Privacy Policy
Hilo Research Privacy Policy
Version: v1.0.0
Last updated: 2026-08-15
Effective date: 2026-02-24
This Privacy Policy explains how Hilo Research (河洛投研; also known as HiLo Quant Research) ("we", "us") collects, uses, shares, and protects your personal information when you use our services (the "Service"), and what rights and remedies you have.
Important: Please read this policy carefully, especially the key clauses. When you complete registration and click the "Agree" button, you are deemed to have fully understood and agreed to this policy.
1. Scope
This policy applies to all scenarios in which you use the Service through our website/app, including registration, login, browsing, feature usage, and customer support.
2. Information we collect
2.1 Information you provide
- Account information: email address, verification code, and other required information you provide.
- Support and feedback: content you submit when contacting us.
2.2 Information we collect automatically
- Device identifiers and fingerprint: we may assign a temporary device ID, or generate a device fingerprint based on your browser/device characteristics. This information is used for security and risk control (e.g., preventing malicious registrations and limiting abuse while not logged in), and to temporarily identify your device before registration to associate your agreement-browsing behavior. A device fingerprint cannot directly identify you.
- Agreement acknowledgment records: when you register, log in, or re-acknowledge after an agreement update, we may record:
- the agreement type (Terms of Service / Privacy Policy) and the specific version number
- the time of acknowledgment (to the second)
- your IP address and device information (User-Agent) at that time
- the operation type (e.g., view, check "agree")
These records are important for fulfilling legal obligations and demonstrating that you have read and agreed to the relevant agreements, and we retain them as described in Section 7.
- Usage information: pages visited, feature usage counts, timestamps, error information, etc.
- Technical information: browser type, operating system, language settings, time zone, screen resolution, etc.
2.3 Cookies / local storage and similar technologies
We may use cookies, localStorage, sessionStorage and similar technologies to:
- remember login status and preferences (e.g., language/theme);
- provide security and anti-fraud protections;
- measure performance and improve the product.
You can refuse or clear cookies in your browser settings, but this may affect the normal use of some features (e.g., auto-login).
3. How we use information (purposes)
We may process your personal information for:
- providing and maintaining the Service (registration, login, feature delivery);
- security and risk control (anti-fraud, anomaly detection, rate limiting, abuse governance);
- product improvement (debugging, analytics, experience optimization);
- support and notices (service updates, issue responses);
- compliance and rights protection (fulfilling legal obligations, enforcing agreements, protecting legitimate rights and interests, including retaining agreement acknowledgment records for regulatory inspections or legal disputes).
4. Legal bases for processing
- EEA/UK (GDPR): where applicable, we process personal data based on contract performance, legitimate interests, your consent, or legal obligations.
- Mainland China (PIPL, etc.): we process personal information based on conditions provided by law (e.g., necessary for contract performance, legal obligations, your consent). For sensitive personal information and cross-border transfers, we will provide notice and obtain separate consent where required.
- Certain U.S. states (e.g., California): we provide required notices and rights mechanisms (e.g., access/know, delete, correct, opt-out).
5. Sharing and disclosure
We may share or disclose information in the following circumstances:
- Service providers: we may share with vendors (processors) providing infrastructure/security/analytics, to support Service operation. Such providers may only process data within our authorization and are subject to confidentiality obligations.
- Legal requirements: to comply with laws/regulations or judicial/regulatory requests, or to protect security and rights.
- Business transactions: in mergers, acquisitions, or asset transfers, we will provide notice and take protective measures as required.
Unless otherwise required by law or with your separate consent, we do not sell your personal information to unrelated third parties.
If you use a third-party account (e.g., Google, WeChat) to log in, we will collect necessary information within the scope you authorize. Please refer to that platform's privacy policy.
6. Cross-border transfers
Your information may be processed outside your country/region. We will take necessary measures required by applicable law (e.g., SCCs, impact assessments).
If you are located in mainland China, we will provide cross-border transfers in accordance with PRC laws and obtain separate consent where required.
7. Retention
We retain personal information only for the minimum period necessary for the purposes described above, unless laws and regulations require otherwise. Specific periods include:
- Account information: after you cancel your account, we will delete or anonymize it within 30 days (may be extended as needed to complete services prior to cancellation, but not beyond legal requirements).
- Agreement acknowledgment records: retained for 3 years from your last account activity (e.g., login or feature usage), to meet limitation periods and regulatory review needs.
- Technical logs (including IP and device information): retained for 6 months for security analysis and troubleshooting.
- Temporary device identifier: if you do not complete registration, it will be automatically cleared after 30 days.
8. Security
We take reasonable administrative, technical, and organizational measures to protect information. However, the internet is not absolutely secure—please keep your credentials safe.
9. Your rights
To the extent provided by applicable law, you may have rights to:
- access, correct, and delete your personal information;
- withdraw consent (without affecting the lawfulness of processing before withdrawal);
- cancel your account;
- obtain copies or port your information (where applicable);
- object to or restrict certain processing;
- complain to regulators (where applicable).
To exercise these rights, please contact us using the information in Section 12. We will respond within a reasonable timeframe as required by law.
10. Children
The Service is generally not intended for minors. If you are a minor, please use the Service with guardian consent and guidance. If we discover that a child under 14 (or a lower age defined by your jurisdiction) provided personal information without guardian consent, we will delete it as soon as possible.
11. Policy updates
We may update this policy and provide notice when necessary. The updated policy becomes effective on the publication date or another notified effective date. If the update involves material changes (e.g., scope of collection, purposes, your core rights), we will prominently notify you (pop-up, in-app notice, or email), and it will take effect after we obtain your renewed consent.
12. Contact
If you have any questions, comments, or requests regarding this policy, please contact: service@heluoquant.com
To protect your account security, we may need to verify your identity when handling rights requests.