This Privacy Policy describes how Wacaco Company Limited (“we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit or make a purchase from www.wacaco.com (the “Site”).
1. Personal Information We Collect
A. Device Information (Collected Automatically)
When you visit the Site, we automatically collect certain information about your device. This includes:
- Technical Data: Your web browser type, IP address, time zone, and details about certain cookies installed on your device.
- Usage Data: Information about the individual web pages or products you view, what websites or search terms referred you to our Site, and how you interact with the Site.
We collect this "Device Information" using standard industry technologies:
- Cookies: Data files placed on your device that often include an anonymous unique identifier. To manage or disable cookies, visit allaboutcookies.org or use our cookie consent banner.
- Log Files: Track actions occurring on the Site, collecting data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- Web Beacons, Tags, and Pixels: Electronic files used to record information about how you browse the Site (e.g., Meta/Facebook Pixels, Google Analytics tags).
B. Order Information (Provided Voluntarily)
When you make a purchase or attempt to make a purchase through the Site, we collect specific personal information required to process and fulfill your request:
- Identity & Contact Data: Your name, billing address, shipping address, email address, and phone number.
- Financial Data: Payment information, including credit card numbers (processed securely via our third-party payment processors; we do not store full credit card data on our servers).
Definition: When we use the term “Personal Information” in this Privacy Policy, we mean both Device Information and Order Information.
2. How and Why We Use Your Personal Information (Legal Bases)
If you are located in the European Union (EU) or United Kingdom (UK), we only process your Personal Information when we have a valid legal basis under the GDPR. We use your data for the following purposes:
|
Purpose / Processing Activity |
Data Type |
Legal Basis for Processing (GDPR) |
|
Order Fulfillment: Processing payments, arranging shipping, providing invoices, and sending order confirmations. |
Order Information |
Performance of a Contract: Necessary to deliver the goods you purchased. |
|
Fraud Prevention: Screening orders and monitoring IP addresses for potential risk, malicious activity, or fraud. |
Device & Order Information |
Legitimate Interests: Protecting our business and customers from financial fraud. |
|
Customer Support: Communicating directly with you regarding inquiries, order updates, or issues. |
Order Information |
Performance of a Contract / Legitimate Interests: Assisting you with your purchases. |
|
Site Optimization: Generating analytics on how customers browse the Site to assess and improve our layout, products, and marketing campaigns. |
Device Information |
Consent: Collected via your preference settings on our cookie banner. |
|
Marketing Communications: Providing targeted advertisements, newsletters, or promotional offers. |
Device & Order Information |
Consent: Only where you have explicitly opted-in to receive marketing. |
SMS/Text Marketing Consent
By providing your mobile phone number at checkout or through an opt-in form, you expressly consent to receive automated marketing text messages from us.
- Consent is entirely voluntary and is not a condition of purchase.
- Message and data rates may apply.
- You can opt out of SMS marketing at any time by replying STOP to any message received.
3. Sharing and Disclosing Your Personal Information
We do not sell your personal data for monetary payment. However, we share your Personal Information with trusted third-party service providers to help us run our store and fulfill our contracts with you, as described below:
- Shopify: We use Shopify to power our online e-commerce platform. You can read more about how Shopify uses your Personal Information here: Shopify Privacy Policy.
- Google Analytics: We use Google Analytics to help us understand how customers interact with the Site. You can read more about how Google uses your data here: Google Privacy Policy. You can completely opt-out of Google Analytics monitoring here: Google Analytics Opt-out.
- Payment Gateways: Third-party processors (such as Stripe, PayPal, or regional gateways) have their own independent privacy policies regarding the data we must provide to them for your purchase-related transactions. We recommend reviewing their privacy statements directly.
International Data Transfers
Wacaco Company Limited is based in Hong Kong, and we utilize fulfillment centers and servers located worldwide, including in China (CN), the United States (US), and the European Union (EU). Consequently, your Personal Information will be transferred outside of your home country.
