return
  • Determining whether access requests involve automation, scripts, crawlers, batch requests, credential stuffing, or other abnormal risks
  • Helping customers protect account security scenarios such as registration, login, password recovery, and pre-checks before SMS or email verification-code sending
  • Helping customers protect transaction points such as order placement, payment, withdrawal, and refund
  • Helping customers protect content interaction points such as comments, posts, likes, voting, and following
  • Helping customers protect marketing activity points such as event registration, coupon claiming, lottery, and points redemption
  • Helping customers protect interface access, API calls, crawler defense, and abnormal traffic defense scenarios
  • Preventing captcha bypass, cracking, replay, interface abuse, and malicious attacks
  • Providing service monitoring, troubleshooting, security audit, log analysis, and technical support
  • Using aggregated, anonymized, or de-identified data to optimize verification experience, accuracy, stability, and security models
  • Fulfilling legal, regulatory, judicial, or compliance obligations

4. Information That May Be Processed

To provide verification and security analysis capabilities, Captcha v4 may process the following information. The information actually processed depends on endpoint platform, SDK version, customer configuration, system permissions, browser or operating system restrictions, and end user authorization status.

4.1 Device Information

Personal information typeConfigurableUse and purposeFrequencyEndpoint
Device brandNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Device modelNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Device systemNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Device versionNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Device languageNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Device nameNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Memory sizeNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Carrier nameNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Screen heightNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Screen widthNoSupporting business and security policiesPassively obtained on each callAndroid, iOS
Whether tabletNoSupporting business and security policiesPassively obtained on each callAndroid, iOS

4.2 Network Information

Personal information typeConfigurableUse and purposeFrequencyEndpoint
IP addressNoSupporting business and security policiesPassively obtained on each callAndroid, iOS, Web/H5
Whether Wi-FiNoSupporting business and security policiesPassively obtained on each callAndroid, iOS, Web/H5
Network generation/typeNoSupporting business and security policiesPassively obtained on each callAndroid, iOS, Web/H5

4.3 Log Information

Personal information typeConfigurableUse and purposeFrequencyEndpoint
IP addressNoTraffic statistics, abnormality troubleshooting, and abuse or security incident detectionPassively obtained when accessing or calling the serviceAndroid, iOS, Web/H5
Browser typeNoTraffic statistics, abnormality troubleshooting, and abuse or security incident detectionPassively obtained when accessing or calling the serviceWeb/H5
Operating systemNoTraffic statistics, abnormality troubleshooting, and abuse or security incident detectionPassively obtained when accessing or calling the serviceAndroid, iOS, Web/H5
Date/timestampNoTraffic statistics, abnormality troubleshooting, and abuse or security incident detectionPassively obtained when accessing or calling the serviceAndroid, iOS, Web/H5
Clickstream dataNoTraffic statistics, abnormality troubleshooting, and abuse or security incident detectionPassively obtained when accessing or calling the serviceWeb/H5

4.4 Android Operating System Application Permissions

PermissionPermission categoryUse and purposeRequest timing
android.permission.INTERNETRequiredDevice network accessApp first installation

4.5 iOS Operating System Application Permissions

PermissionPermission categoryUse and purposeRequest timing
CellularRequiredNetwork requestsWhen accessing the network through cellular network during calls

In addition to the above information, Captcha v4 may generate or process verification tokens, challenge IDs, verification results, error codes, verification status, and necessary customer configuration information during service operation, for captcha loading, display, interaction, server-side verification, result return, troubleshooting, and security audit.

Geelab Captcha v4 does not by default require end users to provide names, government-issued identification numbers, bank card numbers, precise geolocation, contacts, SMS messages, photos, audio, video, or account passwords.

The Captcha v4 SDK should not read customer page form content, password fields, SMS verification codes, payment credentials, or user-entered business content unless the customer separately and actively submits such information and has completed necessary notice and authorization.

5. How Customers Use Verification Results

Customers may take the following actions based on verification results returned by Captcha v4:

  • Allow the request
  • Require re-verification
  • Add secondary verification
  • Rate-limit or delay processing
  • Submit to manual review
  • Reject high-risk requests

Customers shall ensure that use of verification results is lawful, reasonable, transparent, and consistent with notices to end users. Customers shall bear all risks and responsibilities for business actions based on verification results, including without limitation allowing, rejecting, secondary verification, and rate limiting. Geelab is not responsible for customer business decisions.

6. Cookies, Local Storage, and SDK Identifiers

To ensure the normal operation of Captcha v4 and related functions, Geelab may store small data files called cookies on a computer or mobile device, and use local storage, session storage, cache, SDK tokens, anonymous identifiers, device-related technical identifiers, and other similar technologies. Cookies usually contain identifiers, site names, and certain numbers and characters.

Captcha v4 may use cookies, local storage, cache, verification tokens, and similar technologies to complete verification flows, identify abnormal access, maintain verification status, and prevent replay attacks.

7. Data Sharing

Geelab does not sell Captcha v4 end user data. Geelab may share relevant data within the following scope:

  • Returning verification results, verification tokens, error codes, logs, or necessary technical information to the customer
  • Disclosing necessary information as required by law, regulation, judicial process, or security incident handling
  • Using anonymized or aggregated data to improve services and security models

Geelab will not disclose a customer's raw verification logs, raw interaction data, or request logs that identify end users to other customers.

