PANW Price Assistant

PRIVACY POLICY

Your information

Operator: Summerle Tan · Effective and updated: October 8, 2026 · Version 2026-10-08-v1

Privacy contact: panwapp@163.com

Privacy at a glance: Information is used for account access, licensing, service security and technical support, not advertising or sale. Projects are managed on your device. You can delete your account in the app or contact us about privacy requests.

1. Scope and purpose

PANW Price Assistant is an internal productivity tool for authorized company colleagues to configure products, prepare budgetary quotes and organize projects. This policy covers its account and pricing backend and related support website. Until any formal company handover, Summerle Tan is responsible for account and information administration. Before a company formally takes over operation, the operator identity, administrator responsibilities and privacy contact will be updated and communicated to users. The app and this website do not represent official Palo Alto Networks support.

2. Account, license and device information

Registration and account services process a name or display name, username, account ID, registered email where provided, password-verification information, registration and approval status, license ID and validity, allowed device count, and the version and time of notices accepted. Administrator-created accounts without email do not require a real email address.

We process an app-generated random device ID, device-name label, operating-system platform, app-reported version, first and most recent connection times, device-release status, and login/session verification information. The app-generated ID is not an advertising identifier.

License-extension requests include their dates, decisions and any optional note you submit. Do not include unrelated sensitive information. These records support authentication, registration approval, licensed access, device limits, recovery, deletion and service security, not advertising or marketing.

3. Local projects and pricing requests

Project names, customer names, opportunity IDs, distributor and reseller names, status, expected close dates, notes, quote versions and configuration lists are managed in the device-local project database. The current project library does not automatically synchronize projects to a cloud project service operated by us.

To retrieve products and prices, the app sends the required SKUs, product search terms and authorization information to the pricing backend. Current pricing interfaces do not require project or customer details. Request paths and technical information can still appear in operational or network access logs.

User-initiated backups, PDF/spreadsheet exports and sharing can include project and quote details. Backups also contain an account identifier and account email where present. The system file picker, share sheet and print/export functions process files and destinations you choose. Selected apps, recipients and storage providers apply their own terms. Export files may remain in the app cache. Files kept on the device can also be affected by operating-system backup or device-management settings you independently enable.

The local project database and exported backups do not provide application-level encryption. Integrity checks are not encryption. Use protected devices and storage locations, and avoid unnecessary personal or sensitive details.

4. Logs, administrators and service providers

The pricing backend records request time, endpoint path, method, response status and duration, and account/device IDs when a session is identified. Administrative audit records may include operation targets, times, summaries and outcomes. Network addresses are used for rate limiting; NAS, reverse proxy and other infrastructure may separately retain network addresses and access logs.

163/NetEase email services deliver verification codes, password-recovery codes, registration decisions and license-extension notices. Email providers and mailbox systems process addresses, message content and necessary name, account or request information. Authorized administrators receive information needed for account and license administration. Support emails and attachments are used to answer your request; do not send passwords, API keys or unrelated confidential customer information.

This public website uses OpenAI Sites hosting. The platform processes information needed to serve visits and provides visitor/page-view statistics. Website visits are distinct from app account and pricing activity. We do not upload user databases or local project records to this static website host. Email and hosting providers apply their service and privacy terms and can process information through infrastructure outside your location; information is not guaranteed to remain only on the NAS or in one country.

We do not sell user information, use it for advertising or marketing, or use it for cross-app advertising tracking. No additional data recipients or advertising/user-behavior analytics SDKs are used in the current app flow. Necessary email, hosting and infrastructure processing is not excluded by this statement.

5. Permissions and security

The current app flow does not actively read contacts, location, the photo library or audio recordings, and does not enable user image or voice uploads. Backup restore processes the file you select; exporting and sharing are initiated by you.

Account and pricing connections use HTTPS. Login tokens and the app-generated device ID use system secure storage. Server-side passwords are stored as salted hashes rather than plaintext account records; passwords still need to be transmitted securely when registering, signing in, resetting or confirming deletion. Account, license and administrator checks restrict access. These measures do not mean local files, exports, email, logs or backups are end-to-end encrypted, and no system is absolutely secure.

6. Retention and deletion of records

Account, license and device information is retained for the period needed to provide the authorized account service. Registration and verification records are retained as needed to complete approval, account recovery or related enquiries. Expiry of a verification code or session prevents its continued use; it is not the same as deleting all historical records.