To safeguard these transfers from the EU and UK, we rely on legally binding Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your data receives an equivalent level of protection globally.
Legal Compliance
We may disclose your Personal Information if required to do so by law, to respond to a valid subpoena, search warrant, or other lawful government request, or to protect our legal rights and enforce our Terms of Service.
4. Behavioral Advertising & Your Opt-Out Rights
We use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. To learn more about how targeted advertising works, visit the Network Advertising Initiative’s (“NAI”) educational page at networkadvertising.org.
You can opt-out of targeted advertising across common platforms directly through these links:
- Meta / Facebook: Facebook Ad Settings
- Google: Google Ad Settings
- Bing / Microsoft: Bing Personalized Ads
- Digital Advertising Alliance Portal: You can opt out of multiple third-party advertising tracking tools simultaneously via the DAA portal: optout.aboutads.info.
Global Privacy Control & Do Not Track
Modern privacy laws require platforms to recognize automated opt-out signals. While our Site may not alter data practices based on legacy, non-standardized browser "Do Not Track" (DNT) headers, we recognize and respect Global Privacy Control (GPC) signals where legally mandated. If our system detects a valid GPC signal, it will automatically opt you out of target-advertising tracking cookies.
5. Your Global Privacy Rights
Depending on where you reside (including the EU, UK, Canada, and various US states like California), you possess specific statutory rights regarding your Personal Information:
- Right of Access / Portability: The right to request copies of the personal data we hold about you and receive it in a structured, machine-readable format.
- Right to Rectification: The right to request that we correct any inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): The right to request that we delete your personal information, subject to certain legal exceptions (such as our legal requirement to maintain tax or transactional records).
- Right to Restrict or Object to Processing: The right to object to our processing of your data, or request that we restrict how we use it (including opting out of direct marketing).
- Right to Withdraw Consent: Where our processing is based entirely on your consent, you have the right to withdraw that consent at any time.
If you wish to exercise any of these rights, please submit a request to us at support@wacaco.com. We will verify your identity before responding to the request within the legally required timeframe (typically 30 days for GDPR requests).
6. Data Retention
When you place an order through the Site, we will maintain your Order Information in our secure financial and transactional records to comply with global corporate tax, financial accounting, and anti-fraud regulations. We retain this data until a legitimate deletion request is submitted, provided it does not conflict with our statutory data retention obligations.
7. Age of Consent
By using this Site, you represent that you are at least the age of majority in your state, province, or country of residence, or that you are the age of majority and have given us your express consent to allow any of your minor dependents to use this Site. We do not knowingly collect or solicit personal data from children under the age of 16.
8. California Privacy Rights (CCPA / CPRA Notice)
For residents of California, this section supplements our policy:
- Shining the Light: We do not sell your personal data to third parties for monetary compensation. However, our use of advertising pixels and analytical tracking may be categorized as "sharing" or "selling" under the broad definitions of California law.
- Opt-Out: You have the absolute right to direct us not to sell or share your personal information. To exercise this right, please email support@wacaco.com with the subject line "CCPA Do Not Sell/Share My Info" or adjust your cookie preferences via our Site banner.
9. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time to reflect updates to our operational, legal, or regulatory obligations. Changes and clarifications will take effect immediately upon being posted on the Site. If we make material alterations to this policy, we will update the "Last Updated" date at the top of this page.
10. Contact Information and Complaints
For more information about our privacy practices, if you have questions, or if you would like to file an official privacy complaint, please contact us:
- By Email: support@wacaco.com
- By Mail:
WACACO COMPANY LIMITED
Room B, 19/F Tower 3, China Hong Kong City,
33 Canton Road, Tsim Sha Tsui, Kowloon,
Hong Kong.
If you are an EU or UK resident and feel your data concerns have not been properly addressed, you maintain the statutory right to lodge a formal complaint with your local Data Protection Supervisory Authority.