Privacy policy
Last updated: April 2026
This Privacy Policy explains how MomijiHQ Ltd (“we”, “us”, “our”) collects, uses, stores and protects personal information when you use www.lovemomiji.com (the “Website”) or purchase products from our store.
By using the Website or placing an order, you agree to the practices described in this Privacy Policy.
We may update this Policy from time to time. Any changes will be posted on this page with an updated date.
1. Who We Are
This Website is operated under licence by MomijiHQ Ltd (Company No. 07966442).
The Momiji brand and all associated intellectual property are owned by Mallet & Chisel Limited (Company No. 04125951), registered at Lifford Hall, Kings Norton, Birmingham B30 3JN, United Kingdom.
You can contact us at: https://lovemomiji.com/en/contact-us
Or email us at: help@momijihq.com
MomijiHQ Ltd is the Data Controller for the purposes of UK GDPR and, where applicable, EU GDPR.
2. The Information We Collect
We collect two types of information:
2.1 Personal information you provide
-
Name
-
Billing and delivery address
-
Email address
-
Phone number
-
Payment method details (we do not store full card numbers)
-
Order history
-
Account information (if you create an account)
-
Social media interaction data (if you engage with us via Instagram or Facebook, including through quiz flows or click-to-message campaigns)
2.2 Device and browsing information
Collected automatically through cookies and similar technologies:
-
IP address
-
Browser type and device type
-
Pages viewed and time stamps
-
Referring and exit pages
-
Purchase and browsing behaviour (used for personalisation and marketing)
This helps us improve the Website and personalise your experience.
3. How We Use Your Information
3.1 To fulfil your order (contractual necessity)
-
Processing payments
-
Shipping your order
-
Providing order updates
-
Handling returns or customer service enquiries
3.2 To send you Momiji news (legitimate interest or consent)
If you sign up for emails or messages, we’ll send updates about new releases, competitions, events and exclusive offers. You can unsubscribe at any time via the link in any email, or by contacting us directly.
3.3 To comply with legal obligations
Including tax, fraud prevention, and responding to lawful requests.
3.4 To improve our Website and services
We analyse browsing behaviour to understand how customers use our site. This may include using automated tools to generate product recommendations.
3.5 To run advertising and measure its performance
We use Meta (Facebook and Instagram) and TikTok to serve advertisements to potential and existing customers. To do this, we share limited data with these platforms — such as page views, add-to-cart events and purchase completions — via advertising pixels or APIs installed on our Website.
This data is used to measure the performance of our advertising, build audiences for future campaigns, and show relevant ads to people who have visited our Website. Meta and TikTok each act as independent data controllers for their own processing. You can manage your advertising preferences via your account settings on each platform.
Meta’s Privacy Policy: https://www.facebook.com/privacy/policy/
TikTok’s Privacy Policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
3.6 Automated systems, profiling and recommendations
We use automated systems, including AI-powered tools, to analyse browsing and purchase behaviour so we can personalise your experience and recommend products that might be of interest to you. We rely on legitimate interests as our lawful basis for this processing.
We do not use automated decision-making that produces legal effects or similarly significant impacts on you (for example, we do not use automation alone to make decisions about credit, eligibility, or differential pricing).
4. Legal Bases for Processing
Under UK GDPR (and EU GDPR where applicable), we rely on:
-
Contractual necessity — to process your order and provide customer service
-
Legitimate interests — for marketing to existing customers, analytics, personalisation and fraud prevention
-
Consent — for email marketing sign-ups, non-essential cookies and Meta advertising where required
-
Legal obligation — for tax records, fraud reporting and responding to regulatory requests
5. Sharing Your Information
We share your data only with trusted partners who help us operate the Website, fulfil your orders, and market our products. We require all partners to handle your data securely and only for the specific purpose for which it is shared.
Order fulfilment & payments
-
Shopify — our ecommerce platform (stores order, customer and payment data)
-
Shopify Payments, PayPal, Klarna — payment processing
-
Warehouse and fulfilment partners — for shipping your order
Email marketing & automation
-
Klaviyo — our email marketing and automation platform. We share your name, email address, purchase history and browsing behaviour with Klaviyo to send order communications and, where you have consented, marketing emails. Klaviyo is based in the United States and participates in the UK Extension to the EU-US Data Privacy Framework. Privacy Policy: https://www.klaviyo.com/legal/privacy/privacy-notice
Social messaging & engagement
-
ManyChat — our Instagram messaging and automation platform. If you interact with us via Instagram DMs or click-to-message campaigns, ManyChat processes your Instagram username, message content and any information you provide during those interactions. ManyChat is based in the United States. Privacy Policy: https://manychat.com/legal/privacy
Advertising
-
Meta (Facebook / Instagram) — we use Meta’s advertising tools, including the Meta Pixel and/or Conversions API, which share limited behavioural data about Website visitors with Meta for ad measurement and targeting. See Section 3.5 for further detail. Privacy Policy: https://www.facebook.com/privacy/policy/
-
TikTok — we use TikTok’s advertising tools, including the TikTok Pixel, which shares limited behavioural data about Website visitors with TikTok for ad measurement and targeting purposes. TikTok is based in the United States (operated by TikTok Inc.). Privacy Policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
Website & analytics
-
Website developers — for technical maintenance and development
-
Analytics providers — to understand how customers use our site
Other tools
From time to time we may use additional third-party tools to help us operate our business. Where any such tool processes your personal data, we will ensure appropriate data processing agreements are in place and will update this Policy to reflect any material additions.
