LEGAL INFORMATION · PRIVACY POLICY
Privacy policy
AOYE Resources (Guangdong) Co., Ltd. takes personal-information and privacy protection seriously. This policy explains how we collect, use, store and protect information when providing our website and services.
Information we collect
We may collect the information you provide for an enquiry, assessment, job-seeking or service request, together with limited first-party browsing and content-interaction data.
How we use information
Information is used to respond to enquiries, assess service needs, support a requested recruitment or employment process and improve website content and service delivery. We do not sell personal information.
Storage and protection
Access is limited to authorised personnel with a service need. We use appropriate access controls, encrypted transmission and backup practices. Retention follows applicable requirements and service needs.
Your choices
You may ask to access, correct or delete personal information, subject to identity verification and applicable legal obligations. You may withdraw an earlier consent for future processing.
Cookies and analytics
This site automatically performs limited first-party content and conversion analysis to understand page visits, article reading, action links, registrations and successful logins. The browser stores a random first-party visitor identifier for up to 12 months to maintain a continuous signed-out visitor profile. Events include the event time and type, page path without a query string, structured browser and operating-system names/versions and device category, referrer category and hostname, validated UTM fields and the restricted from source label retained within the same visit, business line, language, market, content title, category, route family, publication/version identity, foreground reading seconds, scroll-depth bucket and CTA identifiers.
To analyse real usage, this site also records page interactions such as button and link actions, dead clicks and repeated rage clicks, heatmap coordinates, page-performance metrics including Web Vitals, and front-end exceptions, and uses session replay to reconstruct a visit. Replay may show public page structure and text, but every input value is masked; canvas content, copied text and form content are not recorded. Network diagnostics contain request URL paths without query strings or fragments, timing and response status, never request or response headers/bodies or console logs. Error reports carry the deployed version; source maps used to locate source-code errors are uploaded only to the private error-analysis system and are not publicly served.
When you complete your name and phone and actively submit an assessment, that submission record includes your submitted name, phone, region, age band, education, certificates, experience, language choices and displayed matches. It is linked to the same visitor's earlier and later browsing for consultant follow-up and content analysis. The existing consultant notification includes an analysis record ID and an internal-only journey link. Unsubmitted contact details are not collected by analytics, and submitted details are not treated as verified account identity or used to merge people. Step events contain only the step number. The from parameter is stored separately as a restricted source label, never as a full query string.
Apart from that limited valid assessment-submission snapshot, analytical events do not store names, phone numbers, email addresses, WeChat identifiers, or form/message text. All analytics channels exclude device fingerprints, raw IP addresses, full user agents, full query strings, passwords, verification codes and access tokens. A source IP is used only in request memory with the existing offline IP2Region database to derive country and, in mainland China, province-level attribution; it is not written to event, attribution or edge-spool storage. Only these coarse attribution fields are exported to the private PostHog project, never a city or precise location. The public attribution database does not store account identifiers. Its private country/province copy follows the same visitor journey and is linked to a confirmed account only through the existing server-side identity flow. Public raw events, the PostHog protocol edge spool, the account-analysis outbox and coarse attribution are retained for no more than 30 days. Private analytical events, including coarse attribution and assessment-submission snapshots, are retained for 12 months.
Before events leave the public host, raw event, visit and browser identifiers are replaced with stable, domain-separated HMAC derivatives. A controlled local device then pulls them into a dedicated internal PostHog project. After a visitor successfully registers or signs in, the server links the earlier signed-out visitor profile to that platform account. Signing out or switching accounts rotates the visitor identifier so that two accounts are not merged.
Account profiles use an HMAC-derived account identifier as the person identity and contain only the internal account ID, the user-provided display name after contact-shaped values are excluded, role and existing business-ownership labels. PostHog is not linked to Enterprise WeChat or CRM contact identities. Governed PostHog events, person profiles, aliases and replays are retained for 12 months, then deleted and verified as no longer queryable. The login notice does not create a new legal-consent receipt, require an existing account to re-sign or overwrite the consent evidence from first business activation.
Contact
For privacy questions, contact Zhuhai headquarters: (0756) 2299 220; Macau: +853 6890 6869; Hong Kong: +852 4613 6662. Last updated: 6 September 2026.
