Privacy Policy
Last Updated: [Update Date, e.g. 03 July 2026]
We at Soline Limited ("we", "us", "our Company") respect your concerns about privacy. This Online Privacy Notice describes the types of personal information we collect at laymis.com (the "Site"), how we use the information, with whom we share it, and the choices available to users of our Site regarding our use of the information. We also describe the measures we take to protect the security of the information and how you can contact us about our privacy practices.
Our privacy practices comply with the Hong Kong Personal Data (Privacy) Ordinance (PDPO), EU GDPR, California CCPA, Nevada privacy laws and relevant data protection regulations applicable to Middle East regions, and may be adjusted to meet local legal requirements for customers located in different countries. You can view region-specific supplementary clauses below:
- European Union & EEA
- California, USA
- Nevada, USA
Information We Collect
The types of personal information users submit to our Site include:
- Contact information (such as full name, shipping/postal address, WhatsApp/telephone number, and email address)
- Account login credentials for the Site
- Payment information (such as payment card details, PayPal wallet information, bank transfer records)
- Purchase and transaction information (product order records, tasbih/bead customization requirements, delivery logs)
- Voluntary supplementary information you provide (e.g. stone preference, gift note content, custom engraving text)
The provision of your personal information is voluntary. However, if you do not provide us with necessary personal information, we may not be able to deliver goods, process payments, fulfill your orders, or respond to your customer inquiries.
Information We Collect By Automated Means
When you use our Site, we may collect certain information by automated means, using technologies such as cookies, web server logs, web beacons (including tags and pixels from third parties such as Facebook, Instagram, TikTok) and JavaScript.
Cookies are small files that websites send to your computer or other Internet-connected devices to uniquely identify your browser or store browsing preferences on your device. Our Site may use HTTP cookies and browser local storage. Your browser settings allow you to receive cookie reminders, restrict or disable cookies. Please note that disabling essential cookies may cause partial functions of our website to be unavailable.
When collecting data via cookies, our web servers record: device model, operating system, browser type, system language, country & time zone of your device, referral page URL, public IP address, pages you browse, stay duration and interactive behaviors on the Site. We deploy web beacons and JavaScript to capture the above browsing data.
Our Site embeds third-party social media plug-ins for Instagram, Facebook, Pinterest, TikTok, and YouTube. These platform providers collect user data independently through automated tracking tools, governed by their own separate privacy policies.
We may transmit your site data securely to authorized third-party marketing partners for advertising attribution and performance measurement. These partners may set unique cookies on your device and exchange anonymized data with our servers.
We deploy third-party web analytics tools including Google Analytics and Google Ads to analyze user website behavior. All browsing data (including anonymized IP addresses) is collected or shared with these service providers. You may opt out of their tracking via official opt-out channels provided by Google.
How We Use the Information We Collect
We may use collected personal data for the following legitimate purposes:
- Provide handcrafted tasbih, gemstone bracelets and related after-sales services
- Create, maintain and manage your customer account
- Process order payments, cross-border shipping and customs coordination
- With your explicit consent, send promotional SMS/email marketing, event notifications, discount offers, customer surveys and market research
- Respond to pre-sales consultation, after-sales complaints, repair/restring service requests
- Conduct anonymized aggregate data analysis for business operation optimization
- Develop new bead & tasbih products, upgrade website user experience
- Prevent fraud, identify unauthorized transactions and mitigate legal liabilities
- Comply with Hong Kong PDPO, GDPR, CCPA and other local data protection laws
- Record order packing video evidence for dispute resolution, retain transaction records for legal compliance
We also use automated tracking data to customize page content, deliver interest-based product advertisements, optimize website operation. With your consent, we may display our product ads on third-party websites via retargeting technology.
Online Tracking & Retargeting
We run retargeting advertising to display our bead/tasbih product ads on external websites based on your browsing history. Our retargeting partners use cookies to track cross-site user activity. You may opt out of interest-based advertising via industry opt-out platforms.
Our Site does not support browser "Do Not Track" signal requests.
Information We Share
We never sell your personal data for commercial profit, and only disclose your information under the circumstances listed below:
- Authorized service providers: Payment processors, international logistics couriers, web hosting platforms, advertising analytics partners. All third-party vendors are contractually restricted to only process data under our instructions and cannot reuse your information for unrelated purposes.
- Affiliated business entities under our operation, solely for order fulfillment and customer service management.
- With your separate opt-in consent, share basic contact information with trusted brand partners for relevant product promotions; you may withdraw consent for marketing data sharing at any time free of charge. Withdrawal does not invalidate lawful data processing completed before consent revocation.
We reserve the right to disclose your personal data if:
- Mandated by court order, local law enforcement or government regulatory requirements
- Necessary to prevent physical injury, financial loss, or investigate fraudulent/illegal order activities
- Our business undergoes full/partial asset transfer, merger, reorganization or liquidation, and customer data will be transferred as part of business assets
Notice to California Residents (CCPA Rights)
1. Access & Data Portability Right
You have the right to request us to disclose all categories of personal data collected about you within the past 12 months, including data source categories, commercial collection purposes, third-party recipients and specific personal records stored by us, subject to CCPA legal exceptions.
