Privacy Policy
Version: 1.3
Last updated: September 3, 2026
Effective date: September 3, 2026
Website: https://www.hisicar.com
Public privacy-policy URL: https://www.hisicar.com/en/content/privacy-policy
This Privacy Policy contains important information about how HISICAR handles Personal Data. Please read it carefully before using our website, creating an account, contacting us, accepting a pro forma invoice (“PI”), making a payment, arranging vehicle export or using a third-party login, messaging or maps feature.
When you choose Google sign-in, the application shown on Google's OAuth consent screen is HISICAR. The sign-in flow requests only the basic OpenID Connect identity data described in Section 13.1: your Google subject identifier, email address and verification status, and the display name or profile-picture URL that Google supplies. Technical OAuth parameters are processed only for server-side login validation.
Google user data — plain-language summary
HISICAR uses Google Sign-In only to authenticate or bind a HISICAR account. The current authorization request asks for the OpenID Connect scopes openid, email and profile only. When Google supplies them, we receive the stable Google subject identifier (sub), Google account email address, email_verified status, display name and profile-picture URL. We do not request or access Gmail, Google Drive, Calendar, Contacts, YouTube, Google Ads, Google Workspace files or any other Google API data through this sign-in flow.
We use this Google user data only to create or sign in to a HISICAR account, link or unlink the Google login, verify the account email, protect the login against fraud or replay, display the returned name or profile image in the HISICAR account, and provide a user-requested account, inquiry or transaction feature. We do not sell Google user data, use it for advertising, marketing profiles, credit or lending decisions, data-broker activity, a separate Google-data database, or artificial-intelligence/machine-learning training.
We protect Google user data in transit with HTTPS/TLS and keep Google credentials on the server. Access to stored records is limited by least-privilege, role-based controls and audit logging, and records are deleted or anonymised under the retention and deletion rules below.
Google handles the authorization and token exchange under Google's own terms and privacy notice. HISICAR does not send Google user data to Google for any additional purpose. Other disclosure is limited to contracted providers that host, store, deliver or secure the visible sign-in or avatar feature, a recipient you expressly direct for a requested feature, security or abuse investigation, and legally required disclosure. We retain linked Google identity data only while it is needed for the linked HISICAR account or a requested feature. When you unlink Google, we delete the Google binding and stop future Google sign-in; a name or avatar copied into your HISICAR profile may remain as your account profile under the retention rules below until you remove it or close the account. When the account is closed, Google-derived profile fields are deleted or anonymised as part of the account-deletion workflow, subject to a documented legal, security or transaction-record exception. Any residual backup or security-log copy remains only until the applicable rotation or legal-retention period and is not used for another purpose. Temporary authorization codes, state, nonce and token-validation data are used only for login validation and expire or are purged under the retention schedule. To request access, correction or deletion of Google-derived data, email info@hisicar.com with the subject “Google user data deletion or access request”. Section 13.1 contains the controlling, detailed disclosure.
HISICAR's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Contents
- About HISICAR and this Policy
- Defined terms
- Who is responsible for your Personal Data
- When this Policy applies
- Personal Data we collect
- Personal Data relating to other people
- Where Personal Data comes from
- How and why we use Personal Data
- Legal bases for processing
- When information is required
- Sensitive Personal Data
- Cookies, online activity and device information
- Third-party authentication, messaging, payments and maps
- 13.1 Google Sign-In and Google user data
- Artificial intelligence, recommendations and automated review
- How we disclose Personal Data
- Group-company data handling
- International data transfers
- How long we keep Personal Data
- Security
- Your privacy rights and choices
- Marketing communications
- Account closure and deletion
- Region-specific provisions
- Children
- Business information that is not Personal Data
- Changes to this Policy
- Contacting us and making a complaint
1. About HISICAR and this Policy
HISICAR is a business-to-business platform for sourcing, purchasing, preparing, exporting, transporting and supporting new and used vehicles. The platform is intended for overseas business buyers, including dealers, importers, fleet operators, agents and other commercial purchasers.
This Policy explains:
- what Personal Data we collect or receive;
- the people to whom the data relates;
- how and why we use the data;
- the legal grounds on which we rely;
- the organisations with which we disclose data;
- how cross-border transfers work;
- how long data is kept;
- the safeguards we use; and
- the rights and choices available to individuals.
“HISICAR” is a brand and platform name. It is not a substitute for identifying the company responsible for a particular processing activity. The relevant entity is described below and, for a vehicle transaction, in the accepted PI.
2. Defined terms
For this Policy:
Account User means an individual who creates or uses a buyer, partner or authorised business account.
Buyer means the legal entity or commercial purchaser for which an Account User acts. A company is not itself an individual, but information about its representatives, owners and personnel may be Personal Data.
Buyer Representative means an owner, director, beneficial owner, employee, agent, signatory, account administrator or other individual connected with a Buyer.
Group Company means an entity that is under common ownership or control with the website operator and is specifically identified in the Legal Notice or a transaction document. Group affiliation does not automatically make all Group Companies joint controllers.
Personal Data means information relating to an identified or identifiable individual. It includes “personal information,” “personal data,” “personally identifiable information” and similar concepts under applicable law.
Processing means any operation performed on Personal Data, including collecting, recording, organising, storing, reviewing, using, changing, retrieving, disclosing, transmitting, combining, restricting, deleting or anonymising it.
Services means the HISICAR website, accounts, inquiries, customer support, PI and sales process, payment, vehicle inspection and preparation, export, logistics, after-sales, marketing and related compliance services.
Transaction Participant means an individual involved in an inquiry or transaction, such as a representative, payer, beneficial owner, consignee, notify party, final user, driver, broker or service contact.
Visitor means an individual who visits or interacts with our website without necessarily creating an account or completing a transaction.
Vehicle Data means data about a vehicle, its use or location. Vehicle Data is Personal Data when it relates or can reasonably be linked to an individual.
3. Who is responsible for your Personal Data
Responsibility depends on the activity. The entities below do not become joint controllers merely because they share a brand or cooperate on a transaction.
3.1 General website and account services
Unless a page tells you otherwise, the controller or PRC “personal information processor” for the public website, general buyer account and website customer support is:
Shanghai Sitou Technology Co., Ltd. (上海丝投科技有限公司)
Privacy email: info@hisicar.com
3.2 Vehicle inquiries and transactions
The seller and PRC exporter identified in the applicable PI control Personal Data that they need to quote, sell, inspect, prepare, license, export, deliver and support the vehicle. Another Group Company may process data for them under a written service or data-processing agreement, or may act independently for a service that it clearly identifies.
