HaiRoute Cookie Policy
Last updated: 2026-07-02
Effective date: 2026-07-02
Website / service: hairoute.ai
Operated by: LDCY TECH HK LIMITED (香港靈動創意科技資訊有限公司)
Version status: Publication version
Language
This Cookie Policy is prepared in English and Chinese. Both versions are intended to have legal effect. If there is any inconsistency, ambiguity or conflict between the English and Chinese versions, the English version shall prevail, unless HaiRoute expressly states otherwise in writing.
1. Introduction
HaiRoute is a product operated by LDCY TECH HK LIMITED (香港靈動創意科技資訊有限公司), a company incorporated in Hong Kong ("HaiRoute", "we", "us" or "our"). This Cookie Policy explains how we use cookies and similar technologies in connection with HaiRoute's websites, dashboards, documentation, authentication flows, billing pages, support pages, marketing pages and related browser-based services (the "Online Services").
This Cookie Policy is governed by the laws of the Hong Kong Special Administrative Region. We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "PDPO") and our Privacy Policy. Any dispute relating to this Cookie Policy is subject to the governing law and dispute resolution provisions of our Terms of Service (see Terms of Service, Section 22).
This Cookie Policy should be read together with HaiRoute's Privacy Policy, Terms of Service (including its Acceptable Use provisions) and, where applicable, the Data Processing Agreement ("DPA"). Capitalised terms not defined in this Cookie Policy have the meanings given in those documents.
This Cookie Policy focuses on cookies and similar technologies that store information on, or access information from, a user's browser or device. It does not replace the Privacy Policy or Terms of Service for API logs, Customer API Data, Service Metadata, security records, abuse investigation records or evidence preservation.
2. What Are Cookies and Similar Technologies?
Cookies are small text files placed on your browser or device when you visit a website or use an online service. Cookies may help a service remember your session, login status, language, region, preferences, security settings or prior actions.
Similar technologies may include pixels, web beacons, tags, scripts, local storage, session storage, software development kits, device or browser signals and other technologies that store information on, or access information from, your browser or device.
In this Cookie Policy, "cookies" includes cookies and similar technologies unless the context requires otherwise.
3. How We Use Cookies
We use cookies for the following purposes:
- Strictly necessary operation: to provide the Online Services, keep you signed in, maintain sessions, remember cookie choices, route traffic, balance load, prevent duplicate submissions and operate account or dashboard features.
- Security, fraud prevention and abuse detection: to protect accounts, API keys, sessions and the Services; detect suspicious login activity, credential misuse, malicious automation, scraping, excessive requests, fraud, payment abuse, unauthorised access and violations of our Terms, including the Acceptable Use provisions.
- Preferences and functionality: to remember language, region, theme, dashboard layout, documentation preferences and other choices.
- Payment and billing: to support checkout, payment security and billing workflows, including cookies set by our third-party payment processor.
- Consent management: to remember your cookie choices and maintain records of consent or opt-out preferences.
As of the effective date, we do not deploy performance/analytics cookies or marketing/advertising cookies, and we do not use third-party analytics, advertising, bot-management or support-chat providers that set cookies. If we introduce such cookies in the future, we will update this Cookie Policy and, where required by applicable law, obtain your consent before setting non-essential cookies.
We do not intentionally store prompt bodies, completion bodies, uploaded files or API request/response content in cookies. Processing of Customer API Data, Service Metadata and security or enforcement records is described in the Privacy Policy, Terms of Service and DPA.
4. Categories of Cookies We May Use
| Category | Purpose | Can it be disabled in our cookie preference tool? | Currently in use? |
|---|---|---|---|
| Strictly necessary cookies | Required to provide the Online Services, authenticate users, maintain sessions, process security choices, remember cookie preferences, route traffic and operate core dashboard features. | No. These cookies are necessary for the Online Services to work. You may block them in your browser, but some features may not function. | Yes |
| Security and abuse prevention cookies | First-party cookies used to protect accounts, prevent cross-site request forgery, detect suspicious activity and support enforcement of our Terms, including the Acceptable Use provisions. | Usually no where they are necessary for security or service integrity. | Yes (first-party only) |
| Functionality cookies | Used to remember user choices such as language, region, theme, layout or documentation settings. | Yes, where not strictly necessary. | Yes |
| Payment and billing cookies | Set by our third-party payment processor to support checkout, payment security and fraud prevention during billing. | Necessary for checkout and payment security. | Yes (during checkout) |
| Performance and analytics cookies | Would be used to measure site and dashboard usage, identify errors and improve reliability and product design. | Yes, where required by law or our consent settings. | No — not currently deployed |
| Marketing and advertising cookies | Would be used to measure lawful marketing campaigns, referrals and attribution. | Yes. We would not use these unless permitted by law and, where required, with your consent. | No — not currently deployed |
As of the effective date, HaiRoute uses only strictly necessary, first-party security, functionality and third-party payment cookies. We do not currently deploy analytics, marketing, advertising, third-party bot-management/security or support-chat cookies. This table describes categories we may use; if we begin using any category not currently in use, we will update this Cookie Policy and, where required, obtain consent.
5. Security, Abuse Prevention and Evidence Preservation
HaiRoute provides AI gateway, routing, billing and enterprise administration services. Because misuse of AI services can create serious legal, safety, security, payment and model-provider risks, we may use strictly necessary, first-party cookies and similar technologies to help protect the Services and investigate suspected misuse. For example, they may help us authenticate users and protect sessions; detect account takeover, credential compromise or unauthorised dashboard access; identify suspicious login or request patterns; reduce fraud, chargebacks and payment abuse; and support rate limits, security challenges and access controls.
