LAST UPDATED: 01 JULY 2026 · EFFECTIVE IMMEDIATELY · v3.2

1 · Overview & Scope

This Privacy Policy (“Policy”) applies to the website lunjitrading.com (the “Website”) and to all mobile applications published by Lunji Trading (“we”, “us”, “our”) on the Apple App Store, Google Play Store, and any other distribution platform we may use (collectively, the “Apps”). It explains how we collect, use, disclose, and safeguard information when you visit the Website or use the Apps.

By accessing the Website or downloading, installing, or using any of the Apps, you confirm that you have read and understood this Policy. If you do not agree with any provision, please discontinue use immediately and uninstall the Apps.

Studio Name: Lunji Trading
Website: lunjitrading.com
Studio Address: University of Stirling Innovation Park, Stirling, Scotland, United Kingdom
General Contact: contact@lunjitrading.com
Support Contact: support@lunjitrading.com

Our overarching philosophy is privacy-by-default and data-minimisation. Our Apps are engineered to process as much data as possible on-device. Where networked services are required, we use end-to-end encryption and never sell personal data.

2 · Data Controller & Data Protection Officer

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws, the data controller is:

Lunji Trading
University of Stirling Innovation Park
Stirling, Scotland, United Kingdom
Email: contact@lunjitrading.com

We have appointed a Data Protection Officer (DPO) who can be contacted at contact@lunjitrading.com with the subject line “DPO”. The DPO oversees compliance with this Policy and applicable data protection legislation, and serves as the point of contact for supervisory authorities and data subjects.

For users in the United Kingdom, our nominated representative under Article 27 UK GDPR is available upon written request. For users in the European Union, our nominated representative under Article 27 EU GDPR is available upon written request.

3 · Information We Collect

We apply the principle of data minimisation. We collect the minimum information necessary to provide and improve our services. The categories of information we may collect include:

3.1 · Information You Provide Directly

  • Account information: When you create an account within any of our Apps, we collect an anonymous user identifier, your display name (if you choose one), and authentication credentials stored locally on your device.
  • Support correspondence: When you contact us via support@lunjitrading.com or the contact form on this Website, we collect your name, email address, company, and the contents of your message.
  • Newsletter opt-in: If you subscribe to updates, we collect your email address and consent timestamp.
  • Survey responses: Voluntary responses to in-app or email surveys about user experience.

3.2 · Information Collected Automatically

  • Device information: Device model, operating system version, app version, locale, and language settings.
  • Usage analytics: Aggregated, anonymised counts of feature usage, session duration, crash logs, and performance metrics. You may opt out of analytics in each App’s Settings panel.
  • IP address: Collected automatically by web servers when you visit the Website. Used for security (fraud prevention) and aggregated geographic analytics. Not used for advertising.
  • Advertising identifiers: Where advertising is enabled (see §7), the platform advertising identifier (IDFA on iOS, GAID on Android) is accessed subject to your consent via the App Tracking Transparency prompt or equivalent.

3.3 · User-Generated Content

Our Apps may allow you to create, store, and synchronise content (notes, documents, vaults, budgets, training data, etc.). All such content is stored on your device by default. Cloud synchronisation, where offered, is end-to-end encrypted with keys held solely on your devices — we cannot read your content.

4 · How We Use Information

We use the information we collect for the following purposes:

  • To operate, maintain, and improve the Website and Apps.
  • To provide customer support and respond to your enquiries.
  • To send you technical notices, security alerts, and administrative messages.
  • To send you product updates and newsletters only if you have explicitly opted in.
  • To detect, prevent, and address fraud, security incidents, and abuse.
  • To comply with legal obligations and enforce our Terms of Service.
  • To deliver advertising through third-party ad networks where you have given consent (see §7).
  • To generate aggregated, anonymised analytics that help us understand feature usage patterns.

We do not use your information for automated decision-making that produces legal effects concerning you, except as required for fraud prevention (e.g., automated bot detection).

