Skip to content

Cart

Your cart is empty

Privacy policy

PRIVACY POLICY


United Arab Emirates / Hong Kong / Australia
Legal entity: Website
TINKERBELL TRADING - FZCO: www.trinityconcept.store
Legal entity: Jurisdictions
TINKERBELL TRADING - FZCO: United Arab Emirates / Hong Kong / Australia
Legal entity: Last updated
TINKERBELL TRADING - FZCO: 3 August 2026
Legal entity: Effective date
TINKERBELL TRADING - FZCO: 3 August 2026
 

1. Who we are and how to contact us
TINKERBELL TRADING - FZCO, trading as Trinity Concept (“we”, “us”, “our”), operates www.trinityconcept.store (the “Website”) and currently sells in-stock jewellery online for delivery to Australia. Products are manufactured in Mainland China and dispatched from Trinity Concept’s fulfilment warehouse in Hong Kong. Made-to-order and personalised enquiries are handled separately through WhatsApp Business.
Item: Legal entity
Details: TINKERBELL TRADING - FZCO
Item: Trading name
Details: Trinity Concept
Item: Place of registration
Details: Dubai, United Arab Emirates
Item: Commercial licence
Details: 89247
Item: Licensing authority
Details: Dubai Integrated Economic Zones Authority (DIEZA)
Item: Registered office
Details: Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates
Item: Website
Details: www.trinityconcept.store
Item: Privacy contact
Details: trinity.concept.contact@gmail.com

For processing governed by the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”), Trinity Concept acts as Controller. For processing governed by the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), Trinity Concept acts as data user. To the extent that the Australian Privacy Act 1988 (Cth) applies, Trinity Concept is an APP entity for the relevant handling of personal information. These terms are used only in their proper regional context.
2. Scope
This Policy applies when you browse or use the Website, create or manage an account, place or receive an order, provide product specifications, contact us, request a return or warranty remedy, upload evidence, submit a review, choose marketing or interact with cookies and similar technologies.
The collection-point notices in Section 15 form part of this Policy. The relevant notice should be displayed or linked at or before the associated Website form. Where Hong Kong law applies, those notices operate as Personal Information Collection Statements (“PICS”). Where the Australian Privacy Act applies, they support notification under APP 5. For UAE-facing forms, they provide short-form information under the UAE PDPL.
3. Personal data we collect
• Identity and contact data: name, title, country or region, billing and delivery address, email address and telephone number.
• Order and transaction data: Products, price, currency, discounts, order status, delivery and tracking details, gift messages, returns, refunds and correspondence.
• Product specifications: size, engraving, personalisation, made-to-order instructions and other information needed to produce or fulfil an order.
• Payment and fraud data: payment status, limited payment identifiers, billing data, authentication results and risk indicators. Where payment is processed directly by a payment provider, Trinity Concept does not receive full card numbers or CVV codes.
• Account data: login identifier, password hash, saved addresses, wish list, order history and preferences, if those functions are enabled.
• Customer-service and claims data: correspondence, order number, photographs or videos of Products and packaging, evidence of damage or non-conformity and remedy records.
• Review and content data: display name, rating, review, Product reference, purchase-verification status and optional media.
• Marketing data: channel choices, consent evidence, interests, purchase history, message interactions and suppression status.
• Technical data: IP address, browser, device, operating system, language, approximate region, pages viewed, sessions, security events and identifiers from cookies or similar technologies.
• Customs and verification data: identification or customs information only where objectively required for lawful international delivery, sanctions screening or another confirmed legal requirement.
We do not seek sensitive personal data for ordinary shopping. Do not send health information, unrelated identity documents, payment credentials or images of unrelated persons unless specifically requested for a lawful and necessary purpose.
4. Sources of personal data
• directly from you through Website forms, email or another confirmed channel;
• from a purchaser who provides a gift recipient’s delivery details;
• from payment, fraud-prevention, delivery, customs, manufacturing, Hong Kong fulfilment, CRM, email and customer-service providers involved in your transaction;
• automatically from the Website and enabled cookies or similar technologies; and
• from public authorities or public sources where lawful and necessary.
If you provide another person’s details, such as a gift recipient, you should have a lawful reason to do so and, where appropriate, direct that person to this Policy.
5. Why we process personal data
Purpose: Accept and perform orders
Typical data: Identity, contact, order, specifications, delivery and payment status
Why it is used: Take steps at your request; form and perform the sale contract.
Purpose: Manufacture and personalise
Typical data: Product specifications and minimum order references
Why it is used: Produce, quality-check and identify the Product.
Purpose: Payment, refunds and fraud prevention
Typical data: Billing, status, authentication and risk data
Why it is used: Process transactions, protect customers and prevent misuse.
Purpose: Delivery and customs
Typical data: Recipient, address, contact, order value/category and required customs data
Why it is used: Dispatch, insure, deliver and clear the shipment.
Purpose: Accounts and service
Typical data: Account data, order history and correspondence
Why it is used: Provide requested features and support.
Purpose: Returns, warranty and claims
Typical data: Order data, communications, photos/video and evidence
Why it is used: Assess and provide remedies; establish, exercise or defend rights.
Purpose: Reviews
Typical data: Display name, content, verification and optional media
Why it is used: Verify, moderate and publish content at your request.
Purpose: Website security and operation
Typical data: Technical, session, security and necessary-cookie data
Why it is used: Provide the requested service and protect systems.
Purpose: Analytics and advertising
Typical data: Usage data and identifiers
Why it is used: Only under the notice and choice required for the actual activity and jurisdiction.
Purpose: Marketing
Typical data: Contact, channel, consent, preferences and engagement
Why it is used: Only under valid consent/no objection or another permission expressly allowed by applicable law.
Purpose: Legal and regulatory compliance
Typical data: Order, transaction, tax, customs and verification data
Why it is used: Meet applicable obligations and respond to lawful requests.

