Device Fingerprint

Compliance and Privacy

Privacy notice for Geelab Device Fingerprint data processing and customer disclosure obligations

This Product Privacy Notice applies where a customer integrates the Geelab Device Fingerprint service into its website, H5 page, iOS application, or Android application. It supplements the Privacy Policy for this product.

This Notice helps customers understand the data categories, processing purposes, role allocation, retention, cross-border processing, and end user notice requirements involved in the Geelab Device Fingerprint service.

This Notice does not replace the customer's own privacy policy, Cookie/SDK notice, application permission notice, or consent management mechanism for end users.

Customers shall determine whether and how to disclose the Geelab Device Fingerprint service to end users based on business scenarios, applicable regions, end user locations, integration platforms, SDK versions, system permissions, and order configurations.

The Geelab Device Fingerprint service helps customers identify device identity, assess device runtime environment risks, and provide device-risk assistance in scenarios such as registration, login, transactions, marketing anti-cheating, content interaction, and game security.

1. Processing Role

Customers determine whether to integrate the Device Fingerprint service, the platforms and business scenarios for integration, trigger timing, service region, business context, and how to use device risk results. Therefore, for end user data, customers are usually the controller or business, and Geelab usually processes relevant data as the customer's processor, service provider, or contractor.

Geelab provides device identification and risk identification results, but usually does not directly make final decisions facing end users regarding registration, login, transaction, marketing risk-control actions, account bans, or other decisions with legal or similarly significant effects. Customers shall make final business decisions based on their own rules, manual review, and other risk-control signals.

Geelab will not use customer end user data for advertising targeting, cross-site tracking for non-security purposes, user profiling for other customers, or make raw data that identifies a single customer or end user available to other customers.

2. Supported Client Platforms

Geelab Device Fingerprint currently supports:

  • Web/H5
  • iOS
  • Android

3. Processing Purposes

Geelab may process Device Fingerprint data for the following purposes:

  • Generating or assisting in generating stable device identifiers
  • Identifying same-device reuse, multi-account association, abnormal access sources, and device reuse risks within the customer's own business scope
  • Identifying emulators, cloud phones, virtual machines, Root, jailbreak, Hook, code injection, debugging, automated environments, environment spoofing, browser private mode, or other high-risk runtime states
  • Returning results such as fp, risk_code, risk_label, client_ip, client_type, and access_list
  • Helping customers conduct risk control in registration, login, transaction, marketing anti-cheating, content interaction, and game security scenarios
  • Preventing fraud, automated attacks, mass registration, credential stuffing, account abuse, fake transactions, activity cheating, fake traffic or reviews, and interface abuse
  • Providing service monitoring, troubleshooting, log audit, security response, and technical support
  • Using aggregated, anonymized, or de-identified data to improve device risk identification capabilities, model accuracy, service stability, and security
  • Fulfilling legal, regulatory, judicial, or compliance obligations

Geelab will not use customer end user data for advertising targeting, cross-context behavioral advertising, cross-site profiling for non-security purposes, single-user identification for other customers, or commercial marketing unrelated to device risk identification and security protection.

Where the GDPR, UK GDPR, or other data processing laws apply, the customer is usually responsible for determining the legal basis for using the Device Fingerprint service, such as legitimate interests, consent, performance of a contract, legal obligation, or another applicable basis. The customer shall complete necessary assessments before integration and explain the legal basis in its privacy notice.

When Geelab acts as the customer's processor, it usually processes customer end user data according to customer instructions, the service agreement, and the data processing agreement. When Geelab independently processes customer contact and account data for Console accounts, customer support, billing, contracts, security operations, service improvement, or legal obligations, Geelab may act as a controller or independent responsible party, as described in the Geelab Privacy Policy.

3.2 U.S. State Privacy Law Disclosures

Where the CCPA/CPRA or other U.S. state privacy laws apply, the Geelab Device Fingerprint service is used for security and integrity, fraud prevention, service provision, debugging, quality assurance, internal operations, attack detection, and risk assistance purposes. Geelab does not sell customer end user data and will not share customer end user data for cross-context behavioral advertising.

Customers should still confirm, based on their own business, whether they have obligations relating to sale, sharing, targeted advertising, use of sensitive personal information, automated decision-making, consumer requests, authorized agents, appeals, or global privacy control signals.

