Z-TRIP User Privacy Policy V2.0

Update Date: June 10, 2026

Effective Date: June 26, 2026

Welcome to Z-TRIP! Z-TRIP is an integrated business travel management platform providing domestic/international flight tickets, domestic/international hotels, train tickets (including high-speed rail), car hailing/taxi services, domestic/international tour packages, visas, insurance, reimbursement, and management services. It is researched, developed, and operated by Shanghai Zaitu Network Technology Co., Ltd. (Unified Social Credit Code: 91310000MA1K33GA5P, Registered Address: Room 302-1, 3rd Floor, No. 14, Lane 1401, Jiangchang Road, Jing'an District, Shanghai, hereinafter referred to as "we" or "us"). The platform includes Z-TRIP official website (www.z-trip.cn), Z-TRIP mobile application (APP), Z-TRIP WeChat mini-program, and Z-TRIP software development kits (SDKs) and application programming interfaces (APIs) provided for use on third-party websites and applications (collectively referred to as "this Platform"). Specific services will be provided by qualified service suppliers (including airlines, hotels, etc.).

We fully understand the importance of personal information to you, and your trust is of paramount importance to us. We will protect your personal information and privacy in accordance with the Civil Code of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, other relevant laws and regulations, technical specifications, and with reference to industry practices.We specifically draw your attention to the following: We hope you will carefully read and fully understand this policy before using our services, and make your choices regarding usage only after fully understanding the information processing rules. If you have any questions regarding the content of this policy or the on-screen prompts, please do not proceed to the next step; please contact us via the methods provided at the end of this policy, and we will provide you with a complete explanation and clarification. If you do not agree with the content of this policy, our services may not function properly, or may not achieve the intended service effects, and you should immediately cease using our services. By clicking, checking, or otherwise actively confirming your agreement to this policy on the page, you signify that, with full knowledge, you voluntarily, clearly understand, and agree to all the contents of this policy. We specifically draw the attention of minors under the age of 18 (especially children under the age of 14) and their guardians to the provisions regarding the protection of minors in Article 6 of this policy, and urge you to cautiously authorize and provide the personal information of minors.

This policy provides a complete explanation of how we collect, use, share, transfer, entrust for processing, publicly disclose, store, transmit across borders, and protect your personal information; it also clearly defines your legal rights to manage your personal information, the methods for exercising those rights, and the response time limits. Among these,key terms involving core user rights and interests, sensitive personal information, separate consent, third-party sharing, public disclosure, and cross-border transfer are highlighted in bold for your particular attention.

Table of Contents

I. How We Collect and Use Your Personal Information

II. How We Share, Transfer, Entrust for Processing, and Publicly Disclose Your Personal Information

III. How We Store, Transfer Across Borders, and Protect Your Personal Information

IV. How You Can Manage Your Personal Information

V. How We Use Cookies and Other Similar Technologies

VI. Protection of Minors

VII. General Data Protection Regulation

VIII. Updates to this Policy

IX. Contact Us

I. How We Collect and Use Your Personal Information

(I) How We Collect Your Personal Information

1. We will collect the personal information you provide when registering/logging into your account on this Platform. When you register or log in, you must provide the necessary equipment for internet access, including personal computers, mobile phones, modems, or other necessary connecting devices, and you shall bear the costs of telephone and network services incurred for your personal internet access. To prevent others from impersonating you to register/log in to or use our services, we will send a verification SMS message to your mobile phone. The cost of this SMS message will be borne by us, and you are not required to pay any fees. To ensure the consistency of functionality or services, when you log in again, we may re-verify the logged-in account and device.All login verification is solely for account security purposes and will not excessively collect sensitive device information.

2. When you use our services through this Platform or other means, we will collect personal information you provide or update. If you use our services through this Platform, in addition to the personal information you enter or update, we will also collect your personal information through automated means and will strictly collect your personal information based on the mobile device operating system permissions you actively authorize, with no background silent collection behavior.

3. Your employer intends to or has already established a cooperative relationship with us. We will collect the employee information table/collection of your personal information shared with us by your employer, or the employee information table/collection of your personal information transmitted to us by its administrator/responsible person.Before transmitting employee information to us, the employer shall ensure that it has legally obtained the employee's consent. We only receive personal information from legitimate sources.

4. We may collect relevant information about you through our affiliates, service providers, and business partners. For example, when you make a booking, change, or cancellation through the websites or APPs of our affiliates, service providers, or business partners, the booking, change, or cancellation information you provide to them may be forwarded to us to process your order and ensure the smooth completion of your business travel. We will verify the legitimacy of the source of your personal information according to agreements with our affiliates, service providers, and business partners, andrefuse to accept illegally obtained personal information.

(II) What Personal Information We Need to Collect from You

1. To better provide you with services, we will follow the principle of "lawfulness, legitimacy, necessity, specificity, and clarity," collecting and using personal information solely for the purpose of providing service functions, and not collecting information unrelated to the services. Processing activities beyond the agreed scope must obtain your explicit consent or authorization again; otherwise, we will not carry them out. You acknowledge and agree that we will collect the following personal information that you enter on this Platform or otherwise provide to us:

1) When you register an account on this Platform, you need to provide your mobile phone number or email address and set a password to create the account. You shall provide legal, genuine, and valid registration information; otherwise, you shall bear the responsibility and consequences arising from any violation. The mobile phone number and email address are necessary for account registration; failure to provide them will prevent you from registering and using our services.

2) Personal information you enter or update after logging into your account on this Platform [e.g.,Chinese/English name, (ID card/Hong Kong and Macau Pass/Mainland Travel Permit for Hong Kong and Macau Residents/Mainland Travel Permit for Taiwan Residents/Taiwan Travel Permit/Passport/Mainland Residence Permit for Hong Kong, Macau, and Taiwan Residents/Foreign Permanent Resident ID Card) identification document number and validity period, nationality/region, gender, date of birth, mobile phone number, email address, etc.]; Among the foregoing information, identification document numbers and Chinese/English names are considered sensitive personal information. You shall enter or update legal, genuine, and valid personal information that is timely, detailed, and accurate; otherwise, you may be unable to use our services or may use them incorrectly, and you shall bear the resulting responsibility and consequences.

3) When you use a corporate unified account/administrator-assigned account/third-party authorized login to access your account on this Platform, you or your employer need to provide your Chinese/English name, company name, department, employee ID, position, mobile phone number, email address, etc., for confirming employee status, assigning service permissions, and implementing corporate travel management policies. The aforementioned personal information is collected solely for corporate travel management and will not be used for commercial marketing.

4) When you book, change, or cancel domestic/international flight tickets through this Platform, you need to provide thepassenger's Chinese/English name, identification document number and validity period, nationality/region, gender, date of birth, mobile phone number, email address, etc. Additionally, you may voluntarily choose to provide the passenger's airline membership card account information to receive mileage accumulation benefits; refusal to provide membership card account information will not affect the flight booking service.

5) When you book, change, or cancel domestic/international hotel reservations through this Platform, you need to provide theguest's Chinese/English name, nationality/region, mobile phone number, email address, etc.; in special circumstances (e.g., promotional rates, hotel requirements), you may also need to provide the guest's identification document number and validity period, gender, date of birth, etc. Identification document numbers are necessary for hotel verification and are collected only when mandatory required by the hotel.

6) When you book, change, or cancel train tickets (including high-speed rail) through this Platform, different information needs to be provided depending on the booking or change method you select. When you choose "Z-TRIP Booking," you need to provide thepassenger's Chinese/English name, identification document number and validity period, nationality/region, gender, date of birth, mobile phone number, etc. When you choose "12306 Booking," you additionally need to provide your China Railway Customer Service Center (i.e., www.12306.cn, hereinafter "12306") account information. Refusal to provide 12306 account information, you may switch the booking method; this does not affect the train ticket booking service.

7) When you use car hailing/taxi services through this Platform, you need to provide thepassenger's Chinese/English name, mobile phone number, email address, etc.; in special circumstances (e.g., requirements of the car hailing/taxi platform/service provider), you may also need to provide the passenger's identification document number and validity period, nationality/region, gender, date of birth, etc.

8) When you book, change, or cancel domestic/international tour package services through us, you need to provide theparticipant's Chinese/English name, identification document number and validity period, nationality/region, gender, date of birth, mobile phone number, email address, height, weight, shoe size, degree of myopia, etc. Height, weight, shoe size, and degree of myopia are optional fields, collected solely for safety considerations related to activities such as bungee jumping/aerial rides, outdoor climbing/mountain exploration, water sports/diving, horseback riding/cycling, etc. You may refuse to provide them; refusal will not affect standard tour package services.

