Who is responsible
Crowdlume is operated by Yang Ding, an individual based in Beijing, China. Yang Ding is responsible for the personal information described here. Contact for privacy, account closure, and support: support@crowdlume.com.
Updated September 8, 2026. This policy explains how personal information is handled when you visit crowdlume.com, use an account, request research, or purchase services.
Crowdlume is operated by Yang Ding, an individual based in Beijing, China. Yang Ding is responsible for the personal information described here. Contact for privacy, account closure, and support: support@crowdlume.com.
We process your verified email and the basic profile returned by an available sign-in method; service selections, quantities, public target URLs, instructions, delivery evidence and progress; payment references, amounts, currency, balance entries and payment or refund status; and correspondence you send to support. Do not include passwords, private keys, or sensitive personal information in an order note. Crowdlume does not request or store your full payment-card number or card security code. Where Waffo Pancake checkout is offered, card details are provided directly to that payment service, not to Crowdlume. The payment methods actually available are those displayed at checkout.
We process technical and security records, including request times, errors, IP address and approximate country. First-party visit events record landing pages, referral category, campaign fields, language, device class and purchase-funnel steps. These analytics tables exclude your order target URL and IP address. Restricted administrator notifications may separately include your email, IP, country, landing page and referral or campaign context for security, support and conversion attribution. A search or AI referral classification is an estimate based on available attribution, not proof of your identity or interests. For research requests we process the submitted public page, audience description, research goal, eligibility confirmation, consent time, invitation status and written responses. Invitation tokens are stored as hashes; participant identity is not included in the report. An unfinished research draft may remain on your device for up to seven days and is removed after successful submission.
We use the necessary information to provide accounts, reconcile payments, fulfill and review orders, return research reports and provide support. We also use limited records for fraud prevention, security, dispute handling and applicable accounting obligations. Depending on the applicable law, processing is based on performing our agreement, legal obligations, consent when required, or legitimate interests that do not override your rights. We do not treat visiting the website as consent to every use of personal information.
Authentication uses cookies or browser storage to maintain your session. Browser storage also supports drafts and attribution. We use Google Analytics 4 to understand website use, in addition to first-party analytics. You can control cookies through your browser and use Google's analytics opt-out tools; disabling necessary storage can prevent sign-in or draft recovery. Google explains its practices at https://policies.google.com/privacy and provides an opt-out at https://tools.google.com/dlpage/gaoptout. This site does not currently offer an account-level cookie preference center. Service and security emails are separate from promotional communications.
Only information needed for the relevant function is shared with authentication, hosting, email, payment, analytics and fulfillment services. Restricted operational notifications are delivered through Telegram. When Waffo Pancake is available, it receives the information required to process that payment and handle payment compliance or disputes under its own applicable terms. We may disclose information to comply with a valid legal requirement or protect against fraud and harm. We do not sell customer information as a business activity. Service providers may process information outside China or your country, including in the United States. We limit access and the data shared and apply safeguards required by applicable law; contact us to ask about the arrangements relevant to your information. Public blockchain transactions cannot be erased by Crowdlume.
Nonessential account information is deleted or anonymized within 90 days after account closure. Support correspondence is kept for two years after the case closes. Security and access records are kept for up to 180 days. Order and payment records are kept for at least three years after the transaction; legal obligations, an active dispute or a documented legal hold may require longer retention. Information retained for those reasons is restricted to that purpose and reviewed when the obligation ends. Account closure does not erase financial records that must be retained. We review records for deletion or irreversible anonymization when their retention period ends, including copies under our control held in support and operational notification systems. Independent payment providers may have their own legally required retention periods.
We use HTTPS and account-based access controls and restrict administrative access. No system can guarantee absolute security. We handle security incidents and any required notifications according to applicable law. Email support@crowdlume.com to request access, correction, deletion, account closure, restriction, portability or to object to processing, where those rights apply. You may withdraw consent for processing that relies on it without affecting earlier lawful processing. We verify requests proportionately and respond within 30 calendar days, or explain any lawful extension. You may complain to your competent data-protection authority. Please do not send identity documents unless we explain why they are necessary and provide an appropriate method.
Accounts and purchases are for people aged 18 or over. If you believe a child has provided information, contact us so we can investigate and remove information as required. Third-party websites have their own privacy practices. Material changes to this policy will be communicated through the website or account email before taking effect where required; the date above identifies this version. English and Chinese versions are available. Mandatory local privacy rights are not limited by either translation.