This Privacy Policy explains how Yidefeinuo (Shanghai) Culture Media Co., Ltd. (registered Chinese name: 意德斐诺(上海)文化传媒有限公司), trading as Local Lens China (Local Lens China, we, us or our), collects, uses, stores and shares personal information when you visit https://locallenschina.com, use our itinerary-planning tools, submit a travel enquiry, communicate with us or purchase a travel service (together, the Services).
1. Data controller
The controller responsible for personal information collected independently by Local Lens China is:
- Legal name: Yidefeinuo (Shanghai) Culture Media Co., Ltd. (registered Chinese name: 意德斐诺(上海)文化传媒有限公司)
- Entity and jurisdiction: limited liability company established under the laws of the People's Republic of China
- Registered address: Room 701, Nos. 190 and 200 Haifang Road, Jing'an District, Shanghai, China
- Privacy email: locallenschina@yeah.net
This mailbox is monitored. We aim to acknowledge privacy and support enquiries within 24 hours of receipt. A complete rights request may require the longer response period described in Section 11.
Waffo Pancake acts as an independent controller for payment, billing, tax, fraud, compliance, receipt, refund, chargeback and merchant-of-record transaction data that it collects. Its processing is described in Waffo's Privacy Policy.
2. Personal information we collect
We collect only information reasonably needed for the purposes described below.
2.1 Information you provide
Depending on the feature or Service, this may include:
- Travel enquiries: name, email address or WhatsApp number, preferred contact method and language.
- Trip details: destination, preferred dates, trip length, group size, budget range, interests, service requests, package preference and whether you already have an itinerary.
- Pricing and checkout selections: selected product and package, number of travellers, displayed package price and currency, selected extras and the calculated total before payment.
- Requests and assistance needs: questions and information you choose to provide about dietary, mobility, accessibility or other arrangements. This information may reveal health, religious or other sensitive details. Please provide only what is necessary. Where applicable, we process voluntarily supplied sensitive information with your explicit consent or where needed to arrange a requested Service and permitted by law.
- Booking and fulfilment information: booking reference, selected product and package, traveller names, ages where ticket rules require them, pickup details, language, agreed itinerary and supplier arrangements.
- Identity or travel-document information: only when a named ticket, attraction or other confirmed service requires it. We will request this separately and explain why it is needed. Do not place passport numbers or payment-card security information in an open enquiry field.
- Planner content: planner messages, answers, selected destinations, generated itineraries, itinerary changes and saved-route information.
- Account information: email address, authentication identifiers and account preferences if you create or use an account.
- Communications: emails, WhatsApp messages, support requests, feedback and other information you send us.
2.2 Payment and transaction information
When Waffo Pancake processes a purchase, we may receive transaction and fulfilment information such as the order or payment reference, product, package, displayed or paid amount, currency, payment status, refund status, applicable tax information and fraud or dispute status.
Full payment-card numbers and card security codes are collected by Waffo Pancake and are not stored on Local Lens China servers. Do not send those details to us by email, WhatsApp or an enquiry form.
2.3 Information collected automatically
When you use the Website, we and our infrastructure or analytics providers may process:
- IP address and approximate country or region derived from it;
- browser type, operating system, device category, language and time zone;
- requested pages, timestamps, referring page, navigation, interactions, performance and error information;
- consent state and limited browser or device identifiers where permitted;
- campaign attribution such as source, medium and campaign values; and
- security and fraud-prevention logs.
We sanitise public analytics URLs to avoid sending planner conversations, itineraries, enquiry content, credentials or arbitrary query parameters to analytics providers. We do not intentionally collect precise device geolocation through public-site analytics.
2.4 Information from other parties
We may receive information from:
- Waffo Pancake about orders, payments, refunds or disputes;
- a traveller who books or enquires on behalf of other people;
- travel suppliers where necessary to confirm or deliver a booking;
- authentication, infrastructure, email and security providers; and
- WhatsApp or another communication service when you choose to contact us through that service.
If you provide another person's information, you must have an appropriate reason and authority to do so and must tell them about this Policy where required.
