Privacy Policy and Website & App FUTURE MALL HK Mobile Application Terms of Use
Privacy Policy
1. Our Commitment
We appreciate your trust in us. We are committed to protecting your privacy, taking all reasonable precautions, and complying with all applicable laws and regulations regarding the protection of personal data to safeguard your personal information from misuse. The purpose of this Privacy Policy is to help you understand the types of personal data we collect, how we use and protect your personal data, and your rights and choices.
2. Categories of Personal Data We Collect
The categories of personal data we collect include, but are not limited to:
a. Your title, name, gender, phone number, email address, residential address, mailing address, billing address, delivery address, or other contact information, your birth year, month, and date, your payment or credit card information, username and password, and any other personal data voluntarily provided by you; and
b. Your computer, mobile phone, or other electronic/communication device's IP address, real-time location information, browser settings, browsing history, websites that referred you to our platform, and other internet record information.
3. Collection of Your Personal Data
We may obtain your personal data through various means, such as:
a. When you shop at our online or physical stores;
b. When you participate in our events or promotions;
c. When you apply for or use our membership card or participate in any of our membership or promotional programs;
d. When you register an account with us;
e. When you participate in any surveys or marketing activities;
f. When you log in to visit our website, use our mobile app, or browse any of our social media pages;
g. When you use WiFi services at our stores or events;
h. When you contact us in person, by phone, email, or any social media platform to inquire or provide information;
i. When verifying your identity;
j. When you subscribe to our marketing or promotional materials.
You may choose not to provide the requested personal data, but if you choose not to, we may not be able to provide you with our products, services, or offers, or you may not be able to log into our platform or use certain features.
You need to ensure that the personal data provided is accurate, and you must contact us to update it if there are any changes to protect your membership rights. You have the right to request access to your personal data and to correct, update, or delete such data. If you reside in the European Union, you have additional rights regarding your personal data. Please refer to Section 11, "Data Subject Rights."
4. Purpose of Collecting Personal Data
Your personal data may be used for one or more of the following purposes ("Purposes"):
a. Communicate with you;
b. Verify your identity and any accounts you have opened with us, and manage or consolidate relevant accounts;
c. Manage any membership or other marketing, promotional offers, or corporate activities we participate in, including providing you with the benefits you are entitled to;
d. Process your product or service orders (e.g., retaining the contents of your shopping cart, making arrangements related to billing, payment, refunds, and delivery);
e. Handle and respond to your inquiries, suggestions, or complaints;
f. Conduct customer surveys or organize events for customers;
g. Provide customer service to you;
h. Conduct analyses to help us better understand customer needs and improve our services and product quality;
i. Personalize the content on our shopping website/mobile app and social networking/media platforms to provide you with a better customer experience;
j. Design specific promotional offers;
k. Conduct advertising campaigns, including targeted advertising;
l. Conduct direct marketing activities;
m. Fulfill our responsibility to maintain records of processing activities;
n. Comply with legal, regulatory, or compliance requirements, handle inquiries from law enforcement or regulatory bodies, or obtain legal advice; and
o. Any other purposes directly related to any of the above circumstances.
We will only collect personal data that is necessary to achieve the specified purpose or directly related to that purpose. If we intend to use personal data for purposes other than those mentioned above, we will obtain your consent before using your personal data.
5. Direct Marketing
We will use your personal data for direct marketing, including promotions and marketing of the Sa Sa Group (including all companies wholly owned by Sa Sa International Holdings Limited engaged in the business of selling cosmetics and beauty products). We will not provide your personal data to any third parties for direct marketing purposes.
If you wish to stop receiving information related to direct marketing activities, you can contact our customer service officer using the methods listed in the 'Contact Us' section below to indicate your preference or request that we change your preference (at no additional cost). If you receive information about direct marketing activities via email, please use the unsubscribe link provided to stop receiving messages.
For customers in Hong Kong, Singapore, and Macau, we will not use your personal data for direct marketing without your consent. We may use your personal data, such as your name, mobile number, email address, and/or residential address, to inform you about our latest products and/or promotional activities.
For customers in Singapore and Malaysia, we will use your personal data to provide goods and services to you, and you agree that we may process your personal data in accordance with this privacy policy. If you agree to our use of your personal data for advertising or direct marketing, we will continue to send you information related to direct marketing activities until you opt out of receiving such communications.
