Last Updated: September 13, 2022
PERSONAL INFORMATION WE COLLECT AND USE
The types of information we collect when you use the Site depend on the features you use on the Site. “Personal information” is information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, whether on its own or in conjunction with other data accessible by us, with a particular individual, device, or household. For example, when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers on Stripe and PayPal), email address, and phone number. We refer to this information as “Order Information.”
We will handle your personal information in accordance with this Privacy Statement and describe the information collected below:
- Identifiers, which may include name, address, online identifier or username, Internet Protocol address, or email address. These are sourced directly from you or indirectly from you (e.g., from observing your actions on the Site). They are used to fulfill or meet the reason you provided the information, to contact you in relation to our Site, to respond to an inquiry, for product and service improvement, to screen for potential risk or fraud, or to process an order. For example, when you create an account, you provide your first and last name, email address, and other identifying information. We disclose this information for business purposes to internet service providers, administrative service providers, and payment processors.
- Personal information categories contained in customer records, which may include name, address, telephone number, bank account number, credit card number, debit card number, or any other payment and financial information. We source this information directly from you. We use this information to fulfill or meet the reason you provided the information, to contact you in relation to our Site, to respond to an inquiry, to screen for potential risk or fraud, or process an order. For example, we need your payment information when you purchase services from us. We disclose this information for business purposes to internet service providers, administrative service providers, and payment processors.
- Characteristics of protected classifications, such as age or gender. We source this information directly from you. We use this information to fulfill or meet the reason you provided the information or to provide relevant services. For example, we may use this information for targeted advertising. We do not disclose this information to third parties.
- Commercial information, which may include records of services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. We source this information directly from you. We use this information to fulfill or meet the reason you provided the information, to contact you in relation to our Site, to screen for potential risk or fraud, and to respond to an inquiry or process an order. For example, we keep track of your purchases to create a purchase history. We disclose this information for business purposes to internet service providers, administrative service providers, and payment processors.
- Internet, technical or other similar network activity, which may include usage and browsing history; device information, including device properties; search history; information on your interaction with our Site; and error logs. We source this information directly or indirectly from you (e.g., from observing your actions on our Site). We use this information to fulfill or meet the reason you provided the information, to screen for potential risk or fraud, or to improve our Site. We disclose this information for business purposes to administrative service providers, data analytics providers, and internet service providers. Please see our Cookie Notice by clicking here for more information on our collection, use, and opt-out options.
- Inferences drawn from other personal information, which may include a profile reflecting a person’s preferences, interests, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. We source this information directly or indirectly from you, (e.g., from observing your actions on our Site). We use this information to fulfill or meet the reason you provided the information. We do not disclose this information to third parties.
- Website interactions. We also use technology to monitor how you interact with our Site. This may include without limitation which links you click on, information that you type into our online forms, and your interaction with our chat feature, which explicitly references this privacy statement. We utilize session replay technology during these interactions to monitor and record mouse clicks and movements, keystrokes, and pages and content viewed by you. This is all information collected directly from you and your interactions with the Site and its features. Please discontinue use of the Site if you do not consent to our collection of such information. We use this information to better understand our Site visitors, to fulfill or meet the reason you provided the information, to contact you in relation to our Site, to respond to an inquiry, to screen for potential risk or fraud, or otherwise meet the needs of our Site and Site visitors. We disclose this information for business purposes to administrative service providers, data analytics providers, and internet service providers.
HOW WE COLLECT YOUR PERSONAL INFORMATION
We collect your personal information:
Directly from you. You may give us your personal information when you do any of the following:
- Access or use the Site;
- Create an account on the Site;
- Enter into a contract with us or purchase our products;
- Apply for or inquire about our Site or products;
- Participate in a promotion, survey, event or other marketing campaign organized by us;
- Subscribe to our newsletters, alerts or notices;
- Request marketing materials to be sent to you; or
- Contact us.
- When you interact with the Site. As you interact with and use the Site, we may automatically collect your personal information, e.g. your internet, technical or other similar network activity. We may also collect personal information by using website cookies.
Third parties or publicly available sources. We may receive your personal information from third parties, which include:
- Internet, technical or other similar network activity from analytics providers such as Google, advertising networks and social media platforms such as Facebook and Instagram; and
- Identifiers and commercial information from providers of technical, payment and delivery services.
