Privacy first

Privacy Policy — HK TRENRIX CO., LIMITED 🐼🔒

Plain-English summary; full policy below. Effective 24 September 2026. Covers our website, mobile apps, and every ad-network partner we work with. 🌍

Manage Cookies Email DPO
Effective date 24 September 2026 (last updated 24 September 2026)

Operator: HK TRENRIX CO., LIMITED.
Registered address: Rm 701(127) 7/F NEW MANDARIN PLZ TWR B 14 SCIENCE MUSEUM RD, Tsim Sha Tsui East, Hong Kong.
General support: support@xinhengtonghk.com  ·  Key-account contact: chenhongzhou@xinhengtonghk.com

Welcome to HK TRENRIX. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have under data-protection law. We operate the website at xinhengtonghk.com and a suite of mobile applications published on the Apple App Store and Google Play. We take privacy seriously and have written this policy in plain English so European and American users can understand it. If anything below is unclear, please email us at support@xinhengtonghk.com.

We process personal data on the following legal bases under the General Data Protection Regulation (where applicable): (i) consent, for advertising personalisation and for placing non-essential cookies; (ii) performance of a contract, for delivering the services you request; (iii) compliance with a legal obligation, for tax, accounting, and law-enforcement purposes; and (iv) legitimate interest, for security, fraud prevention, basic analytics, and product improvement, balanced against your rights and freedoms.

📑 Contents

  1. Information we collect
  2. Cookies and tracking technologies
  3. Third-party SDKs and partners
  4. Ad formats and platforms
  5. App distribution channels
  6. Children's privacy (COPPA)
  7. GDPR rights (EEA)
  8. UK GDPR rights
  9. CCPA / CPRA rights (California)
  10. PIPEDA (Canada)
  11. LGPD (Brazil)
  12. Australia Privacy Act 1988
  13. Singapore PDPA
  14. Hong Kong PDPO
  15. International data transfers
  16. Data retention
  17. Security measures
  18. Changes to this policy
  19. Contact

01 Information We Collect

We collect personal data in two ways: automatically, when you visit our website or use our apps, and voluntarily, when you choose to provide it (for example, by filling in the contact form or subscribing to our newsletter).

Information collected automatically includes IP address, approximate geolocation derived from IP, browser type and version, operating system, device identifiers (IDFA / GAID / IDFV), referring URL, pages viewed, timestamps, ad identifiers, crash logs, performance diagnostics, and interactions with in-app ads. This data is gathered through our first-party analytics pipeline and through the third-party SDKs listed in Section 3 below.

Information collected voluntarily includes name, email address, company name, job title, country, and any message content that you send through our inquiry or newsletter forms, plus any information you choose to share with our support team by email. If you are a key-account contact, we may also store your business address, phone number, and contract information in our CRM system.

Sensitive personal data. We do not knowingly collect special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sexual orientation or sex life) through our websites or apps. If you voluntarily submit such information through a free-text field, we will delete it as soon as we become aware.

Children's data. We do not knowingly collect personal data from children under the age of digital consent in any country where our service is offered. See Section 6 below for the COPPA-specific process.

02 Cookies and Tracking Technologies

We use cookies, local storage, and similar tracking technologies on our website and inside our apps. These technologies fall into four categories:

  • Strictly necessary — session cookies, security tokens, and load-balancing cookies that are required for the site or app to function. These cannot be disabled.
  • Performance and analytics — first-party and third-party cookies that measure traffic, page-load time, and crash behaviour so that we can improve our products.
  • Functionality — cookies that remember preferences such as language, region, and consent choices.
  • Advertising — cookies and mobile advertising identifiers (IDFA, GAID) used by the ad networks listed in Section 3 to deliver, measure, and personalize ads.

You can manage cookie preferences through our consent banner (which defaults to "deny" for visitors we believe to be located in the European Economic Area, the United Kingdom, or California), or through your browser's privacy settings. For mobile apps, you can reset or limit ad identifiers through your device settings ("Limit Ad Tracking" on iOS, "Opt out of Ads Personalization" on Android). Declining non-essential cookies will not prevent you from using our website, but it may reduce the relevance of advertising shown inside our apps.

