Last revised on 27 March 2026, and effective on 1 April 2026.
HEYCHIC PTY LTD (hereinafter referred to as "HEYCHIC") and its affiliated
companies (hereinafter collectively referred to as "HEYCHIC" or "we/us/our")
attach great importance to your privacy and the protection of your personal
information.When you purchase and/or use the products and/or services provided by HEYCHIC, browse and/or use HEYCHIC online services, and participate in HEYCHIC member activities and/or other activities carried out by HEYCHIC (hereinafter collectively referred to as "HEYCHIC Products and/or Services"), we may process your personal information.
We hope to explain to you through this Privacy Policy (hereinafter referred to as "this Policy"): what personal information of yours we collect, how we process this personal information, and the ways we provide for you to exercise your information rights. We also hope this Policy will help you decide whether to provide your personal information to us.
1. What personal information does HEYCHIC collect?
To provide you with the basic functions of HEYCHIC Products and/or Services,
such as online shopping on the HEYCHIC App, we need to process your necessary
personal information. If you refuse to provide the aforementioned necessary
information, you will not be able to use the basic functions of HEYCHIC
Products and/or Services normally. For personal information that you can opt
to fill in or choose to provide, if you refuse to provide it, we may not be
able to provide you with certain specific functions that rely on such
information, but it will not affect your normal use of the basic functions of
HEYCHIC Products and/or Services.
HEYCHIC will collect your personal information in the following scenarios where HEYCHIC Products and/or Services are provided. For any sensitive personal information that may be involved, we will bring it to your attention by bolding and underlining it. If the personal information you provide belongs to someone else, you must ensure that you have obtained the authorized consent of that person.
If HEYCHIC needs to collect your personal information in scenarios not listed in this Policy, we will separately explain the personal information processing rules applicable to such scenarios; at the same time, matters not explicitly explained in those personal information processing rules will be governed by the provisions of this Policy.
1.1 HEYCHIC Official Website
When you browse the HEYCHIC official website, in order to display our products
and/or services to you, we will collect your device service log information,
including: IP address, information about your Internet Service Provider (ISP),
relevant information of the device you use for the services (browser type,
operating system information), your browsing information (the URL that linked
you to the HEYCHIC official website, the URL of the webpage you visit on the
HEYCHIC official website, as well as the specific services and functions you
browse or use), language used, and the date and time of your visit.
To realize relevant business functions and provide you with more convenient and higher-quality HEYCHIC Products and/or Services, we will request you to enable the following permissions:
| Business Scenario | Scenario Description | Access and Use Permissions | Method of Disabling and its Impact |
|---|---|---|---|
| Finding nearby stores | When you enter the "Stores" page on the HEYCHIC official website, the website will attempt to use your current geographical location to assist you in finding stores around you. | Precise geographical location permission , rough geographical location permission | You can turn off the geographical location permission in your browser settings. After turning it off, you will not be able to use the location-based store finding function, but you can still find stores by entering a city name or an address. |
1.2 HEYCHIC App
1. Registering a member account directly on the HEYCHIC App. When you register
a member account via the HEYCHIC App, you need to enter your mobile phone
number to complete the registration. After successful registration, you can
also choose to fill in your nickname, birthday, gender, and email address. If
you choose not to provide this optional information, it will not affect your
registration, but it may affect your membership experience and the relevant
benefits and discounts you are entitled to enjoy under the *Terms and
Conditions of HEYCHIC Member Activities*. For example: if you choose not to
provide your birthday, you will not receive a complimentary birthday shopping
voucher when you become a Gold or Platinum member; if you choose not to
provide an email address, you will not be able to receive various
notifications sent by us via email.2. Registering a member account on the HEYCHIC App via a third-party platform account. When you register a member account using an account you have already registered on a third-party platform (e.g., Google, Facebook, X, Apple, Yahoo), subject to obtaining your authorized consent, we will obtain your information from that third-party platform to facilitate your registration. The type of information we collect depends on the settings of the third-party platform, specifically involving the username, profile picture, user identifier on the third-party platform, birthday, mobile phone number, gender, and region saved under your third-party platform account; when you use your Apple ID to register a member account, we will obtain the name and email address saved under your Apple ID. If any of the above information is missing, we may request supplementary information from you under the direct registration scenario described above. If you choose not to authorize this, you can still register a member account directly through the HEYCHIC App.