For customers in the EU, unless you object to receiving direct marketing communications, we rely on legitimate interests as the legal basis for using your personal data to directly market to you. You have the right to opt out of receiving messages related to direct marketing at any time. You can (a) contact our customer service officer using the methods described in "Contact Us" or (b) if you receive messages via email, click the unsubscribe link provided. We will properly record your decision, and your choice to opt out of receiving direct marketing messages will not affect the legality of how we have processed your personal data in the past.
6. Use of Your Personal Data
We will handle the information you provide in accordance with relevant laws and regulations (including but not limited to collecting, storing, retaining, using, transferring, and disclosing). We will ensure that your data is secure, accurate, and up-to-date, and will not retain it longer than necessary.
7. Legal Basis for Processing Personal Data of EU Customers
We have the following lawful bases to process your personal data:
Use of data in accordance with our legitimate interests
We may use your personal data in the pursuit of our legitimate interests, but these interests will not override any potential harm to you.
We believe that we have a certain legal basis for using your personal data, including but not limited to:
- Providing you with services, including verifying your identity and any accounts you open with us, managing any membership or other marketing activities, processing your product or service orders and retaining the contents of your shopping cart, making arrangements related to billing, payment, refunds, and deliveries, handling and responding to your inquiries, suggestions, or complaints, conducting analysis for other purposes, processing your personal data and carrying out direct marketing activities within your expectations.
- Fulfill our legal obligations (such as preventing money laundering and terrorist activities);
- Help us better understand our customers’ needs and improve the quality of our services;
- Ensure the smooth operation of our services;
- Help protect the security of our systems and prevent unauthorized access or cyberattacks; and
- Safeguard the commercial interests of our shareholders.
Consent
We may use your personal data with your consent. Your consent is valid under the following conditions:
- It is given voluntarily and without any pressure from us;
- You need to know what you are consenting to – we will ensure you have sufficient information;
- We will obtain your consent for each item – we will avoid requesting bundled consent so you clearly know what you are agreeing to;
- Your consent must be active and proactive – we will obtain your consent in a clear and unambiguous manner, such as providing checkboxes for you to tick.
You have the right to withdraw your consent at any time, and we provide detailed instructions on how to do so under the “Contact Us” section below.
Fulfilling Our Contractual Obligations
We may use your personal data to fulfill our contract with you, for example, we need your credit card and bank account information to process your payments.
Fulfilling Our Legal Obligations
In addition to fulfilling our contract with you, we may also use your personal data to comply with and fulfill our legal obligations.
8. Data Collected Automatically
Cookies are data stored by your browser on your computer or other internet-related devices when you browse websites. We use cookies for different purposes:
a. Necessary cookies. These cookies allow you to browse our website and its content, such as logging into the site or accessing protected areas, so they are essential. These cookies cannot be disabled; otherwise, the website will not function properly. However, these cookies do not store any personal information.
b. Functional cookies. These cookies are used to enhance your shopping experience. For example, they may remember the country you selected and your previous purchases for use during your next visit. The data collected by these cookies is anonymous and is not used to track your browsing activities on other websites. You can choose to disable them.
c. Targeting cookies. Most of these cookies are provided by third parties. They can record your settings, the websites you visit, and track your browsing activities on other websites. Examples of cookies we use include Google Analytics and Adobe Analytics. The data collected can be shared with other advertising networks for advertising purposes. Similarly, you can opt out of these cookies.
By continuing to use our website without changing your settings, you agree to our use of these cookies.
How to Control and Delete Cookies
You can set your browser to block all or some cookies. Please click the following link:
Chrome: https://support.google.com/chrome/answer/95647
Internet Explorer: https://support.microsoft.com/en-gb/help/17442/
Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
Safari: https://support.apple.com/kb/ph21411
Please note that if you change your browser to block certain cookies, you may not be able to access some parts of our website, and other services may also not function properly.
In addition to using cookies, we may also collect your information automatically through our mobile applications or online platforms, such as web server logs. Web server logs record your activities when using a mobile device or personal computer to browse websites. For example, web server logs can record the keywords you have searched for or the online links you have visited. They can also record your browser information, such as your IP address and the cookies placed in your browser by the server. Data collected automatically may be used for certain purposes.
9. CCTV
We have installed CCTV in our stores for security reasons. The data obtained from CCTV will only be used in accordance with the requirements of the Personal Data (Privacy) Ordinance and will not be retained longer than necessary.
