Read how Runlian Technology Co., Limited handles the information that flows through the Runonly glasshouse.
Last updated: 9 September 2026. Applies to every Runonly product under the care of Runlian Technology Co., Limited.
This Privacy Policy explains what Runlian Technology Co., Limited (referred to below as the Company, we, us or our) collects and uses when people visit the Runonly website, read our pages, sign up to our mailing list, or become a Florist Client who runs a boutique flower shop on our systems. This policy is shared on the glasshouse website roseonly.autos and on the digital products that the Company builds and tends.
The Runonly name is the trading identity under which Runlian Technology Co., Limited builds its boutique commerce and delivery software. The software behind the rose rooms is designed by a development team that works under the Runonly brand at the Company studio address of Rm 712 7/F GOODLUCK INDL CTR, 808 LAI CHI KOK RD, Lai Chi Kok, Hong Kong (HK).
The party responsible for the processing described in this policy is Runlian Technology Co., Limited, a company established in Hong Kong. Our registered studio and principal place of business is Rm 712 7/F GOODLUCK INDL CTR, 808 LAI CHI KOK RD, Lai Chi Kok, Hong Kong (HK). We operate the public website at the domain roseonly.autos and we provide the digital products that we describe under the trading name Runonly.
If you have a question about this policy or about any information we hold about you, please write to us at contact@roseonly.autos or telephone us at +15094790428. We will answer every privacy question as quickly as we can, normally within five working days. When you write, tell us exactly which part of this policy your question concerns, so that we can give you a precise answer rather than a general one.
The Runonly development team, which the Company directs, does not see raw consumer databases without a lawful reason. When a Florist Client asks for help with an order, we may assist under that client instruction and under the terms that this policy sets out.
Personal data means any information that relates to an identified or identifiable living person. This can include a name, an email address, a telephone number, a postal address, an online identifier, an order reference, or a combination of details that together point to one person. We treat personal data carefully and we never sell it.
A Visitor means any person who browses this website, opens our campaign emails, or otherwise reads material that the Company publishes without opening a Florist Client account. A Florist Client means a flower shop or studio that licenses one or more of our products to run its own business. A Recipient means the person who is due to receive a bouquet or arrangement booked through a Florist Client platform, or the person who asks for a quotation or a re-delivery.
Processing means almost anything we might do with information, including collecting, recording, storing, organising, using, disclosing, combining and deleting it. Where this policy says that we process information, it uses that wider sense of the word. References to laws include the Hong Kong Personal Data (Privacy) Ordinance, the laws of the server region, and any data protection rule that applies to our visitors and clients where they live.
We collect only the information that we genuinely need, and we try hard to limit that amount. The categories below reflect the main ways that data reaches us. Because every product differs, some of the details here may not apply to the exact page you visited or the exact service your shop has licensed.
First, we collect information that you give us directly. If you write through the contact form, we receive your name, your email address, the subject you chose and the text of your message. If you telephone, we may make a short written note of the reason for your call so that we can follow up honestly. If you subscribe to a newsletter, we receive the email address you entered and the time at which you subscribed.
Second, we collect information automatically when someone uses this website. This includes the type of web browser, the operating system, the rough geographic region derived from the internet address, the pages visited, the length of each visit, and the general source that brought a person here. Most of this automatic information is gathered in aggregate and cannot identify a single person on its own.
Third, when a Florist Client runs one of our products, that product uses the data required to sell flowers responsibly. The data belongs to the Florist Client, but it flows through infrastructure that we operate and maintain. We handle this client data only to provide the service, to keep it secure, and to follow the instructions that the Florist Client gives us under its own contract.
Visitors to the Runonly website give us very little. We do not ask you to register simply to read our pages, we do not require an account to browse the portfolio or the service list, and we do not force a newsletter on anyone. A visitor who wants to stay purely anonymous is welcome to read everything we publish without giving us anything but automatic technical details.
If a visitor uses the contact form, we keep the message together with the contact email so that we can answer. If a visitor enters a conversation about possible work, we keep enough detail to remember the shop and the request across separate emails, so that the visitor does not have to repeat everything while negotiating with us.
We do not build a profile of individual website visitors for advertising. We do not send unsolicited commercial email to people who visit our public pages. We may study aggregated patterns, such as which service page is read most often or which region sends the highest number of enquiries, so that we can publish material that genuinely helps boutique florists.
When a shop becomes a Florist Client, we hold the business contact details that were supplied, including the trading address, the responsible owner contact, the email address and the invoice and payment information needed to run the account. We also hold records of the products licensed, the support messages exchanged, the agreed renewal date and the technical settings of the shop itself.
This client information lets us maintain a clear account, send honest invoices, provide trained support and keep the working relationship professional. We do not use the private details of a Florist Client to market to the clients of that Florist Client. The consumer relationships that belong to a flower shop are the business asset of the flower shop, not a resource that we silently harvest.
