私隱政策

PRIVACY POLICY

MOCAR BEAUTY 私隱政策

This policy sets out: 

  1. the information we collect about you when you visit our website, use our products or services, or otherwise interact with us;
  2. how we use, share, store, and secure the information; and
  3. how you may access and control the information. 

In this policy, “MOCAR BEAUTY” or “we” refers to MOCAR  “

In this policy, “personal information” refers to any data, information, or combination of data and information that is provided by you to us, or through your use of our products or services, that relates to an identifiable individual.

  1. What information we collect about you 
    1. We collect the following types of information about you:
      1. account and profile information that you provide when you register for an account or sign up for our products or services, for example Name, email addresses, phone numbers, addresses (collectively, “Account Data”);
      2. information you provide through support channels, for example when you report a problem to us or interact with our support team, including any contact information, documentation, or screenshots (collectively, “Support Data”);
      3. content you provide through use of our products or services, for example Store and product information by merchants; Product reviews and ratings from customers (collectively, “User Content”);
      4. communication, marketing, and other preferences that you set when you set up your account or profile, or when you participate in a survey or a questionnaire that we send you (collectively, “Preference Data”); 
      5. information about your device or connection, for example your internet protocol (IP) address, log-in data, browser type and version, time-zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our products or services and information we collect through cookies and other data collection technologies (please read our Cookies Policy for details) (collectively, “Technical Data”); and
      6. Information about your use of or visit to our Platform, for example your clickstream to, through, and from our Platform, products you viewed, used, or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods to browse away from the page (collectively, “Usage Data”).
    2. We collect the above information when you provide it to us or when you use or visit our Platform. We may also receive information about you from other sources, including:
      1. our personnel, agents, advisors, consultants, and contractors based in Hong Kong, Taiwan, Malaysia in connection with our operations or services, for example our staff engaged in the fulfilment of your order, processing of your payment, and provision of support services;
      2. other services linked to your account, for example if you register or log in your account using your Facebook credentials, we receive your name, your profile picture, your mobile phone number and email address to authenticate you, as permitted by your Facebook profile settings;
      3. our business partners and service providers based in Hong Kong, Taiwan, Malaysia who provide reselling and customer support services in Hong Kong, Taiwan and Malaysia, and analytics applications.
    3. We do not collect sensitive data or special category data about you. This includes details about your race, ethnic origin, politics, religion, trade union membership, genetics, biometrics, health, or sexual orientation.
  2. How we use information we collect
    1. We only use your personal information where the law allows us to. We use your personal information only where:
      1. we need to perform the contract we have entered into (or are about to enter into) with you, including to operate our products or services, to provide customer support and personalised features, and to protect the safety and security of our Platform;
      2. it satisfies a legitimate interest which is not overridden by your fundamental rights or data protection interests, for example for research and development, and in order to protect our legal rights and interests
      3. you've given us consent to do so for a specific purpose, for example we may send you direct marketing materials or publish your information as part of our testimonials or customer stories to promote our products or services with your permission; or
      4. we need to comply with a legal or regulatory obligation.
    2. If you have given us consent to use your personal information for a specific purpose, you have the right to withdraw your consent any time by contacting us (please refer to paragraph 8 for contact information), but please note this will not affect any use of your information that has already taken place.
    3. We do not share your personal information with any company outside our group for marketing purpose, unless with your express specific consent to do so.
    4. For visitors to or users of our Platform who are located in the European Union, we have set out our legal bases for processing your information in the Legal Bases Table at the end of this policy.
  3. How we share information we collect
    1. We may share personal information on aggregated or de-identified basis with third parties for research and analysis, profiling, and similar purposes to help us improve our products and services.
