Operator
This Privacy Policy is published by HONORICH TRADE CO., LIMITED ("HONORICH", "we", "us", "our"). It explains how we handle personal data collected through this website, our wholesale operations, and the HONORICH mobile management application published on Google Play and the Apple App Store (together, the "Services").
If you do not agree with this Policy, please do not use the Services. By using the Services, you confirm you have read and understood this Policy and our Terms of Service.
1. Introduction and scope
This Privacy Policy describes the categories of personal data we collect, the purposes for which we use it, the legal bases on which we rely (where applicable), the categories of recipients with whom we share it, the retention periods we use, and the rights you have over your data. It applies to:
- Visitors to https://hongruix.com and any subdomain we operate.
- Wholesale and trade-services customers and prospects who contact us by email, telephone, or contact form.
- Users of the HONORICH mobile management application, available on Google Play and the Apple App Store.
- Recipients of any commercial communications we send with your consent.
It does not apply to third-party sites or services that we link to from within our Services. We are not responsible for the privacy practices of third parties; please review their policies separately.
2. Information we collect
We collect personal data in three broad ways: data you give us directly, data collected automatically as you use the Services, and data we receive from third parties.
2.1 Data you give us
- Contact-form and email data. Name, company, email, phone number, enquiry category, and the contents of your message when you submit the contact form or write to support@hongruix.com or haozhe@hongruix.com.
- Wholesale account data. Billing and shipping addresses, tax registration numbers where required, order history, and shipping documentation references needed to fulfil your orders.
- App account data. The credentials you set up to access the HONORICH mobile app, your notification preferences, and the warehouse or shipping addresses you save inside the app.
2.2 Data collected automatically
- Device and connection data. IP address, device type, operating system, browser type and version, screen resolution, locale, and time zone.
- Advertising identifiers. Google Advertising ID (GAID) on Android devices and Identifier for Advertisers (IDFA) on iOS devices, where the platform and your settings allow.
- App telemetry. App version, session start and end timestamps, screens viewed, button interactions, crash logs, and performance metrics.
- Cookies and similar. Cookies, local storage, and similar technologies set on your browser when you visit our website. See section 13.
2.3 Data received from third parties
- Ad mediation platforms. Impression, click, and conversion signals shared back through the mediation layer (see section 5 for the full list and what each platform receives).
- Logistics and freight partners. Shipment status updates and customs documentation references related to your orders.
3. How we use information
We use the data we collect for the following purposes:
- To provide the Services. Process wholesale orders, fulfil shipments, manage inventory, operate the mobile app, and respond to enquiries.
- To respond to enquiries. Reply to messages you send us, route enquiries to the right team, and keep a history of the relationship.
- To support advertising in the mobile app. Display splash / app-open, rewarded video, interstitial, and banner ad units, and to measure their performance. We rely on consent where required by applicable law.
- To analyse and improve the Services. Produce aggregate analytics about how the Services are used, run A/B tests on UI flows, and prioritise engineering work.
- For compliance and legal protection. Meet our record-keeping obligations, detect fraud and abuse, enforce our Terms, and respond to lawful requests from public authorities.
We do not sell personal data. We do not use your contact data to send marketing communications unless you have opted in, and every marketing email includes an unsubscribe link.
4. Legal bases for processing (GDPR Article 6)
Where the General Data Protection Regulation (Regulation (EU) 2016/679) applies, we rely on the following legal bases:
- Consent (Art. 6(1)(a)). For non-essential cookies, for personalised advertising inside the app (where required), and for marketing communications. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Contract (Art. 6(1)(b)). To process orders, fulfil shipments, and provide the wholesale and trade services you have requested.
- Legal obligation (Art. 6(1)(c)). To meet tax, customs, accounting, and anti-money-laundering record-keeping obligations.
- Legitimate interests (Art. 6(1)(f)). To secure the Services, prevent fraud, perform aggregate analytics, and operate our business. We balance our interests against your rights and freedoms and offer opt-out paths where appropriate.
Where local law requires a different or additional basis, we apply that basis in parallel.
5. Sharing and third parties (including ad mediation platforms)
We share personal data with a controlled set of recipients, all of which are bound by confidentiality and data-protection obligations.