4. Information That May Be Processed

Geelab Device Fingerprint performs identification based on multi-dimensional weak features and security signals. By default, it does not require end users to provide names, government-issued identification numbers, bank card numbers, account passwords, contacts, SMS messages, photos, audio, video, or raw biometric data.

The Geelab Device Fingerprint SDK should not read customer page form content, password fields, SMS verification codes, payment credentials, or user-entered business content unless the customer separately and actively submits such information and has completed necessary notice and authorization.

The information actually processed depends on endpoint platform, SDK version, customer configuration, system permissions, browser or operating system restrictions, and end user authorization status. Geelab processes relevant information only to the extent necessary for device fingerprint generation, device risk identification, server-side query, troubleshooting, security audit, and technical support.

This Notice discloses data categories, processing purposes, recipient categories, retention periods or criteria, cross-border transfers, and rights channels. Geelab will not disclose complete algorithms, risk rules, weights, thresholds, model feature combinations, or details that could be used to circumvent risk-control measures.

Data categoryRepresentative examplesPrimary purposes
Device and system informationDevice model, brand, system platform, system version, system language, screen parameters, device type, memory, system propertiesDevice identification, device environment risk identification, abnormal device detection
Browser and runtime environment informationUser agent, browser information, browser language, time zone, resolution, plugin information, storage capability, cookie-enabled statusWeb/H5 device fingerprint generation, automated environment and abnormal browser detection
Network informationIP address, network type, network generation, carrier-related informationRegional routing, risk identification, security audit, troubleshooting
Local technical identifiers and SDK tokensCookies, local storage, session storage, cache, Keychain, SharedPreferences, SDK tokens, device-related technical identifiersToken generation, device continuity identification, server-side query, and risk judgment
Risk results and server-side query resultsfp, risk_code, risk_label, client_ip, client_type, access_listReturning device fingerprints, risk labels, risk codes, and list-hit results to customers
Logs and request contextRequest time, access logs, error logs, security logs, necessary request contextService monitoring, troubleshooting, security response, compliance audit
Necessary business context submitted by customersApplication ID, scene identifier, business serial number, order number, or other context configured by customersHelping customers make risk judgments within business scenarios. Customers are responsible for ensuring submitted content is lawful, necessary, and disclosed

5. Server-Side Result Data

Customer servers may call the Device Fingerprint query API to obtain final results. Server-side queries usually involve customer application ID, query token, request time, device fingerprint value, risk code, risk label, client IP, client type, list-hit result, and necessary business context.

Customers shall submit business context only to the extent relevant and necessary for device risk identification, and shall avoid submitting sensitive information unrelated to device risk identification. Customers shall properly protect server-side keys such as private_key and shall not embed keys in clients, front-end pages, public repositories, or other insecure environments.

Geelab is not responsible for data security incidents caused by customers embedding server-side keys such as private_key in clients, public repositories, or insecure environments.

Geelab processes necessary context only according to customer configurations and service interfaces. If a customer submits user IDs, order numbers, phone numbers, email addresses, or other identifiable information, the customer is responsible for the lawfulness, necessity, and notice obligations for such information.

6. Device Risk Identification Scope

Geelab Device Fingerprint may identify the following risks:

  • Emulators, virtual devices, cloud phones, or virtual machines
  • Root, jailbreak, or system tampering
  • Hook, code injection, repackaging, or signature abnormality
  • Debugging, automation tools, or script environments
  • System clones, multi-instance environments, or environment spoofing
  • Browser private mode or abnormal browser environments
  • Device reuse, multi-account association, abnormal frequency, or list hits

To avoid reducing risk-control effectiveness, this Notice discloses only risk-identification categories. Geelab will not disclose complete risk codes, hit rules, weights, thresholds, bypass detection details, or anti-circumvention logic.

7. How Customers Use Results

Customers may use device fingerprint results and risk results to:

  • Allow requests
  • Trigger Captcha v4 or other secondary verification
  • Rate-limit, demote, or delay processing
  • Conduct manual review
  • Strengthen identity verification
  • Reject high-risk requests
  • Apply blacklist, whitelist, or device-list strategies

Customers should avoid making decisions that have significant effects on end users based solely on a single device risk result. For high-impact scenarios, customers are advised to combine manual review, appeal mechanisms, and other risk signals.