3.3 Stripe payments
For a Stripe checkout displayed by HISICAR, the Stripe contracting merchant and online payment recipient is:
Hong Kong Racer House International Technology Limited
Privacy/payment contact: info@hisicar.com
Unless the accepted PI expressly identifies it as the Vehicle Seller, this Hong Kong company receives the payment as an authorised group collection agent for the Seller. It processes Personal Data needed to initiate, receive, reconcile, refund and defend the payment. Stripe, card networks, financial institutions and fraud-prevention providers may separately determine why and how they process data under their own terms and law.
3.4 Stores, warehouses, clubs and local services
If you deal directly with a Group Company store, warehouse, vehicle club or other local service, the collection notice, appointment record or PI identifies that entity and its role. If two entities jointly determine a purpose and essential means, we will identify the joint arrangement and a contact point instead of relying on the general phrase “HISICAR Group.”
3.5 Representatives
At this Policy's effective date, no EEA, UK, Russian or other local privacy representative is identified in the Legal Notice. A responsible HISICAR entity does not intentionally offer a service in a jurisdiction where a local representative is mandatory unless that representative has been validly appointed and its identity and contact details are published in the Legal Notice and the relevant regional notice.
4. When this Policy applies
This Policy applies when you:
- visit a HISICAR website or landing page;
- create, authenticate, bind, secure or close an account;
- submit a vehicle inquiry, request a quotation or communicate with sales/support;
- act for a Buyer, payer, consignee, final user or other transaction party;
- receive, review or accept a PI or other electronic agreement;
- pay by Stripe, bank transfer or approved in-person cash;
- arrange inspection, preparation, export, shipment, import support, warranty, recall or after-sales service;
- subscribe to an email, WhatsApp, WeChat, Telegram or other communication;
- use a referral, recommendation, chat, map, location or third-party login feature;
- exercise a privacy right, complain or participate in an investigation; or
- otherwise interact with us in connection with the Services.
This Policy does not govern a third party’s independent website, account or app merely because we link to it. Employees and job applicants require separate workforce/recruitment notices. A business partner processing data entirely for its own purposes is responsible for its own notice.
5. Personal Data we collect
The categories below are comprehensive for the Services described, but we collect only data relevant to an enabled feature and legitimate purpose.
5.1 Contact, profile and preference data
- name, display name and job title;
- business and, where justified, personal contact details;
- email address, telephone number and WhatsApp number;
- mailing, billing, registered and delivery address;
- country, region, city, time zone and preferred language;
- communication and accessibility preferences;
- profile image and information you choose to add; and
- marketing subscriptions, consent and opt-out status.
5.2 Account and authentication data
- account and internal user identifiers;
- login name and password hash, but not a readable password;
- email/telephone verification status;
- authentication method and provider;
- login history, session, refresh, MFA and recovery status;
- one-time challenge and binding state;
- account type, role, permissions and organisation membership;
- security alerts, device/session revocations and lockouts; and
- evidence of accepting website terms and privacy notices.
5.3 Third-party identity data
Depending on the provider and permission you select, we may receive:
- Google or Apple subject identifier, name, email, verification status and profile information. Google-specific access, use, sharing, security, retention and deletion rules are in Section 13.1;
- an Apple private-relay email address if you select “Hide My Email”;
- WeChat openid/unionid, nickname, avatar and authorised profile information;
- a verified WhatsApp telephone number used for one-time-password login or binding;
- Telegram subject/user identifier, name, username, profile image, authentication date and, only if separately requested and approved, telephone number or permission for bot messages;
- provider access/identity token metadata needed to validate the authentication; and
- the fact that the account is linked or unlinked.
We do not receive a provider password. Provider scopes are limited to what is shown at the time. Telegram login and Google Maps apply only after they are actually enabled and displayed; their inclusion in this Policy does not mean they are currently active.
5.4 Business and authority data
- legal and trading name, company type and registration number;
- registered office, principal place of business and operating countries;
- tax, customs, importer, dealer and other licence numbers;
- certificate of incorporation, business licence, registry extract and constitutional documents;
- business activity, website, expected volume and intended vehicle use;
- authorised representatives, signatures, powers of attorney and approval limits;
- directors, officers, shareholders, controllers and ultimate beneficial owners;
- ownership percentage and control relationship; and
- evidence that the representative may bind the Buyer.
5.5 Identity and compliance data
Where proportionate to risk or legally required, this may include:
- date of birth, nationality, residence and government identifier;
- passport, national ID or other identity document and verification result;
- proof of address;
- politically exposed person, sanctions, watchlist and adverse-information results;
- ownership/control analysis and possible-match resolution;
- payer identity and relationship to the Buyer;
- source of funds or source of wealth evidence;
- bank-account ownership confirmation;
- final user, final use, destination, transit route, storage and resale plan;
- import/export/re-export permit and end-user certificate;
- risk rating, red flags, reviewer notes, escalation and decision; and
- legally permitted fraud, theft, misuse or prior breach information.
We do not collect an identity document simply because it might be useful. Collection must be supported by an approved risk rule, transaction need or law.
5.6 Inquiry, PI and contract data
- vehicle search and requested specification;
- inquiry, negotiation, quote and reservation information;
- Buyer and representative snapshot used in the PI;
- PI number, version, price, deposit, balance, Incoterm and destination;
- incorporated policy versions and download record;
- clickwrap/e-signature, timestamp, language, IP/device evidence and text hash;
- contract amendments, consents, explanations and authority evidence;
- messages, files, images, audio or video you submit;
- cancellation, claim, complaint, dispute and settlement information; and
- legal hold, evidence and enforcement records.
5.7 Payment and financial data
- amount, currency, due date and payment schedule;
- payer and billing/contact details;
- payment method type and tokenised/provider identifiers;
- Stripe checkout/payment intent/session, settlement and reconciliation status;
- card country, brand and last digits if provided by Stripe;
- fraud/risk/authentication result, refund and chargeback data;
- corporate bank beneficiary snapshot, transfer reference and remittance evidence;
- sending bank, payer account holder and source relationship;
- approved cash-store, redemption code, receipt, amount, currency and receiving staff; and
- finance approvals, ledger allocations, fees, exchange differences and refund destination.
HISICAR is designed so full card numbers and card security codes do not enter or remain on HISICAR servers. Do not send them by email, chat or document upload.
5.8 Vehicle, export and fulfilment data
- VIN/chassis number, registration/title and ownership history;
- make, model, specification, production/registration date and mileage;
- inspection, diagnostic, accident, repair, battery, preparation and condition records;
- photographs, video and document metadata;
- export eligibility, licence, deregistration, customs and tax documentation;
- seller, exporter, consignee, notify party, broker, importer and final user;
- warehouse, carrier, freight forwarder, vessel, route, port and tracking event;
- transport/insurance documents, estimated and actual milestones;
- delivery, acceptance, warranty, parts, after-sales, safety and recall records; and
- vehicle location or connected-vehicle data only where a documented service requires it.