5.1 Categories of recipients
- Logistics and freight partners. For the purpose of fulfilling shipments and customs declarations.
- Cloud and infrastructure providers. For hosting, storage, and authentication of the Services.
- Email and customer-support tooling. For routing enquiries and sending transactional emails.
- Professional advisers. Auditors, legal counsel, and tax advisers bound by professional duties of confidentiality.
- Ad mediation platforms. For delivering advertising inside the mobile app and measuring its performance.
- Public authorities. Where we are legally required to disclose.
5.2 Ad mediation platforms — full disclosure
The HONORICH mobile app integrates the following twenty (20) ad mediation platforms. Each receives only the data categories it requires to deliver, measure, and attribute advertising. We publish the platform name, the data categories shared, and a link to the platform's own privacy / partner-policy URL.
For each platform we share: impression signals, click signals, IP-derived coarse geolocation, advertising identifier (GAID / IDFA, where available), device and OS metadata, and contextual information about where the ad is shown (screen name, ad unit type, mediation auction ID). We do not share the contents of your orders, your contact data, or your account credentials with these platforms.
- Google AdMob — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://policies.google.com/privacy
- Google AdSense — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://policies.google.com/privacy
- Meta Audience Network — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.facebook.com/policy.php
- Unity Ads — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://unity.com/legal/privacy-policy
- AppLovin — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.applovin.com/privacy
- ironSource / Digital Turbine — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.digitalturbine.com/privacy-policy/
- Vungle (Liftoff) — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://vungle.com/privacy/
- Chartboost — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.chartboost.com/privacy/
- AdColony (Digital Turbine) — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.adcolony.com/privacy-policy/
- Pangle / ByteDance — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.pangleglobal.com/privacy
- TikTok Audience Network — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.tiktok.com/legal/privacy-policy
- InMobi — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.inmobi.com/privacy-policy/
- StartApp — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.startapp.com/policy/privacy-policy
- Tapjoy — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.tapjoy.com/legal/privacy-policy
- Yahoo / Verizon Native — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://legal.yahoo.com/us/en/yahoo/privacy/index.html
- Amazon Publisher Services — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual, header-bidding auction context. Privacy URL: https://aps.amazon.com/aps/privacy/
- Mintegral — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.mintegral.com/en/privacy/
- Liftoff (Vungle parent) — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://liftoff.io/privacy-policy/
- Moloco — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual. Privacy URL: https://www.moloco.com/privacy-policy
- DT FairBid (Digital Turbine) — Data shared: impression, click, IP, GAID/IDFA, device and OS metadata, contextual, real-time bidding auction context. Privacy URL: https://www.digitalturbine.com/fairbid-privacy/
6. Ad unit disclosures
The HONORICH mobile app integrates four (4) ad units. Each unit is described below together with the data it may collect and the user controls available. Revenue from these ad units funds continued free access to the app.
6.1 Splash and app-open ads
Full-screen units shown while the app is launching or returning to foreground. They collect impression signals, click signals, device and OS metadata, and coarse IP-derived geolocation. Frequency is capped so that no user sees more than a small number per session. Users cannot disable splash ads without disabling the app's launch experience; we mitigate this by capping frequency and keeping the unit brief.
6.2 Rewarded video ads
Opt-in video units that reward the viewer with an in-app benefit (for example, a fee credit on the next order) once the video has been watched in full. They collect impression, completion, click signals, and advertising identifiers. Users can decline to watch rewarded video at any time; declining simply means the user does not earn the associated reward.
6.3 Interstitial ads
Full-screen units shown at natural transition points (for example, between screens), and never inside an active order, checkout, or pricing flow. They collect impression, click, device and OS metadata, and advertising identifiers. Frequency is capped.
6.4 Banner ads
Small, persistent units shown only on screens that are not part of an active order, checkout, or pricing flow. They collect impression, click, and contextual signals. Banner ad slots are clearly labelled as advertising.
6.5 User controls
- Reset advertising identifier. Reset your GAID in your device's Google settings, or your IDFA via the App Tracking Transparency prompt on iOS 14.5 and above.