We also honour Global Privacy Control (GPC) signals where the relevant browser transmits them. A GPC signal is treated as a valid opt-out of sale or sharing for the browser session.

03 Third-Party SDKs and Partners

Our mobile applications integrate third-party software development kits (SDKs) for analytics, advertising, and crash reporting. Each SDK acts as a joint or independent data controller under most privacy regimes and has its own privacy practices. The full list of ad monetization partners integrated into our apps is:

1 Google AdMob
2 Google Ad Manager
3 Google AdSense
4 Meta Audience Network
5 AppLovin
6 AppLovin MAX
7 Unity Ads
8 Unity LevelPlay
9 ironSource
10 Vungle (Liftoff)
11 Chartboost (InMobi via Glance)
12 InMobi
13 Tapjoy
14 Pangle (ByteDance)
15 Amazon Publisher Services (APS)
16 StartApp
17 Mintegral
18 Smaato
19 AdColony (Digital Turbine)
20 Digital Turbine
21 HyprMX
22 Ogury
23 Persona.ly
24 SuperAwesome (kid-safe)

Each of the SDKs above may collect device identifiers, IP address, approximate location, app-usage events, ad-impression and click data, and (where the user has granted consent) advertising identifiers. We rely on each SDK's own privacy policy and certification regime. A detailed compliance matrix (with privacy URLs, opt-out URLs, and certifications) is maintained in our internal document docs/ad-platforms.md and is available upon request to support@xinhengtonghk.com.

In addition to advertising SDKs, our apps may include analytics SDKs (such as Firebase Analytics, Google Analytics for Firebase, or app-store-provided analytics), crash-reporting SDKs (such as Firebase Crashlytics or equivalent), and attribution SDKs (such as Adjust, AppsFlyer, or Singular) to measure install sources, in-app engagement, and product stability. These SDKs are governed by their own privacy policies and are listed in our internal compliance matrix.

04 Ad Formats and Platforms

Our apps integrate the four major mobile ad formats:

Open-screen (splash) ads

Full-screen ads that appear at app launch or return-to-foreground, usually lasting three to eight seconds and offering a "Skip" button where required by local law. Open-screen ads may be sourced through Google AdMob, AppLovin, Meta Audience Network, Unity Ads, ironSource, Vungle, InMobi, Mintegral, Pangle, Digital Turbine, or Smaato.

Rewarded video ads

Opt-in video ads where the user chooses to watch a video (typically 15–30 seconds) in exchange for an in-app reward such as extra lives, in-app currency, or a content unlock. Rewarded video ads may be sourced through Google AdMob, AppLovin MAX, Unity LevelPlay, ironSource, Vungle, Tapjoy, Pangle, Mintegral, AdColony (Digital Turbine), HyprMX, Ogury, and Persona.ly.

Interstitial ads

Full-screen ads shown at natural transition points in the app flow (for example, between levels, after completing a task, or before returning to a content list). Interstitial ads may be sourced through Google AdMob, Google Ad Manager, Meta Audience Network, AppLovin, Unity Ads, ironSource, Chartboost, InMobi, Tapjoy, Pangle, Amazon Publisher Services, StartApp, Mintegral, Smaato, AdColony (Digital Turbine), and Persona.ly.

Banner ads

Rectangular ads embedded in fixed or scrollable layouts near the top or bottom of a screen. Banner ads may be sourced through Google AdMob, Google AdSense, Google Ad Manager, AppLovin, Unity Ads, ironSource, InMobi, Pangle, Amazon Publisher Services, Smaato, HyprMX, and Persona.ly.

All four formats are sourced through the SDK partners in Section 3. Ad creative and frequency are managed by each partner's mediation stack and are subject to the partner's own policy on frequency capping, child-directed treatment, and sensitive-category restrictions. We configure cap settings in our mediation dashboard to limit how often any given user sees each format, and we honour platform-provided signals (such as Apple's "AdTrackingTransparency" framework on iOS and Google's "User Messaging Platform" on Android) to honour user consent before showing personalised ads. Where required by law, non-personalised contextual ads are shown in place of personalised ads.

