Privacy Policy

1. Introduction

At Hedge Club Shanghai (“we,” “us,” or “our”), accessible via hedgeclubsh.com, we are deeply committed to protecting your personal data and respecting your privacy. We believe that privacy is a fundamental right, and we take our responsibilities in processing and safeguarding your personal information seriously. This Privacy Policy outlines how we collect, use, store, share, and protect your personal data in accordance with applicable international data privacy laws, including but not limited to the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Scope and Data Controller

This Privacy Policy applies to all personal data collected through hedgeclubsh.com and associated digital services. Hedge Club Shanghai is the data controller determining the purposes and means of processing your personal data. Our processing activities are governed by this Policy, and users interacting with our website and services acknowledge the applicability of this Policy and the rights it extends to them under applicable laws.

3. Categories of Data Processed

We process the following categories of personal information, all of which are subject to protective measures:

a) Usage Data
We collect data on your interactions with our website, including browser type, IP address, device identifiers, date and time of access, pages visited, session duration, and referring URLs.

b) Account Data
If you create an account or make a booking through hedgeclubsh.com, we collect your full name, billing and shipping addresses, email address, and telephone number.

c) Profile Data
This includes preferences, past purchases, user behavior on the site, and other profile attributes derived from interactions with our website and services.

d) Communication Data
We collect correspondence sent through our contact forms, support inquiries, and message logs to maintain service quality and continuity.

e) Technical Data
We gather information about your device and operating system, device settings, mobile network data, and browser configurations.

f) Transaction Data
This includes payment transaction history, billing details, delivery and logistical information associated with any order or service.

g) Preference Data
We store information related to your communication and marketing preferences, as well as expressed product interests or consents.

4. Legal Bases for Processing

We process your personal data only when legally permitted to do so, based on the following justifications:

– Performance of a Contract: To fulfill our obligations in providing services you have requested.
– Legitimate Interests: For business operations, service improvement, fraud prevention, and security purposes.
– Consent: For sending marketing and promotional materials or placing non-essential cookies, where freely given consent is required.
– Legal Obligation: When we are legally required to retain or disclose data to comply with regulatory duties.

5. Your Rights Under Applicable Laws

Under the GDPR (for EU/EEA residents) and the CCPA (for California residents), you may exercise the following rights:

– Right of Access: Request details of personal data we hold.
– Right to Rectification: Request correction of inaccurate or incomplete data.
– Right to Erasure: Request deletion of data, provided it is not required for lawful purposes.
– Right to Restrict Processing: Limit processing in specific instances.
– Right to Data Portability: Receive your data in a structured, commonly used format for transmission to another controller.
– Right to Object: Oppose processing based on legitimate interest or direct marketing.
– Right to Non-Discrimination: Under the CCPA, you are entitled to equal service and price even if you exercise privacy rights.

These requests can be exercised by contacting us at [email protected].

6. Security Measures

We implement a range of technical and organizational measures designed to ensure the confidentiality, integrity, and availability of your personal data. Measures include:

– SSL encryption during transmission of data
– Role-based access control and authentication
– Regular data backups and redundancy protocols
– Staff privacy training and access limitation by necessity

7. International Data Transfers

Where personal data is transferred outside the jurisdiction in which it is collected—including outside the European Economic Area (EEA)—we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or compliance with relevant regional adequacy decisions.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, unless a longer retention period is legally required or justified. General retention periods include:

– Account and profile data: Retained until deletion by the user or inactivity beyond a specific period
– Transaction data: Retained for up to 7 years for tax and audit purposes
– Communication and support inquiries: Retained for 3 years for service continuity
– Website analytics data: Retained for up to 26 months for performance monitoring and optimization

9. Cookie Policy

We use cookies and similar tracking technologies to enhance user experience and monitor the use of our website. Cookies set on hedgeclubsh.com include:

– Essential Cookies: Necessary for site functionality, including login and security features
– Functional Cookies: Enable personalization and user interface settings
– Analytics Cookies: Help us understand user behavior and website performance (e.g., Google Analytics)
– Performance Cookies: Measure performance of pages and site features

10. Cookie Management and Compliance

Users are presented with a cookie banner on their first visit to our site. You may choose to accept all, reject non-essential cookies, or manage your preferences. In accordance with GDPR and CCPA, we do not activate non-essential cookies until user consent is obtained. You can also manage cookie preferences through your browser settings.

11. Protection for Children

Our website and services are not intended for, nor do we knowingly collect personal information from, children under the age of 13. If we discover that we have inadvertently gathered personal data from a child without verifiable parental consent, we will promptly delete such data in accordance with applicable legal requirements.

12. Changes to the Privacy Policy

We reserve the right to update this Privacy Policy at our discretion. Changes will be communicated via this webpage or through direct notice where appropriate. Continued use of hedgeclubsh.com following updates constitutes acceptance of the modified terms.

13. Contact

For inquiries, requests, or concerns regarding your personal data or this Privacy Policy, please contact us via email at [email protected]. We aim to respond promptly to fulfill your rights and ensure your privacy remains protected in accordance with all applicable laws.

Hedge Club Shanghai is dedicated to maintaining full compliance with global privacy standards including GDPR and CCPA. Your trust is important to us. Please reach out to us should you have any questions regarding how we protect your information.