Privacy policy
Privacy Policy
Last updated: [Month Day, Year]
This Privacy Policy describes how Lylara (“Lylara,” “we,” “us,” “our”) collects, uses, discloses, and protects your personal information when you visit [lylara.com] (the “Site”), make a purchase, interact with our emails/ads, or contact us (collectively, the “Services”). By using the Services, you agree to this Policy and our Terms of Service.
If you have questions or want to exercise your privacy rights, contact us at privacy@lylara.com.
1) Information we collect
We collect information in three ways: (a) directly from you, (b) automatically via cookies/pixels, and (c) from service providers and partners.
A. Information you provide
-
Contact & profile: name, email, phone, billing/shipping address, account login (hashed), preferences.
-
Order & payments: products purchased, delivery details, payment confirmation from our processor (we do not store full card numbers).
-
Support & UGC: messages to customer support, product reviews, photos you upload, survey responses, sweepstakes entries.
-
Marketing choices: newsletter/SMS opt-ins or opt-outs.
B. Information collected automatically
-
Device & usage: IP address, device/browser type, language, time zone, cookie IDs, pages viewed, clicks, referring/exit pages, approximate location (from IP).
-
Cookies/SDKs/pixels: placed by us and partners for analytics, site performance, fraud prevention, and advertising (retargeting/measurement).
C. Information from third parties
-
E-commerce platform & hosting (e.g., Shopify), payment processors, fraud prevention, marketing & analytics (e.g., ad networks, email/SMS platforms), fulfillment/carriers/warehouses, and customer support tools may provide or process information on our behalf to deliver the Services. Lylara
2) How we use information
We use personal information to:
-
Provide the Services: process orders, payments, shipping/returns/exchanges, and account management. Lylara Communicate: order and account notices, service updates, and—with your consent or as permitted by law—marketing by email/SMS/post.
-
Personalize & measure: remember preferences, improve the Site, run analytics and A/B tests, and show relevant ads.
-
Security & fraud prevention: detect and prevent fraud, abuse, or illegal activity. Lylara Compliance: tax/accounting, legal requests, and enforcing our Terms.
Where required (e.g., EEA/UK visitors), we rely on legitimate interests, contract performance, consent, and/or legal obligations as our legal bases.
3) Cookies and tracking
We use cookies and similar technologies to operate the store, remember your settings, measure performance, and support advertising. You can control cookies in your browser; blocking some cookies may break site features. For Shopify-related cookies, see Shopify’s Cookie Policy. Shopify
-
Global Privacy Control (GPC). We honor the GPC signal where required; if detected, we treat it as a valid opt-out of “sale” / “sharing” / targeted advertising for that browser/device. Learn more about GPC here. California Attorney General+1
-
We do not respond to other “Do Not Track” signals at this time.
4) How we disclose information
We may disclose personal information to:
-
Service providers/contractors: e-commerce platform, payment processors, anti-fraud, analytics/advertising, email/SMS, cloud hosting, fulfillment and shipping partners.
-
Business partners: for co-marketing/ads (subject to their policies).
-
Legal/compliance: to comply with law or protect rights/safety.
-
Corporate transactions: merger, acquisition, financing, or sale.
-
At your direction: e.g., when you use social logins/widgets or request us to share information. Lylara
We do not use or disclose sensitive personal information (e.g., precise geolocation, health data) to infer characteristics or beyond limited permitted purposes. Lylara
5) Advertising, “sale,” and “sharing”
Some states (e.g., CA/CO/CT/NJ/VA) define “sell” or “share” broadly to include certain data disclosures for targeted advertising. We may engage in targeted ads with partners (e.g., Meta, Google) that could be considered a “sale”/“sharing.” You can opt out:
-
Use our “Do Not Sell or Share My Personal Information” link: [your-link: /pages/do-not-sell]
-
Adjust cookies in your browser and disable ad personalization where available.
-
Enable Global Privacy Control in supported browsers. California Attorney General
We do not knowingly sell/share data of consumers under 16. Lylara
6) Retention
We keep personal information only as long as necessary to provide the Services and for legitimate business needs (e.g., tax/accounting, fraud prevention, dispute resolution), then delete or de-identify it according to our retention schedule. Lylara
7) Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data. No method of transmission or storage is 100% secure; please use caution when sharing information online. Lylara
8) Your privacy rights
Your rights depend on your location. We will not discriminate against you for exercising them and may need to verify your identity (and, where applicable, your authorized agent).
For U.S. state privacy laws (e.g., CA/CO/CT/NJ/VA/UT)
You may have the right to:
-
Know/Access the categories and specific pieces of personal information we collected.
-
Delete personal information.
-
Correct inaccuracies.
-
Portability: receive a copy in a usable format.
-
Opt-out of sale/sharing/targeted advertising (see Section 5).
-
Limit use of sensitive personal information (not typically processed by us).
-
Appeal a decision: reply “Appeal” to our response and we’ll review. Splendor
Submit requests via privacy@lylara.com or [web form URL]. If you send a GPC signal, we process it as an opt-out for that browser/device. California Attorney General
For EEA/UK visitors
Where GDPR/UK GDPR applies, you have the rights to access, rectify, erase, restrict, port, and object (including to profiling for direct marketing). You may also lodge a complaint with your local authority. If we transfer data outside the EEA/UK, we use appropriate safeguards (e.g., Standard Contractual Clauses). Lylara
9) Children
Our Services are intended for adults and we do not knowingly collect personal information from children. Parents/guardians may contact us to request deletion of a child’s data. We do not knowingly sell/share data of users under 16. Lylara
10) International transfers
We and our service providers may process information in the United States and other countries/regions (e.g., EU/UK/Asia). Where required, we use lawful transfer mechanisms (such as SCCs). Lylara
11) User-generated content
Reviews, photos, and other content you post publicly may be viewable by others. Do not share information you prefer to keep private. Lylara
12) Changes to this Policy
We may update this Policy to reflect changes to our practices or for legal/operational reasons. We’ll post the new date at the top and follow any notice requirements under applicable law.