PRIVACY POLICY
POLICY OVERVIEW
This Privacy Policy governs all personal data collected via our official website, email, WhatsApp chat, SMS marketing, social media official accounts, virtual try-on tool and customer support communications (collectively “Services”). We operate fine jewelry business supplying lab-grown diamonds, lab-grown colored gemstones and moissanite bespoke custom jewelry.
This policy complies with:
- Hong Kong Personal Data (Privacy) Ordinance Cap.486 (PDPO)
- EU GDPR & UK GDPR
- U.S. state privacy laws including CCPA/CPRA (California), Colorado, Virginia, Nevada
- U.S. COPPA Children’s Online Privacy Protection Act
By browsing, registering, submitting inquiries or placing orders with us, you consent to our data collection, usage, storage and disclosure practices set out below. If you disagree with this policy, cease all use of our Services immediately.
DATA COLLECTION & USE
2.1 Information You Voluntarily Submit
- Contact identifiers: Full legal name, email address, mobile phone number, shipping and billing postal address, WhatsApp contact
- Account credentials: Login password, ring size preferences, wishlist and favorite product collections
- Payment data: Credit/debit card billing details processed solely by PCI-DSS certified third-party payment providers; we do not permanently store full card numbers
- Transaction data: Order records, custom jewelry specifications, deposit and full payment history
- Communication content: Customer service chat logs, product reviews, engraving requests, contact information of friends you refer (you warrant you hold valid consent from referred contacts)
- Identity verification documents: Government-issued ID photos, only requested for high-value orders to complete anti-fraud and anti-money laundering compliance
- Biometric data: Facial and hand anchor points captured by Virtual Try-On function, collected only with your explicit consent and fully deleted once your browsing session ends
- Marketing consent records: Your opt-in status for promotional emails and SMS text messages
2.2 Automatically Collected Device & Behavioral Data
We gather data through cookies, web pixels, device fingerprinting and server log files:
- IP address, approximate geographic location, device model, browser type and operating system
- Website browsing activity: Visited pages, click tracks, internal search keywords, session duration, entry and exit URLs
- Mobile advertising identifiers, shopping cart status and website error diagnostic logs
2.3 Data Obtained From Third Parties
Social platform profile information (if you log in via Google or Meta accounts), international logistics & fulfillment partners, gemstone suppliers, advertising analytics vendors and publicly available demographic data.
We process your personal data only on valid legal grounds for limited legitimate purposes:
- Performance of contract: Process orders, produce custom jewelry, arrange global shipping, issue invoices and provide after-sales warranty & repair services.
- Your explicit consent: Send marketing emails/SMS, activate Virtual Try-On biometric capture, share data for cross-site targeted advertising. You may withdraw your consent at any time.
- Legitimate business interest: Website operation & optimization, traffic analytics, fraud prevention, AML compliance screening, customer service improvement and advertising campaign performance measurement.
- Legal compliance obligation: Fulfill Hong Kong tax and anti-money laundering regulations, EU & U.S. cross-border trade rules, respond to official regulatory requests and resolve legal disputes.
We will never use collected personal data for new purposes inconsistent with those listed above without obtaining separate new consent from you.
We only share your data with limited authorized third parties necessary to deliver our Services:
- Order fulfillment vendors: Payment processors, international shipping/logistics providers, jewelry manufacturing ateliers and insurance service providers
- Technical & analytics partners: Cloud hosting providers, website analytics tools and Virtual Try-On system suppliers
- Advertising platforms: Meta, Google Ads and other third-party ad networks for interest-based targeted marketing
- Compliance & legal parties: Hong Kong customs, law enforcement agencies, independent auditors and legal counsel (only when legally required)
- Successor entities: In the event of company merger, asset sale, restructuring or insolvency, customer data may transfer as business assets bound by identical privacy protection terms.
We will not sell, rent or lease your personal data to unrelated third parties for independent marketing unless you provide separate opt-in consent. For California residents, please refer to Section 10 regarding data “sharing” for targeted advertising under CCPA.
We deploy four categories of cookies on our website:
- Necessary Cookies: Mandatory core cookies for shopping cart, account login and order functions; cannot be disabled.
- Performance Cookies: Measure website loading speed, system error logs and anonymous visitor statistics.
- Functional Cookies: Save your language, region and jewelry size preference settings.
- Targeting/Advertising Cookies: Deliver personalized ads across external third-party websites and track marketing conversion performance.
You may manage or block all non-necessary cookies via your browser’s built-in settings or our website cookie preference center. Disabling targeting cookies will not remove all advertisements but will turn off personalized interest-based recommendations. Our website recognizes Global Privacy Control (GPC) browser signals as a formal opt-out request for California residents regarding data sale and sharing activities.