Cookies are only one part of this process. HaiRoute may also generate and retain Service Metadata, API logs, security records, billing records, investigation notes and other evidence as described in the Privacy Policy and Terms of Service. Detailed rules on prohibited conduct and enforcement are set out in the Acceptable Use provisions and other enforcement provisions of our Terms of Service. Where a suspected violation, dispute, chargeback, security incident, provider request, legal process or enforcement matter arises, HaiRoute may preserve relevant records for the period reasonably necessary for investigation, enforcement, dispute resolution, legal hold, regulatory response or applicable limitation periods, subject to applicable law (including the PDPO).
6. Cookie Inventory
The table below reflects HaiRoute's current deployment as of the effective date. As our Services develop, the cookies we use may change; this inventory should be re-verified through a technical cookie scan whenever the deployment changes, and before each publication.
| Cookie or technology | Provider | Category | Purpose | Typical duration |
|---|---|---|---|---|
hairoute_session |
HaiRoute (first-party) | Strictly necessary | Maintains authenticated dashboard session and account access. | Session or short fixed period |
csrf_token or equivalent |
HaiRoute (first-party) | Strictly necessary / security | Helps prevent cross-site request forgery and unauthorised form submissions. | Session |
hairoute_cookie_consent |
HaiRoute (first-party) | Strictly necessary / consent management | Stores your cookie consent or opt-out preferences. | 6 to 12 months, or as configured |
hairoute_region or equivalent |
HaiRoute (first-party) | Functionality | Remembers region, language or interface preference. | Up to 12 months |
| Payment / billing cookies | Current third-party payment processor used for checkout | Strictly necessary / functionality | Supports checkout, payment security, fraud prevention and billing workflows during payment. | As disclosed by the payment processor and the payment flow |
As of the effective date, HaiRoute deploys only the first-party cookies listed above plus cookies set by the third-party payment processor used during checkout. We do not currently deploy analytics, marketing/advertising, third-party bot-management/security or support-chat cookies. HaiRoute should re-verify this inventory through technical cookie scans and vendor review whenever the deployment changes and before material publication updates.
7. Third-Party Cookies and Vendors
As of the effective date, third-party cookies are limited to those set by our third-party payment processor during checkout and, where applicable, cookies set by our hosting or infrastructure providers. We do not currently use third-party analytics, advertising, bot-management or customer-support vendors that set cookies on our Online Services.
Where third-party vendors are used, they may process information according to their own privacy and cookie policies. HaiRoute does not control all third-party cookie practices. We use reasonable measures to select vendors appropriate for our Services and contractual needs, but you should review the relevant third-party policies where they apply. If we add further vendors that set cookies (for example, analytics, support or marketing tools), we will update this Cookie Policy accordingly.
8. Your Cookie Choices
Where required by applicable law, we will ask for your consent before setting non-essential cookies. Consent must be given through a clear positive action where affirmative consent is required; continued browsing alone will not be treated as consent in those cases. You can manage cookie choices through your browser settings and, where available, through account settings or any cookie preference tool we make available. If we deploy non-essential cookies that require consent, we will provide an appropriate consent mechanism, such as a cookie banner or preference centre, that allows you to enable or disable non-essential cookie categories where required.
Most browsers allow you to block, delete or receive alerts about cookies. If you block or delete cookies, some parts of the Online Services may not work properly. For example, you may not be able to sign in, maintain a secure session, use dashboard features, complete billing steps or save preferences.
Strictly necessary cookies, including cookies required for authentication, security, fraud prevention, consent management, service integrity, load balancing and core dashboard functionality, may not be disabled through our cookie preference tool.
9. Regional Choices: PDPO, Do Not Track and Global Privacy Control
We handle personal data collected via cookies in accordance with the PDPO and our Privacy Policy. Under the PDPO, you may have rights to access and correct your personal data and to make privacy-related requests; the Privacy Policy explains how to exercise them.
Some browsers or extensions may send "Do Not Track" or "Global Privacy Control" signals. Because "Do Not Track" is not a uniform legal standard, we respond to it as required by applicable law. Where applicable law requires recognition of valid opt-out preference signals, including Global Privacy Control, HaiRoute will honor those signals for any sale, sharing, targeted advertising or similar processing that applies to HaiRoute. As of the effective date, HaiRoute does not sell or share personal data for cross-context behavioural advertising.
10. Eligibility
The Services are intended for individual customers outside Mainland China, business customers, developers and organisations. Individual customers must be at least 18 years old. The Services are not directed to children, and we do not knowingly use cookies to profile, target or market to children.
For more information about how HaiRoute processes personal data and handles privacy matters relating to minors or children, please see our Privacy Policy.
11. Changes to this Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our Services, vendors, cookies, technologies, legal requirements or business practices. We will indicate the updated date and may provide additional notice for material changes through our website, dashboard, email or cookie banner.
Continued use of the Online Services after the effective date of an updated Cookie Policy means the updated Cookie Policy applies to future use of cookies and similar technologies.
12. Contact Us
For privacy or cookie questions, requests, complaints or concerns, please contact:
LDCY TECH HK LIMITED (香港靈動創意科技資訊有限公司)
Product: HaiRoute
Website: hairoute.ai
Email: privacy@hairoute.ai