Security & Privacy

Your data security and privacy are our top priorities. We adhere to international standards and regional regulations.

View our full Data Protection Framework β†’

πŸ‡­πŸ‡° PDPO Compliance

We fully comply with the Personal Data (Privacy) Ordinance (PDPO) of Hong Kong, which governs how personal data is handled.

  • βœ“Data collection transparency
  • βœ“User consent management
  • βœ“Data retention policies
  • βœ“Right to access and correction
  • βœ“Data subject rights protection

🌏 Cross-Border Data Compliance

As a Hong Kong-registered entity processing data submitted by clients operating across multiple jurisdictions, SneakersLite's data handling practices align with:

  • βœ“Hong Kong Personal Data (Privacy) Ordinance (PDPO)
  • βœ“China Personal Information Protection Law (PIPL)
  • βœ“China Data Security Law (DSL)

Client data submitted via API is processed solely for authentication purposes. Cross-border data transfers are conducted in accordance with applicable legal requirements in each operating jurisdiction.

πŸ“‹ Data Ownership & Usage

Clients retain full ownership of all images and authentication reports submitted through the SneakersLite API. Submitted data is used exclusively for:

  • βœ“Delivering contracted authentication results
  • βœ“Anonymised model training to improve authentication accuracy (with client consent per service agreement)

Client data is never sold, disclosed to third parties, or used outside the scope of the contracted service.

πŸ” Data Protection

Enterprise-grade security measures protect your authentication data and personal information.

  • βœ“End-to-end encryption
  • βœ“Regular security audits
  • βœ“Secure API endpoints
  • βœ“Access control & monitoring
  • βœ“Incident response plan

AWS Infrastructure

ComponentProviderRegionEncryption
ServersAWS EC2APACAES-256
DatabaseAWS RDSAPACAES-256
StorageAWS S3APACAES-256
CDNAWS CloudFrontGlobalTLS 1.3
DDoS ProtectionAWS ShieldGlobalN/A
SSL/TLSAWS ACMGlobalTLS 1.3

Security Standards & Compliance Frameworks

SneakersLite actively aligns its security practices to the following internationally recognised standards as part of our ongoing commitment to data protection. We are working toward formal certification as the platform scales.

πŸ”’

ISO 27001

Information Security Management (aligned practices)

βœ“

SOC 2

Service Organization Controls (aligned practices)

πŸ›‘οΈ

PCI DSS

Payment Card Industry Data Security Standard (aligned practices)

Security Questions?

Contact our security team for any inquiries about our privacy practices and security measures.