Privacy Policy
This policy describes how HK TRISENTA CO., LIMITED ("HK TRISENTA", "we", "us", "our") collects, uses, stores, shares, and protects personal data on xinjiace.com and in the HK TRISENTA mobile applications published on the Apple App Store and Google Play.
Last updated: September 23, 2026. We will post a change-log note in-app and update the date above whenever this policy changes materially. Continued use of the website or our apps after the effective date means you accept the revised policy.
A1. Introduction & identity of the controller
A1.1 Who we are
HK TRISENTA CO., LIMITED is a private company incorporated in Hong Kong, with its operating office at:
Rm 701(127) 7/F NEW MANDARIN PLZ TWR B 14 SCIENCE MUSEUM RD, Tsim Sha Tsui East, HK.
We operate the website xinjiace.com and publish the HK TRISENTA mobile applications on the Apple App Store and Google Play under the publisher name "HK TRISENTA CO., LIMITED".
A1.2 Our role under data-protection law
For the website and the in-app sign-in services, HK TRISENTA acts as the data controller. For personal data handled by integrated advertising SDKs inside our apps, HK TRISENTA acts as a controller with respect to its own first-party data; some ad networks may act as independent or joint controllers under their own privacy policies. Section A10 enumerates each network.
A1.3 Designated privacy contact
All privacy enquiries, rights requests, and complaints should be sent to support@xinjiace.com. We acknowledge receipt within five business days and respond substantively within statutory windows (typically 30 days under GDPR/UK GDPR, 45 days under CCPA/CPRA).
A1.4 Change log
We commit a "Last updated" date on every revision. Material changes (a new category of personal data, a new SDK, a new processor, a new regional right) trigger an in-app banner on next launch and a re-prompt for consent where required.
A2. Scope of this policy
A2.1 What this policy applies to
- The website at xinjiace.com, including all subpages and the corporate blog.
- HK TRISENTA mobile applications published on the Apple App Store under publisher "HK TRISENTA CO., LIMITED".
- HK TRISENTA mobile applications published on Google Play under developer "HK TRISENTA CO., LIMITED".
- Email, telephone, and postal communications initiated by us in response to enquiries or contracts.
A2.2 What this policy does not apply to
- Third-party websites linked from our pages (the linked site's own policy applies).
- Advertisers' own websites when the user clicks an ad served by an SDK listed in Section A10.
- Background checks, KYC, or trade-compliance checks performed by banks, customs authorities, or logistics partners — those are governed by their own notices.
A3. Personal data we collect
A3.1 Data you give us directly
- Contact form — your name, email, company, phone (optional), message body.
- Newsletter sign-up — your email address.
- In-app account registration — display name, email, password (hashed).
- Commercial engagements — invoicing details, shipping addresses, tax identifiers as required by trade compliance.
A3.2 Data collected automatically on the website
- IP address, user-agent string, referrer, page URL, timestamp.
- Approximate country derived from IP (no precise geolocation).
- Aggregated analytics (page views, scroll depth, traffic sources).
A3.3 Data collected automatically in the apps
- Device identifiers — IDFA (iOS) and GAID (Android) where the user has consented to tracking.
- Device properties — OS version, app version, device model, locale, time zone.
- In-app events — screen views, feature usage, ad interactions, session length.
- Crash logs and diagnostics.
A3.4 Data collected by ad SDKs
Each integrated advertising SDK may collect additional data for ad selection, measurement, and fraud prevention. Section A10 lists every SDK and its data practices. We do not allow interest-based advertising from any SDK for users who have opted out or who are in jurisdictions that prohibit it without consent.
A3.5 Cookies & similar technologies
The website uses cookies and local storage in the following categories:
- Strictly necessary — session, security, language preference. Cannot be disabled.
- Preferences — your settings (e.g., reduced-motion preference).
- Statistics — anonymized, aggregated analytics.
- Marketing — only set if you opt in via the cookie banner.
In our apps, the equivalent of "cookies" is the device identifier (IDFA/GAID) and the SDK's own local storage. Manage these via iOS Settings → Privacy → Tracking and Android Settings → Ads.
A4. Lawful basis for processing (jurisdiction-aware)
We map each processing activity to one or more lawful bases, taking into account the visitor's jurisdiction.
A4.1 GDPR (EU) & UK GDPR
Under Article 6 GDPR / UK GDPR, we rely on:
- Consent — for non-essential cookies, advertising identifiers, and interest-based advertising.
- Contract — to deliver the services you request and to manage commercial relationships.
