1. Scope and responsibility
1.1. This Privacy Policy explains how Datamoll collects, uses, stores, shares and protects personal data when a person uses datamoll.com, an account, an official bot, an API, Support, payment functions or another official Datamoll service (together, the “Platform”).
1.2. Datamoll is responsible for the processing described here as Platform operator and, where applicable, determines the purposes and means of that processing.
1.3. Terms defined in the Datamoll Terms of Sale and Use (the “Terms”) have the same meaning in this Policy. This Policy is one of the three public legal documents identified in clause 1.5 of the Terms.
1.4. This Policy is a notice and does not treat every use of the Platform as consent. Datamoll relies on the appropriate legal basis for each purpose and requests consent separately where consent is required.
1.5. The Platform is intended for persons aged 18 or older and authorized representatives of organizations. Datamoll does not knowingly offer accounts to children.
2. Data we process and its sources
2.1. Account and contact data may include username, email address, contact handle or telephone number, internal user identifier, language, account settings, registration date and account status.
2.2. Authentication and acceptance data may include password hashes, external login identifiers, session and security identifiers, accepted document versions and hash, acceptance source, date and time, IP address, user agent and a hashed session fingerprint.
2.3. Commercial records may include Orders, delivered product references, quantities, prices, Balance entries, top-ups, refunds, referral attribution and rewards, reviews and account restrictions. Secret Product contents are processed only where necessary for delivery, security or a claim.
2.4. Payment data may include amount, currency or cryptoasset and network, provider and transaction identifiers, status, wallet or masked payment-method details, conversion and fee information, and risk signals. A hosted provider normally processes full card details; Datamoll receives only the information needed to reconcile the payment.
2.5. Technical data may include IP address, approximate country or region, date and time, browser, operating system, device characteristics, referrer, cookie or session identifiers, requested route, response status, request ID and security events.
2.6. API and integration data may include partner or user identifier, connected domain, API credential identifier, endpoint and method, timestamps, request and external Order identifiers, Idempotency-Key, status, error class, limits and diagnostic events.
2.7. Support and claim data may include messages, Order or payment identifiers, screenshots, videos, uploaded files, attempt time, IP country or provider, device or browser information, exact error text and correspondence with a provider or supplier.
2.8. Fraud-prevention and verification data may include transaction patterns, IP and device links, payment ownership evidence and, only where proportionate and necessary, identity or source-of-funds material.
2.9. Data comes directly from the User, automatically from Platform use, from payment and technical providers, from suppliers involved in an Order, from official bots or integrations, and from lawful public or official sources where necessary for security or compliance.
2.10. Required fields are identified in the relevant form or process. If required account, payment, security or Order data is not provided, Datamoll may be unable to register the account, process the transaction, deliver the Product, verify ownership or decide the request; optional fields may be left blank without preventing unrelated functions.
2.11. If a User chooses Google sign-in or account connection, Datamoll receives the signed Google Account subject identifier, email address, email-verification status and, where applicable, the Google Workspace hosted-domain claim. Datamoll does not request the Google profile scope and does not retain Google access or refresh tokens after authentication.
3. Purposes and legal bases
3.1. Datamoll processes data to register and authenticate Users, maintain accounts and sessions, record acceptance of the legal document set, provide the Platform and communicate essential service information.
3.2. Data is processed to accept and reconcile payments, maintain Balance records, create, deliver and support Orders, operate referrals and reviews, and handle corrections, refunds, claims and disputes.
3.3. Technical and integration data is processed to operate APIs and bots, preserve idempotency and Order integrity, diagnose failures, measure reliability and prevent duplicate or unauthorized operations.
3.4. Data is processed to secure accounts and infrastructure, detect fraud and abuse, enforce geographic and service restrictions, verify identity or payment source where necessary, and establish or defend legal claims.
3.5. Depending on the purpose and applicable law, processing is based on performance of a contract or steps requested before it, compliance with a legal obligation, Datamoll’s or another person’s legitimate interests that are not overridden by the User’s rights, or consent.
3.6. Where processing is based on consent, the User may withdraw it at any time. Withdrawal does not affect prior lawful processing and does not stop processing required for a contract, law, security or legal claims.
3.7. Datamoll does not use personal data for a new purpose incompatible with the stated purpose without giving any required notice and establishing a valid legal basis, including obtaining consent where required.
3.8. Google identity data is used only to authenticate the User, create or connect the requested Datamoll account, verify control of an eligible mailbox and protect the account. It is not used by Datamoll for advertising or independent marketing.
4. Cookies and browser storage
4.1. Datamoll uses cookies and similar browser storage. When this information is linked to an account, device, Order or User activity, it is processed as personal data.