    2. If you use any third-party software in connection with our products or services, for example any third-party software that our Platform integrates with, you might give the third-party software provider access to your account and information. Policies and procedures of third-party software providers are not controlled by us, and this policy does not cover how your information is collected or used by third-party software providers. We encourage you to review the privacy policies of third-party software providers before you use the third-party software.
    3. Our Platform may contain links to third-party websites over which we have no control. If you follow a link to any of these websites or submit information to them, your information will be governed by their policies. We encourage you to review the privacy policies of third-party websites before you submit information to them.
    4. We may share your information with government and law enforcement officials to comply with applicable laws or regulations, for example when we respond to claims, legal processes, law enforcement, or national security requests. 
    5. If we are acquired by a third party as a result of a merger, acquisition, or business transfer, your personal information may be disclosed and/or transferred to a third party in connection with such transaction. We will notify you if such transaction takes place and inform you of any choices you may have regarding your information. 
  4. How we store and secure information we collect
    1. We use Google Cloud data hosting service based in United States to host the information we collect.
    2. We have adopted the following measures to protect the security and integrity of your personal information:
      1. information is encrypted using TLS/SSL technology;
      2. your account is password-protected;
      3. access to your personal information is restricted to personnel or service providers on a strictly need-to-know basis, who will only process your information on our instructions and who are subject to a duty of confidentiality; and
      4. our information collection, storage, and processing practices are reviewed regularly. 
    3. We have put in place procedures to deal with any suspected privacy breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
    4. While we implement safeguards designed to protect your information, please note that no transmission of information on the Internet is completely secure. We cannot guarantee that your information, during transmission through the Internet or while stored on our systems or processed by us, is absolutely safe and secure.
    5. We only retain personal information for so long as it is reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. 
      Merchants may copy and store customer’s information out of our system which cannot be controlled by us. You as customers should check with respective Merchant’s privacy policy.
  5. Your rights
    1. You have the right to:
      1. be informed of what we do with your personal information;
      2. request a copy of personal information we hold about you; 
      3. require us to correct any inaccuracy or error in any personal information we hold about you;
      4. request erasure of your personal information (note, however, that we may not always be able to comply with your request of erasure for record keeping purposes, to complete transactions, or to comply with our legal obligations);
      5. object to or restrict the processing by us of your personal information (including for marketing purposes);
      6. request to receive some of your personal information in a structured, commonly used, and machine readable format, and request that we transfer such information to another party; and
      7. withdraw your consent at any time where we are relying on consent to process your personal information (although this will not affect the lawfulness of any processing carried out before you withdraw your consent).  
    2. You may opt out of receiving marketing materials from us by using the unsubscribe links in our communications, or by contacting us. Please note, however, that even if you opt out from receiving marketing materials from us, you will continue to receive notifications or information from us that are necessary for the use of our products or services.
    3. As a security measure, we may need specific information from you to help us confirm your identity when processing your privacy requests or when you exercise your rights. 
    4. Any request under paragraph 5.1 will normally be addressed free of charge. However, we may charge a reasonable administration fee if your request is clearly unfounded, repetitive, or excessive.
    5. We will respond to all legitimate requests within one (1) month.  Occasionally, it may take us longer than a month if your request is particularly complex or if you have made a number of requests.
  6. Changes to this policy
    1. We may amend this policy from time to time by posting the updated policy on our Platform. By continuing to use our Platform after the changes come into effect, you agree to be bound by the revised policy.
  7. Policy towards children
    1. Our products and services are not directed to individuals under 16. We do not knowingly collect personal information from individuals under 16. If we become aware that an individual under 16 has provided us with personal information, we will take steps to delete such information. Contact us if you believe that we have mistakenly or unintentionally collected information from an individual under 16.
  8. Contact us
    1. Please contact us at Mocar16888@gmail.com  submit any written request to:
    2. MOCAR

