Language and currency: EN · SEK
Bag

RAYLISSM · 10 October 2026

Privacy policy

What personal data we collect, why, who receives it and your rights.

Who is responsible for your data

I.T APPARELS LIMITED, trading as RAYLISSM, 31/F, Tower A, Southmark, 11 Yip Hing Street, Wong Chuk Hang, Hong Kong, is the data user (under Hong Kong law) and the controller (under the EU and UK GDPR) of the personal data described here. Contact: support@raylissm.shop, +852 5974 3863.

We follow the Personal Data (Privacy) Ordinance (Cap. 486, “PDPO”) and its six Data Protection Principles. Where we sell to people in the European Economic Area, Switzerland or the United Kingdom, we also follow the EU General Data Protection Regulation, the Swiss Federal Act on Data Protection and the UK GDPR.

What we collect and why

DataWhy we use itLegal basis (EEA/UK)
Name, delivery and billing address, email, phoneTo process, deliver and support your order and to send order emailsPerformance of a contract
Order history, amounts, currencyTo keep accounting records and handle returns, withdrawals and refundsLegal obligation; contract
Payment detailsEntered directly with our payment service provider, which processes the payment and checks it for fraud. We receive only a confirmation, the payment type and, for cards, the last four digits.Contract; legitimate interest in preventing fraud
Account login (only if you create an account)To let you see your orders and save addressesContract
Messages and withdrawal notices you send usTo answer you and process your withdrawal or returnContract; legal obligation; legitimate interest
Technical data (IP address, browser, pages requested)Server logs to keep the site secure and working, and to limit spam on our formsLegitimate interest

We collect only what we need for these purposes (DPP1). We do not use your data for advertising, we do not sell it, we do not build profiles and we do not use it for any new purpose without your explicit and voluntary consent (DPP3). We do not send marketing emails.

Who we share it with

We share personal data only with service providers who need it to deliver our service, and only for that purpose:

  • our payment service provider(s) (payments and fraud prevention);
  • postal and courier companies, and customs authorities (delivery and customs declarations for your parcel);
  • our website hosting and email providers.

We may also disclose data where the law requires it, for example to tax authorities or to a court.

Transfers outside your country

We are based in Hong Kong, so your data is processed in Hong Kong and in the countries where our service providers operate. We follow the Privacy Commissioner for Personal Data’s Guidance on Cross-border Data Transfer, including its recommended model contractual clauses, as a matter of practice.

If you are in the EEA, Switzerland or the UK: the transfer of your order data to us in Hong Kong is necessary to perform the contract you ask us to enter into (Article 49(1)(b) GDPR). Where our service providers transfer data internationally, they use safeguards such as the European Commission’s standard contractual clauses.

How long we keep it

  • Order and accounting records: 7 years, as required by Hong Kong tax law.
  • Withdrawal and return records: 7 years, with the order.
  • Customer account: until you ask us to close it.
  • Messages: 2 years after the matter is closed.
  • Server logs: up to 30 days.

We do not keep personal data longer than necessary (DPP2).

Security

The whole site runs over HTTPS. Payment details go directly to our payment service provider, which is PCI DSS compliant. Access to customer data is limited to the people who need it to fulfil orders (DPP4).

Hong Kong does not currently require data-breach notification. We will notify the Privacy Commissioner for Personal Data and the people affected anyway where a breach creates a real risk of harm. Where the EU or UK GDPR applies to us, we will notify the relevant supervisory authority as that law requires.

Your rights

Under the PDPO you can ask to see the personal data we hold about you (a data access request) and to correct it (DPP6). We respond within 40 days. We may charge a fee that is not excessive for a data access request; we will tell you the amount first.

If you are in the EEA, Switzerland or the UK, you also have the right to erasure, to restrict or object to processing and to data portability, and you can withdraw consent at any time where we rely on consent.

To use any of these rights, email support@raylissm.shop. We may ask you to confirm your identity.

You can complain to the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk). If you are in the EEA, you can complain to the data protection authority in your country (for example Datatilsynet in Denmark, or the data protection authority of your federal state in Germany); in the UK, to the Information Commissioner’s Office; in Switzerland, to the Federal Data Protection and Information Commissioner.

Cookies

We use only cookies that are necessary for the shop to work: your bag, your currency, sign-in if you use an account, and fraud prevention at checkout. We do not use analytics or advertising cookies. Details are on our cookie policy.

Children

Our shop is not aimed at children, and we do not knowingly collect data from anyone under 16.

Changes to this policy

Hong Kong’s data protection law is under review. We will update this policy if the requirements change, and show the date of the latest version at the top of this page.