Privacy Policy

Last Updated: August 20, 2025

PLEASE READ THIS PRIVACY POLICY CAREFULLY. BY ACCESSING OR USING THE TOHIFY PLATFORM IN ANY MANNER, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED IN THIS POLICY. IF YOU DO NOT AGREE WITH ANY PART OF THIS POLICY, YOU MUST DISCONTINUE USE OF THE PLATFORM IMMEDIATELY.

This Privacy Policy ("Policy") is issued by Tohpros Technologies Limited, a company incorporated under the laws of Hong Kong SAR, operating the marketplace platform at www.tohify.com (the "Platform"). This Policy describes how we collect, use, store, share, and protect personal information obtained from individuals who visit, register on, or transact through the Platform ("you", "your", or "User"). This Policy is incorporated into and forms part of our Terms & Conditions.

1. Identity of the Data Controller

The data controller responsible for the processing of your personal information under this Policy is:

Tohpros Technologies Limited
Unit B, 3/F., Kai Wan House, 146 Tung Choi Street, Mong Kok, Hong Kong, China
Website: www.tohify.com
Email: help@tohify.com

Where applicable law requires the appointment of a data protection representative or officer, such details will be made available upon request by contacting us at the email address above.

2. Scope and Application of This Policy

This Policy applies to all personal information collected by Tohify in connection with your use of the Platform, regardless of whether you are a visitor, registered user, buyer, or seller. It covers personal information collected through the Platform's website, mobile interfaces, APIs, and any associated communications channels including email and messaging systems.

This Policy does not apply to the data practices of third-party sellers operating on the Platform, third-party payment processors, or any external websites linked to from the Platform. We encourage you to review the privacy policies of any third parties with whom you interact.

3. Categories of Personal Information We Collect

3.1 Information You Provide Directly. We collect personal information that you voluntarily provide to us when you interact with the Platform, including:

  • Identity and Contact Information: Your full name, email address, username, profile photograph, country of residence, and any other information you choose to include in your public profile.
  • Account Credentials: Your login email address and password. Passwords are stored using industry-standard one-way cryptographic hashing and are never accessible to Tohify personnel.
  • Seller Information: Business name, professional qualifications, portfolio materials, service descriptions, pricing, and any additional information provided for the purposes of creating and managing listings.
  • Financial Information: When you make a purchase or receive payment, our third-party payment processors (Stripe, PayPal, Payoneer) collect and process your payment card or bank account details directly. Tohify does not store, process, or have access to your full payment credentials. We receive only transaction metadata such as transaction status, billing name, billing address, and the last four digits of a payment card, as required for order management and fraud prevention.
  • User-Generated Content: Reviews, ratings, comments, messages, files, images, and any other content you submit, upload, or transmit through the Platform.
  • Communications: The content of messages you send to Tohify's support team, dispute resolution requests, and any other direct correspondence with us.
  • Identity Verification Information: Where required for compliance or security purposes, we may request copies of government-issued identification documents. Such documents are handled with the highest level of confidentiality and are stored securely in accordance with applicable law.

3.2 Information Collected Automatically. When you access and use the Platform, we automatically collect certain technical and behavioural data, including:

  • Device and Network Data: IP address, device type and model, operating system and version, browser type and version, language settings, time zone, and mobile network information.
  • Usage and Interaction Data: Pages and listings viewed, search queries entered, links clicked, features used, time spent on pages, referring URLs, exit pages, and the dates and times of your visits.
  • Transaction Data: Details of purchases made, services ordered, listings posted, order history, and payment status information.
  • Cookies and Similar Tracking Technologies: We use cookies, web beacons, pixel tags, local storage objects, and similar technologies to collect data about your interactions with the Platform. A detailed description of the types of cookies we use and how to manage your preferences is provided in Section 7 of this Policy.

3.3 Information Received from Third Parties. We may receive information about you from third parties in the following circumstances:

  • Social Login Providers: If you choose to register or log in using a third-party account (such as Google), we will receive basic profile information from that provider, including your name and email address, in accordance with your privacy settings on that platform.
  • Payment Processors: We receive transaction confirmation and status information from our payment service providers following the completion of a purchase.
  • Fraud Prevention and Compliance Services: We may receive information from identity verification and fraud detection service providers to protect the security of the Platform and its users.