Because the Company builds software rather than selling flowers itself, we depend on clear communication with our Florist Clients. We therefore retain a summary of every significant support decision, so that a question raised in March can be understood again in October without confusion. This record refers to the business account and to the people who manage it, and it is kept only for the life of the contract and the retention period that section eleven describes.
When a customer places an order through a Florist Client platform that we operate, the platform records the name of the recipient, the delivery address, a telephone number where one is given, the items ordered, the special instructions and the date the delivery is wanted. This information is processed on behalf of the Florist Client so that the arrangement can be made, wrapped, labelled and delivered to the right doorstep at the right time.
We deliberately separate order information from any wider marketing use. A delivery address exists to get flowers to a doorstep; it does not become a mailing list. We do not sell recipient lists, and we do not let our engineers browse the private content of orders for curiosity. Access to order detail inside the software is limited to the staff of the Florist Client and to the handful of Company engineers whose duty requires them to repair or maintain the system.
The Company may process limited recipient information in our own capacity, for example to confirm that a delivery was attempted, to resolve a dispute about a missing order, or to comply with a lawful request. In every such case we keep our handling minimal, transparent and time-limited.
We use the information that we hold for clear and limited purposes, and we do not repurpose it silently. The main purposes are to provide and improve our products, to answer questions and support tickets, to keep the glasshouse running safely and reliably, to send the invoices and notices that a business relationship requires, to send marketing only where a person has consented, and to comply with the law.
For visitors and newsletter subscribers, we use the email address to deliver the content that was asked for and to notice unsubscribes so that we never send unwanted mail. For contact-form messages, we use the details given to respond to the exact enquiry, to follow a project conversation and to provide the quoted work. For Florist Clients, we use account data to manage the licence, to bill correctly, to give support and to renew services at the agreed time.
For consumer orders handled through a client platform, the information is used to fulfil that order, to communicate with the buyer about its progress, to arrange payment with the payment vendor, to plan the delivery route and to stay in touch only in the ways that the specific product has openly promised. Where a tool sends an automated status message, that message is a necessary part of the service and not a channel for unrelated promotion.
We rely on several lawful grounds for our processing, depending on the situation. For ordinary administration of a contract, the ground is the performance of that contract with the visitor or the Florist Client. When we answer a pre-contractual question, we rely on the steps that the enquirer asked us to take before entering into an agreement.
For processing that flows from a legal duty, such as keeping records demanded by tax law or responding to a court order, the ground is compliance with a legal obligation. Where we have a legitimate commercial or security interest that does not override the rights of the individual, such as keeping our systems safe from abuse or understanding crude usage patterns so that the website works, we rely on our legitimate interest and balance it carefully against any impact on the person concerned.
For electronic marketing that is not necessary to a service, we rely on consent where consent is required by the law of the place where the person lives. Consent can always be withdrawn easily, by using the unsubscribe link in an email or by writing to us at the contact details in section nineteen.
Like nearly every modern business, we rely on a small set of trusted vendors to host the website, to send transactional email, to take payments for contracts and to provide analytics in an aggregated form. Each vendor is selected with an eye on its own privacy and security practice, and each one receives only the data that its role truly requires.
The vendors never own the personal data that passes through their systems on our behalf, and their contracts stop them from using that data for their own advertising. We review the vendor list from time to time and we will update this policy if a vendor is changed or if a new vendor begins to handle personal data on our behalf.
For the payment side of Florist Client renewals, the card details are collected and tokenised by the payment vendor rather than stored on our own ordinary servers. That practice reduces the risk that a full card number is ever at rest in a place where a mistake could expose it.
We keep personal data no longer than the purpose needs it, and we delete or anonymise it when that purpose is finished. The exact period depends on the type of data. Contact-form messages and their replies are kept for a reasonable time after the conversation ends, so that a returning enquirer can be recognised and served well.
Account and invoice records for Florist Clients are held for the life of the active contract and then for the length required by tax and accounting rules, which commonly runs to several years after the last invoice. Newsletter subscription records last until a person unsubscribes or the list closes. Order information handled on behalf of a Florist Client is retained according to the wishes of that client and the retention default set inside the product, which is designed to forget delivery detail as soon as it is no longer useful.
When a retention period ends we aim to delete the data cleanly rather than merely hiding it. Where complete deletion is impractical inside a backup, we shorten the relevant records or isolate them until the next scheduled purge. We will tell a visitor or client how long a particular category is kept if they ask.
We protect information with a combination of technical and organisational measures suited to its sensitivity. Transport over the public internet is encrypted, accounts that control access to client data are protected with strong passwords and two-factor checks where possible, and access to production data is limited to the small set of people whose job genuinely requires it.
