Welcome to Leftover.biz. This Privacy Policy explains how we collect, use, store, share, and protect your personal information. We are headquartered in the Hong Kong Special Administrative Region (Hong Kong SAR) and are committed to complying with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong, as well as international privacy frameworks such as the General Data Protection Regulation (GDPR) applicable to our users in the European Economic Area.
At Leftover.biz, we understand that privacy is essential. We treat your data with the utmost care, respect, and responsibility. By accessing or using our website, mobile services, applications, or any other services provided by us, you consent to the terms outlined in this Privacy Policy.
This Privacy Policy applies to all users who access our platform, whether as buyers, sellers, registered members, or casual visitors. It governs how your data is handled when you browse our website, place an order, interact with customer service, or engage with us through third-party platforms.
We collect various types of personal data depending on how you interact with our services. When you create an account, we collect information such as your full name, gender, date of birth, and nationality. When you provide your contact details, we store your email address, phone number, and residential or business address. When you access and use your account, we collect usernames and passwords, purchase preferences, product interests, and transaction histories.
When you make a purchase or become a seller, we collect financial data such as encrypted payment details, transaction IDs, billing information, and in some cases, bank account information for disbursement of funds. We do not store raw credit or debit card numbers on our servers. All payments are securely processed through third-party payment processors that comply with international financial security standards such as PCI-DSS.
When you access our platform through a browser or mobile device, we automatically collect certain technical data, which may include your IP address, browser type and version, device identifier, operating system, mobile carrier, and the time and date of access. Additionally, we may collect location information if location tracking is enabled on your device or browser.
While browsing the platform, we monitor how you interact with the site, such as which pages you visit, the time you spend on each page, and what actions you take. This behavioral and usage data helps us understand how to improve our services. We also collect information about your marketing preferences, such as whether you have subscribed to newsletters, how you respond to email campaigns, and your participation in surveys or feedback forms.
There are several ways through which we collect this data. When you provide information directly to us—for example, when registering, purchasing, or contacting support—that data is stored securely in our systems. We also collect data automatically using cookies, web beacons, and similar technologies. These tools help us personalize your experience, remember your preferences, and understand how you use the site. We may also receive data from third parties such as analytics providers, advertising networks, payment processors, logistics companies, or social media platforms if you choose to log in using social accounts.
The primary reason we collect your personal data is to fulfill our contractual obligation to provide the products and services you have requested. This includes processing orders, managing payments, shipping products, and handling returns or refunds. We also collect data to maintain the platform’s functionality, improve user experience, personalize content, and ensure technical reliability.
We may use your data to send promotional offers, newsletters, and product recommendations if you have consented to receive such communications. In cases where we rely on consent, you can withdraw it at any time by contacting us. Furthermore, we may process your data to comply with our legal and regulatory obligations, including tax filing, law enforcement requests, fraud detection, and protection of intellectual property.
Under the GDPR and the PDPO, we rely on several legal grounds to process personal data. These include your explicit consent, contractual necessity, compliance with legal obligations, and our legitimate interests in maintaining the security, usability, and integrity of our platform.
In the course of operating our business, we may need to share your personal data with third parties. These third parties may include payment gateways such as Stripe, PayPal, or Alipay; logistics companies like DHL, SF Express, or Hong Kong Post; and cloud hosting providers or analytics platforms. All third-party service providers are contractually required to use your data only for the purpose of providing services to us and are bound by strict confidentiality and data protection obligations.
We may also disclose your data to government authorities, law enforcement agencies, or regulatory bodies in compliance with legal obligations, or if we believe in good faith that such disclosure is necessary to prevent fraud, enforce our Terms of Service, protect our rights, or respond to legal claims.
Given our global operations and international customer base, your data may be transferred to, stored in, or processed in jurisdictions outside of your country of residence, including the European Union, the United States, Singapore, Mainland China (for logistics purposes), and other countries where our partners operate. We ensure that any international data transfers comply with applicable data protection laws by implementing measures such as Standard Contractual Clauses (SCCs), Data Processing Agreements (DPAs), and encryption protocols.
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy. If you maintain an account with us, your account information is retained for the duration of your use of our platform and for a period of up to three years after account closure. Order history is retained for at least six years to comply with financial and tax regulations. Customer service records and feedback may be stored for up to two years, while data related to email marketing preferences will be kept until you unsubscribe or withdraw your consent.
We implement strong technical and organizational safeguards to protect your data from unauthorized access, alteration, loss, or destruction. This includes the use of encryption, secure sockets layer (SSL) technology, role-based access controls, regular security audits, and multi-factor authentication for internal systems. We continuously monitor our infrastructure and update our security protocols to address emerging threats.
You have several rights under applicable data protection laws. These rights include the right to request access to your data, the right to rectify incorrect or outdated information, the right to request deletion of your data under certain conditions, the right to restrict processing in specific scenarios, the right to receive a copy of your data in a portable format, and the right to object to processing based on legitimate interests. You also have the right to withdraw consent at any time when we rely on your consent to process data.
If you wish to exercise any of these rights, you can contact us by sending an email to privacy@leftover.biz. We aim to respond to all requests within thirty calendar days and may ask for verification of your identity before fulfilling your request. In some cases, where the request is excessive or manifestly unfounded, we may charge a reasonable fee or refuse the request, explaining the reason.
We use cookies and similar tracking technologies on our website to improve functionality, provide a better browsing experience, and analyze site traffic. Essential cookies are necessary for the basic operation of the site. Performance cookies help us measure website usage and identify areas for improvement. Functionality cookies remember your settings and preferences. Targeting cookies are used for advertising purposes to display relevant content.
By using our website, you agree to the placement of cookies on your device unless you disable them in your browser settings. You may manage your cookie preferences at any time through your browser or by using tools provided on our platform.
Our services are not intended for individuals under the age of thirteen. We do not knowingly collect personal data from children. If we learn that we have collected data from a child without appropriate parental consent, we will delete the data as quickly as possible. If you believe that a child has provided us with personal information, please contact us immediately.
Our platform may contain links to websites operated by third parties. We are not responsible for the privacy practices or the content of those websites. We encourage users to read the privacy statements of any external websites they visit through our platform.
This Privacy Policy may be updated from time to time to reflect changes in legal requirements, technology, or our business operations. When we make material changes to this policy, we will notify you by posting a notice on our website or contacting you via email. We recommend that you review this page periodically to stay informed about how we handle your data.
If you have any questions, comments, or complaints regarding this Privacy Policy or our privacy practices, you may contact our Data Protection Officer. Our official address is Leftover.biz, Unit 2101, Times Square Tower One, 1 Matheson Street, Causeway Bay, Hong Kong SAR. You can reach us by email at privacy@leftover.biz.
If you are not satisfied with our response to a data rights request or privacy inquiry, you have the right to file a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong or with your relevant national data protection authority if you are located in the European Union or another jurisdiction with enforceable privacy rights.
By continuing to use our platform, you acknowledge that you have read and understood this Privacy Policy and agree to the terms and practices described herein.