Scope
This policy applies to ucardradar.com and the public browsing, account, membership subscription, feedback, evidence review, support contact, notification, partner link, and related information services provided directly by UCard Radar. Information processed by third-party card providers, issuers, wallets, exchanges, app stores, identity verification providers, payment providers, or external websites as independent service providers is governed by their respective policies; this policy does not replace those third-party policies.
Entity Responsible for Processing Personal Information
For personal information whose processing purposes and methods are determined directly by UCard Radar, Shenzhen Tongda Smart IoT Technology Co., Ltd. is the personal information processor under the Personal Information Protection Law of the People's Republic of China and acts as the corresponding data controller where other applicable data protection laws apply.
- Legal name: Shenzhen Tongda Smart IoT Technology Co., Ltd.
- Contact address: Area 5, 5th Floor, Building M2, Maqueling Industrial Park, Keji Zhonger Road, Science Park, Yuehai Subdistrict, Nanshan District, Shenzhen, Guangdong Province, China
- Privacy requests may be sent to support@ucardradar.com or submitted through the privacy contact option on this website.
- Payment, identity verification, login, infrastructure, email, or external website service providers may, depending on the actual function, act as entrusted processors, independent personal information processors, or independent data controllers. Their specific roles depend on the relevant data flows, contracts, and channels actually used by the user and are not determined categorically merely because a provider is named in this policy. Paddle or Creem may independently process information for checkout, payment collection, invoicing, tax, fraud prevention, and refund management under their privacy statements; NOWPayments may process information required for payments, compliance verification, and on-chain transactions under its terms. The UCard Radar operating entity receives only the data necessary for product delivery, account activation, order support, and compliance.
Information We May Process
| Information Type | Examples | Collection Context | Purpose | Public Status |
|---|---|---|---|---|
| Basic access logs | IP address, browser, device type, access time, and page path | Generated automatically when visiting the website | Security protection, troubleshooting, spam prevention, and statistical analysis | Not public |
| Account and authentication information | Email address, display name or avatar, login provider identifier, password hash, verification status, session data, and security metadata | When registering, logging in, verifying an account, or using restricted features | Authentication, account security, access control, and abuse prevention | Not public; passwords are not stored in plaintext |
| Preferences and feature usage information | Language, time zone, country or region signals, favorites, follows, alerts, notification preferences, and feature activity | When configuring an account or using membership features | Providing personalized settings, monitoring, alerts, reports, and service improvements | Not public |
| Membership and order information | Plan, benefits, order and payment identifiers, status, amount, currency or network, billing/card/IP country signals, invoice or receipt, and refund and dispute status | When purchasing, renewing, canceling, or handling subscription disputes | Order verification, benefit delivery, billing support, refunds, fraud prevention, and recordkeeping | Not public; full payment credentials are generally processed directly by payment service providers |
| User feedback content | Card name, usage region and original region inputs, purpose and date of use, KYC result, account or fund freeze status, fee and payment compatibility feedback, evidence type, optional contact email, hashed IP/user agent, and review status | When a user submits feedback | Reviewing risk signals, generating user feedback summaries, and triggering risk reassessment | May be made public only after redaction |
| Contact and communication information | Email address, name or form of address, organization, contact request, support correspondence, attachment metadata, hashed IP/user agent, and email delivery and notification records | When users contact us, subscribe to notifications, or have requests processed | Responding to inquiries, correcting data, handling complaints, sending service notifications, and maintaining delivery security | Not public |
| Evidence files | Screenshots, emails, customer service records, app screenshots, and transaction failure screenshots | When a user uploads evidence | Verifying the authenticity of feedback and conducting internal risk reviews | Private by default; original images are not made public |
| Advertising and partner click data | Click time, source page, referring page, partner link or card identifier, and hashed IP and user agent information | When clicking an Affiliate or Partner Link | Attribution, fraud prevention, partner analytics, and audits | No identifiable feedback or evidence materials are provided to partners |
| Administration and audit logs | Authorized personnel identifiers, operation times, affected objects, changes, and security incident records | During administrative, review, or security operations | Access control, auditing, security investigations, and change tracking | Authorized personnel only |
Information We Do Not Proactively Collect
UCard Radar does not issue or manage crypto payment cards and does not request full card numbers, CVV, wallet private keys, seed phrases, exchange passwords, or original KYC identity documents through forms on this site. If a user selects a third-party payment channel, the relevant payment service provider may directly collect information required to complete the payment under its privacy policy; UCard Radar generally receives only the order identifier, payment status, and data required for reconciliation.
