Compliance and Privacy
Privacy notice for Captcha v4 data processing across Web/H5, iOS, and Android
This Product Privacy Notice applies when a customer integrates Geelab Captcha v4 into its website, H5 page, iOS application, or Android application. It supplements the Geelab Privacy Policy for this product.
Captcha v4 is a security service used to identify genuine user interactions and defend against automated attacks, mass registration, credential stuffing, interface abuse, malicious scripts, and other abusive behavior.
1. Processing Role
On customer websites or applications, the customer usually determines whether to integrate Captcha v4, the integration scenarios, verification trigger conditions, and how verification results are used in the customer's business. Therefore, for end user data, the customer is usually the controller or business, and Geelab usually provides verification services as the customer's processor, service provider, or contractor.
Geelab does not directly decide whether a customer allows end users to register, log in, place orders, post content, or continue access. The customer shall make final decisions based on its own business rules.
Geelab will not use customer end user data for advertising targeting, cross-site tracking for non-security purposes, user profiling for other customers, or make raw data that identifies a single customer or end user available to other customers.
2. Supported Platforms
Geelab Captcha v4 currently supports:
- Web/H5
- iOS
- Android
3. Processing Purposes
Geelab may process Captcha v4 data for the following purposes:
- Providing captcha loading, display, interaction, verification, and result return
- Determining whether access requests involve automation, scripts, crawlers, batch requests, credential stuffing, or other abnormal risks
- Helping customers protect account security scenarios such as registration, login, password recovery, and pre-checks before SMS or email verification-code sending
- Helping customers protect transaction points such as order placement, payment, withdrawal, and refund
- Helping customers protect content interaction points such as comments, posts, likes, voting, and following
- Helping customers protect marketing activity points such as event registration, coupon claiming, lottery, and points redemption
- Helping customers protect interface access, API calls, crawler defense, and abnormal traffic defense scenarios
- Preventing captcha bypass, cracking, replay, interface abuse, and malicious attacks
- Providing service monitoring, troubleshooting, security audit, log analysis, and technical support
- Using aggregated, anonymized, or de-identified data to optimize verification experience, accuracy, stability, and security models
- Fulfilling legal, regulatory, judicial, or compliance obligations
4. Information That May Be Processed
To provide verification and security analysis capabilities, Captcha v4 may process the following information. The information actually processed depends on endpoint platform, SDK version, customer configuration, system permissions, browser or operating system restrictions, and end user authorization status.
4.1 Device Information
| Personal information type | Configurable | Use and purpose | Frequency | Endpoint |
|---|---|---|---|---|
| Device brand | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Device model | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Device system | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Device version | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Device language | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Device name | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Memory size | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Carrier name | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Screen height | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Screen width | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
| Whether tablet | No | Supporting business and security policies | Passively obtained on each call | Android, iOS |
4.2 Network Information
| Personal information type | Configurable | Use and purpose | Frequency | Endpoint |
|---|---|---|---|---|
| IP address | No | Supporting business and security policies | Passively obtained on each call | Android, iOS, Web/H5 |
| Whether Wi-Fi | No | Supporting business and security policies | Passively obtained on each call | Android, iOS, Web/H5 |
| Network generation/type | No | Supporting business and security policies | Passively obtained on each call | Android, iOS, Web/H5 |
4.3 Log Information
| Personal information type | Configurable | Use and purpose | Frequency | Endpoint |
|---|---|---|---|---|
| IP address | No | Traffic statistics, abnormality troubleshooting, and abuse or security incident detection | Passively obtained when accessing or calling the service | Android, iOS, Web/H5 |
| Browser type | No | Traffic statistics, abnormality troubleshooting, and abuse or security incident detection | Passively obtained when accessing or calling the service | Web/H5 |
| Operating system | No | Traffic statistics, abnormality troubleshooting, and abuse or security incident detection | Passively obtained when accessing or calling the service | Android, iOS, Web/H5 |
| Date/timestamp | No | Traffic statistics, abnormality troubleshooting, and abuse or security incident detection | Passively obtained when accessing or calling the service | Android, iOS, Web/H5 |
| Clickstream data | No | Traffic statistics, abnormality troubleshooting, and abuse or security incident detection | Passively obtained when accessing or calling the service | Web/H5 |
4.4 Android Operating System Application Permissions
| Permission | Permission category | Use and purpose | Request timing |
|---|---|---|---|
android.permission.INTERNET | Required | Device network access | App first installation |
4.5 iOS Operating System Application Permissions
| Permission | Permission category | Use and purpose | Request timing |
|---|---|---|---|
| Cellular | Required | Network requests | When accessing the network through cellular network during calls |
In addition to the above information, Captcha v4 may generate or process verification tokens, challenge IDs, verification results, error codes, verification status, and necessary customer configuration information during service operation, for captcha loading, display, interaction, server-side verification, result return, troubleshooting, and security audit.
