Privacy Policy
Last updated: April 15, 2026
Data Controller
The data controller responsible for your personal data is:
Hanlin Industrial Co., Ltd. (formerly Guangzhou VG Leather Co., Ltd.)
Registered Address: No.5 1st Industrial Street, Lingnan Industrial Park, Shiling Town, Huadu District, Guangzhou, Guangdong, China
Email: info@hanlinbags.com
Introduction
Hanlin Industrial Co., Ltd. respects your privacy and is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This privacy policy informs you about how we look after your personal data when you visit our website and tells you about your privacy rights and how the law protects you.
Information We Collect
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: including name, username, or similar identifier
- Contact Data: including email address, telephone numbers, and shipping/billing address
- Technical Data: including internet protocol (IP) address, your login data, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
- Usage Data: including information about how you use our website, products and services
- Marketing and Communications Data: including your preferences in receiving marketing from us and your communication preferences
Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
- Performance of a Contract (Art. 6(1)(b)): Processing necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract (e.g., providing our services, processing orders)
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, provided your interests and fundamental rights do not override those interests (e.g., improving our services, fraud prevention, network security)
- Legal Obligation (Art. 6(1)(c)): Processing necessary for compliance with a legal obligation to which we are subject (e.g., tax and accounting requirements)
- Consent (Art. 6(1)(a)): Processing based on your explicit consent (e.g., marketing communications, non-essential cookies). You have the right to withdraw consent at any time.
How We Use Your Information
We use your personal data for the following purposes:
- To provide and maintain our service (Legal basis: Contract performance)
- To notify you about changes to our service (Legal basis: Contract performance)
- To provide customer support (Legal basis: Contract performance)
- To gather analysis or valuable information so that we can improve our service (Legal basis: Legitimate interests)
- To monitor the usage of our service and ensure network security (Legal basis: Legitimate interests)
- To detect, prevent and address technical issues and fraud (Legal basis: Legitimate interests and legal obligations)
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track the activity on our Service and store certain information. We use the following categories of cookies:
- Strictly Necessary Cookies: Essential for the operation of our website. These cannot be disabled.
- Analytics/Performance Cookies: Help us understand how visitors interact with our website. We use these based on your consent.
- Marketing Cookies: Used to track visitors across websites to display relevant advertisements. We use these based on your explicit consent.
Data Sharing and Disclosure
We may share your personal information with the following categories of recipients:
- Service Providers: Third-party vendors who provide services on our behalf (e.g., hosting providers, payment processors, shipping companies) under strict data processing agreements
- Legal Authorities: When required by law, court order, or governmental regulation
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business
International Data Transfers
Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA), including China. When we transfer your data internationally, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, including: (1) EU Standard Contractual Clauses (SCCs) approved by the European Commission, (2) Adequacy decisions where applicable, and (3) Additional technical and organizational security measures to protect your data during transfer.
Data Security
The security of your data is important to us. We implement appropriate technical and organizational measures to protect your personal information, including encryption in transit (TLS/SSL), access controls, and regular security assessments. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our retention periods are:
- Account Data: Retained for the duration of your account plus 2 years after closure (for legal defense purposes)
- Transaction Data: Retained for 7 years after the transaction (to comply with tax and accounting laws)
- Marketing Data: Retained until you withdraw your consent or unsubscribe
Your Data Protection Rights
Under GDPR, you have the following data protection rights:
- Right to Access (Art. 15): You can request copies of your personal data
- Right to Rectification (Art. 16): You can request correction of inaccurate or incomplete data
- Right to Erasure/'Right to be Forgotten' (Art. 17): You can request deletion of your data under certain conditions
- Right to Restrict Processing (Art. 18): You can request limitation of processing under certain conditions
- Right to Data Portability (Art. 20): You can request transfer of your data to another controller
- Right to Object (Art. 21): You can object to processing based on legitimate interests or direct marketing
- Right to Lodge a Complaint (Art. 77): You have the right to complain to a supervisory authority in your EU member state of residence, workplace, or place of alleged infringement
To exercise any of these rights, please contact us using the details below. We will respond to your request within one month (extendable to three months for complex requests).
Automated Decision-Making and Profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. All decisions affecting you involve human intervention.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the 'Last updated' date at the top. For significant changes, we will provide additional notice (e.g., email notification or prominent banner).
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to lodge a complaint, please contact us:
- By email: info@hanlinbags.com
- By visiting this page on our website: https://www.hanlinbags.com
- By phone number: +1(626)620-8370

