BIOGEEK 百吉盾牌标志BIOGEEK
产品 资讯 论坛 WIKI 个性化 关于
登录

隐私政策 PRIVACY POLICY

我们收什么、不收什么 What we collect, and what we deliberately do not

我们只收账户运行、社区身份、公开心声与发货必需的资料。本站没有第三方广告代码,没有行为追踪,也不根据账户建立健康画像。 We collect only what is needed to run an account, provide community identity and public messages, and deliver an order. There is no third-party advertising code, behavioural tracking or health profiling tied to accounts.

生效日期:2026 年 9 月 1 日 Effective 1 September 2026

一、我们收集哪些资料1. What we collect

只在你主动创建账户、登录、下单或联系我们时收集: Only when you choose to create an account, sign in, place an order or contact us:

  • 账户资料:电子邮箱、公开社区昵称、注册时间与账户状态Account data: email address, public community display name, registration time and account status
  • 安全资料:随机盐值与不可逆的密码哈希、会话令牌与一次性验证令牌的哈希、登录限流记录;我们不保存明文密码或验证链接原文Security data: a random salt and irreversible password hash, hashes of session and one-time verification tokens, and rate-limit records; we do not store plaintext passwords or verification links
  • 收货信息:收件人姓名、香港地区与详细地址、联系电话Delivery details: recipient name, Hong Kong district and address, contact phone number
  • 联系方式:电子邮箱,用于发送订单状态与快递单号Contact: your email address, used to send order status and the tracking number
  • 订单信息:订单编号、所购商品与数量、金额、支付状态Order data: order number, items and quantities, amount, payment status
  • 社区内容:你主动提交的讨论、回复、投票以及审核状态Community content: discussions, replies and votes you choose to submit, together with their moderation status
  • 公开心声:你主动提交的正文、可选昵称、可选联系方式与审核状态;昵称公开时会脱敏,联系方式不公开Public messages: the text, optional nickname, optional contact details and moderation status you choose to submit; public nicknames are masked and contact details are never published
  • 邮件往来:你写给我们的内容,以及我们的回复Correspondence: what you write to us and our replies

浏览、阅读报告和购买产品都不需要注册。只有使用社区身份等账户功能时才需要主动创建账户。 Browsing, reading reports and buying products do not require registration. You create an account only if you choose to use community identity or another account feature.

二、我们不收集什么2. What we never collect

  • 明文密码——密码只在提交时用于计算不可逆哈希,不写入数据库或日志Plaintext passwords — a password is used only to calculate an irreversible hash when submitted and is not written to the database or logs
  • 完整卡号、有效期、CVC 安全码——付款在支付机构的页面完成,这些数据从不经过我们的服务器Full card numbers, expiry dates or security codes — payment happens on the payment provider's page, and none of it passes through our servers
  • 身份证件号码——结账与配送均不索取Identity document numbers — checkout and delivery do not ask for them
  • 健康状况、病史、用药记录——个性化推荐目前不落库、不与订单关联Health conditions, medical history or medication records — the personalisation tool does not store them or link them to an order
  • 跨站行为数据——本站没有部署广告像素或第三方分析脚本Cross-site behavioural data — no advertising pixels or third-party analytics scripts are deployed here

三、存在你浏览器里的东西3. What sits in your browser

购物车内容、语言与地区选择保存在你自己浏览器的本地存储里,不会用于识别你的身份。登录后,浏览器还会保存一个最长 30 天的 HttpOnly 会话 Cookie;它只含随机令牌,不含邮箱、昵称或密码,退出登录会使其失效。 Cart contents, language and region choices stay in your browser's local storage and are not used to identify you. After sign-in, the browser also stores an HttpOnly session cookie for up to 30 days. It contains only a random token — no email, display name or password — and signing out invalidates it.

四、用途4. How we use it

  • 账户服务:验证邮箱、重设密码、验证登录、保持会话、显示社区昵称、防止批量撞库或滥用Account service: verifying email, resetting passwords, authenticating sign-in, maintaining sessions, showing a community display name and limiting automated abuse
  • 社区服务:审核并发布讨论与回复、记录投票、处理违规内容Community service: moderating and publishing discussions and replies, recording votes and handling content that breaches the rules
  • 公开心声服务:审核并公开意见、建议与批评;仅在需要回复时使用你主动留下的联系方式Public message service: reviewing and publishing opinions, suggestions and criticism; optional contact details are used only when a reply is needed
  • 处理订单:核对金额、安排发货、寄送快递单号Fulfilling orders: verifying the amount, arranging dispatch, sending tracking
  • 售后:退换货、批次追溯、回应你的查询After-sales: returns, batch traceability, answering your questions
  • 法定义务:保存交易与会计记录Legal obligations: keeping transaction and accounting records

我们不会把你的资料出售、出租或交换给任何第三方用于营销。未经你另行同意,我们不会向你发送营销邮件。 We do not sell, rent or trade your data to anyone for marketing, and we do not send marketing email without your separate consent.