4.2. Necessary data supports sessions, login, account and transaction security, storage of the cart and an applied coupon, and remembrance of a cookie choice where such a choice is offered. Datamoll and its technical providers use it only to deliver requested functions.
4.3. Session, login and security data is retained for the active session period and no longer than 12 months. Cart data remains until checkout, removal by the User or browser clearing; information about the number of items in the cart remains for up to 30 days. A browser record of a cookie choice, when used, remains for up to 180 days.
4.4. Preference data may include the selected language, currency and visual theme, recently viewed Products and the state of dismissed notices. A temporary notice state is normally stored for 24 hours; other preferences remain until changed or removed by the User or browser.
4.5. When analytics is enabled, Google Analytics may receive information about visited pages, Product interactions, referral source, approximate device and network characteristics, event times and Order event parameters. Datamoll and Google use this data for audience measurement, diagnostics and aggregate reporting. Analytics data in the browser may remain for up to two years unless that period is shortened; passwords, delivered credentials and full card details are not sent to analytics.
4.6. Advertising and referral data may include the source and parameters of an advertising campaign, a unique visit identifier that contains no name or contact details, and a referral code. Datamoll uses it to assess advertising campaigns and record a referral relationship; the result may be reflected in the relevant affiliate account. Campaign data remains for up to 30 days, the visit identifier for up to 12 months, and referral data for the period shown by the Platform, not exceeding 365 days.
4.7. Where the Platform offers a choice, necessary technologies remain active while preferences, analytics, advertising and referral tracking are selected separately. The choice record may include selected categories, the notice version, date and time, language, source, a technical record identifier, an authenticated User ID and minimized IP, browser or session information. Recording browsing content is not required to prove the choice. Consent to direct marketing by email or bot is separate.
4.8. A User may change or withdraw an optional choice through any Cookie Settings section made available on the Platform. If that section is unavailable, the relevant data may be deleted or blocked in browser settings and Support may be contacted about a server-side choice record. Withdrawal stops future consent-based processing but does not undo processing that was lawful before withdrawal. Blocking necessary technologies may prevent login, checkout or security checks.
5. Service providers and disclosures
5.1. Datamoll does not sell personal data and does not disclose it to third parties for their independent direct marketing.
5.2. Data may be provided to hosting, infrastructure, content-delivery, security, email, messaging, support, analytics and development providers only to the extent needed for their services.
5.3. Payment, banking, cryptoasset and fraud-prevention providers receive the information required to initiate, verify, reconcile, refund or dispute a transaction and apply their own privacy notices where they act independently.
5.4. A supplier or technical fulfillment provider may receive the minimum Order and diagnostic information needed to fulfill an Order or investigate a defect. Datamoll does not authorize independent marketing use of that information.
5.5. Official bots and connected platforms, including messaging services, process identifiers and message data under their own terms as well as Datamoll’s instructions where applicable.
5.6. Data may be disclosed to courts, regulators, law-enforcement or other competent authorities where required by a valid legal process, or where law permits disclosure to protect rights, safety and Platform integrity.
5.7. Data may be transferred in a merger, financing, restructuring or sale of all or part of the service, subject to confidentiality and applicable data-protection requirements.
5.8. Google processes the authorization request under Google’s own terms and privacy notice. Datamoll sends Google the OAuth client and protocol values required for authentication and receives only the identity claims described in clause 2.11.
6. International data transfers
6.1. The Platform serves Users and uses providers in more than one country. Personal data may therefore be processed outside the User’s country.
6.2. Where required, Datamoll uses an applicable transfer mechanism, contractual safeguards, adequacy decision or another lawful basis for the transfer.
6.3. Protection and legal rights may differ by country. Datamoll limits transferred data to what is reasonably required for the relevant service or legal purpose.
6.4. A User may contact Datamoll for available information about safeguards applicable to a particular transfer, subject to confidentiality and security limits.
7. Fraud prevention, verification and automated analysis
7.1. Datamoll may combine account, device, IP, payment, Order, API and behavior signals to identify unusual activity, compromised access, prohibited regions, duplicate operations and refund abuse.
7.2. Risk signals may lead to an additional authentication step, request for payment ownership, identity or source-of-funds evidence, delayed processing, or a proportionate restriction of the affected operation, API key or funds.
7.3. Verification is limited to information reasonably necessary for the identified risk. Datamoll may withhold details that would enable circumvention, or where disclosure is prohibited by law or a provider.
7.4. Automated tools may prioritize or temporarily stop a transaction. Where required by applicable law, Datamoll does not make a decision producing legal or similarly significant effects solely by automation without a permitted basis and appropriate safeguards.