- Legitimate interest — for website analytics, security, fraud prevention, and direct marketing to existing clients (with opt-out).
- Legal obligation — for trade-compliance record-keeping and tax requirements.
A4.2 CCPA / CPRA (California)
Under the California Consumer Privacy Act as amended by the CPRA, HK TRISENTA is a business. Our advertising and analytics vendors are service providers under the relevant contract terms. We collect the categories of personal information enumerated in Section A3 and have collected the following categories of sensitive personal information in the past 12 months: none (we do not intentionally collect SPI).
A4.3 LGPD (Brazil)
Under Lei Geral de Proteção de Dados (Art. 7), we rely on the corresponding lawful bases — consent for non-essential cookies and ad identifiers, contract for service delivery, legitimate interest for analytics, and legal obligation for trade-compliance records.
A4.4 PIPEDA (Canada)
Under the Personal Information Protection and Electronic Documents Act, we obtain meaningful consent at the point of collection and limit use to the identified purpose (the appropriate-purpose test).
A4.5 Australia — Privacy Act 1988 (APPs)
We comply with Australian Privacy Principles 3–13, including notification at collection, use limitation, disclosure, data quality, security, access, and correction.
A4.6 Singapore — PDPA
Under the Personal Data Protection Act, we observe the Consent, Notification, Purpose, Accuracy, Protection, Retention, and Access/Correction obligations.
A4.7 Japan — APPI
Under the Act on the Protection of Personal Information, we observe the purpose-of-use limitation and proper-acquisition principles, and respond to disclosure, correction, and cessation-of-use requests.
A5. How we use personal data (purposes)
- A5.1 To respond to enquiries and deliver the services you request.
- A5.2 To operate, secure, and improve the website and the apps.
- A5.3 To show advertising inside our apps via integrated advertising SDKs (Section A10).
- A5.4 To measure ad performance, attribute installs, and prevent fraud.
- A5.5 To comply with applicable law, enforce our terms, and resolve disputes.
A6. Cookies, SDKs, and similar technologies
A6.1 What they are
Cookies are small text files stored on your device. SDKs are software libraries integrated into our apps that perform similar functions. We use them to make the website and apps work, remember your preferences, measure usage, and (with consent) personalize advertising.
A6.2 Cookie categories
See Section A3.5 for the website categories and their examples. Each category can be toggled in the cookie banner that appears on your first visit. Your choice is stored for 12 months.
A6.3 In-app device identifiers
Inside our apps, the equivalent of a cookie is the device identifier (IDFA on iOS, GAID on Android). You can reset or limit these at any time:
- iOS — Settings → Privacy & Security → Tracking.
- Android — Settings → Privacy → Ads → Reset advertising ID / Opt out of ad personalization.
A6.4 Manage your preferences
You can also use your browser's privacy settings, your device's advertising settings, and the Global Privacy Control signal (see Section A16) to manage cookies and tracking.
A7. App-store compliance
A7.1 Apple App Store Review Guidelines
Our iOS apps comply with the Apple App Store Review Guidelines, including:
- All required purpose strings on every permission and tracking request (e.g., NSUserTrackingUsageDescription).
- Honoring App Tracking Transparency (ATT) — we do not access IDFA without your explicit consent.
- Kid-category declarations where applicable (Section A9).
- Account-deletion requirements: if you sign in, you can delete your account from inside the app, which removes your personal data subject to our retention schedule.
A7.2 Google Play Developer Program Policy
Our Android apps comply with the Google Play Developer Program Policy, including:
- The User Data policy — we collect only data necessary for the feature, with prominent disclosure.
- The Permissions policy — we request the minimum permissions needed.
- The Families policy, where applicable.
- Prominent disclosure of any sensitive data collection (none in the current build).
A7.3 Data Safety & App Privacy sections
The Google Play Data Safety section and the Apple App Store App Privacy section describe, for each app, the categories of data collected versus shared, and the purposes. Section A3 above is the canonical list; the in-store disclosures are derived from it.
A8. International data transfers
A8.1 Where data may be processed
Personal data may be processed in Hong Kong, the European Economic Area (EEA), the United Kingdom, the United States, Singapore, Japan, and other jurisdictions where our service providers operate.
A8.2 Transfer mechanisms
- EU Standard Contractual Clauses (Commission Decision 2021/914) for transfers out of the EEA.
- UK International Data Transfer Agreement (IDTA) for transfers out of the UK.
- EU-US Data Privacy Framework reliance, where a recipient is certified.
- Contractual safeguards and supplementary measures (encryption in transit, access controls) elsewhere.
