隐私政策
Effective Date: January 4, 2026
Applicable Law: This Privacy Policy is formulated in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia and relevant regulations issued by the Personal Data Protection Department (JPDP) of Malaysia.
CozyTeaCorner ("we", "us", "our") operates the Shopify store cozyteacorner.myshopify.com (the "Store") and is committed to protecting the privacy and personal data of our customers ("you", "your") in Malaysia. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal data when you access or use our Store, purchase our products, or interact with our services. By accessing or using our services, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy.
1. Types of Personal Data We Collect
We may collect the following types of personal data from you in the course of providing services to you:
1.1 Personal Identification Data
-
Basic personal information: Full name, gender, date of birth, nationality, and identification document details (e.g., Malaysian IC number, passport number) (if required for customs clearance or order verification).
-
Contact information: Email address (e.g., your registered email or cozyteacorner@outlook.com for communication), phone number, residential address, shipping address, and billing address.
1.2 Transaction and Order Data
-
Order details: Order number, product purchased, quantity, price, payment amount, order date, delivery date, and order status.
-
Payment information: Payment method (e.g., credit card, PayPal, Maybank2u), last 4 digits of credit card number (we do not store full credit card information; payment processing is handled by authorized third-party payment service providers), and transaction records.
1.3 Technical and Usage Data
-
Device information: Device type, operating system, browser type and version, IP address, MAC address, and unique device identifiers.
-
Usage data: Pages you visit on our Store, time and duration of visits, click-through rates, search queries, browsing history, and information about how you interact with our products and services.
-
Cookies and tracking data: We use cookies and similar tracking technologies (e.g., web beacons) to collect information about your browsing behavior. For details, please refer to Section 6 "Cookies and Similar Technologies".
1.4 Other Relevant Data
-
Communication records: Content of emails, messages, or calls between you and our customer service team (e.g., inquiries, complaints, return/refund requests).
-
Marketing preferences: Your preferences for receiving marketing communications (e.g., newsletters, promotional offers) and your opt-in/opt-out records.
-
Data provided voluntarily: Information you submit through surveys, reviews, feedback forms, or social media interactions with our Store.
2. Purposes of Collecting and Using Personal Data
We collect and use your personal data for the following legitimate purposes, which are necessary to fulfill our contractual obligations to you or to achieve our legitimate business objectives:
-
Processing and fulfilling your orders: Verifying your identity, processing payments, arranging delivery, updating order status, and providing after-sales services (e.g., returns, refunds, replacements).
-
Providing customer support: Responding to your inquiries, resolving complaints, handling disputes, and providing you with information about our products and services.
-
Sending marketing communications: Sending you newsletters, promotional offers, new product announcements, and other marketing materials that may be of interest to you, provided that you have given your explicit consent.
-
Improving our products and services: Analyzing user behavior and feedback to optimize the design and functionality of our Store, enhance product quality, and develop new products or services that meet your needs.
-
Ensuring the security of our services: Detecting and preventing fraud, unauthorized access, cyberattacks, and other security risks; complying with relevant security regulations and protecting the legitimate rights and interests of you and our Store.
-
Complying with legal and regulatory obligations: Fulfilling obligations under Malaysian laws and regulations (e.g., tax filing, customs clearance, record-keeping requirements) and responding to requests from competent authorities (e.g., courts, regulatory bodies).
-
Conducting business analysis and research: Anonymizing and aggregating personal data to conduct market research, statistical analysis, and business planning, which will not identify you individually.
3. How We Disclose and Share Personal Data
We will not disclose or share your personal data with any third party except in the following circumstances:
-
With your explicit consent: We will share your personal data with third parties only if you have given your prior explicit consent, and we will inform you of the purpose and scope of the sharing.
-
With service providers: We may share your personal data with authorized third-party service providers who assist us in providing services to you, such as: We will enter into confidentiality agreements with these third-party service providers, requiring them to process your personal data only in accordance with our instructions and relevant laws and regulations, and to take adequate security measures to protect your personal data.
-
Payment processors (e.g., PayPal, Stripe) to process payments securely;
-
Logistics and delivery companies (e.g., Pos Malaysia, GDEX) to arrange order delivery;
-
IT service providers to maintain the operation and security of our Store;
-
Marketing service providers to send marketing communications (with your consent);
-
Audit and accounting firms to fulfill financial and audit obligations.
-
-
For legal and regulatory purposes: We may disclose your personal data to comply with legal obligations, respond to legal proceedings, or protect the legitimate rights and interests of our Store, you, or other third parties (e.g., preventing fraud or illegal activities).
-
In the event of business transfer: If we undergo a merger, acquisition, restructuring, sale of assets, or other business transfer, your personal data may be transferred to the successor entity, provided that the successor entity will comply with this Privacy Policy and relevant laws to protect your personal data.
-
Anonymized or aggregated data: We may share anonymized or aggregated data (which cannot identify you individually) with third parties for market research, academic research, or other legitimate purposes.
4. Storage and Protection of Personal Data
4.1 Storage Period
We will store your personal data only for the period necessary to fulfill the purposes stated in this Privacy Policy or as required by Malaysian laws and regulations. After the storage period expires, we will securely delete or anonymize your personal data to ensure that it no longer identifies you.
