SHINEPEARL Back to home

Privacy Policy

Last updated: 26 August 2026

Contents

  • 1. Introduction
  • 2. Developer and Operator of the Services
  • 3. Scope of This Privacy Policy
  • 4. Information We Collect
  • 5. Information You Provide Directly
  • 6. Information Collected Automatically
  • 7. Information From Third Parties
  • 8. How We Use Your Information
  • 9. Legal Bases for Processing
  • 10. Cookies and Similar Technologies
  • 11. How We Share Your Information
  • 12. International Data Transfers
  • 13. Data Retention
  • 14. Data Security Measures
  • 15. Privacy for Children
  • 16. Your Rights and Choices
  • 17. Third Party Links and Services
  • 18. Changes to This Privacy Policy
  • 19. Contact Us

1. Introduction

ShinePearl takes the protection of personal information seriously. This Privacy Policy explains how the systems design studio and its associated website collect, use, store and disclose personal information when you visit the website at shinepearl.buzz, when you contact the studio, and when you use any of the platforms, dashboards or integrated systems that the studio designs and operates for its clients.

This Privacy Policy is written in plain language wherever possible, but it also covers the detail required by the privacy regulations of the jurisdictions in which the company operates, including the General Data Protection Regulation of the European Economic Area and the California Consumer Privacy Act of the United States. By using the website or the services, you confirm that you have read and understood the terms set out in this document.

If you have any questions about this Privacy Policy, or about how your personal information is handled, you should contact the studio using the details provided in the final section of this document. We answer privacy questions quickly and we treat every request with the same care that we apply to the systems we build.

2. Developer and Operator of the Services

The website and all related systems are developed and operated by the developer ShinePearl on behalf of, and as part of, the trading company described below. ShinePearl acts as the design and engineering studio that builds the platforms, dashboards and data systems, while the trading company provides the operating context, the trade experience and the commercial relationships behind those systems.

The company responsible for the services described in this Privacy Policy is:

Changsha Yingyueyan Electronic Trading Co., Ltd.
No. 55, Aoxia Group, Yangtan Village, Gaoping Town,
Liuyang, Changsha - 410000, China (CN)

The studio can be reached by email at chat@shinepearl.buzz and by telephone at +16185821472. Any correspondence about personal data should be directed to the email address above so that the privacy team can acknowledge the request without delay.

Where this Privacy Policy refers to the company, the studio, ShinePearl, we or us, it means Changsha Yingyueyan Electronic Trading Co., Ltd. and the ShinePearl studio operating under it. Where the policy refers to you, it means the individual using the website or the services described in this document.

3. Scope of This Privacy Policy

This Privacy Policy applies to personal information collected through the website at shinepearl.buzz, through direct correspondence such as email, telephone and the contact form, and through the platforms and systems that the studio builds and operates for its commercial clients.

The policy also applies to personal information that may appear inside business systems that the studio integrates, for example contact names on purchase orders, employee details in supplier records, or recipient names on shipping manifests. In all of these cases the studio limits its use of personal information to the purposes required to deliver the service, and it applies the same protective standards described in this document.

This policy does not apply to the practices of third parties that are not controlled by the company. Where the website links to external services, or where a client system connects to an outside provider, the privacy practices of that provider are governed by the provider own policy. Section 17 of this document provides more detail about third party links.

4. Information We Collect

The studio collects information that is necessary to operate the website, to respond to inquiries, and to build and maintain the systems it delivers. The amount of information collected depends on how you interact with the studio. A visitor who simply reads the website generates very little personal data, while a client who commissions a platform will share business contact details and technical information as part of the engagement.

The categories of information the studio may collect are grouped under three headings in the sections that follow: information you provide directly, information collected automatically, and information received from third parties. Each category is described in detail so that you can understand what is collected, why it is collected, and how long it is kept.

The studio does not intentionally collect sensitive categories of personal data such as health records, political opinions or religious beliefs, and it does not use personal information for automated decision making that produces legal effects without a human review step.

