Privacy Policy

Last Updated: January 1, 2026

1. Introduction

International Digital Commerce Group Limited, a private company limited by shares incorporated in Hong Kong SAR, Business Registration Number 79486948, with its registered office at Room 1405, 135 Bonham Strand Trade Centre, 135 Bonham Strand, Sheung Wan, Hong Kong (the "Company", "we", "us", or "our"), operates the Lombaro brand and website at Lombaro.com (the "Website"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you visit our Website, purchase our products, or interact with our services. By using our Website or services, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Website or services.

2. Data Controller

For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable, the data controller is: International Digital Commerce Group Limited Room 1405, 135 Bonham Strand Trade Centre 135 Bonham Strand Sheung Wan, Hong Kong Business Registration Number: 79486948 Email: privacy@Lombaro.com

3. Information We Collect

3.1 Information You Provide to Us

We collect personal information that you voluntarily provide to us when you:

Create an Account

  • Name
  • Email address
  • Password (encrypted)
  • Date of birth (if required for age verification)
  • Account preferences

Place an Order

  • Billing name and address
  • Shipping name and address
  • Email address
  • Telephone number
  • Payment information (processed by third-party payment processors)
  • Order details and purchase history

Contact Us

  • Name
  • Email address
  • Telephone number
  • Message content
  • Any other information you choose to provide

Subscribe to Marketing Communications

  • Email address
  • Name (optional)
  • Communication preferences

Submit Reviews or User Content

  • Name or username
  • Email address
  • Review text and ratings
  • Photos or videos (if uploaded)

3.2 Information Collected Automatically

When you visit our Website, we automatically collect certain information about your device and browsing activity:

Device and Browser Information

  • IP address
  • Browser type and version
  • Operating system
  • Device type (desktop, mobile, tablet)
  • Screen resolution
  • Language preferences

Usage Information

  • Pages visited and content viewed
  • Date and time of visits
  • Referring website or source
  • Links clicked
  • Products viewed and added to cart
  • Search queries
  • Session duration and navigation paths

Location Information

  • Approximate geographic location based on IP address
  • Precise location (only if you grant permission)

3.3 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Payment Processors: Transaction information from Stripe, Airwallex, PayPal, and other payment service providers
  • Shipping Carriers: Delivery status and tracking information
  • Analytics Providers: Aggregated usage and demographic data
  • Social Media Platforms: If you interact with us on social media or use social login features
  • Fraud Prevention Services: Information to verify identity and prevent fraud
  • Marketing Partners: Information about your interactions with our marketing campaigns

3.4 Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing activity. For detailed information about the cookies we use and how to manage your preferences, please refer to our Cookie Policy.

4. How We Use Your Information

We use your personal information for the following purposes:

4.1 To Provide Our Services

  • Process and fulfill your orders
  • Manage your account and preferences
  • Communicate with you about your orders and account
  • Provide customer support and respond to inquiries
  • Process payments and prevent fraud
  • Arrange shipping and delivery
  • Process returns and refunds

4.2 To Improve Our Services

  • Analyze usage patterns and trends
  • Conduct research and development
  • Test new features and functionality
  • Optimize Website performance and user experience
  • Troubleshoot technical issues

4.3 To Communicate with You

  • Send order confirmations and shipping updates
  • Respond to your questions and requests
  • Send service announcements and updates
  • Send marketing communications (with your consent)
  • Conduct surveys and request feedback

4.4 For Marketing and Advertising

  • Send promotional emails and newsletters (with your consent)
  • Display personalized advertisements
  • Conduct marketing campaigns and promotions
  • Analyze marketing effectiveness
  • Retarget visitors with relevant ads

4.5 For Security and Fraud Prevention

  • Verify your identity
  • Detect and prevent fraud, abuse, and illegal activity
  • Protect the security of our systems and data
  • Enforce our terms and conditions
  • Comply with legal obligations

4.6 For Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Protect our legal rights and interests
  • Resolve disputes

5. Legal Basis for Processing (GDPR)

If you are located in the European Union, the United Kingdom, or another jurisdiction with similar data protection laws, we process your personal data based on the following legal grounds:

5.1 Contractual Necessity

Processing is necessary to perform our contract with you (e.g., to process your orders, provide customer support, and deliver products).

