Who we are
This Privacy Policy applies to dollupboutique.com (the “Site”), operated by Doll Up Boutique Limited, BRN C18159019, VAT 27646277, registered in Quatre Bornes, Mauritius. We are the “data controller” of the personal information described below.
For any privacy-related question, contact us at [email protected].
What we collect
We collect only the information needed to run the shop and serve our customers:
- Account info: first name, last name, email, password (hashed), and optionally phone number — when you register an account.
- Order info: billing and shipping address, phone, items ordered, payment method, and order notes you add.
- Wishlist & cart: the items you save are stored against your account if signed in, otherwise locally in your browser.
- Communications: the content of messages you send us by email, WhatsApp, Instagram or Facebook.
- Technical data: device, browser, IP address, pages visited, and timestamps — collected automatically through cookies and server logs to keep the site fast and secure.
How we use your data
We use your data to:
- Process and deliver your orders, and contact you about them.
- Provide customer support before and after sale.
- Operate features such as account, wishlist, order tracking and saved addresses.
- Send transactional emails (order confirmations, delivery updates, password resets).
- If you opted in: send marketing emails about new drops, sales and giveaways. You can unsubscribe at any time.
- Improve the site, prevent fraud, and meet our legal obligations.
Legal bases
Under the Mauritius Data Protection Act 2017, we process your data on the following bases:
- Contract — to fulfil your order and account.
- Consent — when you opt in to marketing emails or non-essential cookies.
- Legitimate interest — to keep the site secure, prevent abuse, and improve our service.
- Legal obligation — when we must keep records (e.g. for tax or accounting).
Who we share data with
We don't sell your data. We share it only with the providers we need to run the shop:
- Hosting & infrastructure: Coolify, Cloudflare.
- Couriers: our delivery driver and Mauritius Post — to deliver your parcel.
- Payment proof channels: Juice, bank transfer, myT Money — when you send proof of payment.
- Email service (when enabled) — to send transactional and (if you opted in) marketing emails.
- Authorities — if compelled by law (police, courts, tax authorities).
Each of these only receives the minimum data needed for the task.
How long we keep it
Account data is kept for as long as your account is active. Order data is kept for up to 10 years to meet accounting and tax obligations. Marketing data is kept until you unsubscribe. Server logs are typically purged within 90 days.
Cookies
We use cookies and similar technologies for three things:
- Strictly necessary — to make the site work (login session, cart, security).
- Functional — to remember your preferences (region, recently viewed).
- Analytics — to understand which pages people use most so we can improve them. We don't use ad-tracking cookies.
You can disable cookies in your browser, but some parts of the site (cart, checkout, login) won't work without the necessary ones.
Your rights
Under the Mauritius Data Protection Act 2017 you have the right to:
- Ask what data we hold about you (right of access).
- Have inaccurate data corrected (rectification).
- Have your data erased when no longer needed (deletion).
- Restrict or object to certain uses (e.g. marketing).
- Receive a copy of your data in a portable format.
- Withdraw consent at any time, where we relied on consent.
- Lodge a complaint with the Mauritius Data Protection Office.
To exercise any of these rights, email [email protected]. We'll respond within 30 days.
Security
We use industry-standard measures — HTTPS encryption, hashed passwords, role-based admin access, and regular backups — to protect your data. No system is perfect, so if we ever discover a breach that affects you we will notify you and the Data Protection Office without undue delay.
Children
The site is intended for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, contact us and we'll delete the account.
International transfers
Some of our service providers (e.g. hosting, email) are based outside Mauritius. When data is transferred abroad we ensure it is to providers that offer an adequate level of data protection.
Changes to this policy
We may update this policy occasionally. The “Last updated” date at the top will reflect the most recent change. Material changes will be communicated by email or a notice on the site.
Contact
Doll Up Boutique Limited
Quatre Bornes, Mauritius
Email: [email protected]
WhatsApp: +230 5941 6359