6 · Sharing & Disclosure

We do not sell, rent, or lease your personal data to third parties. We may share information in the following limited circumstances:

  • Advertising networks: Where you have consented, advertising identifiers and contextual signals are shared with ad partners listed in §7 to deliver and measure advertising.
  • Service providers: Trusted vendors who perform services on our behalf (cloud hosting, email delivery, crash reporting) under strict data-processing agreements.
  • Legal compliance: Where required by valid legal process, court order, or applicable law.
  • Safety: Where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Lunji Trading, our users, or others.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.

Where personal data is shared with third-party processors, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs), Data Processing Agreements (DPAs), and equivalent mechanisms.

7 · Advertising Platforms (Ad Networks)

Some of our Apps integrate third-party advertising platforms to support free tiers and to keep the apps accessible to as many users as possible. Where present, these integrations are designed to comply with the Apple App Store Guidelines (notably Guidelines 5.1.1 and 5.1.2), the Google Play Developer Policy (Ads policy), the EU GDPR, the UK GDPR, the US CCPA/CPRA, the Brazilian LGPD, and applicable age-protection laws.

Advertising is always opt-in on iOS via the App Tracking Transparency (ATT) framework, and on Android via the appropriate privacy controls. Users can revoke consent at any time in device settings or within each App’s settings panel.

7.1 · Integrated Advertising Platforms

The following advertising platforms may be integrated within our Apps. Each operates under its own privacy policy; we list them so that you can review their practices.

  • Google AdMob (Google LLC) — in-app advertising, mediation platform, AdMob privacy & messaging. Governed by Google Privacy Policy and Google’s EU User Consent Policy.
  • Google AdSense / Google Mobile Ads SDK
  • Google Ad Manager (DFP)
  • Meta Audience Network (Meta Platforms, Inc.) — formerly Facebook Audience Network. Governed by Meta Privacy Policy.
  • Unity Ads (Unity Technologies)
  • AppLovin MAX / AppLovin Exchange (AppLovin Corporation)
  • Vungle (Vungle, Inc., now part of Liftoff)
  • ironSource / Supersonic Ads (ironSource, now Unity)
  • Chartboost (Chartboost, Inc., now part of LoopMe)
  • Tapjoy (Tapjoy, Inc.)
  • InMobi (InMobi Technology Services Pvt. Ltd.)
  • Pangle (ByteDance Ltd.) — TikTok / Pangle advertising network.
  • Mintegral (Mobvista International Technology Limited)
  • AdColony (AdColony, Inc., now part of Digital Turbine)
  • MoPub (Xandr) — historically; now consolidated into Xandr / Microsoft Advertising.
  • Amazon Publisher Services / Amazon Mobile Ads
  • Smaato (Smaato, Inc.)
  • Verizon Media / Yahoo Native
  • BidMachine
  • Ogury
  • DT Exchange (Digital Turbine Exchange)
  • Liftoff Monetize
  • Moloco
  • Yandex Ads (where serving Russian-language markets)
  • Tencent Ads / WeChat Ads (where serving Mainland China-distributed builds)
  • Start.io
  • Wortise

7.2 · Consent Management & IAB TCF

For Apps distributed in the European Economic Area (EEA), the United Kingdom, and Switzerland, advertising requires prior consent under the ePrivacy Directive. We implement an IAB-registered Consent Management Platform (CMP) that surfaces the IAB Transparency & Consent Framework (TCF v2.2) signal to all integrated vendors. Vendors not on the IAB Global Vendor List are blocked until consent is provided.

7.3 · Children-Directed Advertising

We do not serve personalised advertising to users under the age of 13 (or higher age of digital consent in the relevant jurisdiction). Our Apps that may attract a younger audience either (a) disable advertising entirely, (b) serve only contextual, non-personalised advertising, or (c) gate the entire App behind an age verification screen. See §12 for full age-related provisions.

