Privacy Policy | Curveins

Thank you for visiting CURVEINS (the "Website").
This privacy and security policy (the “Policy”) explains the information we collect about you on the Website, as well as information collected when you otherwise communicate or interact with CURVEINS, how we use your personal data, some of the security steps taken to protect that information, and the choices you have to review, revise and/or restrict our use of this information.
This Policy is part of the Terms & Conditions of Use that govern the Website and is binding on all Website users.
If you have any objections to this Privacy Policy, you should immediately discontinue use of the Website.

1. Data We Collect

Field Source Required?
Name Account registration; checkout Yes, to create an account or place an order
Email address Account registration; checkout Yes, to create an account or place an order
Phone number Checkout; customer service Yes for delivery updates when you place an order; otherwise optional
Billing / shipping address Checkout Yes for paid and shipped orders
Payment details (card number, expiry, billing info) Checkout, via payment provider Yes to complete payment. We do not store CVV
Order history, cart and product selections Checkout; Shopify storefront Created when you shop or check out
IP address, device, browser, OS, approximate location Cookies; Microsoft UET; analytics Collected automatically when you visit
On-site events (pages viewed, clicks, add-to-cart, purchase) Cookies; Microsoft UET; Google Analytics Collected automatically, subject to cookie settings where required
Marketing identifiers (cookie IDs; hashed email where used) Microsoft UET; Klaviyo; cookies Used for measurement and remarketing where permitted
Customer service messages Email / support Only if you contact us
Currency preference Temporary cookie / IP-based conversion tool Stored to keep currency consistent while you browse
We do not knowingly collect personal data from children under 16. If we learn that we have, we will delete it.

2. How We Use Personal Data

Order fulfilment

We use name, email, phone, address and payment information to take payment, confirm orders, ship goods, handle returns and send delivery updates.

Account

We use name, email and account credentials so you can register, log in, view orders and update your details.

Risk control and fraud prevention

We use order, device and technical data to detect abuse, chargebacks and suspected fraud, and to secure checkout.

Marketing email

If you subscribe or applicable law allows, we use your email and name (and purchase history where relevant) to send newsletters and product emails. You can unsubscribe at any time.

Microsoft UET remarketing and conversion measurement

We use Microsoft Universal Event Tracking (UET) to measure ad performance and, where permitted, to show or limit Microsoft Advertising ads based on site activity (for example visits, add-to-cart and purchases). See Section 5.

Analytics

We use Google Analytics and similar tools to understand traffic, page performance and checkout drop-off so we can operate and improve the site.We keep data only as long as needed for the purpose above or as required by law (for example accounting records). We cannot delete data that we must retain for bookkeeping or an ongoing contract.

3. Who We Share With

We do not sell or rent personal data for third-party marketing lists. We share data only as needed to run the store, as follows.

Payment providers

We share payment and billing data needed to process the transaction. Card data is handled by the payment provider; we do not store CVV.

Logistics / carriers

We share name, delivery address, phone number and order contents so the carrier can deliver and contact you about the shipment.

Shopify

We share storefront, cart, checkout, account and order data with Shopify because the Website is hosted and processed on the Shopify platform.

Microsoft (UET / Microsoft Advertising)

We share online identifiers, IP-related data and event data (pages, cart and purchase events) with Microsoft so ads can be measured and, where allowed, remarketed. See Section 5.

Google Analytics (GA)

We share device, usage and event data with Google so we can analyse site traffic and performance.

Klaviyo

We share email, name and order/engagement events with Klaviyo to send service and, where permitted, marketing emails and to manage unsubscribes.
We may also share data if required by law, to protect rights or safety, or if the business is merged, reorganised or sold. Service providers may only use the data to provide their service to us.

4. Cookies and similar technologies

We use session and persistent cookies, pixels and similar tools to keep you logged in, remember currency and cart, measure traffic, and (where permitted) support advertising measurement.You can delete or block cookies in your browser. Blocking some cookies may stop checkout, account login or currency persistence from working fully.

