HaiToken Cookie Policy
Last Updated: 2026-07-26 Effective Date: 2026-07-26 Website / Service: haitoken.ai Operator: LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司 Version Status: Published Version
Reading Guide
Please pay particular attention to the bold headings and the numbered clauses. This Cookie Policy explains how HaiToken uses cookies and similar technologies in its online Services. Section 4 contains a table of the cookie types we may use and whether each is currently deployed. Section 6 contains our current cookie inventory. As of the effective date, HaiToken uses only strictly necessary cookies, first-party security cookies, functionality cookies and third-party payment cookies. If the English and Chinese texts differ, the English text prevails.
Language
This Cookie Policy is prepared in English and Chinese. Both texts are intended to have legal effect. If there is any inconsistency, ambiguity or conflict between the English text and the Chinese text, the English text prevails, unless HaiToken expressly states otherwise in writing.
1. Introduction
HaiToken is a product operated by LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司, a company incorporated in Hong Kong ("HaiToken", "we", "us"). This Cookie Policy explains how we use cookies and similar technologies in connection with the HaiToken website, console, documentation, authentication flows, billing pages, support pages, marketing pages and related browser-side services (the "online Services").
This Cookie Policy is governed by the laws of the Hong Kong Special Administrative Region. We process personal data in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and our Privacy Policy. Any dispute relating to this Cookie Policy is subject to the governing-law and dispute-resolution provisions of our Service Agreement (see Section 22 of the Service Agreement).
This Cookie Policy should be read together with the HaiToken Privacy Policy, the Service Agreement (including its Acceptable Use terms) and, where applicable, the Data Processing Agreement ("DPA"). Capitalized terms not defined in this Cookie Policy have the meanings given in those documents.
This Cookie Policy focuses on cookies and similar technologies that store information on, or access information from, a user's browser or device. For API logs, Customer API Data, Service Metadata, security records, abuse-investigation records or evidence preservation, this policy does not replace the Privacy Policy or the Service Agreement.
2. What Are Cookies and Similar Technologies?
Cookies are small text files placed on your browser or device when you visit a website or use an online service. Cookies can help the Services remember your session, login status, language, region, preferences, security settings or prior actions.
Similar technologies may include pixels, web beacons, tags, scripts, local storage, session storage, software development kits, device or browser signals, and other technologies that store information on, or access information from, your browser or device.
In this Cookie Policy, unless the context requires otherwise, "cookies" includes cookies and similar technologies.
3. How We Use Cookies
We use cookies for the following purposes:
- Strictly necessary operation: to provide the online Services, keep you logged in, maintain sessions, remember cookie choices, route traffic, load-balance, prevent duplicate submissions, and operate account or console features.
- Security, anti-fraud and abuse detection: to protect accounts, API Keys, sessions and the Services; to detect suspicious logins, credential abuse, malicious automation, scraping, abnormally high-frequency requests, fraud, payment abuse, unauthorized access, and violations of the Service Agreement (including its Acceptable Use terms).
- Preferences and functionality: to remember language, region, theme, console layout, documentation preferences and other choices.
- Payment and billing: to support checkout, payment security and billing flows, including cookies set by our third-party payment service providers.
- Consent management: to remember your cookie choices and maintain a record of consent or opt-out preferences.
As of the effective date, we do not deploy performance/analytics cookies or marketing/advertising cookies, and we do not use third-party analytics, advertising, bot-management or customer-chat providers that set cookies. If we introduce such cookies in the future, we will update this Cookie Policy and, where required by applicable law, obtain your consent before setting non-essential cookies.
We do not intentionally store prompt bodies, completion bodies, uploaded files or API request/response content in cookies. The processing of Customer API Data, Service Metadata and security or enforcement records is described in the Privacy Policy, the Service Agreement and the DPA.
4. Types of Cookies We May Use
| Type | Purpose | Can it be turned off in our cookie-preference tool? | Currently used? |
|---|---|---|---|
| Strictly necessary cookies | Necessary to provide the online Services, authenticate users, maintain sessions, process security choices, remember cookie preferences, route traffic and operate core console features. | No. These cookies are necessary for the online Services to function. You may block them via your browser, but some features may not work. | Yes |
| Security and abuse-prevention cookies | First-party cookies used to protect accounts, prevent cross-site request forgery, detect suspicious activity, and support enforcement of our Service Agreement (including its Acceptable Use terms). | Generally cannot be turned off in the preference tool where necessary for security or Service integrity. | Yes (first-party only) |
| Functionality cookies | Used to remember user choices such as language, region, theme, layout or documentation settings. | Can be turned off where not strictly necessary. | Yes |
| Payment and billing cookies | Set by our third-party payment service providers to support checkout, payment security and anti-fraud during billing flows. | Necessary for checkout and payment security. | Yes (at checkout) |
| Performance and analytics cookies | If enabled, used to measure website and console usage, identify errors, and improve reliability and product design. | Can be turned off where required by law or where our consent settings apply. | No — not currently deployed |
| Marketing and advertising cookies | If enabled, used to measure lawful marketing campaigns, referrals and attribution. | Can be turned off. We will not use such cookies unless permitted by law and, where required, with your consent. | No — not currently deployed |
As of the effective date, HaiToken uses only strictly necessary cookies, first-party security cookies, functionality cookies and third-party payment cookies. We do not currently deploy analytics, marketing, advertising, third-party bot-management/security or customer-chat cookies. This table describes the types we may use; if we begin using any type not currently used, we will update this Cookie Policy and obtain consent where required.