4. Legal Bases for Processing Personal Information

Where applicable data protection legislation requires us to identify a legal basis for each processing activity, we rely on the following:

  • Performance of a Contract: Processing necessary to provide our services to you, including account management, order fulfilment, payment processing, and dispute resolution.
  • Legitimate Interests: Processing necessary for our legitimate business interests, including platform security, fraud prevention, improvement of our services, and marketing of our platform, provided that such interests are not overridden by your fundamental rights and freedoms.
  • Legal Obligation: Processing necessary to comply with applicable laws and regulations, including tax, financial reporting, and anti-money laundering obligations.
  • Consent: Where we rely on your consent for specific processing activities, such as the placement of non-essential cookies or the sending of direct marketing communications, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

5. Purposes for Which We Use Your Personal Information

We use the personal information we collect for the following purposes:

  • Account Creation and Management: To register, authenticate, maintain, and administer your user account, and to verify your identity where required.
  • Service Delivery: To facilitate the listing, purchase, delivery, and fulfilment of services and digital products transacted through the Platform, and to communicate with you regarding the status of your orders.
  • Payment Processing: To initiate, process, verify, and record financial transactions, and to prevent and investigate fraud and unauthorized transactions.
  • Customer Support and Dispute Resolution: To respond to your inquiries, resolve disputes, investigate complaints, and provide technical assistance.
  • Platform Safety and Security: To detect, investigate, and prevent fraudulent, abusive, or unlawful activity, to enforce our Terms & Conditions, and to protect the rights, property, and safety of Tohify, our users, and third parties.
  • Platform Improvement and Analytics: To analyse how users interact with the Platform, to identify usage trends, to diagnose technical issues, and to improve the functionality, performance, and user experience of the Platform.
  • Personalisation: To tailor the content and listings displayed to you based on your browsing history, preferences, and transactional behaviour on the Platform.
  • Marketing and Promotional Communications: To send you newsletters, promotional offers, product updates, and information about new features or services, where you have consented to receive such communications or where we have a legitimate interest in doing so. You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us directly.
  • Legal and Regulatory Compliance: To comply with applicable laws, regulations, judicial orders, and lawful requests from public authorities, including for tax, accounting, and anti-money laundering purposes.

6. Disclosure and Sharing of Personal Information

We do not sell, rent, or trade your personal information to third parties for their own independent marketing or commercial purposes. We may, however, share your personal information in the following circumstances:

6.1 With Other Platform Users. Certain information in your public profile — including your username, profile photograph, listings, ratings, and reviews — is visible to all users of the Platform as an inherent feature of the marketplace. For the purposes of order fulfilment, Tohify may share relevant contact or shipping information between buyers and sellers as necessary to complete a transaction.

6.2 With Third-Party Service Providers. We engage trusted third-party companies and individuals to perform services on our behalf. These service providers have access to personal information only to the extent necessary to perform their functions and are contractually obligated to maintain its confidentiality and security. Categories of service providers include:

  • Payment Processing: Stripe, PayPal, Payoneer — for the secure processing of financial transactions.
  • Cloud Infrastructure and Hosting: Providers who store and manage Platform data on secure, enterprise-grade servers.
  • Email and Communication Services: Providers used for transactional emails, account notifications, and customer support communications.
  • Analytics Providers: Including Google Analytics, used to collect aggregated, anonymised data about Platform usage patterns.
  • Advertising and Retargeting Partners: Including Google Ads and Meta (Facebook) Pixel, used to serve relevant advertisements to users who have previously visited the Platform. You may opt out of interest-based advertising through your browser settings or via the opt-out tools provided by these platforms.
  • Fraud Prevention and Identity Verification Services: Used to detect and prevent fraudulent activity on the Platform.

6.3 For Legal and Regulatory Purposes. We may disclose your personal information to law enforcement agencies, regulatory bodies, courts, or other public authorities where we are legally required or permitted to do so, including where necessary to: (i) comply with a legal obligation or court order; (ii) protect and defend the rights or property of Tohify; (iii) prevent or investigate possible wrongdoing in connection with the Platform; or (iv) protect the personal safety of users or the public.

6.4 In Connection with Business Transactions. In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction involving Tohify, your personal information may be transferred as part of the transaction. We will notify you via email and/or a prominent notice on the Platform prior to your personal information being transferred and becoming subject to a different privacy policy.