3. How we use personal information and our legal bases
Where GDPR, UK GDPR or a similar law applies, we rely on the following legal bases. Other jurisdictions may describe these grounds differently.
| Purpose | Personal information involved | Legal basis where applicable |
|---|---|---|
| Answer an enquiry and take requested pre-contract steps | Contact and trip details, requests, communications | Steps requested before entering a contract; legitimate interests |
| Display the selected package price and calculate the booking total before checkout | Product, package, traveller count, selected extras, price and currency | Steps requested before entering a contract; contract performance |
| Confirm, deliver and support a booking | Booking, traveller, itinerary and supplier information | Contract performance; legal obligations |
| Process payment, receipts, refunds and disputes | Transaction and limited booking information | Contract performance; legal obligations; legitimate interests |
| Provide planner and saved-itinerary features | Planner content, account or recovery identifiers, email | Contract performance or requested service; legitimate interests |
| Arrange an accessibility, dietary or similar request | Information you voluntarily provide | Explicit consent where required; contract or legal claims where permitted |
| Send essential service messages | Contact, booking, payment and security information | Contract performance; legitimate interests; legal obligations |
| Secure the Services and prevent fraud | Device, network, log, account and transaction information | Legitimate interests; legal obligations |
| Measure and improve public pages | Limited usage, performance and campaign information | Legitimate interests; consent where required |
| Meet tax, accounting, tourism, consumer and regulatory duties | Booking, identity and transaction records | Legal obligations |
| Establish, exercise or defend legal claims | Relevant booking, communication, log and transaction records | Legitimate interests; legal claims |
We do not use personal information for a materially different purpose without providing any notice or obtaining any consent required by law.
4. Payments and Waffo Pancake
Where identified at checkout, Waffo.com Limited and its applicable affiliate (Waffo Pancake) acts as merchant of record and authorised reseller. Waffo may process payment details, billing identity, location, transaction, tax, receipt, fraud, refund, chargeback and compliance information for its own merchant-of-record purposes.
We receive only the transaction and order information reasonably needed to reconcile payment, provide the travel Service, support the traveller and handle a refund or dispute. Waffo's independent handling of personal information is governed by Waffo's Privacy Policy.
5. Cookies, local storage and analytics
The public Website currently uses privacy-limited analytics to understand page usage and reliability. It does not use analytics data to identify the content of planner conversations, itineraries or travel enquiries.
Strictly necessary storage may be used for security, language, authentication, planner continuity, saved-route recovery or another feature specifically requested by the user. The Website currently keeps optional analytics and advertising storage denied by default. If we later offer a way to enable optional storage, we will first provide a clear choice to Reject, Accept or Customize optional categories, make rejecting as easy as accepting, and allow users to reopen the preference control and withdraw consent.
| Tool | Purpose and current configuration | Provider information |
|---|---|---|
| Vercel and Vercel Analytics | Website hosting, delivery, performance, security and limited page analytics. Analytics URLs are sanitised before sending. | Vercel Privacy Notice |
| Google Analytics | Limited page and interaction measurement. Advertising and analytics storage are configured as denied by default; Google may still receive limited consent-mode signals where legally permitted. | Google Privacy Policy |
| Microsoft Clarity | Limited page-usage and usability measurement. Advertising and analytics storage are configured as denied unless a future consent mechanism validly enables them. Planner, itinerary and enquiry areas are intended to be masked. | Microsoft Privacy Statement |
Blocking necessary storage may prevent a requested feature from working. A recorded cookie preference is not consent to marketing, sensitive-information processing or a materially unrelated purpose.
We do not currently use personal information for targeted advertising or sell it for cross-context behavioural advertising. Optional analytics and advertising storage is currently disabled. If we introduce optional storage, we will provide the consent and preference controls described above before enabling it.
6. Automated and AI-assisted processing
Itinerary-planning functions may use automated rules to process planner messages, trip preferences or itinerary content for the requested functionality. We do not currently send traveller planner content to an external artificial-intelligence provider. Automated output may be inaccurate and does not make a legal or similarly significant decision about you.
