Privacy policy
Royden So, Hong Kong SAR. Effective 25 August 2026.
This policy explains what personal data this private preview site collects, why, and what you can do about it. The site is operated by Royden So, an independent design and engineering practice based in Hong Kong SAR, who is the data user for it.
It covers this site only. It doesn't cover a prototype's imagined product, a client's own service, or any third-party site we link to.
1. The short version
- There is no analytics, no advertising, no tracking pixel and no third-party script on this site.
- One cookie, and it exists to keep you signed in.
- We hold your work identity, meaning a login name and the name you pick when you comment, and the things you write here.
- We never sell, rent or share your data for anyone else's marketing, because there is nobody to sell it to.
- Screenshots taken with a comment are stored privately and are never publicly readable.
- Ninety days after your access ends, the review record is deleted.
2. What we collect
Account and sign-in:
- The login name and password we issued to your organisation. Credentials are configured by us; you don't create an account and there's no sign-up form.
- A display name for the login, so the interface can greet a person rather than a role.
- Which workspaces that login may open.
- Failed sign-in attempts, counted in memory against an IP address and a username for ten minutes, to slow down password guessing. Nothing is written to a database and nothing survives a restart.
What you do here:
- Comments and replies you write, the author name you chose from your organisation's roster, and the position of the pin on the screen.
- Approvals and requested changes: the decision, the name recorded against it, and the time.
- Progress ticks and changelog read state, so we can show you what changed since you last looked. Read state is stored against your chosen viewer name.
- A screenshot of the screen at the moment a pin was dropped, when you drop one, stored in a private file store.
Automatically, from the infrastructure:
- Ordinary server logs from our hosting provider: IP address, user agent, request path, status and timestamp. We don't build profiles from them and we look at them only to fix a problem or investigate suspicious access.
- The session cookie described below.
And separately, outside this site:
- Email you send us, and the address you send it from, kept as part of the project record.
3. What we don't collect
- No analytics, product analytics, session recording, heatmaps or A/B tooling. There's no such package in this codebase.
- No advertising, no remarketing, no third-party trackers, no social pixels.
- No location data beyond whatever an IP address implies in a log.
- No payment details. Nothing is charged here.
- No biometric, health or government identifier data.
- No data about your customers, unless someone types it into a comment, which the acceptable use policy asks you not to do.
We don't sell personal data, and we don't share it for anyone's marketing.
5. Why we use it
- To let the right people in, and keep everyone else out.
- To show each client their own workspace and nothing else.
- To run the review: attribute a comment, thread a reply, record a decision, show what changed since your last visit.
- To do the work you engaged us for, and to keep a record of it.
- To keep the site secure and investigate misuse.
- To comply with a legal obligation, if one ever applies.
In each case the processing is necessary to perform the engagement between us, or serves our legitimate interest in running a private preview safely. We don't process anything here for marketing, and we don't use it to make automated decisions about anyone.
6. Who can see what
Inside the practice, Royden So can see everything. There's no wider team with access, and no contractor is given a login without a confidentiality agreement.
Between clients, workspaces are separated three ways: a login is scoped to named workspaces, each client deployment is built with only its own workspace compiled in, and every request that touches shared data checks the workspace against the session on the server. One client can't read another's comments, screens or decisions.
We disclose data to a third party only where a service provider needs it to run the site, where you ask us to, or where the law requires it. If we're ever compelled to hand something over, we'll tell you first unless we're legally barred from doing so.
7. Where it lives, and who processes it
Three providers, each doing one job:
- Vercel, for hosting and delivery, and for the ordinary server logs that come with it.
- Neon, a managed Postgres database, for the review record: comments, approvals, changelog entries and read state.
- Vercel Blob, a private file store, for screenshots taken with a comment. Files are stored with private access and are readable only through an authenticated request to this site.
- Google Workspace, for email correspondence with us.
Each is bound by its own terms and processes data on our instructions. We don't use any of them to profile you.
These providers operate globally, so your data may be stored or processed outside Hong Kong, including in the United States and the European Union. Where that happens, we rely on the providers' contractual data protection commitments, and we ask you not to put sensitive personal data here in the first place.
8. How long we keep it
- The session cookie: seven days, or until you sign out.
- Failed sign-in counters: ten minutes, in memory only.
- Comments, approvals, changelog entries, read state and screenshots: for the engagement, and ninety days after access ends. Then deleted.
- Server logs: for as long as our hosting provider retains them, which is a short window measured in days, not years.
- Email and the project record: for as long as we may need it for the engagement, a dispute, or our tax and accounting obligations, and no longer than seven years.
- A deleted comment goes immediately, and takes its replies and its screenshot with it.
Ask before the ninety days are up and we'll export the review record for you. Ask us to delete something sooner and we'll do it, unless we need it for a live dispute or the law says otherwise.
9. How it's protected
- Every page and route sits behind a password wall enforced at the edge, before any content is served.
- The session is a signed cookie: it can't be forged or edited without the signing key.
- Sign-in attempts are throttled per address and per username.
- Each client deployment compiles only its own workspace, so another client's material isn't merely hidden, it isn't in the build.
- Screenshots are stored privately and served only through an authenticated request.
- Access is granted per engagement and withdrawn when it ends.
Being straight with you: this is a private preview protected by a shared password, not a hardened production system. A shared password is only as good as the people who hold it. Don't store anything here you'd be harmed by losing or exposing, and tell us quickly if a credential goes astray.
If we ever discover a breach affecting your data, we'll tell you promptly, with what we know and what we're doing about it.
10. Your rights
Under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong, you may ask us whether we hold personal data about you, ask for a copy of it, and ask us to correct it if it's wrong.
- Send the request to contact@roydenso.com, and tell us enough to find the data, which is usually the login and the workspace.
- We'll respond within forty days. If we can't, we'll tell you why within that time.
- We may charge a fee for a copy, and it won't be more than the direct cost of providing it.
- If we refuse, we'll tell you the reason.
- We may need to confirm you're the person the data is about before we hand anything over.
If you're in the EU, the UK or California, we'll also honour requests to access, correct, delete, port or restrict processing of your personal data, and object to it, to the extent those rights apply. We don't sell personal data or share it for cross-context behavioural advertising, so there's nothing to opt out of.
Where the personal data in question belongs to your organisation's project record rather than to you personally, ask your organisation first. We'll usually route the request through whoever holds the engagement with us.
11. Children
This is a professional tool for a client engagement. It isn't directed at children, and we don't knowingly collect data from anyone under 18. If a credential reaches someone under 18, tell us and we'll remove any data associated with it.
12. Changes to this policy
The current version is always on this page with its effective date at the top. If something material changes, we'll say so on the sign-in screen or email the address on your account before it takes effect.
13. Contact, and complaints
For anything in this policy, including an access or correction request: contact@roydenso.com.
If you're not satisfied with how we've handled it, you can complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, at pcpd.org.hk. We'd rather you came to us first, and we'll try to fix it.
Royden So, Hong Kong SAR.