Privacy Policy

ECHO SAGE LIMITED (“we,” “us,” or “our”) is committed to protecting the privacy and security of your personal information. As a Hong Kong-based e-commerce company specializing in women’s dresses and shawls, we collect and use your data only to deliver high-quality services, process orders, and enhance your shopping experience—while adhering to Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and international data protection standards. This policy explains what information we collect, how we use it, and your rights regarding your data.​

1. Information We Collect​

We gather two types of information to support our services:​

  • Personal Identification Information: Collected when you place an order, create an account, or contact customer service. This includes your full name, email address, phone number, shipping/billing address, and payment details (e.g., credit card numbers—processed securely via third-party payment providers, not stored by us).​
  • Non-Identifiable Information: Automatically collected through our website or app, such as your IP address, browser type, device information, browsing behavior (e.g., products viewed, pages visited), and order history. This data is aggregated and used to improve our website functionality and tailor product recommendations.​

2. How We Use Your Information​

Your personal data is used for specific, legitimate purposes, including:​

  • Order Processing & Fulfillment: To process your purchases, arrange shipping, send order confirmations, and provide delivery updates.​
  • Customer Service: To respond to your inquiries, resolve issues (e.g., returns, exchanges), and provide post-purchase support.​
  • Account Management: To maintain your user account, track your order history, and enable personalized features (e.g., saving shipping addresses for future orders).​
  • Marketing (With Consent): To send you updates about new products, promotions, or exclusive offers—only if you have opted in to receive such communications. You can unsubscribe at any time via the link in our emails.​
  • Security & Compliance: To detect and prevent fraud, protect our website from unauthorized access, and comply with legal obligations under Hong Kong law.​

3. How We Protect Your Information​

We implement robust technical and organizational measures to safeguard your data from unauthorized access, disclosure, or misuse:​

  • Secure Storage: Personal information is stored on encrypted servers with restricted access, and payment details are handled by PCI DSS-compliant third-party providers (e.g., PayPal, Stripe) to ensure maximum security.​
  • Data Access Controls: Only authorized staff (e.g., customer service, order processing teams) have access to your data, and they are required to adhere to strict confidentiality policies.​
  • Website Security: Our website uses SSL (Secure Sockets Layer) encryption to protect data transmitted between your device and our servers, indicated by the “https://” prefix and padlock icon in your browser.​

4. Sharing Your Information​

We do not sell, rent, or share your personal information with third parties for their own marketing purposes. We may share data only in the following limited circumstances:​

  • Service Providers: With trusted third parties who assist us in delivering services (e.g., courier companies for shipping, payment processors for transactions, IT providers for website maintenance). These parties are contractually obligated to protect your data and use it only as instructed by us.​
  • Legal Requirements: If required by law, court order, or regulatory authority to disclose information to comply with legal obligations (e.g., preventing fraud or responding to a government request).​

5. Your Rights​

Under Hong Kong’s PDPO, you have the following rights regarding your personal information:​

  • Access & Correction: Request a copy of the personal data we hold about you, and ask to correct any inaccurate or incomplete information.​
  • Erasure: Request the deletion of your data if it is no longer needed for the purposes for which it was collected (e.g., after your account is closed).​
  • Withdraw Consent: Opt out of marketing communications at any time, or withdraw consent for other non-essential uses of your data (where applicable).​
  • Data Portability: Request a copy of your data in a structured, machine-readable format to transfer to another service provider (e.g., if you switch to a different e-commerce platform).​

To exercise these rights, please contact us at [email protected] with your full name, email address, and details of your request. We will respond within 30 days of receiving your inquiry.​

6. Policy Updates​

We may update this Privacy Policy from time to time to reflect changes in laws, technology, or our business practices. Any updates will be posted on our website with a revised “Last Updated” date, and we will notify you via email if significant changes are made (e.g., new data collection practices). We encourage you to review this policy periodically.​

For questions or concerns about our privacy practices, please contact our Data Protection Officer at [email protected]. We are available 9 AM–6 PM (Hong Kong Time) to assist you.