On the organisational side, the Company gives privacy duties to a named person, trains the team who handles client data, and keeps written guidance about what may and may not be done with personal information. We log significant access and we review those logs when something looks unusual. We also test our systems for obvious weaknesses and we patch them quickly when a fix is published.
No security is perfect, and we cannot promise that a determined attacker will never succeed. What we can promise is care: we keep our attack surface small, we never demand more personal data than we need, and if we ever discover a breach that is likely to create a real risk for people, we will tell the affected individuals and the relevant authorities as the law requires.
Runlian Technology Co., Limited operates from Hong Kong, and parts of our infrastructure may be hosted in other regions in order to keep the service fast and resilient. When personal data crosses a border, we take reasonable steps to ensure that it continues to receive a consistent, high standard of protection rather than weakening as it travels.
Where a transfer involves personal data of individuals who live under a law that restricts such moves, we rely on safeguards that the law recognises, such as standard contractual clauses or an adequacy decision, and we document the basis on which each such transfer is made. In practice we choose hosting and vendors that already offer recognised safeguards so that lawful holes do not open.
We will tell you, on request, where your personal data is ordinarily stored and which safeguard applies to any cross-border flow that concerns you. This information helps you judge whether the Company is the sort of partner whose use of the cloud you find acceptable.
Depending on where you live, the law gives you a set of clear rights over the personal data we hold. In most places these include the right to know what we hold about you, to ask for a copy of it, to have obvious mistakes corrected, to ask to have the data erased, to limit how we use it, and to object to uses that rely on our legitimate interest.
You also have the right to move your data in a structured, commonly used and machine-readable form where the processing is automated and based on consent or on a contract. And where a decision is made about you purely by machine in a way that has a serious legal effect, you have the right not to be subject to that decision and to have a human review it.
To exercise any of these rights, write to us at the address in section nineteen and tell us which right you are using. We may ask you to confirm who you are before we act, so that we do not hand personal data to someone who merely claims to be you. We will usually respond within one month; if your request is complex we will tell you that it needs longer, together with the reason.
The boutique software that we build is intended for the owners and staff of flower shops, for adults buying gifts, and for recipients who are part of a lawful order. We do not design our consumer services for children, and we do not knowingly collect personal data from a child without the consent of a parent or guardian where that consent is required.
If a child has used a public form on this website or signed up for a product without appropriate permission, a parent or guardian may contact us and ask us to remove the account or the record. We will act on that request quickly and we will confirm what steps we took once the removal is complete.
We also make a practical effort to avoid accidental collection. Buttons and prize entrances that appeal mainly to children do not form part of our range, and where a delivery note does carry a message for a young person, that message remains part of the normal order rather than a separate data capture.
Our website and the material we publish may link to other websites that we do not control, such as payment pages, social profiles or business directories. When you leave our pages and visit one of those third party services, the privacy rules that govern your experience are the ones that those services publish, not this policy.
We choose the links that we share with care, but we cannot be responsible for the content or the data practice of every page beyond our own control. Before you give personal information to a linked site, we encourage you to read the privacy policy of that site and to judge whether its standards match your own expectations.
Because this policy only covers the Runonly glasshouse and the products we directly operate, it does not govern any separate page that a Florist Client may host under its own name. In that situation the client of the shop is the data controller for the consumer relationship, and the shop should give its own customers a privacy notice that describes its choices.
We will update this Privacy Policy from time to time, so that it keeps pace with the way the glasshouse works, with the products we have introduced, and with changes in the law. When we make a significant change, we will mark the date of the change at the top of the policy and, where the change affects a Florist Client directly, we will tell that client through the account.
For changes that only tidy wording or add nothing new to the rights of individuals, we may publish the new version without individual notice, because the overall promise stays the same. Whenever a change is made, the updated policy replaces earlier versions from the date the change is published on this page unless the law says otherwise.
If you keep using our website or a licensed product after a change is published, your continued use is taken as acceptance of the updated version. If you do not agree with a changed policy, you may stop using the affected service and, where you are a Florist Client, you may follow the ending terms of your separate agreement.
The best first step for any privacy question is an email to contact@roseonly.autos, sent with the words Privacy Request in the subject line so that we route it to the right desk at once. You may also telephone +15094790428 and ask for the privacy office, and we will treat a call that way with the same care as a written enquiry.
For formal correspondence, please write to Runlian Technology Co., Limited at Rm 712 7/F GOODLUCK INDL CTR, 808 LAI CHI KOK RD, Lai Chi Kok, Hong Kong (HK). Mark the envelope clearly as a privacy matter so that it reaches the responsible person rather than sitting in a general tray.
If you believe that we have not handled your personal data properly, you first have our promise that we will listen and correct a genuine mistake. If you remain unsatisfied after giving us a fair chance to put things right, you also have the right to complain to the data protection authority where you live or where an alleged harm took place. We will cooperate fully with any proper investigation.