Privacy Policy
Last updated: April 2026
Cookie Cream is committed to protecting your privacy. This policy explains how we collect, use, share, and protect your personal data. It is designed with reference to Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and the EU General Data Protection Regulation (GDPR).
1. Information we collect
- Account information: when you register, we collect your name, email address, and login credentials.
- Service information: tasks, categories, habits, settings, and other content you create while using the app.
- Usage information: device information, IP address, browser type, system activity logs, and service interaction data used for diagnostics and performance improvement.
- Cookies and tracking technologies: we use cookies to maintain login state, remember preferences, and support basic site analytics.
2. How we use information
We process your data based on the following legitimate interests:
- Providing, operating, and maintaining the core Cookie Cream service.
- Processing billing, where applicable, and customer support requests.
- Sending service-related notices, such as system updates and security alerts.
- Analyzing and improving user experience while protecting system security.
3. Sharing and processors
We do not sell your personal data. We only share data with trusted third parties in limited situations:
- Service providers: partners who provide cloud infrastructure, databases, authentication, and payment processing. They are bound by strict confidentiality obligations.
- Legal requirements: when required to comply with Hong Kong court orders or applicable law.
4. Your rights (PDPO & GDPR)
Wherever you are located, we give you control over your personal data. You may:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete information.
- Erasure / right to be forgotten: request permanent deletion of your account and related personal data.
- Restriction and objection: restrict processing or object to processing based on legitimate interests in certain situations.
- Data portability: export your tasks and account data in a structured, machine-readable format.
5. Retention and security
We use industry-standard safeguards, including SSL/TLS in transit and database protection, to protect your data. Your data is retained only while your account remains active or as required by law. When you delete your account, we remove your personal data from active systems and backups within 30 days.
6. Contact us
If you have questions about this Privacy Policy or want to exercise your rights, including withdrawing consent or filing a complaint, contact our Data Protection Officer:
- Email: privacy@cookie-cream.com
- Address: Hong Kong SAR (registered address placeholder)