6. Regional legal framework
6.1 United Arab Emirates
Where the UAE PDPL applies, personal data is processed with consent unless processing without consent is permitted by UAE law. For ordinary ecommerce activities, permitted cases may include taking steps at your request or performing a contract, fulfilling a legal obligation, establishing or defending legal claims, protecting your interests or another case expressly permitted by the UAE PDPL. We do not use “legitimate interests” as a general standalone ground under the UAE PDPL.
Where consent is used, it must be specific, clear and capable of withdrawal through an accessible method. Before processing begins, we provide information about the purposes, the sectors or establishments with which data is intended to be shared inside or outside the UAE and the safeguards used for cross-border processing.
6.2 Hong Kong
Where the PDPO applies, Trinity Concept follows the six Data Protection Principles: lawful and fair collection limited to necessary data (DPP1); accuracy and retention limitation, including controls over data processors (DPP2); use only for the stated or directly related purpose unless prescribed consent is obtained (DPP3); security and processor controls (DPP4); openness about privacy policies and practices (DPP5); and access and correction rights (DPP6).
At or before a relevant collection point, the applicable notice identifies the purpose, whether fields are obligatory or voluntary, the consequences of not providing obligatory information, the classes of transferees and how to request access or correction. Before personal data is used for direct marketing, we provide the notice and obtain the consent or indication of no objection required under Part 6A of the PDPO. Silence is not treated as consent.
6.3 Australia
To the extent that the Australian Privacy Act applies, and as a matter of our privacy practice, we follow the Australian Privacy Principles. We manage personal information openly and transparently (APP 1); allow anonymity or pseudonymity where practicable (APP 2); collect only information reasonably necessary for our functions and provide collection notices (APPs 3–5); use or disclose information only for the primary purpose or a permitted secondary purpose and manage direct-marketing choices (APPs 6–7); take reasonable steps before overseas disclosure (APP 8); maintain quality and security and destroy or de-identify information no longer needed where permitted (APPs 10–11); and provide access and correction procedures (APPs 12–13).
Whether the Privacy Act applies depends on facts including whether Trinity Concept carries on business in Australia, has the required Australian link and is covered by or exempt from the Act. This Policy does not assert that the Act applies merely because the Website is accessible in Australia.
Where identification is not necessary, you may browse the Website or make a general enquiry anonymously or using a pseudonym. Identification is normally required to accept payment, deliver jewellery, verify an order, prevent fraud or handle a return, complaint or warranty claim.
7. Who may receive personal data
• Manufacturers and production partners, for the specifications and minimum order data needed to manufacture, personalise, repair or quality-check a Product.
• Fulfilment and logistics partners, for recipient and shipment data needed to pick, pack, insure, dispatch and deliver a Product, including direct dispatch from Mainland China if used.
• Couriers, freight carriers and customs agents, for delivery, shipment and legally required customs information.
• Payment and fraud-prevention providers, for transaction, authentication, refund and dispute data.
• Ecommerce, hosting, cloud, security, authentication, CRM, email-marketing and customer-support platforms actually used by Trinity Concept;
