This
policy sets out:
A. the information we collect
about you when you visit our website, use our products or services, or
otherwise interact with us;
B. how we use, share, store,
and secure the information; and
C. how you may access and
control the information.
In
this policy, “Festivo Limited” or “we” refers to Festivo and “Platform”
means our website at www.festivo.online
and our software, namely Festivo sites and applications.
In
this policy, “personal information” refers to any data, information, or
combination of data and information that is provided by you to us, or through
your use of our products or services, that relates to an identifiable
individual.
1. What information we collect
about you
1. We collect the following
types of information about you:
a. account and profile
information that you provide when you register for an account or sign up for
our products or services, for example Name, email addresses, phone
numbers, addresses (collectively, “Account Data”);
b. information you provide
through support channels, for example when you report a problem to us or
interact with our support team, including any contact information,
documentation, or screenshots (collectively, “Support Data”);
c. content you provide through
use of our products or services, for example Store and product information
by merchants; Product reviews and ratings from customers (collectively, “User
Content”);
d. communication, marketing,
and other preferences that you set when you set up your account or profile, or
when you participate in a survey or a questionnaire that we send you
(collectively, “Preference Data”);
e. information about your
device or connection, for example your internet protocol (IP) address,
log-in data, browser type and version, time-zone setting, browser plug-in types
and versions, operating system and platform, and other technology on the
devices you use to access our products or services and information we
collect through cookies and other data collection technologies (please read our
Cookies Policy for details) (collectively, “Technical Data”); and
f. Information about your use
of or visit to our Platform, for example your clickstream to, through, and
from our Platform, products you viewed, used, or searched for, page response
times, download errors, length of visits to certain pages, page interaction
information (such as scrolling, clicks, and mouse-overs), or methods to browse
away from the page (collectively, “Usage Data”).
2. We collect the above
information when you provide it to us or when you use or visit our Platform. We
may also receive information about you from other sources, including:
a. our personnel, agents,
advisors, consultants, and contractors based in Hong Kong, Taiwan,
Malaysia in connection with our operations or services, for example our
staff engaged in the fulfilment of your order, processing of your payment, and
provision of support services;
b. other services linked to
your account, for example if you register or log in your account using
your Facebook credentials, we receive your name, your profile picture, your
mobile phone number and email address to authenticate you, as permitted by your
Facebook profile settings;
c. our business partners and
service providers based in Hong Kong who provide reselling and
customer support services in Hong Kong and analytics applications.
3. We do not collect sensitive
data or special category data about you. This includes details about your race,
ethnic origin, politics, religion, trade union membership, genetics,
biometrics, health, or sexual orientation.
2. How we use information we
collect
1. We only use your personal
information where the law allows us to. We use your personal information only
where:
a. we need to perform the
contract we have entered into (or are about to enter into) with you, including
to operate our products or services, to provide customer support and
personalised features, and to protect the safety and security of our Platform;
b. it satisfies a legitimate
interest which is not overridden by your fundamental rights or data protection
interests, for example for research and development, and in order to protect
our legal rights and interests
c. you've given us consent to
do so for a specific purpose, for example we may send you direct marketing
materials or publish your information as part of our testimonials or customer
stories to promote our products or services with your permission; or
d. we need to comply with a
legal or regulatory obligation.
2. If you have given us
consent to use your personal information for a specific purpose, you have the
right to withdraw your consent any time by contacting us (please refer to
paragraph 8 for contact information), but please note this will not
affect any use of your information that has already taken place.
3. We do not share your
personal information with any company outside our group for marketing purpose,
unless with your express specific consent to do so.
4. For visitors to or users of
our Platform who are located in the European Union, we have set out our legal
bases for processing your information in the Legal Bases Table at the end of
this policy.
3. How we share information we
collect
1. We may share personal
information on aggregated or de-identified basis with third parties for
research and analysis, profiling, and similar purposes to help us improve our
products and services.
2. If you use any third-party
software in connection with our products or services, for example any
third-party software that our Platform integrates with, you might give the
third-party software provider access to your account and information. Policies
and procedures of third-party software providers are not controlled by us, and
this policy does not cover how your information is collected or used by
third-party software providers. We encourage you to review the privacy policies
of third-party software providers before you use the third-party software.
3. Our Platform may contain
links to third-party websites over which we have no control. If you follow a
link to any of these websites or submit information to them, your information
will be governed by their policies. We encourage you to review the privacy
policies of third-party websites before you submit information to them.
4. We may share your
information with government and law enforcement officials to comply with
applicable laws or regulations, for example when we respond to claims, legal
processes, law enforcement, or national security requests.
5. If we are acquired by a
third party as a result of a merger, acquisition, or business transfer, your
personal information may be disclosed and/or transferred to a third party in
connection with such transaction. We will notify you if such transaction takes
place and inform you of any choices you may have regarding your information.
4. How we store and secure
information we collect
1. We use Google Cloud data
hosting service based in United States to host the information we
collect.
2. We have adopted the
following measures to protect the security and integrity of your personal
information:
a. information is encrypted
using TLS/SSL technology;
b. your account is
password-protected;
c. access to your personal
information is restricted to personnel or service providers on a strictly
need-to-know basis, who will only process your information on our instructions
and who are subject to a duty of confidentiality; and
d. our information collection,
storage, and processing practices are reviewed regularly.
3. We have put in place
procedures to deal with any suspected privacy breach and will notify you and
any applicable regulator of a breach where we are legally required to do so.
