iMaster 投资大师
Home

Privacy Policy

Effective: August 25, 2026Last updated: August 25, 2026

This Policy is intended to describe our actual data practices in plain language and provide privacy disclosures and request methods for residents of California and other U.S. states.

If the English and Chinese versions conflict, the English version controls except where applicable law requires otherwise.

1

Scope and responsible company

Lansum International Corp. (“Lansum,” “we,” “us,” or “our”) operates iMaster (投资大师), a web-based personal investment intelligence service. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit imaster.lansum.com, create or use an iMaster account, connect an investment account, install the progressive web app, subscribe to notifications, or contact us.

This Policy applies to iMaster. A linked brokerage, brokerage connectivity provider, identity provider, market-data provider, AI provider, or other third party may process information under its own privacy notice. Lansum products outside iMaster may also have separate notices.

2

Personal information we collect

The categories below describe personal information we may have collected during the preceding 12 months. Whether a category applies to you depends on the features you use.

  • Identifiers and profile information: account identifier, name, email address, profile image, preferred language, and authentication-related identifiers received from Lansum Auth. iMaster does not receive your Lansum Auth password or passkey.
  • Financial and investment information: the name and type of a connected institution or account; masked account number; account balance, buying power, holdings, positions, orders, transactions, deposits, withdrawals, dividends, fees, and related synchronization status. Brokerage credentials are entered in a provider-controlled authorization flow when available. Provider tokens and user secrets handled by iMaster are kept server-side and encrypted at rest.
  • Preferences and user-provided content: watchlists, manual account or transaction records, investment goals, time horizon, liquidity needs, risk tolerance, investment experience, product-risk preferences, base currency, notification settings, feedback, and support communications.
  • Internet, device, and usage information: IP address and request metadata ordinarily processed by hosting and security systems; browser or device type; session and security events; pages or features used; PWA installation, offline, update, and platform events; and diagnostic or error information.
  • Notification information: push-subscription endpoint and cryptographic delivery keys processed by Lansum Message or the applicable push provider, notification preferences, delivery status, and related audit events.
  • Derived information and inferences: portfolio totals, performance, allocation, concentration, exposure, risk scores, research signals, watch items, and other analytics derived from information you provide or authorize us to receive.
  • Public and licensed market information: prices, security identifiers, company filings, news, research signals, and market events. This information generally is not personal information unless associated with your account, holdings, or activity.

We do not intentionally collect Social Security numbers, government identification numbers, biometric identifiers, precise geolocation, medical information, or the contents of consumer communications other than messages you choose to send us. Please do not submit those items through ordinary support channels.

3

Sources of personal information

  • Directly from you, including preferences, watchlists, feedback, manual records, and information included in a privacy or support request.
  • From Lansum Auth and Lansum Message when they provide identity, account, session, or notification services.
  • From brokerage connectivity providers and financial institutions you expressly authorize, including SnapTrade, Plaid, Webull, and supported institutions.
  • Automatically from your browser, device, network request, session, service worker, and security interactions with iMaster.
  • From public sources and licensed market, news, filings, research, and data providers.
  • From service providers assisting with hosting, databases, security, support, communications, and AI processing.
4

Why we collect and use information

  • Authenticate users, maintain sessions, prevent account confusion, and secure access.
  • Register and manage user-authorized brokerage connections and synchronize accounts, balances, holdings, orders, and transaction history.
  • Provide portfolio views, performance calculations, research, market briefings, risk analytics, alerts, watchlists, and user-requested AI-assisted explanations.
  • Operate the PWA, deliver requested notifications, remember necessary settings, and maintain service continuity.
  • Respond to support and privacy requests, communicate material service or policy changes, and administer the relationship.
  • Detect fraud, abuse, security incidents, disabled connections, and technical failures; debug and improve reliability.
  • Comply with law, enforce our terms, establish or defend legal claims, and protect users, Lansum, and others.
  • Perform internal measurement and product improvement using information reasonably necessary and proportionate to those purposes.
5

Disclosures for business purposes

During the preceding 12 months, we may have disclosed the categories described above for business purposes to the following categories of recipients. We disclose only information reasonably necessary for the service or direction involved.

  • Identity and messaging providers, including Lansum Auth and Lansum Message, for authentication, profile synchronization, account communications, and notifications.
  • Brokerage connectivity providers and financial institutions, including SnapTrade, Plaid, Webull, and a brokerage selected by you, to create, maintain, refresh, reconnect, or delete an authorized connection.
  • Cloud, database, security, and operational providers that host or protect the service, store encrypted data, deliver content, or help diagnose failures.
  • AI and research-processing providers when a feature requires them to summarize or analyze the information submitted for that request. Inputs may include a security symbol, market data, news, or relevant holdings context. We do not authorize those providers to use iMaster personal information for their own advertising.
  • Market, news, research, and data providers as necessary to request licensed information and operate their integrations.
  • Professional advisers and authorities when reasonably necessary for legal, accounting, security, compliance, or claims purposes, or when disclosure is required by valid legal process.
  • Transaction counterparties in connection with a proposed or completed financing, merger, acquisition, reorganization, or transfer of assets, subject to appropriate confidentiality and legal requirements.
  • Recipients you direct, authorize, or intentionally interact with.
6

No sale, cross-context behavioral advertising, or financial incentive

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we have not done so during the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.

iMaster does not currently use third-party advertising cookies or offer a financial incentive or price difference in exchange for retaining, selling, or sharing personal information. If these practices change, we will provide the notices and choices required by applicable law before the change applies.

7

Sensitive personal information

Financial account information and credentials used to permit account access may be treated as sensitive personal information under California law. We use and disclose this information only as reasonably necessary to provide requested account connectivity, maintain security, prevent fraud, perform services on our behalf, and satisfy legal obligations. We do not use sensitive personal information to infer characteristics about you for advertising or unrelated purposes.

Because our current use is limited to legally permitted operational purposes, iMaster does not presently offer a separate “Limit the Use of My Sensitive Personal Information” link. You may still submit a privacy request using the methods below.

8

Cookies, tracking signals, and third-party collection

iMaster uses necessary cookies and similar browser storage for authentication, security, OAuth state, service-worker operation, offline support, and essential preferences. See the Cookie Policy for details.

We do not currently allow advertising parties to collect personal information about your activities over time and across unaffiliated websites through iMaster. Because “Do Not Track” is not a uniform standard, the service does not respond to ordinary DNT signals. We treat legally recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out where applicable; because iMaster does not sell or share information for cross-context behavioral advertising, the signal does not change our current practices.

9

Data retention

We retain each category only as long as reasonably necessary and proportionate for the purpose collected. The period varies based on the following criteria:

  • Account and profile data: while your account is active and for a limited period afterward needed to complete deletion, secure backups, resolve disputes, prevent fraud, or satisfy law.
  • Broker connection credentials: while the connection remains authorized and until deletion, revocation, replacement, or expiration can be processed, subject to provider and legal requirements.
  • Holdings, transactions, snapshots, and calculated performance: while needed to provide historical continuity and the features you request. Disconnecting a brokerage connection stops future synchronization but may not automatically erase historical records; you may request deletion, subject to applicable exceptions.
  • Preferences, research, watchlists, and notification records: while the related feature or account remains active and for a reasonable operational or audit period.
  • Security, request, and diagnostic logs: for the period reasonably needed to protect the service, investigate incidents, enforce rate limits, and meet legal or audit obligations.
  • Support and privacy requests: for as long as needed to respond, document compliance, and establish or defend legal claims.

When retention is no longer justified, we delete, de-identify, or securely dispose of the information in accordance with operational and backup processes.

10

California and U.S. state privacy rights

Subject to applicable law and exceptions, California residents may request:

  • Know and access: categories, sources, purposes, recipient categories, and specific pieces of personal information we maintain.
  • Delete personal information, subject to security, legal, transaction-completion, and other statutory exceptions.
  • Correct inaccurate personal information.
  • Opt out of sale or sharing for cross-context behavioral advertising. We do not currently engage in either practice.
  • Limit certain uses or disclosures of sensitive personal information where the right applies. Our current uses are limited to operational purposes described above.
  • Data portability in a readily usable format where required and technically feasible.
  • Non-discrimination: we will not unlawfully discriminate against you for exercising a privacy right.

Residents of other U.S. states may have comparable rights, including rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale, or certain profiling, and appeal a denied request. We will honor rights to the extent required by the law applicable to you.

11

How to exercise privacy rights

You may submit a request through the Lansum contact form, by email to security@lansum.com, by calling +1 (626) 818-0858, or by writing to: Lansum International Corp., Attn: iMaster Privacy, 1351 Doubleday Ave, Ontario, CA 91761, USA.

State that your request concerns “iMaster Privacy” and identify the right you wish to exercise. Do not send a password, access token, full account number, government ID, or other sensitive credential in an ordinary message.

Verification and timing

We may verify a request using information already associated with your account and may require you to authenticate to iMaster. We use verification information only for verification, security, fraud prevention, and compliance. Where California law applies, we generally confirm receipt within 10 business days and respond within 45 calendar days. We may extend the response once by up to 45 additional days when reasonably necessary and will explain the extension.

Authorized agents and appeals

An authorized agent may submit a request where permitted by law. We may require proof of authorization and direct identity verification unless the agent holds a valid power of attorney. If we deny a request, you may appeal by replying through the same channel with “Privacy Appeal” and an explanation. You may also contact the privacy regulator or attorney general in your state.

12

Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we process. Measures include access controls, server-side secret isolation, encryption of supported provider tokens at rest, encrypted network transport, authorization checks, webhook verification, logging, and data minimization. No transmission or storage method is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your device and Lansum Auth account and for signing out on shared devices. Notify us promptly if you believe your account or connected data has been accessed without authorization.

13

Children

iMaster is a financial information service intended for adults and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn that we have done so without legally sufficient parental authorization, we will take reasonable steps to delete the information. The service is not intended for anyone under 18 to connect or manage a brokerage account.

A parent or guardian who believes a child provided personal information may contact us using the methods above.

14

Processing in the United States

iMaster is operated from the United States. Information may be processed in the United States and other locations where our service providers operate. Privacy and government-access laws in those locations may differ from those in your residence. Where required, we use appropriate contractual or other safeguards for cross-border transfers.

15

Changes and contact

We may update this Policy to reflect product, legal, security, or provider changes. We will post the revised Policy with a new “Last updated” date. Lansum Auth ordinarily presents a one-time notice for a new disclosure version. If a change introduces processing that legally depends on consent or otherwise requires affirmative agreement, Auth will request explicit acceptance before iMaster issues or renews application access. Prior versions may be requested through our contact channel.

Questions, accessibility requests, or requests for this Policy in an alternative format may be directed to security@lansum.com, our contact form, or the postal address in Section 10.