6.5 With Your Consent. We may share your information with third parties for purposes not covered by this Policy where you have given us your explicit prior consent to do so.

7. Cookies and Tracking Technologies

7.1 What Are Cookies. Cookies are small text files stored on your device by your web browser when you visit a website. We also use related technologies such as web beacons, pixel tags, and local storage objects. Together, these technologies allow us to recognise your device, remember your preferences, and analyse how you use the Platform.

7.2 Categories of Cookies We Use:

  • Strictly Necessary Cookies: These cookies are essential for the Platform to function correctly and cannot be disabled. They include cookies that enable you to log in to your account, maintain your session, complete transactions, and access secure areas of the Platform.
  • Performance and Analytics Cookies: These cookies collect anonymous information about how visitors use the Platform, such as which pages are visited most frequently and whether users encounter error messages. This data helps us improve the Platform's performance. We use Google Analytics for this purpose.
  • Functionality Cookies: These cookies allow the Platform to remember choices you make (such as your language preference or currency) and provide enhanced, personalised features.
  • Targeting and Advertising Cookies: These cookies are used to deliver advertisements that are more relevant to you and your interests. They also limit the number of times you see an advertisement and help measure the effectiveness of advertising campaigns. They are placed by advertising networks such as Google and Meta with our permission.

7.3 Managing Your Cookie Preferences. You can control and manage cookies through your browser settings. Most browsers allow you to refuse, delete, or receive notifications about cookies. Please note that disabling certain cookies may affect the functionality of the Platform. For more information about managing cookies, visit www.allaboutcookies.org. To opt out of Google Analytics tracking, you may install the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

8. International Transfers of Personal Information

Tohify operates globally, and your personal information may be transferred to and processed in countries other than your country of residence, including Hong Kong, the United States, and other jurisdictions where our service providers maintain data processing facilities. These countries may have data protection laws that differ from, and may offer less protection than, the laws of your home jurisdiction.

Where personal information is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been recognised as providing an adequate level of data protection, we ensure that such transfers are subject to appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, binding corporate rules, or other legally recognised transfer mechanisms.

By using the Platform and providing us with your personal information, you acknowledge that your information may be transferred to and processed in jurisdictions outside your own.

9. Data Retention

  • We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations, and to resolve disputes or enforce our agreements.
  • Account Information: Retained for the duration of your account's active status, and for a period of up to three (3) years following account closure, to the extent required for legal and compliance purposes.
  • Transaction Records: Retained for a minimum of seven (7) years following the date of each transaction, in accordance with applicable tax and financial record-keeping requirements.
  • User-Generated Content: Retained for as long as the relevant listing, order, or account to which it relates remains active, subject to any legal holds or dispute resolution requirements.
  • Communications and Support Records: Retained for a period of up to three (3) years following the closure of a support interaction or dispute, to the extent necessary for quality assurance and legal compliance.
  • Marketing Data: Retained until you withdraw your consent or opt out of marketing communications, after which your data will be suppressed from marketing activities but may be retained in anonymised form for analytics purposes.
  • Upon expiry of the applicable retention period, personal information will be securely deleted or anonymised in accordance with our internal data destruction procedures. Where deletion is not immediately possible (for example, due to backup storage cycles), the information will be securely isolated and protected from further processing until deletion can be carried out.

10. Security of Personal Information

Tohify takes the security of your personal information seriously and implements a comprehensive set of technical and organisational measures designed to protect your data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include:

  • Encryption: All data transmitted between your browser and the Platform is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data at rest, including passwords and financial information, is stored using strong cryptographic methods.
  • Access Controls: Access to personal information is strictly limited to authorised Tohify personnel and service providers who require it for legitimate business purposes. All access is logged and audited.
  • Security Monitoring: We employ continuous monitoring systems to detect and respond to security incidents, unauthorized access attempts, and anomalous behaviour.
  • Third-Party Security Standards: Our payment processing partners are certified to PCI-DSS Level 1, the highest standard for payment card data security.
  • Staff Training: All Tohify personnel with access to personal information receive regular training on data protection obligations and security best practices.

Notwithstanding these measures, no method of electronic transmission or storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in accordance with our legal obligations.