05 App Distribution Channels

Our mobile applications are distributed through (a) the Apple App Store under the Apple Developer Program License Agreement (the "Apple EULA") and the Apple Media Services Terms and Conditions, and (b) Google Play under the Google Play Developer Distribution Agreement and the Google Play Developer Program Policies.

Apple App Store

By downloading or using our apps through the App Store, you agree to the Apple EULA, which is incorporated into this Privacy Policy by reference. Apple processes certain data (such as the App Store account, download events, and crash logs) as an independent controller. You can review Apple's privacy practices at https://www.apple.com/legal/privacy/ and exercise your Apple-ID-level privacy choices in your Apple device settings. Where our apps request App Tracking Transparency (ATT) consent before accessing the IDFA, we honour the user's choice and serve only contextual ads to users who decline. Our apps maintain a Privacy Manifest (in line with Apple's privacy-manifest requirement) declaring the APIs we use and the limited reasons for each API's use.

Google Play

By downloading or using our apps through Google Play, you agree to the Google Play Terms of Service and the Google Play Developer Distribution Agreement. Google processes certain data (such as your Google account, payment method, and Play Store activity) as an independent controller. You can review Google's privacy practices at https://policies.google.com/privacy and manage ad-personalization settings at https://adssettings.google.com. Our apps integrate Google's User Messaging Platform (UMP) to surface jurisdiction-specific consent forms for users in the European Economic Area, the United Kingdom, and other regions where consent is required for personalized advertising or for transferring device identifiers to ad partners.

Both Apple and Google provide their own age-rating and data-safety systems. Our apps are submitted with age ratings and data-safety labels appropriate to their content, and we update those labels whenever the data practices of the app change. Our apps may also be distributed through enterprise channels, beta programmes (TestFlight, Google Play Internal Testing, Google Play Closed/Open Beta), or alternative app-distribution mechanisms permitted by Apple and Google in their respective countries.

06 Children's Privacy (COPPA and equivalent)

Our apps and services are not directed to children under the age of 13, and we do not knowingly collect personal data from children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). If we learn that we have inadvertently collected personal data from a child under 13, we will delete the data as soon as possible. Parents or guardians who believe that a child under 13 has provided personal data to us may contact us at support@xinhengtonghk.com, and we will respond within thirty (30) days.

For users located in the European Economic Area, the United Kingdom, or other jurisdictions with a higher age of digital consent (commonly 14, 15, or 16), we apply that higher age. Where we offer an experience that is suitable for children, we rely on the SuperAwesome SDK (Section 3, item 24) for child-safe ad serving, which does not use behavioural advertising and does not collect persistent device identifiers for users flagged as children.

07 GDPR Rights (European Economic Area)

If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation (Regulation (EU) 2016/679):

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request that we correct inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten") — request that we delete your personal data in certain circumstances.
  • Right to restriction of processing — request that we limit the processing of your personal data in certain circumstances.
  • Right to data portability — request that we provide your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to object — object to processing based on legitimate interest, including profiling.
  • Rights related to automated decision-making and profiling — not be subject to a decision based solely on automated processing that produces legal effects concerning you, except where permitted by law.
  • Right to withdraw consent — where processing is based on consent, withdraw that consent at any time without affecting prior processing.
  • Right to lodge a complaint — lodge a complaint with the supervisory authority in your country of residence.

To exercise any of these rights, email support@xinhengtonghk.com. We will respond within thirty (30) days, or sooner where required by local law. Where the request is complex or numerous, we may extend the response period by up to two further months under Article 12(3) of the GDPR, and we will inform you of any such extension within thirty (30) days of receiving the request together with the reasons for the delay. We may need to verify your identity before responding in order to protect against fraudulent requests.

08 UK GDPR Rights

If you are located in the United Kingdom, you have the same rights described in Section 7 above under the United Kingdom General Data Protection Regulation (the "UK GDPR") and the Data Protection Act 2018. The UK Information Commissioner's Office (ICO) is the supervisory authority for most UK data-protection matters, and you may contact the ICO at https://ico.org.uk. International transfers from the UK are governed by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, plus applicable adequacy regulations.

