Legal

Global privacy policy, telemetry constraints, and cryptographic data handling

Universal compliance instrument · binding upon platform use

Legal instrument

ZALIPLAY GLOBAL PRIVACY POLICY

Last Updated: June 30, 2026

ZALIPLAY GLOBAL PRIVACY POLICY

Last Updated: June 30, 2026

This Global Privacy Policy describes how Zaliplay ("the Platform", "we", "us") collects, processes, stores, and protects personal data across web, mobile, and live-streaming surfaces. By creating an account or using the Platform, you consent to the practices described herein.

SECTION 1: CATEGORIES OF DATA WE COLLECT

We collect the minimum data required to operate a global creator economy and content delivery network.

  1. 1.1

    ACCOUNT IDENTITY DATA: Email address, phone number (E.164), username, display name, country code, password hash (bcrypt), and optional tax identifiers for payout compliance.

  2. 1.2

    TELEMETRY & SESSION DATA: Playback position, ad-impression timestamps, live-chat participation, withdrawal metadata, and API fingerprints for rate limiting and financial integrity.

  3. 1.3

    DEVICE METRIC DATA: Browser user-agent, viewport dimensions, connection quality hints, and coarse interaction signals (focus, visibility) for attention validation.

SECTION 2: TOWN SQUARE GEOGRAPHIC POSITION DATA

Geographic position data is used transparently and dynamically solely to render proximity live-stream map pins inside our Town Square layout engine.

  1. 2.1

    When you open Town Square, the client may request device geolocation permission. Coordinates are converted to geohash prefixes and sent to our discovery API to fetch nearby live nodes and sponsored Launchpad pins.

  2. 2.2

    We do not store continuous GPS trails by default. Location queries are ephemeral routing inputs unless you explicitly save a pinned location in a feature that discloses persistence.

  3. 2.3

    Deny or revoke location permissions at any time; Town Square falls back to a regional default grid without precise positioning.

SECTION 3: POINTER EVENTS & SCROLL VELOCITY METRICS

Pointer event data and viewport scrolling acceleration metrics are processed locally on your device to optimize immediate feed personalization.

  1. 3.1

    Scroll velocity, dwell time, and card interest signals are computed in-browser to power our micro-behavioral feed engine and thematic prefetch of shorts trays.

  2. 3.2

    Raw pointer trajectories are not uploaded verbatim. Aggregated interest tags and creator affinity scores may sync to your account levers when authenticated.

  3. 3.3

    Anonymous sessions discard local velocity buffers on tab close unless converted to an account-backed preference profile.

SECTION 4: CRYPTOGRAPHIC HASHING & PSEUDONYMIZATION

  1. 4.1

    DEVICE SIGNATURE HASHING: Client applications generate a stable device signature using SHA-256 over a salted fingerprint bundle. Only digests are transmitted for relay-reward attestation.

  2. 4.2

    ATTENTION HEARTBEAT INTEGRITY: Live-viewer heartbeats use HMAC-SHA256 with a server-shared secret. Payloads include hashed session tokens — never raw keystroke content.

  3. 4.3

    PASSWORD & TOKEN STORAGE: Passwords are hashed with bcrypt. Refresh tokens are stored as opaque SHA-256 digests. JWT access tokens are short-lived.

SECTION 5: MACHINE LEARNING & RECOMMENDATION PROCESSING

  1. 5.1

    Video and audio features may be analyzed to improve recommendations, Catalyst timing, and copyright detection. See Terms of Service Section 8 for license scope.

  2. 5.2

    We do not sell personal profiles to third-party data brokers. Aggregated analytics may be shared with infrastructure subprocessors under data-processing agreements.

SECTION 6: DATA SHARING, TRANSFERS & YOUR RIGHTS

  1. 6.1

    PROCESSORS: Cloud hosting, payment rails, and transcoding partners receive only fields necessary for their service.

  2. 6.2

    CROSS-BORDER TRANSFERS: Data may be processed in the United States, European Union, or other infrastructure regions with appropriate safeguards.

  3. 6.3

    YOUR RIGHTS: You may request access, correction, portability, or deletion subject to our Account Deletion Protocol. Financial ledger entries may be retained as legally required.

Return to Creator Command Center