7.5. A User may ask Support for human review of a restriction, provide relevant evidence and challenge an error, unless such review or disclosure is legally prohibited.
7.6. A restriction does not permit unrelated personal data or funds to be retained without a purpose and legal basis.
8. Retention and deletion
8.1. Datamoll keeps personal data only for as long as reasonably necessary for the purpose collected, legal and accounting obligations, security, prevention of abuse and establishment, exercise or defense of claims.
8.2. Account and contact data is generally kept while the account is active and afterward only for closure, recovery, fraud prevention, disputes and mandatory recordkeeping.
8.3. Order, Balance, payment, refund, referral, legal-acceptance and cookie-choice records may be kept for the applicable accounting, tax, contract, accountability and limitation periods.
8.4. Security, access and API logs are generally kept for a shorter operational period unless an incident, claim, abuse investigation or legal duty requires longer preservation.
8.5. Support evidence is kept for the claim and any reasonable appeal or limitation period. Backups are overwritten on a controlled cycle; deletion from active systems may therefore take time to reach every backup.
8.6. While Google is connected, Datamoll stores the Google subject identifier, the account email and verification state, and the connection time. A User may disconnect Google in account security after setting a local password; the active connection identifier is then removed, subject to limited security, audit, legal and backup retention.
9. Security and confidentiality
9.1. Datamoll uses technical and organizational measures appropriate to the nature and risk of the data, including access controls, protected connections, credential protection, logging, monitoring and recovery procedures where applicable.
9.2. Access is limited by role and operational need. Providers are selected and instructed with regard to confidentiality and security appropriate to their function.
9.3. Diagnostic logs are designed not to contain API secret values, account passwords, delivered credential contents, authorization headers or cookie contents.
9.4. No storage or transmission method is completely secure. Users must protect passwords, API keys, email and devices, and notify Support promptly of suspected compromise.
9.5. Datamoll investigates personal-data incidents and notifies affected persons and competent authorities when required by applicable law.
10. User rights
10.1. Subject to applicable law, a person may request access to personal data, correction of inaccurate data, deletion, restriction, objection, withdrawal of consent and data portability where the relevant right applies.
10.2. A request may be submitted through Support or to admin@datamoll.com and should identify the account and the right being exercised without sending unnecessary secret information.
10.3. Datamoll may verify identity and account ownership before acting on a request and may ask for clarification where necessary to locate the data.
10.4. A request may be limited or refused where the law permits or requires, including to protect another person, preserve security, comply with recordkeeping or establish and defend legal claims. The principal reason will be provided where allowed.
10.5. For a valid Hong Kong data access or correction request, Datamoll responds within 40 days as required by applicable law, or within any shorter period that another mandatory law requires. If compliance cannot be completed within the applicable period, the requester is informed as required.
10.6. Withdrawal from marketing does not stop necessary service, security, transaction or legal notices.
10.7. A person may complain to a competent data-protection or privacy authority where that right is available, without first waiving the right to contact Datamoll.
11. Communications and children
11.1. Datamoll may send service messages about login, security, payments, Orders, claims, API operation and changes to legal documents through the account, email, an official bot, API or another selected channel.
11.2. Marketing messages are sent only with the consent or other legal basis required by applicable law and include a practical way to opt out.
11.3. A User must keep contact details current. Delivery and provider records may be used to determine whether a message was sent or failed.
11.4. If Datamoll learns that a child provided personal data contrary to clause 1.5, it may close the account and delete the data unless retention is legally required.
11.5. Before personal data is used for direct marketing where Hong Kong law applies, Datamoll identifies the kinds of data, the classes of Products or services to be promoted and a free response channel, and does not begin that use without the consent required by law.
11.6. A direct-marketing opt-out may be submitted at any time and without charge. Datamoll records and implements the choice and provides any confirmation required by applicable law.
12. Changes, language and contacts
12.1. The current version, publication date and effective date are shown on this page.
12.2. Datamoll may update this Policy when processing, providers, law or security requirements change. Material changes are notified through an appropriate channel before or when they take effect, as required.
12.3. Where a change requires consent, Datamoll will request it. Continued use alone is not treated as consent where applicable law requires a separate affirmative action.
12.4. The English version is controlling. Russian, Chinese and Vietnamese versions are translations, subject to any mandatory rule requiring another language or consumer-favorable interpretation.
12.5. Privacy requests and legally significant messages may be sent to admin@datamoll.com or through Support.
12.6. Commercial terms and refund procedures are governed respectively by the Terms and the Refund, Warranty and Product Verification Policy.
- Operator
- Datamoll
- Legal notices
- admin@datamoll.com