私隱政策聲明

小賣店 (香港) 有限公司(以下簡稱「本公司」、「我們」)承諾嚴格遵守香港法例第 486 章《個人資料(私隱)條例》的要求。為此,本公司確保員工在處理從顧客及潛在客戶(以下統稱「顧客」、「閣下」)收集的個人資料時,遵從嚴格的安全及保密標準。

本公司強烈建議閣下仔細閱讀本私隱聲明(以下簡稱「本聲明」),以了解本公司處理個人資料的政策和實務。

若閣下對本聲明有疑問,請聯絡本公司的資料保障主任:

  • 電郵:pidcs@kouriten.jp

1. 收集個人資料的途徑

本公司透過多項途徑收集顧客的個人資料,包括但不限於:

  • 本公司網站及網上表格(如會員登記、保修登記、查詢表格);
  • 訂單交易(不論線上或線下);
  • 活動報名及參與期間的互動;
  • 網上社交服務平台(如 Facebook, Instagram)當閣下使用 Facebook 或 Google 帳號 登入本網站時,我們會經由相關平台獲取閣下的 公開個人檔案資料(包括姓名及頭像)以及電郵地址, 用作建立及驗證會員帳戶之用;
  • 顧客與本公司員工之間的通訊(書面或口頭)。

我們收集的資料可能包括:姓名、地址、電郵、電話、出生日期、性別、交易記錄及網站登入帳號等。此外,我們的系統亦可能自動收集日誌檔(如 IP 地址、瀏覽器類型、Cookies),詳情請參閱第 6 章。

2. 收集個人資料的目的

本公司收集及使用閣下的個人資料,主要作以下用途:

  • 處理訂單、提供產品及服務;
  • 處理付款及核實交易;
  • 識別及驗證會員身份;
  • 處理查詢、投訴及售後服務;
  • 進行市場研究、統計分析以改善服務;
  • 直接促銷(詳見第 4 章);
  • 防止欺詐及保障網絡安全。

若顧客未能提供某些被列為「必須」的資料,本公司可能無法為閣下提供相關服務或完成訂單。

3. 披露或轉移資料

本公司會將顧客的個人資料保密,但在以下情況下,我們可能會向第三方披露或轉移資料:

  • 第三方服務供應商:包括協助我們營運業務的物流公司、 支付網關(如 錢方 QFPay)、IT 支援、市場推廣合作夥伴等;
  • 法律要求:為了遵守適用法律、法規、法院命令或回應執法機關的要求;
  • 權益保障:為了保障本公司的權利、財產或安全,或為了防止欺詐行為。

由於我們擁有海外顧客,在處理跨境訂單時,相關的物流及送貨資料將不可避免地轉移至收件地之物流合作夥伴。

4. 直接促銷 (Direct Marketing)

本公司擬使用閣下的姓名、聯絡資料及交易記錄作直接促銷用途(包括發送有關本公司的產品、優惠及活動資訊)。

  • 徵求同意:我們在使用閣下的資料作直接促銷前,會先徵求閣下的同意(或表示不反對)。
  • 取消訂閱:閣下可隨時要求我們停止將閣下的資料用於直接促銷。閣下可透過電郵底部的「取消訂閱」連結,或直接電郵至 pidcs@kouriten.jp 通知我們,我們將免費處理閣下的要求。

5. 查閱及更正權利

根據《個人資料(私隱)條例》,閣下有權:

  • 查詢本公司是否持有閣下的個人資料;
  • 索取該等資料的副本;
  • 要求更正任何不準確的資料;
  • 要求刪除閣下的會員帳戶或個人資料(在不違反其他法律規定的前提下)。

如欲行使上述權利,請電郵至 pidcs@kouriten.jp 聯絡資料保障主任。本公司有權就處理查閱資料的要求收取合理費用。

如何撤銷社交帳號授權及刪除資料: 若閣下希望刪除經由 Facebook 或 Google 登入而產生的個人資料,閣下可以: (1) 直接電郵至 pidcs@kouriten.jp 聯絡資料保障主任;或 (2) 透過社交平台(如 Facebook)的『應用程式與網站』設定頁面,手動移除對『小賣店 Kouriten』的授權。

6. Cookies 及日誌檔

當閣下瀏覽本網站時,我們會使用 Cookies 及類似技術收集非個人識別資料(如瀏覽習慣、點擊流數據)。這些數據用於分析網站流量、優化用戶體驗及提供更切合閣下興趣的推廣內容。閣下可透過修改瀏覽器設定停用 Cookies,但這可能會影響網站的部分功能。

7. 安全性及支付安全

本公司極度重視資料安全,並採取適當的電子及管理措施保護閣下的資料。

  • 數據加密:本網站使用安全通訊端層 (SSL) 技術加密傳輸敏感資料。
  • 信用卡資料:本公司的網上交易經由第三方支付服務供應商(包括但不限於 錢方 QFPay)處理。 本公司不會在其伺服器上儲存閣下的完整信用卡資料。 所有敏感的付款資料均由支付服務供應商直接處理及加密儲存,符合支付卡行業資料安全標準 (PCI DSS)。
  • 儘管我們已採取保安措施,但互聯網上的資料傳輸無法保證百分之百安全,閣下須自行承擔相關風險。

8. 資料保留

本公司會將顧客的個人資料保存直至完成收集資料的原定目的為止,或根據適用法律規定的保存期限(例如稅務法例要求的會計記錄保存期)。當資料不再需要用於任何法律或業務目的時,我們會將其安全銷毀或匿名化。

9. 其他條款及聲明修訂

  • 條款分割性:倘若本私隱聲明的任何部分被法院或相關監管機構視為無效或不可執行,該部分將被視為與本聲明分割,而其餘部分之有效性及可執行性將不受影響。
  • 聲明修訂:本公司保留隨時修改本私隱聲明的權利。修訂後的版本將刊登於本網站,並自刊登之日起生效。建議閣下定期瀏覽本頁面以了解最新政策。

10. 語言

本私隱聲明備有中文及英文版本。如中、英文版本有任何歧義或不符,概以中文版本為準。


【English Version】

Privacy Policy Statement

Kouriten (HK) Limited (hereinafter referred to as "the Company", "we", "us") is committed to strict compliance with the requirements of the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong). We ensure that our employees adhere to strict standards of security and confidentiality when handling personal data collected from existing and potential customers (hereinafter referred to as "Customers", "you").

We strongly recommend that you read this Privacy Policy Statement (hereinafter referred to as "this Statement") carefully to understand our policies and practices regarding the treatment of personal data.

If you have any questions about this Statement, please contact our Data Protection Officer:

  • Email: pidcs@kouriten.jp

1. Collection of Personal Data

We collect personal data from customers through various channels, including but not limited to:

  • Our website and online forms (e.g., membership registration, warranty registration, enquiry forms);
  • Order transactions (whether online or offline);
  • Event registration and participation;
  • Social media platforms (e.g., Facebook, Instagram) When you choose to log in to our website using Facebook or Google, we will obtain your public profile information (including your name and profile picture) and your email address from the respective platform. This data is used solely for the purpose of creating and authenticating your membership account.;
  • Communication between customers and our staff (written or verbal).

The data we collect may include: name, address, email, telephone number, date of birth, gender, transaction records, and website login credentials. In addition, our systems may automatically collect log files (e.g., IP addresses, browser types, Cookies). Please refer to Section 6 for details.

2. Purpose of Collection

We collect and use your personal data primarily for the following purposes:

  • Processing orders and providing products and services;
  • Processing payments and verifying transactions;
  • Identifying and verifying membership identity;
  • Handling enquiries, complaints, and after-sales services;
  • Conducting market research and statistical analysis to improve services;
  • Direct marketing (see Section 4);
  • Preventing fraud and ensuring network security.

If you fail to provide certain data marked as "mandatory," we may be unable to provide relevant services or complete your order.

3. Disclosure or Transfer of Data

We keep customers' personal data confidential, but we may disclose or transfer data to third parties in the following circumstances:

  • Third-party Service Providers: Including logistics companies, Payment Gateways (e.g., QFPay), IT support, and marketing partners who assist in our business operations;
  • Legal Requirements: To comply with applicable laws, regulations, court orders, or requests from law enforcement agencies;
  • Protection of Rights: To protect the rights, property, or safety of the Company, or to prevent fraud.

As we serve overseas customers, when processing cross-border orders, relevant delivery information will inevitably be transferred to logistics partners in the destination country.

4. Direct Marketing

We intend to use your name, contact details, and transaction history for direct marketing purposes (including sending information about our products, offers, and events).

  • Consent: We will obtain your consent (or indication of no objection) before using your data for direct marketing.
  • Unsubscribe: You may request us to stop using your data for direct marketing at any time. You can do this by clicking the "Unsubscribe" link at the bottom of our emails or by emailing us directly at pidcs@kouriten.jp. We will process your request free of charge.

5. Access and Correction Rights

Under the Personal Data (Privacy) Ordinance, you have the right to:

  • Check whether we hold your personal data;
  • Request a copy of such data;
  • Request correction of any inaccurate data;
  • Request deletion of your membership account or personal data (subject to other legal requirements).

To exercise the above rights, please contact our Data Protection Officer at pidcs@kouriten.jp. We reserve the right to charge a reasonable fee for processing data access requests.

Instructions for Revoking Social Account Authorization and Data Deletion: If you wish to delete personal data generated through Facebook or Google login, you may: (1) Contact our Data Protection Officer directly at pidcs@kouriten.jp; or (2) Manually remove the 'Kouriten' authorization via the 'Apps and Websites' settings on your social platform (e.g., Facebook).

6. Cookies and Log Files

When you visit our website, we use Cookies and similar technologies to collect non-personally identifiable information (e.g., browsing habits, clickstream data). This data is used to analyze website traffic, optimize user experience, and provide marketing content tailored to your interests. You can disable Cookies by modifying your browser settings, but this may affect some functions of the website.

7. Security and Payment Safety

We take data security seriously and implement appropriate electronic and managerial measures to protect your data.

  • Data Encryption: This website uses Secure Socket Layer (SSL) technology to encrypt the transmission of sensitive data.
  • Credit Card Data: Our online transactions are processed by third-party payment service providers (including but not limited to QFPay). The Company does not store your full credit card information on its servers. All sensitive payment data is directly processed and encrypted by the payment service provider, in compliance with the Payment Card Industry Data Security Standard (PCI DSS).
  • Despite our security measures, data transmission over the Internet cannot be guaranteed to be 100% secure. You acknowledge that you transmit data at your own risk.

8. Data Retention

We retain customers' personal data only for as long as necessary to fulfill the original purpose of collection, or as required by applicable laws (e.g., accounting records retention required by tax laws). When data is no longer needed for any legal or business purpose, we will securely destroy or anonymize it.

9. General Provisions and Amendments

  • Severability: If any part of this Privacy Policy Statement is deemed invalid or unenforceable by a court or relevant regulatory authority, that part shall be deemed severed from this Statement, and the validity and enforceability of the remaining parts shall not be affected.
  • Amendments: The Company reserves the right to amend this Privacy Policy Statement at any time. The amended version will be published on this website and will be effective from the date of publication. We recommend that you check this page regularly for the latest policy.

10. Language

This Privacy Policy Statement is written in both Chinese and English. In the event of any discrepancy or inconsistency between the two versions, the Chinese version shall prevail.