Privacy
Privacy Policy
This notice explains how the website and mobile apps handle data when you use location, support, AI, and personalisation features.
Data we handle
Current location
When you choose “Use current location”, your device asks for permission first. Coordinates are used for nearby services, restaurants, or arrival searches and are sent to the relevant first-party search endpoint. The feature does not write coordinates to a personal location history, although hosting and network services may keep ordinary request logs.
Support form
The support form collects your name, email, subject, and message to handle enquiries, data issues, or deletion requests. It is stored in Supabase and restricted to authorised service-role access. Do not submit identity numbers, payment details, or unnecessary sensitive data.
Search and AI input
When you use the assistant or natural-language commands, the system may briefly store the input, endpoint, IP address, browser information, referring page, and basic request metadata for safety, debugging, and service improvement. Where a generated answer is needed, the question and necessary context may be processed by the configured OpenAI, Anthropic, or Groq provider.
Local preferences and account state
Recent searches, arrival selections, favourites, comparison lists, baskets, alerts, rewards comparisons, the latest rewards-catalog cache, and interface state may be stored in localStorage or a functional cookie on your device. Anonymous data stays on that device. If you sign in and enable sync, household-list state may be stored in Supabase, where database rules limit access to that account's own record.
Service providers and public data sources
Processing for the platform
- Vercel: hosting, ordinary request logs, Web Analytics, and Speed Insights.
- Supabase: database, authentication, and authorised synced state.
- OpenAI, Anthropic, or Groq: processes a question only when that AI provider is configured and a generated answer is needed.
- OpenStreetMap: map tiles load directly from its servers, which may receive your IP address and the requested map area.
Public data sources
The platform primarily fetches livelihood data server-side from government departments, public bodies, and reviewed public sources. Ordinary browsing does not send your support message or local lists to those data suppliers. If you open an official link, that website's privacy terms apply directly.
View data sources and methodsPartner offers and affiliate links
Partner or affiliate offers are clearly labelled as sponsored or partner links and state that we may receive a commission. Compensation does not change comparison calculations, search ranking, or recommendation order, and it does not change the on-device miles formula. An offer is not shown without a current agreement, official source, validity period, permitted product and platform, valid signature, and approved destination host. The secure partner feed and every commercial CTA are off by default and have separate operational kill switches; the older general commercial-offer feed remains disabled. The mobile app shows a CTA only where an individual agreement expressly covers iOS or Android, and there is no advertising identifier, attribution SDK, or user-level campaign parameter.
Applications for cards, accounts, investments, loans, or insurance, and any extra-reward claim, open the approved company's HTTPS domain directly in the system browser after the destination name is shown. Hong Kong Life Helper does not embed bank application forms and does not collect or store an applicant's name, contact details, application number, documents, banking information, or payment data. The company handles its own privacy terms, eligibility decision, application, and reward claim.
A Trip.com search box is created only after you explicitly choose “Load Trip.com search”. The hotel, flight, and train search boxes generated after that action are supplied directly by Trip.com. Trip.com receives ordinary request information, the static affiliate identifiers, and the destination, dates, itinerary, and passenger details you enter in the box, and may use cookies or local storage under its own privacy terms. Closing the search box only removes the third-party content from the screen; it does not mean Trip.com's cookies or local storage have been cleared. Affiliate links for attractions, car rental, and transfers open Trip.com directly. Trip.com handles search, prices, availability, booking, payment, refunds, and support; this service's servers and app code do not log those searches, clicks, or bookings or collect traveller or payment details.
Retention, deletion, and your choices
- Support and AI input
- The platform's cleanup configuration uses a seven-day retention limit, with expired records removed by a protected daily retention-cleanup process.
- Preferences on your device
- Kept until you remove items in the app, clear site/app data, or uninstall the app.
- Account sync and provider records
- The current code does not set one automatic expiry date for account lists or provider infrastructure records; retention also depends on service settings and legal requirements.
Access, correction, or deletion
You can decline location and withdraw permission in device settings at any time. You can also clear local data. To ask about, correct, or delete support records, AI input, or synced account state, use the support form with the email used, approximate date, and relevant feature so the correct record can be found. Do not add extra sensitive data to the message.
Contact support / request deletionPolicy updates
This policy was last updated on 2026-08-17. If data handling changes materially, we will update this page and date. “Hong Kong Life Helper” identifies this service; the current contact channel is the support form.