We do not use traveller content to train our own general-purpose AI model. Before enabling an external artificial-intelligence provider, we will update this Policy to identify the provider and explain the relevant information, purpose, location and safeguards.
Please do not submit passport numbers, payment-card details, medical records or other unnecessary sensitive information to an AI-assisted planner.
7. How we share personal information
We do not sell personal information. We share it only as reasonably necessary for the purposes in this Policy:
- Payment and merchant of record: Waffo Pancake for checkout, billing, tax, receipts, fraud review, refunds and disputes.
- Database and authentication: Supabase for protected application data, accounts and server-side storage.
- Hosting and delivery: Vercel for hosting, network delivery, runtime logs and analytics.
- Email delivery: Resend for requested route emails, acknowledgements and service communications.
- Analytics: Google and Microsoft as described in Section 5.
- Travel fulfilment: the guide, driver, attraction, ticketing provider, clothing-rental studio, photographer or other supplier that needs limited information to confirm or provide the selected Service. We disclose the responsible supplier where required and do not give suppliers unrelated enquiry information.
- Communications: WhatsApp/Meta or another service when you choose that channel; its own privacy terms also apply.
- Professional advisers and authorities: lawyers, accountants, insurers, regulators, courts, law enforcement or consumer/tourism authorities where necessary and lawful.
- Business transaction: a purchaser or successor in a merger, reorganisation or sale, subject to appropriate notice and continued protection.
- With your direction or consent: for another clearly explained purpose you choose.
Service providers may process information only for the contracted purpose, subject to their agreements and applicable law.
8. International transfers
Local Lens China serves international travellers. Information may therefore be processed outside the traveller's country, including in China where local travel suppliers provide a confirmed Service and in countries or regions where our hosting, database, communications, analytics or payment providers operate. Payment information may also pass from the payment provider to card networks, banks or fraud-prevention services in other countries or regions.
We disclose only the information reasonably needed for the relevant purpose. Where a cross-border transfer is subject to the Personal Information Protection Law of the People's Republic of China or another applicable law, we will complete any required personal-information protection impact assessment, use an applicable standard contract or other lawful transfer mechanism, and obtain separate consent where required. We will not claim that a particular safeguard applies unless the required agreement or legal basis is in place.
You may contact us for information about safeguards relevant to your information.
9. Retention
We retain personal information only for the period needed for the stated purpose, legal obligations, disputes and security. Our retention schedule is:
| Record | Retention period |
|---|---|
| General customer and travel information, including enquiries, booking details, travel-document copies and service communications | 3 years after the trip ends or, if no booking is made, 3 years after the last substantive interaction; then delete or anonymise unless needed for an unresolved dispute, claim or longer legal duty |
| Financial, invoice, refund, dispute, tax and accounting records | For the period required by applicable accounting, tax, payment and other laws, which may be longer than 3 years |
| Anonymous planner session and messages | 7 days from creation unless converted to an account-owned session or another saved feature |
| Emailed private itinerary | 7 days if the private link is not verified; up to 180 days after verification, unless deleted earlier |
| Account-owned planner content | While the account is active, then delete or anonymise within 30 days after a valid deletion request or account closure, subject to required records |
| Public content-attribution events | 90 days, then delete or aggregate |
| Security and application logs controlled by us | 90 days unless needed for an active security investigation or legal obligation |
| Backups containing deleted records | Isolated from normal use and removed according to the applicable provider's secure backup lifecycle, unless lawfully preserved for an active incident, dispute or legal obligation |
Payment providers and other independent controllers keep their records according to their own policies and legal duties. Aggregated or irreversibly anonymised information may be retained longer because it no longer identifies an individual.
10. Security
We use measures designed to protect personal information, including HTTPS encryption in transit, access controls, restricted server-side credentials, rate limits, input validation, database row-level security where applicable, minimised payment records and separation between public and administrative systems.
No internet transmission or storage method is completely secure. If a personal-data breach is likely to risk your rights, we will notify affected people and relevant authorities without undue delay and within any legally required period, including 72 hours where that specific legal requirement applies.