3. Binding a member account with a third-party platform account on the HEYCHIC App. If you have already registered a member account and intend to bind your account registered on a third-party platform (e.g., Google, Facebook, X, Apple, Yahoo) with your member account, subject to obtaining your authorized consent, we will obtain from the third-party platform the username, profile picture, user identifier on the third-party platform, birthday, mobile phone number, gender, and region saved under your third-party platform account; if you bind your Apple ID with your member account, we will obtain the name and email address saved under your Apple ID. Choosing not to bind accounts will not affect your membership status, but the HEYCHIC products and/or services you consume on that third-party platform will not accumulate growth points in your member account.
4. Browsing and using the HEYCHIC App. When you browse and use the HEYCHIC App, we will collect your device service log information, including: IP address, information about your Internet Service Provider, operating system information, App version information, the link that directed you to the HEYCHIC App, the URL of the visited webpage, as well as the specific services and functions browsed or used, language used, date and time of visit, and relevant device information (including your application installation list and IDFV). In addition, SDKs embedded in the HEYCHIC App will also collect relevant device information.
5.Participating in specific activities on the HEYCHIC App. When you participate in specific activities organized or launched by us on the HEYCHIC App, we will collect information related to your participation in such activities (for example, information provided to participate in HEYCHIC member activities or recipient and mailing address information collected to send you gifts). In addition, when browsing and participating in specific activities (such as store activities, member tasks) on specific pages (such as the "HYECHIC Members" page and the "My" page), we will collect your precise geographical location information (subject to your authorized consent), so that you can view and participate in relevant activities applicable to your region.
6.Using specific functions or experiencing specific effects on the HEYCHIC App. When you use specific functions or experience specific effects in the HEYCHIC App, we will collect your relevant device sensor information. We will only collect your sensor information in necessary specific scenarios, and the types of sensor information collected may vary depending on the scenario: (1) when you participate in our interactive activities and need to quickly scan to identify target objects, we will collect your accelerometer sensor information; (2) when you shake the device to quickly open your member QR code, we will collect your gyroscope sensor information (collected only in the iOS version of the HEYCHIC App) and accelerometer sensor information; (3) when you shake the device to experience specific animation effects, we will collect your gyroscope sensor information (collected only in the iOS version), rotation vector sensor information, and magnetic field sensor information (collected only in the Android version), as well as accelerometer sensor information; and (4) when you need to switch between portrait and landscape modes while playing videos, we will collect your accelerometer sensor information (collected only in the Android version).
To realize relevant business functions and provide you with more convenient and higher-quality HEYCHIC Products and/or Services, we will request you to enable the following permissions:
| Business Scenario | Scenario Description | Access and Use Permissions | Method of Disabling and its Impact |
|---|---|---|---|
| Login | When you log into your HEYCHIC member account by scanning a QR code with your mobile phone | Camera permission | You can turn off the camera permission on your phone system settings page. After turning it off, you will not be able to scan the QR code. |
| Message push | When you open the HEYCHIC App for the first time | Notification permission | You can turn off the notification permission on your phone system settings page. |
| Finding nearby stores | When you use the finding nearby stores function | Precise geographical location permission, rough geographical location permission | For iOS users, you can turn off the precise geographical location permission in your phone system settings page. |
| Shopping or reservation services | When you purchase goods and services online or use online space reservation services | Precise geographical location permission | You can turn off the geographical location permission. |
| Participating in specific activities | When you browse and participate in specific activities | Precise geographical location permission | You can turn off the geographical location permission in system settings. |
| Customer service | When you communicate with online customer service and proactively upload pictures | Camera permission, Photo permission | You can turn off camera and photo permissions. |
| Modifying profile picture | When you manually modify your profile picture information | Photo permission | You can turn off the photo permission. |
| Applying for return service | When you apply for a return of HEYCHIC products | Camera permission, Photo permission | You can turn off the permissions on your phone system settings page. |
| Saving pictures | When you participate in user activities and need to save pictures | Photo permission | You can turn off the photo permission. |
| Card number search | When you use the HEYCHIC App to scan the card number | Camera permission | You can turn off the camera permission. |
| Adding activity schedule reminders | When you participate in activities and need reminders | Read calendar permission, write calendar permission | You can turn off the calendar permissions. |
| Logging into member account | When you use Face ID or fingerprint recognition | Face ID permission, fingerprint sensor permission | You can turn off biometric authentication in system settings. |
| Sharing content of specific services | When you participate in activities and need to share content | Clipboard permission | You can turn off clipboard permission in system settings. |
1.3 Others
1. Participating in surveys. If you participate in customer surveys or
interact with us in various other ways, with your consent, we will collect
your relevant information. The type of information collected is related to the
content of the survey or the purpose and method of interaction, which may
include your personal information.