11. Your Rights as a Data Subject

Depending on your country of residence and the applicable data protection legislation, you may have the following rights with respect to your personal information held by Tohify. We are committed to honouring these rights and will respond to all valid requests within the timeframe required by law (generally within thirty (30) days of receipt, subject to any necessary extensions).

  • Right of Access: You have the right to request confirmation of whether we hold personal information about you, and if so, to request a copy of that information together with details of how it is processed.
  • Right to Rectification: You have the right to request the correction of any inaccurate or incomplete personal information we hold about you.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request the deletion of your personal information where it is no longer necessary for the purposes for which it was collected, where you have withdrawn your consent, or where the processing is unlawful, subject to applicable legal retention obligations.
  • Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal information in certain circumstances, for example where you contest the accuracy of the data or where you have objected to processing based on legitimate interests.
  • Right to Data Portability: Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used, machine-readable format and to have it transmitted to another data controller where technically feasible.
  • Right to Object: You have the right to object at any time to the processing of your personal information for direct marketing purposes, or to processing based on our legitimate interests, on grounds relating to your particular situation. Where you object to direct marketing, we will cease processing your data for that purpose without requiring justification.
  • Rights in Relation to Automated Decision-Making: Where we make decisions about you solely through automated processing that produces legal or similarly significant effects, you have the right to request human review of that decision, to express your point of view, and to contest the outcome.
  • Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

To exercise any of the above rights, please submit a written request to help@tohify.com with the subject line "Data Subject Request" and include sufficient information to verify your identity. We reserve the right to request additional verification where necessary to prevent fraudulent requests. We will not charge a fee for processing reasonable requests, but we reserve the right to charge a reasonable administrative fee or refuse requests that are manifestly unfounded, excessive, or repetitive.

12. Children's Privacy

The Platform is intended solely for users who are eighteen (18) years of age or older. Tohify does not knowingly collect, solicit, or process personal information from individuals under the age of eighteen. If you are a parent or legal guardian and you have reason to believe that your child has provided personal information to Tohify without your consent, please contact us immediately at help@tohify.com. Upon verification, we will take prompt steps to delete such information from our records. If we become aware that we have inadvertently collected personal information from a minor, we will take immediate action to delete that information and, where applicable, terminate the associated account.

13. Third-Party Links and Services

The Platform may contain links to third-party websites, applications, or services that are not owned or controlled by Tohify. This Policy applies solely to information collected by Tohify through the Platform. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We strongly encourage you to review the privacy policy of every website or service you visit. The inclusion of a link to a third-party site on the Platform does not constitute an endorsement by Tohify.

14. "Do Not Track" Signals

Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is currently no universally accepted standard for how websites should respond to DNT signals, the Platform does not currently alter its data collection or use practices in response to DNT signals. We will continue to monitor developments in this area and will update this Policy if our practices change.

15. Changes to This Privacy Policy

Tohify reserves the right to update, modify, or replace this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or business operations. All changes will be effective upon posting to the Platform, and the "Last Updated" date at the top of this Policy will be revised accordingly.

Where changes are material — meaning they significantly affect your rights or how we process your personal information — we will provide you with prominent advance notice via email to the address associated with your account and/or via a conspicuous notice on the Platform, no less than fourteen (14) days prior to the changes taking effect. We encourage you to review this Policy periodically to remain informed about how we protect your information. Your continued use of the Platform following the effective date of any revised Policy constitutes your acceptance of the updated terms.

16. How to Lodge a Complaint

If you have concerns about how Tohify handles your personal information and are not satisfied with our response to your inquiry, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. For users in the European Economic Area, this would be the data protection authority in your EU member state. For users in the United Kingdom, this would be the Information Commissioner's Office (ICO). For users in Hong Kong, this would be the Office of the Privacy Commissioner for Personal Data (PCPD).

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and encourage you to contact us in the first instance at help@tohify.com.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the manner in which we process your personal information, please contact our privacy team at:

Tohpros Technologies Limited
Unit B, 3/F., Kai Wan House, 146 Tung Choi Street, Mong Kok, Hong Kong, China
Website: www.tohify.com
Email: help@tohify.com

We use cookies to improve your experience on Tohify. By continuing to browse, you agree to our use of cookies as described in our Privacy Policy.