Trust centre · Personal data
Privacy policy
This policy describes the personal data covenantdesk.hk collects, why it is collected, who else processes it, how long it is kept, and how to ask for a copy or a correction. It covers this website only. It does not cover the borrower data a lender holds inside its own Covenant Desk system, where the lender is the data user and its own policy applies.
Section one
What this website collects, and when
Nothing on this site requires an account. Personal data reaches us only when you type it into one of four places.
| Where | What you provide | Why that field exists |
|---|---|---|
| Demo and enquiry form | Your name, company, work email, telephone number if you give one, your role, staff numbers, current loan system, the workflow you want to modernise, your timeline, and any notes you write. | The qualification fields let us prepare a relevant demonstration instead of a generic one. Only the plan, name, company, email, timeline and notes are required. |
| Homepage email capture | A work email address. | It carries into checkout so you do not retype it, and it reaches us so an enquiry started here is not lost if you close the tab. |
| Lending news signup | A work email address, a WhatsApp number, or both. | Whichever you prefer to be reached on. One is required; neither individually. The email version also receives a confirmation with recent briefings. |
| Checkout | Your name, company, work email, telephone number if you give one, and the connected lending companies you name. | To take payment, issue a receipt, and create the portal account. Card details are entered directly into Stripe and never reach our servers. |
Each of these sends an email to [email protected] so a person can reply. We do not buy contact lists, and we do not collect personal data about you from third parties.
Section two
What we do with it
Answering you
An enquiry is used to reply, arrange a demonstration, and continue that conversation. Replies go to the address you gave.
Fulfilling an order
Checkout details are used to take payment through Stripe, issue a receipt, and create the account that activates your portal access.
Sending what you asked for
If you sign up for the lending news briefing, the address or number you gave is used to send it. Every briefing can be stopped by replying or writing to us.
Understanding the site
Aggregate measurement tells us which pages and guides are useful. It is deliberately built so that no personal detail is sent to it — see section four.
We do not sell personal data. We do not share it for anyone else's marketing. We do not use it to make automated decisions about you.
Section three
Who else handles it
These providers process data on our behalf so the site can function. Each is named so you can read its own terms.
Stripe
Payment processing at checkout. Card details are entered into Stripe's own fields and are never received or stored by Covenant Desk.
DigitalOcean
Hosting for the website and its API endpoints, in the Singapore region.
Cloudflare
Content delivery and protection in front of the site.
Namecheap Private Email
The mail service that carries enquiry, receipt and briefing email.
Google Analytics 4
Aggregate site measurement. See the next section for what is and is not sent to it.
My Covenant portal
Buyer account activation after a purchase, at my.covenantdesk.hk.
Section four
Measurement and browser storage
The site sends a fixed set of events to Google Analytics 4 (measurement ID G-FJ6XYK5Q73). The measurement layer is written so that no personal data is ever sent as an event parameter — no name, email address, telephone number, HKID, address or company name. The only identifier it emits is lead_id: a random value generated in your browser that is not derived from, and cannot be reversed into, any personal detail. It lets a completed enquiry be matched to the pages that preceded it without Google receiving anything about you.
The site stores a small number of values in your own browser. They stay on your device and are not sent to us except as noted:
| Key | Where it lives | What it is for |
|---|---|---|
| cd_lead_id | localStorage | A random correlation id. Sent to Google Analytics and included with an enquiry so a completed enquiry can be matched to the pages that preceded it. |
| cd_first_touch | localStorage, 90 days | How you first arrived at the site. |
| cd_news_prompt_seen | localStorage | Stops the news prompt reappearing for a week after you dismiss it. |
| cd_lead_email | sessionStorage | Carries the address you typed on the homepage through to checkout. Cleared when the tab closes. |
| cd_entry_guide, cd_purchase, cd_debug | sessionStorage | Which guide you entered on, a one-off purchase handoff, and a measurement debug flag. |
Clearing your browser storage removes all of these. The site continues to work without them; the measurement layer is written to fail quietly when storage is unavailable, as it is in private browsing.
Section five
How long it is kept
Enquiries
Enquiry email is kept in the [email protected] mailbox for as long as the commercial conversation is live, and then for as long as we may need it to answer a question about that conversation.
Orders
Order and payment records are kept for the period Hong Kong business and tax record-keeping requires.
Briefing signups
Kept until you ask to stop receiving the briefing, after which the address or number is removed.
Measurement
Held by Google under the retention period configured for the property. It contains no personal detail from us.
Section six
Your rights, and how to use them
Under the Personal Data (Privacy) Ordinance (Cap. 486) you may ask us what personal data we hold about you, ask for a copy, and ask us to correct anything inaccurate.
- Write to [email protected] with enough detail to find the record — usually the address you used and roughly when.
- We confirm receipt and may ask for something that reasonably identifies you, so the data is not disclosed to the wrong person.
- We respond within 40 days, which is the period the Ordinance allows for a data access request. A fee may apply for a data access request, as the Ordinance permits.
- If we correct something, we tell you what changed. If we decline a request, we tell you why.
If you are not satisfied with how we have handled a request, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
Section seven
Boundaries worth stating plainly
This covers the website, not a lender's system
Where a lender runs Covenant Desk over its own borrower records, that lender is the data user and remains responsible for the personal data in it. This policy does not govern that data, and we do not use it for our own purposes.
We are not a credit reference agency
Covenant Desk does not operate a credit database and does not issue consumer credit reports or scores. Nothing you send through this website is added to any credit record.
Providing data is voluntary
Every field on this site is optional in the sense that you may choose not to submit the form. If you do not provide a work email we cannot reply, which is the only consequence.
Changes to this policy
If this policy changes, the date under the title changes with it. Material changes will be described on the page rather than made silently.
Questions about this policy: [email protected], or WhatsApp +852 4706 1132.

