This Policy explains how CONVERT IT FZ LLC, trading as Infinite Worlds Lab, collects, uses, shares, transfers, retains and protects personal data in connection with the Store and Products.
1. Controller and scope
Controller. CONVERT IT FZ LLC is the controller for personal data it determines how and why to process. Contact: legal@infiniteworldslab.com; address: FDAM0201, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. Shopify and other providers may also act as independent controllers for processing described in their own notices.
Scope. This Policy applies to Store visitors, purchasers, account users, subscribers, commission customers, people appearing in submitted materials, support contacts and other persons whose data we process in connection with the Store.
2. Personal data we collect
Identity and contact. Name, email, billing address, country, account identifiers, company details and communication preferences.
Transaction. Products ordered, price, currency, tax information, payment status, transaction identifiers, refunds, disputes, fraud signals, invoices, delivery, download and access history. We do not ordinarily receive complete payment-card numbers from the payment provider.
Account and technical. Login and security data, device and browser information, IP address, approximate location, language, time zone, referral source, pages and interactions, cookies, consent records, authentication results and diagnostic logs.
Commission and user material. Briefs, prompts, messages, preferences, reference images, audio, video, names, likenesses, location information, documents, revisions, approvals and outputs. These materials may include personal data about you or other people.
Communications and feedback. Support requests, emails, reviews, survey responses, social-media communications and records needed to investigate complaints or enforce rights.
3. Sources
Direct collection. We collect data from you at checkout, account creation, subscription, commission intake, support and other interactions.
Providers and platforms. We receive data from Shopify, payment providers, fraud-prevention services, digital-delivery and course platforms, analytics, email, advertising platforms and social networks according to their settings and your interactions.
Other people. A customer may submit personal data about another person in a commission brief. The customer must have a lawful basis and provide any required notices and permissions before doing so.
4. Purposes of processing
Contract and service. We process data to verify and accept orders, collect payment, create accounts, deliver files and access, perform commissions, provide support, communicate about an order and enforce licences.
Security and disputes. We process data to authenticate transactions, prevent fraud and abuse, protect accounts and systems, investigate incidents, preserve evidence, respond to payment disputes and establish, exercise or defend legal claims.
Compliance. We process data to maintain accounting and tax records, respond to lawful requests, screen legal risk and comply with consumer, e-commerce, privacy, sanctions and other obligations.
Improvement and analytics. We use limited usage and feedback data to understand performance, diagnose errors, improve Products and plan content, subject to consent requirements for non-essential cookies.
Marketing. We send promotional communications only where we have the consent or other lawful basis required. You may withdraw consent or unsubscribe at any time without affecting transactional messages.
5. Legal grounds and consent
Grounds. Depending on applicable law, processing is based on your consent, steps requested before or performance of a contract, compliance with legal obligations, protection of rights and security, or legitimate interests that are not overridden by your rights.
Withdrawal. Where processing is based on consent, you may withdraw it prospectively. Withdrawal does not affect earlier lawful processing and may make an optional feature or commission instruction impossible to perform.
Required data. If you do not provide data needed for payment, delivery, rights clearance, fraud review or legal compliance, we may be unable to accept or fulfil an order.
6. Commission material and AI providers
Processing instruction. Commission materials may be uploaded to or processed with third-party creative, hosting and artificial-intelligence tools where reasonably necessary to produce, edit, store or deliver Custom Work.
Sensitive material warning. Do not submit passwords, payment-card data, government identifiers, medical records, intimate material, children's data, trade secrets or other highly sensitive information unless we have expressly agreed in writing on a suitable secure process.
Third-party terms. Retention, human review, model-improvement use and other processing by an AI provider depend on the provider and account settings used for the commission. The commission intake or proposal should identify material provider-specific terms where required. If confidentiality or no-training treatment is essential, obtain written confirmation before submitting material.
7. Sharing
Service providers. We share only data reasonably necessary with providers of ecommerce hosting, checkout, payments, fraud prevention, customer accounts, file delivery, course access, cloud storage, AI and creative processing, email, support, analytics, consent management, accounting and security.