5.9 Communications and customer-support data
- website chat messages and session identifier;
- email and attachments;
- WhatsApp Business, WeChat or Telegram messages sent to our business channel;
- telephone number, call notes and, only after legally adequate notice, call recording/transcript;
- channel permissions, opt-in, template, delivery/read status and opt-out;
- support routing, assigned employee and response history;
- satisfaction feedback and complaint handling; and
- AI-assisted draft/reply metadata where enabled.
WhatsApp, WeChat and Telegram are not emergency channels. Provider systems may independently retain message and account information.
5.10 Website, device and online-activity data
- IP address and, for some analytics, an IP hash;
- date/time, request, browser, operating system, device and user agent;
- approximate country/region inferred from network information;
- referring page, referral code, landing path and campaign source;
- pages and vehicle records viewed, search, click, like, favourite and share event;
- anonymous visitor identifier and linkage to an account after login;
- recommendation input/output and engagement;
- session, security, error, performance and abuse-detection logs;
- Cookie/consent choices and policy/vendor version; and
- bot, rate-limit, suspicious-login and fraud signals.
The Cookie Policy identifies the current first-party Cookie names and duration. Non-essential technologies are subject to regional consent or opt-out requirements.
5.11 Maps and location data
When a map feature is enabled, we may process:
- an address, port, store, warehouse or delivery location you enter;
- map query, selected place, coordinates and route;
- approximate location derived from IP; and
- precise device geolocation only after your affirmative action and browser/device permission, and after any consent required by law.
We do not continuously track precise location merely because a map is visible. Google may independently receive IP, device, query, map interaction and location information when Google Maps loads.
5.12 Rights, investigations and incident data
- identity and authority used to verify a request;
- request, response, search and redaction record;
- complaint, appeal and regulator correspondence;
- security event, affected systems/data, containment and notification; and
- legal advice, privilege, claim, arbitration, court or law-enforcement record.
5.13 Inferences and generated information
We may derive an approximate region, language preference, vehicle interest, business risk, fraud signal, compliance risk, likely support topic or recommended vehicle. We do not infer sensitive traits for advertising. Human review is required before a HISICAR compliance flag becomes a final adverse transaction decision, subject to lawful emergency security blocks.
6. Personal Data relating to other people
If you provide data about a director, owner, employee, payer, consignee, final user or other person, you confirm that:
- the data is accurate and relevant;
- you have a lawful basis and authority to provide it;
- providing it does not breach confidentiality or another person’s rights;
- you have given that person this Policy or another legally sufficient notice where required; and
- you will not submit unnecessary identity, financial, health, family or other sensitive data.
We may contact the individual directly to verify authority or provide a notice. We may refuse or delete information that is excessive or lacks a lawful purpose.
7. Where Personal Data comes from
We receive data from:
- you and the device/browser you use;
- the Buyer and its authorised users;
- a payer, consignee, final user or other transaction participant;
- Google, Apple, Tencent/WeChat, Meta/WhatsApp, Twilio, Telegram or an email/identity provider you choose;
- Hong Kong Racer House International Technology Limited, Stripe, banks, card networks and payment providers;
- sellers, exporters, dealers, vehicle owners and Group Companies providing an identified service;
- inspection, repair, manufacturer, recall, warehouse, logistics, customs, insurance and after-sales providers;
- corporate registries, sanctions/watchlists, government portals and other lawful public sources;
- identity, fraud, security and compliance providers under contract;
- referral partners and agents, where their collection was lawful;
- authorities, courts, arbitral tribunals and professional advisers; and
- information we generate through the Services.
We take reasonable steps to assess source reliability and correct material inaccuracies before relying on them for an adverse decision.
8. How and why we use Personal Data
For Google user data, the more specific limits in Section 13.1 apply and prevail over any broader purpose described below.
8.1 Provide and administer the website
We use data to deliver pages, select language/region, maintain sessions, remember requested preferences, provide search and vehicle information, operate chat, diagnose faults, maintain availability and protect the Services.
8.2 Create, authenticate and secure accounts
We use data to register and verify an account, perform passwordless or third-party login, bind/unbind a provider, issue and refresh sessions, provide MFA/recovery, merge authorised anonymous activity after login, manage permissions and investigate compromise.
8.3 Respond to inquiries and provide support
We use contact, vehicle-interest, business and communication data to answer questions, route the inquiry to an appropriate employee, prepare a quotation, preserve conversation context, respond through the selected channel and improve support quality.
8.4 Verify Buyers and authority
We use business, representative, ownership and authority data to establish who is contracting, whether the signatory may bind the Buyer, whether the Buyer is acting commercially and whether the information is internally consistent.
8.5 Conduct trade, sanctions, fraud and payment-risk checks
We use identity, ownership, payer, destination, route, final-user/use, vehicle and device information to prevent fraud and theft, screen applicable restrictions, avoid unlawful diversion, verify the payment source, investigate anomalies and cooperate with regulated institutions.
8.6 Prepare, form and administer contracts
We use data to create a PI, freeze vehicle/price/customer snapshots, present incorporated policies, record acceptance and authority, manage amendments, reserve a vehicle, administer cancellation and preserve enforceable records.
8.7 Process payments, refunds and disputes
We use payment data to present eligible methods, create a Stripe or bank-transfer instruction, reconcile cleared funds, issue a receipt, allocate deposit/balance, initiate and track refunds, respond to chargebacks, prevent duplicate/fraudulent returns and keep accounting records.
8.8 Inspect, prepare, export and deliver vehicles
We use transaction and Vehicle Data to establish title, conduct inspection/preparation, obtain export licences, make customs declarations, create documents, book carriage, provide tracking, deliver, handle claims and provide after-sales/recall support.
8.9 Personalise and recommend
With consent where required, or under a documented legitimate interest where permitted, we use vehicle views, likes, favourites, shares, inquiries and account preferences to order or recommend vehicles. We provide a non-personalised path where required and do not use personalised recommendation to alter the accepted PI price secretly. Google user data is not used as recommendation input; Section 13.1 controls.
8.10 Communicate service and legal information
We use contact details to send authentication codes, security alerts, PI/payment/shipping updates, document requests, recall/safety notices, complaint responses and material policy changes. These are not marketing merely because they are sent electronically.
8.11 Market our Services
Where permitted, we use contact, business interest and engagement data to send news, inventory or event information and measure a campaign. Consent and opt-out rules are described in Section 21. Authentication-only telephone/email data is not repurposed for marketing without a valid basis. Google user data is not used for marketing or advertising; Section 13.1 controls.
8.12 Improve, audit and develop
We analyse aggregated or appropriately protected data to understand performance, diagnose issues, train staff, test controls, improve search/recommendations, reduce fraud, evaluate service quality and design new features. Before using customer content to train a general-purpose external AI model, we must provide a specific notice, establish a lawful basis, contractually address model use and obtain consent where required. This Policy does not silently authorise unrestricted AI training. Google user data and data derived from it are subject to the stricter limits in Section 13.1.