4.2 Storage Security
We take appropriate technical and organizational measures to protect your personal data from unauthorized access, use, disclosure, modification, loss, or damage. These measures include but are not limited to:
-
Implementing data encryption technologies (e.g., SSL/TLS encryption) to protect data during transmission and storage;
-
Using secure servers and access control systems to restrict access to personal data (only authorized personnel have access to your personal data);
-
Regularly updating and maintaining security software and systems to prevent cyberattacks;
-
Conducting security training for employees to enhance their awareness of data protection;
-
Establishing emergency response plans for data breaches to minimize the impact of breaches.
However, please note that no data transmission or storage method is 100% secure. We will do our best to protect your personal data, but we cannot guarantee absolute security. You should also take appropriate measures to protect your personal data (e.g., not disclosing your account password to others).
5. Your Rights Regarding Personal Data
Under the Personal Data Protection Act 2010 (PDPA) of Malaysia, you have the following rights regarding your personal data held by us:
-
Right of access: You have the right to request access to your personal data held by us, including the purpose of processing, the categories of data, and the third parties with whom the data has been shared.
-
Right of correction: You have the right to request correction of any inaccurate or incomplete personal data held by us.
-
Right to withdraw consent: If you have given consent for us to process your personal data for a specific purpose (e.g., marketing), you have the right to withdraw your consent at any time. Withdrawing consent will not affect the legality of data processing conducted before the withdrawal.
-
Right to erasure (right to be forgotten): Under certain circumstances (e.g., the data is no longer necessary for the purpose of processing, or you withdraw consent and there is no other legal basis for processing), you have the right to request erasure of your personal data.
-
Right to data portability: You have the right to request us to provide your personal data in a structured, commonly used, and machine-readable format, or to transmit the data to another data controller (where technically feasible).
-
Right to object to processing: You have the right to object to the processing of your personal data for direct marketing purposes or for scientific/historical research or statistical purposes, where such processing is likely to cause substantial damage or distress to you.
-
Right to complaint: If you believe that our processing of your personal data violates the PDPA or this Privacy Policy, you have the right to file a complaint with us or the Personal Data Protection Department (JPDP) of Malaysia.
To exercise any of the above rights, please contact us at cozyteacorner@outlook.com with the subject line "Personal Data Rights Request - [Your Full Name]". You need to provide sufficient information to verify your identity (e.g., order number, registered email, phone number), and we will process your request within 30 days of receiving it (or within a longer period if required by law, and we will inform you of the reason for the delay).
6. Cookies and Similar Technologies
6.1 What Are Cookies
Cookies are small text files stored on your device (computer, mobile phone, tablet) when you access our Store. They help us recognize your device, remember your preferences, and improve your browsing experience. We may also use similar technologies such as web beacons, pixels, and local storage.
6.2 Types and Purposes of Cookies We Use
-
Necessary cookies: These cookies are essential for the operation of our Store. They enable you to navigate the Store, use its features (e.g., adding products to the cart, processing payments), and access secure areas. Without these cookies, our services cannot be provided normally. We do not need your consent to use necessary cookies.
-
Performance and analytics cookies: These cookies collect information about how you use our Store (e.g., which pages you visit most often, whether you encounter errors). We use this information to analyze and improve the performance of our Store, optimize user experience, and conduct market research. These cookies do not identify you individually.
-
Functionality cookies: These cookies allow our Store to remember your preferences (e.g., language settings, shipping address) and provide personalized features. They may also be used to remember your login status (if you have an account with us) to avoid repeated login.
-
Marketing cookies: These cookies are used to track your browsing behavior on our Store and other websites, and to send you targeted marketing communications (e.g., promotional offers, new product information) that may be of interest to you. We will only use marketing cookies if you have given your explicit consent.
6.3 Managing Cookies
You can manage or delete cookies through your browser settings. Most browsers allow you to block or delete cookies, but please note that blocking necessary cookies may affect the functionality of our Store and your browsing experience. For more information on how to manage cookies, please refer to the help documentation of your browser.
7. Third-Party Links and Services
Our Store may contain links to third-party websites or services (e.g., social media platforms, payment service providers, logistics companies). This Privacy Policy does not apply to these third-party websites or services. We are not responsible for the privacy practices or content of third parties. We recommend that you review the privacy policies of these third parties before accessing or using their services.
8. Children's Privacy
Our products and services are not intended for children under the age of 13. We do not intentionally collect personal data from children under the age of 13. If we become aware that we have collected personal data from a child under the age of 13 without the consent of a parent or guardian, we will immediately delete the relevant data and contact the parent or guardian to inform them of the situation.
9. Changes to This Privacy Policy
We reserve the right to modify or update this Privacy Policy at any time to comply with changes in Malaysian laws and regulations (e.g., amendments to the PDPA) or adjustments to our business operations. Any changes will be posted on this page with an updated effective date. If the changes significantly affect your rights and interests, we will notify you via email (sent to your registered email address) or through a prominent notice on our Store at least 7 days before the changes take effect.
We encourage you to review this Privacy Policy periodically. Your continued access to or use of our services after the changes take effect constitutes your acceptance of the revised Privacy Policy.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, the processing of your personal data, or the exercise of your data rights, please contact our data protection officer (DPO) through the following channels:
-
Email: cozyteacorner@outlook.com
-
Shopify Store Message: Through the "Contact Us" section on cozyteacorner.myshopify.com
-
Business Hours: Monday to Friday, 9:00 AM - 6:00 PM (Malaysia Time, GMT+8); excluding public holidays in Malaysia
We will respond to your inquiry within 30 days of receiving it. If you are not satisfied with our response, you may file a complaint with the Personal Data Protection Department (JPDP) of Malaysia.