2. Participating in activities. In addition to the activities mentioned in other scenarios in this Policy, if you participate in other specific activities organized or launched by us, with your consent, we will collect information related to your participation in such activities (for example, information provided to participate in HEYCHIC member activities, or recipient and mailing address information collected to send you gifts).
3. Customer service communication. If you contact our customer service to consult us about the purchase and use of HEYCHIC Products and/or Services, or submit requests to us regarding after-sales services or dispute resolution, you may need to provide necessary personal information so that we can answer or resolve your issue as soon as possible. We will also retain the customer service communication records as necessary.
4. Job applications. If you wish to apply for job opportunities at HEYCHIC, you will need to submit your resume to us. Your resume will contain your personal information so that we can understand your personal background, contact you, and complete recruitment-related processes.
2. How do we process your personal information?
HEYCHIC will only process your collected personal information for the purposes
stated in this Policy, which include the following:
(1) Accepting and processing your orders and payments, and delivering corresponding HEYCHIC Products and/or Services;
(2) Processing and analyzing information and consumption behaviors regarding your purchase and use of HEYCHIC Products and/or Services, to provide you with personalized content displays and recommendations;
(3) With your consent, contacting you to obtain your feedback on HEYCHIC Products and/or Services;
(4) Processing your inquiries and questions regarding HEYCHIC Products and/or Services, responding to them or communicating with you;
(5) Analyzing and generating data statistics regarding your visits to HEYCHIC online services;
(6) If you have provided us with your personal profile or submitted your resume online, communicating with you and managing situations related to HEYCHIC job opportunities and specific positions;
(7) Verifying your identity and updating our records for the purpose of maintaining the security of your member account or for other reasonable purposes (for example, when you need to reset your member email address);
(8) With your consent, HEYCHIC and its suppliers will send you communications related to brands, products, activities, and promotional plans via the email address or other contact methods you provided, and communicate with you about matters related to these communications;
(9) Based on your choice, helping you register a member account using an account you have registered on a third-party platform and the personal information saved under that account; or, provided you have already registered a member account, binding the account registered on the third-party platform with your member account; or helping you create a member account.
If HEYCHIC needs to use your personal information for other purposes or uses not stated in this Policy, HEYCHIC will seek your consent separately before using and processing your personal information (except where laws and regulations stipulate otherwise).
3. How do we use Cookies, web beacons, and similar technologies?
We may use Cookies, web beacons, and similar technologies to collect usage
information from the HEYCHIC official website and/or the HEYCHIC App.
Cookies are very small data documents stored on your hard drive by websites. Among their many functions, Cookies can help us improve our website and your experience. We use Cookies to determine which areas and features are popular, and to count the number of your visits to our website. In addition to Cookies, we also use other similar technologies such as web beacons. Web beacons are electronic images that may be used on our website or in emails. We use web beacons to deliver Cookies, count visits, understand usage and campaign effectiveness, and determine whether an email has been opened and acted upon.
If you do not wish to accept Cookies, please set your web browser to reject Cookies, or set it to notify you when a Cookie is received. When Cookies are disabled, you may not be able to use certain features of the HEYCHIC official website.
3.1 How does HEYCHIC entrust processing, share with third parties, transfer
to third parties, or disclose your personal information?
◼ Entrusted Processing To provide you with HEYCHIC Products and/or Services,
we may entrust third-party service providers to assist us in providing
relevant operational and service support. During this process, these
third-party service providers will process your personal information to
realize the functions of our products and/or services, which include:
(1) SMS sending service providers;
(2) Software and system technical service providers;
(3) Marketing, research, and data analysis service providers;
(4) Map service providers;
(5) Invoice service providers;
(6) Website/system server hosting service providers.