8.13 Comply with law and protect rights
We use data for corporate, export, customs, tax, accounting, foreign-exchange, network-security, privacy, recall and other legal duties; to answer lawful authority requests; to obtain advice; and to establish, exercise or defend claims. Requests from foreign judicial or law-enforcement bodies for data stored in the PRC are handled through legally permitted channels.
8.14 Business restructuring
If a relevant business or asset is reorganised, financed, sold or acquired, necessary data may be disclosed under confidentiality and due diligence controls. We will not use a restructuring to avoid this Policy or mandatory rights.
9. Legal bases for processing
The basis depends on the person, purpose and jurisdiction. The table below is a framework, not an attempt to replace mandatory local analysis.
| Purpose | Typical Personal Data | Typical legal basis |
|---|---|---|
| Website delivery and security | Device, session, log, account | Contract/requested service; legal obligation; legitimate interest in a secure service |
| Inquiry and requested support | Contact, communications, vehicle interest | Steps at your request; contract; legitimate interest; channel consent where required |
| Account and authentication | Contact, identifiers, security | Contract/requested service; security/legal obligation; legitimate interest |
| Business and authority verification | Corporate, representative, ownership | Contract risk; legal obligation; legitimate interest in identifying counterparties |
| Sanctions/export/fraud review | Identity, ownership, payer, route, use | Legal obligation; public interest/substantial legitimate interest; explicit/separate consent if a local rule requires it for sensitive data |
| PI, sale and fulfilment | Contact, contract, Vehicle Data, logistics | Contract and steps at request; legal obligations |
| Payments and refunds | Payer, transaction, bank/provider data | Contract; legal/accounting obligations; fraud-prevention interests |
| Recommendations and analytics | Online activity and preference | Consent where required; otherwise documented legitimate interest with objection/non-personalised option |
| Marketing | Contact, subscription, engagement | Consent or another specifically permitted local basis; opt-out |
| Precise geolocation | Device location | User request and prior revocable consent where required |
| Claims and investigations | Contract, communication, evidence | Legal obligation; establishment/exercise/defence of claims; legitimate interest |
9.1 PRC statutory bases
Under the Personal Information Protection Law, processing may be necessary to conclude or perform a contract at an individual’s request, necessary for statutory duties, based on consent, or supported by another statutory ground. We do not describe all processing as “consent” when withdrawal cannot realistically stop processing needed for a contract or law. Separate consent is obtained where required, including for certain sensitive information, disclosures to another processor and cross-border transfers, unless a valid exception applies.
9.2 EEA and UK bases
Where GDPR or UK GDPR applies, we identify the relevant controller, purpose and basis: contract, steps requested before contract, legal obligation, legitimate interests, consent, vital interests or public task only where actually available. A Buyer’s contract does not automatically make every use of its employee’s data “contract necessary.” Legitimate-interest uses are supported by a balancing assessment. Consent is not used where there is no genuine choice.
10. When information is required
We identify required fields and explain the consequence of not providing them. You can ordinarily browse public inventory without creating an account. However, we may be unable to:
- authenticate you without the required login identifier;
- issue a reliable PI without Buyer and authority information;
- accept funds without payer and reconciliation data;
- proceed with a high-risk transaction without beneficial-owner, final-user/use or source-of-funds information;
- export without required vehicle, customs and consignee data; or
- deliver or support a vehicle without necessary destination/contact information.
Optional profile data, precise location, marketing, expanded provider permissions and non-essential analytics can be refused without losing unrelated core functions.
11. Sensitive Personal Data
Depending on law, identity documents, financial-account/payment data, precise location, biometric verification, government identifiers, sanctions/PEP results, certain nationality/residence data, and connected-vehicle location may be sensitive.
Before processing sensitive data, we:
- establish a specific and necessary purpose;
- collect the minimum fields and avoid unnecessary copies;
- give an enhanced notice about need and impact;
- obtain separate/explicit consent where required;
- restrict access and downloads;
- encrypt, redact or tokenise where appropriate;
- complete a privacy impact assessment when required;
- define a shorter review/deletion cycle; and
- log access, disclosure and deletion.
We do not ask you to send full card details, authentication secrets or unnecessary identity documents through ordinary messages.
12. Cookies, online activity and device information
The Cookie Policy lists our known first-party Cookies, including authentication, temporary authentication/MFA state, language, liked vehicles, anonymous visitor and referral attribution Cookies. It also explains categories, duration and controls.
In jurisdictions requiring prior consent, non-essential analytics, behavioural recommendation, referral attribution, advertising and optional third-party map technologies must remain off until valid consent. Continuing to browse is not consent. Withdrawal must stop future non-essential use as easily as acceptance.
Where one anonymous identifier can support both a user-requested function and recommendation activity, it must be technically separated or its use must be limited to the requested function and security until the required consent is recorded. Optional analytics or recommendation use is not permitted before that point. A Secure or HttpOnly attribute does not by itself make a Cookie legally necessary.
13. Third-party authentication, messaging, payments and maps
The Third-Party Services Notice explains each integration in detail. In summary:
- Google login: Google authenticates you and sends approved identity claims. Section 13.1 explains exactly which Google user data the current sign-in flow accesses and how Google’s Limited Use requirements apply. Google’s terms and privacy notice also apply.
- Apple login: Apple may send a stable identifier, name and email; a private-relay address may be used.
- WeChat login: Tencent/WeChat provides openid/unionid and approved profile information for a website login.
- Email: HISICAR may use a password, verification code or magic link. The email delivery provider processes the address, message, security and delivery-status data needed to send and protect the communication under written data-protection and security requirements.
- WhatsApp: login/binding uses a one-time code to a WhatsApp telephone number rather than a generic Meta OAuth login. WhatsApp Business support separately processes messages and opt-in/opt-out data. Meta direct service or Twilio must be identified in the vendor register.
- Telegram: if enabled, Telegram Login/OIDC may provide profile claims and optional telephone/message permission only after separate approval. Current social/contact references do not by themselves mean Telegram login is active.
- Stripe: Hong Kong Racer House International Technology Limited is the stated Stripe merchant/payment recipient. Stripe and financial partners process transaction, authentication, fraud, refund and dispute data under their own roles.
- Google Maps: if enabled, Google receives device, query and map interaction information; precise location requires the appropriate user action, permission and consent.
We minimise scopes, validate authentication on the server, register approved domains/redirects, protect client secrets and allow unlinking where supported. Unlinking a provider stops future login through that provider but does not automatically delete the HISICAR account or records needed for transactions and law.
13.1 Google Sign-In and Google user data
Application identification
Application name shown on Google's OAuth consent screen: HISICAR.
Application operator: Shanghai Sitou Technology Co., Ltd.
