+3110 - 747 00 00

LIMITED TIME OFFER: 20% OFF SITEWIDE

Privacy and Cookie Policy

Last updated: Aug 14, 2026

DiamondsByMe takes the protection of personal data seriously. This policy explains what personal data we collect, use or disclose when you visit our Singapore website, use our services or visit our premises, why we handle it, who receives it, how long we keep it and how you can exercise your rights.

Who we are and how we use information

DiamondsByMe B.V. is the organisation responsible for personal data handled through www.diamondsbyme.com/en-sg/.

DiamondsByMe B.V.

Dienstenstraat 25

3161 GN Rhoon

The Netherlands

Dutch Chamber of Commerce: 24376433

Email and Data Protection Officer contact: [email protected]

Telephone: +31 10 747 0000

This policy applies to customers and visitors in Singapore.

Depending on how you use our website and services, we may collect, use or disclose:

  • name, address, town or city, email address and telephone number;
  • account, order, delivery and invoice information;
  • product specifications such as ring size, metal, stone, engraving and configuration choices;
  • payment method, payment status and data needed for payment or refund; we do not normally receive full payment-card details;
  • customer service, chat, complaint, return, warranty, repair and service information, including photographs you send;
  • newsletter subscription, marketing preferences and consent records;
  • technical information such as IP address, device, browser, cookies and website use;
  • fraud prevention, security and misuse information;
  • CCTV images at our premises; and
  • recruitment information such as contact details, CV and correspondence.

We do not request more personal data than reasonably necessary. Without required information, we may be unable to fulfil an order, payment, delivery or service request.

We collect, use or disclose personal data for purposes that a reasonable person would consider appropriate, after notifying you of those purposes and with consent, deemed consent or another basis permitted by the Personal Data Protection Act 2012 (PDPA):

  • to create accounts, make and deliver orders, take payment, and handle returns, warranties, repairs and services;
  • to comply with accounting, tax, consumer-law, product-safety and other legal obligations and lawful requests from authorities;
  • for customer service, security, fraud prevention, quality improvement, statistics, business operations and establishing or defending legal claims; and
  • for newsletters and analytical, personalisation or marketing technologies where consent is required or has been requested. Consent may be withdrawn with reasonable notice, subject to legal or contractual consequences explained to you.

CCTV protects staff, visitors, jewellery, goods and premises and helps prevent or investigate incidents. We use signs at the premises, restrict access and retain footage only as reasonably necessary.

We use personal data to record and make the configured jewellery, communicate about the order, process payment and arrange delivery.

Payments may be handled by Adyen, Pay.nl, Klarna or PayPal. Delivery details may be shared with carriers including DHL and FedEx.

Payment partners may independently conduct payment, fraud, credit or risk checks under their own notices and terms.

When you contact us, we use contact information, messages, order details and submitted photographs to deal with the request.

Freshdesk/Freshchat and Minimal AI may support chat, information retrieval, drafting and conversation summaries. Important decisions on orders, complaints, warranty or fraud are not made solely by AI where meaningful human review is needed.

Marketing, cookies and recipients

Commercial electronic messages are sent in accordance with Singapore’s Spam Control Act and, for telemarketing to Singapore telephone numbers, the Do Not Call provisions of the PDPA. Required messages include accurate sender details and a functional unsubscribe facility. Valid unsubscribe requests are acted on within 10 business days.

We may retain a minimal suppression record to respect an opt-out.

Messages necessary for an order, payment, delivery, return, warranty, repair, security or requested service are service communications rather than newsletters.

CookieHub manages preferences. Essential storage and access technologies support the website and services.

We use CookieHub to provide transparency and choice for cookies and similar technologies. We obtain consent or provide an opt-out where required under the PDPA or another applicable rule and use personal data only for notified and permitted purposes.

Personalisation, remarketing and advertising technologies are used according to the preferences selected through CookieHub. You can accept, refuse or later change non-essential technology preferences through the cookie settings.

The CookieHub notice provides the current technical list of technologies, providers, purposes and durations.

With consent where required, services may include Google, Meta, Microsoft, TikTok and Pinterest for analytics, measurement, personalisation and remarketing.

