Privacy & Data Protection
We prioritize the protection of personal information for all visitors and customers. This document outlines the types of data we collect, how it is used, and the measures taken to safeguard sensitive information such as payment card details and contact information.
Information We Collect
We collect information to provide our services efficiently and improve the shopping experience, including:
- Account & identity data: name, username, password, and other registration details.
- Contact & fulfillment data: billing and shipping addresses, phone number, and delivery instructions.
- Payment information: credit/debit card details and billing information, securely processed through trusted payment gateways.
- Order & transaction history: purchased items, returns, exchanges, and related communications.
- Device & usage information: IP address, browser type, device information, and site activity collected via cookies or analytics tools.
- Customer communications: inquiries, feedback, and reviews submitted through the website.
How We Use Your Information
- To process orders, payments, returns, and exchanges.
- To provide customer support and respond to inquiries.
- To personalize product recommendations and marketing communications where consent is provided.
- To detect and prevent fraud, unauthorized transactions, or security issues.
- To analyze site usage and improve our services and offerings.
- To comply with legal obligations and protect our rights and property.
Payment Security
- All payments are processed through PCI-compliant third-party payment providers.
- Full credit card numbers are not stored on our systems; only masked numbers or tokens may be retained to facilitate returns or refunds.
- All payment transmissions use TLS/HTTPS encryption to secure data in transit.
- Access to payment information is restricted to authorized personnel with strict security controls.
- Regular monitoring, vulnerability assessments, and security testing are conducted to ensure payment safety.
Protecting Personal Data
- Access to personal information is limited to authorized personnel on a need-to-know basis.
- Multi-factor authentication and secure credentials are required for administrative access.
- Encryption is used for sensitive data stored in our systems.
- Vendors and service providers are contractually obligated to protect personal information.
- Employee training is provided for privacy, data handling, and phishing awareness.
Cookies & Tracking
We and our partners use cookies and similar technologies to enable essential site functions, enhance user experience, prevent fraud, and gather analytics. You may control cookie preferences via your browser or site settings. Disabling certain cookies may affect site functionality.
Sharing & Disclosure
- With service providers performing essential functions (payment processing, shipping, hosting, analytics) under strict confidentiality agreements.
- To comply with legal obligations or protect rights and property.
- During business transfers such as mergers or acquisitions, under confidentiality safeguards.
- In aggregated or anonymized form that does not identify individuals.
Data Retention & Minimization
We collect only the information necessary for the purposes outlined and retain it only as long as required for service provision, legal compliance, or dispute resolution. When data is no longer needed, it is securely deleted or anonymized.
User Rights & Controls
Depending on your location, you may access, correct, delete, or restrict the processing of your personal data. Account settings allow you to manage preferences and consent. Verified requests are handled according to applicable law.
International Data Transfers
Personal information may be processed or stored in countries outside your residence. Transfers are protected by appropriate safeguards such as standard contractual clauses or adequacy mechanisms.
Children
Our services are not directed to children under the age of 16 unless otherwise required by law. We do not knowingly collect data from children below the applicable age. If we discover such data, it will be deleted promptly.
Breach Response
We maintain an incident response program to detect, contain, and investigate security events. Confirmed breaches affecting personal data will follow legal notification procedures to affected individuals and authorities as required.
Third-Party Services
Our website may link to or integrate with third-party services, which have their own privacy practices. We encourage reviewing their policies before sharing personal data.
Continued use of our website constitutes acceptance of these privacy practices. Please refer to account controls and site settings for managing your personal information.