Attn: Chief Executive Officer

    1. Please contact us in the first instance if you have any questions or concerns. If you have unresolved concerns, you have the right to file a complaint with a data protection authority in the country where you live or work or where you feel your rights have been infringed.

Last updated: 27 June 2023

 

COOKIES POLICY

Cookies are small text files that are placed on your device by a web server when you access our Platform. We use cookies to identify your access and monitor usage and web traffic on our Platform to customise and improve our products and services.

We use both persistent cookies and session cookies. A persistent cookie stays in your browser and will be read by us when you return to our Site or a partner site that uses our services. Session cookies only last for as long as the session lasts (usually the current visit to a website or a browser session).

We use the following types of cookies: 

      1. Strictly necessary cookies – these are cookies that are required for the operation of our site. They include, for example, cookies that enable you to log into secure areas of our website.
      2. Analytical/performance cookies – these allow us to recognise and count the number of visitors and to see how visitors move around our Site when they are using it. This helps us to improve the way our site works, for example, by ensuring that users are easily finding what they are looking for.
      3. Functionality cookies – these are used to recognise you when you return to our site.
      4. Targeting cookies – these cookies record your visit to our site, the pages you have visited, and the links you have followed.

You can block cookies by activating the setting on your browser that allows you to refuse the use of all or some cookies. However, if you do so, you may not be able to access all or parts of our site.

 

TRUEDEPTH CAMERA

We use TrueDepth technologies with our camera SDK to provide real-time face filters within the App. From time to time, we may use information from Apple’s TrueDepth camera to improve the quality of lenses. None of the information collected by the TrueDepth ever leaves the user’s device. Information from TrueDepth camera is used in real time - this information is not stored in our servers or shared with third parties. For more information about TrueDepth technologies, you may visit https://support.apple.com/en-us/HT208108.

 

LEGAL BASES TABLE

Processing purpose

Type of data processed

Legal basis

To register you (Merchant) as a user on our Platform

Account Data

To perform our contract with you (Merchant)

To register you (Customer) as a user on our Platform for the Merchant

Account Data

To perform the Merchant's sale contract with you (Customer)

To enable you (Merchant) to use our products and services

Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content

To perform our contract with you (Merchant)

To enable you (Customer) to use our products and services  to purchase at Merchant’s website

Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content

To perform the merchant's sales contract with you (Customer) 

To study usage of our products and services

Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content

Legitimate interest to improve our Platform, products, and services

To notify you (Merchant) about changes to our products, services or terms

Account Data

To perform our contract with you

To notify you (Customer) about changes to the our and the Merchant's products, services or terms

Account Data

To perform the merchant's contract with you

To provide information on products or services that may be of interest to you (Merchant)

Account Data, Preference Data

Consent, which you may withdraw any time

To provide information on products or services from Merchants that may be of interest to you (Customer)

Account Data, Preference Data, Usage Data

Consent, which you may withdraw any time

To gather feedback on our products, services, or features

Account Data, Usage Data

Legitimate interest to improve our Platform, products, and services

To administer and maintain safety and security of our Platform

Technical Data

To perform our contract with you

This translation is provided for your convenience only. Each party agrees that the agreement is entered into in the English language. In the event of an inconsistency between the translation and the English version, the English version shall prevail.

本政策列明: 

  1. 我們於閣下瀏覽我們的網站、使用我們的產品或服務,或以其他任何方式與我們互動時,所收集的資料;
  2. 我們如何運用、分享、儲存有關資料及相關的保密措施;以及
  3. 閣下如何閱覽及控制有關資料。 