- Limit ad tracking. Enable "Limit Ad Tracking" (iOS) or "Opt out of Ads Personalization" (Android) on your device.
- In-app preferences. The HONORICH app exposes an advertising-preferences screen in Settings > Privacy, where you can review the categories of advertising signals used and the controls described above.
7. App-store specific clauses
The HONORICH mobile app is published on Google Play and the Apple App Store. The following store-specific commitments apply.
7.1 Google Play
We comply with the Google Play Developer Distribution Agreement, the Google Play Developer Policy, and Google's Families Policy where relevant. We maintain an accurate Data Safety form for the app, declaring the data categories we collect, the purposes, the security practices, and the user controls. We do not publish the app under Google Play's "Designed for Families" framework because the app is a B2B wholesale management tool, not a children-directed product.
7.2 Apple App Store
We comply with the Apple App Store Review Guidelines, including the privacy-related guidelines. We maintain an accurate App Privacy nutrition label, declare the data categories we collect, and respond to privacy questions in App Store Connect before each release. The app is not published under the Apple Kids Category because the app is a B2B wholesale management tool, not a children-directed product.
7.3 Families and children compliance
Although the app is not directed to children (see section 10), we nonetheless respect the Google Play Designed for Families framework and the Apple Kids Category by ensuring that the app does not include child-directed ad units, does not include social features directed at minors, and does not collect more data than is necessary for the B2B wholesale workflow.
8. International transfers
We are headquartered in Hong Kong and our infrastructure operates across multiple regions. Personal data may be transferred to, and processed in, the United States, the European Economic Area (EEA), Singapore, and Hong Kong.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a third country that is not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by technical and organisational measures (encryption in transit, encryption at rest, access controls, and vendor due diligence). Where the transfer is from another jurisdiction, we apply the equivalent transfer mechanism required by local law.
A list of the countries where our primary processors operate is available on request.
9. Regional rights
Depending on where you live, you may have one or more of the following rights. We honour all of them.
9.1 GDPR (EU / EEA / UK)
If you are in the European Union, the European Economic Area, or the United Kingdom, the General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR give you the right to access, correct, delete, restrict, or port your personal data, to object to processing based on legitimate interests or for direct marketing, to withdraw consent at any time, and to lodge a complaint with your local supervisory authority.
9.2 CCPA and CPRA (California, USA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you the right to know what categories of personal information we collect and share, to correct inaccurate personal information, to delete personal information we have collected, to opt out of the sale or sharing of personal information (we do not sell personal information), to limit the use of sensitive personal information, and to non-discrimination for exercising your rights.
9.3 PIPEDA (Canada)
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the right to access your personal information, to challenge its accuracy, and to withdraw consent, subject to the exceptions permitted by PIPEDA. You may also lodge a complaint with the Office of the Privacy Commissioner of Canada.
9.4 LGPD (Brazil)
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the right to confirmation of the existence of processing, access, correction, anonymisation, portability, deletion, and the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
9.5 PIPL (Mainland China)
If you are in Mainland China, the Personal Information Protection Law (PIPL) gives you the right to know, decide, and limit the processing of your personal information, the right to access, correct, and delete personal information, the right to portability, the right to withdraw consent, and the right to lodge a complaint with the relevant Cyberspace Administration authority. This applies in particular to users of our mobile app located in Mainland China.
9.6 Singapore PDPA
If you are in Singapore, the Personal Data Protection Act 2012 (PDPA) gives you the right to access and correct your personal data, to withdraw consent, and to lodge a complaint with the Personal Data Protection Commission (PDPC).
9.7 Hong Kong PDPO
If you are in Hong Kong, the Personal Data (Privacy) Ordinance (PDPO) gives you the right to be informed of the purpose of collection, the right to access and correct personal data, and the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD).
9.8 How to exercise your rights
To exercise any of the rights above, write to support@hongruix.com or haozhe@hongruix.com with a description of your request and proof of identity. We respond within the timeframes required by applicable law (typically 30 days under GDPR, 45 days under CCPA/CPRA).
10. Children's privacy
The HONORICH Services are not directed to children. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child in violation of this Policy, we will delete it as soon as possible.