10. Sharing of Data and How It Is Shared
We may need to disclose or transfer your personal data locally or overseas on a limited basis to SASA Group companies, third-party service providers, or business partners in order to achieve certain purposes. If personal data is to be transferred overseas, we will protect your personal data through contracts or other appropriate measures, and your personal data will be used to achieve the intended purposes in accordance with a standard no lower than that of your jurisdiction and under cross-border data transfer mechanisms in accordance with the data protection laws of your jurisdiction.
We may also disclose or transfer your personal data to other locations based on legal or regulatory requirements, or when necessary to protect our interests (to the extent permitted by law), for example, disclosing it to insurance companies in case of potential claims.
We also reserve the right to transfer your personal data in the event of a merger, acquisition, or corporate reorganization (to the extent permitted by law).
11. Rights of Data Subjects
You have the right to request a copy of the personal data we hold about you or to correct any personal data we hold that is inaccurate or incomplete. We will not unreasonably delay and will process your request within the personal data law time limits applicable in your jurisdiction (subject to any legal extensions). If we refuse your request to access or correct your personal data, we will explain the reasons for the refusal.
Singapore customers have the right to withdraw your consent for us to collect, use, or disclose your personal data at any time in writing through the channels listed under “Contact Us” below. Upon receiving a request to withdraw consent, we will cease collecting, using, or disclosing your personal data unless legally permitted. However, withdrawing consent may prevent us from continuing to provide products and services to you. You also have other rights concerning your personal data, including requesting a copy of your personal data, correcting or updating it, requesting us to stop using and disclosing it, or, in certain situations and except as otherwise limited or exempt, deleting the personal data we have collected about you.
Malaysian customers may exercise your statutory rights, including (i) objecting to direct marketing or (ii) notifying us to withdraw your consent through the channels listed under “Contact Us” below.
EU residents have the following rights under the General Data Protection Regulation (GDPR) at any time we hold or process your personal data:
i. Right to object
- You have the right to object to our processing of your personal data based on one of the following reasons: (i) our legitimate interests; (ii) the performance of a task carried out in the public interest or in the exercise of official authority; (iii) direct marketing to you; and/or (iv) for scientific, historical, research, or statistical purposes.
The above "legitimate interests" category is the most commonly applied reason in our relationship with you. If you object to our processing of your personal data on the grounds that we consider necessary, we will stop the relevant activities unless one of the following applies:
- Important legal basis outweighs your interests; or
- Required for the establishment, exercise, or defense of legal claims.
ii. Withdrawal of consent
- When we have obtained your consent to process your personal data for certain activities (such as automated personal analysis), you may withdraw your consent at any time unless we have another legal basis to continue processing your personal data. If we do, we will inform you; otherwise, we will stop the activity you have consented to.
iii. Submission of data subject access requests
- You may request that we provide the personal data we hold about you and request that we rectify, update, or delete such data. We may conduct inquiries regarding your request; we may refuse your request if permitted by law, but we will explain the reasons for the refusal. If we provide you with the personal data we hold about you and your request is clearly unfounded or excessive, we may charge you a fee; if you request additional copies, we will charge a reasonable administrative fee where permitted by law.
iv. Right to Deletion
You may request us to delete your personal data in certain circumstances. Generally, the data must meet one of the following criteria:
- The purpose for collecting and/or processing the data no longer exists;
- You have withdrawn your consent for us to process your personal data, and we have no reason to continue processing it;
- Your data has been processed unlawfully (e.g., not in accordance with the General Data Protection Regulation);
- Deletion is necessary to fulfill our responsibilities as a data processor in the EU or its member states; or
- We believe we have a legitimate interest in processing your personal data, but we cannot demonstrate that the rationale for continuing to process it outweighs your objection.
We can only refuse your deletion request based on the following reasons:
- Exercising the right to freedom of expression and information;
- Fulfilling legal obligations or performing tasks in the public interest or in the exercise of official authority;
- Reasons of public safety in the public interest;
- Archiving purposes, data collection, or statistical purposes;
- Establishing, exercising, or defending legal claims.
We will follow reasonable procedures to process your request for data deletion.
v. Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances. Upon accepting your request, we may only continue to store the data but cannot further process it until: (i) the situations outlined in footnote 1 are resolved; (ii) you give consent; or (iii) continuing processing is necessary to establish, exercise, or defend legal claims, protect the rights of others, or for reasons deemed important to the public interest by the EU or its member states.
