Draft—For Client and Legal Review · PRIVACY POLICY
Privacy Policy
This draft organizes the disclosures a final Siomai House privacy policy is expected to contain. It describes only the behavior confirmed in the current website code and marks all client- or legal-dependent practices for review.
Information collected
The public inquiry forms are designed to request a name, email address, telephone number where needed, preferred contact method, message, and limited details relevant to the selected inquiry. Order inquiries may also request a product, quantity, and general location.
The client and legal adviser must confirm the complete production data inventory, including any information collected outside this website or by a future receiving service.
Purpose of collection
The intended purpose of the current form fields is to understand and respond to the visitor's selected inquiry. A final policy must identify the approved purposes and applicable legal basis for each form and any later use of the information.
Contact and inquiry forms
Each inquiry type has a separate Cloudflare Worker endpoint with client-side and server-side validation. The endpoint forwards information only when an approved HTTPS receiving service is configured and explicitly confirms receipt.
No receiving service is configured in the source-controlled environment. The website does not currently use a site database to persist inquiry records, and it does not display a success confirmation without a confirmed receipt.
Franchise and reseller applications
The public franchise and reseller forms are limited to an initial inquiry. They do not request government identification, selfies, social-media accounts, payment information, or a complete home address.
If a later application process requests additional documents or business information, the client must document the purpose, recipients, security, retention, and approved collection channel before those fields are added.
Career applications
Career submission is disabled in the current website. The career interface requests only the minimum contact and desired-position details needed to explain the planned workflow.
Recruitment-specific information is organized separately in the Applicant Privacy Notice. That notice also remains a draft for client and legal review.
- Review the Applicant Privacy Notice before enabling any career application or document upload.
File uploads
The current website does not accept or store file uploads. Résumé selection and career submission are disabled because private storage, restricted reviewer access, file-content validation, malware scanning, retention, deletion, and recruitment delivery have not been configured.
Files must never be placed in public website assets. Any future upload process requires an approved private-storage architecture and an updated privacy notice before activation.
Analytics and cookies
No analytics, advertising, personalization, marketing pixel, or non-essential cookie integration was found in the current application code. Accordingly, the website does not show a consent banner for optional cookies that are not installed.
Cloudflare hosting and security behavior, request logs, and any production-only tools must still be verified. See the draft Cookie Policy for the review checklist.
Third-party links
The website links to services such as Facebook, telephone, and email applications, and may add a client-approved Google Maps link. Following those links transfers the visitor to a separate service governed by that provider's own terms and privacy practices.
The client must confirm every third-party recipient, processor, embedded service, or cross-border transfer used in production before final approval.
Retention
No approved retention period has been provided. The current site does not persist form records in a site database, but any configured receiving service may create records outside the website.
The final policy must state retention and deletion periods for each inquiry, applicant file, email system, backup, security log, and service provider involved.
Security
The current code includes validation, same-origin checks, payload limits, honeypot and timing controls, HTTPS receiver restrictions, and duplicate-submission integration points. These measures do not constitute a claim of legal compliance or complete security.
The client must approve the production access controls, incident process, vendor safeguards, encryption, backup, file scanning, and accountability measures before describing them as final practices.
Data-subject requests
The responsible entity, privacy contact, identity-verification procedure, request channels, response periods, applicable rights, complaint route, and any lawful limitations have not been confirmed.
A qualified legal adviser should approve the rights-request process before it is presented to visitors as operational.
Company contact information
The client must confirm the legal entity responsible for personal information, its relationship to the Siomai House brand, the approved privacy contact or data-protection officer, mailing address, email address, telephone number, and effective date.
The general website contact page remains available for ordinary inquiries, but it is not represented here as the final privacy-request channel.
Contact details pending approval.
The responsible legal entity, privacy contact, mailing address, email address, telephone number, and request-handling process must be confirmed before this draft becomes final.
Use the current contact page