WINWAY INTERNATIONAL GROUP LIMITED
Effective date of this revision: 09 September 2026
This privacy policy describes how personal information is collected, used, stored, shared and protected in the course of the catalogue and marketplace services run by Winway International Group Limited, a company with its registered suite at Rm 1406A 14/F THE BELGIAN BANK BLDG, 721-725 NATHAN RD, Mong Kok, Hong Kong (HK). The policy was prepared and is administered by the developer Winway Group.
You do not have to read this document to use this website, but you should read it before you hand over any personal details. If anything here reads like fine print written to confuse you, then treat it as a warning sign and reach out to us at help@listontech.lat or +17345633216 for a plain translation before you continue.
We will only combine short practical language with the legal clarity that careful record keeping demands. The headings give you the summary; the paragraphs give you the detail. When a rule differs by region, the region with the stricter limit wins for the person whose rights are affected.
This policy applies to every person who touches the digital vitrine, whether the person is a visitor reading the catalogue, a merchant preparing a listing, a studio selling finished goods, a buyer enquiring through the contact form, a supplier sending documents for verification, or an employee of a partner channel who shares operating files with our team. When we say you, we mean the individual whose personal information is being handled.
The policy does not replace your local privacy law; it sits comfortably beneath the stricter of any applicable law and our promises. Where the law requires a separate consent screen, a deletion tool, or a regional representative, we follow that law in addition to this document. Nothing in this page diminishes a right that any privacy regulation has already granted to you.
This site is operated for Winway International Group Limited from the address Rm 1406A 14/F THE BELGIAN BANK BLDG, 721-725 NATHAN RD, Mong Kok, Hong Kong (HK). If you use the site, the company acts as the controller for most day to day processing described here, while the developer Winway Group maintains the underlying software and holds isolated technical access where the contract demands.
The named company behind this catalogue and marketplace suite is Winway International Group Limited, a commercial entity organised under the laws in force where it is registered. Our registered office is Rm 1406A 14/F THE BELGIAN BANK BLDG, 721-725 NATHAN RD, Mong Kok, Hong Kong (HK).
Some of the software decisions, incident handling steps and server configurations are implemented by the developer Winway Group. The developer does not own your data and does not decide whether your record is permitted into a listing catalogue; those judgement calls belong to the operating company. Nevertheless, the developer receives instructions as a processor and is bound by contract to treat any personal information it touches as confidential.
Our business sits in the Computer Systems Design and Related Services and Professional, Scientific, and Technical Services industry groups. That classification matters because it shapes the kind of files we are allowed to keep: technical metadata about listings, merchant standing records and configuration logs rather than casual data harvested from unrelated hobbies or friends.
Personal information is any detail that can identify you, whether used alone or combined with anything else in our control. A business name alone is rarely enough, but a business name tied to a contact email, an address, a payment settlement record or a phone number can identify the real person running that business, and that combination is treated with care here.
Examples in our files include your name, your email address, your telephone number, your billing and delivery addresses, the tax or registration number of your company, the results of an identity check, your internet address at the moment you write to us and the equipment profile you browse with.
We treat aggregated statistics that no longer single you out as outside the scope of this policy. That is why we will always try to export and analyse grouped trends rather than inspect individual records whenever a report can answer the same question.
Direct collection happens when you choose to hand information over. If you fill in the name, email, subject and message fields of the contact form, we receive exactly the text you typed and nothing from your keyboard that you did not intend to send.
If you apply to join the catalogue, we may later ask for your full legal name, your merchant trading name, your company registration certificate, a copy of a passport style identity document, a bank account identifier for settlement and the signatures needed by law. Those items are requested only once you reach the merchant application stage, never while you are simply browsing.
When you telephone +17345633216, we may keep a short summary of the subject and the action promised, and we may place a note in your account so a different team member can continue the conversation without asking you to repeat yourself. Voice files are recorded only where your jurisdiction clearly permits call recording and the call begins with a clear spoken notice.