5.2 Legitimate Interests

Processing is necessary for our legitimate business interests, such as:

  • Improving our products and services
  • Analyzing usage and trends
  • Preventing fraud and ensuring security
  • Conducting marketing and advertising (where not based on consent)
  • Managing our business operations

We balance our legitimate interests against your rights and freedoms and will not process your data where your interests override ours.

5.3 Consent

Processing is based on your explicit consent, such as:

  • Marketing communications
  • Non-essential cookies
  • Sharing data with third parties for marketing purposes

You may withdraw your consent at any time by contacting us or using the unsubscribe mechanism in our communications.

5.4 Legal Obligation

Processing is necessary to comply with legal obligations, such as tax and accounting requirements, responding to legal requests, and complying with regulatory requirements.

6. How We Share Your Information

We may share your personal information with the following categories of recipients:

6.1 Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Payment Processors: Stripe, Airwallex, PayPal, and other payment service providers to process payments
  • Shipping Carriers: DHL, FedEx, UPS, and other carriers to fulfill and deliver orders
  • Cloud Hosting Providers: To host our Website and store data
  • Email Service Providers: To send transactional and marketing emails
  • Analytics Providers: Google Analytics and similar services to analyze Website usage
  • Customer Support Tools: To provide customer service
  • Marketing Platforms: To conduct marketing campaigns and advertising
  • Fraud Prevention Services: To verify identity and prevent fraud

These service providers are contractually obligated to protect your information and use it only for the purposes for which it was disclosed.

6.2 Business Transfers

If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your personal information may be transferred to the acquiring entity or successor. We will notify you of any such transfer and any choices you may have regarding your information.

6.3 Legal Requirements and Protection

We may disclose your information if required to do so by law or in response to:

  • Legal processes (subpoenas, court orders, legal proceedings)
  • Requests from government authorities or law enforcement
  • Protection of our legal rights and interests
  • Investigation of fraud, security issues, or illegal activity
  • Protection of the safety and security of individuals

6.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

6.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you with third parties for analytics, research, and marketing purposes.

7. International Data Transfers

We are based in Hong Kong and operate internationally. Your personal information may be transferred to, stored in, and processed in countries other than your country of residence, including Hong Kong, the United States, the European Union, and other jurisdictions where our service providers operate. These countries may have data protection laws that differ from those in your country. When we transfer your personal data to other countries, we take appropriate measures to ensure that your data is protected in accordance with this Privacy Policy and applicable data protection laws.

7.1 EU Data Transfers

If you are located in the European Union or the United Kingdom, we ensure that transfers of your personal data to countries outside the EU/UK are protected by appropriate safeguards, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms

You may request a copy of the safeguards we use for international transfers by contacting us at privacy@Lombaro.com.

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account Information: For the duration of your account plus a reasonable period thereafter, or as required by law
  • Order and Transaction Data: For at least 7 years for tax and accounting purposes, or as required by law
  • Marketing Communications: Until you unsubscribe or withdraw consent
  • Customer Support Records: For 3-5 years or as required by law
  • Website Usage Data: Typically 12-24 months, unless longer retention is required

When we no longer need your personal information, we will securely delete or anonymize it in accordance with our data retention policies and applicable laws. We may retain certain information for longer periods where required by law, to resolve disputes, enforce our agreements, or for legitimate business purposes.

9. Your Rights and Choices

9.1 Access and Portability

You have the right to request access to the personal information we hold about you and to receive a copy of your data in a structured, commonly used, and machine-readable format (data portability).

9.2 Correction and Update

You have the right to request that we correct or update inaccurate or incomplete personal information. You can update your account information by logging into your account or contacting us.