7.4 · Sensitive Categories

Our advertising integrations respect sensitive-category restrictions: we do not permit behavioural targeting based on health conditions (e.g., pregnancy, mental health), sexual orientation, religious belief, political affiliation, or trade union membership. AdMob and the major networks offer sensitive-category exclusion APIs that we enable by default.

7.5 · Limit Ad Tracking / Opt-Out

You can opt out of personalised advertising at any time:

  • iOS: Settings → Privacy & Security → Tracking → toggle off “Allow Apps to Request to Track”.
  • Android: Settings → Privacy → Ads → “Opt out of Ads Personalisation”.
  • In-App: Each App’s settings panel exposes a privacy controls link.

8 · Ad Formats & Their Behaviour

Where advertising is enabled, the following formats may be presented. Each is designed to be dismissible, labelled as advertising, and never disguised as content.

8.1 · Banner Ads

Small, fixed-size or adaptive rectangular ad units displayed at the top or bottom of a screen. Banner ads load asynchronously and consume a constant amount of screen real estate. They do not interrupt the user’s flow and can be dismissed by closing the containing screen. Banner ads are typically filled via the SDKs listed in §7.1, with waterfall or bidding mediation managed by AdMob, AppLovin MAX, or equivalent platforms.

8.2 · Interstitial Ads

Full-screen ad units presented at natural transition points (e.g., between levels in a game, between screens in a workflow). They are clearly labelled “Advertisement”, display a countdown timer before the close button becomes interactive, and never appear back-to-back or interrupt an in-progress user action. Frequency capping is enforced to limit how often any one user sees an interstitial.

8.3 · Rewarded Video Ads

Opt-in video ads that users choose to watch in exchange for an in-app reward (e.g., unlocking a feature, extending a timer, receiving bonus content). The reward is contingent on completion of the video, and the user is informed in advance of the reward and the required watch duration. Rewarded video ads are particularly valued by ad networks and are subject to the most stringent content review by the mediation platforms.

8.4 · Native Ads

Ad units styled to match the surrounding content but always labelled with a visible “Ad” or “Sponsored” badge. Used sparingly to avoid deceiving the user.

8.5 · Open Ads (App-Open Ads)

Full-screen ads presented when the user re-opens the App after backgrounding it. Open ads include a clearly visible close button after a brief period and never block core functionality of the App beyond a few seconds. They are skipped entirely when the user has opted out of personalised advertising.

8.6 · MREC (Medium Rectangle) Ads

300×250 (or platform equivalent) in-feed ad units commonly used in scrollable content.

8.7 · Adherence to Platform Rules

All ad formats comply with Apple App Store Guideline 5 (specifically 5.1.1, 5.1.2, 5.1.3) and Google Play Developer Policy “Ads” section, including:

  • Clear “Advertisement” labelling.
  • No advertising to children under 13 in child-directed Apps.
  • No ads that simulate system alerts or interfere with normal operation.
  • Explicit handling of ATT on iOS 14.5+ and the Privacy Sandbox on Android.

9 · App Store Compliance

9.1 · Apple App Store

Our Apps published on the Apple App Store comply with the Apple Developer Program License Agreement, the App Store Review Guidelines (including Section 5 “Software Requirements” and Section 5.1 “Privacy”), the App Store Review Guidelines for Kids Category apps where applicable, and Apple’s Human Interface Guidelines. Each App ships with a clearly labelled Privacy Policy URL accessible from the App Store listing and from within the App itself (Settings → Privacy).

We honour the App Tracking Transparency (ATT) framework: any tracking activity as defined by Apple is preceded by the system ATT prompt and only proceeds with the user’s affirmative consent. Our advertising SDKs are configured to respect the user’s ATT response.

Each App’s “App Privacy” section in the App Store accurately reflects the data we collect, the data linked to the user, and the purposes of processing. We update this disclosure whenever our data practices change and submit updated versions via App Store Connect.