5. Information You Provide Directly

When you use the contact form on the website, the studio receives the name, email address, subject and message that you type into the form. This information is used solely to respond to your inquiry and to keep a record of the correspondence in case a follow-up is needed. You are not required to provide more information than the form asks for.

When you email the studio directly, the studio receives the content of your message, your email address, and the technical metadata that email systems attach to messages, such as the timestamp and the routing information used to deliver the mail. This information is treated as confidential and is used only for the purpose of the correspondence.

When you commission the studio to build a system, the engagement documentation may include business contact details for yourself and for other people in your company, including names, job titles, business email addresses and telephone numbers. This information is used to deliver the project, to schedule meetings, and to provide support after launch. Payment and billing records may include invoicing addresses and bank details, which are handled under the security controls described in Section 14.

6. Information Collected Automatically

When you visit the website, the web server and the hosting provider automatically record technical information about the request. This includes the IP address of the device making the request, the browser type and version, the operating system, the referring page, the pages viewed and the approximate time of the visit. This information is used to keep the website secure, to diagnose faults and to understand which parts of the site are most useful.

The studio uses this technical information in an aggregated form wherever possible, so that individual visitors are not identifiable from the reports that are reviewed. Where raw logs are kept, access to them is restricted to the engineers who need them for security monitoring, and the logs are retained only for the period described in Section 13.

The website may set small data files known as cookies to remember simple preferences, such as whether a visitor has acknowledged an informational notice. These cookies do not track visitors across unrelated websites, and they can be disabled in the browser without stopping the website from working. Section 10 explains cookies in more detail.

7. Information From Third Parties

In the course of operating a trading business, the studio may receive personal information about you from other parties. For example, a client may provide the studio with the contact details of a person at a supplier, at a freight forwarder or at a customs agent so that a system integration can be configured correctly. The studio receives this information only in the context of a legitimate business relationship, and it uses it only for that purpose.

If you are listed on a shipping document, a purchase order or an invoice that passes through a system operated by the studio, the studio may process your name and contact details in order to route the document correctly. This processing is limited to what the transaction requires and does not extend to any use beyond the trade operation in question.

Publicly available business information, such as a company registration record or a published trade license, may be collected and stored in the supplier register that the studio maintains. This information is used for verification and for compliance with anti-fraud obligations, and it is kept in line with the retention rules in Section 13.

8. How We Use Your Information

The studio uses personal information for a clear and limited set of purposes. The primary purpose is to operate the website and to answer inquiries. When a visitor sends a message through the contact form or by email, the information is used to respond, to provide the requested information, and to maintain a record of the conversation so that the studio can follow up consistently.

The second purpose is to deliver contracted services. When the studio builds a platform, a dashboard or an integration, personal information that appears in the scope of the work is used to design, test, deploy and support the system. This includes configuring user accounts, training team members, migrating data and providing post-launch support.

The third purpose is compliance and security. Personal information may be used to verify identities, to detect fraud, to respond to legal requests and to meet the record-keeping obligations of the trading jurisdictions in which the company operates. The studio does not sell personal information to anyone, and it does not use personal information for marketing purposes without a clear and separate consent where the law requires one.

9. Legal Bases for Processing

Where the General Data Protection Regulation or an equivalent law applies, the studio relies on specific legal bases for each type of processing. The primary basis is consent, where you freely agree to the processing of your information for a stated purpose and can withdraw that agreement at any time without penalty.

The second basis is the performance of a contract. When you or your company engage the studio to build a system, processing the information needed to deliver that system is necessary for the contract, and the studio is entitled to process the information to the extent the work requires it.

The third basis is legitimate interest. The studio processes technical logs, records business correspondence and maintains supplier registers on the basis that these activities are necessary for the legitimate interests of running a secure and well-governed trading and engineering business. In every case the studio balances its interests against your rights and freedoms, and it stops a processing activity where the impact on you would outweigh the benefit to the business.