• Google and Meta analytics, advertising and conversion technologies, only after the required disclosure and user choice have been implemented;
• Professional advisers, insurers and auditors, where necessary for advice, insurance, audit, disputes or corporate transactions.
• Public authorities, courts and regulators, where disclosure is required or permitted by applicable law.
A recipient’s role depends on its actual control over the purposes and means of processing. Some providers act on our instructions; others act independently and may provide their own privacy notice. We do not sell personal data for monetary consideration.
8. International processing and transfers
Depending on your location, the Products ordered and the providers involved, personal data may be processed in the United Arab Emirates, Mainland China, Hong Kong and Australia, and in other confirmed service-provider locations. Manufacturing data may be processed in Mainland China, fulfilment and dispatch data in Hong Kong, and delivery data in Australia. Not every route applies to every customer.
8.1 UAE transfers
Where the UAE PDPL governs a transfer, personal data is transferred only through a route permitted by UAE law. Depending on the destination and purpose, this may involve an approved level of protection, contractual safeguards, explicit consent, a transfer necessary for a contract or legal claim, or another statutory exception.
8.2 Hong Kong transfers
Section 33 of the PDPO is not currently in force. We nevertheless apply the DPPs to collection, use, retention and security, use contractual and organisational controls with overseas providers and may use the PCPD’s recommended model contractual clauses where appropriate.
8.3 Australian overseas disclosures
Where APP 8 applies, we take reasonable steps before disclosing personal information to an overseas recipient so that the recipient does not breach the APPs in relation to that information, subject to statutory exceptions. Likely countries include the UAE and, depending on the Product and providers, Mainland China, Hong Kong, Australia and other confirmed service locations.
9. Retention
We keep personal data only for as long as reasonably necessary for the purpose, applicable law and legitimate recordkeeping, dispute and security needs. Retention is based on the following criteria rather than a single universal period:
Category: Orders and delivery
Retention approach: For fulfilment, returns, warranty, tax/accounting/customs and potential claim periods.
Category: Payment and transaction records
Retention approach: For reconciliation, refunds, chargebacks, fraud prevention and applicable financial recordkeeping.
Category: Accounts
Retention approach: While active, then deleted or restricted under an approved inactivity rule, except records retained separately.
Category: Correspondence and complaints
Retention approach: Until resolved and for any additional period justified by claims, audit or regulatory requirements.
Category: Returns and warranty evidence
Retention approach: Until the remedy and dispute period ends; unnecessary photos are deleted or restricted.
Category: Reviews
Retention approach: While published or needed for moderation, verification and legal protection; removal requests are assessed.
Category: Marketing consents and suppression
Retention approach: Consent records for evidential and compliance purposes; limited suppression data may be kept to respect opt-out.
Category: Cookies and tracking
Retention approach: As stated in the live Cookie Settings register.
Category: Security and technical logs
Retention approach: For security, troubleshooting and fraud-prevention periods proportionate to risk.
Category: Legal holds
Retention approach: Longer where necessary for an investigation, legal claim or binding authority request.