本私隱政策中,「MOCAR BAEUTY」或「我們」意指 MOCAR無限公司,「平台」則指我們的網站 mocarcosmetic.myshopify.com 

本政策中,「個人資料」意指任何閣下向我們,或透過使用我們的產品或服務時,向我們提供關於具有身分的人士的任何數據、資料或上述兩項給合而成的數據與資料。

  1. 我們向閣下收集的資料 
    1. 我們將向閣下收集以下類型的資料:
      1. 閣下登記帳戶或註冊使用我們的產品或服務時提供的帳戶及個人檔案資料,例如姓名、電郵地址、電話號碼及通訊地址等(通稱「帳戶資料」)
      2. 閣下透過用戶支援渠道提供的資料,例如向我們報告系統問題,或與我們的用戶支援部溝通時,提供的任何聯絡資料、文件或截圖(通稱「支援資料」);
      3. 閣下於使用我們產品或服務時提供的內容,例如商戶提供的店舖及產品資料,以及顧客提供的產品評價評分等(通稱「用戶內容」);
      4. 閣下設定帳戶或個人檔案時選擇的通訊、推廣及其他喜好設定,或閣下於我們發送的問卷調查中填寫的資料(通稱「喜好資料」); 
      5. 閣下的裝置或網絡資料,例如網際協定(IP)地址、登入資料、瀏覽器樣式及版本、時區設定、瀏覽器插件種類及版本、操作系統及平台、閣下裝置上用作閱覽我們產品或服務的其他技術,以及我們透過記憶體cookie及其他資料收集技術(詳情請參閱我們的Cookie政策)收集的資料(通稱「技術資料」);以及
      6. 閣下於我們平台上的使用及瀏覽資料,例如前往、瀏覽及離開我們平台時的點擊流、瀏覽、使用或搜尋過的內容、頁面響應使間、下載錯誤、個別頁面的瀏覽時間、頁面互動資料(例如使用時的上下捲動、點擊及鼠標移動)或離開頁面方法等(通稱「使用資料」)。
    2. 我們於閣下使用或瀏覽我們的平台時收集上述資料。此外,我們亦可能會於其他來源取得閣下的資料,包括:
      1. 與我們的服務或營運有聯繫的香港、台灣及馬來西亞員工、經紀、顧問及承包商等,例如跟進閣下訂單、處理付款流程以及提供支援服務的員工;
      2. 其他有關閣下帳戶的服務,例如透過Facebook登入的話,根據閣下Facebook個人檔案設定的批准權限,我們將獲取閣下姓名、頭像、流動電話號碼以及電郵地址作核實身分之用;
      3. 我們的業務伙伴及服務供應商——其總部設於香港、台灣及馬來西亞,為香港、台灣及馬來西亞地區提供轉售及顧客支援服務,以及分析應用程式。
    3. 我們不會向閣下收取敏感或特殊種類的資料,包括閣下的種族、政治立場、宗教、工會身份、遺傳資料、生物識別資料、健康狀態或性向等。
  2. 收集資料使用方式
    1. 我們只會於法律許可的情況,以及下列情況下使用閣下的個人資料:
      1. 我們需要行使我們跟閣下達成(或即將達成)的協議,包括營運我們的產品或服務、提供客戶支援服務及個人化功能,以及保障我們平台的安全;
      2. 有關資料符合合法利益,例如用作產品或服務開發,或保障我們的法律權益,惟此合法利益並不凌駕閣下的根本權利或資料保障權益;
      3. 閣下已准許我們於特定情況下使用有關資料,例如我們或會直接向閣下發送推廣資訊,或發佈閣下的資料用作服務認可或客戶成功故事,在閣下允許的前提下作推廣我們的產品或服務之用;或
      4. 我們需要遵從適用的法律或監管法規。
    2. 如閣下曾准許我們於指定情況下使用有關的個人資料,閣下有權於任何時間聯絡我們(請參閱第8段)去撤回許可,但此將不會對任何已使用的資料構成任何影響,敬希垂注。
    3. 除非閣下特意准許,我們不會與任何我們集團外的公司分享閣下的個人資料作推廣用途。
    4. 於歐盟國家的平台瀏覽及使用者可參閱本政策末段的法律基礎表,以了解我們處理閣下資料的法律基礎。
  3. 資料分享方式
    1. 我們或會與第三方分享不留名的綜合個人資料,用作研究、分析、歸納,以及類似用途,以改善我們的產品及服務。
    2. 如閣下使用與我們產品或服務有關聯的第三方軟件,例如任何我們平台併合的第三方軟件,該第三方軟件供應商或具有閣下帳戶及資料的閱覽權。我們並無控制第三方軟件供應商的政策及處理手法,而本政策亦不涵蓋第三方軟件供應商如何收集及使用閣下的資料。我們鼓勵閣下於使用第三方軟件前,檢視第三方軟件供應商的私隱政策。