◼ Sharing with Third Parties
1. HEYCHIC may share your personal information with partners and other third parties. Our partners include the following types:
(1) Payment institutions: To fulfill your order, we need to provide your order number, order amount, payment time, HEYCHIC store number, and merchant number to Square, Shopify, Afterpay, Paypal, etc., to confirm your payment instructions and complete the payment.
(2) Courier/delivery service companies: To fulfill your order, we need to share the recipient name, contact information, address, and order information you provide with courier/delivery service companies to provide you with delivery services.
2. To comply with the requirements of applicable laws and regulations, and to protect the rights, property, or safety of you, other HEYCHIC customers, HEYCHIC, and its employees, we may provide your personal information to government agencies, regulatory bodies, and law enforcement departments.
3.2 Information Transfer
Without your prior consent, HEYCHIC will not transfer the personal information
we collect to third parties. However, if HEYCHIC is involved in a merger,
acquisition, asset sale, or restructuring due to other reasons, HEYCHIC may
transfer your personal information to the parties involved in the
aforementioned transactions. If such events occur, we will require the
transaction parties who receive and hold your personal information to continue
to be bound by this Policy. Before transferring your personal information, we
will send you an appropriate notice, informing you of the name or personal
name and contact information of the recipient, and ensure that your personal
information will be protected in a manner consistent with this Policy. If the
recipient changes the processing purpose or processing method, we will require
the relevant data recipient to obtain your consent again.3.3 Information Disclosure
If we believe that it is necessary to disclose your personal information to
respond to public health emergencies, or to protect the life, health, and
property safety of HEYCHIC customers, the public, or HEYCHIC employees in
emergencies, we will disclose your personal information within the scope
permitted by applicable laws and regulations.3.4 What communications will members receive?
If you are a member, to ensure the normal operation of HEYCHIC member
activities and protect your rights under the Star Rewards Card and member
account, we will send you communications regarding your member account and/or
communications exclusive to members (for details, please refer to the *Terms
and Conditions of HEYCHIC Member Activities*) (hereinafter referred to as
"Member Communications"). If you refuse to receive such communications, please
apply to HEYCHIC to terminate the member account in accordance with the terms
and conditions you agreed to when registering.If you are a member, you have the right to independently choose via the HEYCHIC official website or HEYCHIC App whether to receive other communications (including promotional information related to HEYCHIC Products and/or Services) sent to the contact information you provided by HEYCHIC or HEYCHIC's suppliers, other than Member Communications.
3.5 How do you inquire about and/or modify your personal information?
You can follow the instructions below to inquire about and modify your
personal information:HEYCHIC Official Website: You can inquire about or modify your personal information on the "My Account" - "Manage My Account" page.
HEYCHIC App: You can inquire about or modify your personal information by clicking on your profile picture under "My".
You may supplement your birthday information after completing the member account registration. To ensure you can enjoy relevant benefits and discounts according to the provisions of the *Terms and Conditions of HEYCHIC Member Activities*, the birthday information you submit cannot be modified.
For other HEYCHIC activities you participate in, the information that can be inquired about and modified, as well as the methods of inquiry and modification, shall be subject to the provisions of the terms and conditions you agreed to when participating in such HEYCHIC activities.
3.6 How do you withdraw your consent?
For your personal information collected based on your consent, you can give or
withdraw your authorized consent at any time. You can change the scope of your
authorization for us to continue collecting your personal information or
withdraw your authorization by deleting information, turning off device
functions, etc., or by contacting us to do so via the contact methods listed
in the "Questions and Feedback" section of this Policy. You can also withdraw
all your authorizations for us to continue collecting your personal
information by canceling your account. However, please note that for certain
types of personal information, such as information necessary to realize the
basic functions of HEYCHIC Products and/or Services, or information necessary
for us to fulfill our obligations under applicable laws and regulations, we
may not be able to respond to your request to withdraw consent or
authorization. Except for circumstances where we cannot respond, when you
withdraw your consent or authorization, we will no longer process the
corresponding personal information, but your decision to withdraw will not
affect the personal information processing activities previously conducted
based on your consent or authorization.
