Privacy policy

Privacy Policy

Introduction
We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you how we process your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.
Purpose and Notice of this Privacy Policy
This privacy policy is designed to provide you with information about how this website collects and processes your personal data through your use of this website, including any information you may provide through this website when you sign up for our newsletter, purchase products or services or participate in events and other activities held on it.
This website is not intended for children and we do not knowingly collect information relating to children.
It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your information. This privacy policy supplements other notices and privacy policies and is not intended to replace them.
It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during your relationship with us.
Third-Party Links
This website may contain links to third-party websites, plugins and applications. Clicking on these links or enabling these connections may allow third parties to collect or share information about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
Data We Collect About You
Personal information, or personal information, is any information that can identify an individual. It does not include information from which the identity has been removed (anonymous information).
We may collect, use, store and transfer different types of personal data about you, which we group together below: Identity information includes first name, last name, username or similar identifier, title, national identification number, date of birth and gender. Contact information includes billing address, shipping address, email address and telephone number. Financial data includes bank account and payment card details. Transaction data includes payment details about you and other details about products and services you have purchased from us. Technical information includes Internet Protocol (IP) address, your login details, browser type and version, time zone setting and location, browser plug-in type and version, operating system and platform, WiFi and other technology on the devices you use to access this website. Personal Data includes your username and password, purchases or orders you make, your interests, preferences, feedback and survey responses. Usage Data includes information about how you use our website, products and services. Marketing and Communications Data includes [your preferences for receiving marketing messages from us and our third parties and your communications preferences].
Location Data includes GPS-based location information generated when you use this website. We also collect, use and share Aggregated Data, such as statistical or demographic data, for any purpose. Aggregated Data may be derived from your Personal Data but is not considered Personal Data under the law because it does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a particular website feature. However, if we combine or connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we will treat the combined data as Personal Data and use it in accordance with this Privacy Policy.
We do not collect any Special Categories of Personal Data/Sensitive Personal Information about you (this includes, but is not limited to, race or origin, religious or philosophical beliefs, personal ideology, social status, criminal record, medical record or trade union membership, genetic data, biometric information, health information, information about sex life or sexual orientation). We also do not collect any information about criminal convictions and offences.
If you fail to provide personal data
If we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have provided to us, but we will notify you if this happens at the time.
How is your personal data collected?
We use different methods to collect data from and about you, including through:
Direct interactions. You may give us your identity, contact information and financial information by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you: purchase our products or services; create an account on our website; subscribe to our membership or newsletter; request to be sent marketing communications; enter a competition, promotion or survey; or give us feedback or contact us. Automated technologies or interactions. We automatically collect Technical Information about your device, browsing actions and patterns as you interact with our website. We collect this personal information by using cookies, server logs and other similar technologies. We may also receive Technical Information about you if you visit other websites that use our cookies. Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources, such as:
Technical Information from:
Analytics providers [such as Google outside the EU];
Ad networks; and
Search information providers.
Contact information, financial and transaction information from providers of technical, payment and delivery services. Identity and contact information from publicly available sources [such as Companies House and the Electoral Register within the EU]. How we use your personal data We will only use your personal data where we are permitted by law. Most commonly, we use your personal data in the following circumstances:
When we need to perform a contract we are about to enter into or have entered into with you. Where it is necessary for our legitimate interests or those of a third party (e.g. fraud prevention, IT security, use of customer or employee data), and your interests and fundamental rights do not override those interests. We commit to using data in a proportionate and fair way for users. Where we need to comply with a request from an administrative or judicial authority based on a legal obligation. To provide you with information or advertising related to our products or services, based on the preferences you have shared with us.
Generally, we do not rely on consent as a legal basis for processing your personal data, although we will obtain your consent before sending you third-party direct marketing messages by email or text message. You have the right to withdraw your consent to marketing at any time by contacting us.
Purposes for which we use your personal data
We have described below in a table format all the ways we plan to use your personal data, and the legal basis we rely on to do so. We have also identified our legitimate interests where appropriate.
Please note that we may process your personal data for more than one lawful ground, depending on the specific purpose for which we are using your data. Please contact us if you need to know the specific legal basis we rely on to process your personal data (there are multiple bases listed in the table below).
