1. Introduction
REBORN Feminine Wellness ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with our website and services.
This Privacy Policy applies to all visitors and users globally, and we comply with:
- Personal Data Protection Act 2010 (PDPA) — Malaysia
- General Data Protection Regulation (GDPR) — European Union
- California Consumer Privacy Act (CCPA/CPRA) — USA
- Australian Privacy Act 1988 & Australian Privacy Principles — Australia
Perfect Life Wellness Sdn Bhd (202001039611 / 1395932-U) is the data controller for all personal information collected through this website.
2. Information We Collect
2.1 Information You Provide Directly
- Identity & Contact: Name, email address, phone number, date of birth, gender, mailing address
- Appointment Data: Service preferences, appointment dates/times, health notes, skin conditions, treatment preferences
- Payment Information: Billing address and payment method (processed securely via Stripe — we do not store full credit card numbers)
- Communications: Messages through WhatsApp, email inquiries, and customer support conversations
- Marketing Preferences: Newsletter subscriptions, language preferences, and promotional interests
2.2 Information Collected Automatically
- Browsing Data: Pages visited, time on page, links clicked
- Device Information: IP address, browser type, operating system, device type
- Cookies & Tracking: Essential, analytics, marketing, and preference cookies
- Location Data: Country/region inferred from IP address (not precise GPS)
2.3 Third-Party Information
- Google Calendar: Event details and appointment confirmations
- Google Analytics: Aggregated user behavior and traffic data
- Gmail: Email address for confirmations and reminders
- Stripe: Payment transaction records and billing information
3. How We Use Your Information
Essential Service Functions
- Process and manage product orders and shipments
- Schedule, confirm, and manage appointments
- Send appointment reminders and follow-ups
- Process payments and generate invoices
- Provide customer support and handle complaints
- Prevent fraud and enhance security
Marketing & Communication
- Send promotional emails, SMS, and WhatsApp messages (only with your consent)
- Personalize your shopping and browsing experience
- Conduct surveys and gather feedback
Legal & Compliance
- Comply with applicable laws and regulations
- Fulfill tax and accounting obligations
- Respond to legal requests or investigations
- Protect our legal rights and prevent misuse
4. Legal Basis for Processing (GDPR — EU Users)
We process your personal data on the following legal bases:
- Consent: For marketing communications and non-essential cookies
- Contract Performance: To fulfill appointment and purchase obligations
- Legal Obligation: To comply with tax, accounting, and data protection laws
- Legitimate Interest: For website security, fraud prevention, and analytics
- Vital Interest: For health and safety in appointment-related services
You may withdraw consent at any time by updating your preferences or contacting us directly.
6. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Appointment Records | 3 years | Service history & complaints |
| Purchase / Order History | 5–7 years | Tax, accounting, warranty |
| Customer Account | Active + 1 year | Service continuity & audit |
| Payment Information | 7 years | Legal / tax compliance |
| Marketing Communications | Until unsubscribed | Ongoing consent |
| Website Analytics | 26 months | Google Analytics default |
| Cookies | Session to 2 years | As per cookie type |
After retention periods, data is securely deleted or anonymized. You can request deletion at any time (subject to legal obligations).
7. Your Rights
All Users
- Right to Access — Request a copy of your personal data
- Right to Correct — Update or correct inaccurate information
- Right to Delete — Request deletion of your data
- Right to Opt-Out — Unsubscribe from marketing communications
- Right to Complain — Lodge complaints with your local data protection authority
GDPR Additional Rights (EU Users)
- Right to Restriction — Restrict processing of your data
- Right to Portability — Receive data in a portable format
- Right to Object — Object to processing for legitimate interests
To exercise your rights, contact: admin@reborn.global
8. Security Measures
- Encryption: TLS/SSL encryption for data in transit
- Access Controls: Limited employee access to personal data on a need-to-know basis
- Secure Payment Processing: PCI-DSS compliance via Stripe
- Regular Security Audits: Periodic vulnerability assessments
- Secure Backups: Encrypted regular data backups
No security system is completely impenetrable. While we take every precaution, we cannot guarantee absolute security.
10. International Data Transfers
Our services may involve transferring your data to servers in different countries. For EU users, we use Standard Contractual Clauses (SCCs) approved by the European Commission. All service providers are bound by data processing agreements.
11. Children's Privacy
REBORN services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware of such collection, we will delete it promptly. Parents or guardians with concerns should contact admin@reborn.global.
12. Marketing & Communications Preferences
- Email: Click "Unsubscribe" in any marketing email
- SMS / WhatsApp: Reply "STOP" to opt out
- Account Settings: Update notification preferences in your profile
- Contact Us: Email admin@reborn.global
We will honor your preferences promptly. You will still receive transactional emails for confirmed orders and appointments.
13. California-Specific Disclosures (CCPA/CPRA)
California residents have the following additional rights:
- Right to Know — Categories and specific pieces of personal information collected
- Right to Delete — Request deletion (with limited exceptions)
- Right to Correct — Correct inaccurate personal information
- Right to Opt-Out — Opt out of data sales (we do not sell your data)
- Right to Non-Discrimination — No penalties for exercising your rights
Under California Civil Code § 1798.83 ("Shine the Light"), California residents may request disclosure of third-party marketing sharing. Contact admin@reborn.global.
14. Australia — Privacy Act Compliance
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988. Australian residents can lodge complaints with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
- APP 1 — Transparent management of personal information
- APP 2 — Lawful and fair collection
- APP 5 — Notification about collection and use
- APP 6 — Disclosure limitations
- APP 11 — Data security
- APP 12–13 — Access and correction rights
15. Malaysia — PDPA Compliance
As a Malaysia-based business, we comply with the Personal Data Protection Act 2010 (PDPA). This includes obtaining proper consent, limiting data use to stated purposes, maintaining data accuracy, and allowing access and correction requests.
Malaysian residents may lodge complaints with the Personal Data Protection Commissioner (PDPC) at www.pdpc.gov.my.
16. Contact Us — Privacy Inquiries
REBORN Feminine Wellness
Perfect Life Wellness Sdn Bhd
Company Registration: 202001039611 (1395932-U)
Email: admin@reborn.global
We will respond to all privacy requests within 30 days as required by law.
17. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal requirements, business practices, or services. We will notify you of material changes via email or a prominent website notice, and update the "Last Updated" date at the top. Your continued use of our Services after changes constitutes acceptance of the updated policy.