Privacy Policy
This Privacy Policy is designed to be comprehensive, clear, and ready for your Shopify store. It balances the strict requirements of the GDPR (EU), CCPA/CPRA (California), and PIPEDA (Canada) while remaining readable for your customers.
Privacy Policy
Last Updated: 2026.03.26
This Privacy Policy describes how LORLON (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit or make a purchase from our store.
Operating as a retailer incorporated in HK, we are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Personal Information Protection and Electronic Documents Act (PIPEDA).
1. Personal Information We Collect
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases.
-
Order Information: We collect names, billing addresses, shipping addresses, payment information (processed securely via Shopify Payments), email addresses, and phone numbers.
-
Device Information: We automatically collect information about the version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
-
Customer Support Information: Any information you provide during communications with our support team.
2. How We Use Your Personal Information
We use your personal information to provide our services to you, which includes:
-
Fulfilling Orders: Processing payments, arranging for shipping, and providing you with invoices and/or order confirmations.
-
Communication: Screening orders for potential risk or fraud and providing you with information or advertising relating to our products or services (based on your preferences).
-
Site Optimization: Using analytics to understand how our customers browse and interact with the Site to improve our user experience.
3. Legal Basis for Processing (GDPR Only)
If you are a resident of the European Economic Area (EEA), we process your personal information under the following legal bases:
-
Your consent;
-
The performance of the contract between you and the Site;
-
Compliance with our legal obligations;
-
For our legitimate interests, which do not override your fundamental rights and freedoms.
4. Sharing Your Personal Information
We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above.
-
Shopify: We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
-
Google Analytics: We use Google Analytics to help us understand how our customers use the Site. You can opt-out here: https://tools.google.com/dlpage/gaoptout.
-
Meta Pixel: We use the Meta Pixel to track visitor activity and deliver targeted advertising.
-
Compliance with Law: We may share your information to comply with applicable laws and regulations or to respond to a lawful request for information we receive.
5. Cookies
A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies.
-
Consent: When you first visit our site, you will see a cookie banner. By clicking "Accept," you consent to our use of non-essential cookies.
-
Control: You can control and manage cookies through your browser settings. However, removing or blocking cookies can negatively impact your user experience.
6. Your Rights
Residents of the European Union (GDPR)
If you are an EU resident, you have the following rights:
-
Right to Access: Request a copy of the data we hold about you.
-
Right to Erasure: Request that we delete your personal data.
-
Right to Portability: Request that we transfer your data to another service.
-
Right to Objection: Object to the processing of your data for direct marketing.
Residents of California (CCPA/CPRA)
If you are a California resident, you have the following rights:
-
Right to Know: The right to request disclosure of what personal information we collect and how we use it.
-
Right to Delete: The right to request the deletion of your personal information.
-
Right to Opt-Out of Sale/Sharing: We do not "sell" your data in the traditional sense, but we do "share" it for targeted advertising (Meta Pixel/Google). You may opt-out of this sharing.
-
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Residents of Canada (PIPEDA)
Canadian residents have the right to access their personal information and challenge the accuracy and completeness of that information. We ensure all data transfers and storage meet PIPEDA’s "comparable level of protection" standards.
7. Data Retention
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information.
8. International Transfers
Your personal information will be transferred outside of Europe, including to Canada and the United States, for storage and processing by Shopify. We rely on recognized transfer mechanisms (such as Standard Contractual Clauses) to ensure your data remains protected.
9. Contact Us
For more information about our privacy practices, if you have questions, or if you would like to exercise any of your rights (Access, Erasure, Opt-Out), please contact us at:
Officer Email: support@lorlon.com