5. Microsoft UET

We use Microsoft Universal Event Tracking (UET) on the Website, including product and checkout pages. UET is a tag that sends Microsoft information about visits and events (such as page views, add-to-cart and completed purchases), together with online identifiers and technical data, so we can measure Microsoft Advertising campaigns and, where permitted by law and your settings, show remarketing ads.
Microsoft processes this data under its own terms. Read the Microsoft Privacy Statement: https://www.microsoft.com/privacy/privacystatement
You can limit this activity through cookie settings, Microsoft ad settings, the industry opt-out tools in Section 6, and by sending a Global Privacy Control (GPC) signal, which we honour as described below.

6. Opt-out

Marketing email

Use the unsubscribe link in any marketing email, or email support@curveins.com (mailto:support@curveins.com). Transactional emails about an existing order may still be sent.

Cookies

Change cookie settings in your browser (and, where shown, our cookie banner). Clearing cookies can reset opt-out cookies.

Interest-based advertising

These tools opt you out of participating companies’ interest-based ads in that browser. They do not stop all ads.

Global Privacy Control (GPC)

We treat a valid GPC signal as a request to opt out of “sale” / “share” of personal information for cross-context behavioural advertising, where those concepts apply (including California). Learn more: https://globalprivacycontrol.org/Opt-outs are browser- or device-specific unless you also email us.

7. Your rights

Email support@curveins.com (mailto:support@curveins.com) to exercise any right below. We may need to verify your identity. We will respond within the time required by the law that applies to you.

GDPR (EEA / UK)

Where GDPR or UK GDPR applies, you may request access, correction, deletion, restriction, portability, and to object to processing based on legitimate interests, including profiling for direct marketing. You may withdraw consent at any time without affecting prior lawful processing. You may lodge a complaint with your local supervisory authority.

CCPA / CPRA (California)

California residents may request to know the categories and specific pieces of personal information we collected, the sources, purposes and categories of recipients; request deletion; request correction; and opt out of sale or sharing of personal information. We do not sell personal information for money. We may “share” identifiers and internet activity with advertising partners (including Microsoft UET) for cross-context behavioural advertising. You may opt out via GPC, cookie controls, the tools in Section 6, or by emailing us. We will not discriminate against you for exercising these rights. An authorised agent may submit a request if we can verify both the agent and your authorisation.

Other countries

Depending on where you live, local law may give you similar access, correction, deletion or marketing-objection rights. Email support@curveins.com (mailto:support@curveins.com) and we will handle the request under the law that applies.


8. Security and retention

  • The Website is served over HTTPS.
  • Payment and other sensitive data in transit are encrypted.
  • We do not store CVV. Card numbers are processed by the payment provider, not kept in our own card vault.
  • Access to personal data is limited to staff and processors who need it.
  • No method of transmission or storage is completely secure.
Retention (typical)
  • Account data: while the account remains open, then deleted or anonymised unless law requires longer.
  • Order, payment and invoice data: for the order lifecycle plus the period required for tax and accounting (often up to 7 years).
  • Support emails: for as long as needed to resolve the query and keep a service record.
  • Marketing lists: until you unsubscribe or the list is suppressed.
  • Cookies / UET / analytics identifiers: for the life of the cookie or the vendor’s configured retention, unless you delete them sooner.
If a personal-data breach is likely to result in a risk to you, we will notify affected users and, where required, the authority, without undue delay and in any event within 72 hours of becoming aware where that deadline applies.

9. Third-party sites

Links on the Website may go to third-party sites. Their privacy practices are their own. Read their policies before you provide data.

10. International transfers

CURVEINS is registered in the BVI. Shopify, payment, logistics, Microsoft, Google and Klaviyo may process data in the United States and other countries. Where a transfer law requires safeguards (for example GDPR standard contractual clauses), we rely on the platform’s or vendor’s transfer mechanism.

11. Changes

We may update this Policy. The “Last updated” date will change when we do. Material changes will be indicated on this page and, where required, by email. Continued use after the update means you accept the revised Policy.

Contact

Guangzhou Kunying Brand Management Co., Ltd., operating as CURVEINS
Address: Room 202, No. 24, 88 Xinjiao Middle Road, Haizhu District, Guangzhou
Email: support@curveins.com