Please protect private itinerary links and account credentials. Contact us promptly if you believe information or an account has been accessed without authority.
11. Your choices and rights
Depending on your location, you may have the right to:
- know whether and how we process your personal information;
- request access to or a copy of it;
- correct inaccurate or incomplete information;
- request deletion;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent without affecting earlier lawful processing;
- opt out of marketing;
- appeal a decision where applicable; and
- complain to your local data-protection authority.
To make a request, email locallenschina@yeah.net with “Privacy Request” in the subject. We may request proportionate information to verify identity and protect other people. We aim to acknowledge the request within 24 hours and to provide the substantive response within 30 calendar days, or within another period required by applicable law. Some information may be retained where law permits or requires it, including for tax, fraud prevention or legal claims.
You may also use browser controls to limit cookies or storage. Consent can be withdrawn as easily as it was given once an optional consent control is offered.
12. Marketing
An enquiry, booking, receipt, private-itinerary email, safety message, policy notice or direct response is a service communication, not consent to marketing.
We do not currently send promotional email, SMS or WhatsApp marketing. If we introduce promotional marketing, we will first obtain any consent required by applicable law and include an unsubscribe method in every promotional email. You may also opt out by emailing locallenschina@yeah.net. Opting out of marketing does not stop essential booking, payment, security or legal messages.
We do not use enquiry contact details, saved-itinerary emails or support details for unrelated cold outreach.
13. Children
Only a person aged 18 or older may create a paid booking or submit an independent travel-service order. A child may participate only through a booking made and supervised by an appropriate adult.
Where the Personal Information Protection Law of the People's Republic of China applies, personal information of a child under 14 is treated as sensitive personal information. We will process it only for a specific and necessary travel purpose, with the consent of a parent or other guardian and any separate consent required by law. The 14-year threshold concerns special privacy protection; it does not allow a person under 18 to make an independent paid booking.
Before collecting personal information about a child under 14, we will provide the parent or guardian with a dedicated notice, obtain any consent required by applicable law and specify an appropriate collection method. We will not request such information through a general enquiry field or an AI-assisted planner. If these safeguards are not available for a particular booking, we will not collect or process the child's personal information.
We collect a child's name, age or travel-document details only when reasonably required for a confirmed ticket, supplier rule, safety arrangement or legal obligation. We will explain the purpose, recipient and relevant retention before requesting unusually sensitive information, and the booking adult must be authorised to provide it. A guardian's permission for one booking is not permission to use the child's information for another purpose.
Children's information is shared only with the supplier or authority that needs it to provide the confirmed Service or meet a legal requirement, and is retained no longer than the applicable booking or legally required record. We do not knowingly use children's information for marketing, profiling or behavioural advertising. Do not send a child's passport number or document image through a general enquiry or AI-assisted planner; wait for a specific, secure request connected with a confirmed booking.
If you believe a child submitted personal information without appropriate authority, contact us so we can review and delete it where required.
14. Third-party links and services
The Website links to attractions, transport providers, social platforms and other third-party services. Their privacy practices are governed by their own policies. Opening a third-party link does not authorise us to receive information from that party unless separately explained.
15. Changes to this Policy
We may update this Policy to reflect changes in law, providers or our Services. We will post the new “Last updated” and effective dates. For a material change, we will provide reasonable advance notice through the Website, email or an in-product notice where required. A new purpose requiring consent will not apply until the necessary consent is obtained.
16. Contact us
For privacy questions or rights requests:
- Privacy email: locallenschina@yeah.net
- Support email: locallenschina@yeah.net
- Legal entity: Yidefeinuo (Shanghai) Culture Media Co., Ltd. (registered Chinese name: 意德斐诺(上海)文化传媒有限公司)
- Registered address: Room 701, Nos. 190 and 200 Haifang Road, Jing'an District, Shanghai, China
- Website: https://locallenschina.com
Version: 1.0
Last updated: 7 September 2026
Effective date: 7 September 2026