HISICAR sign-in surfaces: https://www.hisicar.com (public site) and https://dashboard.hisicar.com (management console)
Public privacy-policy URL: https://www.hisicar.com/en/content/privacy-policy
Privacy contact: info@hisicar.com
This subsection describes the HISICAR Google OAuth application and website sign-in. It applies when the Google sign-in option is displayed and enabled for a HISICAR public or console login. Google Sign-In is optional. Google Maps is a separate feature and is not covered by this subsection.
Google user data is used only for Google Account sign-in or binding, security, email verification, displaying returned profile data and user-requested account or transaction communications. It is not used for general analytics, vehicle recommendations, marketing, advertising, separate database creation or artificial-intelligence/machine-learning training.
Data collection — data accessed from Google
When you select the Google sign-in option, HISICAR collects and processes the Google user data returned for the OpenID Connect scopes openid, email and profile. The current authorization request uses only those three scopes:
| Scope | Data made available to HISICAR and the sign-in purpose |
|---|---|
openid | A stable Google subject identifier (sub) to associate the Google Account with a HISICAR account |
email | The Google account email address and email_verified status for account contact and verification |
profile | Basic profile claims, such as a display name and profile-picture URL, when Google returns them |
In plain terms, HISICAR accesses your Google Account identifier, email address, email-verification status, display name and profile-picture URL when Google supplies those claims.
The current flow collects the following data when Google provides it within those scopes:
- the stable Google subject identifier (
sub), which we use as the external identity key rather than using an email address as a unique key; - the Google account email address and its
email_verifiedstatus; and - basic profile claims made available by the
profilescope, including a display name and profile-picture URL. The current server does not separately read or retain a given name, family name, profile URL or locale; any future use of an additional claim requires the notice and consent change described below.
The application stores the Google subject identifier (sub), email, email_verified status and, when Google provides them, the returned display name and profile-picture URL. It may save the returned profile-picture URL as your HISICAR avatar when no existing avatar is present. It temporarily processes the authorization code, ID token, issuer, audience, expiry and nonce only to validate the server-side login. We do not receive your Google password, request offline access, or retain a Google access token or refresh token as a reusable credential. We do not request or access Gmail, Google Drive, Calendar, Contacts, YouTube, Google Ads, Google Workspace files or other Google API data through Google Sign-In.
Google processes the authorization request and token-exchange request needed to authenticate you, then returns an authorization response to HISICAR. Google handles its processing under its own terms and privacy policy. HISICAR does not send Google user data to Google for any additional purpose.
Data usage — how Google user data is used
Data usage: We use Google user data, and data derived from it, only to provide or improve user-facing HISICAR functionality that is visible in the account and sign-in experience. This includes:
- creating or authenticating a HISICAR account and binding or unbinding the Google identity;
- verifying the account email, maintaining the linked-login record and protecting sessions against fraud, replay and compromise;
- displaying the returned name or profile image in your HISICAR account/profile; and
- completing a user-requested account, inquiry or transaction feature using the HISICAR contact details needed for that feature.
The returned email may be used for account, security and user-requested transaction communications only; it is not used for optional marketing or advertising under this subsection.
When object storage is configured, we may copy the avatar image to HISICAR-controlled object storage or a CDN solely to display that avatar. Google user data is not used as an input to vehicle recommendations or behavioral profiling.
Google user data and its raw, aggregated, anonymized or derived forms are not used for any advertising or marketing, including targeted advertising and serving or displaying user, personalized, retargeted or interest-based advertisements; sale, rental or transfer to advertising platforms, data brokers or information resellers; determining credit-worthiness or for lending purposes; creating a separate database of Google user data; or developing, improving or training generalized, foundational or non-personalized artificial-intelligence or machine-learning models. Any storage is limited to the minimum linked-account or feature record needed for the visible feature. We do not access, aggregate or analyse Google user data for display, sale or distribution to a third party conducting surveillance. Google Workspace APIs are not used to develop, improve or train non-personalized AI/ML models.
For Google user data, this subsection controls over any broader statement elsewhere in this Policy about purpose, access, recipient, transfer, retention or deletion. This precedence applies to the broader use, disclosure, transfer, retention and deletion statements in Sections 8, 14, 15, 16, 17 and 21. If the separate Third-Party Services Notice is less specific, this subsection controls for Google user data.
Data sharing — sharing and onward transfer
Data sharing: We do not sell Google user data. Google receives the authorization and token-exchange requests needed to authenticate you. HISICAR does not send Google user data to Google for any additional purpose. Other recipients are limited to the following, and only to the minimum extent needed:
- to contracted hosting, database, object-storage, CDN, email-delivery or security providers that support the visible sign-in, account or avatar feature, subject to confidentiality, access controls and the affirmative consent required by the Google consent screen and any applicable HISICAR feature-specific notice;
- to a recipient you expressly direct as part of a requested account, inquiry or transaction feature, with your affirmative consent and limited to the HISICAR contact information needed for that feature;
- for security, fraud or abuse investigation;
- to comply with an applicable law or binding legal process; or
- as part of a merger, acquisition or sale of developer assets only after your explicit prior consent.
The contracted processor categories above are limited to the providers needed to host, store, deliver, secure or operate the visible HISICAR feature. The identity, role and processing location of the currently enabled provider can be requested from info@hisicar.com. We do not share Google user data with advertisers, data brokers, information resellers or unrelated third parties except as expressly described above; where an exception requires consent, we obtain it.
We do not intentionally disclose raw Google authorization codes, ID tokens, access or refresh tokens or the Google subject identifier to sellers, exporters, other customers, advertisers, data brokers, information resellers or unrelated Group Companies. Any transient gateway or logging processing is limited to security and operations controls described below. A general recipient category in Section 15 or Section 16 does not by itself authorize a Google-data transfer; this subsection controls if another section is broader. Employees, agents, contractors and successors who handle Google user data must follow the same restrictions. Humans may not inspect Google credentials. Access to a specific Google-derived field is limited to your affirmative agreement to view that field for support, a security or abuse investigation, legal compliance, or permitted aggregated internal operations; access is role-based and logged.
Data retention and deletion — security and lifecycle
The current server flow uses HTTPS/TLS, validates the authorization state and nonce and checks the Google issuer, audience, expiry and verified-email claim where relevant. Google client secrets remain server-side. Google-derived fields are held in access-controlled HISICAR systems under the safeguards in Section 19, including least-privilege access, encryption or equivalent protection at rest where appropriate, audit logging and controlled deletion. We do not expose Google credentials to the browser or include them in ordinary user-facing responses. Any request metadata retained in technical logs is subject to the applicable retention and access controls.
