1. Introduction and Scope

Miracle Charms Holding Limited respects the privacy of every person whose information it handles. This policy describes the practices that apply across the group, including the websites operated by the company, the ticketing and booking platforms it builds, the membership and loyalty systems it manages, the access control equipment deployed at venue doors, and the reporting services it provides to venue operators. Because the company works in the field of computer systems design and related services, much of its activity involves processing information on behalf of venue owners, and this policy distinguishes carefully between information the company controls and information it processes for others.

This policy does not cover the practices of independent third parties whose services you may reach from a page operated by the company. When you follow a link to an external service, the privacy notice of that service governs the information it collects. We encourage you to read the privacy notice of any service before providing personal information to it.

2. Information We Collect

The company collects several categories of information, and the category depends on the relationship you have with us. Identity information includes your name, and where you create an account, a username and a password hash. Contact information includes your email address, telephone number and postal address. Transaction information includes the seats you reserve, the events you attend, the amounts you pay and the method of payment. Access information includes records of entries and exits generated by venue door equipment. Membership information includes your tier, your points balance, your benefits and your redemption history. Technical information includes an internet protocol address, a device type, a browser type and a set of timestamps associated with your use of a platform.

We also collect the content of communications you send to us, such as an enquiry submitted through a contact form or an email sent to contact@maotaihotel.mom. Where you apply to work with us, we collect the information you choose to include in an application. Some information is aggregated or de-identified before it is used for reporting, and such information is no longer treated as personal information because it can no longer be linked to an individual.

3. How We Collect Information

We collect information directly from you when you complete a form, purchase a ticket, register a membership, contact the company or sign a contract. We collect information automatically when you use a platform, through server logs, cookies and similar technologies. We collect information from venue operators when they provide guest records as part of an engagement. We collect information from payment providers, who confirm the outcome of a transaction without disclosing your full payment credentials to us. We may also receive information from partners who operate a joint programme, but only where you have been told about the sharing in advance and only where a lawful basis exists.

Where information is collected automatically, it is generally technical in nature and is used to keep a platform secure, to diagnose faults and to understand how features are used. We do not attempt to identify an individual from technical information unless a security incident or a legal obligation requires it.

4. Why We Process Information

We process personal information to provide the services you request, to perform a contract with you or with a venue operator, to comply with legal obligations, to protect the safety and security of venues and their guests, and to pursue legitimate interests that are balanced against your rights. Those legitimate interests include preventing fraud, maintaining the reliability of platforms, improving the quality of the services the company offers, and preparing internal reporting that does not identify individuals.

Where consent is the appropriate basis, we ask for it clearly and we make it as easy to withdraw as it was to give. Withdrawing consent does not affect processing that already took place on the basis of that consent, and it does not affect processing carried out on another lawful basis, such as the performance of a contract or compliance with law.

5. Ticketing and Booking Data

When you reserve a seat or a place at an event, the company records the details needed to honour that reservation. Those details include the identity of the purchaser, the identity of any additional guests where this is required for admission, the performance or session selected, the seat or area assigned, the price paid and the status of the reservation. We retain a record of the reservation so that we can resolve disputes, process a refund or an exchange, and demonstrate that a sale was legitimate.

Reservation records can reveal information about attendance at a venue, and we treat that information with care. We do not sell reservation data, and we do not disclose it to unrelated parties for their own marketing. Where a venue operator needs access to reservation data to run a performance, we provide access under a written agreement that limits the use of the information to the operation of that venue.

6. Membership and Loyalty Data

Membership and loyalty systems hold information about your tier, your points, your benefits and your redemption history. This information allows a venue to recognise you at the point of service and to apply the benefits to which you are entitled. We maintain a ledger of earn and burn events so that balances are accurate and auditable, and we keep a record of any manual adjustment with the reason for the adjustment and the identity of the responsible team member.

Where a loyalty programme spans several venues in a group, your membership information may be visible to staff at each participating venue, but only to the extent needed to serve you. We do not reveal your full transaction history to a venue that has no reason to see it, and we do not use membership information to make automated decisions that produce a legal effect concerning you.