We disclose information only as needed for the purposes above, with consent, or where legally required. Recipients may include:

  • Afosto for webshop, account and order management;
  • Adyen, Pay.nl, Klarna, PayPal and financial institutions;
  • DHL and FedEx;
  • Freshdesk/Freshchat, Minimal AI, Klaviyo and Typeform;
  • Trustpilot;
  • Cloudflare, CookieHub, Make.com and BigQuery;
  • Google, Meta, Microsoft, TikTok and Pinterest;
  • professional advisers, insurers, accountants and competent authorities.

Each recipient receives only what is necessary. We do not sell personal data.

After a purchase, we may provide name, email address and order number to Trustpilot to send a review invitation. Trustpilot acts under its own responsibility when you create an account or publish a review.

We work with NDBM Thailand Co., Ltd. and our own craftspeople in Thailand. Necessary order and product information may be accessed there for manufacture, engraving, planning, quality control, repair and service.

Access is limited. Payment information, marketing preferences, browsing behaviour and unrelated customer information are not made available for production.

We use contractual, organisational and technical safeguards.

DiamondsByMe is established in the Netherlands. Personal data collected from customers in Singapore is therefore transferred to and processed in the Netherlands.

Necessary order and product information may also be disclosed to NDBM Thailand Co., Ltd. and our craftspeople in Thailand for manufacture, engraving, planning, quality control, repair and service.

For transfers outside Singapore, we use contractual, organisational and technical measures designed to ensure a standard of protection comparable to the PDPA, unless an applicable exemption applies.

Service providers may also use systems or subprocessors in other countries. Where practicable, we identify the countries in which overseas recipients are likely to be located and review material changes to these arrangements.

Retention, security and your rights

We retain personal data only while it remains necessary for a legal or business purpose and then cease retention or dispose of it properly. Broadly:

  • tax and financial records: generally seven years after the relevant financial year;
  • order, product, warranty and service records: as required for the contract, statutory rights, claims and the additional lifetime warranty; essential records may be kept longer to assess a lifetime-warranty claim;
  • ordinary customer service conversations: generally up to two years; records forming part of an order, return, complaint, warranty or service case generally up to five years, unless a legal duty, active dispute or warranty administration requires longer;
  • account information: while active or reasonably needed, subject to legal retention duties;
  • newsletter data: until opt-out, with a minimal suppression or evidence record retained as needed;
  • fraud and security information: generally no more than two years after no incident or dispute remains;
  • recruitment information: generally four weeks after the process, or up to one year with consent;
  • CCTV: up to four weeks unless needed for an incident, report or legal proceedings;
  • Custom Design requests through Typeform, Make.com and Google Sheets: up to two years if no order follows; necessary data becomes part of the order file if one does;
  • pseudonymised analytics and server-tracking data in BigQuery: up to 25 months;
  • Trustpilot invitation data: up to three years; BCC messages processed for the invitation service up to 30 days; and
  • cookie and analytics information: according to CookieHub and the selected preferences.

We use appropriate technical and organisational measures, including access controls, secure connections, supplier agreements, logging, back-ups and periodic reviews.

No system is risk-free. We assess suspected data breaches under the PDPA. Where a breach is notifiable because it is likely to cause significant harm or is of significant scale, we notify the Personal Data Protection Commission and affected individuals as soon as practicable, as required.

Subject to the PDPA and its exceptions, you may request access to personal data in our possession or control and information about how it was used or disclosed during the preceding year. You may also request correction of an error or omission.

You may withdraw consent with reasonable notice. We will explain the likely consequences and cease the affected collection, use or disclosure as required, but may retain data needed for legal or business purposes.

Send requests to our Data Protection Officer at [email protected]. We may request proportionate information to verify identity.

We respond as soon as reasonably possible and within the period required by the PDPA. If more time is needed, we will inform you.

If you believe we have mishandled your personal data, email our Data Protection Officer at [email protected] with enough information for us to investigate. A specific form is not compulsory.

We investigate the complaint and respond within a reasonable period, generally within 30 days. We will keep you informed where further time is reasonably required.

If you are not satisfied with our response, you may contact the Personal Data Protection Commission Singapore:

Personal Data Protection Commission Singapore

www.pdpc.gov.sg

Use the complaint and review channels published by the PDPC.

The PDPC generally encourages individuals to approach the organisation first so that it has an opportunity to address the concern.

We may update this policy when our services, systems or the law change. The latest version is published on www.diamondsbyme.com/en-sg/. We provide additional notice of significant changes where reasonably appropriate.