When you request to exercise the above rights or make other appeals, we will verify your identity and reply with processing opinions or results within 15 business days.
3.7 Storage period of your personal information
We will store your collected personal information for the reasonably necessary
period required to achieve the personal information processing purposes stated
in this Policy, unless otherwise stipulated by laws and regulations or
otherwise authorized and agreed by you.When determining the specific storage period for personal information, we usually consider the following factors:
(1) The necessary period required to ensure the operation and security of the member account (in the event that you are a member);
(2) The necessary period required to smoothly fulfill your order, and to provide you with relevant customer service and after-sales support after the order is completed;
(3) The necessary period required to meet the requirements of financial audits, tax declarations, etc.;
(4) Special provisions of laws and regulations regarding the storage period of personal information;
(5) The storage period required under the provisions of laws concerning the statute of limitations, or to perform relevant legal obligations in cooperation with government department investigations;
(6) The personal information storage period separately agreed upon between us and you.
3.8 Where is your personal information stored?
Your personal information that we collect in Australia will be stored within
Australia.
For the purpose of managing the Group's global business and safeguarding our service standards, we will transfer the collected personal information to countries and regions outside Australia, and/or allow access to the personal information stored in Australia from countries and regions outside Australia, only when necessary and in compliance with applicable laws and regulations. We will fulfill the obligations of cross-border data transfer of personal information in accordance with the requirements of applicable laws and regulations, and ensure that the recipient protects your personal information to a standard no lower than that stipulated in this Policy through contractual agreements and other forms.
3.9 Information security
HEYCHIC attaches great importance to and is committed to protecting your
personal information. We will adopt security protection measures that meet
industry standards and are reasonably feasible, and equip suitable personnel
to ensure the security of your personal information from both technical and
organizational structure aspects, to prevent your personal information from
being modified, accessed, disclosed, used, or deleted under unauthorized
circumstances.
If an information security incident occurs, we will take appropriate and necessary disposal measures in accordance with the requirements of laws and regulations.
3.10 Revision of the Privacy Policy
We may revise this Policy from time to time. If we revise this Policy, we will
publish the revised Privacy Policy through relevant channels such as the
HEYCHIC official website, the HEYCHIC App, or email notifications. We
encourage you to frequently check this Policy to understand the content of any
revisions.
From the effective date of the revision of this Policy, your purchase and/or use of HEYCHIC products and/or services provided by HEYCHIC, your access, browsing and/or use of the HEYCHIC official website, the HEYCHIC App and/or any HEYCHIC online services, and your participation in HEYCHIC member activities and/or other activities carried out by HEYCHIC will be deemed as your full understanding and complete agreement to the revised Policy. For the personal information that you did not authorize to provide prior to the revision of this Policy, and which is not necessary to realize the basic functions of HEYCHIC Products and/or Services, we will still seek your consent separately based on your usage circumstances.
3.11 Links to other websites
Please note that HEYCHIC online services may contain links that can connect to
other websites. These websites do not necessarily follow the provisions of
this Policy. Please refer to and understand the respective privacy protection
policies of these websites.3.12 Questions and feedback
If you have any questions, complaints, or other concerns regarding this Policy
that cannot be answered here, you may contact us in the following ways, and
relevant personnel will assist you in resolving issues related to this Policy
or your personal information rights: Email:
customercare@heychic.com.au.3.13 Definitions
Personal Information"Personal information" refers to various types of information recorded electronically or in other ways relating to an identified or identifiable natural person, excluding information after anonymization processing.
Sensitive Personal Information
"Sensitive personal information" refers to personal information that, once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or harm to personal or property safety, including biometric identification, religious beliefs, specific identities, medical health, financial accounts, tracking traces, and other information, as well as the personal information of minors under the age of fourteen.
HEYCHIC Online Services "HEYCHIC online services"
in this Policy refers to the relevant services provided by HEYCHIC through its own websites or mobile applications, or through HEYCHIC-related stores on third-party platforms, including:
(a) HEYCHIC official website, URL is www.heychic.com.au;
(b) HEYCHIC App, i.e., the HEYCHIC mobile application operated and managed by HEYCHIC.




Google
Facebook
Apple