7. Venue and Access Data

Venue systems generate records when a ticket is scanned or a member enters a room. These records support admission, capacity management and safety. Access data is retained for a limited period, and it is used to operate the venue, to investigate an incident and to meet any legal requirement that applies to the operator. Where the law requires the company to keep access records for a defined period, we keep them for that period and then delete them according to a documented schedule.

Images captured by venue cameras, where such cameras are present, are governed by the notice displayed at the venue and by the instructions of the venue operator. The company may maintain the systems that store such images, but it does not use them for any purpose other than the purpose for which they were captured, unless a legal obligation requires otherwise.

8. Cookies and Similar Technologies

A cookie is a small file that a website stores on your device. The company uses cookies that are necessary for a platform to function, for example to keep a session open while you complete a purchase, and cookies that help us understand how a platform performs. Necessary cookies are set without consent because the service cannot work without them. Other cookies are set only where you have agreed, and you may refuse them without losing access to the core functions of the platform.

You can control cookies through your browser settings, and you can delete cookies that have already been stored. Blocking all cookies may prevent some features from working, and we recommend that you allow necessary cookies if you intend to complete a booking. We do not use cookies to build advertising profiles of visitors across unrelated websites.

9. How We Share Information

We share information only where there is a clear reason and a lawful basis. We share information with a venue operator when the operator needs it to deliver a service you have requested. We share information with payment providers to complete a transaction and to manage a refund. We share information with professional advisers, auditors and insurers where this is necessary to run the business. We share information with authorities where the law compels disclosure or where disclosure is necessary to protect the safety of a person or the security of a venue.

We do not sell personal information, and we do not trade it for advertising. Where a corporate transaction such as a merger or a reorganisation affects the company, information may be transferred to a successor entity as part of that transaction, and we will take steps to ensure that the successor honours the commitments in this policy or gives you clear notice of any change.

10. Service Providers and Processors

The company relies on service providers for hosting, payment processing, email delivery, analytics and support. These providers are engaged as processors, and they act only on the documented instructions of the company. We require each processor to protect information to a standard that is at least equivalent to the standard the company applies, and we require each processor to assist us in meeting our obligations where a person exercises a right.

Before we engage a processor, we assess the risk that the engagement creates, and we take into account the sensitivity of the information, the volume of information involved and the location of processing. We review our processors periodically, and we end an engagement where a processor can no longer demonstrate adequate protection.

11. International Transfers

The company is based in Hong Kong and uses infrastructure that may be located in several jurisdictions. When information is transferred outside Hong Kong, we take steps to ensure that the transfer is lawful and that the information continues to receive an appropriate level of protection. Those steps may include contractual commitments, an assessment of the legal framework of the destination, and technical measures such as encryption.

Where a transfer would create a material risk to the rights of an individual, we will either avoid the transfer, apply additional safeguards, or inform the affected individuals so that they can decide how to proceed. We keep a record of our international transfer arrangements so that they can be reviewed and updated as circumstances change.

12. Retention of Information

We keep personal information only for as long as it is needed for the purpose for which it was collected, for a longer period where the law requires it, or for a longer period where it is necessary to resolve a dispute. Each category of information is covered by a retention rule, and those rules are reviewed at least once a year. When a retention period ends, information is deleted or anonymised so that it can no longer be linked to an individual.

Transaction records are generally kept for the period required by accounting and tax law. Access records are kept for a shorter period unless they are connected to an incident under investigation. Enquiries that do not lead to a contract are removed after a reasonable period, and recruitment records are kept only as long as there is a prospect of a future engagement or as the law requires.

13. Security of Information

The company protects information with a combination of technical and organisational measures. Technical measures include encryption in transit, encryption at rest where appropriate, access controls based on the principle of least privilege, network segmentation, monitoring for unusual activity and regular patching. Organisational measures include written procedures, staff training, background checks where appropriate, and an incident response plan that is tested rather than merely documented.

No system can be completely secure, and we do not promise that a breach will never occur. We do promise that we will act quickly and honestly if one does. Access to personal information is limited to personnel who need it to perform their duties, and every access is logged so that it can be reviewed. We test backups regularly, because an untested backup is not a protection but a hope.