The final basis is legal obligation. Where the company is required by law to keep certain records, to answer a lawful request or to comply with a regulator, the processing is carried out to meet that obligation.

10. Cookies and Similar Technologies

Cookies are small text files that a website stores on the device of a visitor. The website uses cookies sparingly and only for the purposes described below. A cookie cannot read other files on your device, cannot run programs, and cannot deliver a virus.

The website uses a minimal set of functional cookies that remember preferences that make the site more pleasant to use, such as the collapsed state of an accordion or the confirmation of an informational notice. These cookies do not contain personal identifiers and they do not follow you around the web.

If analytics technology is enabled in the future, it will be configured to pseudonymize identifiers, to respect the do not track signal where it is available, and to avoid collecting precise location data. You can disable all cookies in your browser settings at any time. Doing so may change how some parts of the website behave, but it will not prevent you from reading the content or contacting the studio.

11. How We Share Your Information

The studio does not sell, rent or trade personal information. Information is shared only in the limited circumstances described here, and always with a contract or a legal basis in place that protects your data.

Service providers: the studio works with a small number of service providers who help run the website and the studio infrastructure, such as hosting providers, email services and analytics tooling. These providers receive only the information needed to perform their role, and they are bound by written agreements that require them to protect the data and to use it only for the stated purpose.

Business partners: where a platform operated by the studio connects to a bank, a payment processor, a freight forwarder or a customs agent, the minimum information needed to complete a transaction is shared with that partner. This sharing is necessary for the trade operation and is limited to the fields the transaction requires.

Legal and safety: the studio may disclose personal information where a court order, a regulator or a law enforcement request requires it, or where the disclosure is necessary to protect the safety of any person, to protect the property of the company, or to enforce the terms of an engagement.

12. International Data Transfers

The company is registered in China, and the studio operates from an office in Gaoping Town, Liuyang, Changsha. Information collected through the website and through client systems may therefore be stored on servers located outside the country in which you are based. Where your information is transferred across borders, the studio applies safeguards appropriate to the jurisdictions involved.

Where the transfer involves data of people in the European Economic Area, the United Kingdom or Switzerland, the studio relies on mechanisms that provide an adequate level of protection, such as standard contractual clauses approved by the relevant authorities, and it reviews those mechanisms as the legal landscape changes.

For data of people in other regions, the studio applies its own internal standard of protection, which is described in Section 14 and which mirrors the principles of this policy regardless of where the data physically sits. The technical controls do not change with geography; only the legal framework used to authorize the transfer does.

13. Data Retention

The studio keeps personal information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. When neither need remains, the information is deleted or made anonymous in a secure manner.

Contact form submissions and email correspondence are retained for a period of up to three years from the last contact, so that a conversation can be resumed without loss of context. Technical server logs are retained for a shorter period, typically thirty days, unless a security incident requires them to be kept longer for an investigation.

Client engagement records, including invoices, contracts and delivery documents, are retained for the period required by the tax and accounting laws of the jurisdictions in which the company operates, which is commonly five to seven years. Supplier register records are retained for as long as the business relationship continues and are reviewed on a rolling basis. All retention periods are applied automatically by the records management schedule, and deletion is performed so that the data cannot be recovered.

14. Data Security Measures

The studio applies a defense in depth approach to the protection of personal information. This means that no single control carries the whole burden; instead, several independent layers of protection are combined so that a failure in one layer does not expose the data.

At the technical level, all data in transit is protected with transport layer security, data at rest is encrypted using accepted encryption standards, and payment data is tokenized so that card details never touch the business systems in raw form. Access to production systems is granted on a least privilege basis, which means every person has only the access their role requires and nothing more.

At the process level, the studio enforces separation of duties for sensitive actions, logs access events for review, and conducts regular vulnerability assessments. Staff members are trained in data handling at least once a year, and the incident response plan is rehearsed so that a suspected breach can be contained, assessed and reported without delay.