- We do not proactively collect original identity documents
- We do not require users to submit bank card numbers
- We do not require users to submit wallet private keys, seed phrases, or transaction passwords
- We do not require users to submit full card numbers, CVV, or payment passwords
- We do not require users to submit exchange login information
- We do not submit KYC on behalf of users
- We do not process user deposits, withdrawals, currency exchanges, or payments on users' behalf
- We do not hold user funds in custody
Before You Submit
Do not submit private keys, seed phrases, full card numbers, CVV, account passwords, complete images of identity documents, or other highly sensitive information in feedback, comments, screenshots, or contact emails.
How User Feedback and Evidence Files Are Handled
Feedback and evidence are used to verify risk signals. Evidence files are stored in private spaces by default and may be viewed only by authorized personnel through short-lived protected links. Any public display requires user authorization and review and uses a redacted summary rather than the original file.
Public Display Principle
We may publish redacted summaries such as “multiple reports of KYC failures for a card,” “users in a particular region reported card-linking failures,” or “some users reported delayed refunds,” but we should not publish user identities, contact details, complete screenshots, or information that could identify an individual.
How We Use Information
- Provide card search, filtering, comparison, and risk rating displays
- Review feedback and evidence submitted by users
- Identify fee changes, regional restrictions, stricter KYC requirements, card suspension, and refund risks
- Update card details, risk events, ratings, and data sources
- Respond to user inquiries, complaints, and correction requests
- Analyze website visits, search trends, and page performance
- Conduct anti-spam, anti-abuse, and security protection activities
- Maintain audit records of administrative operations and data changes
- Measure Affiliate / Partner Link clicks and advertising performance
- Improve website content, product experience, and data quality
Commercial-Use Boundaries
UCard Radar does not operate a business model based on selling personal information. We disclose information only to the extent necessary to provide services requested by users, use necessary service providers, follow user instructions or consent, protect security or rights, complete compliant corporate transactions, or fulfill legal obligations. We do not provide identifiable user feedback or evidence to card providers, advertisers, or data brokers for their independent marketing.
Legal Bases and Information Sharing
Where applicable law requires a legal basis for processing to be identified, we rely, as appropriate to the specific circumstances, on: performing a user's request or a contract (accounts, subscriptions, orders, and support); legitimate interests (security, fraud prevention, audits, and service improvements, provided these interests do not override user rights); consent (public feedback, optional communications, or non-essential technologies, which may be withdrawn where applicable); and legal obligations or legal claims (tax, disputes, law enforcement, and recordkeeping).
- Infrastructure, storage, security, identity, email, and payment service providers process information only to the extent necessary to provide the corresponding functions.
- When users expressly request or authorize us to provide information to a designated recipient, we may process it as instructed.
- To investigate fraud, abuse, or security incidents or protect legal rights, necessary information may be provided to professional advisers, auditors, insurers, or relevant authorities.
- If a merger, restructuring, financing, or asset transaction occurs, information may be disclosed to relevant parties subject to confidentiality and applicable legal safeguards.
- When we receive a binding legal request, we process it under applicable law after verifying its authority and scope.
Third-Party Services and External Links
UCard Radar pages may contain links to official brand websites, card provider pages, help centers, app stores, media articles, regulatory materials, Affiliate Link, or Sponsored Link. Clicking these links takes users to third-party websites or services.
- UCard Radar does not control third-party websites' privacy policies, Cookies, account systems, KYC processes, or data processing practices.
- Users should review the privacy policies and terms of service of third-party websites themselves.
- UCard Radar does not process users' registration, KYC, deposits, spending, refunds, account freezes, or fund disputes on third-party platforms.
- Third-party services may be located in different countries or regions and may be subject to different data protection rules.
Data Retention Periods
We determine retention periods based on the purpose of processing, account and order status, feedback or dispute handling, security audits, and applicable recordkeeping obligations. When information is no longer needed, it will be deleted or anonymized, except where continued retention is required for legal obligations, dispute handling, or security needs.
- Access, security, and error logs: retained as needed for security protection, spam prevention, anomaly investigations, and troubleshooting.
- Account and authentication records: retained while the account is active, while access and security requests are being handled, and during necessary audit periods. After an account is closed, they are retained only to the extent required for disputes, security, or legal requirements.
- Membership, order, refund, and dispute records: retained as needed for benefit delivery, reconciliation, customer service, fraud prevention, tax, and payment dispute handling.
- Preference, favorite, follow, alert, and notification records: retained while the relevant features are provided or the user retains the setting and may be deleted through account settings or an applicable request.
- User feedback: retained while used for risk analysis, historical records, and data traceability.
- Evidence files: retained as needed for review, dispute handling, risk event tracking, or processing user requests.