A8.3 Storage and retention
See Section A14 for the retention schedule. Backups are encrypted and stored in the same region as the primary data where possible.
A9. Children
A9.1 Applicable thresholds
- COPPA (US) — children under 13.
- GDPR-K (EU) — under 16 by default, with member-state reductions to 13 (e.g., Germany, France, Italy, Spain in practice).
- UK Age-Appropriate Design Code (AADC) — under-18 protections in any service likely to be accessed by children.
- LGPD (Brazil) — under-18, with parental consent for under-12.
A9.2 Our apps and site
HK TRISENTA's apps and the website are B2B and are not directed to children under 13. We do not knowingly collect personal data from children. If we learn we have, we delete it.
A9.3 Deletion window
If we discover that we have collected data from a child under 13 without verifiable parental consent, we delete the data within 30 days of confirmation.
A9.4 Parents & guardians
If you believe your child has provided data to us, write to support@xinjiace.com with the child's account identifier; we will locate and delete the data.
A10. Advertising SDKs integrated in our apps
The HK TRISENTA apps integrate the following advertising platforms. Each subsection describes the SDK behaviors, the data it collects, our lawful basis / consent posture, how to opt out, and a link to the network's own privacy page. The order is alphabetical.
A10.1 — Google AdMob
- SDK behaviors: Initializes at app start, mediates ad requests, renders banner / interstitial / rewarded / native formats, caches ad assets locally.
- Data collected: Device identifiers (IDFA / GAID where consented), IP, coarse location, app instance ID, ad interaction events, crash logs.
- Lawful basis: Consent (GDPR / UK GDPR) for personalisation; contract or legitimate interest for non-personalised ads.
- Opt-out: iOS Settings → Privacy → Tracking; Android Settings → Ads. Network privacy controls at policies.google.com/privacy.
- Reference: Google AdMob documentation.
A10.2 — Google Ad Manager
- SDK behaviors: Ad-server mediation, line-item targeting, frequency capping, reporting.
- Data collected: Device identifiers (consented), IP, coarse location, ad request metadata, interaction events.
- Lawful basis: Consent (GDPR / UK GDPR) for personalisation; legitimate interest for non-personalised ads.
- Opt-out: Same device controls as A10.1. Reference at policies.google.com/privacy.
- Reference: Google Ad Manager.
A10.3 — Meta Audience Network
- SDK behaviors: Mediation, native / banner / interstitial / rewarded formats, conversion mapping for Facebook/Meta campaigns.
- Data collected: Device identifiers (IDFA/GAID), advertising ID, IP, OS version, app events, coarse location.
- Lawful basis: Consent (GDPR / UK GDPR); opt-in required for Meta-platform tracking.
- Opt-out: iOS Settings → Privacy → Tracking; Meta account controls at Facebook ad preferences.
- Reference: Meta Audience Network.
A10.4 — Unity Ads
- SDK behaviors: Game-style mediation, rewarded video, playable ads, banner, interstitial.
- Data collected: Device identifiers, IP, coarse location, app instance ID, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR); legitimate interest for non-personalised ads.
- Opt-out: iOS Settings → Privacy → Tracking; Android Settings → Ads. Unity privacy controls at unity.com/legal.
- Reference: Unity Ads.
A10.5 — AppLovin
- SDK behaviors: Mediation via AppLovin MAX, in-app bidding, banner / interstitial / rewarded / native formats.
- Data collected: Device identifiers (consented), IP, coarse location, app metadata, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR); legitimate interest for non-personalised ads.
- Opt-out: Device-level controls as above. AppLovin opt-out at applovin.com/optout.
- Reference: AppLovin Privacy Policy.
A10.6 — ironSource (Unity LevelPlay)
- SDK behaviors: Mediation, rewarded video, offerwall, in-app bidding.
- Data collected: Device identifiers, IP, coarse location, app instance ID, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. ironSource privacy at is.com/privacy-policy.
- Reference: ironSource developers.
A10.7 — Pangle (ByteDance)
- SDK behaviors: Mediation, banner / interstitial / rewarded / native / splash formats, in-app bidding.
- Data collected: Device identifiers (IDFA/GAID/ OAID), IP, coarse location, app events, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Pangle privacy at pangleglobal.com/privacy.
- Reference: Pangle.
A10.8 — Vungle
- SDK behaviors: Video-focused mediation, rewarded video, interstitial, banner, in-app bidding.
- Data collected: Device identifiers, IP, coarse location, app instance ID, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Vungle privacy at vungle.com/privacy.
- Reference: Vungle.