You have the right to request the restriction of processing your personal data in the following situations:
- When you contest the accuracy of the data we are processing. In this case, processing of your personal data will be restricted until the accuracy of the data is verified;
- When you object to our legitimate interest in processing your personal data. In this case, you can request that we restrict processing of your personal data until our legitimate interest is verified;
- When we are processing your personal data unlawfully, but you prefer restriction of processing instead of deletion;
- When we no longer need to process your personal data, but you require it to establish, exercise, or defend legal claims.
If we have already shared your personal data with third parties, we will notify them of the restrictions unless it is impossible or involves disproportionate effort. We will also inform you before lifting any restrictions on processing.
vi. Right to Rectification
You also have the right to correct any inaccurate or incomplete personal data we hold about you, including by way of a supplementary statement. If we have already shared such personal data with third parties, we will inform the third parties of the correction unless it is impossible or involves disproportionate effort. You may also request details of such third parties from us. If we believe it is reasonable not to comply with your request, we will explain the reasons to you.
vii. Right to Data Portability
The right to data portability applies to (i) personal data we process automatically (i.e., without human intervention); (ii) personal data you provided; and (iii) personal data we obtained with your consent and for fulfilling a contract.
You have the right to transfer your personal data to another data processor, meaning you can transfer the details we hold about you to your employer or third parties. We will provide your data to you in a commonly readable format to enable the transfer, or we will directly transfer the data to the recipient.
viii. Right to Lodge a Complaint with a Supervisory Authority
You also have the right to lodge a complaint with the supervisory authority in your jurisdiction.
If you wish to exercise these rights or withdraw your consent for us to process your personal data (where our legal basis for processing is consent), the "Contact Us" section under this privacy policy provides detailed instructions on how to contact us. Please note that we will retain communications with you to handle the issues you raise.
If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with the supervisory authority responsible for data protection in your place of residence or contact our customer service representatives listed under "Contact Us."
12. Retention of Personal Data
We regularly review the personal data we hold. We will not retain your personal data for longer than necessary to fulfill the purposes for which it was collected. Except as permitted by applicable laws and regulations, we will delete personal data that has fulfilled its purpose within a reasonable period.
We will permanently delete your personal data after the retention period expires. However, some of your personal data may still be stored in our systems, such as data waiting to be overwritten. For our purposes, this data can no longer be used, meaning that even if it exists in electronic systems, our employees cannot retrieve or use it.
13. Data Protection
To protect and prevent your personal data from accidental, unlawful, or unauthorized access, we will maintain appropriate measures to ensure the confidentiality and security of the personal data we collect and process.
14. Third-Party Websites
This privacy policy only applies to us and not to any other third parties (including websites they operate). When clicking on links and/or advertisements that connect you to third-party websites or websites affiliated with our company, you will be subject to their privacy policies. While we support the protection of online privacy, we will not be responsible for any actions taken by third parties outside of our network.
15. Children's Policy
Our website and mobile applications are not intended for direct use by individuals aged 16 or under. If you are 16 years old or younger, you should use our website and mobile applications with the supervision of a parent or guardian and should not provide any personal data to us.
16. Amendments to the Privacy Policy
We may modify this privacy policy from time to time and publish it on our website and mobile platforms. You should review this privacy policy periodically to ensure you are aware of the latest version.
17. Contact Us
If you have any questions about this privacy policy or wish to exercise your rights to access and correct your personal data:
For online shopping, please contact our customer service representatives:
WhatsApp: +852-6379-4905, +852-6202-6393
Email: futuremall2025@gmail.com
Mail: FUTURE MALL Network Limited: Shop 01, Block AC, Yisheng Industrial Centre, 16 Shing Yip Street, Kwun Tong, Kowloon, Hong Kong, ZITOU NO.1 Shop, G/F
This privacy policy is available in both English and Chinese versions.
[1] You may request us to restrict the processing of your personal data in the following circumstances: (a) when you dispute the accuracy of the personal data we are processing about you. In this case, our processing of your personal data will be restricted until the accuracy of the data is verified; (b) when you object to our processing of your personal data based on legitimate interests. In this case, you may restrict our processing of your personal data until our legitimate interests are verified; (c) when we are processing your personal data unlawfully, but you choose to restrict our processing rather than deleting your personal data; (d) when we no longer need to process your personal data, but you require the data to establish, exercise, or defend legal claims.