10.1 COPPA (United States)
The Children's Online Privacy Protection Act (COPPA) applies to children under the age of 13 in the United States. We do not knowingly collect personal data from children under 13.
10.2 GDPR-K (European Union)
Article 8 of the GDPR sets the default age of consent at 16, with member states permitted to lower it to 13. We do not knowingly collect personal data from children under the age set by their member state.
10.3 Google Play Designed for Families
Our app is not published under the Google Play Designed for Families framework. The HONORICH Services are a B2B wholesale management tool and are not designed or marketed to children.
10.4 Apple Kids Category
Our app is not published under the Apple Kids Category. The HONORICH Services are a B2B wholesale management tool and are not designed or marketed to children.
10.5 Reporting
If you believe we have collected personal data from a child, please write to support@hongruix.com and we will delete the data promptly.
11. Data retention
We retain personal data only for as long as we need it for the purposes described in this Policy, or as required by law.
- Contact-form enquiries. Up to 24 months from the last interaction, unless a longer retention period is required for legal or accounting reasons.
- Wholesale account and order data. Up to 7 years from the last transaction, in line with tax and customs record-keeping obligations.
- App account data. Up to 24 months after the last sign-in, after which the account is deleted or anonymised.
- App analytics. Up to 13 months.
- Ad-attribution data. Up to 90 days, unless a longer retention period is required for tax, accounting, or anti-fraud reasons.
- Server logs. Up to 90 days, then aggregated and anonymised.
When personal data is no longer needed, we either delete it or anonymise it so that it can no longer be associated with you.
12. Security
We protect personal data with a combination of technical and organisational measures.
- Transport encryption. TLS 1.2 or higher for all data in transit between your device and our services.
- At-rest encryption. Industry-standard encryption for personal data stored on our infrastructure.
- Access controls. Role-based access, least-privilege principles, and multi-factor authentication for administrative access.
- Vendor due diligence. We vet every processor we engage with, document the data they handle, and require them to meet a security bar that is at least as high as ours.
- Incident response. We have an incident-response process that includes notification procedures aligned with applicable law (for example, GDPR Article 33 / 34, CCPA breach-notification, and PDPA breach-notification).
No system is perfectly secure. If you have a security concern, please write to support@hongruix.com.
13. Cookies and similar technologies
We use cookies and similar technologies on hongruix.com.
13.1 Categories of cookies
- Strictly necessary. Required for the website to function (for example, session cookies, CSRF tokens). These cookies cannot be disabled.
- Functional. Remember your preferences (for example, language, region, theme). Disabling these will reset your preferences on each return visit.
- Analytics. Help us understand aggregate traffic and usage patterns so that we can improve the site.
- Advertising. Used on any browser-rendered advertising surfaces. These cookies are not used for personalised advertising on the website at this time.
13.2 How to manage cookies
- Browser controls. Most browsers allow you to refuse or delete cookies through their settings. The relevant help pages for major browsers are linked in our cookie banner.
- Cookie banner. The first time you visit hongruix.com you will see a cookie banner that lets you accept or reject non-essential cookies. You can change your selection at any time from the "Cookie settings" link in the website footer.
- Do Not Track. We respect the Do Not Track (DNT) browser signal where technically feasible.
14. Changes to this policy
We may update this Policy from time to time. When we do, we update the "Last updated" date at the top of the Policy. If the change is material — for example, if we add a new ad-mediation platform, broaden the categories of data we collect, or change the purposes for which we use data — we will display an in-app notice and a banner on the website.
Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the updated Policy. If you do not agree with the updated Policy, please stop using the Services and write to support@hongruix.com to close your account.
15. Contact
For any privacy question, data-subject request, or complaint, please contact us.
If you are not satisfied with our response, you may lodge a complaint with your local supervisory authority — for example, the European Data Protection Board (EU), the Information Commissioner's Office (UK), the California Privacy Protection Agency (USA), the Office of the Privacy Commissioner of Canada, the Autoridade Nacional de Proteção de Dados (Brazil), the Personal Data Protection Commission (Singapore), or the Office of the Privacy Commissioner for Personal Data (Hong Kong).
© 2026 HONORICH TRADE CO., LIMITED. All rights reserved.