Privacy

1. Introduction

At Choco & Friends (“we”, “our”, “us”), your privacy matters. This Privacy Policy

explains how we collect, use, and protect your information when you visit our website,

shop online, or interact with us. By using our services, you consent to this policy.

 

2. Information We Collect

We may collect:

● Personal Information: name, email, phone number, billing/shipping address,

payment details.

● Order Information: products purchased, order history, payment confirmations.

● Technical Data: IP address, browser type, device type, cookies, browsing activity.

● User-Generated Content: reviews, comments, uploaded images.

● Marketing Preferences: newsletter sign-ups, campaign responses.

 

3. How We Use Your Information

● To process and fulfill orders.

● To communicate with you about purchases, updates, and promotions.

● To personalise your shopping experience.

● For analytics and website improvements.

● For fraud prevention, legal compliance, and dispute resolution.

 

4. Legal Basis (NZ/AU + GDPR Alignment)

We process data based on:

● Consent (marketing emails, cookies).

● Contract (to fulfill orders).

● Legitimate Interest (fraud prevention, improving services).

● Legal Obligation (tax, accounting requirements).

 

5. Data Sharing

We may share data with:

● Service Providers: payment processors, shipping carriers, email platforms.

● Analytics/Advertising Partners: e.g. Google Analytics, Meta Ads (with consent).

● Legal Authorities: where required by law.

● We never sell your personal information.

 

6. Cookies & Tracking

We use cookies and similar tools to:

● Keep items in your cart.

● Remember preferences.

Analyse website traffic.

Run targeted ads (Google, Meta, TikTok).

●  You may disable cookies in your browser, but some site features may not work properly.

 

7. International Data Transfers

● If your data is transferred outside your country (e.g. AU, NZ, UK, USA), we apply

safeguards such as GDPR Standard Contractual Clauses.

 

8. Data Retention

● Order records: kept for 7 years (legal requirement).

● Marketing data: kept until you opt out.

● Inactive accounts: deleted after 24 months of inactivity.

 

9. Your Rights

Depending on your location (NZ Privacy Act, GDPR, CCPA), you may:

● Access your data.

● Correct inaccurate data.

● Request deletion.

● Restrict or object to processing.

● Opt-out of marketing at any time.

● To exercise your rights, contact us at: hello@chocoandfriends.com

 

10. Data Security

We take reasonable precautions to protect your data:

● SSL encryption for payments.

● Secure servers with restricted access.

● Regular malware scans and audits.

● No method is 100% secure, but we follow best practices.

 

11. Policy Updates

We may update this Privacy Policy from time to time. Changes take effect upon posting.

Last updated: 27th September 2025.

 

12. Contact Us

If you have any questions or concerns:

● Email: hello@chocoandfriends.com