A10.9 — Chartboost
- SDK behaviors: Gaming mediation, banner / interstitial / rewarded video formats, programmatic exchange.
- Data collected: Device identifiers, IP, coarse location, app instance ID, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Chartboost privacy at chartboost.com/privacy.
- Reference: Chartboost.
A10.10 — InMobi
- SDK behaviors: Mediation, banner / interstitial / rewarded / native / splash formats, programmatic.
- Data collected: Device identifiers (consented), IP, coarse / precise location (where granted), app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls + InMobi opt-out.
- Reference: InMobi Privacy Policy.
A10.11 — Tapjoy
- SDK behaviors: Offerwall / rewarded video mediation, in-app bidding, frequency capping.
- Data collected: Device identifiers, IP, coarse location, app instance ID, ad interaction events.
- Lawful basis: Consent (GDPR / UK GDPR) — rewarded content is always opt-in.
- Opt-out: Device-level controls + Tapjoy in-app privacy settings. Reference at tapjoy.com/legal/privacy-policy.
- Reference: Tapjoy.
A10.12 — Mintegral
- SDK behaviors: Mediation, banner / interstitial / rewarded / native / splash formats, programmatic.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Mintegral privacy at mintegral.com/en/privacy.
- Reference: Mintegral.
A10.13 — Digital Turbine
- SDK behaviors: On-device mediation, app install and content recommendation, in-app bidding.
- Data collected: Device identifiers, IP, coarse location, app events, device properties.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Digital Turbine privacy at digitalturbine.com/privacy-policy.
- Reference: Digital Turbine.
A10.14 — Liftoff
- SDK behaviors: Mediation, programmatic bidding, banner / interstitial / rewarded / native / splash formats.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Liftoff privacy at liftoff.io/privacy-policy.
- Reference: Liftoff.
A10.15 — Moloco
- SDK behaviors: Programmatic bidding, in-app DSP, banner / interstitial / rewarded / native formats.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Moloco privacy at moloco.com/privacy-policy.
- Reference: Moloco.
A10.16 — Yahoo (Verizon Media)
- SDK behaviors: Programmatic, native / display / video formats, mediation.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Yahoo privacy at Yahoo Privacy.
- Reference: Yahoo Inc..
A10.17 — Smaato
- SDK behaviors: Programmatic exchange, header bidding, mediation.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Smaato privacy at smaato.com/privacy.
- Reference: Smaato.
A10.18 — Start.io
- SDK behaviors: Programmatic, mediation, banner / interstitial / rewarded / native / splash formats.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Start.io privacy at start.io/privacy-policy.
- Reference: Start.io.
A10.19 — Appodeal (aggregation)
- SDK behaviors: Header bidding aggregator that calls into multiple of the networks above; reports performance and runs waterfall / in-app bidding.
- Data collected: Device identifiers, IP, coarse location, app events.
- Lawful basis: Consent (GDPR / UK GDPR).
- Opt-out: Device-level controls. Appodeal privacy at appodeal.com/privacy-policy.
- Reference: Appodeal.
A11. Ad formats used in our apps
The HK TRISENTA apps serve four formats. Each description covers what the format is, when it shows, the user controls available, and which SDKs typically serve it.
A11.1 — Open-screen (splash) ads
A full-screen ad shown at app launch, typically for up to 5 seconds and skippable thereafter. Shown on cold launch or throttled by frequency-cap. Served by Google AdMob, Pangle, Mintegral, InMobi, Digital Turbine, Liftoff, Start.io, Appodeal.
User controls: Skippable after the timer; mute controls respected; no auto-play with sound if the device is silenced; throttled after the first session to avoid repeat interruption.
A11.2 — Rewarded video ads
A full-length video the user opts in to watch in exchange for an in-app reward (a hint, a feature unlock, a temporary boost). Never auto-plays; never plays sound without device-blessed audio. Served by Google AdMob, Meta Audience Network, Unity Ads, AppLovin, ironSource / Unity LevelPlay, Pangle, Vungle, Chartboost, InMobi, Tapjoy, Mintegral, Digital Turbine, Liftoff, Moloco, Start.io, Appodeal.
User controls: Always opt-in; reward credited only on completion (per the SDK's policy); mute / unmute toggle during playback; clear UI label that the next item is a rewarded ad.
A11.3 — Interstitial ads
A full-screen ad shown at natural transition points (e.g., between major screens, on level / section change). Never shown on first launch. Frequency-capped (typically one per minute at most, fewer in practice). Served by all networks in A10 as available.
User controls: Dismissible after the standard close timer; never on first launch; never stacked; never immediately after a rewarded ad.