If a customer uses device fingerprint results for blacklists, whitelists, device lists, or account actions, the customer is responsible for list sources, list updates, false-positive handling, appeals, and correction mechanisms. Geelab only returns relevant hit results according to customer configurations or interfaces, unless otherwise agreed in writing.

Customers shall bear all risks and responsibilities for business decisions made based on device fingerprint results. Geelab is not responsible for customer business actions, including allowing, blocking, rate limiting, review, or similar actions.

8. Cookies, Local Storage, and SDK Identifiers

To ensure the normal operation of the Device Fingerprint service and related functions, Geelab may store small data files called cookies on a computer or mobile device, and use local storage, session storage, cache, SDK tokens, anonymous identifiers, device-related technical identifiers, and other similar technologies. Cookies usually contain identifiers, site names, and certain numbers and characters.

The Device Fingerprint service may use cookies, local storage, cache, Keychain, SharedPreferences, SDK tokens, or similar technologies to support device identification, token generation, server-side queries, and risk identification.

End users may manage some local data through browser or device settings, but disabling or clearing relevant information may affect device identification accuracy or cause the customer to trigger additional verification, rate limiting, review, or access rejection.

9. Data Sharing

Geelab does not sell Device Fingerprint end user data. Geelab may share relevant data within the following scope:

  • Returning device fingerprints, risk codes, risk labels, client IP, client type, list-hit results, and necessary logs to customers
  • Disclosing necessary information as required by law, regulation, judicial process, or security incident handling
  • Using anonymized or aggregated data to improve services and security models

Geelab will not disclose a customer's raw device fingerprints, raw collection signals, list data, or query logs that identify end users to other customers.

10. Data Retention

Device Fingerprint data is retained only for the period necessary for device identification, security analysis, troubleshooting, compliance audit, dispute handling, and service improvement.

Unless otherwise agreed in an order, product configuration, or data processing agreement, the following retention periods apply:

Data categoryRetention period
Temporary tokens, online or offline query status10 minutes
Raw collection signalsNo more than 12 months
fp, risk_code, risk_label, client_ip, client_type, access_list query resultsNo more than 12 months
Security logs, error logs, and audit logsNo more than 12 months
Customer application configurations, list configurations, and key metadataDuring the customer account term
Aggregated, anonymous, or de-identified dataMay be retained long-term where it does not identify an individual or customer

If a customer requests deletion or export of data related to its application, Geelab will assist according to the data processing agreement and available technical capabilities. Backup data will be deleted on a rolling basis according to backup cycles.

11. Data Region

The Device Fingerprint service may use Global, Europe, or North America service regions depending on customer configuration. Customers shall select an appropriate region based on business coverage and compliance requirements, and ensure that client and server configurations are consistent.

For current region planning guidance, see Region Selection.

12. Customer Notice Obligations

Customers shall explain their integration of the Geelab Device Fingerprint service in a privacy policy, Cookie/SDK list, application permission notice, or other appropriate location, and explain processing purposes, data categories, service provider, collection methods, data sharing, retention period, user rights channels, and contact details.

Customers are advised to use layered notices:

  • Disclose the Geelab Device Fingerprint service, processing purposes, personal data categories, recipient categories, retention periods or criteria, cross-border transfers, user rights, and contact details in the main privacy policy
  • Disclose cookies, local storage, SDK tokens, local technical identifiers, whether they are necessary or security technologies, storage duration, and management method in the Cookie, Tracker, or SDK list
  • Explain in iOS, Android permission notices or App Store or Google Play data safety disclosures whether optional capabilities such as IDFA, advertising ID, location, Wi-Fi, and device status are enabled, their trigger timing, and their purposes
  • Maintain more detailed technical signal lists and integration instructions in developer documentation, while avoiding public disclosure of complete algorithms, model weights, risk thresholds, hit rules, or bypass detection details

When integrating the Geelab Device Fingerprint service, customers shall comply with the following requirements:

