
This Privacy Policy explains how BACKWIN (we, us, our) collects, uses, and protects personal data of users of our website. Our independent 3C‐product website operates in China and serves users in Europe, North America, and South America. We comply with relevant privacy laws including the EU GDPR, California’s CCPA, and Brazil’s LGPD. This policy covers all visitors and registered users, and is provided in English (other language versions may be available for convenience, but the English version governs).
1. Data Collection and Purpose
We collect the following personal data directly from you or automatically through your use of our site:
Identity and contact data: name, email address, account login credentials.
Technical data: IP address, device/browser information, and cookies that help identify your device and improve security.
Usage data: browsing and click behavior on our site (pages viewed, items clicked) via analytics and tracking tools.
Transaction data: payment details (e.g. credit card information, bank account) when you make a purchase, plus billing and shipping addresses.
We collect this data for legitimate business and legal purposes, including:
Account management: to create and maintain your user account, authenticate logins, and communicate with you.
Order processing: to process purchases (e.g. verifying your payment, arranging shipping) and to prevent fraud or other unlawful activity.
Service improvement: to analyze how our website is used and to improve our offerings and functionality. For example, we use Google Analytics cookies to collect site usage information without personally identifying individual visitors.
Marketing (with consent): to send you promotional messages or newsletters if you opt in. You can always opt out of marketing communications.
We only collect data that is relevant and necessary for these purposes. In particular, we do not collect sensitive data (such as health or biometric data) except where required by law or with explicit consent. Under data protection principles, we minimize data collection and will not keep your information longer than needed.
2. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to provide and improve services. These may include:
Functional cookies: necessary for site functionality (e.g. keeping you logged in, remembering items in your shopping cart).
Analytics cookies: to understand website usage and performance. For example, we use Google Analytics, which “uses a set of cookies to collect information on behalf of businesses… without personally identifying individual visitors”.
Advertising/tracking pixels: to provide personalized content or ads and measure their effectiveness. We use Facebook (Meta) Pixel and similar tools; Meta notes that it “uses cookies, pixels, and other tracking technologies to collect personal data for a range of uses, including analytics and ad targeting”. These tracking tools may collect information even if you do not have an account with that service.
You can control cookie settings in your web browser (e.g. to reject non-essential cookies) or use privacy tools. Note that disabling functional cookies may prevent certain features of the site from working properly.
3. User Account Information
When you register an account, we store your provided name, email address, and a chosen password. We use this information to authenticate your login and manage your account. You can update or delete this information through your account settings at any time. Your email may also be used (with your consent) to send order confirmations or marketing newsletters; you can unsubscribe or opt out of such emails at any time.
Your IP address and login history are recorded to protect your account (e.g. detect suspicious logins) and to fulfill security obligations. We do not use account information for any purposes other than those described (e.g. it will not be shared with unrelated third parties).
4. Data Storage and International Transfers
Your personal data are stored on secure servers located in China. We take measures to protect data in transit and at rest (e.g. SSL encryption, data encryption, access controls; see Data Security below). When personal data is transferred internationally (for example, from EU or Brazilian users to our servers in China), we ensure compliance with applicable laws:
EU GDPR: The European Commission has the power to recognize countries as providing adequate protection. As of January 2026, the EU has recognized Brazil as providing adequate protection of personal data. China is not currently an EU-adequate country, so transfers from the EU to China require appropriate safeguards. In practice, we rely on legally permitted mechanisms under Article 46 of the GDPR (such as EU Standard Contractual Clauses) and any other necessary measures to ensure your EU data remains protected.
Brazilian LGPD: The LGPD likewise restricts cross-border transfers unless the destination country provides adequate protection or proper safeguards. Since China is not designated as adequate under LGPD, we similarly apply suitable safeguards (such as contractual clauses) for transfers from Brazil to China.
Other jurisdictions: We comply with local laws regarding data transfers.
In all cases, we process and store data only as needed by our services and legal requirements. For example, EU guidelines emphasize that “data must be stored for the shortest time possible,” taking into account business needs and legal obligations (e.g. tax, labor, or warranty laws).
5. Third-Party Service Providers
We use certain third-party services to operate our website and provide our services. These include, for example:
Payment Processors: Third-party payment gateways (such as banks or payment platforms) that process your credit card or bank payments securely. We only share the necessary payment information with these processors under strict contractual terms.
Analytics and Hosting Services: Providers like Google Analytics and hosting/CDN services. These help us analyze traffic and deliver content quickly. As noted above, Google Analytics uses cookies to collect site usage data.
Advertising and Social Media: Services like Facebook Pixel or social login providers, which allow us to run targeted ad campaigns or let you sign in using social accounts. Meta’s privacy materials explain that its tools (e.g. Pixel) “collect personal data for analytics and ad targeting”.
