Privacy Policy

Privacy Policy

Last updated: June 12, 2026

This Privacy Policy explains how ELKLU (“we”, “our”, or “us”) collects, uses, stores, and protects your personal information when you visit our website at elklu.com or place an order with us.

1. Data Controller

The Data Controller responsible for your personal data under this Privacy Policy is:

ELKLU
Hong Kong SAR
Email: support@elklu.com
Phone: +852 6344 5991

For any questions about how we handle your data, or to exercise your data rights, contact us at support@elklu.com.

2. What Information We Collect

We collect the following types of information:

  • Information you provide: Name, billing/shipping address, email, phone number, payment method (we never see or store your card number — it is handled directly by PayPal / NOWPayments).
  • Order information: Items purchased, order history, customer service correspondence.
  • Information collected automatically: IP address, browser type, device type, pages visited, referring URL, timestamps. Collected via standard web analytics.
  • Cookies and similar technologies: Session cookies (cart, checkout), preference cookies (currency, language), analytics cookies (Google Analytics).

3. How We Use Your Information

  • Process and fulfill your orders
  • Send order confirmation, shipping, and delivery emails
  • Respond to customer service inquiries
  • Process refunds and returns
  • Detect and prevent fraud or abuse
  • Improve our website, products, and customer experience
  • Comply with legal obligations (tax records, regulatory requirements)

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4. Data Protection

We take the protection of your personal data seriously and implement industry-standard safeguards:

  • Encryption in transit: Our entire website runs on HTTPS with TLS encryption. All data transmitted between your browser and our servers is encrypted.
  • Encryption at rest: Sensitive data stored in our database is protected by access controls and encryption.
  • Payment security: We do not store credit card information on our servers. All payment data is handled directly by our PCI-DSS compliant payment partners (PayPal, NOWPayments).
  • Access controls: Only authorized personnel may access customer data, and only for legitimate business purposes (order fulfillment, customer support, fraud prevention).
  • Server security: Our servers are protected by firewalls, intrusion detection, and regular security updates.
  • Retention limits: We retain personal data only as long as needed to fulfill the purposes described in this policy or as required by law.
  • Incident response: In the event of a data breach affecting your personal data, we will notify affected users within 72 hours of becoming aware, as required by applicable law.

5. Data Retention

We retain your personal data only as long as necessary for the purposes set out in this Privacy Policy, or as required by law. Specific retention periods:

  • Order data (name, address, items, payment reference): 7 years from order date — required by tax and accounting law.
  • Customer service correspondence: 3 years from last contact — for warranty and dispute resolution.
  • Marketing data (email list): Until you unsubscribe, then deleted within 30 days.
  • Website analytics: 26 months (Google Analytics standard).
  • Cookies: Session cookies expire when you close the browser; preference cookies expire after 12 months.
  • Account data (if you create an account): Until you request deletion, then permanently removed within 30 days.

After the retention period ends, data is securely deleted or anonymized for statistical purposes. You may request earlier deletion at any time by emailing support@elklu.com — see Section 6 (Your Rights).

6. Third-Party Services

We share data with the following service providers, only as needed to deliver our services:

  • Payment processors: PayPal (cards via guest checkout), NOWPayments (cryptocurrency)
  • Shipping carriers: USPS, UPS, FedEx, DHL — for delivery
  • Email service: Our hosting provider for transactional emails
  • Analytics: Google Analytics (anonymized IP)
  • Google Merchant Center / Google Customer Reviews: If you opt in at checkout, your email and order details are shared with Google for the customer survey

Each of these processors is bound by their own privacy policy and data protection terms.

7. Your Rights

Subject to applicable law (including GDPR for EU residents and CCPA for California residents), you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correct: Request correction of inaccurate or incomplete data
  • Delete: Request deletion of your personal data (“right to be forgotten”)
  • Restrict processing: Request that we limit how we use your data
  • Data portability: Request your data in a portable, machine-readable format
  • Object: Object to certain types of processing, including direct marketing
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, email support@elklu.com. We will respond within 30 days.

8. Cookies

We use cookies to remember your shopping cart, your preferences, and to measure how visitors use our site. You can disable cookies in your browser settings, but parts of our website (cart, checkout) may not work correctly without them.

9. Children

Our website is not intended for users under 13 years old, and we do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us and we will delete it.

10. International Data Transfers

ELKLU is based in Hong Kong. Your data may be processed in Hong Kong and any country where our service providers operate. We ensure all transfers comply with applicable data-protection laws.

11. Updates to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect the most recent change. Significant changes will be communicated via email or a notice on our website.

12. Contact Us

Questions, requests, or complaints about this policy:

ELKLU — Data Protection
Email: support@elklu.com
Phone: +852 6344 5991
Hours: Monday – Friday, 10:00 AM – 6:00 PM (HKT, GMT+8)