10. Security and data incidents
We use measures appropriate to the nature and risk of the data, including access controls, authentication, encryption or secure transmission where appropriate, backups, logging, secure configuration, vendor review, confidentiality obligations and incident-response procedures.
If an incident occurs, we investigate, contain and remediate it, preserve appropriate records and assess the legal and practical notification steps required for the affected processing. Where UAE law requires notification to the competent authority or affected individuals, we follow the applicable requirements. Where the Australian Notifiable Data Breaches scheme applies, we assess and notify eligible data breaches as required. Hong Kong currently has no general statutory data-breach notification duty, but the PCPD recommends timely notification where appropriate and DPP4 security obligations continue to apply.
11. Your rights and choices
11.1 United Arab Emirates
• receive information about processing, recipients or recipient sectors, retention criteria and cross-border safeguards, subject to lawful exceptions;
• request transfer of data where statutory conditions are met;
• request correction, completion, erasure, restriction or cessation in permitted cases;
• object to certain automated processing and request human review where applicable;
• withdraw consent where processing relies on consent; and
• submit a complaint to the UAE Data Office or other competent authority where applicable.
11.2 Hong Kong
• ask whether we hold your personal data and make a valid data access request;
• request correction of inaccurate personal data; and
• require us to cease using personal data for direct marketing free of charge.
A valid data access request is handled under the prescribed form, identity, timing, fee and refusal rules. We respond not later than 40 calendar days after receiving a valid request, subject to the PDPO provisions on refusal or inability to comply. A permitted access fee must not be excessive. Correction and direct-marketing cessation requests are handled without charge.
11.3 Australia
Where the Privacy Act applies, you may request access under APP 12 and correction under APP 13. We respond within a reasonable period. We do not charge for making a request or for correction; any permitted charge for providing access will not be excessive. You may make a privacy complaint to Trinity Concept and, after giving us a reasonable opportunity to respond, to the Office of the Australian Information Commissioner (“OAIC”). Additional deletion or preference controls may be offered as a company practice but are not described as statutory rights where the Act does not provide them.
12. Requests and complaints
Email trinity.concept.contact@gmail.com with the subject “Privacy Request” or “Privacy Complaint”. Describe the request or concern and the relevant account, order or interaction. We may verify identity, clarify scope, protect third-party data, refuse or limit a request where law permits, and explain the reasons and available review or complaint route.
Where the relevant law applies and the matter is not resolved, you may complain to the UAE Data Office or other competent UAE authority, the Office of the Privacy Commissioner for Personal Data in Hong Kong, or the OAIC. For an Australian privacy complaint, you should generally complain to Trinity Concept first and allow a reasonable period for a response.
13. Children
The Website and online sales are intended for adults. A person under 18 may not place an order. If we learn that a child’s personal data was provided contrary to applicable requirements, we will take appropriate steps, including deletion or obtaining required authorisation.
14. Cookies and marketing communications
14.1 Cookies and similar technologies
The Cookie Policy explains strictly necessary, preference, analytics and marketing technologies. Cookie Settings allow you to accept all, reject non-essential technologies, choose categories and change your decision. Cookie choices are separate from email, SMS and messenger marketing choices.
14.2 Marketing is optional
Marketing is not required to browse, create an account or purchase. Trinity Concept currently plans to use email and WhatsApp Business for marketing communications, including personalised marketing based on interests, saved items, purchase history and interactions, where separately selected and legally permitted. Each active channel uses a separate unticked choice.
Order acknowledgements, Order Acceptance, payment and security notices, production updates, delivery tracking, returns, warranty correspondence and essential account notices are transactional. We do not use those communications as a vehicle for substantial promotional content without the relevant permission.
Channel consent does not authorise analytics cookies, advertising pixels, customer-list audience matching, enhanced conversions or a third party’s own marketing. Those activities require separate notice and any legally required choice in Cookie Settings or a separate permission.
14.3 Withdrawal and unsubscribe
• use the unsubscribe link in an email;
• use the stated STOP or opt-out instruction in an SMS or messenger message;
• change choices in the preference centre, if available; or
• contact trinity.concept.contact@gmail.com.
Withdrawal applies to the relevant channel and does not affect lawful processing before withdrawal. We retain a limited suppression record so the opt-out is respected. We do not require payment, account creation or unnecessary personal information to unsubscribe.
For commercial electronic messages with an Australian link, we identify the sender, provide a functional unsubscribe facility and honour unsubscribe requests within five working days. For Hong Kong commercial electronic messages, we provide accurate sender information and an unsubscribe facility and honour unsubscribe requests within ten working days. Where Hong Kong Part 6A direct-marketing rules apply, you may also require cessation of use of your personal data for direct marketing at any time and free of charge. UAE channel-specific consent, sender-identification, operator and do-not-call requirements are applied where relevant to the actual channel.
14.4 Marketing choices shown at collection points
Choice: Email
Public wording: I would like to receive Trinity Concept marketing by email about jewellery, collections, launches, restocks, events and offers. I can unsubscribe at any time.
Choice: SMS
Public wording: I would like to receive Trinity Concept marketing by SMS at the number provided. Message or carrier charges may apply. I can opt out at any time.
Choice: Messenger
Public wording: I would like to receive Trinity Concept marketing through WhatsApp Business. I can opt out using the stated method or by contacting Trinity Concept.
Choice: Personalised marketing
Public wording: I agree that Trinity Concept may use my stated interests, saved items, purchase history and interactions with selected Trinity Concept communications to tailor marketing through the channel(s) I selected.