- Order & transaction records: Retained for 7 years to comply with Hong Kong tax and anti-money laundering legal requirements
- Marketing contact data: Retained only until you submit a formal opt-out request
- Virtual Try-On biometric data: Permanently deleted immediately after your browsing session ends
- Anonymous browsing analytics data: Automatically anonymized after a maximum of 24 months
- Unresolved customer complaint records: Retained only until relevant disputes are fully closed
After the retention period expires, all identifiable personal data will be securely anonymized or permanently erased from our systems.
Our company is registered in Hong Kong. Your personal data may be transferred and stored in the United States, European Union, Southeast Asia or other regions where our authorized service providers operate.
For EU/UK users: We execute Standard Contractual Clauses (SCCs) with overseas data processors to guarantee equivalent GDPR-compliant data protection standards.
For Hong Kong residents: All cross-border data transfers only proceed to jurisdictions with adequate data protection frameworks or with your explicit written consent.
YOUR PRIVACY RIGHTS
All visitors worldwide hold the following rights:
- Access: Request a full copy of all personal data we hold about you
- Rectification: Correct inaccurate or incomplete contact, account or order information
- Erasure: Request full permanent deletion of your personal data (excluding records we must retain under tax/AML law)
- Restriction of processing: Suspend marketing or analytics data usage
- Data portability: Receive your order and contact data in machine-readable format
- Withdraw consent: Revoke permission for SMS/email marketing, Virtual Try-On biometric capture and targeted advertising at any time
Additional Rights for EU & UK Residents (GDPR)
You have the right to object to automated behavioral profiling. If you believe we violate data protection regulations, you may submit a formal complaint to your local European data supervisory authority.
Additional Rights for Hong Kong Residents (PDPO)
You may submit data access, correction or deletion requests via our designated privacy contact channel listed at the bottom of this policy. You hold the right to lodge a formal complaint with the Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong if you consider our data handling practices unfair or non-compliant.
Additional Rights for California Residents (CCPA/CPRA)
- Right to know all categories of personal data we collect, sell or share, together with corresponding third-party recipients
- Right to delete and correct inaccurate personal information (subject to mandatory legal retention exceptions)
- Right to opt out of “sharing” personal information for cross-site targeted advertising (see Section 10 below for opt-out instructions)
- Right to receive equal, non-discriminatory service after exercising any CCPA privacy rights
We do not knowingly collect or share personal data of minors under 16 for targeted advertising activities. Any data sharing for users aged 13–16 requires explicit parental consent.
Our website and Services are not intended for users under 13 years old. We do not knowingly collect personal information from children under 13. If we discover we have obtained minor’s data without valid parental consent, we will erase all relevant records immediately upon notification from legal guardians. Users aged 13–17 may only use our Services with parent or legal guardian approval.
Under California CPRA rules, sharing identifiers, browsing activity and commercial purchase data with advertising platforms for cross-site targeted marketing counts as “sharing” of personal information, which grants California residents an opt-out right.
If you are a California resident and wish to opt out of all such data sharing for targeted ads:
- Enable the Global Privacy Control (GPC) signal inside your browser settings; our website will automatically honor this signal as a full opt-out request.
- Alternatively, send a formal opt-out request via our privacy inquiry email listed at the end of this policy, including your full name, registered email address and shipping address for identity verification.
Opt-out requests only apply to the specific browser and device you use to submit the request. If you clear browser cache or switch devices, you will need to resubmit your opt-out preference. Opting out will not block generic non-targeted advertisements on our website or third-party platforms.
SECURITY, UPDATES & CONTACT
We adopt industry-standard administrative, physical and technical security measures including end-to-end encrypted data transmission, password encryption, restricted internal staff data access and secure cloud storage to protect your personal data against unauthorized access, loss, alteration or disclosure.
No internet data transmission can be guaranteed 100% secure against unknown network risks, and we cannot eliminate all inherent online transmission vulnerabilities.
We reserve the right to update this Privacy Policy to reflect business adjustments or revised legal regulatory requirements. All updated versions will be published on this page with a revised “Last Updated” date. Your continued use of our website after publication constitutes full acceptance of the revised policy. We may notify registered account holders of major material policy changes via their registered email address.
Official Website: https://www.jomomojewelry.com/
Privacy Compliance Inquiry Email: 【填写企业隐私合规邮箱】
Customer Service WhatsApp / Hotline: 【填写海外客服联络号码】
JOMOMO Registered Hong Kong Address: 【填写香港完整注册地址】
To exercise any privacy rights including access, correction, deletion or opt-out requests, submit your application via the above privacy email with your full legal name and registered contact information for identity verification. We will respond to all valid formal requests within 45 calendar days as required by U.S. state privacy laws, EU GDPR and Hong Kong PDPO.