1. Introduction and scope
Who we are
The controller for the processing described in this policy is Hairun Trading Co., Limited, a company incorporated in the Hong Kong Special Administrative Region, with its registered office at Rm 03, 24/F, Ho King Comm Ctr, 2-16 Fayuen St, Mongkok, Hong Kong. References to "we", "us" and "our" refer to this legal entity.
What this policy covers
This policy applies to personal information we collect through (a) our corporate website at hairiun.com, (b) the Hairun Mobile application on Android and iOS, and (c) B2B sales communications including email, voice calls and the contact form. It also covers personal information we receive from third-party service providers who process data on our behalf.
What this policy does not cover
This policy does not cover third-party sites we link to, including the websites of the advertising partners listed in section 7. Those parties have their own privacy notices and your use of their services is governed by their terms.
2. Information we collect
Information you give us
We collect personal information that you provide directly, including your name, company name, country, email address and the body of messages you submit through the contact form or by email. We also collect notes from voice calls when you call our office and consent to a call being summarised.
Information collected automatically
When you visit our corporate website we automatically receive technical information from your device and browser, including IP address, user-agent string, referring URL and aggregated page counts. We do not set marketing cookies in this version of the site; we do not run third-party analytics scripts.
Information from app stores and devices
When you install or use the Hairun Mobile app, we receive the install referrer from the Google Play Store or the Apple App Store, and may receive the Android AD_ID or the iOS IDFA subject to App Tracking Transparency consent (see section 8).
3. How we use information
Purposes
We use the information we collect for the following purposes: responding to enquiries, fulfilling and documenting orders, complying with trade, tax and corporate law, protecting the security of our systems and customers, and improving our products and services. We do not sell personal information.
Legal bases (GDPR / UK GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract (to respond to enquiries and fulfil orders), legitimate interest (to secure and improve our services), legal obligation (to comply with tax, customs and corporate law) and consent (for any marketing communications and for in-app advertising personalisation).
4. Children and age thresholds
Minimum age
Our services are not directed to children. The minimum age to use them is: 13 in the United States under the Children's Online Privacy Protection Act (COPPA), 14 in Spain and for users under 14 in Korea, 16 in the European Union by default, the United Kingdom, the Netherlands and France, and 18 where local law requires adult status. Operators of the Hairun Mobile app must meet the minimum age for their jurisdiction.
What we do if we learn of a child's data
If we learn that we have collected personal information from a person below the applicable minimum age without verified parental consent, we will purge that information from our systems within 30 days and notify the submitting party where contactable.
5. International data transfers
Where data goes
Personal information we collect is processed in Hong Kong, the European Union, the United States and Singapore — depending on the service provider hosting the relevant workload. Our email and contact-form processors operate in the EU; our hosting and DNS are US-based; our billing and corporate records are stored in Hong Kong and Singapore.
Safeguards
Where personal information is transferred across borders, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, recognised adequacy decisions, and supplementary technical and organisational measures including encryption in transit and at rest, scoped access and vendor due diligence.
6. Sharing and processors
Service providers
We share personal information with vetted service providers who act as processors on our behalf, including hosting providers, email providers, the freight forwarders and customs brokers we coordinate with, and the payment partners we use for invoicing. Each processor is bound by a written data-processing agreement that limits the use of personal information to the purposes set out in this policy.
Advertising partners (mobile app)
When you use the Hairun Mobile app, advertising partners receive personal information necessary to serve and measure ads. The full list of advertising partners currently in scope is:
- Google AdMob
- Google AdSense
- Google Ad Manager
- Meta Audience Network
- Unity Ads
- AppLovin
- ironSource
- InMobi
- Vungle
- Chartboost
- Tapjoy
- Digital Turbine
- Pangle (ByteDance)
- Mintegral
- Liftoff
The list may evolve as we expand or contract our advertising partners. We will update this section on material changes with at least 30 days' notice on the home page banner.
Legal disclosures
We disclose personal information only in response to lawful requests by competent authorities, including subpoenas, court orders and regulatory inquiries. We challenge over-broad or improper requests through established procedures and will notify the affected user where lawful to do so.
7. In-app advertising — full disclosure
Ad formats
The Hairun Mobile app serves advertising through four formats. The disclosure below uses both industry terms and Chinese terms to ensure clarity for cross-border teams.
- Splash ads (开屏广告) — full-screen ads shown when the app launches, skippable after 5 seconds.
- Rewarded video (激励视频) — opt-in video ads that grant a reward (such as a freight quote discount) after viewing.
- Interstitial ads (插屏广告) — full-screen ads shown at natural transition points, such as between catalogue screens.
- Banner ads (Banner广告) — standard placements at the bottom of catalogue and tracking screens.
Personalisation signals
Advertising partners may use the following signals to personalise ads and measure performance: device advertising identifiers (Apple IDFA and Android AD_ID), coarse location (only with explicit user consent where required), and contextual signals such as the language of the app, the catalogue section you are browsing, and the time of day.
How to opt out
You can limit ad personalisation at any time using the platform controls on your device: Apple's Settings → Privacy & Security → Tracking → Limit Ad Tracking on iOS, and Android's Settings → Google → Ads → Opt out of Ads Personalisation. You can also use the in-app privacy settings to reset your advertising identifier. Vendor-specific preferences are available at Google My Ad Center, Meta Ad Preferences, and equivalent pages operated by each advertising partner listed in section 6.
8. App Tracking Transparency (ATT)
iOS ATT prompt
The Hairun Mobile app for iOS uses Apple's App Tracking Transparency framework. The prompt text (NSUserTrackingUsageDescription) displayed to users reads approximately: "Hairun Mobile uses tracking to personalise advertising and measure ad performance. You can decline and still use the app; the experience is unchanged." The prompt is shown at the first launch where tracking is technically applicable. If you decline, advertising partners receive only contextual signals and aggregated performance metrics — no device advertising identifier is shared.
Android equivalents
The Hairun Mobile app for Android requests the com.google.android.gms.permission.AD_ID permission on first launch where the underlying device supports it. Where Android Privacy Sandbox topics are available on the device, the app uses them as a privacy-preserving alternative to the legacy AD_ID.
9. Regional rights
EEA & UK
If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict and port your personal information; to object to processing based on legitimate interest; to withdraw consent at any time without affecting prior lawful processing; and to lodge a complaint with your supervisory authority.
California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we have collected about you, to delete it, to correct inaccuracies, to opt out of any sale or sharing of personal information (we do not sell personal information), to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights.
China (PIPL)
If you are in the People's Republic of China, you have the rights granted by the PIPL, including separate consent for processing of sensitive personal information, the right to a cross-border transfer assessment, the right to deletion, and the right to explanation of significant decisions made solely by automated processing.
Brazil (LGPD)
If you are in Brazil, you have the rights granted by the LGPD: confirmation of the existence of processing, access, correction, anonymisation, portability, elimination of unnecessary or excessive data, and information about sharing with third parties.
Japan (APPI)
If you are in Japan, you have the rights granted by the APPI: disclosure of the purpose of processing, opt-out of third-party transfer of personal information, and disclosure of the source of personal information acquired from third parties.
Other regions
If you are in Korea (PIPA), Australia (Privacy Act), Canada (PIPEDA), Singapore (PDPA), South Africa (POPIA) or any other jurisdiction with comparable rights, you may exercise equivalent rights — access, erasure, correction and portability — by contacting us using the details in section 13. We will respond within the time limits set by your local law.
10. Security
Technical measures
We protect personal information using TLS in transit, encryption at rest where supported by the underlying processor, scoped access enforced by role-based controls, multi-factor authentication on administrative accounts, and continuous logging of access events.
Organisational measures
We train staff on data-protection obligations at onboarding and annually, conduct vendor due diligence before engaging any new processor, maintain an incident-response runbook with defined roles, and review our security posture quarterly.
11. Retention
Retention periods
We retain personal information only for as long as necessary to fulfil the purposes set out in this policy or as required by law. Current records:
- Enquiry records: 24 months from last contact.
- Order records: 7 years from shipment date, to comply with tax, audit and customs-record requirements.
- App analytics: 13 months aggregated, with raw identifiers stripped at 90 days.
- Job applications: 6 months from application close, unless you ask us to retain your details for longer.
12. Changes to this policy
Notice of changes
We will notify users of material changes to this policy by a banner on the home page of our corporate website and, where you have an account or recent transaction with us, by email. Non-material changes — such as correcting typographical errors or clarifying existing disclosures — will be reflected in the "Last updated" date at the top of this page.
13. Contact the privacy team
For any privacy enquiry, please email support@hairiun.com with the subject line Privacy enquiry, or write to us at Rm 03, 24/F, Ho King Comm Ctr, 2-16 Fayuen St, Mongkok, Hong Kong. We aim to acknowledge privacy enquiries within five business days and to substantively respond within 30 days.