Privacy & Cookies Policy
Privacy Policy
Last updated: 1 Jan 2026
1. Who we are
This privacy notice is issued by FDL LTD based and registered in HONG KONG SAR, owner of the website www.formosadoll.com .
Although we are based outside the European Union, we process data of EU residents and fully comply with Regulation (EU) 2016/679 (GDPR) and Regulation (EU) 524/2013 regarding online dispute resolution.
For any privacy-related questions, contact us at: support@formosadoll.com
2. Scope of This Policy
This Policy explains how we collect, use, disclose, transfer, and protect personal data when you:
-
Visit our website
-
Place an order
-
Contact us
-
Subscribe to marketing communications
-
Interact with our advertising
We process personal data of individuals located in the European Union and the United Kingdom in accordance with:
-
Regulation (EU) 2016/679 (GDPR)
-
UK General Data Protection Regulation (UK GDPR)
-
Applicable local data protection laws
3. Categories of Personal Data Collected
We may collect and process the following categories of personal data:
Identity Data
-
First name
-
Last name
Contact Data
-
Email address
-
Shipping address
-
Telephone number (optional)
Transaction Data
-
Order details
-
Purchase history
-
Payment confirmation data (we do not store full payment details)
Technical Data
-
IP address
-
Device type
-
Browser type
-
Operating system
-
Referral source
Usage Data
-
Website interaction data
-
Pages viewed
-
Cookie preferences
-
Consent logs
We do not intentionally collect special category data under Article 9 GDPR.
Order history is processed strictly for contractual fulfilment and accounting purposes. We do not profile users based on sensitive characteristics.
4. Sources of Data
We collect personal data:
-
Directly from you (e.g. when placing an order or contacting us)
-
Automatically through cookies and tracking technologies
-
From third-party service providers (e.g. payment processors, analytics providers)
5. Purposes of Processing and Legal Basis
We process personal data for the following purposes and rely on the corresponding legal bases under Article 6 GDPR:
| Purpose | Legal Basis |
|---|---|
| Processing and fulfilling orders | Article 6(1)(b) – Performance of a contract |
| Customer support and communication | Article 6(1)(b) – Performance of a contract |
| Fraud prevention and chargeback management | Article 6(1)(f) – Legitimate interest |
| Accounting and tax compliance | Article 6(1)(c) – Legal obligation |
| Marketing communications | Article 6(1)(a) – Consent |
| Website analytics and performance tracking | Article 6(1)(a) – Consent |
| Website security and monitoring | Article 6(1)(f) – Legitimate interest |
Where processing is based on legitimate interest, we ensure that such interest does not override your fundamental rights and freedoms.
You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
6. Automated Decision-Making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
Certain automated systems (such as fraud detection tools or chat systems) may assist our operations but do not independently determine outcomes without human review.
7. Data Sharing
We share personal data only where necessary and proportionate.
Categories of recipients include:
-
Shopify Inc. (e-commerce platform and hosting provider)
-
Payment processors (Shopify Payments, Stripe, PayPal)
-
Courier services (e.g. DHL, UPS)
-
Google LLC (Analytics and Ads, subject to consent)
-
Meta Platforms Inc. (advertising services, subject to consent)
-
Professional advisers (legal, accounting)
All service providers are subject to contractual confidentiality obligations and, where required, Standard Contractual Clauses (SCCs) or equivalent safeguards.
We do not sell or rent personal data.
8. International Transfers
As FDL LTD is established in Hong Kong SAR, personal data may be processed outside the European Union and the United Kingdom.
Where personal data is transferred internationally, we rely on:
-
Standard Contractual Clauses approved by the European Commission
-
The UK International Data Transfer Agreement (IDTA) or UK Addendum
-
Equivalent legally recognised safeguards
You may request further information regarding transfer safeguards by contacting us.
9. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected.
| Category | Retention Period |
|---|---|
| Invoices and accounting records | 10 years (legal obligation) |
| Order and shipment data | Up to 24 months (operational purposes) |
| Data linked to invoicing | Up to 10 years |
| Technical/cookie data | Up to 13 months |
| Consent records | Duration of consent + 5 years |
Where legal obligations require longer retention, data may be stored accordingly.
10. Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
-
SSL encryption across the website
-
PCI-DSS compliant payment processing
-
Role-based access control
-
Two-factor authentication where available
-
Firewall protection
-
Regular security updates via Shopify infrastructure
-
Encrypted backups in distributed data centres
While we implement industry-standard safeguards, no electronic system can guarantee absolute security.
11. Your Rights
Under GDPR and UK GDPR, you have the right to:
-
Access your personal data
-
Rectify inaccurate data
-
Erase data (“right to be forgotten”)
-
Restrict processing
-
Object to processing
-
Request data portability
-
Withdraw consent
-
Lodge a complaint with a supervisory authority
To exercise your rights, contact:
📧 support@formosadoll.com
12. Supervisory Authorities
EU residents may lodge complaints with their local Data Protection Authority.
UK residents may contact:
Information Commissioner's Office (ICO)
https://ico.org.uk
13. Children
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.
If we become aware that personal data from a minor has been collected, we will take appropriate steps to delete it.
14. Data Breaches
In the event of a personal data breach likely to result in risk to individuals’ rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, affected individuals in accordance with Articles 33 and 34 GDPR.
15. Updates to This Policy
We reserve the right to amend this Privacy Policy at any time. Updates will be published on this page with the revised date.
16. Additional Rights for US Residents
If you are a resident of certain US states, including California, you may have additional rights under applicable privacy laws, including:
-
The right to know what personal information we collect and how it is used
-
The right to request deletion of personal information
-
The right to correct inaccurate personal information
-
The right to opt out of the sale or sharing of personal information for targeted advertising
-
The right to non-discrimination for exercising privacy rights
We do not sell personal information for monetary value.
However, certain advertising technologies may constitute “sharing” under applicable US privacy laws.
You may exercise your rights by contacting us at support@formosadoll.com.
California residents may designate an authorised agent to make requests on their behalf.
Cookie Policy
Last updated: 25 Apr 2025
1. What are cookies?
Cookies are small text files sent to your device to enhance your browsing experience, collect statistics, and personalise content and advertisements.
We may also use tracking technologies such as pixels, tags, scripts, and software development kits (SDKs) alongside cookies to understand how users interact with our site and advertising.
2. Types of cookies we use
Our website uses cookies to distinguish you from other users and to better understand how our site is used.
Cookies help us to:
- Estimate the size of our audience and understand how visitors use our site
- Remember your preferences and customize your experience accordingly
- Speed up your browsing and searches
- Recognize you when you return to the site
- These cookies allow us to enhance your experience and show you content that’s more relevant to your interests.
We use the following categories of cookies on our website:
- Essential cookies: Required for basic site functionality, such as shopping cart, checkout, and language preferences. While not mandatory for accessing the website, disabling these cookies may cause certain features, including checkout and account access, to malfunction. Required for basic site functionality (e.g. cart, login, language preferences)
- Analytics cookies: Used to collect anonymous visit data (e.g. Google Analytics with IP anonymisation)
- Advertising cookies: Used by Google Ads to show personalised advertisements
- Third-party cookies: Set by external providers (e.g. Google)
3. Consent and management
You are not required to accept cookies to browse our site. However, certain features (such as placing products in your shopping cart or completing an order) may not function properly without them.
Upon accessing the site, a banner will allow you to:
- Accept all cookies
- Reject non-essential cookies
- Customise your preferences
You can modify your consent at any time by clicking the "Cookie Preferences" link in the website footer.
4. Cookie duration
Cookies have varying lifespans, up to a maximum of 13 months. Essential cookies may only be deleted manually via browser settings.
5. Third-party services used
- Google Analytics 4: With IP anonymisation and aggregated tracking
- Google Ads: For remarketing and conversion tracking, subject to consent
6. Disabling cookies via browser
Most browsers allow you to delete or block cookies. Instructions are available on the official sites of Chrome, Firefox, Safari, Edge, etc.
7. Updates to the Cookie Policy
We reserve the right to update this notice. Any changes will be published on this page with the updated date.