VESMOND
生效日期:2026-07-22EFFECTIVE 2026-07-22

隐私政策Privacy Policy

1. 我们收集的信息1. Information we collect

注册与登录所需的邮箱地址;你的订阅档位与已选公司;产品使用与阅读状态(用于呈现「自上次阅读以来的变化」);你在 Ultra 请求与留言中提交的内容;通过 Stripe 处理的订阅与付款状态;以及用于服务运营核对的汇总页面路由模板、来源类别、国家或地区、账户档位与明显机器人标记。服务器端汇总记录不包含完整网址、查询字符串、邮箱或支付标识;未知页面路径统一记为通用类别。Vesmond 不存储银行卡号。We process the email address needed for registration and sign-in; your subscription tier and selected company; product use and reading state; content you submit through Ultra requests and messages; subscription and payment status processed by Stripe; and aggregate page-route template, source category, country or region, account tier, and obvious-bot markers used for operational reconciliation. Server-side aggregate records do not contain full URLs, query strings, email addresses, or payment identifiers; unknown paths are recorded as one generic category. Vesmond does not store card numbers.

2. 我们如何使用信息2. How we use it

用于账户认证(邮箱验证码登录)、订阅与权限管理、发送必要的交易类邮件(验证码、Stripe 收据)、维护阅读状态、保障服务可靠性与第一方服务器端汇总运营统计,以及在你允许时进行可选浏览器衡量与 Google Ads 归因。我们不会出售你的个人信息。We use this information for account authentication, subscription and access management, necessary transactional messages, reading state, service reliability and first-party server-side aggregate operations, plus optional browser measurement and Google Ads attribution when you allow it. We do not sell your personal information.

3. 服务器端汇总、可选衡量与广告归因3. Server aggregates, optional measurement & advertising attribution

Vesmond 会为所有访客记录范围受限的第一方服务器端汇总页面路由模板计数,以及不含客户值的验证码请求、注册与登录运营计数。这些记录不会触发浏览器向第三方发送请求,也不包含邮箱、用户 ID、完整网址、Google 点击 ID 或支付标识。For all visitors, Vesmond records bounded first-party server-side aggregate page-route-template counts and operational counts for one-time-code requests, registrations, and sign-ins without customer values. These records trigger no browser request to a third party and contain no email address, user ID, full URL, Google click ID, or payment identifier.

只有在你主动选择「允许可选衡量」后,浏览器才会加载 Google Ads 标签和适用页面上的 Cloudflare Web Analytics。未选择或选择「关闭可选衡量」时,不会向 Google 或 Cloudflare 发出新的可选浏览器衡量请求。Only after you actively choose “Allow optional measurement” does the browser load the Google Ads tag and, on applicable pages, Cloudflare Web Analytics. With no choice or “Optional measurement off,” the browser does not initiate new optional measurement requests to Google or Cloudflare.

发送给 Google 的页面位置只允许包含页面来源与路径,以及以下八个广告归因参数:utm_sourceutm_mediumutm_campaignutm_contentutm_termgclidgbraidwbraid。付款返回参数、优惠码、嵌套跳转地址及其他查询参数会被排除;Google 点击 ID 不写入 Vesmond 的数据库。Page location sent to Google is limited to the page origin and path plus eight advertising-attribution parameters: utm_source, utm_medium, utm_campaign, utm_content, utm_term, gclid, gbraid, and wbraid. Payment-return parameters, promotion codes, nested destinations, and other query parameters are excluded; Google click IDs are not written to Vesmond's database.

在你允许衡量时,为了在 3D Secure 跳转后保留广告归因,上述经清理且受长度限制的参数也可能作为 Vesmond 同源付款返回地址的一部分发送给 Stripe。未允许衡量时,发送给 Stripe 的返回地址不包含这些广告归因参数。When you allow measurement, the sanitized and length-limited parameters above may also be included in Vesmond's same-origin payment return address sent to Stripe so attribution can survive a 3D Secure redirect. Without measurement permission, the return address sent to Stripe contains none of these advertising-attribution parameters.

服务器可将首次来源类别、媒介类别、Google 数字广告系列 ID(其他广告系列名称统一记为通用类别)、外部引荐域名与记录日期保存于最长 30 天的第一方 HttpOnly vs_ft Cookie;该 Cookie 采用首次写入,且只接受固定字段与受限格式。在一次成功注册或登录时,账户中仍为空的首触字段可从该 Cookie 写入;已写入字段不会被后续登录覆盖。Google 点击 ID 始终不会写入 Vesmond 的数据库;如需删除已关联的首触记录,可按第 6 节联系我们。The server may save first-source category, medium category, a numeric Google campaign ID (other campaign names are reduced to a generic category), external-referrer hostname, and capture date in a first-party HttpOnly vs_ft cookie for up to 30 days. The cookie is first-write-wins and accepts only fixed fields in restricted formats. On a successful registration or sign-in, account first-touch fields that are still empty may be filled from the cookie; populated fields are not overwritten by later sign-ins. Google click IDs are never written to Vesmond's database; contact us under section 6 to request deletion of linked first-touch records.

