Privacy Policy
Last updated: 2026-04-06 | https://hrt.bbhall.org/
1. Information Collection
1.1 Information You Provide
When you register, place an order, or contact us on our website, we may collect: your name, email address, phone number, shipping / billing address, payment information (held by third-party payment processors; we do not store full credit card numbers), order records, and purchase history.
1.2 Automatically Collected Information
When browsing our website, we automatically collect: IP address, browser type and version, operating system, pages visited and time spent, click and browsing behavior (via Google Analytics), and device identifiers.
1.3 Information from Third Parties
This includes payment providers (card networks), logistics partners (for delivery tracking), and other service providers.
2. Purpose of Data Use
| Purpose | Legal Basis (PDPO) |
|---|---|
| Order processing and fulfillment | Performance of contractual obligations |
| Order confirmation and shipping updates | Legitimate business interests |
| Payment processing and refunds | Performance of contractual obligations |
| Customer service and after-sales support | Legitimate business interests |
| Sending promotional information | Consent of data subject |
| Analyzing website usage trends | Legitimate business interests (anonymized) |
| Fraud prevention and security monitoring | Legitimate business interests |
| Legal compliance (tax, law enforcement) | Legal obligation |
3. Data Sharing
We may share your data in the following circumstances:
- Payment processors: Transaction processing
- Logistics companies: Order delivery
- Technology providers: Hosting, databases, plugin operations
- Legal and regulatory authorities: When required by law or in response to law enforcement requests
All third parties are bound by confidentiality obligations and only use data to provide specified services.
4. Cookie Policy
| Type | Purpose | Expiry |
|---|---|---|
| Essential — woocommerce_cart_hash | Shopping cart functionality | Session |
| Essential — wp_woocommerce_session_* | User login status | 2 days |
| Analytics — _ga / _gid | Google Analytics | 2 years / 24 hours |
| Functional — wc_cart_created | Remember browsing preferences | Session |
You can block cookies through your browser settings, but some features may not function properly.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Order records | 7 years (tax and legal compliance) |
| Customer account data | Until account deletion |
| Communication records | 3 years |
6. Your Rights
Under the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong), you have the right to:
- Right of access: Know what data we hold about you
- Right to correction: Request correction of inaccurate data
- Right to erasure: Request deletion of your account and related data
- Right to object: Object to use of data for direct marketing
- Data portability: Request your data in a commonly used format
7. Data Security
- SSL/TLS encryption (HTTPS)
- Regular system and plugin updates
- Restricted employee access
- Strong passwords and two-factor authentication (2FA)
- Payment data processed by PCI-DSS certified providers
In the event of a data breach, we will notify the relevant authority and affected users within 72 hours.
8. International Data Transfers
If data needs to be transferred outside Hong Kong, we will ensure the recipient provides an adequate level of data protection.
9. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy policies of these sites.
10. Children’s Privacy
Our services are not intended for individuals under 18 years of age, and we do not knowingly collect data from minors.
11. Policy Updates
This policy will be updated on this page with a revised “Last updated” date whenever changes are made.
12. Contact Us
📍 Address: Unit 502, Rise Commercial Building,
5-11 Granville Circuit, Tsim Sha Tsui, Kowloon
📞 Phone: +852-52421269
🏢 Data Controller: INFINITA LIMITED (Incorporated in Hong Kong)
