Legal notice
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
LEGAL ENTITY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
This Privacy Policy is issued by MP ELITE LLC, a Limited Liability Company incorporated in the State of New Mexico, United States of America (EIN: 32-0825617), with registered address at 704 Wallace St, Suite 468, Clovis, NM 88101, USA (hereinafter "the Company", "Heirpearl", "we", "us" or "our").
The Company operates the online store accessible at https://heirpearl.com (hereinafter "the Website").
For any privacy-related matter, the Company may be contacted at:
Email: contact@heirpearl.com
Post: MP ELITE LLC, 704 Wallace St, Suite 468, Clovis, NM 88101, USA
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PREAMBLE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
The Company is committed to protecting the personal information of its customers and visitors. This Policy describes what personal data we collect, on what legal basis, how we use and share it, and what rights you hold as a data subject.
This Policy applies to all users of the Website, regardless of their country of residence. It is drafted in compliance with:
— The Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs);
— The United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
— The European Union General Data Protection Regulation (EU) 2016/679 (EU GDPR).
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 1 — PERSONAL DATA COLLECTED
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1.1 Identity and contact data
First name, last name, email address, telephone number, shipping address, and billing address, collected at the time of order placement or account creation.
1.2 Transaction data
Order number, products purchased, amounts paid, payment method used, and transaction history. Payment card details and banking information are processed exclusively by our certified payment service providers (Shopify Payments / PayPal) and are never stored by the Company.
1.3 Personalisation data
Any text, date, name, message, photograph, or instruction that the Customer voluntarily provides for the purpose of customising a jewellery piece. Such data is used solely for the fulfilment of the relevant order and is not retained beyond the statutory retention period.
1.4 Technical and navigation data
IP address, browser type and version, operating system, pages visited, referral source, duration of visit, collected automatically via cookies and similar tracking technologies.
1.5 Communication data
Content of emails, support messages, product reviews, or survey responses sent to the Company.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 2 — LEGAL BASIS AND PURPOSES OF PROCESSING
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2.1 Performance of a contract (Articles 1.1, 1.2, 1.3)
Processing of identity, transaction, and personalisation data is necessary for the execution of the purchase contract, including order fulfilment, shipping, customer service, and after-sales support.
2.2 Consent (Article 1.4 — marketing cookies, Article 1.5 — marketing communications)
Where the Customer has expressly opted in, the Company may send promotional emails and newsletters. Consent may be withdrawn at any time by clicking the unsubscribe link in any email or by contacting contact@heirpearl.com.
2.3 Legitimate interest (Article 1.4 — analytics)
The Company processes navigation data to improve the Website, detect fraud, and analyse purchasing behaviour, provided such processing does not override the Customer's fundamental rights.
2.4 Legal obligation
Certain data (transaction records, invoices) are retained to comply with applicable tax, accounting, and consumer law obligations.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 3 — RECIPIENTS AND DATA TRANSFERS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3.1 The Company shares personal data only with the following categories of recipient, to the extent strictly necessary:
(a) Shopify Inc. (Ottawa, Canada) — e-commerce platform and payment infrastructure. Privacy policy: https://www.shopify.com/legal/privacy
(b) PayPal Holdings Inc. (San Jose, USA) — payment processing. Privacy policy: https://www.paypal.com/au/legalhub/privacy-full
(c) Fulfilment partner — the Company's manufacturing and logistics supplier receives the Customer's name, delivery address, and personalisation instructions exclusively for the purpose of producing and dispatching the ordered item. No financial or sensitive data is transmitted to the supplier.
(d) Meta Platforms Inc. (Menlo Park, USA) — advertising measurement via the Meta Pixel. Customers may opt out at: https://www.facebook.com/adpreferences
(e) Google LLC (Mountain View, USA) — website analytics via Google Analytics with IP anonymisation enabled. Customers may opt out via: https://tools.google.com/dlpage/gaoptout
3.2 The Company does not sell, rent, or otherwise commercially transfer personal data to any third party.
3.3 International transfers: personal data may be transferred to and processed in the United States. For transfers involving European Economic Area or United Kingdom residents, appropriate safeguards are maintained in accordance with applicable law (Standard Contractual Clauses or equivalent mechanisms).
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 4 — DATA RETENTION
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4.1 Order and transaction data are retained for a period of seven (7) years from the date of the last transaction, in accordance with applicable tax and accounting legislation.
4.2 Marketing data (email opt-ins) are retained until the data subject withdraws consent or requests deletion.
4.3 Navigation and analytics data are retained for a maximum of twenty-six (26) months.
4.4 Support communications are retained for three (3) years from the date of the last exchange.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 5 — RIGHTS OF DATA SUBJECTS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5.1 Australian residents — Australian Privacy Principles
Pursuant to the Australian Privacy Act 1988, you have the right to:
(a) access the personal information we hold about you (APP 12);
(b) request correction of inaccurate, incomplete, or out-of-date information (APP 13);
(c) make a complaint to the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au — if you believe a breach of the APPs has occurred.
5.2 United Kingdom residents — UK GDPR
Pursuant to the UK GDPR and the Data Protection Act 2018, you have the right to:
(a) access, rectification, erasure ("right to be forgotten"), and data portability;
(b) restriction of, and objection to, processing;
(c) withdraw consent at any time without affecting the lawfulness of prior processing;
(d) lodge a complaint with the Information Commissioner's Office (ICO) — www.ico.org.uk.
5.3 European Union residents — EU GDPR
The rights set out in Article 5.2 apply equally under Regulation (EU) 2016/679. Complaints may be lodged with the competent supervisory authority in your Member State.
5.4 All data subjects may exercise the above rights by sending a written request, together with proof of identity, to: contact@heirpearl.com. The Company will respond within thirty (30) calendar days of receipt.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 6 — COOKIES AND TRACKING TECHNOLOGIES
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6.1 The Website uses the following categories of cookies:
— Strictly necessary cookies: essential for the operation of the Website and the checkout process. Cannot be disabled.
— Performance cookies: collect anonymised information about pages visited and errors encountered to improve Website performance.
— Marketing and targeting cookies: used to display relevant advertisements on third-party platforms (Meta, Google).
6.2 Cookie consent is requested upon first visit to the Website. Customers may modify their cookie preferences at any time via their browser settings or our cookie management tool. Declining non-essential cookies does not impair the ability to place orders.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 7 — DATA SECURITY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
7.1 The Company implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, including SSL/TLS encryption for all data transmitted via the Website.
7.2 In the event of a data breach likely to result in a risk to the rights and freedoms of data subjects, the Company will notify the relevant supervisory authority and, where required, affected individuals, within the timeframes prescribed by applicable law.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 8 — MINORS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
8.1 The Website is not directed to persons under the age of sixteen (16). The Company does not knowingly collect personal data from minors. If the Company becomes aware that personal data of a minor has been collected without verifiable parental consent, it will delete such data without delay.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ARTICLE 9 — AMENDMENTS TO THIS POLICY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
9.1 The Company reserves the right to amend this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, or its data processing practices. The updated version will be published on the Website with a revised "Last updated" date. Material changes will be notified to registered customers by email where practicable.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CONTACT
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
For any enquiry relating to the processing of your personal data:
Email: contact@heirpearl.com
Post: MP ELITE LLC, 704 Wallace St, Suite 468, Clovis, NM 88101, USA