This Privacy Policy explains how personal data is collected, used, retained and handled when you visit or make a purchase through www.vandalgems.com.

The privacy data controller for personal data processed through this Website is Vandalgems.

1. Personal Data We Collect

Depending on how you use the Website, we may collect:

  • name and contact details;
  • email address and telephone number;
  • billing and delivery information;
  • order and transaction details;
  • information provided when contacting us;
  • account or checkout information where applicable;
  • cookie and Website preference information; and
  • information required to administer and process an order.

We collect only information reasonably required for the relevant purposes described in this Privacy Policy.

2. How We Use Personal Data

Personal data may be used to:

  • process and administer orders;
  • process payments;
  • communicate with customers regarding orders or enquiries;
  • provide customer support;
  • maintain appropriate business and transaction records;
  • comply with applicable legal and regulatory obligations;
  • manage Website preferences and cookie choices; and
  • administer and maintain the Website.

Personal data is not retained or used for unrelated purposes.

3. Payment Processing by Stripe

Payments made through the Website are processed by Stripe, which acts as our payment processor.

When you make a payment, Stripe may process transaction-related information required to provide its payment services. Depending on the payment method and Stripe integration used, this may include information such as your name, email address, billing or delivery address, payment method information, transaction amount, transaction date, payment status and relevant order information.

Stripe may act as a data processor on behalf of a business using its services and may also act as an independent data controller for certain processing activities. Stripe’s own privacy practices therefore apply to personal data processed by Stripe in its applicable role.

Stripe may process personal data for purposes including payment processing, transaction administration, fraud monitoring, regulatory compliance and provision of its services.

For further information regarding Stripe’s handling of personal data, customers may consult Stripe’s Privacy Policy.

4. Legal Basis for Processing

Where the GDPR applies, personal data may be processed where necessary to perform a contract, comply with a legal obligation, pursue a legitimate interest that is not overridden by applicable rights, or where consent is required and has been obtained.

For customers in Singapore, personal data is handled in accordance with applicable requirements of the Personal Data Protection Act 2012 (PDPA), including applicable requirements concerning collection, use, disclosure, protection and retention.

5. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including order administration, customer service, accounting, record keeping, legal obligations and the establishment or defence of legal claims.

Different categories of information may therefore be retained for different periods.

As a general approach:

  • Order and transaction records: retained for the period reasonably required for order administration, accounting, record keeping and applicable legal obligations;
  • Customer communications: retained for as long as reasonably necessary to manage the enquiry and any related business or legal matter;
  • Account or customer information: retained while the relevant account or customer relationship remains active and for an appropriate period thereafter where required for legitimate business or legal purposes;
  • Consent and preference records: retained for the period reasonably necessary to record and administer the relevant choice and demonstrate compliance where required;
  • Website and cookie-related information: retained according to the relevant cookie purpose and applicable retention period.

When personal data is no longer required for its relevant purpose and there is no applicable business or legal reason to retain it, it will be deleted, anonymised or otherwise removed from identifiable use.

Singapore’s PDPA does not prescribe one fixed retention period for all personal data; instead, organisations must cease retaining personal data when the relevant purposes are no longer being served and retention is no longer necessary for legal or business purposes.

For European customers, the GDPR requires personal data to be kept in identifiable form for no longer than necessary for the purposes for which it is processed.

6. Disclosure of Personal Data

Personal data may be disclosed where reasonably necessary to operate the Website, process orders, process payments, provide requested services, maintain business records or comply with applicable legal requirements.

This may include relevant service providers and payment service providers such as Stripe where required for payment processing.

Personal data is not disclosed for unrelated purposes.

7. International Data Processing

As online services and payment processing may involve service providers operating in different jurisdictions, personal data may be processed outside Singapore or the European Economic Area where applicable.

Where the GDPR applies, transfers of personal data to countries outside the EEA are carried out using an applicable lawful transfer mechanism or other safeguard recognised under applicable data protection law.

Stripe states that its services may involve processing personal data in different jurisdictions and maintains contractual data protection arrangements for applicable processing activities.

8. Cookies

The Website uses cookies and similar technologies for essential Website functions and, where applicable, other purposes described in our Cookie Policy.

Non-essential cookies are used only after the customer has clicked “Accept” on our Cookie banner to provide consent where consent is required.

Please refer to our Cookie Policy for further information concerning cookie categories, purposes and retention periods.

9. Data Protection

Appropriate organisational and data-handling measures are applied to personal data according to the nature and purpose of the processing.

Access to personal data is limited to circumstances in which it is reasonably required for the relevant business, service or legal purpose.

10. Your Data Protection Rights

Depending on your location and applicable law, you may have rights concerning your personal data, including:

  • requesting access to personal data;
  • requesting correction of inaccurate information;
  • requesting deletion where applicable;
  • requesting restriction of certain processing;
  • objecting to certain processing;
  • withdrawing consent where processing is based on consent; and
  • requesting applicable data portability rights.

These rights are subject to applicable legal conditions and limitations.

11. Data Requests

Requests concerning personal data may be submitted using the contact information provided below.

We will review and respond to valid requests within the period required by applicable law.

12. Privacy Policy Updates

This Privacy Policy may be updated when our Website, data processing practices or applicable legal requirements change.

The latest version will be published on this page with the applicable update date.

13. Contact Information

Registered Company Name:
Address:
Telephone:
Email:
Website: www.vandalgems.com