Privacy Policy
WorldcupBox Privacy Policy
Effective Date: March 20, 2026
Welcome to WorldcupBox!
We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose your personal information, and the rights you have. By using our website (the "Site"), you agree to the terms of this Privacy Policy.
WorldcupBox is a globally operating cross-border e-commerce independent station, covering China, the United States, the European Union, and other countries and regions. We strictly comply with applicable privacy laws, including the Personal Information Protection Law of China (PIPL), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA).
1. Information We Collect
1.1 Information You Provide Directly
-
Account Information: When you register an account, we collect your name, email address, and password.
-
Order Information: When you purchase a gift box, we collect your shipping address, phone number, and payment information (payment information is collected directly by third-party payment processors; we do not store your full payment card number).
-
Contact Information: When you contact customer service or participate in activities, we collect the content of your communications.
1.2 Information Collected Automatically
When you visit the Site, we automatically collect certain information, including:
-
Device Information: IP address, browser type, operating system, device identifiers.
-
Usage Data: Browsing behavior, click records, time spent on pages, referring URLs.
-
Cookies and Similar Technologies: We use cookies to remember your preferences, analyze traffic, and personalize content.
1.3 Sensitive Personal Information
Under applicable laws, certain information is considered sensitive personal information, including:
-
Financial account information (used only for payment processing)
-
Precise geolocation information (collected only with your authorization)
-
Personal information of children under 14 (we do not knowingly collect it)
We process sensitive personal information only when there is a specific purpose and necessity, and with strict protection measures.
2. How We Use Your Information
We collect and use your personal information only as necessary for the purposes described in this Privacy Policy:
| Purpose | Legal Basis (GDPR) | Processing Type (PIPL) |
|---|---|---|
| Process your orders and complete delivery | Performance of a contract | Necessary for contract performance |
| Communicate order status and respond to inquiries | Performance of a contract / Legitimate interest | Necessary for contract performance |
| Send you marketing information (with your consent) | Your consent | Separate consent obtained |
| Improve website functionality and user experience | Legitimate interest | Necessary for contract or based on consent |
| Fraud prevention and transaction security | Legitimate interest / Legal obligation | Fulfillment of legal obligations |
| Comply with legal requirements | Legal obligation | Fulfillment of legal obligations |
We follow the principle of minimum necessity, collecting only what is required for the above purposes.
3. Information Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
3.1 Service Providers
We work with carefully selected third-party service providers, including:
-
Logistics partners: such as DHL, FedEx, for order delivery
-
Payment processors: such as Stripe, PayPal, for payment processing (we do not store your full payment card information)
-
Analytics providers: such as Google Analytics, for analyzing website traffic
-
Customer service system providers: for handling your inquiries
These service providers may only access the information necessary to perform their functions and are obligated to protect your information in accordance with our instructions and applicable law.
3.2 Legal Requirements
We may disclose your information if required by law or in good faith belief that it is necessary to:
-
Comply with legal processes or government requests
-
Protect our rights, property, or safety
-
Protect the rights, property, or safety of users or the public
3.3 Business Transfer
In the event of a merger, acquisition, asset sale, or reorganization, your information may be transferred as part of the assets. We will notify you via website notice or email and require the recipient to continue to honor this Privacy Policy.
4. Cross-Border Data Transfer
WorldcupBox is a global business. Your personal information may be transferred to jurisdictions outside your country/region, including China, the United States, and the European Union.
4.1 Transfer Safeguards
We implement the following safeguards to ensure the legality of cross-border transfers:
-
Standard Contractual Clauses (SCCs): Sign data processing agreements containing EU and China SCCs with overseas recipients
-
Transfer Impact Assessment (TIA): Assess the legal environment of the recipient's country
-
Separate Consent: Obtain your separate consent before transferring your personal information overseas (where required by law)
4.2 Data Localization
For users in China, we store personal information primarily on servers located in China. If we need to transfer it overseas, we strictly comply with the requirements of the Personal Information Outbound Transfer Security Assessment Measures, including applying for a security assessment when required.
