Privacy policy
Privacy Policy
ARTICLE 1 – PERSONAL INFORMATION WE COLLECT
When you make a purchase in our store, as part of the buying and selling process we collect the personal information you provide, such as your name, address and email address.
When you browse our store, we also automatically receive your computer's internet protocol (IP) address, which helps us learn more about the browser and operating system you use.
Email marketing: With your consent, we may send you emails about our store, new products and other updates.
SMS marketing: By entering your phone number at checkout, you agree to receive SMS messages (order tracking and abandoned cart recovery) and promotional offers. The number of texts will not exceed 4 per month. You can unsubscribe at any time by replying STOP.
ARTICLE 2 – CONSENT
How do we obtain your consent?
When you provide us with personal information to complete a transaction, verify your payment card, place an order, arrange a delivery or return a purchase, we assume that you consent to our collecting and using this information for that specific purpose only.
If we ask you for personal information for another reason, such as marketing, we will either ask you directly for your express consent or give you the opportunity to decline.
How can I withdraw my consent?
If, after giving your consent, you change your mind and no longer agree to us contacting you, collecting your data or disclosing it, you can let us know at contact@helorya.com
ARTICLE 3 – DISCLOSURE
We may disclose your personal information if we are required to do so by law or if you breach our Terms and Conditions.
ARTICLE 4 – SHOPIFY
Our store is hosted by Shopify Inc., which provides us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored in Shopify's data systems and databases and within the general Shopify application. Your data is kept on a secure server behind a firewall.
Payments:
If you make a purchase through a direct payment gateway, Shopify stores your payment card details. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Your transaction information is kept for as long as necessary to complete your order. Once it is complete, the transaction data is deleted.
All direct payment gateways comply with the PCI-DSS standard managed by the PCI Security Standards Council, a joint effort of companies such as Visa, MasterCard, American Express and Discover.
The PCI-DSS requirements help ensure the secure handling of payment card data by our store and its service providers.
ARTICLE 5 – THIRD-PARTY SERVICES
The third-party providers we use only collect, use and disclose your data to the extent necessary to provide their services.
Some third-party providers, such as payment gateways, have their own privacy policies regarding the information we are required to provide to them for your transactions. We recommend that you read their policies carefully.
Please note that some providers may be located in a different jurisdiction than you or us. If you choose to proceed with a transaction that requires a third-party service, your data may then be subject to the laws of the jurisdiction in which that provider or its facilities are located.
Once you leave our store or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or by our Terms and Conditions.
Links:
By clicking on certain links on our site, you may leave our website. We are not responsible for the privacy practices of other sites and we recommend that you read their policies carefully.
ARTICLE 6 – SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to ensure it is not lost, misused, accessed, disclosed, altered or destroyed inappropriately.
If you provide us with your payment card details, they are encrypted using SSL and stored with AES-256 encryption. Although no method of transmission over the internet or electronic storage is 100% secure, we comply with all PCI-DSS requirements and apply additional generally recognised industry standards.
COOKIES
Below is a list of the cookies we use, so that you can decide whether you wish to allow them.
_session_id — unique session identifier; allows Shopify to store information about your session.
_shopify_visit — no data retained; persists for 30 minutes from the last visit. Used to record the number of visits.
_shopify_uniq — no data retained; expires at midnight the following day. Counts store visits from a unique customer.
cart — unique identifier; persists for 2 weeks; stores information about your shopping cart.
_secure_session_id — unique session identifier.
storefront_digest — unique identifier; used to determine whether the current visitor has access to a password-protected store.
ARTICLE 7 – AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, and that you have given us your consent to allow any minor under the age of 18 in your care to use this site.
ARTICLE 8 – CHANGES TO THIS PRIVACY POLICY
We reserve the right to change this privacy policy at any time, so please review it regularly. Changes take effect immediately upon being posted on the site. If we make changes to the content of this policy, we will notify you here that it has been updated.
If our store is acquired by or merged with another company, your data may be transferred to the new owners so that we can continue to sell products to you.
QUESTIONS AND CONTACT
If you wish to access, correct, amend or delete the personal information we hold about you, file a complaint, or simply obtain more information, please contact us at contact@helorya.com