Privacy Policy

Effective date: 16 July 2025

This Privacy Policy explains how Crafty DIY handles personal data when you visit our pages, purchase or take part in the Little Stories in Shimmer, join our community, or contact our team.

1. Who We Are

Crafty DIY is operated by Grollth Company ("Crafty DIY," "we," "us," or "our"). Our course sales page is available at crafty-diy.com/shimmering-stories.

Email: [email protected]
Address: Room A11, 7/F, Block A, Superluck Industrial Centre Phase 2, 57 Sha Tsui Road, Tsuen Wan, N.T., Hong Kong

2. Scope

This Policy applies when you visit our website or course pages, create an account, enroll in the Little Stories in Shimmer, purchase a product or service, submit artwork, use our community, receive our communications, or otherwise engage with us online or offline. It applies worldwide, with additional disclosures for residents of the EEA/UK under GDPR and California under CCPA/CPRA.

3. Personal Data We Collect

Depending on how you use our services, we may collect identifiers and contact details; account and profile data; transaction, billing, order and course-enrollment data; course progress, assignments and community participation; support messages, reviews, survey responses and testimonials; marketing, analytics and referral data; IP address, browser, device, operating system, language, time zone and security logs; page views, clicks and navigation paths; approximate location derived from IP; artwork, images, documents, audio, video, comments and other content you submit; information from enabled social or single sign-on services; and optional sensitive information you voluntarily provide, such as accessibility needs.

Payment card numbers are handled by our payment processor and are not stored by us. We receive limited transaction details such as payment status, transaction ID, card type or last four digits where provided by the processor.

4. Sources of Data

We collect data directly from you; automatically through cookies, pixels, tags, local storage, SDKs and server logs; and from third parties such as payment processors, course-platform providers, analytics and advertising partners, referral partners, single sign-on providers and publicly available sources.

5. Legal Bases for Processing

Where GDPR or UK GDPR applies, we process data as necessary to perform our contract with you; for legitimate interests such as operating and securing the course, preventing fraud, understanding usage, improving content and conducting business operations; with consent for non-essential cookies, marketing, precise location and certain content uses; to meet legal obligations; and, rarely, to protect vital interests.

6. How We Use Personal Data

  • Provide accounts, course access, lessons, community features and customer support
  • Process payments, enrollments, refunds and transaction records
  • Send service, security, account and course communications
  • Personalize and improve the learning experience, site performance and content
  • Measure marketing, prevent fraud, enforce our terms and comply with law
  • Send optional marketing where permitted, with an unsubscribe option

7. Cookies and Similar Technologies

We may use first- and third-party cookies, pixels, tags, local storage and similar technologies for essential functionality, preferences, analytics, performance and advertising. Where required, we request consent before using non-essential cookies. You can block or delete cookies through your browser, although this may affect functionality. Cookie lifespans vary and may be described in our cookie banner or settings.

8. Payment Processing

Third-party payment processors handle card details according to their own privacy practices and PCI-DSS requirements. We use limited payment information for order fulfillment, fraud prevention, accounting and refunds.

9. Sharing and Disclosure

We do not sell personal information for money. We may share data with service providers supporting hosting, course delivery, video, email, analytics, advertising, payments, customer service and security; instructors, affiliates or partners needed to deliver requested services; regulators, courts, law enforcement and advisers where legally required; parties involved in a business transfer; and other parties with your consent. Content you post in a class community or live session may be visible to other participants.

Advertising-related disclosures of identifiers or usage data may be considered "sharing" under California law. Eligible users may opt out as described below.

10. International Transfers and Retention

Data may be transferred, stored and processed outside your country, including in Hong Kong, the United States, the EEA and the United Kingdom. Where required, we use safeguards such as Standard Contractual Clauses, data-processing agreements and appropriate technical measures.

We retain data only as long as reasonably necessary for the purposes described here. Account data may be kept while active and for up to seven years after closure; transaction records generally for seven to ten years; course submissions for the course duration and a reasonable period after; marketing data until opt-out or generally up to 24 months after the last interaction; and security logs typically for 12 to 24 months, subject to legal and operational needs.

11. Security and Data Breaches

We use appropriate measures such as encryption in transit, access controls, least-privilege permissions, password hashing, administrative multi-factor authentication, monitoring, backups, vendor review and vulnerability management. No method of transmission or storage is completely secure.

If a breach creates a legally reportable risk, we will investigate, contain and remedy it, and notify affected users and authorities within applicable legal timeframes.

12. Your Privacy Rights

Your rights depend on where you live and may be limited by law. EEA/UK residents may have rights of access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority. California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information and receive non-discriminatory treatment. Other jurisdictions may provide similar rights.

To exercise a right, email [email protected] with the subject "Privacy Rights Request." Include enough information to verify your identity and describe your request. Authorized agents may act where permitted with proof of authorization. We will respond within legally required timeframes.

13. Children, Tracking and Third-Party Services

Our services are generally intended for users aged 13 or over, or the applicable age of digital consent. We do not knowingly collect personal data from younger children without verifiable parental consent. Contact us if you believe a child submitted data without consent.

Our site does not currently respond to Do Not Track signals. Where legally required, we honor Global Privacy Control signals as an opt-out of sale or sharing. Third-party sites and services linked from our pages are governed by their own privacy policies.

14. Course Communities and Submitted Content

Artwork, comments, messages, reviews or other information shared in forums, class communities, galleries or live sessions may be visible to other users or the public. Do not share information you want to keep private. We may record live sessions for course access and quality where notice is provided.

15. Profiling, Controllers and Marketing

We may use limited profiling to personalize content, recommendations and marketing. We do not make solely automated decisions that produce legal or similarly significant effects without human involvement. Grollth Company is the controller of personal data processed through Crafty DIY and this course experience. Processors act under appropriate written arrangements where required.

You may unsubscribe from marketing emails using the link in the message or by contacting us. You may also adjust cookie and advertising preferences through available banners, browser settings and platform-level controls.

16. International Users

EEA/UK users may contact their local supervisory authority. In Hong Kong, we handle personal data in line with the Personal Data (Privacy) Ordinance principles relating to purpose, accuracy, retention, security, openness and access or correction.

17. Changes, Governing Law and Contact

We may update this Policy. Material changes will be posted with an updated effective date and additional notice or consent where required. If any provision is invalid, the remaining provisions remain effective.

This Policy is governed by the laws of Hong Kong, subject to mandatory rights in your jurisdiction. Questions, requests or concerns may be sent to [email protected] or mailed to Room A11, 7/F, Block A, Superluck Industrial Centre Phase 2, 57 Sha Tsui Road, Tsuen Wan, N.T., Hong Kong.

Revision history: Version 1.0 — 16 July 2025.

California Business-Purpose Disclosures

Categories that may be disclosed for a business purpose include identifiers to service providers, analytics or advertising partners and payment processors; commercial information to payment processors and operations partners; internet or network activity to analytics, advertising and security providers; approximate geolocation to analytics and security providers; and preference or interest inferences to marketing and analytics partners. We do not knowingly sell personal information of consumers under 16.

Crafty DIY
Little Stories in Shimmer