9) When you apply for a visa through us, you need to provide theapplicant's Chinese/English name, age group (to distinguish visa application fees for adults and children), client type (to determine the required materials for visa application), shipping address, and the contact person's Chinese/English name, mobile phone number, email address, etc. We will separately inform you of the necessary materials for visa application (depending on the requirements of the embassy/consulate you choose) via your email address. Such materials will be used solely for the purpose of applying for the visa with the embassy/consulate and shall not be used for any other purpose.

10) When you book, change, or cancel insurance policies through this Platform, you need to provide theinsured person's Chinese/English name, identification document number and validity period, mobile phone number, email address, residential address, etc. For certain types of insurance, you may need to provide the insured person's nationality/region, gender, date of birth, whether the insured person has social insurance, and the policyholder's Chinese/English name/company name, mobile phone number/contact number, email address, identification document number and validity period/unified social credit code and validity period, nationality/region, relationship between policyholder and insured, and the payee's Chinese/English name/company name, mobile phone number/contact number, email address, bank card account information and validity period, etc. Bank card account information is considered sensitive personal information and is used solely for insurance claims and fee settlement.

11) When you use the "Points Mall" to redeem products through this Platform, you need to provide therecipient's Chinese/English name/company name, mobile phone number/contact number, email address, shipping address, etc. The aforementioned personal information is collected solely for product logistics and delivery.

12) When you bind or unbind personal membership accounts (e.g., our travel membership account, Meituan Travel membership account, Huazhu Group membership account, etc.) through this Platform (to enjoy benefits such as member prices), you need to provide yourmembership card account information, mobile phone number, email address, etc. Binding a membership account is voluntary; refusal to bind will not affect our services.

13) When you make a payment/settlement, you need to provide yourbank card account information, its validity period, the associated mobile phone number, etc., or your Alipay, WeChat, or other third-party payment institution account information, associated mobile phone number, etc. Bank card account information is necessary sensitive personal information for payment settlement; failure to provide it will prevent transaction completion, but you may choose alternative payment methods.

14) After using our services, if you need an (electronic) invoice, you need to provide thebilling information and the contact person's Chinese/English name, mobile phone number, email address, shipping address, etc. The billing information is used solely for tax compliance and invoice delivery.

15)When a minor is included among your travelers, we require you, as their guardian, to provide, or obtain separate consent from the guardian for, the minor traveler's Chinese/English name, identification document number and validity period, nationality/region, gender, date of birth, etc. The personal information of minors is strictly protected in accordance with the provisions of Article 6 of this policy.

16)When you book, change, or cancel services for others through this Platform, you need to provide the traveler's personal information (e.g., Chinese/English name, identification document number and validity period, nationality/region, gender, date of birth, mobile phone number, email address, etc.) . You shall ensure that you have obtained the explicit consent or authorization of the traveler before providing such information, and that they are aware of and accept this policy. If any infringement occurs due to your failure to obtain explicit consent or authorization, you shall bear all resulting legal liability.

2.To facilitate service provision, you acknowledge and agree that we automatically collect the following personal information through cookies, web beacons, or other methods(all automated collection strictly follows the principle of minimum necessity, with no background collection or excessive collection):

1) Your device information or software information, such as device model, operating system version, APP version, network type, IP address, browser/webview information, crash logs, device anonymous identifiers (OAID, push token, etc.).Special Note: In non-essential scenarios, we do not actively collect IMEI, IMSI, MAC address, device serial number, or installed application list. If collection is truly necessary for security risk control, we will separately inform you of the purpose, scope, and retention period of collection via an independent pop-up, and obtain your explicit consent or authorization before proceeding. You have the right to refuse, and refusal will not affect the basic services of this Platform.

2) Information you search for or browse while using our services, such as the search terms or pages you use on the website or APP, and other information you browse or provide while using our services.The aforementioned browsing data is used solely for optimizing service experience and will not be shared externally.

3. To enhance your service experience, we may collect your following personal information based on the relevant permissions of your mobile device operating system that you authorize.Special Note: Permissions such as Camera/Photo Gallery, Location, Notifications, and Storage are all disabled by default. They are only enabled to implement specific functions or services with your explicit consent or authorization. If you refuse to enable them, only the specific functions or services will be affected; the normal use of other functions or services will not be impacted.

1) Images/videos, etc., collected after you actively authorize enabling your Camera/Photo Gallery permission:

① When you use the "Identity/Real-Name Authentication" function or service on this Platform, or when you perform operations such as inquiry, booking, ticket purchase, refund, change, or waiting list via the train ticket service on this Platform with 12306 or its authorized agents (e.g., if you do not have a registered 12306 account, have not activated your 12306 membership, need to cancel your 12306 account, need to retrieve your password, or require further 12306 authentication to continue using the service), we, a qualified third-party certification body, or 12306, in accordance with relevant laws, regulations, and security requirements, may require you to provide your valid, genuinefacial informationFacial information is highly sensitive personal information. The facial information collected herein is used solely for identity/real-name authentication or 12306 authentication and is strictly prohibited for purposes such as facial recognition, user profiling, or marketing push. We must obtain your separate consent via an independent pop-up window. You may withdraw this authorization at any time. Upon withdrawal, we will immediately and permanently delete the collected facial information. If you refuse to authorize facial collection, you may choose other methods such as offline authentication; this does not affect the train ticket booking service.

② When you use the "Check-in" function on this Platform, if you need to provide images/videos for "Check-in," you need to actively authorize enabling your Camera/Photo Gallery permission to provide the images/videos. We will collect the aforementioned images/videos to better provide services. If your employer requires that the images/videos you provide include part or all of your portrait, including facial information, we will collect the images/videos containing part or all of your portrait, including facial information, to better provide services.Facial information is highly sensitive personal information. The facial information collected herein is used solely for identity verification confirmation and shall not be used for other purposes such as facial recognition, facial comparison, or facial authentication. We must obtain your separate consent via an independent pop-up window. You may withdraw this authorization at any time. Upon withdrawal, we will immediately and permanently delete the corresponding facial images/videos. If you refuse to authorize facial collection, you may complete the check-in using images without a portrait.

③ When you use the online customer service on this Platform, if you need to provide images/videos for the online customer service to view, you need to actively authorize enabling your Camera/Photo Gallery permission to provide the images/videos. We will collect the aforementioned images/videos to better provide services. The aforementioned images/videos are used solely for customer service issue verification and will be cleaned according to rules after the service ends.

④ When you use the reimbursement function on this Platform, if you need to provide images/videos such as invoices for reimbursement, you need to actively authorize enabling your Camera/Photo Gallery permission to provide the images/videos. We will collect the aforementioned images/videos to better provide services.

⑤ When you use the management functions on this Platform, if you need to provide images/videos for various management matters, you need to actively authorize enabling your Camera/Photo Gallery permission to provide the images/videos. We will collect the aforementioned images/videos to better provide services.

2) Location information collected after you actively authorize enabling your Location permission: When you use our services (e.g., booking hotels, using car hailing/taxi, check-in, etc.) that require location positioning, you need to actively authorize enabling your Location permission to obtain precise positioning. Furthermore, to recommend nearby services (e.g., hotels, scenic spots, etc.) to you, you need to actively authorize enabling your Location permission to obtain precise positioning. We will collect the aforementioned location information to better provide services. This location information includes precise location information obtained via GPS, WLAN access points, Bluetooth, and base stations and other sensors, or approximate location information obtained via network location (base station, IP, WLAN, etc.), or the region information contained in your account information, or shared information indicating your current or past location uploaded by you or others.Special Note: This Platform does not perform background continuous positioning or silent positioning; it temporarily obtains location information only when you actively use the corresponding function. You may turn off the location permission at any time. Turning it off will only affect hotel positioning, car hailing/taxi positioning, check-in positioning, and nearby services; it will not affect the basic services of this Platform.

3) Information on whether you have viewed service messages or communication messages collected after you actively authorize enabling your Notifications permission: When you use our services (e.g., booking or changing services, order approval services, etc.) or communicate with online customer service, to promptly notify you of the latest service messages or offline messages from customer service, you need to actively authorize enabling your Notifications permission. If you are not logged into your account on this Platform, we will use the corresponding identifier information of the device to ensure basic push functionality. If you are logged into your account, we will use account information to implement push notifications. We will collect information on whether you have viewed the aforementioned service messages or communication messages to better provide services.You may turn off the Notifications permission at any time; after turning it off, you will no longer receive push messages, but this will not affect our services.

4) Files, etc., collected after you actively authorize enabling your Storage permission: If you need to download or save relevant files from this Platform, or if you need to upload files when using services or functions such as online customer service, reimbursement, or management, you need to actively authorize enabling your Storage permission. We will collect the aforementioned files to better provide services.The Storage permission is used solely for file reading and writing. Refusal to authorize will prevent uploading/downloading of files but will not affect the basic services of this Platform.

4. For purposes such as improving service quality and resolving service issues, you acknowledge and agree that we will also collect the following personal information:

1) Customer Service: When you make inquiries, complaints, or suggestions to us via the contact methods provided in this policy, to facilitate contacting you, helping resolve your issue as quickly as possible, or documenting the solution and outcome of the related issue, we will collect the communication/call records and related content (including your contact information, complaint/question/suggestion details, other information you provide to prove the relevant facts, etc.). If you make an inquiry, complaint, or suggestion regarding a specific order, we will also collect your account information, order information, etc. If you make an inquiry, complaint, or suggestion regarding the services of a service provider, to facilitate effective contact and timely resolution of your inquiry, complaint, or suggestion, the service provider will collect the aforementioned information from you.Call and chat records are used solely for after-sales processing and will be deleted immediately upon expiration of the retention period.

2) Review Function: When you use the review function on this Platform, we will collect the review information you send to us.Review content can be edited independently, and you may choose to post anonymous reviews.

3) Questionnaire Surveys: For the purpose of improving service quality, if you participate in our questionnaire surveys, we will collect the response information you provide in the questionnaire.Participation in surveys is entirely voluntary; refusal to participate will not affect our services.

(III) How We Use Your Personal Information

Except in the following circumstances, we will not use your aforementioned personal information without your explicit consent or authorization:

1.To provide you with our services, including booking services, change/cancellation services, order approval services, check-in services, online customer service, reimbursement services, management services, etc.The scope of personal information use is strictly matched to the service scenario.

2.Your facial information, subject to your separate consent (separate pop-up authorization, authorization can be withdrawn at any time, data deleted immediately upon withdrawal), may only be used for identity/real-name authentication or 12306 authentication, or solely for identity confirmation, and shall not be used for other purposes.

3.For the contact information you provide (e.g., mobile phone number, email address, etc.), we may send various notifications to one or more of them during operations, including for identity verification, security verification, service notifications, customer service communications, questionnaire surveys, etc. Additionally, we may also use one or more of these methods to send you commercial information about services, functions, or activities that may interest you. If you do not wish to receive commercial marketing information, you can unsubscribe or refuse it, or you can directly contact us via the methods at the end of this policy to unsubscribe. Service notifications (order reminders, security verification) are not marketing information and cannot be unsubscribed from.

4.To fulfill the obligations stipulated in the business travel service contract signed between your employer and us, and to exercise the rights stipulated in that contract.

5.To achieve the purposes of this policy, fulfill the obligations stipulated in this policy, and exercise the rights stipulated in this policy.

6.To understand, maintain, and improve our services. During data analysis, all personal information is de-identified and anonymized, making it impossible to trace back to a specific natural person.

II. How We Share, Transfer, Entrust for Processing, and Publicly Disclose Your Personal Information

(I) Sharing

1. To ensure you can successfully use our services, we may share your personal information with the following domestic/international entities. Before sharing your personal information, we will enter into written agreements or documents with the following domestic/international entities, strictly requiring them to comply with relevant laws, regulations, and the provisions of this policy. We share only the minimum scope of your personal information necessary for providing the services with the following domestic/international entities.

1) Your Employer: As our client, your employer will receive shared your personal information based on the business travel service contract signed between your employer and us and the corresponding needs of your employer. This sharing is for management purposes such as reconciliation, data statistics, cost control, data analysis (e.g., helping employers analyze potentially non-compliant employee behavior).The shared information is limited to what is necessary for corporate travel management, and the employer shall not use it for other purposes.

2) Our Affiliates: We may share your personal information with our affiliates to enable us to provide you with services related to business travel or other services. They will adopt protective measuresnot less stringent than those in this policy. Our affiliates are Shanghai Z-Trip International Travel Agency Co., Ltd., Shanghai Lingcheng Air Ticket Service Co., Ltd., Zhejiang JingyuanAviation Service Co., Ltd., and Beijing Max International Travel Agency Co., Ltd.

3) Service Providers: Including but not limited to airlines, hotels, 12306 and its authorized agents, car hailing/taxi platforms/service providers, travel agencies, scenic spots, and their agents necessary to fulfill your specific service requests. We will share your personal information with these service providers to enable them to complete the specific services. They will adopt protective measuresnot less stringent than those in this policy.

4) Business Partners: We may provide services to you together with business partners. We will share your personal information with business partners for purposes such as real-name authentication services, communication services, consulting services, technical services, courier services, customer service, market promotion, and advertising placement. For example, to send you commercial information about services, functions, or activities that may interest you, we will provide your mobile phone number and the content of the information to be pushed to SMS service partners. If you do not wish to receive this information, you can unsubscribe or refuse it, or you can directly contact us via the methods at the end of this policy to unsubscribe.

2. To enable you to receive push notifications, log in and share information on third-party platforms, use third-party payments, use maps, use identity/real-name authentication or 12306 authentication, and use one-click mobile phone number login services and functions, third-party software development kits or other applications (hereinafter "Third-Party SDKs") are embedded in this Platform.All Third-Party SDKs integrated into this Platform are fully and individually disclosed in the Appendix to this policy, including the SDK name, developer, purpose of use, information collected, permissions invoked, usage scenarios, and official privacy policy link. Only after you actively consent to use the corresponding Third-Party SDK function will we share your personal information with it. If you refuse to use the corresponding function, the Third-Party SDK will not collect or process any of your personal information. We continuously supervise the data collection practices of Third-Party SDKs. If any SDK is found to collect data illegally, we will immediately cease using that SDK and hold the violator accountable.

3. We may share your personal information as required by relevant laws and regulations, for dispute resolution, as stipulated in written agreements or documents between you and us, or upon lawful request by administrative/judicial authorities.We have the right to refuse requests for personal information that are illegal.

4. Except as provided above or as otherwise required by relevant laws and regulations, if other individuals or entities require us to share your personal information, we will obtain your explicit consent or authorization again in accordance with the law.]

(II) Transfer

We will not transfer your personal information to any individual or entity, except in the following circumstances:

1. With your prior explicit consent or authorization.

2. As required by relevant laws and regulations, or upon lawful request by administrative/judicial authorities.

3. In the event of a merger, acquisition, asset transfer, or similar transaction, if the transfer of your personal information is involved, we will notify you in advance through prominent means such as pop-ups, in-app messages, or SMS messages. We will inform you of the name and contact information of the new individual or entity holding your personal information, and we will require that the new individual or entity holding your personal information continue to be strictly bound by this policy. Otherwise, we will require that individual or entity to re-obtain your explicit consent or authorization.

(III) Entrustment for Processing

To improve information processing efficiency, reduce processing costs, or enhance processing accuracy, we may entrust qualified professional technical service providers or business partners to process your personal information. We will sign an "Entrustment Processing Agreement" with the entrusted party, clearly defining the purpose, duration, processing methods, types of personal information, protective measures, and the rights and obligations of both parties. We will require the entrusted party to strictly process personal information in accordance with the Entrustment Processing Agreement, the provisions of this policy, and relevant laws and regulations, and regularly supervise and audit the entrusted party's processing activities. If the Entrustment Processing Agreement is not in effect, is invalid, is revoked, or terminates, we will require the entrusted party to immediately return your personal information or permanently delete it, without retaining any copies.Without your explicit consent or authorization, we strictly prohibit the entrusted party from sub-entrusting another party to process your personal information.

(IV) Public Disclosure

We will disclose your personal information, in whole or in part, in the following circumstances:

1. In principle, we do not publicly disclose your personal information. If disclosure is necessary, we must obtain your separate consent (separate pop-up authorization, authorization can be withdrawn at any time, data deleted immediately upon withdrawal).

2. As required by relevant laws and regulations, or upon lawful request by administrative/judicial authorities, we may disclose your personal information to other parties or administrative/judicial authorities.

III. How We Store, Transfer Across Borders, and Protect Your Personal Information

(I) Storage

1. Storage Location: Personal information collected and generated within China is stored entirely on servers located within China.

2. Storage Period: We store your personal information only for the shortest period necessary to fulfill the purposes of the business travel service contract and this policy, or as required by relevant laws and regulations. After the expiration of the aforementioned storage period, or after your account on this Platform is deactivated, we will permanently delete or irreversibly anonymize your personal information that is not legally required to be retained. Order, invoice, financial audit, and other legally required information will be irreversibly anonymized and permanently deleted after the retention period expires.

3. Storage Security: We use technical measures that comply with national and industry standards, such as encryption, access control, and data masking, to ensure the security of your stored personal information, and we employ professional personnel according to professional management specifications to safeguard the security of your stored personal information.

4. Cessation of Operations: We aspire to continue serving you. If we cease operations, we will notify you individually or via public announcement, promptly stop collecting, using, and storing your personal information, and permanently delete or irreversibly anonymize your personal information that is not legally required to be retained. Order, invoice, financial audit, and other legally required information will be irreversibly anonymized and permanently deleted after the retention period expires.

(II) Cross-Border Transfer

1. When you conduct cross-border transactions through this Platform (e.g., booking international flights, international hotels, or other services provided by international service providers), or as required by relevant laws and regulations, your personal information may need to be transferred outside of China. In such cases, we will clearly inform you of the name, contact information, processing purposes, processing methods, types of personal information, and your legal rights regarding the overseas recipient. If your personal information needs to be transferred across borders, we must obtain your separate consent (separate pop-up authorization, authorization can be withdrawn at any time, data deleted immediately upon withdrawal).

2. We will also comply with the following conditions as stipulated by relevant laws, regulations, and the Cyberspace Administration of China, and require the overseas recipient to provide the highest level of confidentiality and protection for your personal information obtained:

1) Passing a security assessment organized by the Cyberspace Administration of China;

2) Obtaining personal information protection certification from a professional body;

3) Entering into a contract with the overseas recipient based on the standard contract formulated by the Cyberspace Administration of China, stipulating the rights and obligations of both parties;

4) Other conditions stipulated by laws, administrative regulations, or the Cyberspace Administration of China.

3. We strictly prohibit the overseas recipient from retransferring the information to other non-compliant countries/regions. We will conduct regular audits of the overseas recipient. If non-compliant retransfer is found, we will immediately terminate cooperation and report to the regulatory authorities.

(III) Protection

1. All accounts on this Platform have security protection features. Please keep your username, password, and other personal information safe. We protect the security of your personal information through technical measures such as password encryption and account recovery requiring information verification/real-name authentication, as well as by employing professional personnel according to professional management specifications. We reference domestic and international information security standards and have established an information security protection system. We have obtained certification for both the ISO27001 Information Security Management System standard and the ISO27701 Privacy Information Management System standard.

2. When collecting and using your personal information, we will de-identify your personal information. Our data analysis corresponds only to specific, coded personal information that cannot be directly linked to your real identity, preventing misuse of raw data.

3. We also strictly manage employees who may have access to your personal information, monitoring their operations. We have established a multi-level approval mechanism for important operations such as data access, internal/external transmission and use, masking, and decryption – no operation without approval. We also sign "Confidentiality Agreements" with these employees, requiring them to maintain confidentiality obligations for three years after departure. Concurrently, we regularly train employees on information security and personal information protection laws and regulations, requiring them to develop good operational habits in daily work and enhance data protection awareness.

4. In the event of a security incident such as a data breach or cyberattack, we will immediately activate our emergency response plan and take remedial measures such as blocking the attack, fixing vulnerabilities, and isolating data. We will promptly notify affected users and relevant regulatory authorities as required by laws and regulations, completely retain incident handling records, and bear corresponding legal responsibilities in accordance with the law.]**

5. Except as provided in this policy, stipulated in the business travel service contract, or with your explicit consent or authorization, we will not share, transfer, or disclose your personal information to other parties. We also do not permit other parties to collect your personal information from us by any means or method, or to use, transfer, or disclose the personal information we have collected. If you discover such illegal activities by other parties, you can contact us via the methods at the end of this policy. We will pursue the legal liability of the other party through judicial means.

IV. How You Can Manage Your Personal Information

You legally enjoy rights including the right to know, the right to access/inspect, the right to rectify/supplement, the right to deletion, the right to copy/transfer/data portability, the right to withdraw consent, and the right to deactivate your account. We provide convenient, free, and accessible channels for exercising these rights.

1. Right to Access/Inspect, Rectify/Supplement, and Delete

1) After logging into Z-TRIP official website, you can:

① Through "Profile", click on the basic information module to access/inspect, rectify/supplement, or delete your personal information; through "Profile", click on relevant content in the common information module to access/inspect, add, rectify/supplement, or delete other information.

② Enter through the service booking page, click "Add" or "Delete" to access/inspect, add, or delete other information.

2) After logging into Z-TRIP mobile application (APP) or Z-TRIP WeChat mini-program, you can:

① Through "My", then click on your name at the top, access your personal information to access/inspect, rectify/supplement, or delete it.

② Enter through the service booking page, click "Add" or "Delete" to access/inspect, add, or delete other information.

3) You can also directly contact us via the methods at the end of this policy to access/inspect, rectify/supplement, or delete your personal information that is not legally required to be retained.

4) Order, invoice, financial audit, and other legally required information will be irreversibly anonymized and permanently deleted after the retention period expires. During the legal retention period, you can access/inspect your corresponding anonymized information but cannot directly delete the raw data.

2. Right to Copy/Transfer/Data Portability

1) You can contact us via the methods at the end of this policy to copy your personal information free of charge. We will provide it promptly after verifying your identity.

2) If you need to transfer your personal information and meet the conditions stipulated by the Cyberspace Administration of China, we will provide a secure and compliant transfer pathway.

3) You may request that we export your personal data, such as identity, orders, travel records, etc., in a common, machine-readable structured format. You may also request that this personal data be transferred directly to another data controller (within the bounds of technical feasibility).

3. Withdrawal of Consent

You can turn off permissions such as Camera/Photo Gallery, Location, Notifications, and Storage at any time in your phone's system settings or this Platform's settings, or contact the Platform's online customer service to withdraw all or specific information processing authorizations. Withdrawal of consent does not affect information processing activities that were lawfully conducted prior to the withdrawal, and we shall not refuse to provide basic services solely because you withdrew consent (unless the permission is essential for core fulfillment).

4. Account Registration and Deactivation on this Platform

1) Since we provide services only to employees of enterprises, the registration of your account on this Platform is based on the information provided by your employer. You cannot register an account on this Platform independently. This rule has been communicated to your employer in advance.

2) If you need to deactivate your account on this Platform due to resignation or other reasons, please contact your employer first. We will deactivate your account within 5 working days upon formal request from your employer. If your employer does not cooperate, you may also contact us directly via the methods at the end of this policy, and we will deactivate your account within 10 working days as per your request.

3) Upon deactivation of your account on this Platform, all personal information within that account that is not legally required to be retained will become immediately invalid and be completely cleared. Order, invoice, financial audit, and other legally required information will be irreversibly anonymized and permanently deleted after the retention period expires.

4) After your account on this Platform is deactivated, we will no longer collect, use, or store any personal information corresponding to that account.

V. How We Use Cookies and Other Similar Technologies

1. Unless you have rejected cookies, we will set or access cookies on your device to enable you to log in to or use services or functions of this Platform that depend on cookies. We use cookies to provide you with more personalized services, promotional services, etc. You have the right to choose to accept or reject cookies. You can do so by modifying your browser, APP, or system settings. If you choose to reject cookies, you may not be able to log in to or use services or functions that depend on cookies, but this will not affect the basic services of this Platform. Information collected via cookies is used only for the purposes stated in this policy and not for malicious tracking or illegal profiling.

2. In addition to cookies, we also use other similar technologies such as web beacons and pixel tags on our website. A web beacon is usually a transparent image embedded in a website or email. With the help of pixel tags in emails, we can know whether an email has been opened. The emails we send to you may contain address links to content on our website. If you click on such a link, we will track this click to help us understand your service preferences, so that we can proactively improve service quality. If you do not wish to be tracked in this way, you can unsubscribe or refuse it, or you can directly contact us via the methods at the end of this policy to unsubscribe.

VI. Protection of Minors

1. We provide services only to employees of enterprises. We do not register accounts for minors on this Platform and do not offer independent services to minors.

2. If a minor is included among your travelers, we require you, as their guardian, to provide, or obtain separate consent from the guardian for, the minor's personal information. We only process information necessary to fulfill the contract and will not collect any additional irrelevant information about the minor.

3. If a minor is included among your travelers, and you, as their guardian or having obtained separate consent from the guardian, need to exercise rights such as access/inspection, copy/transfer/data portability, rectification/supplement, deletion, or withdrawal of consent, please contact our Data Protection Officer (DPO) via the methods at the end of this policy using the dedicated channel for minors to exercise these rights. We prioritize responding to requests related to minors.

4. We will not collect, use, share, transfer, or disclose personal information of minors. If you discover that we have collected personal information of a minor in violation of regulations, please ask the guardian to contact our Data Protection Officer (DPO) via the methods at the end of this policy using the dedicated channel for minors to request deletion.

VII. General Data Protection Regulation

If you are an EU data subject (i.e., a natural person within the territory of an EU member state, including EU residents and travelers temporarily entering the EU), or if your use of our services involves the EU (e.g., booking EU flights, EU hotels, EU car hailing/taxi, EU tour packages, EU visas, EU insurance, etc.), in addition to complying with the provisions of this policy and relevant Chinese laws and regulations, we will strictly comply with all provisions of the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). The specific compliance rules and rights and obligations of both parties are as follows:

(I) Scope of Application and Jurisdictional Rules

1. Applicability of Extraterritorial Jurisdiction: In accordance with Article 3 of the GDPR on extraterritorial jurisdiction, although we are registered and operate within China, as long as we provide services to EU data subjectsprocess personal data of natural persons within the territory of EU member states, or monitor the behavior of EU users, the GDPR applies in full, regardless of the platform's registration location.

2. Exemptions: If the processing of EU data subject data is occasional, does not involve the processing of special categories of personal data as defined in Article 9 of the GDPR (race, political opinions, religion, health, biometric data, sex life, etc.), and poses no risk to the rights and freedoms of natural persons within EU member states, some GDPR obligations may be exempt. The identification document numbers, facial information, and health-related information (height, weight, shoe size, degree of myopia in EU tour packages) we collect constitute special category data and are not eligible for this exemption.

(II) Core GDPR Principles for Data Processing (Following GDPR Article 5)

When processing personal data of EU data subjects, we strictly adhere to seven core principles and proactively maintain compliance records for inspection:

1. Lawfulness, Fairness, and Transparency: All data processing activities have a lawful basis. The purpose, scope, and retention period are communicated to you in a clear and understandable manner, with no concealment of data flows.

2. Purpose Limitation: Data is processed solely for specified purposes, such as providing booking services, change/cancellation services, and security verification, and is not reused for purposes beyond the initial agreed scope.

3. Data Minimization: Only the minimum information necessary for providing cross-border services is collected. For non-mandatory safety information such as height, weight, shoe size, and degree of myopia, it is clearly marked as optional, and its collection is never compulsory.

4. Accuracy: A regular data verification mechanism is established, allowing you to correct inaccurate personal information at any time.

5. Storage Limitation: Personal data of EU data subjects is retained only for the duration of service provision and legal retention periods. After service termination, data is deleted or anonymized according to rules.

6. Integrity and Confidentiality: Technical measures such as encryption, access control, and masking are used to protect data against leakage, alteration, or loss.

7. Accountability: We are able to demonstrate at any time to EU supervisory authorities and data subjects that our data processing activities fully comply with GDPR requirements.

(III) Lawful Bases for Data Processing (GDPR Article 6)

For the processing of personal data of EU data subjects, we operate only on one of the following lawful bases. Any processing activity without a lawful basis is immediately terminated:

1. Your explicit, active, affirmative action indicating consent (separate pop-up authorization, consent can be withdrawn at any time, withdrawal does not affect prior lawful processing);

2. To fulfill the obligations stipulated in the business travel service contract signed between your employer and us, and to exercise the rights stipulated in that contract;

3. To fulfill a legal obligation incumbent upon us;

4. To protect your vital interests or the vital interests of another natural person concerning life or physical safety;

5. The processing is necessary for the performance of a task carried out in the public interest;

6. The processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your fundamental privacy rights.

(IV) Protection of Special Categories of Personal Data (GDPR Article 9)

The personal information we collect, such as your identification document number, facial information, health-related information (height, weight, shoe size, degree of myopia in EU tour packages), nationality/region, religion, etc., constitutes special categories of personal data under the GDPR and is subject to the highest level of protection:

1. Processing such data requires your explicit separate consent in writing; oral authorization or default checkboxes are invalid;

2. It is used only within the scope necessary for overseas travel safety, identity verification, or the legal requirements of the destination country, and is strictly prohibited from being shared or transferred externally;

3. Automated marketing and user profiling based on special category data are prohibited;

4. Data is stored with strong encryption throughout its lifecycle, accessible only to designated compliance personnel, with complete access logs retained.

(V) Legal Rights of EU Data Subjects (GDPR Chapter IV)]

In addition to the rights set out in Article 4 of this policy, EU data subjects enjoy the following additional statutory rights under the GDPR. We provide free, convenient, and accessible channels for exercising these rights:

1. Right to be Informed: You may request at any time that we provide clear textual information regarding all details of personal data processing, recipients, cross-border flows, and retention periods.

2. Right of Access: You have the right to obtain, free of charge, a copy of all your personal data stored by us and the processing records. The Platform will respond within 1 month.

3. Right to Rectification: If you find data to be inaccurate or incomplete, you may request correction at any time. The Platform will process it immediately.

4. Right to Erasure (Right to be Forgotten): When there is no lawful reason for retention, you withdraw consent, or the data processing violates the GDPR, you may request the deletion of all your personal data. The Platform will complete the deletion within the specified time frame and notify all recipients to delete the data simultaneously.[5. Right to Restriction of Processing: You may request temporary restriction of data processing (e.g., during verification of data accuracy or lawfulness of processing).

6. Right to Data Portability: You may request that we export your personal data, such as identity, orders, travel records, etc., in a common, machine-readable structured format. You may also request that this data be transferred directly to another data controller (within the bounds of technical feasibility).

7. Right to Object: You may object at any time to data processing based on public interest, commercial marketing, and automated decision-making.

8. Right not to be subject to Automated Decision-making: We will not rely solely on automated decision-making (without human intervention) to make decisions affecting your rights. If we use automated decision-making, we will inform you in advance and provide a manual appeal channel.

(VI) Compliance Rules for Cross-Border Data Transfer (GDPR Chapter V)]

As our services necessarily involve the cross-border transfer of personal data between China and the EU, we will strictly implement the GDPR's cross-border transfer requirements:

1. Prior Notification and Separate Consent: Before transferring your personal data outside the EU, we will separately inform you of the overseas recipient's name, address, data processing purposes, security measures, your rights to redress, and obtain your separate consent before the transfer.

2. Legal Pathways for Cross-Border Transfer (transfer is permitted only if one of the following conditions is met):]

1) Using a country/region recognized by the European Commission as providing adequate protection for data reception;

2) Signing EU Standard Contractual Clauses (SCCs) with the overseas recipient;

3) Completing data protection certification required by the EU;

4) Passing the cross-border data security assessment by the Cyberspace Administration of China;

3. Control over Overseas Recipients: All recipients within the EU (airlines, hotels, local agents, visa authorities, etc.) are required to comply with the GDPR, and binding agreements are signed. If a recipient violates regulations, we immediately terminate data transfer and hold them accountable.

4. Prohibition on retransferring EU data subjects' personal data to other non-compliant countries/regions.

(VII) Data Processing Records and Risk Assessment (GDPR Articles 30, 35)

1. Records of Processing Activities (ROPA): We maintain a complete data processing log containing: data subject types, data categories, processing purposes, data recipients, cross-border transfer situations, storage periods, security measures, and legal basis for authorization. If we process EU user data on a large scale or involve special category data, the log is retained permanently and subject to regulatory inspection.

2. Data Protection Impact Assessment (DPIA): For high-risk activities such as large-scale processing of EU user data, biometric information processing, and bulk cross-border data transfer, we conduct a DPIA in advance to identify privacy risks and implement corrective actions. The assessment report is archived for reference, and key content may be disclosed as required by regulations.

(VIII) EU Representative and Data Protection Officer (DPO) Arrangements (GDPR Articles 27, 37)

1. EU Compliance Representative: As our services involve the EU and require large-scale processing of personal data of EU data subjects, we have designated a dedicated EU Representative within the territory of an EU member state. The EU Representative is responsible for liaising with EU data protection supervisory authorities and handling complaints and inquiries from EU users. The EU Representative's contact information will be permanently displayed at the end of this policy.

2. Data Protection Officer (DPO): We have appointed a dedicated DPO to oversee GDPR and domestic personal information protection compliance, responsible for interfacing with users and regulatory authorities, conducting internal compliance training, and performing security audits. The DPO's contact information will be permanently displayed at the end of this policy.

(IX) Third-Party Processors and Entrustment Management (GDPR Article 28)

1. We sign GDPR-specific data processing agreements with all third-party service providers (push SDKs, payment gateways, map service providers, cross-border travel suppliers, etc.) that process EU user data. These agreements clarify the rights and responsibilities of both parties, data confidentiality, liability for breaches, and prohibition of sub-entrustment.

2. We conduct regular compliance audits of third-party processors under the GDPR. If violations are found, cooperation is immediately terminated.

3. In the event of a data breach or infringement caused by a third-party's processing activities, we assume liability to the data subject first and then seek recourse from the third party.

(X) Data Breach Emergency and Notification Rules (GDPR Articles 33, 34)

1. Breach Reporting: Upon discovery of a personal data breach involving EU data subjects (e.g., leakage, alteration, loss), we report to the relevant EU local data protection authority within 72 hours, providing details on the scope, impact, and remedial measures taken.

2. User Notification: If the data breach poses a high risk to your rights and freedoms, we will promptly inform you of the breach details, risks, and recommended protective actions via SMS, email, in-app messages, etc.

3. Emergency Response: We activate the data breach emergency plan, contain the risk, fix vulnerabilities, trace the source, and completely retain all handling records.

(XI) GDPR Policy Updates and Notification[In the event of amendments to the EU GDPR regulations or changes to our services that alter the applicability of the GDPR, we will publish the updated GDPR policy in a prominent location on this Platform 15 days in advance. The updated policy will take effect after the 15-day public notice period expires. If the changes involve significant rights and interests, we will separately notify EU data subjects via push notifications and re-obtain necessary consents. After the GDPR policy is updated, it shall have the same legal effect as the other provisions of this policy.

(XII) Penalties for Violations and Dispute Resolution

1. Compliance Penalties: We acknowledge that violations of the GDPR can result in substantial fines. We will continuously implement internal compliance controls to mitigate the risk of violations.

2. Dispute Resolution:

1) EU data subjects may first contact our Platform's online customer service, service hotline (400-010-5050), EU Representative (zaitu02@z-trip.cn), or Data Protection Officer (DPO) (cs@z-trip.cn) to resolve GDPR-related disputes.

2) If resolution is not reached through negotiation, you have the right to file a complaint with the competent data protection supervisory authority in your EU member state of residence, or to initiate legal proceedings before the competent courts of the EU member state.

3) Simultaneously, you may still file complaints with domestic authorities such as the Cyberspace Administration of China (www.12377.cn), market supervision authorities/Consumer Protection Association (021-12315), or file a lawsuit with the Jing'an District People's Court in Shanghai, in accordance with relevant Chinese laws and regulations.

VIII. Updates to this Policy

To better serve you, we may update this policy based on changes in laws, regulations, regulatory requirements, service functions, or personal information processing activities. This Platform will publish the updated policy in a prominent location 15 days in advance. The updated policy will take effect after the 15-day public notice period expires. For material changes, we will notify you via pop-ups, in-app notifications, page prompts, or other appropriate means on this Platform, and re-obtain your consent when required by laws and regulations.

Material changes include, but are not limited to: significant changes in the purpose, method, or type of personal information processing; significant changes in the main recipients of shared, transferred, entrusted, or publicly disclosed personal information; significant changes in your rights regarding personal information processing and the methods for exercising them; changes in our contact information or complaint channels; indications of high risk from a personal information security impact assessment, etc.

If you do not agree with the content of the updated policy, our services may not function properly, or may not achieve the intended service effects, and you should immediately cease using our services. By clicking, checking, or otherwise actively confirming your agreement to the updated policy on the page, you signify that, with full knowledge, you voluntarily, clearly understand, and agree to all the contents of the updated policy.

IX. Contact Us

1. If you have complaints, questions, or suggestions related to personal information, or if you have any questions or suggestions regarding the content of this policy, or need to exercise rights such as access/inspection, rectification/supplement, deletion, copy/transfer/data portability, withdrawal of consent, or account deactivation, you can contact us through the following channels:

Company Name: Shanghai Zaitu Network Technology Co., Ltd.

Unified Social Credit Code: 91310000MA1K33GA5P

Registered Address: Room 302-1, 3rd Floor, No. 14, Lane 1401, Jiangchang Road, Jing'an District, Shanghai

National Service Hotline: 400-010-5050

EU Representative Contact/Email: zaitu02@z-trip.cn

Data Protection Officer (DPO) Contact/Email: cs@z-trip.cn

Account Deactivation/Information Deletion Portal: https://m.z-trip.cn/common/setting/

Official Privacy Policy Link:

2. We will review your complaints, questions, or suggestions as soon as possible. After verifying your user identity, we will respond within 10 working days for routine requests, andwithin 5 working days for urgent privacy and security requests. If you are not satisfied with our response, particularly if our personal information processing activities have harmed your legitimate rights and interests, you may also file a complaint with regulatory authorities such as the Cyberspace Administration of China (www.12377.cn), market supervision authorities/Consumer Protection Association (021-12315), or file a lawsuit with the Jing'an District People's Court in Shanghai to resolve the dispute.

Appendix: List of Third-Party SDKs

Note: This list completely and truthfully discloses all Third-Party SDKs integrated into this Platform, including the SDK name, developer, purpose of use, information collected, permissions invoked, usage scenarios, and official links. All SDKs adhere to the principles of lawfulness, legitimacy, minimum necessity, and non-silent collection.There is no background silent illegal collection of personal information or excessive permission invocation.If an SDK natively possesses device identification capabilities, the Platform only calls them in service-essential scenarios and does not collect sensitive device identifiers unnecessarily. The rules for the collection and use of your personal information by the following Third-Party SDKs (e.g., "User Service Agreement," "Privacy Policy") are created, published, and updated by the SDK providers themselves, and the operating parties of the Third-Party SDKs bear independent legal responsibility. Before using the corresponding SDK functions, please be sure to check the latest privacy policies on their official websites and voluntarily choose whether to use them.

1. Third-Party SDK Name: Vivo Push

Developer Name: Guangdong Bubugao Electronic Industry Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: AndroidID, OAID/VAID/AAID, IMSI, BSSID, IMEI, operating system version number, WLAN list, device MAC address, ICCID, EMMCID/UFSID, network type, device model, hardware serial number, SSID, location information, mobile country code, carrier information, language used, system settings, device and application data

Android Permissions Invoked: READ_PHONE_STATE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION, INTERNET

Usage Scenario: Triggered when pushing notifications such as orders and itineraries to users

Official Website Link: [https://dev.vivo.com.cn/documentCenter/doc/706]

2. Third-Party SDK Name: OPPO Push

Developer Name: OPPO Guangdong Mobile Communications Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: IMEI, OAID, hardware serial number, IMSI, AndroidID, IP, Google Advertising ID, BSSID, phone region setting, device model, battery level, phone operating system version and language, network type, message sending result, notification bar status, lock screen status, application information (APP package name and version number, running processes), push SDK version number, carrier information

Android Permissions Invoked: READ_PHONE_STATE, ACCESS_NETWORK_STATE, READ_EXTERNAL_STORAGE

Usage Scenario: Triggered when pushing notification messages to users

Official Website Link: [https://open.oppomobile.com/wiki/doc#id=10288]

3. Third-Party SDK Name: Meizu Push

Developer Name: Meizu Technology Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: BSSID, WLAN list, device MAC address, network type, device model, hardware serial number, SSID, location information, running tasks, AndroidID, carrier information

Android Permissions Invoked: READ_PHONE_STATE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION, GET_TASKS, INTERNET

Supplementary Note: ACCESS_BACKGROUND_LOCATION is a native SDK permission; this application does not actually invoke background positioning capability.

Usage Scenario: Triggered when pushing notification messages to users

Official Website Link: [https://open.flyme.cn/docs?id=202]

4. Third-Party SDK Name: Xiaomi Push

Developer Name: Xiaomi Technology Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: WIFI status, device model, device manufacturer, network type, device location (country or region), SIM card carrier name, device memory, operating system version, Xiaomi Push SDK version, IMEI, hardware serial number, SSID, AndroidID, OAID, running processes, VAID, AAID, MID (for MIUI system), device storage space, SDK version, phone region setting, notification bar status, lock screen status, application information (package name, version name, application name, first installation time, last update completion time)

Android Permissions Invoked: GET_TASKS, READ_PHONE_STATE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, INTERNET

Usage Scenario: Triggered when pushing notification messages to users

Official Website Link: [https://dev.mi.com/console/doc/detail?pld=1822]

5. Third-Party SDK Name: Honor Push SDK

Developer Name: Honor Terminal Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: Android OAID, AAID, PushToken (including Token obtained from third-party push services)

Android Permissions Invoked: None

Usage Scenario: Triggered when pushing messages to users

Official Website Link: [https://developer.honor.com/cn/docs/11002/guides/sdk-data-security]

6. Third-Party SDK Name: Huawei HMS Push

Developer Name: Huawei Technologies Co., Ltd.

Purpose of Use: Push notifications

Platform Involved: Android

Information Collected: BSSID, IMEI, WLAN list, network type, network status, device model, SSID, AAID, phone ID, application ID, application package name, server public IP address

Android Permissions Invoked: READ_PHONE_STATE, WRITE_EXTERNAL_STORAGE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, INTERNET

Usage Scenario: Triggered when pushing notification messages to users

Official Website Link:

[https://developer.huawei.com/consumer/cn/doc/development/HMSCore-Guides/sdk-data-security-0000001050042177]

7. Third-Party SDK Name: Material Design Components

Developer Name: None (Open-source tool)

Purpose of Use: Simplify page layout, improve development efficiency

Platform Involved: Android

Information Collected: Screen resolution, device manufacturer

Android Permissions Invoked: None

SDK Privacy Policy Link: [https://github.com/material-components/material-components-android]

8. Third-Party SDK Name: Picasso

Developer Name: None (Open-source tool)

Purpose of Use: Image downloading and cache management on Android

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [http://github.com/square/picasso]

9. Third-Party SDK Name: WeChat Open Platform

Developer Name: Tencent Technology (Shenzhen) Co., Ltd.

Purpose of Use: WeChat login, content sharing, WeChat Pay

Platforms Involved: Android, iOS

Information Collected: Device MAC address, OAID, UUID, gyroscope sensor information, IMEI, SIM card serial number, AndroidID, IP address, device model, SSID, BSSID, hardware serial number, IDFA (iOS only), shared resources, WeChat avatar, nickname information, WeChat Pay order identifier, location information, installed application package names, clipboard

Android Permissions Invoked: ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION, READ_PHONE_STATE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, INTERNET

Usage Scenarios: Triggered when users use WeChat login, WeChat sharing, or WeChat Pay functions

Official Website Link: [https://open.weixin.qq.com/]

Privacy Policy Link:

[https://support.weixin.qq.com/cgi-bin/mmsupportacctnodeweb-bin/pages/RYiYJkLOrQwuOnb8/]

WeChat Pay Link: [https://posts.tenpay.com/posts/18ed0968618e3db204d4931651708953.html]

10. Third-Party SDK Name: Alipay

Developer Name: Alipay (Hangzhou) Information Technology Co., Ltd.

Purpose of Use: Third-party payment service

Platforms Involved: Android, iOS, HarmonyOS

Information Collected: Device model, brand, device serial number, manufacturer, device MAC address, IMSI, BSSID, WIFI status/parameters/list, SD card directory, sensor information, IMEI, AndroidID, ICCID, AAID, network type, carrier information, hardware serial number, SIM card serial number, IDFA (iOS only), IDFV (iOS only), SSID, IP, running list, installed application packagenames, system settings, system properties, OAID, running processes, operating system

Android Permissions Invoked: ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, READ_PHONE_STATE, READ_EXTERNAL_STORAGE, INTERNET

Usage Scenario: Triggered when users choose Alipay to complete a payment

Official Website Link: [https://opendocs.alipay.com/open/54]

11. Third-Party SDK Name: Baidu Maps & Location

Developer Name: Beijing Baidu Online Network Technology Co., Ltd.

Purpose of Use: Map services such as hotel location search, car hailing positioning, map navigation

Platforms Involved: Android, iOS

Information Collected: AndroidID, device brand and model, carrier information, network status, sensor information, system version, manufacturer, device name, SD card directory, device call status, WLAN list, IP, WIFI status, BSSID, SSID, IDFA (iOS only), location information

Android Permissions Invoked: READ_PHONE_STATE, WRITE_EXTERNAL_STORAGE, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION, GET_TASKS, WRITE_SETTINGS, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, INTERNET, BLUETOOTH

Supplementary Note: ACCESS_BACKGROUND_LOCATION is a native SDK permission; this application does not actually invoke background positioning capability.

Usage Scenario: Triggered when users use location or map-related business functions

Official Website Link: [https://lbsyun.baidu.com/index.php?title=openprivacy]

12. Third-Party SDK Name: Amap Maps & Location

Developer Name: Amap Software Co., Ltd.

Purpose of Use: Map services such as positioning and map navigation

Platform Involved: Android

Information Collected: Base station information, WIFI information, GAID, carrier information, screen resolution, GNSS information, network type, device signal strength, IMEI, MEID, MAC address, OAID, IMSI, serial number, SIM card status, ICCID, hardware serial number, application name, application version number, AndroidID, device model, sensor information, operating system, manufacturer, device name, SD card directory, device call status, WLAN list, IP, WIFI status, BSSID, SSID, IDFA (iOS only), location information

Android Permissions Invoked: READ_PHONE_STATE, WRITE_EXTERNAL_STORAGE, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION, GET_TASKS, WRITE_SETTINGS, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, INTERNET, BLUETOOTH

Supplementary Note: ACCESS_BACKGROUND_LOCATION is a native SDK permission; this application does not actually invoke background positioning capability.

Usage Scenario: Triggered when users use location or map-related business functions

Official Website Link: [https://lbs.amap.com/pages/privacy/]

13. Third-Party SDK Name: China Telecom Unified Authentication

Developer Name: Century Long Information Network Co., Ltd.

Purpose of Use: One-click mobile phone number login

Platforms Involved: Android, iOS

Information Collected: Registered mobile phone number, local phone number, network connection type, network status information, network address, carrier type, mobile device type, mobile device manufacturer, mobile operating system type and version

Android Permissions Invoked: READ_PHONE_STATE, WRITE_SETTINGS, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, CHANGE_NETWORK_STATE, INTERNET

Usage Scenario: Triggered when telecom mobile users use the APP one-click login function

Official Website Link:

[https://e.189.cn/sdk/agreement/show.do?order=2&type=main&appKey=&hidetop=true&isShowPre=&returnUrl=]

14. Third-Party SDK Name: China Mobile Unified Authentication

Developer Name: China Mobile Communications Group Co., Ltd.

Purpose of Use: One-click mobile phone number login

Platforms Involved: Android, iOS

Information Collected: Network type, network address (IP address), network status, carrier type, local phone number information, SIM card status, mobile device type, mobile operating system, hardware manufacturer

Android Permissions Invoked: READ_PHONE_STATE, WRITE_SETTINGS, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, CHANGE_NETWORK_STATE, INTERNET

Usage Scenario: Triggered when China Mobile users use the APP one-click login function

Official Website Link: [http://dev.10086.cn/]

Privacy Policy Link: [https://wap.cmpassport.com/resources/html/contract2.html]

15. Third-Party SDK Name: OAID

Developer Name: China Academy of Information and Communications Technology

Purpose of Use: Generate device anonymous identifier, reduce ad tracking risk

Platform Involved: Android

Information Collected: Network status, call status, OAID, device manufacturer, AAID, VAID

Android Permissions Invoked: READ_PHONE_STATE, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE

Usage Scenario: Triggered in scenarios involving device anonymous identification or ad risk control

Official Website Link: [https://msaollianccnlcalisn2id-120]

16. Third-Party SDK Name: Airbnb

Developer Name: None (Open-source tool)

Purpose of Use: Animation rendering

Platforms Involved: Android, iOS, HarmonyOS

Information Collected: System version information

Android Permissions Invoked: None

Usage Scenario: Triggered during page animation rendering

Official Website Link: [https://github.com/airbnb]

17. Third-Party SDK Name: AppsFlyer

Developer Name: Pushu (Beijing) Technology Co., Ltd.

