Privacy Policy
1. Introduction
Shenzhen GoldMax Tech Co., Ltd. (operating as "GoldMax", "we", "our", "us"), a company registered in Shenzhen, People's Republic of China (Unified Social Credit Code 91440300MA5H7GXJ8K), respects your privacy and is committed to protecting your personal data in compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and the Personal Information Protection Law of the People's Republic of China (PIPL).
This Privacy Policy explains what personal data we collect when you visit goldmax3.com (the "Website") or interact with us, how we use that data, with whom we share it, how long we keep it, and what rights you have over it.
2. Data We Collect
2.1 Data you provide directly
- Contact & inquiry form data (when you submit a quote / sample / spec request via our Website): your name, business email, company name, business phone, country, target SKU, message body, and any attachments you choose to upload.
- Order-related data (if you proceed with a sample or production order): billing/shipping address, tax ID, business registration number, payment confirmation references.
- Correspondence: any messages, emails, or attachments you send to us via sales@goldmax3.com, WhatsApp, or any other channel.
2.2 Data collected automatically
- Technical data: IP address (truncated/anonymized), browser type and version, operating system, device type, screen resolution, referring URL, pages visited, time on page. We do not collect precise GPS or fingerprinting data.
- Cookies and similar technologies: see our separate Cookie Policy.
2.3 Data we do NOT collect
We do not knowingly collect special-category data (race, religion, health, sexual orientation, biometrics for identification, etc.) and do not target minors under 16.
3. How We Use Your Data (Purposes & Legal Basis)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Respond to your B2B inquiry / quote / sample request | Name, email, company, phone, country, message, SKU interest | Performance of a contract / pre-contractual steps (Art. 6(1)(b)) + Legitimate interest in B2B communication (Art. 6(1)(f)) |
| Fulfill and ship a sample or production order | Name, address, tax ID, phone, email, payment reference | Performance of a contract (Art. 6(1)(b)) + Legal obligation (tax/invoice) (Art. 6(1)(c)) |
| Website security, fraud prevention, abuse handling | IP address, request logs, user agent | Legitimate interest (Art. 6(1)(f)) |
| Aggregate, non-identifiable analytics to improve the site | Anonymized page views, device class, country (coarse) | Legitimate interest (Art. 6(1)(f)) — with IP truncation |
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share it only with the following limited categories of recipients, and only to the extent strictly necessary:
- Logistics providers (DHL, FedEx, UPS, EMS, sea freight forwarders) — to ship a sample or production order you placed. They receive only the data needed for delivery (name, address, phone, email).
- Payment processors (T/T bank channel, PayPal for small samples) — to process payment. We do not see or store full card numbers on our servers.
- IT service providers — domain registrar, hosting/CDN (Hostinger, Cloudflare), form/email service (Formspree when active), and our internal CRM. Each is bound by a data-processing agreement.
- EU Authorized Representative (see our Imprint) — for EU regulatory matters only.
- Law enforcement or regulators — only when compelled by valid legal process.
5. International Data Transfers
Our company is based in Shenzhen, China, and the primary data infrastructure is located there. When we transfer your data outside the country of collection (for example, to an EU logistics partner), we rely on one or more of the following safeguards:
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 1 / Module 2 as applicable).
- UK International Data Transfer Addendum for transfers from the United Kingdom.
- Contractual data-processing terms with each downstream recipient.
- For transfers from China: the Standard Contract for Cross-Border Transfer of Personal Information (China CAC, 2023) where applicable.
6. Data Retention
- Inquiry & quote data: 24 months from last interaction, after which it is anonymized for aggregate statistics or deleted.
- Order & invoice data: 7 years from invoice date (PRC tax law + EU VAT record-keeping).
- Server logs (IP, user agent): 90 days, then aggregated or deleted.
- Cookies: see Cookie Policy.
7. Your Rights
Subject to your jurisdiction, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion, subject to legal retention obligations.
- Restriction — limit how we process your data while a complaint is investigated.
- Portability — receive your data in a structured, machine-readable format (JSON / CSV).
- Objection — to processing based on legitimate interest, including direct B2B communications (you can opt out at any time).
- Withdraw consent — where processing is based on consent, you can withdraw it without affecting prior lawful processing.
- Lodge a complaint with your local data-protection authority (for EU residents, the supervisory authority in your Member State; for UK residents, the ICO; for California residents, the California AG).
To exercise any of these rights, email us at the address below. We will respond within 30 days (or the shorter period required by your local law).
8. Security
We protect your data with industry-standard measures: HTTPS/TLS in transit, access controls and least-privilege internally, encryption at rest for our CRM database, and regular backups stored in a separate geographic region. No method of transmission over the internet, however, is 100% secure; if you have reason to believe your interaction with us is no longer secure, please notify us immediately.
9. Children's Privacy
Our Website and services are not directed to children under 16 (or such higher age as your jurisdiction may require). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
10. Changes to This Policy
We will post any material changes on this page and update the "Effective date" above. For significant changes that affect you, we will additionally notify you by email (if you are an active customer or contact) or by a banner on the Website.
11. Contact & Data Protection Officer
For any privacy question, data-access request, or to lodge a complaint, please contact us:
Shenzhen GoldMax Tech Co., Ltd. (Data Controller)
Huarun Building, Futian District, Shenzhen, Guangdong 518000, People's Republic of China
Email: zhuyuki71@gmail.com (Subject: "Privacy Request")
Phone / WhatsApp: +86 135 4246 2845
EU Authorized Representative (for GDPR matters): see our Imprint.
Questions about this privacy policy?
Email: zhuyuki71@gmail.com
Phone: +86 135 4246 2845
Mail: Shenzhen GoldMax Tech Co., Ltd. · Huarun Building, Futian District, Shenzhen, China