Privacy Policy
Last updated: April 2024
GDPR Compliance
Luna Mart is fully committed to GDPR (General Data Protection Regulation) compliance. Your privacy is extremely important to us. This policy explains how we collect, use, and protect your personal data.
1. Information We Collect
We may collect and process the following data:
- Account Information: Name, email address, password, phone number
- Shipping Information: Address, delivery preferences
- Payment Information: Credit card details (processed securely via PCI-compliant payment gateways)
- Browsing Data: IP address, cookies, device information, browser type
- Communication: Messages you send to us via contact forms
- Transaction History: Orders, returns, refunds
2. How We Use Your Data
Your data is used for:
- Processing and fulfilling your orders
- Providing customer support
- Sending transactional emails (order confirmation, shipping updates)
- Improving our website and services
- Legal compliance and fraud prevention
- Analyzing usage patterns (with anonymization where possible)
3. Legal Basis for Processing
We process your data based on:
- Contract: To fulfill your purchase orders
- Legitimate Interest: To improve our services and prevent fraud
- Consent: For marketing communications (opt-in basis only)
- Legal Obligation: To comply with EU tax and consumer protection laws
4. Cookies and Tracking
We use cookies to enhance your experience. You have the right to refuse cookies, though this may affect website functionality. We use:
- Essential Cookies: For site functionality and security
- Analytics Cookies: To understand user behavior
- Preference Cookies: To remember your settings
All cookies comply with GDPR requirements and are disclosed via our cookie consent banner.
5. Data Sharing
We do NOT sell your personal data. We only share information with:
- Payment Processors: For secure payment processing
- Shipping Carriers: To deliver your orders
- Service Providers: For website hosting and analytics
- Legal Requirements: When required by law
All third-party processors are GDPR-compliant and bound by data processing agreements.
6. Your GDPR Rights
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your data (right to be forgotten)
- Portability: Receive your data in a portable format
- Object: Opt-out of marketing communications
- Withdraw Consent: Revoke previously given consent
To exercise these rights, contact us at hello@lunamart.com with proof of identity.
7. Data Retention
We retain your data only as long as necessary for the purposes stated above. Generally:
- Account Data: Until you close your account
- Transaction Data: For 7 years (EU tax compliance)
- Marketing Data: Until you unsubscribe
- Cookies: As specified in our cookie banner
8. Data Security
We implement strict security measures to protect your data:
- SSL/TLS encryption for all data in transit
- PCI DSS compliance for payment processing
- Regular security audits and updates
- Restricted access to personal data (need-to-know basis)
- Employee confidentiality agreements
9. Third-Party Links
Our website may contain links to external sites. We are not responsible for their privacy policies. Please review their policies before providing any personal information.
10. Data Protection Officer
For data protection inquiries, contact us at hello@lunamart.com or submit a data request using your statutory rights.
11. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Your continued use constitutes acceptance of changes.
12. Contact Us
For privacy concerns or to exercise your rights, contact us at:
Luna Mart
Email: hello@lunamart.com
Location: Italy & Sri Lanka