Your decision to provide any personal information is voluntary. However, please note that, if you do not provide certain personal information, we may not be able to accomplish some purposes outlined in this Privacy Statement and you may not be able to use or access certain services on our Site.
LAWFUL BASES ON WHICH WE PROCESS YOUR PERSONAL INFORMATION
We collect and use personal information when we have a lawful basis to do so as follows:
A. To protect your vital interests.
B. At your direction and with your consent.
C. To fulfill contracts we might have with you. This includes, for example, if you make an order through the Site.
D. For other legitimate business purposes, where legally permissible. This includes, but is not limited to, legal compliance and the purposes described below.
E. To comply with a legal obligation. For example, to comply with the law or respond to a legal process or lawful request, including from law enforcement and government agencies.
We process your personal information for the following purposes by relying on the lawful basis referenced:
- For example, to register you as a new customer. We rely on lawful bases B and D listed above.
- To administer, operate, provide, maintain and protect our business and our Site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, as well as ensuring that unauthorized users do not access information on our Site). We rely on lawful bases B and D listed above.
- To deliver relevant content and advertisements to you and measure or understand the effectiveness of the advertising we serve you. We rely on lawful bases B and D listed above.
- To make suggestions and recommendations to you about products or services that may be of interest to you. We rely on lawful bases B and D listed above.
- To send you relevant information about our events, news announcements or promotions. We rely on lawful bases B and D listed above.
- To enable you to complete a survey or participate in a promotion, survey, event or other marketing campaign organized by us. We rely on lawful bases B and D listed above.
- To contact you in relation to all of the above purposes described above. We rely on lawful bases B and D listed above.
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If there is any change in the purposes for which we collect your personal information, we will inform you of such change. If you wish to obtain an explanation as to how the processing for the new purpose is compatible with the original purposes, please contact us through the Data Protection Officer, whose contact details are given at the end of this Privacy Statement. If we need to use your personal information for an unrelated purposes, we will notify you and will explain the legal basis which allows us to do so.
SHARING YOUR PERSONAL INFORMATION
We share your personal information with domestic or foreign third parties to help us use your personal information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your personal information here: https://www.shopify.com/legal/privacy.
We may also share your personal information in the following ways:
- We may share your information with domestic or foreign third parties including our agents, service providers, and consultants as needed for them to provide business-related services to us. Such third parties may manage our customer information and perform services on our behalf, such as website hosting, payment processing, order fulfillment, fraud monitoring, identity verification, processing credit card payments, email or mail delivery and administration, promotion fulfillment, surveys or data analysis, etc. We ask third parties with whom we share your information to confirm that their privacy practices are consistent with ours and applicable law and we provide them with only the information they need in order to perform their services for us.
- We may share your information with third party marketing partners for commercial purposes.
- We may share your information or combine your information with publicly available information when we team up with other domestic or foreign promotional partners to jointly offer or provide products, services, contests, or promotions to our customers, or otherwise to enhance and personalize your shopping experience.
- We may work with domestic or foreign third-party companies that use their tracking technologies (including cookies and pixel tags) on our Site in order to provide tailored advertisements on our behalf. These companies may collect information about your activity on our Site and your interaction with our advertising and other communications, may use this information to determine which ads you see on third-party websites and applications, and may also be used to track your activity across multiple devices. Please see our Cookie Notice by clicking here for more information.
- From time to time we may share, exchange and/or cross-reference our postal mailing list with domestic or foreign selected providers of goods and services that may be of interest to you or opted in by you. If you prefer not to receive mailings from these providers, you can notify us at any time by contacting us at email@example.com. You will need to provide your full name and mailing address to be added to our DO NOT MAIL list.
- Finally, we may also share your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
We have sold the following categories of personal information in the preceding 12 months: Identifiers; Personal information categories contained in customer records; Commercial Information; and Internet, technical or other similar network activity.
We have disclosed the following categories of personal information for a business purpose in the preceding 12 months: Identifiers; Personal information categories contained in customer records; Commercial Information; and Internet, technical or other similar network activity.