The Website must not display a choice for a channel that Trinity Concept has not activated. Each choice must remain unticked by default and refusal must not prevent checkout or account creation.
15. Collection-point privacy notices
The following notices consolidate the Hong Kong PICS, Australian APP 5 notices and UAE short-form notices. The Website should display or prominently link the relevant notice at or before collection. Actual fields and providers must match the live form.
Collection point: Checkout and order
Information: Identity, contact, billing/delivery, order, gift message, specifications, payment status and necessary customs/verification data.
Purpose / consequences: Accept, produce, personalise, pay, deliver and support the order; prevent fraud; comply with customs, tax and legal requirements; handle returns and claims. Required fields are necessary for the relevant step; marketing, account creation and gift messages are voluntary.
Usual recipients: Payment/fraud; ecommerce/hosting/security/support; manufacturers/fulfilment; couriers/customs; advisers and authorities.
Collection point: Account
Information: Name, email, password hash, saved addresses, order history and preferences.
Purpose / consequences: Create and secure the account, remember choices, display order information and provide support. Required registration fields are necessary to create the account; optional preferences may be left blank. Account creation does not subscribe you to marketing.
Usual recipients: Ecommerce, hosting, cloud, authentication, security and support providers; authorities where required.
Collection point: Newsletter and marketing
Information: Name, email, telephone or named messenger, country/region, selected channel, interests, purchase history, interaction and consent evidence.
Purpose / consequences: Send selected Trinity Concept marketing and personalise it only where separately chosen. Voluntary; refusal or withdrawal does not affect shopping or accounts.
Usual recipients: Confirmed communication, CRM/preference and disclosed analytics/advertising providers where separately permitted.
Collection point: Contact form
Information: Contact details, message, order reference and chosen attachments.
Purpose / consequences: Respond, identify relevant orders, provide service and protect legal rights. Information reasonably necessary to answer is required; other comments are voluntary.
Usual recipients: Support/ecommerce, relevant operational providers, advisers and authorities.
Collection point: Returns, complaints and warranty
Information: Contact, order number, Product/delivery information, correspondence, requested remedy and evidence.
Purpose / consequences: Assess the return, defect, damage, warranty or complaint; provide a remedy; prevent fraud; establish or defend rights. Necessary information is required to assess the request.
Usual recipients: Support/ecommerce; manufacturer/fulfilment; courier/customs; payment/insurer; advisers and authorities.
Collection point: Photo or video upload
Information: Uploaded file, Product and packaging image, remaining file metadata, order reference and description.
Purpose / consequences: Verify the issue, prevent substitution or fraud, investigate with relevant providers and determine a remedy. Images are voluntary unless reasonably necessary to verify the issue. Do not upload unrelated persons, payment credentials, unnecessary identity documents or sensitive content.
Usual recipients: Support/ecommerce; relevant manufacturer, fulfilment, courier or insurer; advisers and authorities where necessary.
Collection point: Review submission
Information: Display name, review, rating, Product reference, purchase-verification status and optional media.
Purpose / consequences: Verify, moderate, publish and respond to the review and prevent unlawful or fraudulent content. Submission is voluntary; specified display/content fields may be required for publication.
Usual recipients: Review/ecommerce/hosting/moderation providers, Website visitors after publication, advisers and authorities for legal protection.

Likely overseas locations include the UAE and, depending on the Product and providers, Mainland China, Hong Kong, Australia and other confirmed provider locations. Checkout, account, contact, claim and review data is not used for direct marketing without the required separate notice and choice. Claim or evidence images are not used in marketing or materially different advertising without separate permission.
16. Reviews and user content
When you submit a review, we process it to verify, moderate and publish it. Publication does not grant Trinity Concept an unrestricted advertising right. Identifiable customer content is used in materially different marketing only under a separate permission where required.
17. Changes and contact
We may update this Policy to reflect legal, operational or technical changes. The Website will display the current version and last-updated date. Where a change materially affects an activity based on consent or another user choice, we provide appropriate notice and obtain a new choice where required.
Privacy Contact: TINKERBELL TRADING - FZCO, Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates; Email: trinity.concept.contact@gmail.com; WhatsApp Business: +995 511 50 91 24.