The temporary OAuth state and nonce expire after about 10 minutes and are purged under the retention schedule (currently normally within 7 days). A console binding flow may also create a short-lived binding ticket containing the Google subject identifier, email, verification status and basic profile metadata; it expires after about 10 minutes and cannot be used after expiry. The ticket record is retained only for the binding, security or lawful purpose; after expiry it is removed or anonymised through the applicable scheduled retention or account-deletion cleanup, subject to a documented legal or security exception. The application database does not persist the authorization code or ID token as reusable Google credentials after validation. Infrastructure or gateway logs may retain callback request metadata, potentially including URL query parameters, under the applicable log-retention and access controls; those logs are not used as Google credentials. The Google binding record and Google-derived account fields are retained only while needed for the linked account, a requested feature, security, or a mandatory legal or transaction record. The account-profile and transaction retention periods in Section 18 apply; when a period ends, the data is securely deleted or irreversibly anonymised unless a documented legal hold or other lawful exception applies.
Unless a documented legal, security or transaction-record exception applies, the Google subject identifier, email and verification status are retained only while the Google login remains linked or the feature requires them; unlinking deletes that provider binding. A display name or avatar copied into the HISICAR account profile is treated as account-profile data and follows Section 18 until you remove it or close the account. On account closure, the profile fields are deleted or anonymised, and any residual backup or security-log copy is allowed to expire under the applicable rotation schedule; retained remnants are not used for authentication, advertising, profiling or any other purpose.
You may remove HISICAR from your Google Account third-party connections to stop future Google authorization. You may also unlink Google in HISICAR account settings when another permitted login method remains. Unlinking removes the Google binding and stops future Google sign-in, but does not by itself erase a copied name, email, profile image or records that HISICAR must retain. To request access, correction or deletion, email info@hisicar.com with the subject “Google user data deletion or access request”; we will provide a secure verification channel when needed. We delete or anonymise Google-derived data that is no longer required and restrict any retained data to the lawful purpose; the deletion route and exceptions in Sections 20 and 22 apply.
If we add a Google scope, access a new category of Google user data, change how we access, use, store, share, transfer, retain or delete it, or introduce a materially different purpose or recipient, we will update this Policy and the relevant in-product notice and obtain fresh consent before making that change. Our handling of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Official provider information:
14. Artificial intelligence, recommendations and automated review
Google user data and data derived from it are subject to the specific restrictions in Section 13.1 throughout this section.
14.1 Recommendations
We may use recommendation software to rank vehicles based on views, likes, favourites, shares, inquiries and selected preferences. Recommendation affects presentation, not the legal terms of an accepted PI. Where required, you can choose a non-personalised view or object.
14.2 Support assistance
We may use AI to classify a support topic, retrieve approved knowledge or draft a response. A draft can be reviewed by an authorised employee before sending according to the configured policy. We must not ask an AI service to make binding legal, credit, sanctions, pricing or vehicle-condition decisions without an approved governance process and legally required notice.
14.3 Fraud and compliance flags
Rules or providers may generate a risk signal. HISICAR will provide meaningful human review before a final adverse transaction decision, unless an immediate temporary block is reasonably necessary for security or a regulated provider independently declines. You may ask for review through info@hisicar.com where law provides that right.
14.4 Model training
Customer messages, identity documents, PI content and transaction records are not made available for unrestricted external model training merely because AI assistance exists. Any materially different model-training use requires a documented purpose, vendor terms, minimisation, legal basis, risk assessment and additional notice/consent where required. Google user data is not used to develop, improve or train generalized, foundational or non-personalized AI/ML models; Section 13.1 controls.
15. How we disclose Personal Data
We disclose the minimum data reasonably needed to the following categories. Any disclosure of Google user data is additionally limited by Section 13.1; a category below does not itself authorize a Google-data transfer.
15.1 Buyer and authorised users
We make account, inquiry, PI, payment, fulfilment and support data available to authorised Buyer users according to roles. The Buyer is responsible for managing its users and promptly removing access.
15.2 Seller, exporter and identified Group Companies
We disclose data to the seller, PRC exporter, Hong Kong payment recipient, store, warehouse or service company identified for the transaction. Section 16 explains why “same group” is not a blanket disclosure authority.
15.3 Authentication and communication providers
Google, Apple, Tencent/WeChat, Meta/WhatsApp, Twilio, Telegram and the actual email provider receive data needed to perform the feature you select. Optional phone or messaging permission is not requested unless separately presented.
Google user data is subject to the stricter access and transfer limits in Section 13.1. The provider list above does not by itself authorize any broader Google-data disclosure.
15.4 Payment and financial parties
We disclose data to Hong Kong Racer House International Technology Limited, Stripe, acquirers, issuers, card networks, banks, payment methods, fraud services, accountants and refund/dispute handlers to process, reconcile, authenticate, protect and evidence a payment.
15.5 Vehicle and fulfilment providers
We disclose necessary data to vehicle owners/sellers, inspection and preparation facilities, manufacturers/recall systems, parts/after-sales providers, warehouses, freight forwarders, carriers, ports, tracking providers, customs brokers, insurers and destination agents.
15.6 Technology and professional service providers
Hosting, cloud storage, CDN, security, logging, support, recommendation, document, translation and professional providers may process data under contract and access controls. Before an active provider receives production Personal Data, its identity, service, data, role, location and transfer mechanism must be recorded in the internal vendor register. You may request information about a provider relevant to your data from info@hisicar.com.
15.7 Authorities and legal recipients
We disclose data where lawfully required to customs, commerce, tax, foreign-exchange, police, courts, arbitral tribunals, regulators, licence authorities or other competent bodies; or where necessary to protect rights, safety and lawful trade. We assess authority, scope, jurisdiction and proportionality, and notify you where lawful.
15.8 Corporate transactions
Potential investors, buyers, sellers, lenders and advisers may receive limited data under confidentiality for a genuine transaction. After a completed transfer, affected individuals receive notice where law requires.
15.9 At your direction
We may disclose data when you direct us to an inspector, agent, broker, bank or other recipient. We verify authority and explain when the recipient will use data independently.
15.10 No sale of Personal Data
We do not exchange Personal Data for money as a data-broker business. We do not enable behavioural-advertising disclosures that local law defines as “sale” or “sharing” unless they are separately disclosed, lawfully enabled and accompanied by required opt-out/consent rights.
16. Group-company data handling
The HISICAR-related group includes the companies listed in the Legal Notice, including Shanghai Sitou Technology Co., Ltd., identified PRC vehicle/export/service companies and Hong Kong Racer House International Technology Limited.
Group companies may receive data only where:
- they are named as a transaction party;
- they perform an identified service under instructions and a processing agreement;
- they independently need the data for a disclosed legal purpose; or
- a properly documented joint-control arrangement applies.
Group affiliation does not authorise unrestricted central access. Intercompany agreements must cover purpose, instructions, security, confidentiality, cross-border transfer, rights requests, incidents, retention, audit and deletion/return. Access is role-based and logged. A Group Company may not use transaction data for unrelated marketing merely because another entity collected it. Google user data remains subject to Section 13.1 and is not shared merely because an entity is in the same group.