9.3 Deletion

You have the right to request that we delete your personal information in certain circumstances, such as:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent (where processing is based on consent)
  • You object to processing based on legitimate interests
  • The data has been unlawfully processed
  • Deletion is required by law

Please note that we may not be able to delete your information if we are required to retain it by law or for legitimate business purposes (e.g., to complete transactions, comply with legal obligations, or resolve disputes).

9.4 Restriction of Processing

You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the data or object to processing.

9.5 Objection to Processing

You have the right to object to processing of your personal information based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will stop processing your data for that purpose.

9.6 Withdraw Consent

Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.

9.7 Marketing Communications

You can opt out of receiving marketing communications by:

  • Clicking the "unsubscribe" link in our emails
  • Updating your communication preferences in your account settings
  • Contacting us at privacy@Lombaro.com

Please note that you cannot opt out of transactional or service-related communications (e.g., order confirmations, shipping updates).

9.8 Cookies and Tracking

You can manage your cookie preferences through your browser settings or our cookie consent tool. For more information, please refer to our Cookie Policy.

9.9 How to Exercise Your Rights

To exercise any of your rights, please contact us at: Email: privacy@Lombaro.com Mail: International Digital Commerce Group Limited, Room 1405, 135 Bonham Strand Trade Centre, 135 Bonham Strand, Sheung Wan, Hong Kong We will respond to your request within one (1) month, or as required by applicable law. We may request additional information to verify your identity before processing your request.

9.10 Right to Lodge a Complaint

If you are located in the European Union, the United Kingdom, or another jurisdiction with data protection authorities, you have the right to lodge a complaint with your local supervisory authority if you believe we have violated your data protection rights. EU/UK residents may contact their local data protection authority. A list of EU data protection authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en

10. Security of Your Information

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit (SSL/TLS)
  • Encryption of sensitive data at rest
  • Secure authentication and access controls
  • Regular security assessments and audits
  • Employee training on data protection and security
  • Incident response and breach notification procedures
  • Compliance with Payment Card Industry Data Security Standard (PCI DSS)

While we take reasonable measures to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. Please notify us immediately if you suspect unauthorized access to your account.

11. Children's Privacy

Our Website and services are not intended for individuals under the age of 18 (or the age of majority in their jurisdiction). We do not knowingly collect personal information from children. If you are under 18, please do not use our Website or provide any personal information to us. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information. If you believe we have collected information from a child, please contact us at privacy@Lombaro.com.

12. Third-Party Websites and Services

Our Website may contain links to third-party websites, services, or applications that are not owned or controlled by us. This Privacy Policy does not apply to third-party websites or services. We are not responsible for the privacy practices of third parties. We recommend that you review the privacy policies of any third-party websites or services you visit or use.

13. California Privacy Rights (CCPA)

If you are a California resident, you have certain rights under the California Consumer Privacy Act (CCPA):

13.1 Right to Know

You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which we use it, and the categories of third parties with whom we share it.

13.2 Right to Delete

You have the right to request that we delete your personal information, subject to certain exceptions.

13.3 Right to Opt-Out of Sale

We do not sell your personal information as defined by the CCPA. If our practices change, we will update this Privacy Policy and provide you with the right to opt out.

13.4 Right to Non-Discrimination

You have the right not to receive discriminatory treatment for exercising your CCPA rights.

13.5 Exercising Your Rights

To exercise your CCPA rights, please contact us at privacy@Lombaro.com. We will verify your identity before processing your request.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we will notify you by:

  • Posting a notice on our Website
  • Sending an email to the address associated with your account
  • Other appropriate means

Your continued use of our Website or services after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: International Digital Commerce Group Limited Data Protection Officer Room 1405, 135 Bonham Strand Trade Centre 135 Bonham Strand Sheung Wan, Hong Kong Business Registration Number: 79486948 Privacy Email: privacy@Lombaro.com General Email: info@Lombaro.com Website: www.Lombaro.com We will respond to your inquiries within a reasonable timeframe, typically within one (1) month, or as required by applicable law.