2. Data Deletion Right
You may submit a request to delete all personal data we have stored about you, subject to legal exceptions (e.g. mandatory tax/transaction record retention).
Exercise CCPA Rights
Submit a verifiable consumer request via our official customer email: info@laymis.com. Your request must include sufficient identity verification information (e.g. order number, registered email, shipping address) for us to confirm your identity. We only use submitted verification data to authenticate your request. You may submit 2 access/portability requests within 12 months.
Do Not Sell My Data Right
California residents may request permanent suspension of personal data sale by emailing info@laymis.com. We may reject fraudulent requests with documented reasonable evidence.
Authorized Agent
Only yourself, your written authorized agent or legal guardian for minor children may submit CCPA data requests. Agents must provide written authorization proof, and we still require identity verification of the data owner.
Non-Discrimination
We will not deny services, charge differentiated prices, or provide downgraded product/service quality to any customer who exercises CCPA privacy rights.
California residents may request a list of third parties who received your personal data for direct marketing in the previous calendar year by contacting our support team.
Notice to Nevada Residents
Nevada residents may submit a verified request to stop all sale of your personal information by emailing info@laymis.com.
Your General Data Rights (Global Customers)
In accordance with Hong Kong PDPO, EU GDPR and local regional laws, you hold the following rights:
- Request access to all personal data we store about you
- Request correction, amendment or permanent deletion of inaccurate personal data
- Restrict or fully object to our data processing activities
- Withdraw any marketing consent you previously granted at any time (retrospective data processing remains lawful)
- Request data portability in machine-readable formats for cross-platform transfer
To exercise any privacy rights, contact us via the contact channel specified at the bottom of this policy.
Cross-Border Data Transfers
We store and process your personal data primarily in Hong Kong, and may transfer necessary data to logistics, payment and advertising service providers located in the United States, Europe, Middle East and other regions. Overseas jurisdictions may have different data protection standards than Hong Kong. All cross-border data transfers follow Hong Kong PDPO and GDPR security requirements, and we implement protective measures to secure your personal information.
Data Security Measures
We adopt comprehensive administrative, technical and physical security safeguards to protect your personal data against accidental loss, unauthorized access, alteration, disclosure and illegal destruction. All payment information is processed via encrypted compliant payment gateways.
Third-Party Website Links
Our Site may contain hyperlinks to external third-party websites for your reference. These external platforms operate independently and are not under our control. We strongly recommend you review their independent privacy policies before browsing. We bear no liability for external website content, user behavior or data privacy practices.
Policy Updates
We reserve the right to revise this Privacy Policy periodically to align with updated legal regulations and business practices. Material amendments will be posted with prominent notice on our website homepage, with the latest revision date marked at the top of this document. We will complete all legal notification obligations required by applicable laws.
Minors' Information
Our website is intended for adult customers only. We do not intentionally collect personal data from users under 13 years old. If we confirm we have obtained information from minors without parental consent, we will permanently delete all related records immediately. Contact our support team if you believe a minor has submitted personal data to us.
How to Contact Us
If you have questions, complaints or requests regarding this Privacy Policy or your personal data, please reach our customer support via:
- Email: info@laymis.com
-
Postal Mail:
Soline Limited
RM 5017, /F 5, YAU LEE CENTRE, 45 HOI YUEN ROAD, KWUN TONG, HONG KONG
Attention: Customer Data Support
European Union & EEA Supplementary GDPR Addendum
If you reside in the EU or EEA, the following GDPR clauses replace conflicting general provisions above:
- Personal data we process includes your contact details, account login information, order transaction records, and automated browsing tracking data via cookies.
- Legal bases for data processing: Performance of sales contracts with you, our legitimate commercial business interests, compliance with legal obligations, or your explicit opt-in consent (revocable anytime).
- Data retention period: We store your personal data for the full duration of your customer relationship, plus the statutory limitation period required by EU and Hong Kong laws for transaction record retention.
- Data sharing rules: We will never share your personal data with external third-party marketing companies without your separate written consent. All contracted service providers must sign data protection agreements to secure your information under GDPR standards.
- Your GDPR rights: Right to access, rectify, erase, restrict processing, data portability and object to marketing processing. You may submit a formal complaint to your local EU data protection authority if you are dissatisfied with our data handling response.
- Exercise GDPR rights: Send your request to our official email: info@laymis.com
Cookie Classification for EU Visitors
1. Essential Cookies
Mandatory for basic website navigation, login authentication and order checkout functions; cannot be disabled.
2. Functionality Cookies
Store your browsing preferences (language, region, saved cart items) to customize page display.
3. Analytics Cookies
Track anonymous website traffic data via Google Analytics to optimize site performance.
You may fully disable or customize cookie permissions via your browser settings at any time. Opt-out guides for mainstream browsers (Chrome, Edge, Safari, Firefox, IE) are available on the global cookie information website www.allaboutcookies.org. Opting out of tracking cookies only stops interest-based targeted ads, and you will still receive generic online advertisements.