Privacy policy

🔒 Privacy Policy

1. Scope of Information Collection

1.1 Information You Voluntarily Provide
Scenario Data Type Purpose
Account Registration Name, email, password Account creation, order management
Placing Orders Shipping address, phone, payment details Order processing, delivery
Customer Support Inquiry content, communication records User assistance
Marketing Activities Birthday, preference surveys Personalized recommendations
1.2 Automatically Collected Technical Data
  • Device Information: IP address, browser type, operating system

  • Browsing Behavior: Pages visited, click paths, session duration (via Cookies)

  • Location Data: Country/city (based on IP or shipping address)

    2. Purpose of Data Processing

    We process your data only under lawful bases:
    ✅ Contract Fulfillment: Processing orders, shipping, refunds
    ✅ Legal Obligations: Tax reporting, fraud prevention
    ✅ User Consent: Marketing emails (opt-out anytime)
    ✅ Legitimate Interests: Site optimization, product development

    3. Third-Party Data Sharing

    We share data only when necessary with:

    Third-Party Type Purpose Data Shared
    Carriers (e.g., USPS) Product delivery Name, phone, shipping address
    Payment Processors (e.g., PayPal) Payment processing Order amount, payment account
    Cloud Providers (e.g., AWS) Data storage Fully encrypted data
    Government Authorities Legal requests (e.g., subpoena) Required information

    🔐 Security Requirement: All third parties sign data confidentiality agreements

     

    4. Cookies & Tracking Technologies

    1. Essential Cookies: Maintain shopping cart functionality (non-disablable)

    2. Analytical Cookies (e.g., Google Analytics):

      • Purpose: Traffic analysis, page optimization

      • Opt-out: Browser settings or [Cookie Preference Center Link]

    3. Advertising Cookies (e.g., Facebook Pixel):

Purpose: Targeted ads (requires separate consent)

5. International Data Transfers


Data Storage Location: U.S. servers (add EU-specific clauses if applicable)


Protection Mechanisms:

Implement Standard Contractual Clauses (SCCs) or Privacy Shield framework to secure cross-border transfers


6. Your Rights

Depending on residency, you may exercise:

Right How to Exercise
Access View in account [Profile] section
Rectification Edit account information online
Deletion Submit request via customer support
Data Portability (GDPR) Obtain data copy in machine-readable format
Marketing Opt-out "Unsubscribe" link in emails
Non-Discrimination (CCPA) Equal service despite data sharing refusal

⏳ Response Time: Within 30 days (after verification)


7. Children’s Privacy

We do not knowingly collect data from children under 13


8. Data Security Measures

  • Technical Safeguards: SSL encryption, regular penetration testing

  • Administrative Controls: Staff confidentiality training, least-privilege access

Breach Response: Notify regulators and users within 72 hours of confirmed breaches

9. Policy Updates


Material changes notified via site banners/email