Geelab Captcha v4 does not by default require end users to provide names, government-issued identification numbers, bank card numbers, precise geolocation, contacts, SMS messages, photos, audio, video, or account passwords.
The Captcha v4 SDK should not read customer page form content, password fields, SMS verification codes, payment credentials, or user-entered business content unless the customer separately and actively submits such information and has completed necessary notice and authorization.
5. How Customers Use Verification Results
Customers may take the following actions based on verification results returned by Captcha v4:
- Allow the request
- Require re-verification
- Add secondary verification
- Rate-limit or delay processing
- Submit to manual review
- Reject high-risk requests
Customers shall ensure that use of verification results is lawful, reasonable, transparent, and consistent with notices to end users. Customers shall bear all risks and responsibilities for business actions based on verification results, including without limitation allowing, rejecting, secondary verification, and rate limiting. Geelab is not responsible for customer business decisions.
6. Cookies, Local Storage, and SDK Identifiers
To ensure the normal operation of Captcha v4 and related functions, Geelab may store small data files called cookies on a computer or mobile device, and use local storage, session storage, cache, SDK tokens, anonymous identifiers, device-related technical identifiers, and other similar technologies. Cookies usually contain identifiers, site names, and certain numbers and characters.
Captcha v4 may use cookies, local storage, cache, verification tokens, and similar technologies to complete verification flows, identify abnormal access, maintain verification status, and prevent replay attacks.
7. Data Sharing
Geelab does not sell Captcha v4 end user data. Geelab may share relevant data within the following scope:
- Returning verification results, verification tokens, error codes, logs, or necessary technical information to the customer
- Disclosing necessary information as required by law, regulation, judicial process, or security incident handling
- Using anonymized or aggregated data to improve services and security models
Geelab will not disclose a customer's raw verification logs, raw interaction data, or request logs that identify end users to other customers.
8. Data Retention
Captcha v4 data is retained only for the period necessary to provide verification, security analysis, troubleshooting, compliance audit, and dispute handling.
Unless otherwise agreed in an order, product configuration, or data processing agreement, the following retention periods apply:
| Data category | Retention period |
|---|---|
| Verification tokens and temporary status | 10 minutes |
| Verification logs, security logs, and error logs | No more than 12 months |
| Customer configuration and application information | During the customer account term |
| Aggregated, anonymous, or de-identified data | May be retained long-term where it does not identify an individual or customer |
If a customer requests deletion or export of data related to its application, Geelab will assist according to the data processing agreement and available technical capabilities. Backup data will be deleted on a rolling basis according to backup cycles.
9. Data Region
Captcha v4 may use Global, Europe, or North America service regions depending on customer configuration. Customers shall select an appropriate region based on business coverage and compliance requirements, and ensure that client and server configurations are consistent.
For current region planning guidance, see Region Selection.
10. Customer Notice Obligations
Customers shall explain their integration of Geelab Captcha v4 in a privacy policy, Cookie/SDK list, application permission notice, or other appropriate location, and explain processing purposes, data types, service provider, collection methods, data sharing, retention period, user rights channels, and contact details.
