Third-Party Services Notice
Version: 1.0
Last updated: August 20, 2026
Effective date: September 1, 2026
Website: https://www.hisicar.com
1. Scope
This Notice explains how HISICAR uses third-party authentication, email, messaging, payment and map services.
The availability of a service depends on country, device, provider rules and HISICAR configuration. A service is used only when it is displayed or otherwise enabled for the relevant function. Including a service in this Notice does not mean every service is currently active in every market.
Third parties have their own terms and privacy practices. The HISICAR Privacy Policy separately explains how HISICAR processes Personal Data received through an integration.
2. Service summary
| Service | HISICAR use | Current status/condition |
|---|---|---|
| Password, verification code, magic link, notices and support | Available when the configured email delivery service is operational | |
| Account login and binding | Available only when shown and configured | |
| Apple | Account login and binding | Available only when shown and configured |
| Website QR login and account binding; support/contact where shown | Available only when shown and configured | |
| WhatsApp Business | One-time-password login/binding and business messaging/support | OTP is not Meta OAuth; messaging provider can be Meta direct or Twilio |
| Telegram | Contact/subscription and, only after implementation, website login | Telegram login is not active merely because a social/contact link exists |
| Stripe | Eligible online deposit/payment, refund and chargeback | Merchant/recipient is Hong Kong Racer House International Technology Limited |
| Google Maps | Store, warehouse, port, address or route display/search | Applies only when a map component is enabled and loaded |
3. Email
HISICAR may use email for:
- password login or reset;
- one-time verification code;
- magic link;
- account/security notice;
- PI, payment, shipping, recall and complaint notice;
- requested support; and
- marketing after the required consent or other lawful basis.
Data can include email address, name, language, message content, template, delivery/open/bounce/complaint status, IP/device security information and unsubscribe status.
The email delivery provider processes data needed to deliver and secure the message. Before an email provider receives production Personal Data, HISICAR must record its identity, role, locations and safeguards in the internal vendor register. Information about the active provider may be requested from info@hisicar.com.
Authentication emails are not used for unrelated marketing without a valid legal basis. Marketing email remains disabled unless sender identification, a functional unsubscribe and suppression enforcement are tested and operational.
4. Google sign-in
When a user selects Google sign-in, Google authenticates the user and returns the approved OpenID Connect claims. HISICAR ordinarily requests the minimum claims needed for account login, such as:
- Google subject identifier;
- name;
- email address;
- email-verification status; and
- profile image if enabled.
HISICAR does not receive the Google password. The login state and tokens are validated through the approved server flow. Redirect domains and callback URLs are restricted.
The user can manage Google account connections through Google and can unlink Google from the HISICAR account where the account retains another permitted login method.
Official information:
5. Sign in with Apple
When a user selects Sign in with Apple, Apple can provide:
- an Apple subject identifier;
- name on the first authorised sign-in where provided;
- email address; and
- an Apple private-relay email address if the user selects “Hide My Email.”
HISICAR does not receive the Apple ID password. A private-relay address is treated as the account email and can stop forwarding according to Apple’s controls. The user is responsible for maintaining a working route for necessary account and transaction notices.
Unlinking Apple does not automatically close the HISICAR account or delete transaction records.
Official information:
6. WeChat website login
When a user selects WeChat website login, the browser displays or redirects to the official WeChat authorisation flow. With the approved scope, Tencent/WeChat can provide:
- openid;
- unionid where available;
- nickname;
- profile image; and
- other profile information shown in the authorisation request.
HISICAR uses the identifiers to authenticate or bind the account. It does not receive the WeChat password.
The login uses a time-limited, single-use state and the approved callback domain. The user can unlink WeChat where another permitted login method remains.
Official information:
- WeChat Website Application Login
- WeChat Open Platform Developer Agreement
- WeChat Privacy Protection Guidelines
7. WhatsApp one-time-password login
HISICAR WhatsApp authentication is a one-time-password flow, not a generic Meta OAuth login.
When the user requests a code, HISICAR processes:
- telephone number in international format;
- purpose, such as login or binding;
- language;
- code challenge, expiry and attempt status;
- delivery/provider status; and
- security/device information.
The code is time-limited and must not be shared. Successful verification can bind the verified WhatsApp telephone number to the HISICAR account.
Depending on configuration, the message can be delivered through Meta WhatsApp Business Platform directly or through Twilio. Before either route receives production Personal Data, HISICAR must record and approve the active provider and its role, locations and safeguards. Information about the active route may be requested from info@hisicar.com.
8. WhatsApp Business communications
HISICAR may use WhatsApp Business for requested support and authorised transaction communications.
Data can include telephone number, profile/wa_id made available by the provider, message and attachment, template, timestamp, delivery/read status, opt-in/opt-out and assigned support employee.