A11.4 — Banner ads
A persistent rectangular ad slot embedded in app screens. Dismissible; non-blocking; respects safe areas. Served by all networks in A10 as available.
User controls: In-app "hide this ad slot" toggle for individual screens; auto-refresh capped to a sane cadence; never above the fold of the primary task the user came to do.
A12. Sharing & disclosure
A12.1 Service providers
We share data with vetted service providers acting on our instructions — hosting, email, analytics, the advertising networks in Section A10, and our legal / accounting advisors. All are bound by written contracts that limit use to the specified purpose.
A12.2 Legal compliance & safety
We may disclose data when required by law, regulation, or valid legal process, or when necessary to protect the rights, property, or safety of HK TRISENTA, our users, or others.
A12.3 Corporate transactions
If HK TRISENTA undergoes a merger, acquisition, financing, or sale of assets, your data may be transferred subject to confidentiality and a commitment to honor this policy.
A12.4 With your consent
We share data for any other purpose with your explicit consent.
A13. Security
A13.1 Technical & organizational measures
- Encryption in transit (TLS 1.2+) and at rest.
- Access controls — least-privilege, role-based, audit logging.
- Vendor due diligence — security and privacy review before onboarding a processor.
- Incident-response plan with defined escalation and notification timelines.
A13.2 Residual-risk statement
No system is 100% secure. We continuously improve our safeguards, but we cannot guarantee absolute security. If we determine that a security incident has materially affected your personal data, we will notify you and the relevant authorities as required by law.
A14. Data retention
| Category | Retention |
|---|---|
| Contact-form enquiries | 24 months from last interaction |
| Newsletter subscription | Until you unsubscribe, plus 12 months |
| In-app account | Active account + 24 months after deletion |
| Website analytics | 13 months (aggregated) |
| Advertising identifiers | Per SDK settings (typically 13 months) |
| Server logs | 90 days |
| Trade-compliance records | Per Hong Kong and destination-country statutory minimums (typically 7 years) |
| Tax records | 7 years (Hong Kong) |
A15. Your rights
A15.1 GDPR / UK GDPR
You have the right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection (including to direct marketing and to processing based on legitimate interest), automated-decision-making safeguards, and the right to lodge a complaint with a supervisory authority in your country.
A15.2 CCPA / CPRA
You have the right to know what personal information we collect, delete it, correct it, opt out of sale or sharing (see Section A16), limit use of sensitive personal information, and non-discrimination for exercising your rights.
A15.3 LGPD (Brazil)
You have the right to confirmation of the existence of processing, access, correction, anonymization, portability, deletion, and consent withdrawal.
A15.4 PIPEDA (Canada)
You have the right to access your personal information and correct inaccuracies.
A15.5 Australia — Privacy Act
You have rights under APPs 1–13, including the right to review and correct personal information we hold about you.
A15.6 Singapore — PDPA
You have the right to access and correct your personal data via our DPO contact.
A15.7 Japan — APPI
You have the right to disclosure, correction, and cessation of use of your personal data.
A15.8 How to exercise your rights
Write to support@xinjiace.com with enough information to verify your identity (account email, recent transaction reference, etc.). We respond within 30 days under GDPR / UK GDPR and within 45 days under CCPA / CPRA, with a possible extension of up to 90 days under CCPA when reasonably necessary.
A16. Do Not Sell or Share / Global Privacy Control
A16.1 Honoring GPC signals
We honor the Global Privacy Control (GPC) signal sent by your browser or device. Where GPC is detected, we treat it as a request to opt out of sale or sharing of personal information for California visitors under the CCPA / CPRA.
A16.2 Do Not Sell or Share link
A "Do Not Sell or Share My Personal Information" link is available in the site footer and in the in-app privacy settings.
A17. Third-party links
The website and our apps may link to third-party sites. We are not responsible for those sites' content or privacy practices — review their policies before submitting personal data.
A18. Changes to this policy
We will notify you of material changes via an in-app banner on next launch and by updating the "Last updated" date at the top of this page. Where a change requires renewed consent under GDPR / UK GDPR, we will prompt you accordingly.
A19. Contact us
Privacy enquiries, rights requests, and complaints should be sent to:
HK TRISENTA CO., LIMITED — Privacy
Rm 701(127) 7/F NEW MANDARIN PLZ TWR B 14 SCIENCE MUSEUM RD
Tsim Sha Tsui East, Hong Kong
support@xinjiace.com
We acknowledge receipt within 5 business days and respond substantively within the statutory window for your jurisdiction.