Last updated:
Privacy Policy
Last updated: 2026-08-26
This Privacy Policy explains how CrossBorderHK (the GBA Transfer brand, referred to as “we”, “us” or “our”) handles personal data that you submit through crossborderhk.com, online enquiry and payment pages, WhatsApp, WeChat, telephone, Line or email. We use the principles of Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) as a baseline for this policy. If mandatory law in your location gives you stronger protection, that law prevails.
1. Who we are
This website uses the CrossBorderHK / GBA Transfer brand to provide cross-border private-car transfers and related coordination in Hong Kong, Shenzhen, Macau and the Greater Bay Area. Before paying or confirming a trip, use our Support page to check the service scope and arrangements for that trip.
For privacy questions, email support@crossborderhk.com.
2. Personal data we may collect
We collect data only to the extent reasonably needed for an enquiry, booking, payment or support request. This may include:
- contact details such as your name, WhatsApp, WeChat, telephone number, email address and preferred language;
- trip details such as origin, destination, route, date, time, passenger count, luggage and child-seat requirements;
- quote and payment details such as a quote ID, payment type, currency, amount, booking ID, payment status and payment-provider reference;
- messages you voluntarily send to support, including change, cancellation, complaint and review content;
- technical details such as IP address, browser, device type, page path, language preference and technical logs used for security, analytics or advertising measurement; and
- reviews or other content that you choose to publish publicly. Please do not put passport numbers, full payment-card details or other unnecessary sensitive data in a review.
The payment page is not intended to collect your full card number or card security code directly into our systems. Card payments are processed by Stripe and PayPal payments are processed by PayPal; those providers handle payment data under their own privacy documentation.
3. How we use personal data
We may use personal data to:
- respond to enquiries, prepare quotes, and confirm routes, vehicle permissions, insurance scope and checkpoint plans;
- create and reconcile booking, payment, payment-adjustment, change and after-sales records;
- coordinate with drivers, dispatch staff or the actual service provider about the trip and passenger requests;
- prevent fraud, duplicate payments, abuse, unauthorised access and other security risks;
- handle complaints, reviews, disputes, accounting records, legal requests and regulatory requirements;
- understand website use and improve pages, quoting and support; and
- where permitted by law and where the required choice has been given, measure advertising or marketing performance.
We do not sell customer personal data. We do not use it indiscriminately for purposes unrelated to the enquiry or service. If a new use requires notice or consent under applicable law, we will provide that notice or obtain the required consent.
4. Sharing and cross-border processing
To provide the service, we may share data as needed with:
- people and service providers responsible for dispatch, drivers, checkpoint arrangements or customer support;
- Stripe, PayPal and any other payment, fraud-prevention or reconciliation provider actually enabled;
- hosting, database, logging, security, analytics, advertising-measurement and communications providers;
- a travel companion, company contact or other representative whom you ask us to contact;
- courts, law-enforcement, customs/immigration authorities or other authorised bodies; and
- professional advisers handling disputes, accounting, insurance or legal matters.
Cross-border travel may require data to move between Hong Kong, Mainland China, Macau and other locations where service providers operate. We limit the data shared to what is needed and use reasonable contractual, access, transmission and security controls. Payment and analytics providers may process data in their own locations; please also review the Stripe Privacy Center and PayPal Privacy Statement.
5. Retention
We retain relevant data for as long as needed to complete enquiries, bookings, payment adjustments, complaints and disputes, and for any period required for legal, tax, accounting, insurance or audit purposes. When retention is no longer necessary, we will delete, anonymise or securely dispose of the data.
The exact period can vary depending on whether an order is completed, a dispute exists, a payment provider requires a record, or a legal obligation applies. Third-party providers retain data under their own policies.
6. Security
We use reasonable access controls, transmission protections, permission management, logging and supplier controls having regard to the nature of the data and the risks involved. Access should be limited to people or providers who need it for their work. No internet transmission or electronic storage is completely secure. If a security incident may affect personal data, we will investigate and take remedial or notification steps required by applicable law.
7. Cookies, analytics and advertising technology
The website may use necessary browser storage, cookies or similar technologies to support page functions, recognise payment-flow state, prevent abuse, measure visits and measure advertising. Depending on deployment configuration, it may load Google Tag Manager, Google Ads and optional tools such as Google Analytics, Microsoft Clarity or Plausible.
You can restrict or delete cookies in your browser and use privacy controls offered by third-party providers. Blocking some technologies may affect website or payment functionality. Analytics tags are not intended to read the full card details you enter on a payment provider’s page.
8. Access, correction and privacy requests
Where applicable law allows, you may email support@crossborderhk.com to ask to access or correct personal data we hold about you, or to ask about our main purposes and general practices. To protect customer data, we may ask for enough information to verify your identity and the scope of the request. Requests may be subject to lawful fees, time limits or exceptions.
If you do not want us to use a particular contact channel for non-essential marketing messages, tell us by email and we will process the request within a reasonable period. Communications needed for a service, payment, order security or legal record are not optional marketing messages.
9. Children
The website is not directed to children. A parent or lawful guardian should provide information about a minor’s trip and confirm documents, safety-seat and cross-border arrangements. If you believe we received a child’s data without appropriate authority, please contact us promptly.
10. Changes
We may update this policy when our service, technology or legal obligations change. The new version will be posted on this page with a revised “Last updated” date. We will give additional notice where applicable law requires it.
11. Related pages and contact
This page is a website privacy notice, not legal advice for a particular situation. For formal cooperation or large, sensitive or ongoing data processing, obtain advice from a qualified professional.