CONSENT TO TRANSFER
If you are visiting from outside of Singapore or other regions with data protection laws that differ from those of Singapore, please be aware that any information you provide to us will be transferred, collected, used, and processed in Singapore in accordance with applicable law and approved transfer mechanisms. In some instances, Cariuma may transfer that information to its service providers, affiliates and subsidiaries, across borders, and from your country or jurisdiction to other countries or jurisdictions around the world, such as the U.S. or Canada, in accordance with legal mechanisms for international transfer, as appropriate under the relevant law . Singapore does not, and these other jurisdictions may not, have the same data protection laws as the country you are visiting from and may not afford many of the rights conferred upon data subjects in your country. By using the Site, participating in any of the services, and/or providing us with this information, you acknowledge and consent to the transfer of your personal information, which may not offer the same level of data protection as the country where you reside, in accordance with the terms of this Privacy Statement. Please contact us in the methods provided in the “Contact Us” section for any questions or inquiries regarding data transfers.
Where your personal information is to be transferred out of Singapore or such other jurisdiction in which it is collected, we shall ensure that the standard of protection accorded to the personal information so transferred will be comparable to the protection under Singapore law. When we transfer your personal information, we will take measures to ensure that your personal information remains protected, including through the use of binding written contracts.
Our Site contain links to other third party websites. We are not responsible for the privacy practices or the content of such third party websites. To better protect your privacy, we recommend that you review the privacy statement of any third party website you visit.
HOW WE RESPOND TO DO NOT TRACK SIGNALS
The “Do Not Track” (“DNT”) privacy preference is an option that may be made in some web browsers allowing you to opt-out of tracking by websites and online services. At this time, global standard DNT technology is not yet finalized and not all browsers support DNT. We therefore do not recognize all DNT signals but we do recognize the Global Privacy Control.
We offer these rights to users the Site:
Right to opt of “sales” (as defined under applicable law)
- You have the right to opt out of the sale of your personal information to third parties. We do sell personal information, but we do not knowingly sell the personal information of children under 16 years old. You may opt out of the sale of your personal information by emailing firstname.lastname@example.org or by clicking on the “Do Not Sell My Personal Information” link below and filling out the request form.
Right to Delete
- You have the right to request deletion of your personal information, subject to certain legal exceptions.
Depending on your residence, the further below rights available to you may differ in some respects. We will respond to any below rights request in accordance with local legal regulations. If you wish to make a request regarding any of the above rights, please contact us through the methods provided in the “Contact Us” section at the end of this Privacy Statement.
Right of access or right to know
- You may have the right to get confirmation about whether or not your personal information is being processed. If so, you have the right to access the personal information and other information, such as the purposes, the categories of personal information, the recipients (or categories of recipients) to whom the personal information have been or will be disclosed, for particular recipients in third countries or international organizations, where possible, the predicted period that the personal information will be stored, or, if not possible, the criteria used to determine that period, your rights, etc.
- Where feasible and permitted by law, we will provide a copy of the personal information we are processing.
- For any further copies, we may charge a reasonable fee based on administrative costs. If you make the request by electronic means, and unless otherwise requested, the information shall be provided in electronic form.
Right to rectification
- You may have the right to rectify, complete, or correct an error or omission in your personal information if inaccurate or incomplete.
Right to erasure (“right to be forgotten”)
- You may have the right to the erasure of your personal information in certain circumstances. For examples, see below.
- Your personal information is no longer necessary for the purposes for which they were processed
- You withdraw your consent on which the processing is based, and we have no other legal ground for the processing
- You object to the processing and there are no overriding legitimate grounds for the processing
- Your personal information has been unlawfully processed
- Your personal information has to be erased for compliance with a legal obligation to which we are subject
- This right shall not apply to the extent that processing is necessary for the below purposes.
- For exercising the right of freedom of expression and information
- For compliance with a legal obligation which requires processing by a law to which we are subject
- For the performance of a task carried out in the public interest
- For the establishment, exercise or defense of our legal claims
Right to restriction of processing
- You may have the right to restrict the processing for the below reasons.
- You contest the accuracy of your personal information, for a period enabling us to verify the accuracy of the personal information
- The processing is unlawful and you oppose the erasure of the personal information and request the restriction of their use
- We no longer need the personal information for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims
- You exercised your right to object to processing pending the verification whether our legitimate grounds override yours
Right to data portability
- You may have the right to receive the personal information that you have given us, in a structured, commonly used and machine-readable format. You have the right to send that personal information to another controller, if the processing is based on consent pursuant or on a contract and is carried out by automated means.
Right to object
- You may have the right to object, on grounds relating to your particular situation, to processing of your personal information which is based on our legitimate purposes. We will stop processing the personal information unless we have compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims. If personal information is processed for direct marketing purposes, including profiling, you may object at any time.