    3. 我們的平台或具有第三方網站的連結,而我們無法控制第三方網站。如閣下透過任何此類連結進入第三方網站,或向第三方網站遞交資料,閣下的資料將由第三方網站支配。我們建議閣下於遞交資料予第三方網站前,檢視其私隱政策。
    4. 為遵守適用的法律或法規,我們或會與政府或執法機構人員分享閣下的資料。具體例子包括回應索賠申請、法律程序、執法過程或國家安全要求等。 
    5. 如我們因合併、收購或業務轉移由第三方接管,閣下的個人資料或會披露/轉移予參與有關交易的第三方。如有此類交易發生,我們將通知閣下,並告知閣下就個人資料具有的任何選擇權。 
  4. 收集資料儲藏及保密方式
    1. 我們使用Google Cloud資料寄存服務寄存我們收集的資料,其總部設於美國。
    2. 我們採用下列措施去保障閣下個人資料的安全及真確性:
      1. 資料經TLS/SSL技術加密;
      2. 閣下的帳戶受密碼保護;
      3. 我們嚴格遵從「需要知道」的原則,限制任何人士或服務供應商閱覽閣下的個人資料,而有關人士只會根據我們的指引及合約保密義務去處理閣下的個人資料;以及
      4. 我們會定期檢討資料收集、儲藏及處理手法。  
    3. 就任何懷疑私隱泄露的情況,我們已訂立完善的處理機制,並會適時通知閣下及任何適用的監管機構,確保符合法律要求。
    4. 我們會盡力採用安全措施去保障閣下的資料,但透過互聯網傳輸資料並非絕對安全。我們無法擔保閣下的資料於互聯網傳輸時、存放於我們的系統時,以及我們處理有關資料時,能夠絕對安全及保密,敬希垂注。
    5. 我們保留個人資料的時間,根據達到收集目的之所需時間而定,包括滿足任何法律、會計或匯報要求。
      商戶或複製及儲藏顧客資料於我們系統以外的地方,我們無法控制其處理相關資料的方式。閣下作為顧客,應與相應商戶查詢個別私穩政策。
  5. 閣下的權利
    1. 閣下有權:
      1. 知道我們對閣下個人資料的處理方式;;
      2. 要求取得閣下於我們系統中的個人資料之副本; 
      3. 要求我們變更任何關於閣下不準確或錯誤的個人資料;
      4. 要求我們清除閣下的個人資料(我們或不能恆常地遵從閣下清除紀錄的要求,原因包括內部紀錄需要,用作完成交易,或遵從我們的法律義務等,敬希垂注);
      5. 反對或限制我們處理閣下的個人資料(包括作市場推廣用途);
      6. 要求接收閣下部分的個人資料,而資料格式應條理分明、普及使用,以及可經電腦處理;閣下亦有權要求我們轉移上述資料至另一方;以及
      7. 隨時撤回閣下對我們處理閣下個人資料的許可(然而,閣下撤回許可前已進行的資料處理之合法性將不受此權利影響)。  
    2. 閣下可選擇不接收市場推廣資訊,方式包括透過點擊我們通訊時提供的取消訂閱連結、更新帳戶喜好設定,或與我們聯絡。然而,即使閣下選擇不接收我們的市場推廣資訊,仍將會收到關於使用我們產品或服務的需知訊息。
    3. 為保安理由,閣下處理或更改私隱設定或行使相關權利時,我們或需索取閣下特定的資料用作核實身份。  
    4. 在一般情況下,任何條款5.1列明的要求均屬免費。然而,如閣下的要求並無根據、屬重覆或過量,我們或會收取合理的行政費用。
    5. 我們會於一個月內回應所有合法合理的請求。如閣下的請求比較複雜,或閣下提出超過一項請求,我們則有可能需要較長時間,或超過一個月去處理。
  6. 本政策之變更
    1. 我們或會適時更改本政策,並把最新的版本於我們的平台發佈。於政策變更後繼續使用我們的平台,即意味閣下同意受已更改的政策約束。
  7. 針對兒童的政策
    1. 我們的產品及服務非為16歲以下人士而設。我們不會於知情的情況下向16歲以下人士收集個人資料。在我們知情的情況下,如有16歲以下人士向我們提供個人資料,我們將把有關資料刪除。如閣下相信我們誤用了任何16歲以下人士的資料,請聯絡我們。
  8. 語言
    1. 如使用條款的中英文版本有歧義,將以英文版本為準。
  9. 聯絡我們 
    1. 請電郵至 Mocar16888@gmail.com
    2. 如有任何疑問,請即時聯絡我們。如閣下的疑慮未能釋除,有權於居住或工作的國家,或閣下認為權益受到侵害的地方,向當地的資料保護局投訴。

