Wai Wai Sar Sar

Privacy Policy

Last Updated: 9/20/2025

Introduction

Welcome to our e-commerce platform ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site.

Information We Collect

Personal Information

We collect personal information that you voluntarily provide to us when you:

  • Account Registration: Name, email address, phone number, and password
  • Profile Information: Address, city, zip code, country, and profile image
  • Order Processing: Shipping and billing information, payment details
  • Customer Support: Information you provide when contacting our support team

Automatically Collected Information

We automatically collect certain information when you visit our website:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent on pages, click patterns, referral sources
  • Session Data: Authentication tokens, session identifiers, user preferences
  • Technical Data: Server logs, error reports, performance metrics

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Maintain your login session and shopping cart
  • Analytics Cookies: Understand how you use our website (Google Analytics)
  • Preference Cookies: Remember your settings and preferences
  • Security Cookies: Protect against fraud and unauthorized access

You can control cookie settings through your browser preferences, but disabling certain cookies may affect website functionality.

How We Use Your Information

Service Provision

  • Process and fulfill your orders
  • Manage your account and profile
  • Provide customer support
  • Send order confirmations and shipping updates

Communication

  • Send marketing communications (with your consent)
  • Respond to your inquiries and support requests
  • Send important service updates and notifications

Security and Fraud Prevention

  • Verify your identity and prevent unauthorized access
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations and enforce our terms

Analytics and Improvement

  • Analyze website usage and performance
  • Improve our products, services, and user experience
  • Conduct research and development

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

Service Providers

We share information with trusted third-party service providers who assist us in:

  • Cloud Storage: DigitalOcean Spaces for product image storage
  • Database Services: MySQL database hosting
  • Analytics: Google Analytics for website analytics
  • Error Monitoring: Sentry for application monitoring
  • Payment Processing: Payment processors (when implemented)

Legal Requirements

We may disclose your information if required by law or if we believe such action is necessary to:

  • Comply with legal processes or government requests
  • Protect our rights, property, or safety
  • Prevent fraud or security threats
  • Enforce our terms of service

Data Security

We implement appropriate technical and organizational security measures to protect your personal information:

Technical Safeguards

  • Encryption: Passwords are hashed using bcrypt
  • Secure Headers: CSP, X-Frame-Options, X-XSS-Protection
  • HTTPS: All data transmission is encrypted
  • Access Controls: Role-based access restrictions
  • CSRF Protection: Cross-site request forgery prevention

Administrative Safeguards

  • Access Logging: All data access is logged and monitored
  • Regular Audits: Security reviews and vulnerability assessments
  • Staff Training: Privacy and security awareness training
  • Incident Response: Procedures for handling security breaches

Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

Access and Portability

  • Request access to your personal information
  • Receive a copy of your data in a portable format
  • Request correction of inaccurate information

Deletion and Restriction

  • Request deletion of your personal information
  • Request restriction of processing
  • Object to certain types of processing

Communication Preferences

  • Opt out of marketing communications
  • Update your communication preferences
  • Unsubscribe from email lists

To exercise these rights, please contact us using the information provided in the "Contact Us" section below.

Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain business records

Retention Periods

  • Account information: Until account deletion
  • Order data: 7 years (for tax and legal compliance)
  • Marketing data: Until consent is withdrawn
  • Analytics data: 26 months (Google Analytics default)

Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date
  • Sending email notifications for material changes

Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Email: [email protected]

Address: [Your Company Address]

Phone: [Your Phone Number]

For data protection inquiries, you can also contact our Data Protection Officer at: [email protected]

Compliance

This Privacy Policy is designed to comply with applicable privacy laws, including:

  • GDPR (General Data Protection Regulation) - EU
  • CCPA (California Consumer Privacy Act) - California, USA
  • PIPEDA (Personal Information Protection and Electronic Documents Act) - Canada
  • Other applicable regional privacy laws

This Privacy Policy is effective as of the date listed above and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.