Customer Support and Communication: Platforms for email newsletters or chat support, where we may share your email or order data to help answer your inquiries.
All such third parties are engaged under contractual agreements. These contracts require them to use your personal data only for the agreed service and to maintain data protection standards equal to ours. We do not sell or rent your personal data to any third parties. Except as described above (and except for transfers necessary to perform our services), we do not disclose your personal data outside our organization.
6. User Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
EU (GDPR) Rights: If you are an EU resident (or otherwise covered by GDPR), you have the right to be informed about processing; to access your personal data; to request correction of inaccurate data; to request deletion (“right to be forgotten”); to restrict or object to certain processing; to data portability (receive your data in a usable format); and to withdraw consent at any time. You are also protected from fully automated decisions without human review (Art. 15–21 GDPR).
California (CCPA/CPRA) Rights: California residents have the right to know what personal data we collect, use, share, or sell about them; the right to request deletion of their personal data (subject to certain exceptions); and the right to opt out of any sale or sharing of personal information. (We do not sell your personal data, but we still honor the right to opt-out of any sharing for cross-context advertising.) Consumers also have the right to receive information in a portable format and to non-discrimination for exercising their rights.
Brazil (LGPD) Rights: Brazilian residents have rights similar to the GDPR. Article 18 of the LGPD provides the right to confirmation of data processing; access; correction; anonymization/elimination of unnecessary data; portability; deletion of data processed with consent; information about third-party sharing; details on consent; and revocation of consent.
To exercise any of these rights, you may contact our Data Protection Officer or customer support (see Contact Information below). We will verify your identity and respond in accordance with applicable laws. We aim to respond to data requests promptly and within legal deadlines (e.g. within 30 days under GDPR, 45 days under CCPA, 15 days under LGPD). In some cases we may request additional information to verify your identity. Where data cannot be deleted (e.g. due to legal retention requirements), we will inform you of the reasons. You may also lodge a complaint with an appropriate data protection authority in your jurisdiction if you wish.
7. Data Retention
We retain personal data only as long as necessary for the purposes described above or to comply with legal requirements. For example:
Account and Order Data: We generally keep your account information and order records for as long as you maintain an active account, and thereafter for up to several years as needed for tax, warranty, or regulatory requirements.
Marketing and Analytics Data: If you consent to marketing, we retain contact and preference data until you unsubscribe. Analytics data (e.g. Google Analytics logs) is typically aggregated and stored for analysis for a defined period, then purged or anonymized.
Legal Obligations: Certain laws require us to keep records (e.g. financial transaction data) for a fixed period. In each case we review retention periods periodically.
The EU data protection guidelines state that data should be kept no longer than needed, and U.S. guidance similarly advises “keep it only as long as necessary” for business or legal purposes. When personal data is no longer required, we securely delete, destroy, or anonymize it.
8. Data Security Measures
We implement strong security measures to protect your personal information. These include:
Technical safeguards: We use HTTPS (SSL/TLS) encryption for data in transit, and encryption at rest for sensitive data. Servers are in secure data centers with firewalls and intrusion detection. Access to data is restricted by authentication and the principle of least privilege. We regularly update software and perform security audits.
Organizational safeguards: Only authorized personnel can access personal data, and all staff receive privacy and security training. We maintain internal policies and regularly review them. Our contracts with service providers require them to maintain comparable security standards.
Physical safeguards: If any data is handled on physical media (e.g. backups), it is stored in locked or restricted areas.
As one guideline notes, the most effective data security plans address multiple layers – physical security, electronic safeguards, employee training, and vendor security practices. We strive to meet industry best practices and continually improve our security posture. However, no system can be completely secure, so please also protect your account information (choose a strong password, keep it confidential, etc.).
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Significant changes will be noted on our website, and, if appropriate, we will notify registered users by email or other means. We recommend that you review this page periodically. Your continued use of the site after changes indicates your acceptance of the updated policy.
10. Contact Information
If you have any questions or wish to exercise your privacy rights, please contact us at:
Email: info@backwin.com
Address: Guangzhou Beikewei Technology Co., Ltd.
Address: Room 402, Building A, No. 54, Dagang West Street, Baiyun Lake Street, Baiyun District, Guangzhou
Data Protection Officer: If applicable, contact colln at [lliu3237@gmail.com] for privacy-related inquiries.
You can also withdraw consent to any communications at any time by contacting us or by using unsubscribe links. For residents of the EU, UK, California, Brazil, and other jurisdictions, you may also lodge a complaint with the relevant data protection authority.
Thank you for reviewing our Privacy Policy. We are committed to protecting your personal data and being transparent about our practices.
Last updated: March 7,2026