Service and security logs are retained for necessary fault investigation, access auditing and applicable legal obligations. Database backups are restricted to recovery and continuity purposes. Support and notification emails are retained for handling the relevant request and necessary follow-up. Retention is determined by these purposes, applicable requirements and administrator review, rather than a single automatic expiry for every type of record. Records should be deleted or appropriately de-identified when they are no longer needed. This policy does not claim that an automatic 7-, 30- or 90-day cleanup system is already in operation.

Historical logs, mailbox copies and server backups may remain after account deletion until their retention requirement ends and they are administratively cleared. They are not used to continue normal account access. When handling a privacy request, the administrator reviews the remaining records, explains any necessary retention and applicable limits, and assists with deletion of information that is no longer needed. Any legal retention exception is limited to the relevant records and does not justify indefinite retention of unrelated information.

Successful account deletion removes the active authentication database's account and associated license, device, session, registration, verification, extension and notice records and cleans associated administrative audit references. A hashed deletion receipt remains for safe retries. It does not directly include the original username or email, but is not claimed to be unconditionally anonymous.

7. Your choices and account deletion

Use Account > Delete Account, or Delete Account in the sign-in flow, enter the current password and confirm. Successful deletion invalidates the account's sign-ins and license and removes that account's project database records and login state on the device completing deletion. Other users and the shared price list are unaffected. A sole administrator must first transfer administrator responsibility.

Save needed work first. Deletion does not automatically erase exported/shared files, generated export copies in app caches, local records on other devices, mailbox copies, operating-system backups or old server database backups. Historical server copies follow the retention approach above. A backup restore must not be used to reactivate a deleted account without reviewing and applying the deletion request again.

Release & Sign Out frees a device slot. Sign Out ends a login. Neither permanently deletes the account, and stopping use does not automatically remove server records. For assistance, account corrections, incomplete registrations or privacy requests, contact panwapp@163.com. We may verify your identity to prevent unauthorized disclosure or deletion. We do not require a support email to initiate the app's available account-deletion flow.

8. Audience and policy updates

The app is for authorized business users, is not designed specifically for children, and does not verify age. Its content age rating does not verify the age of each user. We update this page when the app's functionality, providers or data handling changes. This policy describes the present service; it is not a guarantee that every historical copy has already been deleted.

隐私政策

你的信息如何处理

运营者:Summerle Tan · 生效及更新日期:2026 年 10 月 8 日 · 版本:2026-10-08-v1

隐私联系邮箱:panwapp@163.com

隐私摘要:信息仅用于账号访问、许可管理、服务安全和技术支持,不用于广告或出售。项目在设备上管理。你可在 App 内删除账号,也可联系运营者提出隐私请求。

1. 适用范围与用途

PANW Price Assistant 是供获授权的公司同事使用的内部效率工具,用于产品配置、预算报价和项目整理。本政策覆盖账号和报价后台及相关支持网页。在公司完成正式接管之前,由 Summerle Tan 负责账号及信息管理;公司正式接手运营前,会更新运营者身份、管理员职责和隐私联系方式,并向用户告知。本应用和网页不代表 Palo Alto Networks 的官方支持服务。

2. 账号、许可与设备信息

注册及账号服务处理姓名或显示名称、用户名、账号标识、已提供的注册邮箱、密码验证信息、注册与审批状态、许可标识和有效期、设备数量限制,以及已接受告知的版本和时间。管理员创建的无邮箱账号不要求提供真实邮箱。

我们处理应用生成的随机设备标识、设备名称标签、系统平台、应用报告的版本、首次及最近连接时间、设备释放状态,以及登录和会话验证信息。随机设备标识不是广告标识。

许可延期申请包含日期、审批结果及你主动填写的可选备注;请勿填写与申请无关的敏感资料。这些记录仅用于身份验证、注册审批、许可服务、设备限制、账号恢复、删除和安全维护,不用于广告或营销。

3. 本地项目与报价请求

项目名称、客户名称、销售机会编号、总经销商和经销商名称、状态、预计成交日期、备注、报价版本和配置清单在设备端项目数据库中管理。当前项目库不自动同步到由我们运营的云端项目服务。

获取产品和价格时,应用向报价后台发送所需 SKU、产品搜索词及授权信息。当前价格接口不要求提交项目名称或客户资料,但请求路径和技术信息仍可能出现在服务或网络访问日志中。

你主动备份、导出 PDF/电子表格或分享时,文件可以包含项目及报价资料;备份还包含账号标识及已提供的账号邮箱。系统文件选取、共享和打印/导出功能处理你选择的文件与目标。所选应用、收件人和存储服务按其自身条款处理文件,导出副本也可能暂存于应用缓存目录。设备上的文件还可能受你自行启用的系统备份或设备管理设置影响。

本地项目数据库和导出备份不提供本应用层面的加密,完整性校验不等于加密。请使用安全设备和存储位置,避免填写不必要的个人或敏感资料。

4. 日志、管理员与服务提供商

报价后台记录请求时间、接口路径、请求方式、响应状态及耗时;已识别会话还会记录账号和设备标识。管理审计记录可能包括操作对象、时间、摘要和结果。请求限流会使用网络地址;NAS、反向代理及其他基础设施可能另外保存网络地址和访问日志。

163/网易邮件服务用于发送注册验证码、密码恢复验证码、注册决定和许可延期通知。邮件服务及邮箱系统处理收发件地址、正文及必要的姓名、账号或申请信息。获授权管理员可以访问处理账号与许可事务所需的信息。支持邮件及附件用于回答你的请求;不要发送密码、API 密钥或无关的客户机密。

本公开网页由 OpenAI Sites 托管,平台会处理提供网页访问所需的信息并提供访问人数和页面浏览统计。网页访问与 App 的账号、报价活动不同;我们不会向该静态网站上传用户数据库或本地项目资料。邮件和托管服务按其服务与隐私条款处理信息,其基础设施可能位于你所在地区之外;不能保证所有信息只留在 NAS 或单一国家内。

我们不出售用户信息,不用于广告或营销,也不进行跨应用广告追踪。当前应用流程不使用额外数据接收方或广告、用户行为分析 SDK。必要的邮件、网页托管和基础设施处理不因此被排除。

5. 权限与安全

当前应用流程不主动读取通讯录、定位、照片库或录音,也未启用用户图片或语音上传。备份恢复处理你通过系统选取的文件,导出与分享由你主动发起。

账号和报价连接使用 HTTPS,登录令牌及随机设备标识使用系统安全存储。后台账号密码以加盐哈希保存,而非明文账号记录;注册、登录、重置或确认删除时,密码仍需通过安全连接发送以供验证。账号、许可及管理员权限限制访问。这些措施不表示本地文件、导出副本、邮件、日志和备份都采用端到端加密,也不保证系统绝对安全。

6. 数据保留与删除

账号、许可和设备资料在提供获授权的账号服务所需期间保留。注册和验证资料按完成审批、账号恢复及相关查询的必要期间保留。验证码或会话到期后不能继续使用,但这不等于删除所有历史记录。

服务及安全日志用于必要的故障调查、访问审计和适用的法定留存义务;数据库备份限于恢复和业务连续性用途;支持及通知邮件用于处理相关请求和必要后续事务。保留期间依据这些用途、适用要求及管理员审查确定,而不是为所有资料设置同一个自动到期时间。不再必要的资料应删除或适当去标识化。本政策不声称已经部署自动 7 天、30 天或 90 天清理系统。

账号删除后,历史日志、邮箱副本和服务器备份可能保留至其必要留存结束并由管理员清理,但不用于继续提供正常账号访问。处理隐私请求时,管理员会审查剩余资料,说明必要留存原因及适用限制,并协助删除已无必要的信息。法定留存例外只适用于相关记录,不代表可以无限期保留无关资料。

账号删除成功后,活动认证数据库中的账号及关联许可、设备、会话、注册、验证、延期和告知记录被移除,关联管理审计引用也会清理。用于安全重试的散列删除回执会保留;它不直接包含原用户名或邮箱,但不被宣称为无条件匿名数据。

7. 你的选择与账号删除

在 Account > Delete Account 或登录流程的 Delete Account 发起永久删除,输入当前密码并确认。成功后登录和许可证失效,并清理执行删除的设备上该账号的项目数据库记录及登录状态。其他账号和公共价格表不受影响;最后一个管理员须先转移管理员职责。

删除前请先保存需要保留的工作。账号删除不会自动擦除已导出或分享的文件、应用缓存中的导出副本、其他设备本地资料、邮箱副本、系统备份和旧数据库备份,历史服务器副本按上述当前保留方式处理。恢复备份不能在未审查并重新落实原删除请求的情况下重新激活已删除账号。

Release & Sign Out 释放设备名额,Sign Out 退出登录,均不是永久删除账号;停止使用也不自动删除服务器记录。如需协助、更正账号、处理未完成注册或提出隐私请求,请联系 panwapp@163.com。为防止未经授权的披露或删除,我们可能先核实身份;使用 App 已提供的账号删除入口不要求先发送支持邮件。

8. 用户范围与政策更新

应用面向获授权的业务用户,不是专门为儿童设计,也不核验年龄;内容年龄分级不代表已验证每位用户年龄。功能、服务提供商或信息处理发生变化时会更新本页。本政策说明当前服务,并不证明所有历史副本已被删除。