Automated individual decision-making, including profiling
- You may have the right not to be subject to a decision based solely on automated processing, including profiling, except under certain exceptions under local law.
Right to withdraw consent
- Where the processing of personal information is based on your consent, you may have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.
- We will inform you of the likely consequences of the withdrawal of your consent. Subject to any exceptions under applicable law, your personal information will not be collected, used or disclosed to the extent of your withdrawn consent after a reasonable period for the withdrawal process to be fully completed.
Right to anonymity
- You may also have a right to request anonymity. This means that your personal information would not be collected or processed. If you choose to exercise this right, we may not be able to provide you with your requested goods or services.
Right to lodge a complaint with a supervisory authority
- You may have the right to lodge a complaint with a supervisory authority.
YOUR CALIFORNIA RIGHTS
Visitors to the Sites who are California residents may request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please contact us through the methods provided in the “Contact Us” section below.
Below, we provide rights specifically offered to many California residents:
- the right to know. You may request information about the categories and specific pieces of personal information we have collected about you, as well as the categories of sources from which such information is collected, the purpose for collecting such information, and the sale or disclosure for business purposes of your personal information to third parties, and the categories of third parties with whom this information was shared. You may also request a copy of the personal information we have collected, and upon request, we will provide this information to you in electronic form;
- the right to opt out of the sale of your personal information (as described further above);
- the right to request deletion of your personal information (subject to legal exceptions); and
- the right to not be discriminated against for exercising any of the rights applicable to mentioned above. This includes not being discriminated against in connection with financial incentives, which we may offer from time to time. The terms of a financial incentive will be provided at the time you sign up for the financial incentive. You may withdraw from any of the financial incentives. We have calculated the value of the financial incentive by using the expense related to the offer, and the value of your data is the value of the offer presented to you.
You can exercise your rights by contacting us using the details set out in the “Contact Us” section below. Whenever feasible for verification, we will match the identifying information provided by you to the personal information already maintained by us. If, however, we cannot verify your identity from the information already maintained by us, we may request additional information. You may designate an authorized agent to make a request on your behalf. Such authorized agent must have permission to submit requests on your behalf. We may deny a request from an agent that does not submit proof that they have been authorized by you to act on your behalf.
We will cease to retain your personal information or remove the means by which the personal information can be associated with you as soon as it is reasonable to assume that the said information is no longer required for the purposes of their collection or necessary for legal or business purposes, e.g. to comply with our accounting and legal obligations, resolve disputes, and enforce our agreements.
We take reasonable physical, electronic and managerial measures to safeguard and secure any personal information you provide to us.
Please understand, however, that no data transmissions over the Internet can be guaranteed to be 100% secure because of the inherent risks of data transmission over the Internet. Consequently, we cannot ensure or warrant the security of any information you transmit to us and you understand that any information that you transfer to us is done at your own risk. If we learn of a security systems breach we may attempt to notify you electronically so that you can take appropriate protective steps. By using the Site or providing personal information to us, you agree that we can communicate with you electronically regarding security, privacy and administrative issues relating to your use of the Site. We may post a notice via our Site if a security breach occurs. We may also send an email to you at the email address you have provided to us in these circumstances. Depending on where you live, you may have a legal right to receive notice of a security breach in writing.
ACCOUNTS AND PASSWORDS
You are responsible for maintaining the security of your account credentials for the Site. We will treat access to the Site through your account credentials as authorized by you. We may suspend your use of all or part of the Site without notice if we suspect or detect any breach of security. If you believe that information you provided to us is no longer secure, please notify us immediately at the contact methods provided in the “Contact Us” section below.
COLLECTION AND USE OF INFORMATION FROM CHILDREN UNDER THE AGE OF 18
The Site is not intended for use by persons under the age of 18. We do not knowingly collect information from visitors under the age of 18 and, in the event that we learn that a person under the age of 18 has provided us with personal information, we will delete such personal information.
We may update this Privacy Statement from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. Any new change and/or amendments will be noted on this page. We will also update the Last Updated date above. If we make material changes to our Privacy Statement, we will notify you by prominently posting the changes on our Site or by using the contact information you have on file with us. By continuing to use our Site you are agreeing to be bound by any changes or revisions made to this Privacy Statement.
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email or by mail using the details provided below:
Cariuma Central Pte Ltd
ATTN: Data Protection Officer (David Python)
135 Cecil Street #10-01 MYP Plaza