9.2 · Google Play Store

Our Apps published on Google Play comply with the Google Play Developer Distribution Agreement, the Google Play Developer Policy (including the “User Data” and “Ads” sections), the Families Policy where applicable, and the EU User Consent Policy. Each App ships with a Privacy Policy URL accessible from the Play Store listing.

For Apps distributed in the EEA, we use Google Play’s “Data safety” section to provide a transparent, accurate summary of data practices. We honour Google Play’s “Delete account” requirement for Apps that enable account creation.

We honour Google’s EU User Consent Policy: any request for consent is presented in clear, plain language, granular per purpose, and never bundled with consent for unrelated processing. We support Google Play’s “Data safety” form, including the declaration of data shared with third parties (advertising networks).

9.3 · Other Distribution Platforms

Where our Apps are distributed through alternative channels (Huawei AppGallery, Samsung Galaxy Store, Amazon Appstore, Mac App Store, direct distribution), we apply the privacy and disclosure standards of the Apple App Store and Google Play Store as our baseline. Each platform’s specific requirements (e.g., Huawei’s data localisation in Mainland China, Samsung’s content policy) are honoured in addition.

10 · International Transfers

We are based in the United Kingdom. Where personal data is transferred outside the UK / EEA (for example, to a US-based service provider), we rely on one or more of the following safeguards:

  • Adequacy decisions: The European Commission or the UK ICO has determined that the destination country provides an adequate level of protection (e.g., the EU–US Data Privacy Framework for certified US recipients).
  • Standard Contractual Clauses (SCCs): Approved by the European Commission (Module 1, 2, or 3 as applicable) or by the UK ICO, supplemented by Transfer Impact Assessments.
  • Binding Corporate Rules (BCRs): Where applicable.
  • Explicit consent: For occasional, non-repetitive transfers, where the user has been informed of the risks.

Cloud infrastructure (where used) is hosted in UK / EU regions by default. Our advertising partners may process data in the United States and other jurisdictions; each partner’s privacy policy details their data-handling locations.

11 · Regional Compliance

This section explains how our practices align with the major data protection regimes applicable to our users. Where regional laws provide additional rights, those rights are honoured in addition to the baseline GDPR rights described in §14.

11.1 · European Union (GDPR)

The EU General Data Protection Regulation (Regulation (EU) 2016/679) applies to all users in the EEA. We honour all GDPR rights (access, rectification, erasure, restriction, portability, objection) and operate in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality, and accountability (Article 5).

11.2 · United Kingdom (UK GDPR & DPA 2018)

The UK GDPR and the Data Protection Act 2018 apply to all users in the United Kingdom. Our compliance framework aligns with the ICO’s accountability framework, and we maintain a Record of Processing Activities (RoPA) as required by Article 30.

11.3 · United States (CCPA / CPRA & State Laws)

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California residents rights to know, delete, correct, and limit the use of sensitive personal information. We extend these rights to all US users regardless of state residency, in compliance with the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (VCDPA), the Connecticut Personal Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), and other applicable state laws.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising without opt-in consent where required.

11.4 · Canada (PIPEDA & Quebec Law 25)

The Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, An Act to modernize legislative provisions as regards the protection of personal information (Law 25) apply. We comply with the ten fair information principles of PIPEDA and the enhanced consent, transparency, and data-processor obligations of Law 25.

11.5 · Brazil (LGPD)

The Lei Geral de Proteção de Dados (LGPD) applies. We honour all rights of data subjects (confirmation, access, correction, anonymisation, portability, elimination, information on sharing) and have appointed a Data Protection Officer reachable at contact@lunjitrading.com.

11.6 · Australia (Privacy Act 1988 & APPs)

The Privacy Act 1988 and the Australian Privacy Principles (APPs) apply. We handle personal information in accordance with the APPs and notify users of any eligible data breaches under the Notifiable Data Breaches scheme.