14. Your Rights and Choices

Subject to the law that applies to you, you may have the right to ask for a copy of the personal information the company holds about you, to ask for corrections where that information is inaccurate, to ask for deletion where there is no continuing reason for us to keep it, to ask for a restriction on processing, to object to processing based on a legitimate interest, and to ask for a portable copy of information you provided. You may also withdraw consent where consent is the basis of processing.

To exercise a right, write to contact@maotaihotel.mom or call +13093859132. We will verify your identity before we act, because we do not want to release information to the wrong person. We aim to respond within thirty days, and where a request is complex we will explain why more time is needed. If you believe that we have handled your information improperly, you may complain to the company first, and you may also complain to the supervisory authority that applies to you.

15. Privacy for Children

The services operated by the company are not directed at young children, and we do not knowingly collect personal information from a child below the age at which consent can be given without the involvement of a parent or guardian. Where a venue hosts an event that is suitable for families, any information about a child is collected only with the consent of a parent or guardian, and it is used only for the purpose of that event.

If you believe that we hold information about a child without proper consent, please tell us at contact@maotaihotel.mom. We will investigate promptly, and where we find that such information was collected improperly, we will delete it and take steps to prevent a recurrence.

16. Analytics and Reporting Governance

The company builds reporting systems for venue operators, and governance is central to that work. Metrics used in reporting are defined in writing, their lineage is documented, and access to them is controlled. Where possible, reporting uses aggregated or de-identified information so that operators can understand their audiences without intruding on any individual. Where personal information must be used for analysis, the analysis is limited to what is necessary and is subject to the retention and security rules in this policy.

We regularly review the reports we produce to ensure that they do not reveal more than the purpose requires. A report that identifies a single guest when an aggregate figure would serve is a report we would rather not produce, and we design our systems to make the privacy-preserving option the default.

17. Marketing Communications

If you agree to receive marketing from the company, we use your contact information to send news about programmes, services and events that may interest you. You can stop marketing at any time by using the unsubscribe option in a message or by writing to contact@maotaihotel.mom. We honour every unsubscribe request promptly, and we do not require you to give a reason.

Where we send a message for a purpose that is not marketing, such as a confirmation of a booking or a notice about a change to a service, we may send it even if you have opted out of marketing, because the message is necessary for the service you requested. We keep a record of your marketing preferences so that we can respect them across the group.

18. Third Party Services and Links

A page operated by the company may link to a third party service, and a venue may use a third party platform to sell tickets or to manage membership. This policy does not apply to those services, and the company is not responsible for the privacy practices of a third party. Where a third party processes information on behalf of the company, the arrangements described in the section on service providers apply, and the third party is bound by a written agreement.

We select our partners with care, but we cannot control every action they take. If you are concerned about how a partner handles your information, please tell us so that we can look into the matter and, where necessary, reconsider the partnership.

19. Data Breach Response

The company maintains a plan for responding to a breach of security that affects personal information. When a breach is detected, we contain it, assess its scope, and take steps to prevent further harm. Where a breach creates a risk to the rights of individuals, we notify the affected individuals and the relevant authority without undue delay, and we explain in plain words what happened and what we are doing about it.

After an incident, we review what went wrong and we change our practices so that the same failure is less likely to recur. We keep a record of incidents and responses, and we use that record to improve our training and our technical controls.

20. Changes to This Policy

We may update this policy from time to time to reflect a change in our practices, in technology or in the law. When we make a material change, we will give notice on a website operated by the company and, where appropriate, by direct communication. The effective date at the top of this page shows when the current version took effect, and we encourage you to review the policy periodically.

If you continue to use a service after a change takes effect, you accept the updated policy for that continued use. If you do not agree with a change, you may stop using the service and exercise the rights described above in relation to information we already hold.

21. How to Contact Us

Questions, requests and complaints about privacy should be directed to the company using the details below. We welcome the opportunity to resolve a concern directly before it is escalated elsewhere, and we will treat every message with respect and confidentiality.

This policy is provided in English. If a translation is made available for convenience, the English version governs where there is any inconsistency. Thank you for taking the time to read how Miracle Charms Holding Limited protects the information entrusted to it.