5. Your Rights
Depending on your jurisdiction, you may have the following rights:
| Right | Description | GDPR | PIPL | CCPA/CPRA |
|---|---|---|---|---|
| Right to know | Know what information we collect and how we use it | ✓ | ✓ | ✓ |
| Right to access | Obtain a copy of your personal information we hold | ✓ | ✓ | ✓ |
| Right to rectify | Correct inaccurate personal information | ✓ | ✓ | ✓ |
| Right to delete (to be forgotten) | Request deletion of your personal information | ✓ | ✓ | ✓ |
| Right to restrict processing | Restrict how we process your information | ✓ | ✓ | ✗ |
| Right to data portability | Obtain your information in a structured format and transfer it | ✓ | ✓ | ✗ |
| Right to object | Object to processing based on legitimate interests, including marketing | ✓ | ✓ | ✓ (opt-out) |
| Right to withdraw consent | Withdraw your consent at any time | ✓ | ✓ | ✓ |
| Right to non-discrimination | No discrimination for exercising your rights | ✓ | ✓ | ✓ |
To exercise your rights, please contact us at luyi20261688@gmail.com. We will respond to your request within the time period required by applicable law (usually 30 days).
6. Children's Privacy
We do not knowingly collect personal information from children under 14 (or the applicable age under other laws). If we discover that we have inadvertently collected personal information from a child, we will take immediate steps to delete it. Parents or guardians who believe their child has provided us with personal information should contact us immediately.
7. Data Security
We implement industry-standard security measures to protect your personal information:
-
Encryption: TLS 1.3+ for data in transit, AES-256 for data at rest
-
Access Controls: Strict role-based access management, minimizing internal access
-
Security Audits: Regular vulnerability scanning and penetration testing
-
Employee Training: All employees receive regular data privacy and security training
However, no internet transmission or electronic storage method is 100% secure.
8. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law:
-
Account information: Until a reasonable period after you close your account or until you request deletion
-
Order information: For the time necessary to fulfill tax, accounting, and legal obligations (typically 5-7 years)
-
Marketing preferences: Until you unsubscribe
-
Cookie data: As specified in our Cookie Policy
After the retention period expires, your personal information will be deleted or anonymized.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your browsing experience:
-
Necessary cookies: Enable basic functionality of the site; cannot be disabled
-
Functional cookies: Remember your preferences and settings
-
Analytics cookies: Help us understand how visitors interact with the site (e.g., Google Analytics)
-
Marketing cookies: Used for personalized advertising and marketing content
You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
Please see our complete Cookie Policy for more information.
10. Privacy Policy Updates
We may update this Privacy Policy from time to time to reflect legal changes or business adjustments. Material changes will be notified to you by:
-
Prominent notice on the homepage
-
Email notification (if you have a valid email in your account)
-
Updating the "Effective Date" at the top of the policy
We encourage you to review this Privacy Policy periodically to understand how we protect your information.
11. Contact Us
If you have any questions, comments, or complaints about this Privacy Policy or our data processing practices, please contact us at:
WorldcupBox Privacy Team
Email: luyi20261688@gmail.com
Mailing Address (USA):
123 Soccer Way, Suite 100
Los Angeles, CA 90001
USA
Attn: Legal Department
Response Time: We will acknowledge your request within 48 hours and provide a substantive response within 30 days.
Supplemental Information for Specific Jurisdictions
EU Users (GDPR)
If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection supervisory authority. Our lead supervisory authority is [Irish Data Protection Commission / other].
Data Controller: WorldcupBox Ltd.
Legal Bases for Processing: As described in Section 2, we process your personal information based on your consent, performance of a contract with you, our legitimate interests, or compliance with legal obligations.
California Users (CCPA/CPRA)
If you are a California resident, you have the right to:
-
Know the categories and sources of personal information we collect
-
Request deletion of your personal information (subject to exceptions)
-
Opt out of the sale of your personal information (we do not sell it)
-
Not be discriminated against for exercising your rights
Categories of personal information collected: Identifiers (name, email, IP address), commercial information (purchase history), internet activity, geolocation data.
To exercise your rights, please call our toll-free number: [phone number] or email us at luyi20261688@gmail.com.
China Users (PIPL)
If you are located in China, you have all the rights under the Personal Information Protection Law, including:
-
The right to request an explanation of this Privacy Policy
-
The right to request portability of your personal information (subject to CAC conditions)
-
The right to request deletion under circumstances such as when the purpose has been achieved, it is no longer necessary, you withdraw consent, or processing is illegal
Sensitive Personal Information Processing: When we process your sensitive personal information (e.g., payment information), we have obtained your separate consent and informed you of the necessity and impact on your rights.
Personal Information Protection Officer: Mr. Zhang
Contact: luyi20261688@gmail.com
Thank you for trusting WorldcupBox. We are dedicated to protecting your privacy so you can collect World Cup memories with confidence.