5. Security, Abuse Prevention and Evidence Preservation
HaiToken provides AI gateway, routing, billing and enterprise-administration services. Because misuse of AI services can create serious legal, security, payment and upstream model-provider risks, we may use strictly necessary first-party cookies and similar technologies to help protect the Services and investigate suspected abuse. For example, they can help us authenticate users and protect sessions; detect account takeover, credential compromise or unauthorized console access; identify suspicious logins or request patterns; reduce fraud, chargebacks and payment abuse; and support rate limiting, security challenges and access control.
Cookies are only one part of these processes. HaiToken may also generate and retain Service Metadata, API logs, security records, billing records, investigation records and other evidence as described in the Privacy Policy and Service Agreement. Detailed rules on prohibited conduct and enforcement are set out in the Acceptable Use terms and other enforcement provisions of the Service Agreement. In the event of a suspected violation, dispute, chargeback, security incident, Provider request, legal process or enforcement matter, HaiToken may, subject to applicable law (including the PDPO), preserve relevant records for as long as reasonably necessary for investigation, enforcement, dispute resolution, legal hold, regulatory response or applicable limitation periods.
6. Cookie Inventory
The following table reflects HaiToken's current deployment as of the effective date. As the Services evolve, the cookies we use may change; this inventory should be re-verified through a technical cookie scan whenever the deployment changes and before each external release.
| Cookie or technology | Provider | Type | Purpose | Typical duration |
|---|---|---|---|---|
| haitoken_session | HaiToken (first-party) | Strictly necessary | Maintain an authenticated console session and account access. | Session or a short fixed period |
| csrf_token or equivalent | HaiToken (first-party) | Strictly necessary / security | Help prevent cross-site request forgery and unauthorized form submissions. | Session |
| haitoken_cookie_consent | HaiToken (first-party) | Strictly necessary / consent management | Store your cookie consent or opt-out preferences. | 6 to 12 months, or as configured |
| haitoken_region or equivalent | HaiToken (first-party) | Functionality | Remember region, language or interface preferences. | Up to 12 months |
| Payment / billing cookies | Third-party payment service providers used by the current checkout flow | Strictly necessary / functionality | Support checkout, payment security, anti-fraud and billing flows during payment. | As disclosed by the payment service provider and payment flow |
As of the effective date, HaiToken deploys only the first-party cookies listed above and the cookies set by the third-party payment service providers used by the checkout flow. We do not currently deploy analytics, marketing/advertising, third-party bot-management/security or customer-chat cookies. HaiToken should re-verify this inventory through a technical cookie scan and vendor review whenever the deployment changes and before any material external update.
7. Third-Party Cookies and Vendors
As of the effective date, third-party cookies are limited to those set by our third-party payment service providers at checkout and, where applicable, those set by our hosting or infrastructure providers. We do not currently use third-party analytics, advertising, bot-management or customer-support vendors that set cookies on the online Services.
Where third-party vendors are used, they may process information under their own privacy and cookie policies. HaiToken does not control all third-party cookie practices. We take reasonable measures to select vendors appropriate for the Services and contractual needs, but where applicable you should also review the relevant third-party policies. If we add vendors that set cookies (for example, analytics, support or marketing tools), we will update this Cookie Policy accordingly.
8. Your Cookie Choices
Where required by applicable law, we will obtain your consent before setting non-essential cookies. Where the law requires express consent, that consent must be given through a clear affirmative action; in such cases, continued browsing alone will not be treated as consent. You can manage cookie choices through your browser settings and, where available, through account settings or any cookie-preference tool we provide. If we deploy non-essential cookies that require consent, we will provide an appropriate consent mechanism at that time, such as a cookie banner or preference center, and, where required by law, allow you to enable or disable non-essential cookie types.
Most browsers allow you to block or delete cookies, or to receive an alert when cookies are set. If you block or delete cookies, some parts of the online Services may not work properly. For example, you may be unable to log in, maintain a secure session, use console features, complete billing steps or save preferences.
Strictly necessary cookies, including those required for authentication, security, anti-fraud, consent management, Service integrity, load balancing and core console functions, may not be able to be turned off through our cookie-preference tool.
9. Regional Choices: PDPO, Do Not Track and Global Privacy Control
We process personal data collected through cookies in accordance with the PDPO and our Privacy Policy. Under the PDPO, you may have the right to access and correct personal data and to make privacy-related requests; the Privacy Policy explains how to exercise these rights.
Some browsers or extensions may send "Do Not Track" or "Global Privacy Control" signals. Because "Do Not Track" is not a uniform legal standard, we respond as required by applicable law. Where applicable law requires recognition of available opt-out preference signals (including Global Privacy Control), if HaiToken engages in any sale, sharing, targeted advertising or similar processing, HaiToken will honor such signals. As of the effective date, HaiToken does not sell or share personal data for cross-context behavioral advertising.
10. Who the Services Are For
The Services are offered to non-mainland-China individual Customers, enterprise Customers, developers and organizations. Individual Customers must be at least 18 years of age. The Services are not directed to Child Customers, and we do not knowingly use cookies to profile, target or market to Children.
For how HaiToken processes personal information and privacy matters relating to minors or Children, please see our Privacy Policy.
11. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes to the Services, vendors, cookies, technologies, legal requirements or business practices. We will indicate the update date and may provide additional notice of material changes via the website, console, email or a cookie banner.
Continued use of the online Services after the effective date of the updated Cookie Policy means the updated Cookie Policy applies to future use of cookies and similar technologies.
12. Contact Us
For privacy or cookie-related questions, requests, complaints or concerns, please contact:
LDCY TECH HK LIMITED / 香港靈動創意科技資訊有限公司 Product: HaiToken Website: haitoken.ai Email: privacy@haitoken.ai