私隱政策
Privacy Policy
本地測試政策草案 · 正式營運前須由商戶確認商品、配送、保留期限及退貨安排。
Draft policies for local testing; merchant confirmation is required before commercial use.
1. 適用範圍及資料聯絡人Scope and privacy contact
草案日期:2026 年 10 月 10 日。本政策說明 WRH Trading Company Limited / WRH TRADING COMPANY LIMITED 測試站擬依香港《個人資料(私隱)條例》(第 486 章,PDPO)處理資料的安排,尚待商戶確認。資料查閱、更正及私隱查詢請聯絡「私隱事務負責人」:lingfeng9802@gmail.com;電話:64635865。本地測試請使用虛構資料,公開體驗帳戶不適合存放個人資料。
Draft dated 10 October 2026. This policy describes the proposed handling of data by the WRH Trading Company Limited / WRH TRADING COMPANY LIMITED test site under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486, PDPO), subject to merchant confirmation. Address access, correction and privacy enquiries to the Privacy Contact at lingfeng9802@gmail.com; telephone: 64635865. Use fictional information for local testing. The public demonstration account is unsuitable for personal information.
2. 收集的資料及提供選擇Data collected and your choices
註冊需要電郵及密碼,資料庫保存經 Argon2 處理的密碼雜湊,不保存明文密碼。測試結算收集收貨人姓名、電話及地址,並保存商品快照、金額、訂單及支付狀態、時間及帳戶關聯。登入及購物車功能使用必要的會話資料。聯絡表單保存姓名、電郵及留言。您可選擇不提供資料,但欠缺表單標示的必填欄位時無法完成相關註冊、結算或聯絡功能;不影響一般商品瀏覽。
Registration requires an email address and password. The database stores an Argon2 password hash, not a plaintext password. Test checkout collects a recipient name, telephone number and address, and saves product snapshots, amounts, order and payment states, timestamps and account associations. Login and basket functions use necessary session data. The contact form stores a name, email address and message. Providing data is your choice, but fields marked required are necessary for the relevant registration, checkout or contact function. General browsing remains available without them.
3. 資料用途Purposes of use
資料只用於建立及驗證測試帳戶、保持登入、處理及查閱測試訂單、記錄測試支付結果、回應查詢、維護系統安全及排查錯誤,或其他直接相關用途。本版本不作廣告追蹤或直接促銷,也不出售個人資料。擬用於與原目的無關的新目的時,須先按 PDPO 取得所需的訂明同意。
Data is used to create and authenticate test accounts, maintain login, process and display test orders, record test payment results, respond to enquiries, secure the system and diagnose faults, or for directly related purposes. This version does not use advertising tracking or direct marketing and does not sell personal data. Use for an unrelated new purpose requires the prescribed consent required by the PDPO.
4. 必要 Cookie 及外部圖片Necessary cookies and external images
本站只使用支援登入、購物車及表單安全所需的會話 Cookie,不使用廣告 Cookie。瀏覽器拒絕 Cookie 時,部分功能可能無法使用。當瀏覽器直接載入 Unsplash 或 Pexels 等外部來源圖片時,圖片提供者會接收載入所需的連線資料,例如 IP 位址及瀏覽器資訊;其處理安排以各提供者的私隱政策為準。
This site uses only session cookies needed for login, the basket and form security, without advertising cookies. Rejecting cookies may prevent some functions from working. If your browser loads images directly from external sources such as Unsplash or Pexels, the image provider receives connection information needed to deliver them, such as your IP address and browser information. Each provider's privacy policy governs its processing.
5. 存取、服務提供者及境外處理Access, service providers and overseas processing
每站使用獨立資料庫;僅獲授權的管理及技術人員可因測試維護需要存取。公開體驗帳戶的訂單可被其他體驗者看到。採用 Stripe 測試 Checkout 時,會向 Stripe 提供完成測試所需的訂單參考、商品、金額及相關帳戶資料;Stripe 亦會直接收集其托管頁面上的測試付款及連線資料。本商店不儲存完整卡號或 CVC,支付日誌不得記錄密鑰。Stripe 及外部圖片服務可能於香港以外處理資料;實際啟用前須確認供應商、處理地點及適當保障。依法須披露時,只向有權接收的機構提供所需資料。
Each site uses a separate database. Authorised administrative and technical staff may access data as needed for test maintenance. Orders in the public demonstration account are visible to other demonstration users. When Stripe test Checkout is used, Stripe receives the order reference, items, amount and relevant account information needed for the test. Stripe also directly collects test payment and connection information on its hosted page. This store does not retain full card numbers or CVCs; payment logs must not contain secret keys. Stripe and external image services may process data outside Hong Kong. Providers, processing locations and appropriate safeguards must be confirmed before activation. Legally required disclosures are limited to necessary data supplied to authorised recipients.
6. 測試資料保留及清理Test data retention and clearing
擬定的測試資料保留上限一般為建立記錄起 90 天;測試目的提早完成且無需繼續保留時應提早清理。帳戶、測試訂單及聯絡留言需由管理員執行清理腳本,現時並不聲稱已有每日自動刪除排程。會話按系統到期設定失效,過期記錄一併清理;管理員另須檢查備份及匯出檔。若有適用法律責任或尚在處理的合法查閱要求等必要理由,僅保留所需部分至理由終止,再清理。90 天是本測試方案的預設值,並非法定統一保留期;真實營運前須逐類核實保留期限及實際執行安排。
The proposed general test retention limit is 90 days from record creation, with earlier clearing when the test purpose ends and retention is no longer necessary. An administrator must run the clearing script for accounts, test orders and contact messages; no daily automatic deletion schedule is claimed. Sessions expire according to the system setting and expired records are cleared. Administrators must also check backups and exports. Where an applicable legal obligation or a pending valid access request requires retention, retain only the necessary data until that reason ends, then clear it. Ninety days is a test default, not a universal statutory period. Retention periods and operational arrangements for each data category must be confirmed before live use.
7. 查閱、更正及清理要求Access, correction and clearing requests
您可要求確認是否持有您的個人資料、取得副本,以及更正不準確資料,請以中文或英文聯絡 lingfeng9802@gmail.com。我們會要求合理的身分及資料範圍證明;正式查閱要求可使用私隱專員指定的表格。查閱及更正要求一般須按 PDPO 適用規定在收到後 40 天內處理;依法未能如期完成或拒絕時,須在適用時限內書面說明理由,並在法律要求下盡快完成。查閱費用如適用只限不超乎適度的水平,將預先說明。亦可要求清理不再必要的測試資料;此安排不表示香港法律設有無條件刪除權。
You may ask whether your personal data is held, obtain a copy and request correction of inaccuracies by contacting lingfeng9802@gmail.com in Chinese or English. Reasonable verification of identity and the requested data will be required; the Privacy Commissioner's specified form may be used for a formal access request. Access and correction requests are generally handled within 40 days of receipt under the applicable PDPO provisions. If a request cannot lawfully be completed on time, or is refused, written reasons must be given within the applicable deadline and it must be completed as soon as practicable where the law requires. Any access fee must not be excessive and will be explained in advance. You may also request clearing of unnecessary test data; this does not imply an unconditional statutory right to erasure in Hong Kong.
8. 安全及政策變更Security and policy changes
我們採用密碼雜湊、參數化資料庫查詢、表單防偽及帳戶存取控制等基本保護。安全措施不能消除所有風險;請勿在公開體驗環境提交真實或敏感資料。若有資料安全疑慮,請聯絡 lingfeng9802@gmail.com。資料收集、服務提供者或用途如有重大變更,會先更新本政策及相關收集提示,並在法律要求時取得同意。您亦可向香港個人資料私隱專員公署提出私隱查詢或投訴。
Basic safeguards include password hashing, parameterised database queries, form request protection and account access controls. Safeguards cannot remove every risk. Do not submit real or sensitive information to the public demonstration environment. Report data security concerns to lingfeng9802@gmail.com. Material changes to collection, providers or purposes will be reflected in this policy and collection notices before implementation, with consent where legally required. Privacy enquiries or complaints may also be directed to Hong Kong's Office of the Privacy Commissioner for Personal Data.