五、我们会把资料交给谁5. Who else sees it

只在完成订单必需的范围内共享,且仅限以下类别: Only as far as completing your order requires, and only with these:

  • 支付机构:处理付款、退款与风控,会收到你的邮箱、姓名、电话与收货地址Our payment provider, which handles payment, refunds and fraud checks, and receives your email, name, phone number and delivery address
  • 快递公司:派送包裹,会收到你的姓名、地址与电话The courier that delivers the parcel, which receives your name, address and phone number
  • 网站托管、数据库与内容分发服务商 Cloudflare:提供站点、账户数据库和安全基础设施,并处理访问日志中的 IP 地址Cloudflare, our hosting, database and content-delivery provider, which supplies site, account-database and security infrastructure and processes IP addresses in access logs
  • 事务邮件服务商:只为发送邮箱验证、密码重设、订单与安全通知而接收必要的邮箱地址与邮件内容Our transactional email provider, which receives the necessary email address and message content only to deliver verification, password-reset, order and security notices
  • 字体服务:页面字体由 Google Fonts 提供,加载字体时你的 IP 会被该服务接收Google Fonts, which serves the typefaces on these pages and receives your IP address when a font loads

法律要求时(例如司法机关依法调取),我们会依法配合。 Where the law requires it — for example a lawful request from an authority — we comply.

六、保留多久6. How long we keep it

账户资料保留至账户删除;会话最长 30 天;邮箱验证令牌 24 小时、密码重设令牌 30 分钟后失效并清理;只含哈希标识的限流记录通常在 2 天内清理。公开社区与公开心声内容保留至你提出合理删除请求;待审核、拒绝或隐藏的心声通常在 90 天内清理,公开心声所附的私密联系方式会在任一审核终态立即清除。交易与会计记录按香港《税务条例》的要求保存 7 年。与订单无关的邮件往来在处理完毕后保留不超过 2 年。 Account data is kept until deletion. Sessions last no more than 30 days; email-verification tokens expire after 24 hours and password-reset tokens after 30 minutes, then are cleared. Rate-limit records containing only hashed identifiers are normally cleared within two days. Public community and message content remains until a reasonable deletion request; pending, rejected or hidden messages are normally cleared within 90 days, and private contact details attached to a public message are removed immediately once any moderation decision is made. Transaction and accounting records are kept for seven years under the Hong Kong Inland Revenue Ordinance. Non-order correspondence is kept for no more than two years after resolution.

七、你的权利7. Your rights

根据香港《个人资料(私隐)条例》,你有权查阅我们持有的关于你的个人资料,并要求更正不准确之处。发邮件到 hi@biogeek.ai 即可提出,我们会在法定期限内回复;为保护你的资料,我们可能需要先核实你的身份。 Under the Hong Kong Personal Data (Privacy) Ordinance you may ask what personal data we hold about you and require us to correct anything inaccurate. Email hi@biogeek.ai and we will respond within the statutory period. To protect your data we may need to verify who you are first.

你也可以要求删除资料。法定保留期内的交易记录我们无法删除,但可以删除其余部分。 You may also ask us to delete your data. We cannot remove transaction records still inside the statutory retention period, but we can delete the rest.

八、未成年人8. Children

任何年龄都可以浏览本站公开内容,注册账户不要求提供年龄或出生日期。我们对账户只收取运行服务所需的邮箱、社区昵称和安全资料,不将账户资料用于广告画像。若我们明确得知某位儿童的资料依法需要监护人同意,我们会停止相关处理,并在取得所需同意或删除资料前限制该账户。监护人可通过本政策列明的邮箱联系我们查阅、更正或删除相关资料。 People of any age may browse the site's public content, and registration does not ask for age or date of birth. We collect only the email address, community display name and security data needed to operate an account, and do not use account data for advertising profiles. If we learn that a child's data requires parental consent under applicable law, we will stop the relevant processing and restrict the account until the required consent is obtained or the data is deleted. A parent or guardian may use the contact address in this policy to request access, correction or deletion.

九、政策变更9. Changes to this policy

本政策更新后在本页发布即生效,页首标明生效日期。若涉及资料用途的实质性变化,我们会在网站上明显位置提示。 Updates take effect when published on this page, with the effective date shown at the top. If the way we use data changes materially, we will say so prominently on the site.

资料保护相关查询请联系 hi@biogeek.ai。中英文版本如有歧义,以中文版为准。 For data-protection enquiries, write to hi@biogeek.ai. If the Chinese and English versions differ, the Chinese version prevails.

配送政策Shipping policy 退换货政策Returns policy 服务条款Terms of service