As you move through the pages of this or any connected dashboard, standard technical systems log the page you requested, the moment of the request, the general region implied by your internet address, your browser family, your screen resolution and the referring site when one is supplied. This log keeps the vitrine stable and helps us notice when an automated scraper is hammering the window or when a broken pane is slowing honest visitors down.
Automatic collection never listens to your microphone, watches your camera, reads your clipboard or follows you onto unrelated websites for marketing rooms. We do not purchase off the shelf interest graphs that pretend to know your salary, your health or your politics, because none of that is needed to run a clean catalogue.
Where we rely on a third party analytics panel to count visits, we configure that panel to block tracking that would let a rival or an advertiser reconstruct your full browsing map. The raw click stream stays inside our remit and leaves the system only in grouped form.
Marketplaces and payment partners sometimes return records to us. When a synced item sells on a partner channel, that channel may report the transaction, the amount, the shipping window and the buyer fulfilment address needed to complete delivery. We receive those records because we operate the syndication rails, never for unrelated research.
Verification bureaus and public registers may return a standing checker result when we run an identity or sanction lookup that you have approved. Those results are piped straight into the relevant verification file and are not merged into unrelated marketing lists.
Before we accept any record from a partner, we confirm that the partner had a proper basis to send it. A source that refuses to explain its own lawful grounds is not a source we keep feeding.
We process only where a recognised legal basis exists. The main grounds are consent that you may withdraw at any time, the performance of a contract you have entered, the need to comply with a legal obligation such as record keeping for taxes, and the legitimate interest of keeping a marketplace safe and running efficiently.
When we rely on consent, it must be an active, informed and freely given decision, presented with a clear description of what will happen. A pre-ticked box that nobody read is not the standard we use.
When we rely on legitimate interest, we weigh our need against your rights and freedoms first. Selling contact lists to brokers without asking is a practice we do not follow because the balance would always tip away from you.
The record you leave us exists to answer the question you asked, to run the listing you started and to protect the marketplace you trade in. Practically, that means we use data to respond to enquiries, to qualify and verify merchant applicants, to publish agreed listings, to settle payments and fees, to defend against fraud and spam, to measure service quality and to meet the tax and audit duties of Winway International Group Limited.
We also use a small part of the technical data to tune the security of the site. A request pattern that looks like an attack gets treated as an attack rather than as a valued visitor, and we may keep a snapshot of that hostile request for a reasonable defence period.
We do not sell, rent, trade or barter your personal information for cash or for any non monetary advantage. A merchant record that earns us a fee is used to facilitate that agreed service; it is not additionally auctioned to an advertiser.
Curated marketplaces exist precisely because not everyone is allowed through the door. Our Trust and Verification Services exist so that bad actors are caught early. The personal information needed to run those checks, such as identity documents and bank identifiers, is processed under the merchant contract and under applicable anti fraud and due diligence duties.
A buyer benefits from knowing we attempted a real check, and a legitimate seller benefits from the barrier that keeps fraudulent stock from undercutting honest wares. Where the identity check yields a suspicion of serious crime, employees must not quietly bury the result; company policy routes it to the compliance owner for the steps that law requires.
You may withdraw consent to any voluntary marketing associated with verification outreach, but you cannot withdraw the verification itself once you have asked to sell on the marketplace, because a curator cannot safely sell beside sellers it refused to meet.
Cookies are small text files a site places on your device so the site can remember a preference or a session. This vitrine uses strictly necessary cookies to keep your session straight, so that when you log into a merchant dashboard the site knows it is talking to the same browser that signed in.
Preferences and strictly functional markers may be stored so that you are not asked to accept the same choice on every single page. Any marker we use for measurement is limited to the purpose described in the section on analytics and cannot be recombined into a personal dossier by a random advertiser.
You can clear cookies through your browser at any time. Clearing them may sign you out of secure areas and may cause the site to forget a saved display choice, but it will not stop anonymised core statistics because the site can count visits without remembering who you are.
We share personal information only where a lawful reason exists and we keep the disclosure to the minimum needed. Categories of recipients include payment processors, identity and sanction checking bureaus, cloud infrastructure providers, delivery partners when a sale needs shipping and auditors the company appoints by contract.
