Roles of the parties: US3C determines the purposes and means of the iMCheck service, its transactions and the principal processing of personal data, and is responsible for generating, sending and verifying OTPs. SEADRCH provides the iMCheck App, the Notebook Detector laptop inspection software, the underlying systems and data transmission, and processes the necessary data on US3C's lawful instructions. SEADRCH does not participate in or determine final device valuations, purchases, payment, logistics, returns or physical custody. The App is published under a SEADRCH developer account, which does not make SEADRCH a party to those transactions.
1. Scope
This Policy applies to the iMCheck App, the Notebook Detector laptop inspection software, related websites and device inspection interfaces, and the appraisal, recycling and related services provided or arranged by US3C. This page may be hosted on a website managed by SEADRCH as a fixed version agreed by both parties; the hosting location does not alter the actual roles and responsibilities of US3C and SEADRCH.
2. Purposes of Collection
Data is processed only to the extent necessary for the following purposes:
- Mobile number verification, sending OTPs and receiving verification results;
- Device identification, functional and hardware inspection of phones and laptops, and the creation and retrieval of inspection reports;
- Appraisal, re-inspection, purchase, payment, logistics, customer service and dispute handling, for which US3C is responsible;
- Enterprise account, permission and security management for authorized US3C employees;
- System operations, troubleshooting, fraud prevention, information security, auditing and legal compliance;
- Statistics and service improvement based on data that has been lawfully de-identified and cannot reasonably identify an individual.
3. Data Categories and Scope of Each Role
| Category | Content | Processing role and limits |
|---|---|---|
| General user verification data | Mobile number, the OTP entered by the user, and the success or failure of verification | SEADRCH transmits the data to US3C and receives the result; US3C generates, sends and verifies the OTP. SEADRCH does not require a name or email address from general users. |
| US3C employee accounts | System account, company email, account identifier, permissions and necessary operation records | SEADRCH does not collect employee names. |
| Device and inspection data | Brand, model, serial number, IMEI (where applicable), operating system, capacity, battery, processor, memory, storage, components, functional test results and inspection reports of a phone or laptop | Processed according to the inspection items enabled by the user in iMCheck or Notebook Detector and the data actually transmitted by the system. While device data is linked to a mobile number, it may become identifiable data. |
| System and security logs | IP address, timestamp, App version, device identifier, API, error and security events, and the version of terms accepted | Processed only as necessary for operations, security, auditing and evidentiary purposes. Complete OTPs must not be written to general logs. |
| Transaction, payment, identity and logistics data | Order, payment, identity or logistics data separately requested by US3C during the transaction process | Notified and handled separately by US3C under its own responsibility. It is not provided to SEADRCH except under a separate written agreement and lawful notice. |
4. OTP Verification Flow
- The user enters a mobile number in iMCheck.
- iMCheck transmits the mobile number to US3C.
- US3C generates and sends an OTP to the user.
- The user enters the OTP in iMCheck, which transmits it to US3C.
- After verification, US3C returns a success or failure result to iMCheck.
SEADRCH does not determine the content of the OTP, does not send the SMS, and does not independently judge whether an OTP is valid.
5. Retention and Deletion
| Data | SEADRCH retention period |
|---|---|
| Mobile number | Processed only for as long as necessary to complete mobile verification, identify inspection reports and provide the retrieval service. Once the purpose of processing ceases, verification times out, the process is terminated or the service ends, it is deleted, processing stops, or it is processed so that it cannot reasonably be restored. |
| Mobile numbers verified but with no report generated | Deleted once the purpose of verification ceases, verification times out or the process is terminated. |
| OTP | Used only for that single verification and deleted once verification completes, fails, times out or the process is terminated. It is not otherwise retained or used. |
| Verification result | For the validity period of the inspection report, only the success or failure status necessary to provide the service is retained. The content of the OTP is not retained. |
| US3C employee accounts | For the term of the account and, after deactivation, for the period necessary for security, auditing or dispute handling. |
| Inspection reports and other technical records | Retained as required by the actual service, contracts, information security and legal requirements. Their retention period is assessed separately from the purpose of processing the mobile number. On expiry they are deleted, processing stops, or they are de-identified in accordance with law. |
Where retention is genuinely necessary because of law, an order of a competent authority, an information security incident that has occurred, or a specific dispute, the relevant data may be retained with restricted access for the necessary scope and period, and handled in accordance with law once the cause ceases. The retention period applied by US3C after it receives data directly is governed by US3C's own practices and notices.
6. Regions, Recipients and Methods of Use
Regions
In principle in Taiwan, and in the countries or regions where US3C, SEADRCH or their service providers actually deploy, maintain redundancy for, or support the systems. Where cross-border transfer is involved, appropriate safeguards and disclosures will be applied in accordance with law.
Recipients
US3C, SEADRCH acting on its instructions, authorized personnel, and the cloud, SMS/OTP, app store, push notification, crash analytics, payment, logistics and customer service providers necessary to fulfil the purposes, as well as authorities empowered by law. Each recipient receives data only to the extent necessary.
Methods
Entry, transmission, verification, storage, retrieval, linking, report generation, debugging, security management and lawful deletion, by automated or non-automated means. Mobile numbers and OTPs must not be used for marketing, advertising, or any user analysis unrelated to verification and report services.
7. App Permissions and Device Inspection
Permissions such as camera, microphone, Bluetooth, local network, nearby devices and location are requested only where the corresponding inspection, pairing, QR code or store locator feature requires them. A permission being invoked does not mean data is necessarily uploaded or retained long term; actual processing is governed by the feature screens, system behaviour and this Policy. Where a Face ID or fingerprint test only invokes an operating system API, iMCheck does not collect or retain facial templates, fingerprint images or raw biometric data.
8. Data Security and Incident Handling
Within their respective areas of control, US3C and SEADRCH apply reasonable measures including transport encryption, access control, least privilege, log masking, vulnerability management, backup protection and incident response. If an incident occurs that may affect personal data, SEADRCH will notify US3C under the tripartite agreement and provide the necessary technical assistance; US3C is responsible for external notifications and reports to the competent authority as required by law, except where the law requires SEADRCH to perform them directly.
9. Data Subject Rights
Subject to applicable law, you may request to inquire about or review your personal data, obtain a copy, supplement or correct it, or request that collection, processing or use cease, or that it be deleted. Requests concerning general personal data and transactions should be directed to US3C; SEADRCH will provide technical assistance within the scope of the systems it processes, on US3C's lawful instructions. Where required by law, or necessary for contract performance, preservation of rights, information security or a specific dispute, handling may be restricted or deferred in accordance with law, with reasons given.
10. Minors
Where a minor uses services involving transactions or identity data, a legal representative must consent or assist in accordance with law. If it comes to our attention that data of a minor was obtained without a lawful basis, appropriate measures will be taken to restrict or cease processing, or to delete the data.
11. Versions and Amendments
This Policy is published with a fixed version number and effective date, and prior versions are reasonably archived. Material changes to the purposes of collection, data categories, period of use, recipients, regions or rights will be notified before they take effect via the App, the website or other reasonable means; where separate consent is required by law, it will be obtained separately. No document may expand SEADRCH's data processing or transactional responsibilities without SEADRCH's written consent.
12. Contact
US3C Technology Co., Ltd. (US3C)
- Service line
- +886 906-888-337
- Official LINE
- @us3c
- imcheck.3d@gmail.com
- Website
- www.imcheck.com.tw
- Address
- 7F-1, No. 153, Sec. 3, Xinyi Rd., Da'an Dist., Taipei City, Taiwan
Seadrch Technology Co., Ltd. (SEADRCH)
- Service line
- +886 970-062-212
- service@seadrch.com
- Website
- www.seadrch.com
- Address
- 2F, No. 142, Dongnan Rd., Dali Dist., Taichung City, Taiwan
Please direct questions about appraisal, purchase, payment, logistics, returns, transactions or personal data rights to US3C in the first instance. Questions about App technology, or information security matters within SEADRCH's area of control, may be directed to SEADRCH.