Professional and legal recipients. We may share data with auditors, accountants, insurers, banks, payment networks, professional advisers, regulators, courts, law enforcement and rights holders where reasonably necessary and lawful.
Business events. Data may be disclosed under appropriate safeguards in a financing, reorganisation, merger, asset transfer or sale, subject to applicable law and use consistent with this Policy.
No data sale. We do not sell personal data for money. Some analytics or advertising disclosures may be treated as a sale or sharing under certain regional laws; where applicable, we provide required consent or opt-out controls.
8. Shopify and payment processing
Shopify. The Store is expected to operate on Shopify. Shopify processes customer and transaction data to provide storefront, checkout, account, security and related services and publishes its own privacy notices.
Payments. Payment providers process payment credentials, authentication, fraud indicators, transaction data and disputes under their own terms and privacy notices. We generally receive status, limited billing data and transaction identifiers rather than full card details.
9. International transfers
Global providers. The Store and providers may process data outside the UAE and your country, including where Shopify, payment, cloud, AI, support or analytics infrastructure operates.
Safeguards. Where required, we rely on recognised adequate protection, contractual safeguards, explicit consent, contractual necessity, legal-claim necessity or another lawful transfer mechanism. You may request information about applicable safeguards, subject to confidentiality and security limitations.
10. Retention
Criteria. We retain data only for as long as reasonably needed for the stated purpose, contract performance, licence records, support, fraud prevention, security, tax and accounting, legal claims and mandatory retention.
Indicative periods. Order, invoice, tax, payment and licence evidence may be retained for the legally required period and, where appropriate, for the limitation period for claims. Support and commission working files are retained according to operational need and any accepted proposal. Marketing data is retained until opt-out or expiry of the applicable basis.
Deletion and anonymisation. At the end of retention, data is deleted, securely destroyed or anonymised, unless a legal hold, dispute, security need or other lawful exception requires continued retention.
11. Security
Measures. We use risk-appropriate organisational and technical measures such as access controls, provider due diligence, encryption where appropriate, account protection, backups, logging, minimisation and incident procedures.
No absolute security. No internet transmission, provider or storage system is completely secure. You must protect credentials and use secure methods when submitting sensitive reference material.
Incident response. We will assess and notify affected persons and authorities of a personal-data breach where and as required by applicable law.
12. Your rights
Available rights. Subject to applicable law and exceptions, you may request information and access, correction, completion, deletion, restriction, portability, objection to direct marketing or unlawful processing, and human review of certain automated decisions.
Requests. Send a request to legal@infiniteworldslab.com. Identify yourself and the relevant account or transaction without sending excessive identification data. We may request proportionate verification and may reject or limit repetitive, unfounded, security-sensitive or legally restricted requests.
Complaints. You may complain to the competent data-protection authority where applicable. We encourage you to contact us first so we can investigate.
13. Automated processing and fraud
Risk tools. Shopify, payment providers and fraud services may automatically analyse transaction, device, identity and behavioural indicators and recommend authentication, delay, rejection or review.
Human review. Where required by applicable law, you may request human review of a decision based solely on automated processing that has a significant legal or similar effect.
14. Cookies
Technologies. We and providers use cookies, pixels, local storage and similar technologies for security, checkout, accounts, preferences, analytics and, with required permission, advertising.
Separate policy. The Cookie Policy describes categories and controls. Non-essential technologies are used only in accordance with applicable consent requirements.
15. Children
Age restriction. The Store is intended for adults and is not directed to persons under 18. Do not submit children's personal data or likenesses in a commission without prior written agreement and all legally required parental or guardian authorisations.
16. Changes and contact
Changes. We may update this Policy to reflect processing, providers, law or Products. The updated date appears above. Material changes will be notified where required.
Contact. Privacy enquiries and rights requests: legal@infiniteworldslab.com. Postal address: FDAM0201, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.
Company information
CONVERT IT FZ LLC
Trading brand: Infinite Worlds Lab
Licence: 47010997
TRN: 104210723300001
FDAM0201, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
Email: legal@infiniteworldslab.com
Website: infiniteworldslab.com