RAYLISSM · 10 October 2026
Privacy policy
What personal data we collect, why, who receives it and your rights.
Who is responsible for your data
I.T APPARELS LIMITED, trading as RAYLISSM, 31/F, Tower A, Southmark, 11 Yip Hing Street, Wong Chuk Hang, Hong Kong, is the data user (under Hong Kong law) and the controller (under the EU and UK GDPR) of the personal data described here. Contact: support@raylissm.shop, +852 5974 3863.
We follow the Personal Data (Privacy) Ordinance (Cap. 486, “PDPO”) and its six Data Protection Principles. Where we sell to people in the European Economic Area, Switzerland or the United Kingdom, we also follow the EU General Data Protection Regulation, the Swiss Federal Act on Data Protection and the UK GDPR.
What we collect and why
| Data | Why we use it | Legal basis (EEA/UK) |
|---|---|---|
| Name, delivery and billing address, email, phone | To process, deliver and support your order and to send order emails | Performance of a contract |
| Order history, amounts, currency | To keep accounting records and handle returns, withdrawals and refunds | Legal obligation; contract |
| Payment details | Entered directly with our payment service provider, which processes the payment and checks it for fraud. We receive only a confirmation, the payment type and, for cards, the last four digits. | Contract; legitimate interest in preventing fraud |
| Account login (only if you create an account) | To let you see your orders and save addresses | Contract |
| Messages and withdrawal notices you send us | To answer you and process your withdrawal or return | Contract; legal obligation; legitimate interest |
| Technical data (IP address, browser, pages requested) | Server logs to keep the site secure and working, and to limit spam on our forms | Legitimate interest |
We collect only what we need for these purposes (DPP1). We do not use your data for advertising, we do not sell it, we do not build profiles and we do not use it for any new purpose without your explicit and voluntary consent (DPP3). We do not send marketing emails.
Who we share it with
We share personal data only with service providers who need it to deliver our service, and only for that purpose:
- our payment service provider(s) (payments and fraud prevention);
- postal and courier companies, and customs authorities (delivery and customs declarations for your parcel);
- our website hosting and email providers.
We may also disclose data where the law requires it, for example to tax authorities or to a court.
Transfers outside your country
We are based in Hong Kong, so your data is processed in Hong Kong and in the countries where our service providers operate. We follow the Privacy Commissioner for Personal Data’s Guidance on Cross-border Data Transfer, including its recommended model contractual clauses, as a matter of practice.
If you are in the EEA, Switzerland or the UK: the transfer of your order data to us in Hong Kong is necessary to perform the contract you ask us to enter into (Article 49(1)(b) GDPR). Where our service providers transfer data internationally, they use safeguards such as the European Commission’s standard contractual clauses.
How long we keep it
- Order and accounting records: 7 years, as required by Hong Kong tax law.
- Withdrawal and return records: 7 years, with the order.
- Customer account: until you ask us to close it.
- Messages: 2 years after the matter is closed.
- Server logs: up to 30 days.
We do not keep personal data longer than necessary (DPP2).
Security
The whole site runs over HTTPS. Payment details go directly to our payment service provider, which is PCI DSS compliant. Access to customer data is limited to the people who need it to fulfil orders (DPP4).
Hong Kong does not currently require data-breach notification. We will notify the Privacy Commissioner for Personal Data and the people affected anyway where a breach creates a real risk of harm. Where the EU or UK GDPR applies to us, we will notify the relevant supervisory authority as that law requires.
Your rights
Under the PDPO you can ask to see the personal data we hold about you (a data access request) and to correct it (DPP6). We respond within 40 days. We may charge a fee that is not excessive for a data access request; we will tell you the amount first.
If you are in the EEA, Switzerland or the UK, you also have the right to erasure, to restrict or object to processing and to data portability, and you can withdraw consent at any time where we rely on consent.
To use any of these rights, email support@raylissm.shop. We may ask you to confirm your identity.
You can complain to the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk). If you are in the EEA, you can complain to the data protection authority in your country (for example Datatilsynet in Denmark, or the data protection authority of your federal state in Germany); in the UK, to the Information Commissioner’s Office; in Switzerland, to the Federal Data Protection and Information Commissioner.
Cookies
We use only cookies that are necessary for the shop to work: your bag, your currency, sign-in if you use an account, and fraud prevention at checkout. We do not use analytics or advertising cookies. Details are on our cookie policy.
Children
Our shop is not aimed at children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
Hong Kong’s data protection law is under review. We will update this policy if the requirements change, and show the date of the latest version at the top of this page.