4. While we implement
safeguards designed to protect your information, please note that no
transmission of information on the Internet is completely secure. We cannot
guarantee that your information, during transmission through the Internet or
while stored on our systems or processed by us, is absolutely safe and secure.
5. We only retain personal
information for so long as it is reasonably necessary to fulfil the purposes we
collected it for, including for the purposes of satisfying any legal,
accounting, or reporting requirements.
Merchants may copy and store customer’s information out of our system which
cannot be controlled by us. You as customers should check with respective
Merchant’s privacy policy.
5. Your rights
1. You have the right to:
a. be informed of what we do
with your personal information;
b. request a copy of personal
information we hold about you;
c. require us to correct any
inaccuracy or error in any personal information we hold about you;
d. request erasure of your
personal information (note, however, that we may not always be able to comply
with your request of erasure for record keeping purposes, to complete
transactions, or to comply with our legal obligations);
e. object to or restrict the
processing by us of your personal information (including for marketing
purposes);
f. request to receive some of
your personal information in a structured, commonly used, and machine readable
format, and request that we transfer such information to another party; and
g. withdraw your consent at
any time where we are relying on consent to process your personal information
(although this will not affect the lawfulness of any processing carried out
before you withdraw your consent).
2. You may opt out of
receiving marketing materials from us by using the unsubscribe links in our
communications, or by contacting us. Please note, however, that even if you opt
out from receiving marketing materials from us, you will continue to receive
notifications or information from us that are necessary for the use of our
products or services.
3. As a security measure, we
may need specific information from you to help us confirm your identity when
processing your privacy requests or when you exercise your rights.
4. Any request under
paragraph 5.1 will normally be addressed free of charge. However, we
may charge a reasonable administration fee if your request is clearly
unfounded, repetitive, or excessive.
5. We will respond to all
legitimate requests within one (1) month. Occasionally, it may take
us longer than a month if your request is particularly complex or if you have
made a number of requests.
6. Changes to this policy
1. We may amend this policy
from time to time by posting the updated policy on our Platform. By continuing
to use our Platform after the changes come into effect, you agree to be bound
by the revised policy.
7. Policy towards children
1. Our products and services
are not directed to individuals under 16. We do not knowingly collect
personal information from individuals under 16. If we become aware that an
individual under 16 has provided us with personal information, we
will take steps to delete such information. Contact us if you believe that we
have mistakenly or unintentionally collected information from an individual
under 16.
8. Contact us
1. Please contact us at cs@festivo.store or submit any written
request to:
2. Festivo
Shop 11, G/F Shing To
Building, 32-36 Tai Po Road, Sham Shui Po, Kowloon
Attn: Chief Executive
Officer
1. Please contact us in the
first instance if you have any questions or concerns. If you have unresolved
concerns, you have the right to file a complaint with a data protection
authority in the country where you live or work or where you feel your rights
have been infringed.
Last updated: 1 March
2022
COOKIES
POLICY
Cookies are small text
files that are placed on your device by a web server when you access our
Platform. We use cookies to identify your access and monitor usage and web
traffic on our Platform to customise and improve our products and services.
We use both persistent
cookies and session cookies. A persistent cookie stays in your browser and will
be read by us when you return to our Site or a partner site that uses our
services. Session cookies only last for as long as the session lasts (usually
the current visit to a website or a browser session).
We use the following types
of cookies:
a. Strictly necessary cookies
– these are cookies that are required for the operation of our site. They
include, for example, cookies that enable you to log into secure areas of our
website.
b. Analytical/performance
cookies – these allow us to recognise and count the number of visitors and to
see how visitors move around our Site when they are using it. This helps us to
improve the way our site works, for example, by ensuring that users are easily
finding what they are looking for.
c. Functionality cookies –
these are used to recognise you when you return to our site.
d. Targeting cookies – these
cookies record your visit to our site, the pages you have visited, and the
links you have followed.
You can block cookies by activating the setting on your browser that allows you to refuse the use of all or some cookies. However, if you do so, you may not be able to access all or parts of our site.
LEGAL BASES TABLE
Processing purpose | Type of data processed | Legal basis |
To register you (Merchant) as a user on our Platform | Account Data | To perform our contract with you (Merchant) |
To register you (Customer) as a user on our Platform for the Merchant | Account Data | To perform the Merchant's sale contract with you (Customer) |
To enable you (Merchant) to use our products and services | Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content | To perform our contract with you (Merchant) |
To enable you (Customer) to use our products and services to purchase at Merchant’s website | Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content | To perform the merchant's sales contract with you (Customer) |
To study usage of our products and services | Account Data, Transaction Data, Usage Data, Support Data, Technical Data and User Content | Legitimate interest to improve our Platform, products, and services |
To notify you (Merchant) about changes to our products, services or terms | Account Data | To perform our contract with you |
To notify you (Customer) about changes to the our and the Merchant's products, services or terms | Account Data | To perform the merchant's contract with you |
To provide information on products or services that may be of interest to you (Merchant) | Account Data, Preference Data | Consent, which you may withdraw any time |
To provide information on products or services from Merchants that may be of interest to you (Customer) | Account Data, Preference Data, Usage Data | Consent, which you may withdraw any time |
To gather feedback on our products, services, or features | Account Data, Usage Data | Legitimate interest to improve our Platform, products, and services |
To administer and maintain safety and security of our Platform | Technical Data | To perform our contract with you |