Public bodies receive information when the law compels it: a properly served court order, a tax authority summons or a regulator asking under its legal powers. A vague request from somebody claiming they would like information is never enough.
If Winway International Group Limited is acquired or merged, personal information may move with the business as an asset. Before that move happens, the new operator must accept the same duties described here and must sign the same promises about deletion and access.
We do not attempt to run every data centre and mail server by hand. Sub-processors carry out clearly scoped tasks under our written instruction and may not use your data for their own advertising or resell it onward.
A current and readable list of sub-processors is reachable by asking our contact team, because the processing arrangements change as infrastructure moves. Each sub-processor is bound by a contract that matches or exceeds the duty of care in this policy, including a duty to notify us without undue delay if a breach touches your data.
Sub-processors whose only role is transport rarely see the content of your messages; those that do hold practical security controls equivalent to the ones described in our own security section.
Data often crosses borders because the cloud, the settlement networks and the offices of Winway International Group Limited are not all in one country. When data moves from where you live to another place, we check that the destination offers a protection that is still adequate for the sensitivity of the record.
Adequacy can come from a whole region being approved, from standard contractual clauses signed between the parties, or from an alternative safeguards tool recognised by law. We record which mechanism protects each significant data flow so that a regulator can satisfy itself that no data travels into the void.
Residents of a region that grants an express consent requirement for transfers will be shown that requirement before any transfer that law conditions on consent.
Working files and databases are stored with infrastructure providers who meet recognised information security standards, and who return an audit or certification on request. The files are segregated so a catalogue incident does not automatically compromise the merchant verification vault.
Backups exist so that a hardware accident cannot erase your merchant standing overnight. Those backups are retained no longer than the window needed to run a trustworthy restore, and access to the restore stream is itself restricted and logged.
Hard copy documents, where any ever exist, are stored under lock with an access log. Paper that outlives its purpose is shredded rather than thrown into a recycling skip where identity documents could be read by anyone.
We erase or anonymise personal information as soon as the purpose that needed it is finished, subject to the retention windows that law requires. A basic contact enquiry is generally cleared within two years of the last message, while merchant records are kept for the accounting and anti fraud windows applicable to the industry and your region.
Verification files are separate from marketing notes. A standing check result is kept only as long as the listing programme needs it to remain trustworthy, after which it is removed rather than archived for nostalgia.
Our deletion policy runs on schedule tasks that purge expired records automatically, and individual deletion requests shorten those windows immediately where no legal duty to keep the record remains.
Access to personal information is limited to the small group of people whose role genuinely requires it. Every privileged account uses a strong and separate secret, and two factor authentication is required for access to the verification vault and the settlement console.
Transport between your browser and our servers is encrypted, stored secret material is encrypted at rest, and network paths are monitored for anomalies. We patch systems on a schedule and run periodic checks for the common vulnerabilities that let intruders walk in through a forgotten panel.
No security exists that cannot be beaten by a determined adversary with enough resources. We still take the reasonable steps a careful company in this industry is expected to take, and we review those steps whenever the threat picture moves.
Depending on where you live, you may hold rights including the right to access a copy of the record we keep about you, the right to correct an error in it, the right to ask for its deletion, the right to limit or object to certain processing and the right to receive the data you supplied in a portable format so you can move it to another service.
These rights are not unlimited. Where a genuine legal duty requires us to keep a record, we will explain that duty rather than pretend the right does not exist. Where the data belongs to a dispute that is still live, we may keep it until the dispute closes.
Exercising a right is free and must not be punished. Nobody at Winway International Group Limited is authorised to treat an access request as grounds to close your account or raise your fees.
Send any data request to help@listontech.lat and state the right you want to use and the email the account is registered under. We reply within the timeline your law allows, which in many regions is thirty calendar days, and we may take reasonable steps to confirm your identity before handing over a copy of sensitive files.
When your identity cannot be confirmed, we will explain what is missing rather than guess. When your request is complex, we may extend the response period once and will tell you before the original deadline passes.
