Last updated:
Privacy Policy
Last updated: 2026-09-03
This Privacy Policy explains how CrossBorderHK (the GBA Transfer brand, referred to as “we”, “us” or “our”) handles personal data that you submit through crossborderhk.com, online enquiry and payment pages, WhatsApp, WeChat, telephone, Line or email. We use the principles of Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) as a baseline for this policy. If mandatory law in your location gives you stronger protection, that law prevails.
1. Who we are
This website uses the CrossBorderHK / GBA Transfer brand to provide cross-border private-car transfers and related coordination in Hong Kong, Shenzhen, Macau and the Greater Bay Area. “We”, “us” and “our” in this policy mean the operator that controls the relevant data for the service. The service provider or trading name for a particular trip is the one shown in that trip’s formal quote, booking confirmation or receipt. Before paying or confirming a trip, use our Support page to check the service scope and arrangements for that trip.
Our Privacy Officer handles privacy requests through support@crossborderhk.com. This is the contact channel for privacy correspondence, access and correction requests.
2. Personal data we may collect
We collect data only to the extent reasonably needed for an enquiry, booking, payment or support request. This may include:
- contact details such as your name, WhatsApp, WeChat, telephone number, email address and preferred language;
- trip details such as origin, destination, route, date, time, passenger count, luggage and child-seat requirements;
- quote and payment details such as a quote ID, payment type, currency, amount, booking ID, payment status and payment-provider reference;
- messages you voluntarily send to support, including change, cancellation, complaint and review content;
- technical details such as IP address, browser, device type, page path, language preference and technical logs used for security, analytics or advertising measurement; and
- reviews or other content that you submit. A review may be published with the name and text you provide after approval; please do not include passport numbers, full payment-card details, full telephone numbers or other unnecessary sensitive data.
The payment page is not intended to collect your full card number or card security code directly into our systems. Card payments are processed by Stripe and PayPal payments are processed by PayPal; those providers handle payment data under their own privacy documentation.
Do not send passport or identity-document scans, payment passwords or security codes, or medical diagnoses through the website or ordinary messaging channels. If a particular trip lawfully requires additional document information, we will explain the purpose, recipient and submission method separately before asking for it.
3. How we use personal data
We may use personal data to:
- respond to enquiries, prepare quotes, and confirm routes, vehicle permissions, insurance scope and checkpoint plans;
- create and reconcile booking, payment, payment-adjustment, change and after-sales records;
- coordinate with drivers, dispatch staff or the actual service provider about the trip and passenger requests;
- prevent fraud, duplicate payments, abuse, unauthorised access and other security risks;
- handle complaints, reviews, disputes, accounting records, legal requests and regulatory requirements;
- understand website use and improve pages, quoting and support; and
- where permitted by law and where the required choice has been given, measure advertising or marketing performance.
We do not sell customer personal data. We do not use it indiscriminately for purposes unrelated to the enquiry or service. If a new use requires notice or consent under applicable law, we will provide that notice or obtain the required consent.
4. Sharing and cross-border processing
To provide the service, we may share data as needed with:
- people and service providers responsible for dispatch, drivers, checkpoint arrangements or customer support;
- Stripe, PayPal and any other payment, fraud-prevention or reconciliation provider actually enabled;
- Cloudflare for website hosting, database, storage, security and operational logs;
- Resend for transactional booking notifications sent to our booking operations mailbox;
- Google Tag Manager, Google Ads, Google Analytics, Microsoft Clarity or Plausible only when the relevant tool is enabled and you have allowed optional tracking;
- WhatsApp, WeChat, Line or email providers when you choose to contact us through that channel;
- a travel companion, company contact or other representative whom you ask us to contact;
- courts, law-enforcement, customs/immigration authorities or other authorised bodies; and
- professional advisers handling disputes, accounting, insurance or legal matters.
Cross-border travel may require data to move between Hong Kong, Mainland China, Macau and other locations where service providers operate. We limit the data shared to what is needed and use reasonable contractual, access, transmission and security controls. This policy is not a substitute for a separate notice or consent where applicable law requires one. Payment providers may process data in their own locations; please also review the Stripe Privacy Center and PayPal Privacy Statement.
5. Retention
Unless a longer period is needed for an unresolved dispute, legal claim or legal obligation, our target retention periods for data under our control are:
- unpaid or failed payment records and security/activity logs: 90 days;
- completed-trip, contact and customer-service records: 24 months after the last completed trip. We then delete or redact contact details, trip details and customer-service notes from our operational records;
- pending or rejected reviews: 90 days; approved public reviews: 24 months, or earlier if the author asks us to remove them; and
- payment, invoice and accounting records: 7 years from the relevant transaction.
When retention is no longer necessary, we delete, anonymise or securely dispose of the data. A payment provider, messaging platform or email provider may retain data under its own policy; its retention is not controlled by this website.
6. Security
We use reasonable access controls, transmission protections, permission management, logging and supplier controls having regard to the nature of the data and the risks involved. Access should be limited to people or providers who need it for their work. No internet transmission or electronic storage is completely secure. If a security incident may affect personal data, we will investigate and take remedial or notification steps required by applicable law.
7. Cookies, analytics and advertising technology
The website uses necessary browser storage, cookies or similar technologies to support page functions, retain your privacy choice, recognise payment-flow state and prevent abuse. Google Tag Manager, Google Ads and optional tools such as Google Analytics, Microsoft Clarity or Plausible are not loaded until you choose “Allow analytics and advertising” in the privacy prompt.
You can change the choice later using “Privacy preferences” in the website footer, or restrict or delete cookies in your browser. Withdrawing permission prevents optional tags from loading on later pages; you may also need to remove any existing third-party cookies using your browser or that provider’s controls. Blocking necessary technologies may affect website or payment functionality. Optional analytics tags are not intended to read the full card details you enter on a payment provider’s page.
8. Access, correction and privacy requests
You may email our Privacy Officer at support@crossborderhk.com to ask to access or correct personal data we hold about you, or to ask about our main purposes and general practices. Include your name, the contact channel used, booking or payment reference (if any), and the request. To protect customer data, we may ask for enough information to verify your identity and the scope of the request. Requests may be subject to lawful fees, time limits or exceptions; requests made under Hong Kong’s Personal Data (Privacy) Ordinance will be handled within the applicable statutory timeframe.
If you do not want us to use a particular contact channel for non-essential marketing messages, tell us by email and we will process the request within a reasonable period. Communications needed for a service, payment, order security or legal record are not optional marketing messages.
9. Children
The website is not directed to children. A parent or lawful guardian should provide only the information needed for a minor’s trip and confirm safety-seat and cross-border arrangements. If you believe we received a child’s data without appropriate authority, please contact us promptly.
10. Changes
We may update this policy when our service, technology or legal obligations change. The new version will be posted on this page with a revised “Last updated” date. We will give additional notice where applicable law requires it.
11. Related pages and contact
- Terms of Service
- Disclaimer
- Support
- Privacy Officer: support@crossborderhk.com
This page is a website privacy notice, not legal advice for a particular situation. For formal cooperation or large, sensitive or ongoing data processing, obtain advice from a qualified professional.