When integrating Geelab Captcha v4, customers shall comply with the following requirements:
- Before initializing or calling the Geelab SDK, display a clear and easily accessible privacy notice to end users and, where required by applicable law, obtain consent or ensure another lawful processing basis
- List in the notice text the Geelab Captcha v4 service, service provider
GEELAB PTE. LTD., the Geelab Captcha v4 Product Privacy Notice, processing purposes, possible information categories, cookies, local storage or SDK identifiers, data region, and user-rights exercise method - If the customer uses system permissions or other local capabilities on mobile endpoints in connection with captcha services, the customer shall separately display permission notices according to platform rules and obtain end user authorization where required by applicable law or platform rules
- Without necessary notice or authorization to end users, the customer shall not initialize or call Geelab Captcha v4 during first app launch, before the privacy pop-up is displayed, in unrelated background scenarios, or in scenarios unrelated to captcha security purposes
- The customer shall provide rights channels for access, correction, deletion, restriction, objection, data portability, and consent withdrawal, and serve as the primary respondent to end user requests
- If the customer receives an end user request related to Geelab Captcha v4, the customer may contact Geelab where necessary. Geelab will assist in locating, exporting, deleting, or restricting relevant data within commercially reasonable efforts. The customer shall bear the reasonable costs incurred by Geelab in providing assistance, including labor and technical implementation costs. Geelab may require the customer to prepay reasonable costs before providing assistance
- If the customer uses captcha results in high-impact scenarios, the customer shall provide reasonable review, appeal, or correction mechanisms and avoid making decisions that have significant effects on natural persons based solely on a single captcha result
- If the customer changes the use purpose, trigger scenario, data category, retention period, or sharing arrangement for Captcha v4, the customer shall promptly update its privacy notice and, where required by applicable law, re-obtain consent or confirm the lawful processing basis
Reference Notice Text
To protect account security, transaction security, and service stability, we have integrated the Geelab Captcha v4 service provided by GEELAB PTE. LTD. This service may process your device information, browser or application runtime environment information, network information, log information, verification tokens, verification results, and security risk signals through SDKs, cookies, local storage, network requests, and server-side verification, for identifying abnormal behavior such as automated attacks, malicious scripts, batch requests, credential stuffing, and interface abuse. Geelab will process relevant information according to our instructions and will not use such information for cross-context behavioral advertising or sale. You may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the channels listed in our privacy policy.
Reference Disclosure Example
| Disclosure item | Example content |
|---|---|
| Third-party service name | Geelab Captcha v4 service |
| Service provider | GEELAB PTE. LTD. |
| Purpose of use | Account security, transaction security, marketing anti-cheating, anti-automation attacks, abnormal traffic identification, captcha verification, service security audit, and troubleshooting |
| Use scenarios | User registration, login, password recovery, pre-check before SMS or email verification-code sending, order placement, payment, withdrawal, refund, comment, post, like, vote, activity participation, interface access, API call, crawler defense, abnormal traffic defense, or other scenarios requiring automated risk identification |
| Information that may be processed | Device information, network information, log information, clickstream data, verification tokens, challenge IDs, verification results, error codes, verification status, and necessary customer configuration information |
| Processing method | Collection, transmission, computation, verification, result return, logging, deletion, anonymization, or aggregation analysis through SDK, network request, and server-side verification |
| Data sharing and role | Geelab processes relevant information according to our instructions and returns captcha verification results and necessary technical information to us. Geelab will not use relevant information for cross-context behavioral advertising or sale |
| User rights | You may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the contact details or rights request channels listed in this privacy policy |
| Third-party privacy policy | Geelab Captcha v4 Product Privacy Notice |
11. Content Not Processed
Unless a customer separately submits such information or the parties otherwise agree in writing, Geelab Captcha v4 does not actively collect:
- End user names, email addresses, or phone numbers
- Account passwords, payment passwords, or payment credentials
- Government-issued identification numbers or bank card numbers
- Contacts, SMS messages, or call records
- Photos, audio, or video
- Precise geolocation
- Raw biometric data used to identify a natural person, such as facial images, fingerprint images, or raw voiceprint samples
- Page form content, password fields, payment credentials, or user-entered business content, unless the customer actively submits such information and has completed necessary notice and authorization
12. Contact
If you have questions about Captcha v4 data processing, please contact:
- Email:
[email protected]