HISICAR:
- obtains and records required opt-in;
- uses approved templates where required;
- respects provider conversation windows;
- identifies the business sender;
- does not send marketing unless a clear opt-out and suppression enforcement are tested and operational;
- does not treat provider permission as unlimited marketing consent; and
- does not use WhatsApp as an emergency service.
Official information:
- WhatsApp Privacy Policy
- WhatsApp Business Terms
- WhatsApp Business Solution Terms
- WhatsApp Business Data Processing Terms
- Twilio Privacy Notice
9. Telegram
HISICAR may display a Telegram contact or subscription link. That does not mean Telegram is an active HISICAR login method.
If Telegram Login is enabled, HISICAR will use Telegram’s current OIDC or approved login flow and can receive:
- Telegram subject/user identifier;
- first and last name where provided;
- username;
- profile image;
- authentication time; and
- telephone number or permission for bot messages only if separately requested and authorised.
HISICAR registers allowed origins and redirect URLs, validates tokens/signatures on the server, uses state/nonce/PKCE where supported and requests minimum scopes.
A permission for a bot to message the user is separate from permission for general marketing. The user can revoke Telegram authorisation through Telegram and can unlink it from HISICAR where another login method remains.
Official information:
10. Stripe checkout
The Stripe contracting merchant and online payment recipient is Hong Kong Racer House International Technology Limited.
Unless the PI states that it is the Vehicle Seller, it receives the payment as the Seller’s authorised group collection agent.
When a Buyer opens Stripe checkout, Stripe and financial partners can process:
- name and contact details;
- billing and shipping address;
- card or payment-method information;
- amount, currency and transaction reference;
- device, IP and authentication information;
- fraud/risk result;
- payment, refund and chargeback status; and
- other information required by the selected method.
HISICAR uses Stripe-hosted interfaces so full card numbers and card security codes do not enter HISICAR servers. HISICAR receives tokenised/provider identifiers and transaction status needed to reconcile the order.
Stripe can independently decline, review, authenticate, refund or administer a dispute under its terms and law.
Official information:
11. Google Maps
When Google Maps is enabled and loaded, it can be used to display or search:
- store or warehouse;
- port or logistics location;
- entered address;
- selected place or coordinates; and
- route or distance.
Google can receive IP address, device/browser information, map query, selected place, map interaction and location information.
Precise device geolocation is requested only after an affirmative user action, browser/device permission and any consent required by law. HISICAR does not continuously track precise location merely because a map is displayed.
In a prior-consent jurisdiction, optional map scripts remain blocked until consent. A text/address alternative is provided where reasonably available.
Google attribution must remain visible. Google map content is subject to provider restrictions on copying, caching and use.
Official information:
12. Provider roles
A provider can act as:
- a processor/service provider following instructions;
- an independent controller determining its own security, fraud or account purpose;
- a regulated financial institution; or
- a combination of roles for different data.
The HISICAR Privacy Policy identifies HISICAR responsibilities. Provider notices explain the provider’s independent processing. A link to a provider does not transfer HISICAR’s own obligations.
13. International transfers
Authentication, payment, messaging and map providers can process data in multiple countries. HISICAR completes the transfer assessment and mechanism required by applicable privacy law before enabling a restricted transfer.
Using a provider does not by itself constitute a valid cross-border-transfer mechanism. Contractual, assessment, consent, certification or regulator requirements are completed separately.
14. User choices
A user may:
- choose email instead of an optional third-party login where available;
- decline optional profile, telephone, messaging or location scopes;
- unlink an external login after maintaining another permitted account-access method;
- withdraw marketing permission;
- reject non-essential third-party technologies through Cookie Settings whenever those technologies are enabled;
- disable device location; and
- exercise rights under the Privacy Policy.
Unlinking a provider stops future authentication through that connection. It does not automatically delete the HISICAR account, cancel a transaction or erase legally retained records.
15. Security
HISICAR:
- restricts callback and redirect URLs;
- uses single-use state and expiry;
- verifies identity tokens/signatures on the server;
- protects client secrets and webhook secrets;
- validates webhook signatures;
- requests minimum permissions;
- logs linking/unlinking and high-risk changes;
- requires renewed authentication for sensitive account actions; and
- reviews provider changes before release.
The user must protect the provider account and report compromise to info@hisicar.com.
16. Availability and provider changes
A provider may change, suspend or restrict a service by country, account, law or technical condition. HISICAR can disable an integration that is unavailable, insecure or non-compliant and will provide a reasonable alternative where required and practicable.
HISICAR reviews provider terms and privacy changes and updates this Notice where the change materially affects users.
17. No endorsement and no emergency service
Using or naming a provider does not imply that the provider endorses HISICAR or guarantees a vehicle, transaction, payment, map, message or delivery.
Email, WhatsApp, WeChat and Telegram are not emergency channels. Do not use them when delay could threaten life, safety or property.
18. Contact
Questions, unlinking requests and provider-related privacy complaints: info@hisicar.com.