最後更新日期:2023年6月27日

 

COOKIE政策

Cookie是一種小型文字檔案,會於閣下閱覽我們平台時由伺服器儲存到閣下的裝置內。我們使用Cookie來辨識閣下的使用紀錄,從而觀察平台用量及流量,以改善並提供更切合客戶需要的產品及服務。

我們使用持續的Cookie以及非持續的Cookie。持續的Cookie會留在閣下的瀏覽器中,閣下回到我們的網站或使用我們服務之合作伙伴的網站時,我們會閱讀到該Cookie。非持續的Cookie只會在該次瀏覽期間內維持 (通常是目前瀏覽的網站或瀏覽器小節)。

我們使用以下Cookie: 

      1. 絕對必要的Cookie – 此類Cookie對於維持我們的網站運作屬必須,例子包括讓閣下可登入我們網站安全區域的Cookie。
      2. 分析/性能Cookie – 此類Cookie讓我們識別及統計瀏覽者數目,以及得知瀏覽者於使用我們的網站時之瀏覽方式。這有助於我們改善網站的運作,例如設法確保用戶能輕易找到所需資料。
      3. 功能Cookie – 此類Cookie於閣下回到我們的網站時用作識別閣下。
      4. 目標Cookie – 此類Cookie記錄閣下曾否瀏覽我們的網站、閣下瀏覽的頁面,以及追蹤過的連結。

閣下可透過瀏覽器設定,拒絕全部或部分Cookie。然而,這可能導致閣下無法閱覽我們網站的全部或部分內容。

 

原深感測鏡頭 (TRUEDEPTH CAMERA)

我們使用原深感測鏡頭 (TrueDepth) 技術,配合 SDK 相機,從而提供應用程式中實時面部濾鏡。我們或會不時使用蘋果 (Apple) 原深感測鏡頭相機的資料,以提升濾鏡質素。透過原深感測鏡頭收集的資料不會離開用戶的設備,而相關資料將作實時使用,不會儲存於我們的伺服器中,亦不會與第三方分享。如欲查詢更多關於原深感測鏡頭技術的資訊,可瀏覽https://support.apple.com/en-us/HT208108

 

法律基礎表

處理目的

處理資料種類

法律基礎

為閣下 (商戶) 登記成為我們平台的用戶

帳戶資料

向閣下(商戶) 履行我們的合約

替商戶為閣下 (顧客) 登記成為我們平台的用戶

帳戶資料

替商戶向閣下(顧客) 履行銷售合約

讓閣下 (商戶) 使用我們的產品及服務

帳戶資料、交易資料、使用資料、支援資料、技術資料、用戶內容

向閣下 (商戶) 履行我們的合約

讓閣下 (顧客) 於商戶網站使用我們的產品及服務

帳戶資料、交易資料、使用資料、支援資料、技術資料、用戶內容

替商戶向閣下(顧客) 履行銷售合約 

研究對我們產品或服務的使用方式

帳戶資料、交易資料、使用資料、支援資料、技術資料、用戶內容

改善我們的平台、產品及服務之合法利益

通知閣下 (商戶) 我們產品、服務或條款之變更

帳戶資料

向閣下 (商戶) 履行我們的合約

通知閣下 (顧客) 我們及商戶產品、服務或條款之變更

帳戶資料

替商戶向閣下(顧客) 履行合約

提供閣下 (商戶) 或會感興趣的產品或服務資訊

帳戶資料、喜好資料

許可,閣下可隨時撤回

提供閣下 (顧客) 或會感興趣的商戶產品或服務資訊

帳戶資料、喜好資料、使用資料

許可,閣下可隨時撤回

收集對於我們產品、服務或功能的意見

帳戶資料、使用資料

改善我們的平台、產品及服務之合法利益

管理及維持我們平台的安全

技術資料

向閣下履行我們的合約