Privacy Policy
Effective July 27, 2026
This Policy explains how the Company handles personal data when you use DataSalon's website, account features, APIs, and dataset discovery service.
Shanghai Bouncy Labs Co., Ltd. (the "Company," "we," "us," or "our"), based in Shanghai, China, operates DataSalon. The Company is the data controller and personal information processor responsible for the processing described in this Policy.
1. Data we collect
- Account data, including email address, display name, avatar, and the identifiers returned by GitHub or Google when you choose those providers.
- Authentication and security data, including session identifiers, verification attempts, OAuth state, IP-derived rate-limit records, and secret-free security events.
- Content and interactions you choose to submit, such as requests, offers, forum content, comments, bookmarks, likes, notifications, and subscriptions.
- Basic request and device information needed to deliver and secure the Service.
2. How we use data
We use personal data to create and authenticate accounts, provide requested features, maintain per-user ownership boundaries, prevent fraud and abuse, diagnose reliability problems, communicate service messages, and comply with legal obligations. We do not sell personal data or use it for third-party targeted advertising.
3. Authentication providers and processors
Resend processes email addresses and login-email content to deliver passwordless codes. Cloudflare Turnstile processes network and device signals, including IP address, to prevent automated abuse. GitHub and Google process authentication requests when you choose their sign-in options. Their own terms and privacy notices also apply.
4. Retention
- Verification codes are HMAC-protected and expire after 10 minutes.
- OAuth state and browser nonce records expire after 5 minutes.
- Session cookies expire after 7 days and can be invalidated by signing out of all sessions.
- Short-lived abuse-prevention counters expire between 1 minute and 1 hour; failed-code lock records expire after 15 minutes.
- Authentication security logs are normally retained for 180 days. Specific records may be retained longer when reasonably required for an active security investigation, dispute, or legal obligation.
- Account and user-submitted data are retained while needed to provide the Service or meet legal obligations.
5. Cookies
6. Your choices and rights
DataSalon does not currently provide self-service export or deletion controls. This does not limit rights granted by applicable law. You may request access, a copy, correction, deletion, restriction, or objection where applicable by contacting us. We may verify your identity and may retain information when legally required.
The Service also does not currently provide self-service OAuth unlinking or a separate lost-account recovery workflow.
7. Security and international processing
We use access controls, encrypted transport, bounded authentication tokens, rate limits, and least-privilege provider access. No system is completely secure. Service providers may process data in countries other than yours, subject to applicable safeguards and law.
8. Changes and contact
We may update this Policy as the Service or law changes. Material changes will be identified by a new effective date and, when appropriate, additional notice.
Privacy questions or rights requests for the Company may be sent to [email protected].