11.7 · New Zealand (Privacy Act 2020)

We comply with the Information Privacy Principles (IPPs) of the New Zealand Privacy Act 2020.

11.8 · Singapore (PDPA)

The Personal Data Protection Act 2012 (PDPA) applies. We comply with the Consent, Purpose, Notification, Accuracy, Protection, Retention Limitation, and Access/Correction obligations.

11.9 · South Korea (PIPA)

The Personal Information Protection Act (PIPA) applies. Where PII of Korean residents is processed, we comply with the requirements for consent, purpose limitation, retention, destruction, and overseas transfer notification.

11.10 · Japan (APPI)

The Act on the Protection of Personal Information (APPI) applies. We comply with requirements for proper acquisition, purpose of use, security, and third-party provision.

11.11 · India (DPDPA 2023)

The Digital Personal Data Protection Act, 2023 applies to processing of digital personal data of individuals located in India. We comply with consent, purpose limitation, data fiduciary obligations, and the rights of data principals.

11.12 · Mainland China (PIPL)

Where our Apps are distributed in Mainland China via specific stores (e.g., Huawei AppGallery, Xiaomi GetApps), the Personal Information Protection Law (PIPL) applies. For China-specific builds, personal information is stored within Mainland China, separate consent is obtained for cross-border transfer, and the requirements of GB/T 35273 (Personal Information Security Specification) are honoured.

11.13 · Other Regions

For users in regions not specifically enumerated above, we apply the GDPR’s baseline protections as a matter of good practice. If you have questions about your specific jurisdiction, please contact our DPO.

12 · Cookies & Tracking Technologies

The Website uses cookies and similar technologies to operate, secure, and improve the service. We categorise them as follows:

12.1 · Strictly Necessary Cookies

These cookies are essential to the Website’s operation. They enable basic functions such as page navigation, secure area access, and form submission. The Website cannot function without them. They do not require consent under the ePrivacy Directive.

12.2 · Analytics Cookies

We use privacy-respecting analytics (self-hosted or anonymised IP) to understand how visitors use the Website. Where third-party analytics are used (e.g., Plausible, Fathom), they are cookieless by design. Google Analytics is only deployed with IP anonymisation and a suitably configured consent banner.

12.3 · Advertising Cookies

We do not currently deploy advertising cookies on the Website. Should this change in future, we will obtain prior consent via a CMP compliant with the IAB TCF v2.2.

12.4 · Mobile App Identifiers

Within our Apps, platform-provided identifiers (IDFA, GAID) are used solely for advertising purposes as described in §7 and only with your consent. You can reset the IDFA at any time via iOS Settings or opt out of ad personalisation on Android.

12.5 · Do Not Track / Global Privacy Control

We honour the Global Privacy Control (GPC) signal. When your browser sends a GPC header, we treat it as a valid opt-out of “sale” / “sharing” under the CCPA / CPRA.

12.6 · Managing Cookies

You can clear or block cookies through your browser settings. Most browsers also offer private / incognito modes. Note that blocking necessary cookies may impair Website functionality.

13 · Age Restrictions & Children

Our Apps are categorised by intended audience. We honour the following age-related rules:

13.1 · General Audience Apps

Apps intended for general audiences require the user to be at least 13 years old (the minimum age under COPPA) or the higher age of digital consent in the user’s jurisdiction (14 in Italy, Spain, South Korea; 16 in France for certain processing; 18 in Thailand). By using these Apps, you represent that you meet this requirement.

13.2 · Children-Directed Apps (Kids Category)

Apps designed for children (under 13) are clearly marked in their App Store listing and the “Designed for Families” or “Kids Category” banner. For these Apps, we:

  • Do not engage in any behavioural advertising.
  • Do not collect persistent identifiers beyond what is essential to the App’s function.
  • Do not integrate analytics SDKs that build user profiles.
  • Do not include any in-app purchase prompts or external links without parental gate.
  • Comply with COPPA (US), the UK Age-Appropriate Design Code (Children’s Code), the EU GDPR-K provisions, and any other applicable children’s privacy law.