  • Before initializing or calling the Geelab SDK, display a clear and easily accessible privacy notice to end users and, where required by applicable law, obtain consent or ensure another lawful processing basis
  • List in the notice text the Geelab Device Fingerprint service, service provider GEELAB PTE. LTD., the Geelab Device Fingerprint Product Privacy Notice, processing purposes, possible data categories, local storage or SDK identifiers, data region, and user-rights exercise method
  • For IDFA, location, Wi-Fi, device status, advertising identifiers, or other optional capabilities controlled by system permissions, the customer shall separately display permission notices according to platform rules and enable relevant capabilities only after end user authorization
  • Without necessary notice or authorization to end users, the customer shall not initialize or call the Geelab Device Fingerprint service during first app launch, before the privacy pop-up is displayed, in unrelated background scenarios, or in scenarios unrelated to device risk identification
  • The customer shall provide rights channels for access, correction, deletion, restriction, objection, data portability, and consent withdrawal, and serve as the primary respondent to end user requests
  • If the customer receives an end user request related to the Geelab Device Fingerprint service, the customer may contact Geelab where necessary. Geelab will assist in locating, exporting, deleting, or restricting relevant data within commercially reasonable efforts. The customer shall bear the reasonable costs incurred by Geelab in providing assistance, including labor and technical implementation costs. Geelab may require the customer to prepay reasonable costs before providing assistance
  • If the customer uses device fingerprint results in high-impact scenarios, the customer shall provide reasonable review, appeal, or correction mechanisms and avoid making decisions that have significant effects on natural persons based solely on a single device risk result
  • If the customer changes the use purpose, trigger scenario, data category, retention period, or sharing arrangement for the Device Fingerprint service, the customer shall promptly update its privacy notice and, where required by applicable law, re-obtain consent or confirm the lawful processing basis

Reference Notice Text

To protect account security, transaction security, fairness of marketing activities, and service stability, we have integrated the Geelab Device Fingerprint service provided by GEELAB PTE. LTD. This service may process your device and system information, browser or application runtime environment information, network information, necessary local technical identifiers, SDK tokens, device fingerprint results, risk codes, risk labels, client IP, client type, and list-hit information through SDKs, local storage, network requests, and server-side queries, for identifying abnormal devices, automated environments, emulators, Root or jailbreak, Hook, debugging, environment spoofing, device reuse, multi-account association, mass registration, credential stuffing, fake transactions, activity cheating, and other security risks. Geelab will process relevant information according to our instructions and will not use such information for cross-context behavioral advertising or sale. You may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the channels listed in our privacy policy.

Reference Disclosure Example

Disclosure itemExample content
Third-party service nameGeelab Device Fingerprint service
Service providerGEELAB PTE. LTD.
Purpose of useAccount security, transaction security, marketing anti-cheating, anti-fraud, anti-automation attacks, device environment risk identification, abnormal access identification, service security audit, and troubleshooting
Use scenariosUser registration, login, transaction, activity participation, content interaction, interface access, risk request verification, or other scenarios requiring device risk identification
Information that may be processedDevice information, system information, browser or application runtime environment information, network information, log information, local technical identifiers, SDK tokens, device fingerprint results, risk codes, risk labels, client IP, client type, and list-hit information
Processing methodCollection, transmission, computation, identification, result return, logging, deletion, anonymization, or aggregation analysis through SDKs, local storage, network requests, and server-side queries
Data sharing and roleGeelab processes relevant information according to our instructions and returns device fingerprints and device risk identification results to us. Geelab will not use relevant information for cross-context behavioral advertising or sale
User rightsYou may exercise rights such as access, correction, deletion, restriction, objection, data portability, and consent withdrawal through the contact details or rights request channels listed in this privacy policy
Third-party privacy policyGeelab Device Fingerprint Product Privacy Notice

13. Content Not Processed

Unless a customer separately submits such information or the parties otherwise agree in writing, the Geelab Device Fingerprint service does not actively collect:

  • End user names, email addresses, or phone numbers
  • Account passwords, payment passwords, or payment credentials
  • Government-issued identification numbers or bank card numbers
  • Contacts, SMS messages, or call records
  • Photos, audio, or video
  • Precise geolocation used for continuous tracking, trajectory analysis, or non-security purposes
  • Raw biometric data used to identify a natural person, such as facial images, fingerprint images, or raw voiceprint samples
  • Page form content, password fields, payment credentials, or user-entered business content, unless the customer actively submits such information and has completed necessary notice and authorization

14. Contact

If you have questions about Device Fingerprint data processing, please contact: