隐私政策
Privacy Policy
更新日期:2026 年 9 月 9 日。适用于 BEGODE iOS 1.0.8(构建 12);不替代 Android 或 Extreme Wheel 的政策。
1. 运营者与联系方式
BEGODE iOS 由东莞市比高德智能科技有限公司(Dongguan Begode Intelligent Technology Co., Ltd.)提供。有关个人信息、访问、更正或删除的请求,请联系 bgd002@begode.com。官网:www.begode.com。
本政策说明原生 App、配套社区服务及 App 内嵌商城网站的不同处理方式。仅在手机本地处理的数据,与用户主动发布或共享后发送到服务器的数据,不应混为一谈。无需登录或联网即可通过“我的”或登录/注册页面中的“隐私政策”阅读随安装包提供的政策。
2. 账号、内容与服务数据
- 账号与资料:注册、登录、验证码和找回密码涉及邮箱或手机号、密码和验证码、会员 ID、登录令牌及昵称。资料功能还允许填写头像、简介、性别、生日和地区文字,并保存联系方式或位置的展示选择。账号信息用于身份验证、资料展示、账号管理和安全控制。
- 粉圈与社区:主动提交的帖子、图片、视频及其声音、分类、评论、点赞、关注、屏蔽和举报记录,会与账号和时间关联,用于内容展示、互动、管理及防止滥用。头像和公开帖子不是仅本人可见;其他用户可能查看或保存已公开的内容。
- 群组与私信:群名称、简介、头像、地区、成员及角色、加入申请、活动和报名、聊天正文、发送者、会话及时间会由服务保存。群消息及活动按成员权限开放;私有群的基本介绍仍可能出现在发现页面。私信按参与者权限访问,但不提供端到端加密的承诺。
- 排行榜:服务按已有会员骑行记录汇总各周期里程,展示昵称、头像、账号标识、名次及里程。排行榜本身不展示路线坐标;当前没有单独的退出排行榜开关。
- 客服和订单查询:会话标识、消息、语言、工单、用户提供的查询邮箱以及相关账号信息,用于自动回复、查询和人工支持。自动客服可能把消息及对话上下文交由配置的模型服务处理;转人工时相关内容可能进入飞书/Lark 客服系统。请勿在会话中提供与支持事项无关的密码、完整支付资料或他人的敏感信息。
- 运行与安全:服务器处理连接 IP、请求和响应状态、时间、客户端信息及相关会话记录,用于提供服务、故障排查和防止滥用。关闭开发调试输出不代表服务器不会保留运行日志。
3. 位置、路书和车辆数据共享
位置和路线可能暴露你的活动地点或行程。发布路书与实时位置共享均应在了解展示范围后自行开启。当前路书预览不保证默认隐藏住址附近或起终点,请在提交前检查路线;不愿公开时不要发布该路线。
本地骑行和路书
蓝牙车辆状态、手机 GPS 和运动传感器可用于仪表、骑行记录、速度、距离、姿态和方位显示。原始骑行文件可以保存在本机。选择发布路书后,确认提交的路线点、时间、里程、文字、摘要和所选曲线会发送到社区服务器并关联作者保存,向具备访问资格的已登录社区用户展示;这不是仅本人可见的私有云备份。
附近与实时共享
开启附近功能后,App 可发送取整后的大致位置及账号、更新时间。旧附近记录可能保存最近的大致位置。主动开启实时共享后,App 会发送所选车辆指标(例如速度、电压、电流、温度、PWM)、大致位置及更新时间;只有另外明确开启精细 GPS 共享并授予相应权限时,才发送较精细的坐标、精度和定位时间。当前精细共享位置采用短时服务器缓存,过期后不再作为有效实时位置提供;这与已经发布并持久保存的路书轨迹不同。
在线/共享的新鲜度期限用于控制是否继续显示,并不等同所有历史记录和备份立即物理删除。关闭附近开关不会自动删除以往保存的附近记录。收起地图卡片或关闭详情只改变本机显示,不等于停止共享。
后台、断网与停止
普通在线状态主要在前台更新。用户主动开启的实时共享可在切换 App 或锁屏后继续使用后台定位和蓝牙;暂时断网后会重试,不将积压旧定位冒充新的实时位置。用户停止、真实车辆断连或换车、退出或切换账号、撤回相关定位权限会结束共享。iOS 调度、强制退出、系统终止或关机会中断运行,不能保证持续后台运行;重开 App 不会静默恢复精细共享。
停止共享会停止本机后续发送,但在网络不可用时,服务器停止请求可能无法立即送达,接收端会按新鲜度隐藏过期数据。已经展示或由其他用户保存的信息不会因此自动收回。
4. 手机权限与本地存储
- 蓝牙用于连接车辆和读取状态、发送用户发起的车辆控制;定位用于 GPS 仪表、骑行记录及已开启的位置功能;运动传感器用于姿态和方位显示。
- 相机、麦克风及录屏用于用户主动开启的骑行背景和视频录制;保存到相册需要系统授权。选择头像和发帖媒体使用系统媒体选择器。
- 本地黑匣子、固件日志、录像不因生成就自动成为公开帖子;主动选择上传、路书发布、实时共享或系统分享时,相应数据才会交给所选功能或接收方。
- 语言、主题、单位、车辆备注、登录状态、骑行文件和媒体缓存可存于 App 的设备存储。内嵌商城使用独立的非持久化内存网页存储,Cookie、网站登录状态和缓存可在当前网页会话中使用,不复用旧版持久网页存储。切换标签或退出原生 App 账号不一定结束网页会话,也不自动退出商城账号。网页及其存储释放或 App 进程结束后,这份内存网页状态不作为下次会话的持久状态保留;这不表示旧版持久网页文件已经删除。退出账号或删除账号不等同自动擦除全部本地骑行文件、相册视频或其他应用保存的分享副本。
- 可在 iOS 设置中撤回系统权限。撤回会影响依赖该权限的功能,但不会自动收回之前已上传或公开的数据。本 App 不读取手机通讯录,也不把车辆遥测作为 HealthKit 医疗数据处理。
5. 内嵌商城与第三方服务
商城直接在 App 内显示固定的 BEGODE 网站(https://www.begode.com/),保持网页 JavaScript 启用,购物登录和网页 Cookie 使用前述隔离的内存存储。HTTP/HTTPS 链接和收银台也可能在 App 内显示;第三方托管不等同在 App 外输入资料。App 不向商城打开地址或网页存储注入原生账号、登录令牌、骑手标识或车辆数据。主题同步只修改网页 DOM 配色属性、CSS 及主题选择控件值,不通过主题参数或网页存储传递用户身份。网站脚本仍可读取外观属性并独立处理网站数据。
商城由 Shopify 等网页服务支持,独立处理网站账号、咨询、订单及购物流程。依所用功能,网站可处理姓名、邮箱、电话、账单或收货地址、购买记录、支付确认及支付流程信息,以及 IP、推导的大致地区、Cookie、浏览器信息、网页标识、商品交互、搜索和购物车活动。仅浏览首页不等于提交了全部这些资料。商城隐私政策(https://www.begode.com/policies/privacy-policy)另说明网站的分析、营销、广告定制、服务商和营销伙伴共享,请结合网站提供的选择阅读。原生 App 不集成广告 SDK、不读取广告标识符,也不向商城传递原生账号或骑行数据用于广告匹配;这不代表网站及其服务商的处理与原生功能相同。
App 在首个商城请求前安装已知广告、像素和分析资源的阻断规则;规则安装失败或超时则显示加载错误,不加载未应用规则的商城。规则针对已知客户端资源,不关闭所有网页脚本,也不等同关闭网站服务器间的转化或营销数据处理。非持久 Cookie、不注入原生账号和资源阻断不能单独证明网站数据未与用户关联,或所有服务器端广告用途均已停用。网站 Cookie 选择与 iOS 跟踪授权是不同机制,App 不替用户作出网站同意,也不把网站同意当作 iOS 跟踪授权。
接收方还包括 BEGODE API、文件和云基础设施、邮件投递服务,处理支持事项所需的人工客服/飞书及模型服务,Apple 地图和系统功能提供方,以及用户自行选择的系统分享接收方。用户账号、内容或共享位置在相关功能中发送至 BEGODE 服务;服务和供应商可能在包括香港在内的运营地区处理数据。涉及具体供应商、保存或权利请求,可通过本政策联系方式咨询。
6. 保存、删除与隐私选择
服务按账号、功能、安全、争议处理和法律义务保存所需记录。不同类型的数据有不同生命周期:实时共享的新鲜度缓存、持久账号/内容/聊天/路书记录、运营日志和备份不能视为相同的保存期限。
- 可编辑个人资料及相应公开选项;可停止位置共享、撤回系统权限、屏蔽或举报其他用户。
- 删除路书会将其移出社区正常展示和访问,但不代表所有后台原记录或备份立即物理擦除。退出或解散群不自动删除历史消息;当前群聊与私信不提供逐条删除入口。
- 可在 App 的账号登录/安全页面选择“删除账号”,阅读说明并确认。客户端将请求账号删除并清除本机登录状态;这不应理解为所有社区、客服、商城、第三方记录、备份或本地骑行文件同时永久消失。
- 无法登录或需要进一步处理账号、路线、帖子、媒体、消息、客服或其他记录时,可从注册邮箱向 bgd002@begode.com提出请求并说明范围。我们会根据必要身份核验、实际记录和适用义务处理;请勿通过公开帖子提交身份证件或密码。
- 原生 App 账号与商城网站账号的退出、删除和权利请求是不同的操作。商城账号、订单及其他网站资料可通过商城隐私政策中的联系方式和网站选项提出处理请求。关闭网页或释放本机网页数据,不撤回此前发送的信息,也不自动删除网站、支付方、履约方或其他服务商保存的记录。
- 内容已由其他用户保存、截图或通过其他服务分享的副本,不受本机停止或删除操作直接控制。订单/支付等记录还可能需要依相应服务及法定义务保存。
7. 安全、未成年人及更新
我们采用与功能相适应的访问控制、账号验证及传输/设备保护措施,但互联网传输和存储无法保证绝对安全。不要共享账号或密码;公开路线前请考虑同行者及他人的隐私。未成年人应在监护人指导下使用,并遵守适用年龄要求;若认为未成年人不当提供了个人信息,请联系我们。
功能或处理方式变化时,我们会更新本政策并标注日期;涉及新的权限或共享范围时,以 App 和系统当时提供的说明与选择为准。本政策不替代系统授权,也不构成对未经选择的数据共享的授权。
1. Operator and contact
BEGODE iOS is provided by Dongguan Begode Intelligent Technology Co., Ltd. Contact bgd002@begode.com for privacy, access, correction or deletion requests. Our website is www.begode.com. This policy distinguishes on-device processing, community services and the store website embedded in the app. Read the bundled policy without signing in or connecting to the Internet through “Privacy Policy” in Me or the sign-in/registration pages.
2. Accounts, content and support
Registration, sign-in and recovery process an email address or phone number, password, verification code, member ID, token and nickname. Optional profile information includes an avatar, biography, gender, birthday, region text and visibility settings. These support authentication, profile display, account administration and security.
Posts, photos, videos and their sound, comments, likes, follows, blocks and reports are associated with an account and time for community features and moderation. Public avatars and posts can be viewed or saved by others. Groups process profile information, membership/roles, requests, activities, registrations and messages. Basic descriptions of private groups may remain discoverable; membership controls access to member content. Direct messages retain participant IDs, conversations, text and times, with participant access controls; we do not claim end-to-end encryption.
Rankings aggregate existing member riding records and display account identifiers, nicknames, avatars, rank and distance, not route coordinates. There is currently no separate ranking opt-out switch.
Support processes session identifiers, messages, language, related account information, tickets and the email supplied for an order query. Automated support may process messages and conversation context through the configured model service. Human support may receive information through Feishu/Lark. Do not send unrelated secrets or sensitive third-party information. Service infrastructure can retain IP addresses, requests, status, times and session records for operation, troubleshooting and abuse prevention.
3. Location, ridebooks and wheel sharing
Locations and routes can reveal your whereabouts. Review visibility before enabling sharing or publishing a ridebook. Current route previews do not guarantee automatic masking of your home area or trip endpoints. Do not publish a route you do not want to disclose.
Wheel telemetry, GPS and motion sensors support instruments and local riding records. When you confirm publication of a ridebook, the selected route points, times, distances, text, summary and chart data are sent to the community service and retained with the author. Published ridebooks are accessible to eligible signed-in community users, not solely the author as a private cloud backup.
Nearby features can send rounded approximate coordinates and account/update information. Earlier nearby records may retain a last approximate location. A separately initiated live sharing session sends chosen wheel metrics, such as speed, voltage, current, temperature and PWM, plus approximate location and update times. More precise coordinates, accuracy and location timestamps are sent only after separately enabling precise GPS sharing and granting permission. Current precise live locations use short-lived server caching and are no longer supplied as valid live positions after expiry; published ridebook routes are persistent and different.
A freshness interval determines visibility, not instantaneous physical deletion of every record or backup. Disabling nearby discovery does not automatically erase earlier nearby records. Closing a map card changes local display only; it does not stop sharing.
Ordinary online presence primarily updates in the foreground. User-initiated live sharing may continue using background location and Bluetooth when the screen is locked or another app is active. Temporary network failures are retried without representing old queued locations as fresh. Manual stop, an actual wheel disconnection/change, logout/account change or withdrawal of relevant permission ends sharing. iOS scheduling, force-quit, process termination or shutdown can interrupt operation. Restarting does not silently resume precise sharing.
Stopping sharing stops further transmissions from this device. When connectivity is unavailable, the server may not immediately receive the stop request; recipients hide stale data based on freshness. Information already displayed or saved by others is not automatically recalled.
4. Permissions and local files
Bluetooth supports wheel connections and user-initiated controls. Location supports GPS instruments, ride recording and enabled location features; motion sensors support attitude and heading displays. Camera, microphone and screen recording support user-initiated riding video; saving to Photos needs system permission. Avatars and post media use the system picker.
Generating a local blackbox file, firmware log or recording does not itself publish it. Uploading, ridebook publication, live sharing and system sharing transmit the respective selected data. Settings, wheel aliases, sign-in state, riding files and media caches may be stored on the device. The embedded store uses an isolated, non-persistent in-memory website data store for cookies, website sign-in state and caches during the current web session, without reusing the older persistent store. Switching tabs or signing out of the native app does not necessarily end that session or sign out of the store account. When the web view and its data store are released, or the app process ends, this in-memory state is not retained as persistent state for a later session; this does not mean older persistent website files have been deleted. Logout/account deletion does not automatically erase every riding file, Photos video or copy held by another app.
Revoke permissions in iOS Settings. This limits dependent features but does not recall previously uploaded information. The app does not read the phone address book or process wheel telemetry as HealthKit medical information.
5. Embedded store and service providers
The store displays the fixed BEGODE website (https://www.begode.com/) directly inside the app with website JavaScript enabled. Store sign-in and website cookies use the isolated in-memory storage described above. HTTP/HTTPS links and checkout may also remain inside the app; third-party hosting does not mean data entry takes place outside the app. The app does not inject native accounts, sign-in tokens, rider identifiers or wheel data into the store URL or website storage. Theme synchronisation only changes DOM appearance attributes, CSS and the theme-selector value, without passing user identity through theme parameters or website storage. Website scripts can still read appearance attributes and independently process website data.
Shopify and other web services support separate store accounts, support, orders and shopping flows. Depending on the features used, the site can process names, email addresses, phone numbers, billing or delivery addresses, purchase records, payment confirmations and payment-flow information, as well as IP addresses, approximate regions derived from them, cookies, browser information, website identifiers, product interactions, searches and cart activity. Visiting the home page does not mean all of these details have been submitted. The store privacy policy (https://www.begode.com/policies/privacy-policy) separately describes website analytics, marketing, advertising personalisation, providers and marketing-partner sharing; read it alongside the choices provided on the site. The native app does not integrate advertising SDKs, read advertising identifiers or send native account/riding data to the store for advertising matching; this does not mean the site and its providers process data in the same way as native features.
Before the first store request, the app installs rules blocking known advertising, pixel and analytics resources. If installation fails or times out, it shows a loading error rather than loading an unprotected store. These rules target known client-side resources; they do not disable all website scripts or turn off server-to-server conversion or marketing data processing. Non-persistent cookies, not injecting native accounts and resource blocking do not by themselves establish that website data is unlinked to users or that all server-side advertising uses have stopped. Website cookie choices and iOS tracking authorisation are separate mechanisms. The app does not record website consent on a visitor's behalf or treat website consent as iOS tracking authorisation.
Recipients also include BEGODE API/media/cloud infrastructure, email-delivery services, support/Feishu and model services needed for a support interaction, Apple map/system providers and recipients you select through system sharing. Providers may process data in their operating regions, including Hong Kong. Contact us for provider-specific or data-rights questions.
6. Retention, deletion and choices
Records are retained according to account/service needs, security, disputes and legal obligations. Live-data freshness caches, persistent account/content/message/ridebook records, operational logs and backups have different lifecycles.
- Edit your profile and visibility options, stop sharing, revoke permissions, or block/report another user.
- Deleting a ridebook removes it from normal community display and access, but does not immediately physically erase every backend record or backup. Leaving/dissolving a group does not delete historical messages. Individual group/direct-message deletion is not currently offered.
- Use “Delete Account” on the account sign-in/security page and confirm after reading the notice. The app requests deletion and clears local sign-in state. This does not mean every community, support, store, third-party, backup or local riding record disappears simultaneously.
- If you cannot sign in or need further processing of accounts, routes, posts, media, messages or support records, email bgd002@begode.com from your registered address and identify the scope. Requests are handled using necessary identity checks, actual records and applicable obligations. Do not publish identity documents or passwords.
- Native app and store website accounts have separate sign-out, deletion and rights-request processes. Use the contact details in the store privacy policy and the website's available options to request handling of store accounts, orders or other website data. Closing the web view or releasing local website data does not recall previously transmitted information or automatically erase records retained by the store, payment, fulfilment or other providers.
- Copies saved or shared by others cannot be recalled by a local stop/delete action. Order/payment records may remain subject to provider and legal retention obligations.
7. Security, children and changes
We use service-appropriate access controls, authentication and transmission/device protections, but no Internet system is absolutely secure. Do not share passwords; consider companions' privacy before publishing routes. Minors should use the app with guardian guidance and applicable age requirements. Contact us about inappropriate provision of a minor's information.
We update this policy and its date when processing changes. Follow the app/system notices and choices for new permissions or sharing scopes. This policy does not replace system permission or authorise sharing you have not selected.