17. International data transfers
Any international transfer of Google user data is subject to the narrower recipient, consent and purpose limits in Section 13.1.
17.1 Why transfers occur
HISICAR is a cross-border vehicle export service. Personal Data may be transferred from your country to China and Hong Kong, and to the countries where an identified seller, exporter, payment provider, warehouse, carrier, consignee, support provider or authority operates.
17.2 Safeguards
Before a restricted transfer, the responsible entity must:
- map the data, purpose, source, destination and recipient;
- minimise and, where practicable, pseudonymise or encrypt it;
- identify controller/processor roles;
- assess destination law and practical risk;
- select a valid mechanism and execute required documents;
- implement supplementary technical/contractual controls;
- complete an impact assessment and regulator filing/assessment where required; and
- provide notices and obtain separate consent where the applicable law requires it.
Mechanisms may include a PRC security assessment, standard contract, certification or lawful exemption; EEA Standard Contractual Clauses with a transfer impact assessment and supplementary measures; UK IDTA or UK Addendum; approved certification; adequacy; or another legally recognised mechanism. A privacy policy or general consent does not replace a mandatory transfer instrument.
17.3 Government access
We review binding government requests and seek to narrow excessive requests. We do not directly provide data stored in the PRC to a foreign judicial or law-enforcement body where PRC law requires approval or an official cooperation channel.
18. How long we keep Personal Data
We apply a documented retention schedule. A longer period applies only where reasonably necessary for law, accounting/tax/customs/export, limitation, recall/safety, dispute, security, sanctions records or legal hold.
| Category | Retention rule |
|---|---|
| Public website security logs | At least the applicable legal minimum; PRC network logs are generally retained for no less than six months |
| Temporary OAuth/OTP/MFA state | Expires after the configured challenge period (Google OAuth state/nonce is usually 10 minutes) and is purged under the retention schedule, currently normally within 7 days |
| Pending OAuth binding ticket | Expires after about 10 minutes, cannot be reused after expiry, and is removed or anonymised through scheduled retention or account-deletion cleanup when no longer needed, subject to documented legal or security exceptions |
| Consent and terms evidence | Duration of the relationship/transaction plus the applicable claim and defence period |
| Account profile (excluding Google-derived fields) | While active and for 3 years after closure, except transaction/legal records retained below |
| Google binding identifiers, email and verification status | While the Google login is linked or the feature requires them; the provider binding is deleted after unlinking, with only limited residual backup/security-log retention until the applicable rotation or legal period |
| Google-derived display name or avatar copied into the account profile | While needed for the account profile and up to the applicable account-profile period; deleted or anonymised on account closure, subject to documented legal, security or transaction-record exceptions |
| Unsuccessful inquiry and ordinary support | 3 years after the last interaction, unless linked to a deal, complaint, security event or legal hold |
| PI, contract, vehicle, export, customs, payment, tax, refund and chargeback | 10 years after completion or termination, or any longer mandatory accounting, tax, customs or claim period |
| E-commerce transaction information | At least three years after the transaction under the PRC E-Commerce Law, or longer if another rule/claim requires |
| Compliance screening and end-use records | 10 years after completion or termination, or longer where applicable trade law requires |
| Warranty, recall and safety | Warranty/service life and the period reasonably needed for recall, product safety and claims |
| Marketing subscription | Until withdrawal/opt-out or approved inactivity deletion; minimal suppression record retained to honour the opt-out |
| Precise location | Up to 90 days after the requested map use, or for the active transaction and claim period when location is part of delivery evidence; no indefinite raw-location history |
When a period expires, data is securely deleted, irreversibly anonymised, or isolated under a documented legal hold. Backups expire through the protected rotation schedule. Anonymised statistics are not retained as Personal Data if re-identification is not reasonably possible.
19. Security
We maintain safeguards proportionate to the nature, volume and risk, including:
- data inventory, classification and ownership;
- least-privilege and role-based access;
- strong authentication and MFA for privileged access;
- encryption in transit and appropriate protection at rest;
- tokenisation/hosted payment interfaces and no storage of full card security data;
- separation and rotation of secrets;
- secure development, code review, dependency and vulnerability management;
- network, endpoint, malware and abuse protection;
- logging, alerting, audit trails and anomaly investigation;
- backups, restoration testing, continuity and disaster recovery;
- supplier due diligence, processing contracts and access termination;
- privacy/security training and confidentiality duties;
- physical and cash-desk controls where applicable;
- incident plans, exercises and evidence preservation; and
- periodic privacy, security and compliance audits.
No internet service can promise absolute security. If an incident occurs, we investigate, contain, remediate, assess risk, preserve evidence and notify affected individuals and authorities within the period required by applicable law. Report a suspected incident to info@hisicar.com; do not include sensitive credentials in the report.
20. Your privacy rights and choices
Depending on the law that applies, you may have the right to:
- know whether and why we process Personal Data;
- receive the required privacy information;
- access and obtain a copy;
- correct inaccurate or complete incomplete data;
- request deletion;
- restrict processing;
- object to legitimate-interest processing;
- withdraw consent as easily as it was given;
- object to or opt out of direct marketing;
- receive certain data in a portable format;
- request explanation and human review of certain automated decisions;
- close an account;
- designate another person or authorised agent where law permits;
- appeal a denied request; and
- complain to a privacy regulator or seek a judicial remedy.
20.1 How to make a request
Send a request to info@hisicar.com. If an authenticated account tool or Data Rights Request form is displayed, it may also be used. State the right, account/company, relevant transaction and preferred response channel. Do not send unnecessary identity documents initially.
20.2 Verification and authorised agents
We verify identity and authority in a proportionate way. We may ask an agent for a signed authorisation and may confirm directly with the individual. We do not use request-verification data for unrelated purposes.
20.3 Response
We acknowledge and respond within the applicable statutory time. We may extend only where law permits and will explain the reason. If we deny or limit a request, we explain the legal basis and available appeal/complaint route, unless prohibited.
20.4 Limits
Rights may be limited where necessary to protect another person, trade secrets, legal privilege, security, fraud prevention, a binding legal duty or the establishment/defence of claims. We do not charge unless law permits a reasonable fee for a manifestly unfounded or excessive request.
20.5 Non-discrimination
We do not retaliate or deny unrelated service merely because a person exercises a privacy right. Some data remains necessary to authenticate, contract, pay, export or comply with law, and we explain that consequence.
21. Marketing communications
We distinguish marketing from transactional, security, compliance, payment, shipping, recall and support communications.
HISICAR must not send optional marketing through a channel unless it has documented the required consent or other specifically permitted local basis and has a tested, functional unsubscribe or channel-specific opt-out with suppression enforcement. Where those controls are not operational, marketing through that channel remains disabled.