- Partner link click records: retained as needed for attribution, settlement reconciliation, fraud prevention, and commercial audits, then deleted or aggregated and anonymized.
- Administrative audit logs: retained for security, compliance, and accountability purposes.
- Contact emails: retained as needed to handle inquiries, complaints, corrections, or privacy requests.
Data Security Measures
UCard Radar uses technical and organizational measures proportionate to the nature and risks of the information to protect accounts, orders, user feedback, evidence materials, audit records, and private files.
- Role-based and least-privilege access controls
- Credential hashing, session protection, and restricted administrative access points
- Private storage of evidence files and short-lived protected access
- Redaction of sensitive information and review before publication
- Auditing of access, reviews, and material changes
- Spam prevention, rate limiting, and anomalous request detection
- Vendor access and configuration management
- Security incident investigation, response, and recovery procedures
Internet transmission and storage cannot be guaranteed to be risk-free. We make reasonable efforts to protect information but cannot promise that any system is entirely free of security risks.
Cross-Border Processing and Service Providers
UCard Radar uses cloud infrastructure, identity, email, and payment services to provide website, API, file storage, security, login, communication, and order capabilities. Relevant information may be processed in countries or regions outside the user's location. Where applicable, we provide appropriate safeguards through contracts, access controls, encryption, or other organizational and technical measures.
- Cloudflare Workers
- Cloudflare D1
- Cloudflare R2
- Cloudflare KV
- Cloudflare Turnstile
- Google (only when the user chooses to sign in with Google)
- Cloudflare Email Sending or Resend (depending on email feature configuration)
- Paddle (only when the order uses the corresponding payment channel)
- Creem (only when the order uses the corresponding payment channel)
- NOWPayments (only when the order uses the corresponding payment channel)
The service providers actually used depend on project configuration and the features or payment channels selected by the user. Service providers may process information as independent controllers or entrusted processors under their terms.
User Rights and Deletion Requests
To the extent provided by applicable law, users may request access, correction, deletion, restriction of processing, objection to processing, data portability, and withdrawal of consent, and may lodge a complaint with a competent data protection or other regulatory authority. Specific rights and response procedures depend on the law of the user's location.
- Request access to relevant personal information we hold
- Correct inaccurate or incomplete information
- Request deletion or restriction of processing where applicable conditions are met
- Object to processing based on certain legitimate interests
- Request a portable copy of data where applicable conditions are met
- Withdraw consent for public feedback, optional communications, or other consent-based processing
- Lodge a complaint with a competent regulatory authority
To prevent accidental deletion, unauthorized access, or impersonated requests, we may require sufficient information to verify the requester's identity and authority and locate the relevant account, order, contact record, feedback, evidence, or other personal information.
Minors' Privacy
This site is not directed at minors and does not proactively ask minors to submit feedback, evidence, or contact information. If a parent or guardian believes that a minor has submitted personal information to us, they may request verification and deletion through the contact page.
Policy Updates
We may update this Privacy Policy based on product features, data processing practices, service providers, laws and regulations, or operational needs. The latest update date will be displayed on this page after an update. Material changes may be explained through a page notice or other appropriate means.
Last Updated:August 25, 2026
Privacy Contact and Complaints
To submit a privacy rights request, ask about this policy, report a data security issue, or complain about how personal information is processed, contact us through the contact page or privacy support email. We may require sufficient information to verify identity and locate relevant records; do not send highly sensitive credentials in your initial contact.
If you believe your request has not been handled properly, you may lodge a complaint with a competent data protection or other regulatory authority to the extent permitted by applicable law. This page does not replace any supplemental notice that may be required for a particular jurisdiction.
Frequently Asked Questions
Do I need an account to browse UCard Radar?
An account is generally not required for ordinary browsing, searching, or viewing public pages. Favorites, feedback history, Pro/Business subscriptions, monitoring, reports, and other restricted features require login and are subject to access controls.
Must I provide an email address when submitting feedback?
Usually not. An email address is primarily used to contact you when we need further verification, need to respond to a correction request, or are handling a complaint.
Will screenshots I upload be made public?
Not by default. Evidence files are stored privately by default, and the public-facing site displays only redacted summaries, risk types, verification status, or statistical results.
Does UCard Radar sell my personal information?
No. We do not sell users' personal information to advertisers, card providers, or third-party data brokers.
What is recorded for Affiliate clicks?
We may record the click time, source page, referring page, partner link or card identifier, and hashed IP and user agent information for attribution, analytics, and fraud prevention.
How can I request deletion of my feedback or evidence?
You may submit a request through the contact page or support@ucardradar.com and provide sufficient information to help us locate the relevant feedback or evidence.