Phone requests are noted but a formal email ensures your request has a written trail that regulators can review. The number +17345633216 is answered during office hours and mail is read every working day.
The catalogue and merchant suites are designed for businesses and for adults aged eighteen or over. Children under the age at which they may lawfully consent to the services do not have a use for merchant verification or settlement functionality.
We do not knowingly collect the information of children through the vitrine, and we do not market toys, apps or games at minors through this page.
If a parent or guardian believes their child has provided information to us by accident, they should contact help@listontech.lat and we will remove the record promptly and confirm the deletion in writing. Parents are always allowed to act on behalf of a young child for these deletion requests.
Operational messages, such as a confirmation that a merchant account was approved or a transaction settled, are not marketing and continue to arrive because they matter to the service you asked for.
Promotional newsletters are separate. They are sent only when you opted in, each contains working unsubscribe links, and opting out is honoured within a short technical window that never stretches beyond a few working days.
If a message arrives that you believe you never agreed to, report it to our contact team and we will trace how it was sent and fix the source rather than argue about whether you should have ignored it.
We use grouped analytics to understand how many people browse the vitrine, where they linger and which catalogue sections fail to hold attention. Those analytics run on aggregated numbers and are not used to build a pricing profile that charges one visitor more than another for the same service.
Profiling in the strict sense, the automated evaluation of personal aspects, appears only in risk scoring for merchant onboarding, and even there a human can review the decision and change it. Our scoring never awards a low risk label because of a protected characteristic.
If you are a merchant, the listing analytics you see on your dashboard summarise your own catalogue performance. That does not reveal the private browsing of any individual shopper.
The pages of this site link to law pages, partner marketplaces and industry references that are hosted elsewhere. Once you leave our pages, their privacy practices govern you, not ours.
We choose partners whose privacy posture we are willing to present, but we cannot inspect every downstream link they add later. A practical rule applies: if a linked page asks you for more secrets than the task seems to need, stop and ask us first.
Our own pages do not embed invisible trackers from a network of unrelated publishers, so nothing you do just by visiting us is broadcast to a trading desk.
Some onboarding steps are automated so a decision arrives quickly. A document order check, a duplicate listing check and a standing-report scan can run without a person typing each keystroke.
Where an automated decision would produce a legal or similarly significant effect for you, such as refusing a merchant account outright on the basis of a score alone, we provide a way to ask for human review before the decision becomes final.
The human reviewer sees the same score but also sees the evidence and the context a pure algorithm misses. That review pathway is not buried behind forms you must pay to unlock.
We revise this policy when the law changes, when the services change or when better practice becomes the reasonable standard. Material changes are announced on the homepage banner and, where the change is significant, by email to the accounts we hold.
Each page carries an effective date so you can tell at a glance whether you are reading a current revision. Historical versions remain available on request so a dispute about what you agreed to can be settled against the text that was actually live at the time.
Continuing to use the vitrine after a revision to the legal pages normally signals acceptance of the updated terms, and the separate terms document explains exactly when that rule applies.
Start with us. Write to help@listontech.lat with the words privacy complaint in the subject, or call +17345633216, and give us a fair chance to fix the issue in the window your law allows.
If you are not satisfied with our answer, you may escalate to the supervisory authority for the region where you live. We will not retaliate, delete your files as punishment or move your records to another jurisdiction in order to dodge the review.
For records that touch our merchant suite in Hong Kong, the responsible channels there and the competent authority for your home region can both receive a copy of the correspondence trail so that nobody has to rely on memory alone.
The named controller for the operation of this site is Winway International Group Limited, with a registered address at Rm 1406A 14/F THE BELGIAN BANK BLDG, 721-725 NATHAN RD, Mong Kok, Hong Kong (HK).
The contact email of record is help@listontech.lat and the contact telephone of record is +17345633216. The developer contact of record is Winway Group.
These details appear on every legal page so that a regulator, a partner or a visitor always has one stable address to reach, whichever revision of the pages they happen to be reading.