PRIVACY POLICY

Last Updated05 July 2026
Official Websitejomomojewelry.com
Data ControllerJOMOMO Jewelry Limited
Registered JurisdictionHong Kong Special Administrative Region

POLICY OVERVIEW

This Privacy Policy governs all personal data collected via our official website, email, WhatsApp chat, SMS marketing, social media official accounts, virtual try-on tool and customer support communications (collectively “Services”). We operate fine jewelry business supplying lab-grown diamonds, lab-grown colored gemstones and moissanite bespoke custom jewelry.

This policy complies with:

  • Hong Kong Personal Data (Privacy) Ordinance Cap.486 (PDPO)
  • EU GDPR & UK GDPR
  • U.S. state privacy laws including CCPA/CPRA (California), Colorado, Virginia, Nevada
  • U.S. COPPA Children’s Online Privacy Protection Act

By browsing, registering, submitting inquiries or placing orders with us, you consent to our data collection, usage, storage and disclosure practices set out below. If you disagree with this policy, cease all use of our Services immediately.

DATA COLLECTION & USE

2.1 Information You Voluntarily Submit

  • Contact identifiers: Full legal name, email address, mobile phone number, shipping and billing postal address, WhatsApp contact
  • Account credentials: Login password, ring size preferences, wishlist and favorite product collections
  • Payment data: Credit/debit card billing details processed solely by PCI-DSS certified third-party payment providers; we do not permanently store full card numbers
  • Transaction data: Order records, custom jewelry specifications, deposit and full payment history
  • Communication content: Customer service chat logs, product reviews, engraving requests, contact information of friends you refer (you warrant you hold valid consent from referred contacts)
  • Identity verification documents: Government-issued ID photos, only requested for high-value orders to complete anti-fraud and anti-money laundering compliance
  • Biometric data: Facial and hand anchor points captured by Virtual Try-On function, collected only with your explicit consent and fully deleted once your browsing session ends
  • Marketing consent records: Your opt-in status for promotional emails and SMS text messages

2.2 Automatically Collected Device & Behavioral Data

We gather data through cookies, web pixels, device fingerprinting and server log files:

  • IP address, approximate geographic location, device model, browser type and operating system
  • Website browsing activity: Visited pages, click tracks, internal search keywords, session duration, entry and exit URLs
  • Mobile advertising identifiers, shopping cart status and website error diagnostic logs

2.3 Data Obtained From Third Parties

Social platform profile information (if you log in via Google or Meta accounts), international logistics & fulfillment partners, gemstone suppliers, advertising analytics vendors and publicly available demographic data.

YOUR PRIVACY RIGHTS

All visitors worldwide hold the following rights:

  1. Access: Request a full copy of all personal data we hold about you
  2. Rectification: Correct inaccurate or incomplete contact, account or order information
  3. Erasure: Request full permanent deletion of your personal data (excluding records we must retain under tax/AML law)
  4. Restriction of processing: Suspend marketing or analytics data usage
  5. Data portability: Receive your order and contact data in machine-readable format
  6. Withdraw consent: Revoke permission for SMS/email marketing, Virtual Try-On biometric capture and targeted advertising at any time

Additional Rights for EU & UK Residents (GDPR)

You have the right to object to automated behavioral profiling. If you believe we violate data protection regulations, you may submit a formal complaint to your local European data supervisory authority.

Additional Rights for Hong Kong Residents (PDPO)

You may submit data access, correction or deletion requests via our designated privacy contact channel listed at the bottom of this policy. You hold the right to lodge a formal complaint with the Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong if you consider our data handling practices unfair or non-compliant.

Additional Rights for California Residents (CCPA/CPRA)

  1. Right to know all categories of personal data we collect, sell or share, together with corresponding third-party recipients
  2. Right to delete and correct inaccurate personal information (subject to mandatory legal retention exceptions)
  3. Right to opt out of “sharing” personal information for cross-site targeted advertising (see Section 10 below for opt-out instructions)
  4. Right to receive equal, non-discriminatory service after exercising any CCPA privacy rights

We do not knowingly collect or share personal data of minors under 16 for targeted advertising activities. Any data sharing for users aged 13–16 requires explicit parental consent.

SECURITY, UPDATES & CONTACT

We adopt industry-standard administrative, physical and technical security measures including end-to-end encrypted data transmission, password encryption, restricted internal staff data access and secure cloud storage to protect your personal data against unauthorized access, loss, alteration or disclosure.

No internet data transmission can be guaranteed 100% secure against unknown network risks, and we cannot eliminate all inherent online transmission vulnerabilities.