8. Data Retention

Captcha v4 data is retained only for the period necessary to provide verification, security analysis, troubleshooting, compliance audit, and dispute handling.

Unless otherwise agreed in an order, product configuration, or data processing agreement, the following retention periods apply:

Data categoryRetention period
Verification tokens and temporary status10 minutes
Verification logs, security logs, and error logsNo more than 12 months
Customer configuration and application informationDuring the customer account term
Aggregated, anonymous, or de-identified dataMay be retained long-term where it does not identify an individual or customer

If a customer requests deletion or export of data related to its application, Geelab will assist according to the data processing agreement and available technical capabilities. Backup data will be deleted on a rolling basis according to backup cycles.

9. Data Region

Captcha v4 may use Global, Europe, or North America service regions depending on customer configuration. Customers shall select an appropriate region based on business coverage and compliance requirements, and ensure that client and server configurations are consistent.

For current region planning guidance, see Region Selection.

10. Customer Notice Obligations

Customers shall explain their integration of Geelab Captcha v4 in a privacy policy, Cookie/SDK list, application permission notice, or other appropriate location, and explain processing purposes, data types, service provider, collection methods, data sharing, retention period, user rights channels, and contact details.

When integrating Geelab Captcha v4, customers shall comply with the following requirements:

  • Before initializing or calling the Geelab SDK, display a clear and easily accessible privacy notice to end users and, where required by applicable law, obtain consent or ensure another lawful processing basis
  • List in the notice text the Geelab Captcha v4 service, service provider GEELAB PTE. LTD., the Geelab Captcha v4 Product Privacy Notice, processing purposes, possible information categories, cookies, local storage or SDK identifiers, data region, and user-rights exercise method
  • If the customer uses system permissions or other local capabilities on mobile endpoints in connection with captcha services, the customer shall separately display permission notices according to platform rules and obtain end user authorization where required by applicable law or platform rules
  • Without necessary notice or authorization to end users, the customer shall not initialize or call Geelab Captcha v4 during first app launch, before the privacy pop-up is displayed, in unrelated background scenarios, or in scenarios unrelated to captcha security purposes
  • The customer shall provide rights channels for access, correction, deletion, restriction, objection, data portability, and consent withdrawal, and serve as the primary respondent to end user requests
  • If the customer receives an end user request related to Geelab Captcha v4, the customer may contact Geelab where necessary. Geelab will assist in locating, exporting, deleting, or restricting relevant data within commercially reasonable efforts. The customer shall bear the reasonable costs incurred by Geelab in providing assistance, including labor and technical implementation costs. Geelab may require the customer to prepay reasonable costs before providing assistance
  • If the customer uses captcha results in high-impact scenarios, the customer shall provide reasonable review, appeal, or correction mechanisms and avoid making decisions that have significant effects on natural persons based solely on a single captcha result
  • If the customer changes the use purpose, trigger scenario, data category, retention period, or sharing arrangement for Captcha v4, the customer shall promptly update its privacy notice and, where required by applicable law, re-obtain consent or confirm the lawful processing basis

Reference Notice Text

To protect account security, transaction security, and service stability, we have integrated the Geelab Captcha v4 service provided by GEELAB PTE. LTD. This service may process your device information, browser or application runtime environment information, network information, log information, verification tokens, verification results, and security risk signals through SDKs, cookies, local storage, network requests, and server-side verification, for identifying abnormal behavior such as automated attacks, malicious scripts, batch requests, credential stuffing, and interface abuse. Geelab will process relevant information according to our instructions and will not use such information for cross-context behavioral advertising or sale. You may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the channels listed in our privacy policy.

Reference Disclosure Example

Disclosure itemExample content
Third-party service nameGeelab Captcha v4 service
Service providerGEELAB PTE. LTD.
Purpose of useAccount security, transaction security, marketing anti-cheating, anti-automation attacks, abnormal traffic identification, captcha verification, service security audit, and troubleshooting
Use scenariosUser registration, login, password recovery, pre-check before SMS or email verification-code sending, order placement, payment, withdrawal, refund, comment, post, like, vote, activity participation, interface access, API call, crawler defense, abnormal traffic defense, or other scenarios requiring automated risk identification
Information that may be processedDevice information, network information, log information, clickstream data, verification tokens, challenge IDs, verification results, error codes, verification status, and necessary customer configuration information
Processing methodCollection, transmission, computation, verification, result return, logging, deletion, anonymization, or aggregation analysis through SDK, network request, and server-side verification
Data sharing and roleGeelab processes relevant information according to our instructions and returns captcha verification results and necessary technical information to us. Geelab will not use relevant information for cross-context behavioral advertising or sale
User rightsYou may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the contact details or rights request channels listed in this privacy policy
Third-party privacy policyGeelab Captcha v4 Product Privacy Notice

11. Content Not Processed

Unless a customer separately submits such information or the parties otherwise agree in writing, Geelab Captcha v4 does not actively collect:

  • End user names, email addresses, or phone numbers
  • Account passwords, payment passwords, or payment credentials
  • Government-issued identification numbers or bank card numbers
  • Contacts, SMS messages, or call records
  • Photos, audio, or video
  • Precise geolocation
  • Raw biometric data used to identify a natural person, such as facial images, fingerprint images, or raw voiceprint samples
  • Page form content, password fields, payment credentials, or user-entered business content, unless the customer actively submits such information and has completed necessary notice and authorization

12. Contact

If you have questions about Captcha v4 data processing, please contact: