Privacy
Privacy Policy
Last updated: 23 April 2026
Controller
Sinolinks ("we", "our", "us") is a Hong Kong-registered advisory practice. All privacy enquiries: [email protected].
Scope
This policy applies to www.sino-links.com and operated subdomains. It does not apply to external sites we link to.
Data we collect
• Order data: name, work email, company, country, target-company name, and research context — submitted via /verify/order. • Payment data: name, billing address, and card details — collected by Stripe on Stripe's own systems. We never see or store card numbers; we receive a Stripe transaction reference only. • Communications: emails you send and our replies. • Analytics: anonymized page-view data, self-hosted on our infrastructure. No cookies, no personal identifiers. • Security: IP address and basic browser metadata during an automated-abuse challenge at form submission; not persisted by us.
Why we collect it
• Deliver verification reports and related services — contract performance (GDPR Art. 6(1)(b)). • Send order confirmations, report delivery, and correspondence — contract performance. • Detect and prevent fraud, abuse, and automated abuse — legitimate interest (Art. 6(1)(f)). • Send Trade Signal where you have opted in — consent (Art. 6(1)(a)). • Comply with legal, accounting, and tax obligations — legal obligation (Art. 6(1)(c)).
Processors
We engage the following categories of processors: • Payment processor — Stripe (visible to you during checkout) • Cloud infrastructure provider — hosting and database • Content-delivery and security provider — CDN, DDoS protection, automated-abuse challenge • Email delivery provider — transactional mail only (order confirmations, report delivery) • Analytics — self-hosted; no third-party access A current named list of processors is provided to verified data subjects on written request. We do not sell, rent, or share your data with advertising networks or data brokers.
International transfers
As a Hong Kong-based practice serving global clients, some processing occurs outside the EEA or UK. Appropriate safeguards under GDPR Chapter V — including Standard Contractual Clauses where applicable — are in place. The payment processor operates under its own EU-approved transfer mechanisms.
Retention
• Order and payment records: 7 years (Hong Kong Inland Revenue Ordinance). • Newsletter subscribers: until you unsubscribe. • Support correspondence: 3 years unless a dispute is open. • Analytics: aggregated and non-identifiable.
Your rights
Under GDPR and Hong Kong PDPO, you may access, correct, delete, restrict, object to, and port your data, and withdraw newsletter consent at any time. Email [email protected]. We reply within 30 days.
Cookies and tracking
We do not use advertising or third-party tracking cookies. Our analytics is cookie-free. An automated-abuse challenge at form submission may drop a short-lived cookie; it is removed at session end. Stripe Checkout runs on Stripe's own domain under their cookie policy.
Security
Data in transit is TLS-encrypted. Payment data is handled by Stripe under PCI-DSS Level 1 compliance. Database access is restricted to authorized personnel only. We never email passwords or credentials.
Children
Services are not intended for anyone under 18. We do not knowingly collect data from minors.
Changes
We may update this policy. Material changes are noted by updating the "Last updated" date at the top of this page.
Contact
Email: [email protected] Postal correspondence is accepted for verified data-subject requests; the mailing address is provided on reply.