No method of transmission or storage is completely secure, and the studio cannot guarantee absolute protection against every possible threat. It can guarantee that it applies industry standard controls, that it reviews them continuously, and that it reports any confirmed incident in line with the law.

15. Privacy for Children

The website and the studio services are designed for commercial use and are not directed at children. The studio does not knowingly collect personal information from children under the age of sixteen, and the services are not intended for use by anyone under that age.

Where a jurisdiction sets a different minimum age for consent, the higher standard is applied for people in that jurisdiction. If the studio becomes aware that personal information of a child has been collected without appropriate consent, it will delete the information promptly and confirm the deletion to the parent or guardian who reported it.

If you are a parent or guardian and you believe that a child has provided personal information through the website or through a business system, please contact the studio using the details in Section 19 and the matter will be handled without delay.

16. Your Rights and Choices

Depending on the jurisdiction in which you are based, you have a set of rights over your personal information. The studio honors these rights wherever they apply and responds to every valid request without undue delay.

You may request access to the personal information the studio holds about you, a copy of that information in a portable format, and a correction where the information is inaccurate or incomplete. You may ask for the information to be deleted, or for processing to be restricted, where the legal conditions for those requests are met. Where processing is based on consent, you may withdraw that consent at any time, and where processing is based on legitimate interest, you may object to it.

To exercise any of these rights, contact the studio at chat@shinepearl.buzz. The studio will verify the identity of the requester before acting, to protect your information from being disclosed to the wrong person. You also have the right to lodge a complaint with the supervisory authority in the place where you live, work or believe a breach occurred, if you are not satisfied with how a request was handled.

17. Third Party Links and Services

The website may contain links to external websites and services that are not operated by the studio. This Privacy Policy does not govern the practices of those external providers, and the studio is not responsible for the content or the privacy behavior of any third party site.

Where a client system integrates with an outside provider, such as a carrier portal, a payment gateway or a bank interface, data shared with that provider is governed by the provider own terms and privacy policy. The studio reviews the credentials of its integration partners and limits the data shared to the minimum required for the integration to function.

Before you leave the website and visit an external service, you should review the privacy policy of that service so that you understand how your information will be handled. The studio cannot control, and does not accept responsibility for, the practices of third parties.

18. Changes to This Privacy Policy

The studio reviews this Privacy Policy on a regular basis and may update it from time to time to reflect changes in the law, in the services, or in the way the business operates. When a change is made, the last updated date at the top of this document is revised to reflect the effective date.

Where a change is material, such as a new category of data collected or a new sharing arrangement, the studio will draw your attention to the change by posting a notice on the website before the change takes effect. For changes that are minor or clarifying, the updated policy takes effect on the date it is published.

Continued use of the website or the services after a change takes effect means that you accept the updated policy. If you do not agree with a change, you should stop using the services and contact the studio if you want the relevant data to be removed or updated.

19. Contact Us

If you have a question about this Privacy Policy, about your personal information, or about any of the rights described in Section 16, please contact the studio. Every privacy inquiry is acknowledged within one business day and answered as quickly as the subject allows.

The best way to reach the privacy team is by email. You can also write to the registered office of the company or call the studio during business hours.

Changsha Yingyueyan Electronic Trading Co., Ltd.
No. 55, Aoxia Group, Yangtan Village, Gaoping Town,
Liuyang, Changsha - 410000, China (CN)

Email: chat@shinepearl.buzz
Telephone: +16185821472

When you contact the studio, please describe the request clearly and provide enough detail for the identity to be verified. The studio will not use the personal information provided in the request for any purpose other than answering it.

Last updated: 26 August 2026
  • Home
  • Services
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Changsha Yingyueyan Electronic Trading Co., Ltd. · chat@shinepearl.buzz · +16185821472 · No. 55, Aoxia Group, Yangtan Village, Gaoping Town, Liuyang, Changsha - 410000, China (CN)