- Document version
- v1.1 (fixed-version URL, not overwritable)
- Effective date
- September 3, 2026
- Service operator & primary data subject entity
- 優勢科技股份有限公司
(Unified Business Number: 54706671, hereinafter “US3C”) - Commissioned technical processor / App publisher
- 希得趣科技股份有限公司
(Unified Business Number: 55121247, hereinafter “SEADRCH”)
Key role statement:
US3C determines the purposes and methods of processing the iMCheck service, transactions, and primary personal data, and is responsible for generating, sending, and verifying OTPs. SEADRCH provides the iMCheck App, the Notebook Detector laptop diagnostics software, system technology, and data transmission services, and processes necessary data only on US3C’s lawful instructions. SEADRCH does not take part in or determine a device’s final valuation, sale, payment, logistics, returns, or physical custody; the App is published under SEADRCH’s developer account, which does not make SEADRCH a counterparty to the transactions described above.
1. Scope
This policy applies to the iMCheck App, the Notebook Detector laptop diagnostics software, related websites, device diagnostics interfaces, and the valuation, recycling, and related services provided or arranged by US3C. This page may be hosted on behalf of both parties by a SEADRCH-managed website carrying the mutually confirmed fixed version; the hosting location does not change the actual roles and responsibilities of US3C and SEADRCH.
2. Purposes of Collection
Data is processed only within the following necessary scope:
- Phone number verification, OTP delivery, and receipt of verification results;
- Device identification, function and hardware diagnostics, and report creation and lookup for phones or laptops;
- Valuation, re-inspection, buyback, payment, logistics, customer service, and dispute handling conducted by US3C;
- Enterprise account, permission, and security management for authorized US3C employees;
- System operations, troubleshooting, fraud prevention, information security, auditing, and legal compliance;
- Statistics and service improvement based on data that has been lawfully de-identified and cannot reasonably identify an individual.
3. Data Categories & Roles
| Data category | Content | Processing role & limits |
|---|---|---|
| General user verification data | Phone number, the OTP entered by the user, and the verification success or failure result | SEADRCH transmits the data to US3C and receives the result; US3C generates, sends, and verifies the OTP. SEADRCH does not ask general users for a name or email. |
| US3C employee accounts | System account, company email, account identifier, permissions, and necessary operation logs | SEADRCH does not collect employee names. |
| Device & diagnostics data | For a phone or laptop: brand, model, serial number, IMEI (where applicable), operating system, capacity, battery, processor, memory, storage, components, function test results, and diagnostics report | Processed according to the diagnostics items enabled by the user in iMCheck or Notebook Detector and the actual scope transmitted by the system; while device data is linked to a phone number, it may become identifiable data. |
| System & security logs | IP, timestamps, App version, device identifiers, API, error and security events, and terms-consent version | Processed only within the scope necessary for operations, security, auditing, and evidence; full OTPs must not be recorded in general logs. |
| Transaction, payment, identity & logistics data | Order, payment, identity, or logistics data separately requested by US3C during the transaction flow | Separately noticed and handled by US3C in accordance with law; not provided to SEADRCH unless otherwise agreed in writing and lawfully noticed. |
4. OTP Verification Flow
- The user enters a phone number in iMCheck.
- iMCheck transmits the phone number to US3C.
- Upon receiving the phone number, US3C generates and sends an OTP to the user.
- The user enters the OTP in iMCheck, which then transmits the OTP to US3C.
- After verification, US3C returns a success or failure result to iMCheck.
※ SEADRCH does not determine OTP content, does not perform SMS delivery, and does not independently judge whether an OTP is valid.
5. Retention & Deletion
| Data category | SEADRCH retention or processing period |
|---|---|
| Phone number | Processed only for the period necessary to complete phone verification and to identify and look up diagnostics reports; once the processing purpose ceases, verification times out, the flow ends, or the service terminates, it is deleted, processing is stopped, or it is rendered not reasonably recoverable. |
| Phone numbers verified but with no report generated | Deleted once the verification purpose ceases, verification times out, or the flow ends. |
| OTP | Used only for the verification at hand and deleted immediately upon completion, failure, timeout, or end of the flow; not otherwise retained or used. |
| Verification results | Within the validity period of a diagnostics report, only the success/failure status necessary to provide the service is retained; OTP content is not stored. |
| US3C employee accounts | For the account’s validity period and, after deactivation, for the period necessary for security, auditing, or dispute handling. |
| Diagnostics reports & other technical records | Retained according to actual service, contractual, information-security, and statutory needs; the retention period is assessed separately from the processing purpose of the phone number. Upon expiry, data is deleted, processing stopped, or de-identified in accordance with law. |
Where retention is genuinely necessary due to law, a competent authority’s order, an information-security incident that has occurred, or a specific dispute, the relevant data may be retained with restricted access within the necessary scope and period, and processed in accordance with law once the reason ceases. The retention period for data US3C receives directly is handled according to US3C’s actual operations and its notices.
6. Region, Recipients & Methods
Region
In principle, processed in Taiwan and in the country or region where US3C, SEADRCH, or a commissioned service provider actually deploys, backs up, or supports the service; where cross-border transfer is involved, appropriate protection and disclosure will be made in accordance with law.
Recipients
Including US3C, SEADRCH (providing technical services on instruction), authorized personnel, and (as necessary to fulfill these purposes) cloud, SMS/OTP, app store, push notification, crash analytics, payment, logistics, and customer service providers, and authorities with legal jurisdiction. Each recipient obtains data only within the necessary scope.
Methods
By automated or non-automated means: input, transmission, verification, storage, lookup, linking, report generation, debugging, security management, and deletion in accordance with law. Phone numbers and OTPs must not be used for marketing, advertising, or user analytics unrelated to the verification and report services.
7. App Permissions & Diagnostics
Permissions such as camera, microphone, Bluetooth, local network, nearby devices, or location are requested only when needed for the corresponding diagnostics, pairing, QR code, or store-locator functions. A permission being invoked does not mean data is necessarily uploaded or retained long-term; actual processing is governed by the function screens, system behavior, and this policy.
Biometrics & Face ID test note:
If a Face ID or fingerprint test only invokes the operating system’s official API, iMCheck does not collect or store face templates, fingerprint images, or raw biometric data.
8. Data Security & Incidents
Within their respective spheres of control, US3C and SEADRCH adopt reasonable transmission encryption, access control, least privilege, log masking, vulnerability management, backup protection, and incident response measures. If an incident occurs that may affect personal data, SEADRCH will notify US3C under the tripartite agreement and provide necessary technical assistance; US3C is responsible for external notification and reporting to the competent authority in accordance with law, except where SEADRCH is legally required to fulfill this directly.
9. Your Rights
Under applicable law, you may request to query or access, obtain a copy of, supplement or correct, stop the collection/processing/use of, or delete your personal data. Please submit general personal-data and transaction requests to US3C; SEADRCH will provide technical assistance within its commissioned systems and on US3C’s lawful instructions. Where necessary under law or for contract performance, rights preservation, information security, or a specific dispute, processing may be restricted or deferred in accordance with law, with reasons provided.
10. Minors
When a minor uses services involving transactions or identity data, a legal representative should give consent or assistance in accordance with law. If we learn that a minor’s data was obtained without a lawful basis, we will take appropriate measures to restrict, stop processing, or delete it.
11. Versions & Changes
This policy is published with a fixed version number and effective date, and prior versions are reasonably archived. Material changes to the purposes of collection, data categories, usage period, recipients, region, or rights will be notified before taking effect via the App, the website, or other reasonable means; where separate consent is legally required, it will be obtained separately. Without SEADRCH’s written consent, no document may expand SEADRCH’s data-processing or transaction liabilities.
12. Contact
- Service line: 0906-888-337
- LOfficial LINE: @us3c
- Support email: imcheck.3d@gmail.com
- Website: www.imcheck.com.tw
- Address: 7F-1, No. 153, Section 3, Xinyi Road, Da’an District, Taipei City
- Service line: 0970-062-212
- Support email: service@seadrch.com
- Website: www.seadrch.com
- Address: 2F, No. 142, Dongnan Road, Dali District, Taichung City
This document is the fixed version v1.1 of the iMCheck Privacy Policy; its URL is not overwritable. Later revisions will be published under a new version number, and prior versions will be archived.