在你允许衡量时,新账户注册与开始结账可作为仅计数的 Google Ads 次要转化发送。确认一次真实的付费购买后,浏览器会尝试发送一条计数型购买转化。Vesmond 明确加入该购买事件的字段只有公开的转化目标与一个随机生成的 UUID transaction_id;该 UUID 不从 Stripe 或客户信息派生。我们不会向 Google 明确加入实际付款金额、币种、Stripe 付款标识、银行卡信息、邮箱、套餐或 client secret。When you allow measurement, a new account sign-up and the start of checkout may be sent as count-only secondary Google Ads conversions. After a genuine paid purchase is confirmed, the browser attempts to send one count purchase conversion. The only fields Vesmond explicitly adds to that purchase event are the public conversion destination and a randomly generated UUID transaction_id; the UUID is not derived from Stripe or customer information. Vesmond does not explicitly add the actual payment amount, currency, a Stripe payment identifier, card information, email address, plan, or client secret to Google.

为了让普通付款与 3D Secure 返回路径在同一浏览器与设备上尽量使用同一个去重值,已允许衡量的设备会保存条目数量受限的 Stripe PaymentIntent 标识与随机 UUID 本机映射。映射条目可使用的时间最长为 30 天,过期条目会在下一次已同意衡量的访问中删除;若设备不再访问,浏览器可能保留不会再使用的过期字节,直至撤回衡量或浏览器自行清理。PaymentIntent 标识只作为本机查找键,绝不会发送给 Google、D1 或衡量遥测。清除浏览器存储或改用其他浏览器/设备可能产生另一个 UUID,因此这是同设备、同浏览器范围的尽力去重,而不是跨设备的绝对一次保证。To make ordinary payment and a 3D Secure return reuse the same deduplication value where possible on the same browser and device, a consented device stores a bounded local mapping from the Stripe PaymentIntent identifier to a random UUID. Entries are usable for no more than 30 days and expired entries are removed on the next consented visit; if the device never returns, the browser may retain unread stale bytes until revocation or browser cleanup. The PaymentIntent identifier is only a device-local lookup key and is never sent to Google, D1, or measurement telemetry. Clearing browser storage or using another browser or device can produce another UUID, so this is best-effort same-device, same-browser deduplication rather than an absolute cross-device exactly-once guarantee.

独立于这些可选浏览器衡量,Vesmond 可记录范围受限、非个人身份信息的服务器端计费生命周期与首次付费启用事件,以可靠地提供订阅、权限及运营核对。这些必要记录不向 Google 发送支付服务商标识、付款金额或客户信息。Independently of optional browser measurement, Vesmond may record bounded, non-personally-identifying server-side billing lifecycle and first-paid-activation events to provide subscriptions and access reliably and to reconcile operations. These essential records do not send payment-provider identifiers, payment amounts, or customer information to Google.

4. 衡量偏好与撤回4. Measurement preference & revocation

你的选择通过一个有效期最长 180 天的第一方 HttpOnlySameSite=Lax 偏好 Cookie 保存。你可以使用每页页脚的「隐私设置」随时关闭可选衡量。撤回时,本页会先设置一个不含身份信息、服务器可见的待撤回安全 Cookie,并通知同源的其他已打开标签页阻止新的 Vesmond 可选回调与 Google 衡量;随后阻止待发送事件、向已加载的 Google 标签发出拒绝更新,并清除内存及本机保存的支付去重映射与页面可访问的已知 _gcl_* Cookie。已经加载的第三方脚本正在进行的请求可能在重新加载前完成。服务器保存撤回后会删除待撤回 Cookie 并重新加载页面;若保存暂时失败,待撤回 Cookie 会阻止后续请求重新启用可选衡量。第一方服务器端汇总页面计数、运营计数与 vs_ft 不受可选浏览器衡量偏好控制;如需删除已关联的首触记录,可按第 6 节联系我们。Your choice is stored for up to 180 days in a first-party HttpOnly, SameSite=Lax preference cookie. You can turn optional measurement off at any time through “Privacy settings” in every page footer. On revocation, the page first sets a non-identifying, server-visible pending-revocation safety cookie and tells other open same-origin tabs to block new Vesmond optional callbacks and Google measurement. It then blocks pending events, sends a denied-consent update to any loaded Google tag, and clears both in-memory and locally stored payment-deduplication state plus known page-accessible _gcl_* cookies. An in-flight request from an already loaded third-party script may complete before the reload. After the server saves the revocation, it deletes the pending-revocation cookie and reloads the page. If saving temporarily fails, the pending cookie prevents later requests from re-enabling optional measurement. First-party server-side aggregate page counts, operational counts, and vs_ft are not controlled by the optional browser-measurement preference; contact us under section 6 to request deletion of linked first-touch records.

5. 第三方服务商5. Third-party processors

Stripe(支付处理)、Resend(交易类邮件发送)、Cloudflare(网站托管、基础设施与经同意的 Web Analytics)以及 Google(经同意的 Google Ads 衡量与归因)。这些服务商在提供各自服务所需范围内处理信息。Our providers include Stripe for payments, Resend for transactional email, Cloudflare for hosting, infrastructure and consented Web Analytics, and Google for consented Google Ads measurement and attribution. They process information as needed to provide their respective services.

6. 数据保留、请求与联系6. Retention, requests & contact

我们在账户存续期间保留账户与阅读数据。你可以联系 support@vesmond.com 请求访问、更正或删除你的个人数据,或询问本政策与衡量设置。We retain account and reading data while the account remains active. Contact support@vesmond.com to request access, correction or deletion of personal data, or to ask about this policy and measurement settings.