PRIVACY POLICY

EFFECTIVE DATE: [8 APRIL, 2025]


1. DATA CONTROLLER
Business Name: [Haugly]
Registered Address:
Suite 1515, 611Yueken Road, Tianhe District,
Guangzhou City, Guangdong Province, China 510000
Email: info@haugly.com


2. INFORMATION WE COLLECT
2.1 DIRECTLY PROVIDED DATA

  • Order details (name, address, phone, email)
  • Account credentials (username, encrypted password)
  • Payment information processed via Stripe/PayPal

2.2 AUTOMATICALLY COLLECTED DATA

  • Technical identifiers (IP address, browser type via Google Analytics 4)
  • Behavioral data (page clickstreams, cart activities via WooCommerce)
  • Advertising profiles (anonymized through Facebook Pixel)

2.3 THIRD-PARTY SOURCES

  • Shipment status from logistics providers (e.g., DHL API)
  • Email engagement metrics (e.g., Mailchimp open rates)

3. LEGAL BASIS FOR PROCESSING
We process data under:

  • Contractual Necessity: Order fulfillment, shipment tracking (GDPR Art.6(1)(b))
  • Legitimate Interests: Fraud prevention, service optimization (GDPR Art.6(1)(f))
  • Explicit Consent: Cookie consent, marketing subscriptions (PIPL Art.13)

4. INTERNATIONAL DATA TRANSFERS
Your data may be transferred to:

  • EU: Protected by Standard Contractual Clauses (SCCs)
  • USA: Through Privacy Shield-certified providers (e.g., Cloudflare)
  • Asia: Routed via Tencent Cloud Hong Kong data center

5. YOUR RIGHTS
Depending on residency, you may:
✅ Access/delete data via [Account > Privacy Settings]
✅ Rectify inaccuracies by emailing info@haugly.com (72h response)
✅ Opt-out of profiling via Google Analytics opt-out plugin
✅ Request data portability (CSV export of order history)

China-Specific Rights:

  • Withdraw consent under PIPL Article 44
  • Report violations via 12321.cn platform

6. SECURITY MEASURES
We implement WordPress-specific protections:

  • Encryption: TLS 1.3 + WooCommerce database encryption
  • Access Control: Wordfence real-time threat blocking
  • Audits: Annual penetration testing by Acunetix

7. CHILDREN’S PRIVACY
We prohibit registrations from users under:

  • 14 years (China PIPL standard)
  • 16 years (GDPR standard)
    Any detected minor data will be deleted per PIPL Article 31.

8. POLICY UPDATES
Material changes will be notified through:

  • Site-wide banner notices (30-day display)
  • Summary emails to registered accounts
  • Mandatory reconfirmation upon next login

9. DISPUTE RESOLUTION
Preferred through Shanwei Online Arbitration Court. EU residents may contact their local Data Protection Authority (DPA).