Purpose of Use: Ad placement, data statistics and analysis

Platforms Involved: Android, iOS

Information Collected: Device information (device model, sensor information), location information, IDFA (iOS only)

Android Permissions Invoked: ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION

Supplementary Note: ACCESS_BACKGROUND_LOCATION is a native SDK permission; this application does not actually invoke background positioning capability.

Usage Scenario: Triggered in ad placement or data statistics related scenarios

Official Website Link:

[https://market.cmbchina.com/MPage/online/190717190011375/privacy.htm]

18. Third-Party SDK Name: LeakCanary

Developer Name: None (Open-source tool)

Purpose of Use: App memory leak detection

Platform Involved: Android

Information Collected: Current running process, SD card directory, external storage access information, location information, IP address, carrier information, running tasks, UUID, device brand]

Android Permissions Invoked: READ_PHONE_STATE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE

Usage Scenario: Triggered during app operation or fault detection

Official Website Link: [https://github.com/square/leakcanary]

19. Third-Party SDK Name: trove

Developer Name: None (Open-source tool)

Purpose of Use: Development assistance tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/topics/trove]

20. Third-Party SDK Name: Apache

Developer Name: None (Open-source tool)

Purpose of Use: Development assistance tool

Platform Involved: Android

Information Collected: IP address

Android Permissions Invoked: None

Official Website Link: [https://github.com/apache/httpd]

21. Third-Party SDK Name: smack

Developer Name: None (Open-source tool)

Purpose of Use: Communication service component

Platforms Involved: Android, HarmonyOS

Information Collected: IP address

Android Permissions Invoked: INTERNET

Official Website Link: [https://github.com/igniterealtime/Smack]

22. Third-Party SDK Name: zip4j

Developer Name: None (Open-source tool)

Purpose of Use: Compressed file processing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/srikanth-lingala/zip4j/releases]

23. Third-Party SDK Name: GSON

Developer Name: None (Open-source tool)

Purpose of Use: JSON data parsing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/google/gson]

24. Third-Party SDK Name: bouncycastle

Developer Name: None (Open-source suite)

Purpose of Use: Java encryption tool suite

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/bcgit/bc-csharp]

25. Third-Party SDK Name: Wire Protocol Buffer

Developer Name: None (Open-source tool)

Purpose of Use: Protocol data processing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/square/wire]

26. Third-Party SDK Name: Zxing QR Code Scanning

Developer Name: None (Open-source tool)

Purpose of Use: QR code recognition and scanning

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/zxing/zxing]

27. Third-Party SDK Name: okhttp

Developer Name: None (Open-source tool)

Purpose of Use: Network request component

Platform Involved: Android

Information Collected: IP address, current running process

Android Permissions Invoked: INTERNET

Usage Scenario: Triggered when the app initiates a network request

Official Website Link: [https://github.com/square/okhttp]

28. Third-Party SDK Name: chromium

Developer Name: Google Inc.

Purpose of Use: Built-in web view component

Platform Involved: Android

Information Collected: WLAN information (SSID, WIFI status), sensor information, sensor list, IP address, clipboard, application list, phone call status

Android Permissions Invoked: None

Usage Scenario: Triggered when accessing web pages using the built-in browser

Official Website Link: [https://chromium.googlesource.com/chromium/src/]

29. Third-Party SDK Name: Godeye

Developer Name: None (Open-source tool)

Purpose of Use: App memory leak detection

Platform Involved: Android

Information Collected: Running process

Android Permissions Invoked: None

Official Website Link: [https://github.com/zixun/GodEye]

30. Third-Party SDK Name: fastjson

Developer Name: Alibaba (China) Co., Ltd. (Open-source component)

Purpose of Use: JSON data parsing library

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/alibaba/fastjson]

31. Third-Party SDK Name: OkSocket

Developer Name: None (Open-source tool)

Purpose of Use: TCP network communication component

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/xuuhaoo/OkSocket]

32. Third-Party SDK Name: orhanobutlogger

Developer Name: None (Open-source tool)

Purpose of Use: Log printing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/orhanobut/logger]

33. Third-Party SDK Name: ARouter

Developer Name: Alibaba

Purpose of Use: Android componentization routing framework

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/alibaba/ARouter]

34. Third-Party SDK Name: JodaTime

Developer Name: None (Open-source tool)

Purpose of Use: Date and time processing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/JodaOrg/joda-time]

35. Third-Party SDK Name: Tencent Mmkv SDK

Developer Name: Tencent

Purpose of Use: Data storage component

Platforms Involved: Android, HarmonyOS

Information Collected: None

Android Permissions Invoked: None

Link: [https://mvnrepository.com/artifact/com.tencent/mmkv?repo=jcenter]

Privacy Policy Link:

[https://support.weixin.qq.com/cgi-bin/mmsupportacctnodeweb-bin/pages/aY5BAtRiO1BpoHxo]]

36. Third-Party SDK Name: greenrobot EventBus

Developer Name: None (Open-source tool)

Purpose of Use: In-app communication component

Platform Involved: Android

Information Collected: Network type

Android Permissions Invoked: None

Link: [https://github.com/greenrobot/EventBus]

37. Third-Party SDK Name: GreenDAO

Developer Name: None (Open-source tool)

Purpose of Use: Android local database ORM framework

Platform Involved: Android

[nformation Collected: Network type

Android Permissions Invoked: None

Link: [https://github.com/greenrobot/greenDAO]

38. Third-Party SDK Name: iqiyi xCrash

Developer Name: Beijing iQiyi Technology Co., Ltd. (Open-source component

Purpose of Use: App crash and exception capture tool]

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/iqiyi/xCrash]

39. Third-Party SDK Name: PhotoView

Developer Name: None (Open-source tool)

Purpose of Use: Image display component

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/chrisbanes/PhotoView]

40. Third-Party SDK Name: XRecyclerView

Developer Name: None (Open-source tool)

Purpose of Use: List page rendering component

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/XRecyclerView/XRecyclerView]

41. Third-Party SDK Name: JetBrains Java Annotations

Developer Name: None (Open-source tool)

Purpose of Use: Code annotation tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/JetBrains/java-annotations]

42. Third-Party SDK Name: square wire

Developer Name: Square (Open-source tool)

Purpose of Use: Protocol buffer processing tool

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/square/wire]

43. Third-Party SDK Name: NineOldAndroids

Developer Name: None (Open-source tool)

Purpose of Use: Android version compatibility animation library

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Official Website Link: [https://github.com/JakeWharton/NineOldAndroids]

44. Third-Party SDK Name: okio

Developer Name: None (Open-source tool)

Purpose of Use: IO data processing tool

Platform Involved: Android

Information Collected: Device identifiers (AndroidID, IMEI, MAC), device type, device model, IP address

Android Permissions Invoked: None

Link: [https://github.com/square/okio/]

45. Third-Party SDK Name: Facebook Fresco Animated Webp

Developer Name: Open-source tool

Purpose of Use: Animated Webp image loading component

Platform Involved: Android

Information Collected: None

Android Permissions Invoked: None

Link: [https://github.com/facebook/fresco]

46. Third-Party SDK Name: Facebook Fresco

Developer Name: Open-source tool

Purpose of Use: Image loading and caching component

Platform Involved: Android

Information Collected: SD card directory

Android Permissions Invoked: None

Link: [https://github.com/facebook/fresco]

Supplementary Notes on Permission Usage

1. Location Permission: Invoked only when you actively use functions like nearby hotels or car hailing positioning. No background continuous positioning. You can disable this permission at any time in your phone's system settings.

2. Camera/Photo Gallery Permission: Used only for real-name authentication, invoice upload, customer service image upload, and QR code scanning. The permission is not enabled by default. Refusing authorization does not affect the basic booking services of the Platform.

3. Storage Permission: Used only for file download, document upload, etc. Invoked as needed.

4. Network Permission: A basic necessary permission for the Platform to access the internet. Cannot be disabled.

5. This Platform provides only tangible business travel services such as flights and hotels. It does not sell virtual goods, memberships/subscriptions, or digital content.