Necessary for our legitimate interests (to develop our products/services and grow our business)
Marketing
We strive to provide you with choices about certain uses of your personal data, particularly in relation to marketing and advertising.
Our promotional offers
We may use your Identity, Contact, Technical, Usage and Profile information to understand what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant to you (we call this marketing).
You will receive marketing messages from us if you request information from us or purchase [goods or services] from us and you have not opted out of receiving that marketing message.
Third-party marketing
We will get your explicit opt-in consent before we share your personal data with any third party for marketing purposes.
Opt-out
You can ask us or third parties to stop sending you marketing messages at any time.
If you opt-out of receiving these marketing messages, this does not apply to personal data provided to us as a result of a product/service purchase, warranty registration, product/service experience or other transaction.
Cookies
Cookies are text files stored on computers or mobile devices by web servers. The contents of cookies can only be retrieved and read by the server that created the cookies. Cookies are unique to the browser or mobile application you are using. The text in a cookie usually consists of an identifier, a website name, and some numbers and characters.
Sometimes, we store cookies on computers or mobile devices for the purpose of improving user experience, including the following scenarios:
• Ensure that the official website pages function properly. These cookies are necessary for you to browse and use the functions of the official website pages. Without these cookies, you may not be able to use and visit the official website pages normally. For example, these cookies can record the information you enter. You do not need to enter it again the next time you visit.
• Analyze the use of the official website pages to measure and improve the performance of the pages. Such cookies collect information about your behavior when visiting the official website, such as the pages you visit frequently and whether you receive error notifications. With this information, we can improve the structure, navigation and content of the official website and provide you with a better access experience.
If you have any questions about our use of cookies or other similar technologies, you can also contact us through the contact information. We will not use cookies for purposes other than those stated above.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may be inaccessible or not function properly.
Change of Purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use your personal data for another reason and that reason is compatible with the original purpose. If you would like an explanation of how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent in accordance with the rules set out above where this is required or permitted by law.
Disclosure of Your Personal Data
For the purposes set out in the table in paragraph 4 above, we may have to share your personal data with the parties listed below.
• Internal third parties listed in the Glossary.
• External third parties listed in the Glossary.
• Third parties to whom we may choose to sell, transfer or merge parts of our business or assets. Alternatively, we may seek to acquire other businesses or merge with them. If our business changes, then the new owner may use your personal information in the same manner as set out in this Privacy Policy.
We require all third parties to respect the security of your personal information and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal information for their own purposes and only permit them to process your personal information for specified purposes and in accordance with our instructions.
International Transfers
Our products and services are provided through resources and servers located in different locations, and in order to provide our products and services, we may need to transfer your personal information between multiple countries. Pop Mart authorized personnel and third parties acting on our behalf may access, use and process personal information collected from you in countries that are different from the country where you entered your personal information, which may have less stringent data protection laws. When we transfer your personal information to other countries, we will protect your personal information as described in this statement or otherwise disclosed to you at the time of collection (for example, through a privacy statement or supplementary statement for a specific product or service).
Pop Mart has implemented global privacy practices to handle personal information protected by various data protection laws. Pop Mart transfers personal data between countries/regions where we operate in accordance with the standards and conditions of applicable data protection laws, including those related to security and processing.
For personal data from the EU or the UK, we comply with applicable legal requirements to provide adequate safeguards for the transfer of personal data to countries/regions outside the European Economic Area ("EEA") or the UK. We use a variety of legal mechanisms, such as standard contractual clauses, to implement cross-border transfers of your personal data; or implement security measures such as anonymization of the data before cross-border data transfer.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where required by law.
Data Retention
How long will you use my personal data?
We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for longer in the event of a complaint or if we have reason to believe that litigation might arise in relation to our relationship with you. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information, and whether we process your personal information for purposes that can be achieved by other means, and applicable legal, regulatory, tax, accounting or other requirements.
We will retain your personal information for as long as we have an ongoing legitimate business need to process it, to provide you with services or products, or as required or permitted by applicable law. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. How long your information is retained also depends on how you use our website (for example, whether you are logged in as a member or visit our website as a guest) and the nature of the information you provide to us.