If you are located in Switzerland, the Federal Act on Data Protection (FADP) gives you equivalent rights, and the Federal Data Protection and Information Commissioner (FDPIC) is the supervisory authority.

09 CCPA / CPRA Rights (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA"):

  • Right to know — request that we disclose the categories and specific pieces of personal information collected, the categories of sources, the business or commercial purposes, and the categories of third parties with whom personal information is shared.
  • Right to delete — request that we delete personal information we have collected from you, subject to the exceptions in CCPA/CPRA.
  • Right to correct — request that we correct inaccurate personal information.
  • Right to opt out of sale or sharing — direct us not to sell or share your personal information. We do not sell personal information for money; however, the use of advertising SDKs may constitute "sharing" for cross-context behavioural advertising, which you may opt out of.
  • Right to limit use of sensitive personal information — direct us to limit the use of sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected.
  • Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights, including by denying service, charging different prices, or providing a different level of quality.

To exercise your rights, email support@xinhengtonghk.com or use the "Do Not Sell or Share My Personal Information" link on our website. Authorized agents may submit requests on a consumer's behalf in accordance with CCPA/CPRA regulations. We will acknowledge your request within 10 business days and respond substantively within 45 calendar days, with one permitted 45-day extension where reasonably necessary.

10 PIPEDA (Canada)

If you are located in Canada, the Personal Information Protection and Electronic Documents Act ("PIPEDA") gives you the right to access the personal information we hold about you, to challenge its accuracy, and to withdraw consent to its use, subject to legal or contractual restrictions. We obtain meaningful consent for the collection, use, and disclosure of personal information, except where inappropriate. We are accountable for the personal information under our control, including information transferred to third-party processors in other countries. To exercise your rights under PIPEDA, please contact support@xinhengtonghk.com. The Office of the Privacy Commissioner of Canada is the federal supervisory authority and can be reached at https://www.priv.gc.ca. In Quebec, the Act respecting the protection of personal information in the private sector (often referred to as "Quebec Law 25") may impose additional requirements; we apply equivalent or stronger controls globally.

11 LGPD (Brazil)

If you are located in Brazil, the Lei Geral de Proteção de Dados (the "LGPD", Law No. 13.709/2018) gives you the following rights:

  • Confirmation of the existence of processing activities.
  • Access to the personal data we hold about you.
  • Correction of incomplete, inaccurate, or outdated personal data.
  • Anonymization, blocking, or elimination of unnecessary or excessive personal data.
  • Portability of your personal data to another service provider.
  • Elimination of personal data processed with your consent.
  • Information about the entities with whom your personal data has been shared.
  • Information about the possibility of declining consent and the consequences of doing so.
  • Revocation of consent.

To exercise these rights, contact support@xinhengtonghk.com. The Autoridade Nacional de Proteção de Dados (ANPD) is the supervisory authority. We honour LGPD requests free of charge, and where a request is manifestly unfounded or excessive we may charge a proportional fee or decline to act, providing a reasoned response in either case.

12 Australia Privacy Act 1988

If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APP) give you rights relating to the collection, use, disclosure, storage, and destruction of your personal information. We collect personal information by lawful and fair means, only for purposes that are reasonably necessary for or directly related to our functions, and we endeavour to keep it accurate, up-to-date, and secure. You may request access to, or correction of, your personal information by emailing support@xinhengtonghk.com. The Office of the Australian Information Commissioner (OAIC) is the supervisory authority and can be reached at https://www.oaic.gov.au. We do not engage in any conduct that would be in breach of the Notifiable Data Breaches scheme, and we will notify affected individuals and the OAIC as required where an eligible data breach occurs.

13 Singapore PDPA

If you are located in Singapore, the Personal Data Protection Act 2012 (the "PDPA") gives you rights to access and correct your personal data, to withdraw consent (subject to legal or contractual restrictions), and to opt out of marketing communications. We have designated a Data Protection Officer who can be reached at support@xinhengtonghk.com. The Personal Data Protection Commission (PDPC) is the supervisory authority and can be reached at https://www.pdpc.gov.sg. We honour Do-Not-Call (DNC) registry status where it applies and provide a clear unsubscribe path in every marketing email.