When marketing is lawfully enabled, the consent identifies the sender and channel and is not bundled with unrelated contract acceptance; every message identifies the sender; opt-outs are processed promptly; and a minimal suppression record prevents the address or number from being re-added. Opting out of marketing does not prevent messages necessary for an active account or transaction.
Provider permission to message through WhatsApp or Telegram does not by itself authorise marketing. Any enabled use must also satisfy provider template, window, opt-in and opt-out requirements.
22. Account closure and deletion
You may request account closure through info@hisicar.com and, when displayed, the authenticated account settings. Closure disables future ordinary use after security and pending-transaction checks. It does not automatically:
- cancel an accepted PI or payment obligation;
- remove records required for export, customs, tax, accounting, warranty, recall or law;
- erase another party’s legitimate copy;
- delete evidence needed for fraud, security, chargeback, complaint or claim; or
- revoke a third-party provider account.
We delete or anonymise non-required profile and activity data according to the approved retention schedule and restrict retained records to the allowed purpose. Unlinking Google, Apple, WeChat, WhatsApp or Telegram is separate from closing the HISICAR account.
For Google-derived data, the more specific unlinking, access, retention and deletion rules in Section 13.1 apply.
23. Region-specific provisions
These provisions supplement the general Policy. The most protective mandatory rule prevails if there is a conflict.
23.1 People’s Republic of China
For processing subject to PRC law:
- the identified entity acts as the Personal Information Processor or entrusted processor for the stated activity;
- collection follows legality, propriety, necessity, openness, minimum scope and data-quality principles;
- consent is informed, voluntary, explicit and revocable where consent is the basis;
- separate consent is obtained where required for sensitive information, disclosure to another processor, public disclosure and cross-border transfer;
- a personal information protection impact assessment is completed for sensitive information, automated decision-making with major impact, entrusted/disclosure/cross-border processing and other high-risk activities;
- entrusted-processing and recipient agreements define purpose, period, method, categories, protection and return/deletion;
- applicable data-export security assessment, standard contract, certification or exemption is documented;
- requests are supported through a convenient mechanism; and
- incidents and foreign authority requests are handled under PRC requirements.
The PRC privacy contact is info@hisicar.com. You may complain to the competent cyberspace or other authority.
23.2 European Economic Area
GDPR may apply when a responsible HISICAR entity intentionally offers goods/services to individuals in the EEA or monitors their behaviour there. This includes Personal Data of B2B contacts and beneficial owners.
Before EEA targeted launch, the responsible entity must complete and publish:
- Article 13/14 information and legal bases;
- legitimate-interest assessments;
- valid ePrivacy Cookie controls;
- controller/processor and joint-controller arrangements;
- EEA Standard Contractual Clauses, transfer impact assessment and supplementary measures where required;
- a Data Protection Officer where legally required; and
- an Article 27 representative unless an exception clearly applies.
Requests concerning EEA processing may be sent to info@hisicar.com. If an Article 27 representative is legally required for an enabled EEA service, its current identity and contact details will be displayed in the website Legal Notice before that service is offered.
You may complain to a supervisory authority in the country of habitual residence, work or alleged infringement. The list is available through the European Data Protection Board.
23.3 United Kingdom
Where UK GDPR and PECR apply, the rights and obligations in this Policy are interpreted under UK law. Before targeted launch we must assess and publish a UK representative, implement PECR-compliant Cookie/marketing controls and use a valid restricted-transfer mechanism, such as the UK IDTA or UK Addendum where required. EEA SCCs alone do not automatically cover a UK restricted transfer.
Requests concerning UK processing may be sent to info@hisicar.com. If a UK representative is legally required for an enabled UK service, its current identity and contact details will be displayed in the website Legal Notice before that service is offered. The UK complaint authority is the Information Commissioner’s Office.
23.4 Russia
Targeted Russian registration, inquiry or transaction remains unavailable unless the responsible entity has implemented and documented:
- the required initial recording/storage of Russian citizens’ data in Russia;
- operator notification/registration;
- Russian-language privacy notice and consent;
- cross-border-transfer notification, assessment and destination controls;
- local database and remote-access architecture;
- retention, security and regulator-response procedures; and
- local contact and data-subject rights process.
Russian privacy requests may be sent to info@hisicar.com. Targeted Russian data collection remains unavailable until the required operator, database, localisation, notice, consent, transfer and rights arrangements are operational and the legally required details are published.
23.5 South Africa
Where POPIA applies, the responsible party processes information lawfully and minimally, maintains security safeguards, supports access/correction/objection, complies with direct-marketing restrictions, notifies security compromises and satisfies section 72 cross-border requirements. The Information Officer can be contacted through info@hisicar.com. Complaints may be made to the Information Regulator using current official contact details.
23.6 Nigeria
Where the Nigeria Data Protection Act applies, the responsible controller/processor establishes a lawful basis, provides notice, honours rights, protects transfers, conducts required assessments, appoints a DPO and registers as a data controller/processor of major importance where applicable. The privacy contact is info@hisicar.com.
23.7 Kenya
Where the Kenya Data Protection Act applies, the responsible controller/processor meets applicable registration, lawful-processing, notice, data-subject rights, security, breach and cross-border requirements. The privacy contact is info@hisicar.com.
23.8 Other countries
“Europe,” “Central Asia” and “Africa” are not single privacy jurisdictions. We conduct a country launch review and publish any mandatory local notice, representative, localisation, registration, language, rights or transfer terms before targeted collection.
24. Children
The Services are intended for adult business users and are not directed to children. We do not knowingly create a child Buyer account or target children with marketing. If limited information about a minor is genuinely required for a lawful consignee or family contact, it may be processed only where necessary, with appropriate guardian authority and enhanced protection. Contact info@hisicar.com if you believe a child’s data was submitted improperly.
25. Business information that is not Personal Data
Information about a legal entity, vehicle or shipment is not always Personal Data. This Policy applies when that information identifies or can reasonably be linked to an individual, such as a sole trader, named representative, driver, payer or vehicle user. Confidential business information may still be protected by contract, trade-secret or other law even when it is not Personal Data.
26. Changes to this Policy
We assign a version and effective date to each Policy. Material changes are summarised and communicated through an appropriate channel. We obtain fresh consent where a new purpose or law requires it. Posting an update does not retroactively rewrite a frozen PI/contract record or make an incompatible new purpose lawful.
Prior versions and their effective periods are available on request from info@hisicar.com.
27. Contacting us and making a complaint
For a privacy question or request:
Privacy Team
Shanghai Sitou Technology Co., Ltd.
Email: info@hisicar.com
For a Stripe-payment privacy issue involving the Hong Kong merchant:
Hong Kong Racer House International Technology Limited
Email: info@hisicar.com
We will acknowledge a complaint, investigate it independently of the staff directly involved where practicable, explain the result and give the available escalation route. You may also complain to the competent privacy authority in your country. Contacting us first is welcome but does not remove a statutory right to approach a regulator or court.