We do not sell your personal data.
6. Cookies & Tracking Technologies
We use cookies, log files, tags and pixels on our Website. Under UK law, cookies fall into three categories:
-
Strictly necessary — essential for the Website to function (e.g. your shopping basket, login session). These do not require your consent.
-
Analytics and performance — used to understand how visitors use our site. Under the DUAA 2025, some first-party analytics cookies may be used without prior consent provided you can easily opt out.
-
Advertising and tracking — including the Meta Pixel, which tracks activity on our Website and shares it with Meta for advertising purposes. These require your explicit consent, collected via our cookie banner.
You can manage your cookie preferences at any time via our cookie banner or your browser settings.
More information about cookies: http://www.allaboutcookies.org
7. Klarna Payments
If you choose Klarna at checkout, certain personal information will be shared with Klarna so they can assess your eligibility and tailor payment options. Klarna’s Privacy Policy applies to this processing: https://www.klarna.com/uk/privacy/
8. Your Rights
Under UK GDPR (and EU GDPR where applicable), you have the right to:
-
Access your personal data
-
Correct inaccurate data
-
Delete your data (subject to legal retention requirements)
-
Restrict processing
-
Object to processing, including direct marketing
-
Request a copy of your data (data portability)
-
Withdraw consent at any time, where we rely on consent as our lawful basis
8.1 How to exercise your rights
You can exercise your rights by logging into your account, emailing us at help@momijihq.com, or using our contact form at https://lovemomiji.com/en/contact-us. We will respond within one month.
8.2 How to make a data protection complaint to us
If you have a concern about how we handle your personal data, you have the right to raise it with us directly. Please email help@momijihq.com with the subject line “Data Protection Complaint”. We will acknowledge your complaint within 30 days and keep you informed of progress and outcome.
If you are not satisfied with our response, you may escalate your complaint to the Information Commissioner’s Office (ICO) at https://ico.org.uk/. If you are based in the EU, you may also contact your local data protection authority.
We must retain financial records for 6 years for legal reasons.
9. How We Store & Protect Your Data
We use:
-
Encrypted connections (HTTPS)
-
Secure payment gateways
-
Access controls
-
Data minimisation practices
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by law.
10. Children’s Data
Our Website is not intended for children under 13 (or under 16 for visitors in the European Union). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at help@momijihq.com and we will delete it promptly.
11. Third‑Party Links
Our Website may contain links to external sites. We are not responsible for the privacy practices of those websites and encourage you to review their own privacy policies.
12. International Transfers
Some of our service providers are based outside the UK. Where we transfer personal data internationally, we ensure appropriate safeguards are in place:
-
Klaviyo (USA) — UK Extension to the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs)
-
ManyChat (USA) — Standard Contractual Clauses (SCCs)
-
Meta (USA) — Standard Contractual Clauses (SCCs) and participation in the EU-US Data Privacy Framework
-
Shopify (Canada / USA) — Canada benefits from a UK adequacy decision; US-based processing relies on SCCs
-
TikTok (USA) — Standard Contractual Clauses (SCCs)
For any additional processors we use, equivalent safeguards will be in place.
13. Legal Compliance & Disputes
This Privacy Policy is governed by the laws of England & Wales.
If you believe your data has been mishandled, you may complain to the Information Commissioner’s Office (ICO): https://ico.org.uk/. If you are based in the EU, you may contact your local data protection supervisory authority.
14. Data Controller Contact
Cameron Read — Data Controller
MomijiHQ Ltd
Email: help@momijihq.com
Contact form: https://lovemomiji.com/en/contact-us
15. Changes to This Privacy Policy
We keep this Policy under regular review. Any updates will be posted on this page with a revised “Last updated” date. We encourage you to check back periodically.
This policy was last substantively revised in April 2026 to reflect the Data (Use and Access) Act 2025, the addition of Klaviyo, ManyChat and Meta to our technology stack, and updated international transfer disclosures.