13.3 · UK Age-Appropriate Design Code

Where our Apps are likely to be accessed by children (under 18) in the United Kingdom, we conduct a Data Protection Impact Assessment (DPIA) as required by the ICO’s Age-Appropriate Design Code. We default to high privacy settings, do not use nudge techniques, and do not use dark patterns.

13.4 · Verifiable Parental Consent

Where the App’s audience includes children under 13, verifiable parental consent is obtained before any personal data collection that is not strictly necessary for the activity. Methods of verifiable consent include signed consent forms, credit card / payment verification, government-ID check, or knowledge-based authentication, as required by COPPA.

13.5 · Removal of Children’s Data

If you believe we have collected information from a child under the applicable age threshold in error, please contact contact@lunjitrading.com. We will delete the information within 30 days and confirm the deletion in writing.

14 · Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

  • User-generated content stored on-device: Retained until you delete it or uninstall the App.
  • Support correspondence: Retained for 24 months from the last interaction, after which it is anonymised or deleted.
  • Analytics: Aggregated, anonymised analytics retained for up to 26 months.
  • Server logs: Retained for 30 days for security and operational purposes.
  • Newsletter subscription: Retained until you unsubscribe.

Where the law requires a longer retention period (e.g., tax or anti-money-laundering), we retain the data for the legally mandated period.

15 · Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of access — Request a copy of the personal data we hold about you.
  • Right of rectification — Request correction of inaccurate or incomplete data.
  • Right of erasure (right to be forgotten) — Request deletion of your personal data.
  • Right to restrict processing — Request that we limit how we use your data.
  • Right to data portability — Receive your data in a structured, machine-readable format.
  • Right to object — Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — At any time, without affecting the lawfulness of prior processing.
  • Right to lodge a complaint — With your local data protection authority.
  • Right not to be subject to automated decision-making — Including profiling, with limited exceptions.

To exercise any of these rights, please email contact@lunjitrading.com with the subject line “Data Subject Request”. We will respond within 30 days (or earlier where required by law). Where requests are complex or numerous, we may extend the response period by up to two further months and will notify you.

For users in the European Union, our lead supervisory authority is the Information Commissioner’s Office (ICO) of the United Kingdom. You may also lodge a complaint with your local supervisory authority.

16 · Security Measures

We employ industry-standard administrative, technical, and physical safeguards to protect personal data, including:

  • AES-256-GCM encryption for data at rest.
  • TLS 1.3 encryption for data in transit.
  • Apple’s Secure Enclave and Android Keystore for key custody.
  • Two-factor authentication on all studio accounts.
  • Annual third-party security audit.
  • Role-based access control with least-privilege principle.
  • Regular penetration testing.
  • Incident response plan with 72-hour breach notification commitment.
  • SOC 2-aligned controls (where applicable to our service providers).

No system is perfectly secure. If we become aware of a security incident affecting your personal data, we will notify you and the relevant authorities in accordance with applicable law.

17 · Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, our Apps, the law, or for operational, legal, or regulatory reasons. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this Policy.
  • Notify you via in-App notification and / or email where appropriate.
  • Where required by law, seek your renewed consent before the changes take effect.

We encourage you to review this Policy periodically. Continued use of the Website or Apps after changes indicates acceptance of the updated Policy.

18 · Contact Us

For any questions, complaints, or data subject requests relating to this Policy, please contact us:

Lunji Trading
University of Stirling Innovation Park
Stirling, Scotland, United Kingdom
Email: contact@lunjitrading.com
Support: support@lunjitrading.com

We aim to respond to all privacy enquiries within 48 business hours. Where a request requires additional time, we will keep you informed of progress.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For users in the United Kingdom, this is the Information Commissioner’s Office (ico.org.uk). For users in the European Union, this is your national supervisory authority.

— END OF POLICY —