14 Hong Kong PDPO

If you are located in Hong Kong, the Personal Data (Privacy) Ordinance (Cap. 486, the "PDPO") governs the collection, use, disclosure, and handling of personal data. We comply with the six data-protection principles in Schedule 1 of the PDPO, including the requirement to provide a collection notice at or before the time of collection. You have the right to request access to and correction of your personal data held by us. Requests may be addressed to support@xinhengtonghk.com. The Office of the Privacy Commissioner for Personal Data (PCPD) is the supervisory authority and can be reached at https://www.pcpd.org.hk. The PDPO also recognises cross-border transfer principles; we ensure that personal data transferred out of Hong Kong is protected by substantially comparable policies or by contractual obligations.

15 International Data Transfers

Personal data collected from you may be transferred to, stored, and processed in countries other than your country of residence, including the United States, Singapore, Hong Kong, the European Union, and other locations where our cloud and ad-tech providers operate. When we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCC), the UK International Data Transfer Agreement (IDTA), or applicable adequacy decisions, including the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the DPF, and the Swiss-U.S. DPF. Copies of the safeguards we rely on are available on request to support@xinhengtonghk.com. We also conduct transfer-impact assessments for transfers to jurisdictions that may not have been recognised by the European Commission or the UK government as providing adequate protection.

16 Data Retention

We retain personal data for as long as necessary to provide our services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention windows:

  • Account and CRM records — 7 years after the end of the relationship, for accounting and tax compliance.
  • Support correspondence — 3 years after the last interaction.
  • Analytics and product telemetry — 14 months in identifiable form; aggregate analytics may be retained indefinitely.
  • Advertising data — retained by each ad partner according to their own retention policies, listed in our internal docs/ad-platforms.md.
  • Server logs — 90 days.
  • Backups — up to 12 months, encrypted and access-controlled.

When personal data is no longer needed for the purposes described in this policy, we will either delete it, de-identify it, or aggregate it so that it can no longer be associated with you.

17 Security Measures

We employ industry-standard administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These include TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access control (RBAC), multi-factor authentication for production systems, vendor due diligence for sub-processors, continuous vulnerability scanning, and incident response procedures with a 72-hour breach-notification commitment where required by law. We also perform regular internal security reviews, segregate production and development environments, log access to production data, and require all employees and contractors with access to personal data to complete annual privacy and security training.

18 Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of the policy and, where the change is material, provide a more prominent notice through our website, apps, or by email (where you have provided one and have not unsubscribed). We encourage you to review the policy periodically. A version history of this policy is maintained at https://xinhengtonghk.com/privacy.html#version-history and includes a summary of material changes for each version.

19 Contact

If you have any questions about this Privacy Policy, our data practices, or wish to exercise any of your privacy rights, you may contact us at:

  • Email (general support): support@xinhengtonghk.com
  • Email (key account): chenhongzhou@xinhengtonghk.com
  • Postal address: Rm 701(127) 7/F NEW MANDARIN PLZ TWR B 14 SCIENCE MUSEUM RD, Tsim Sha Tsui East, Hong Kong

We will respond to your request as soon as reasonably practicable, and in any event within the timeframes required by applicable law.

For the avoidance of doubt, this Privacy Policy applies to the website xinhengtonghk.com and to all mobile applications published by HK TRENRIX CO., LIMITED on the Apple App Store and Google Play, together with any successor domains or applications we may operate. If we materially change the data practices of an existing app, we will update the data-safety labels in the corresponding app store listing before the change takes effect, in line with Apple and Google platform rules.


Version history

  • v1.0 — 24 Sep 2026: Initial publication. Covers GDPR / UK GDPR / CCPA-CPRA / COPPA / LGPD / PIPEDA / Australia Privacy Act / Singapore PDPA / Hong Kong PDPO, plus all 24 ad-monetization partners. 🐼