Privacy Policy

Privacy Policy

— · —

Last updated: May 30, 2026

Your data is yours. This Privacy Policy explains what ArliaHair ("we", "our") collects, why we collect it, who helps us process it, and the rights you have under GDPR, CCPA/CPRA, and similar privacy laws.

1. Business Information

ArliaHair is operated by Yoseen Hair Limited, Business Registration No. 80004147, FLAT 1506, 15/F, CHEUNG FUNG COMMERCIAL BLDG, 21-25 CHEUNG SHA WAN ROAD, SHAM SHUI PO, HONG KONG 999077.

Website: ArliaHair.com. Privacy and data requests: privacy@arliahair.com. General customer support: support@arliahair.com.

2. What We Collect

Order details - name, billing address, shipping address, email, phone number, items ordered, order notes, and delivery information.

Payment details - handled by payment processors such as Stripe, PayPal, Shop Pay, Apple Pay, Google Pay, and other methods shown at checkout. Full card numbers do not touch or stay on our servers.

Account profile - email, hashed password, order history, saved addresses, and account preferences.

Subscriber preferences - your email or phone number if you opt in, plus engagement signals on the emails or messages we send.

Browsing context - IP address, device type, browser, pages visited, referring URL, cookie identifiers, and advertising or analytics events where permitted.

Care-team correspondence - emails, chat transcripts, order notes, photos you send for shade matching or quality review, and related support records.

3. How We Collect & Why

Some data you give us directly when you create an account, place an order, contact support, request shade help, answer a survey, or subscribe to marketing. Some is collected automatically by cookies, analytics tools, fraud-prevention tools, and similar technologies that help the site work securely and improve over time. Some comes from trusted partners as part of payment, delivery, customer support, or review collection.

Contract - to process payment, accept and fulfill orders, provide order updates, arrange delivery, handle returns or quality concerns, and provide customer support.

Legitimate interest - fraud prevention, site security, store improvements, internal analytics, service quality, and business recordkeeping.

Consent - for marketing emails, SMS where offered, non-essential cookies, and advertising technologies where consent is required.

Legal obligation - tax, accounting, regulatory compliance, lawful requests, and dispute handling.

4. Who We Share With

We share personal information only with service providers and partners that help us operate the store, fulfill orders, process payments, deliver parcels, provide support, collect reviews, run analytics, or comply with law. We do not sell personal information for money.

Shopify - e-commerce platform and order storage.

Stripe / PayPal / Shop Pay and similar payment providers - payment processing and fraud review.

International couriers, including FedEx, UPS, DHL, YunExpress, 4PX, USPS, and comparable carriers - delivery, tracking, customs paperwork, and carrier investigations.

Klaviyo or similar marketing tools - email and SMS only where you have opted in or where otherwise permitted by law.

Google Analytics / Meta Pixel and similar tools - analytics, advertising measurement, and attribution, subject to cookie settings and applicable law.

Judge.me or similar review tools - review invitation and publication where you choose to submit a review.

Gorgias / Zendesk or similar helpdesk tools - customer support and care-team correspondence.

Professional advisers, authorities, or legal recipients - where needed for compliance, claims, fraud prevention, or lawful requests.

5. California Privacy Notice

We do not sell personal information for money. Some analytics, advertising, or cross-context tracking cookies may be considered "sharing" under California privacy law. California residents may opt out of sale or sharing by adjusting cookie preferences where available, using browser privacy controls, or contacting privacy@arliahair.com.

California residents may request access, correction, deletion, portability, and opt-out rights as allowed by law. We will not discriminate against you for exercising privacy rights.

6. International Transfers

Our business is based in Hong Kong, and some service providers may process data in the United States, the European Economic Area, the United Kingdom, or other countries. Where required, we use appropriate safeguards such as Standard Contractual Clauses, data-processing agreements, and partner security controls so protection travels with the data.

7. How Long We Keep It

Order records - kept for 7 years or the period required for tax, accounting, consumer-rights, fraud-prevention, and dispute purposes.

Account data - kept while your account remains active, then deleted or anonymized within a reasonable period after account deletion, subject to legal retention and backup cycles.

Subscriber data - kept until you unsubscribe or withdraw consent, then suppressed or deleted subject to backup cycles and legal requirements.

Support records and quality photos - kept as long as needed to resolve the matter, improve service, defend claims, and meet legal obligations.

Cookies - kept according to the cookie type and your browser or cookie-preference settings.

8. Your Rights

Access - ask us for a copy of the personal data we hold about you.

Correction - ask us to correct inaccurate or incomplete information.

Deletion - request erasure, subject to legal retention, fraud-prevention, accounting, and dispute obligations.

Portability - receive your data in a machine-readable format where applicable.

Opt out of sale or sharing - we do not sell personal information for money, and you may opt out of advertising sharing where applicable.

Withdraw consent - at any time; previous lawful processing remains unaffected.

Marketing opt-out - use the unsubscribe link in our emails, follow the SMS opt-out instructions where SMS is offered, or contact support@arliahair.com.

Email privacy@arliahair.com and we will respond within the timeframe required by applicable law, usually within 30 days. If our reply does not feel right, you may lodge a complaint with your local data-protection authority.

9. Children's Privacy

ArliaHair is not directed to children. We do not knowingly collect personal data from anyone under 13, or under 16 in the EU/UK, without required consent. If you believe we have collected such data, contact us and we will remove it promptly.

10. Security

Data travels over TLS/HTTPS, payments are processed through PCI-DSS-compliant payment infrastructure, and we use reasonable administrative, technical, and organizational measures to protect personal information. No system is perfectly secure. If a verified incident requires notification, we will notify regulators and/or affected users within the timeframe required by applicable law.

11. Cookies

We use necessary cookies to run the site and may use analytics or advertising cookies to understand performance and measure campaigns. You can manage cookies through your browser settings and, where available, our cookie preference tool. Non-essential cookies are used subject to applicable consent requirements.

12. Updates to This Policy

Material changes will be posted here. Where required, we will also notify affected users before the changes take effect. Continuing to use the site after the effective date means you accept the updated version.

13. Contact

Privacy & data requests: privacy@arliahair.com. General inquiries: support@arliahair.com.

Mail: ArliaHair Privacy, Yoseen Hair Limited, FLAT 1506, 15/F, CHEUNG FUNG COMMERCIAL BLDG, 21-25 CHEUNG SHA WAN ROAD, SHAM SHUI PO, HONG KONG 999077.