Lunstra Ltd – Detailed Privacy Policy
Effective Date: 8/8/2025
At Lunstra Ltd, we value your privacy and are committed to maintaining your trust. This Privacy Policy describes in full how your personal information is collected, used, shared, and protected when you use our services or interact with our website (www.lunstra.com). It applies to all site visitors, customers, and users of any Lunstra services.
1. Who We Are
Lunstra Ltd is a UK-based e-commerce company offering high-quality smart home and lifestyle products. We are registered in the United Kingdom and operate fully within the frameworks of UK GDPR and relevant consumer protection laws.
Contact Details:
- Email: [email protected]
- Phone: +44 794442608
- Registered Address: [Insert Registered Company Address Here]
You can contact our Data Protection Officer at the email above for any queries regarding your personal information.
2. What Personal Data We Collect
We collect the following categories of personal data:
A. Information You Provide Directly:
- Full Name
- Billing and Shipping Address
- Phone Number
- Email Address
- Payment Information (handled securely via third-party providers)
- Account login details (if registered)
- Communication history with customer service
B. Automatically Collected Information:
- IP Address
- Device Type and Browser
- Date and time of access
- Page views, clicks, and site behavior
- Referral source (e.g., Google, Facebook ad)
C. Cookies and Analytics Tools: We use cookies and similar technologies (such as pixels and tags) to gather information about your browsing behavior. For more information, see our Cookie Policy.
3. How We Use Your Data
We only collect data necessary to:
- Fulfill your orders and provide customer service
- Confirm payment and delivery
- Respond to customer inquiries
- Offer promotional materials (if you’ve opted in)
- Maintain internal records for accounting and auditing
- Detect and prevent fraud, abuse, or illegal activities
- Improve website performance and personalize your experience
- Comply with legal and regulatory requirements
Example Use Cases:
- Sending you a tracking link after purchase
- Alerting you about your warranty or support eligibility
- Notifying you of a promotion you signed up for
4. Legal Bases for Processing Personal Data
We rely on the following lawful bases under UK GDPR:
- Consent – For sending marketing messages and collecting optional cookies
- Contract – To fulfill orders and deliver services
- Legal Obligation – For invoicing, tax records, fraud checks
- Legitimate Interests – For security, analytics, and improving customer experience
You may withdraw your consent for marketing at any time by clicking the “unsubscribe” link or contacting us.
5. Data Sharing with Third Parties
We only share your data with:
- Payment Processors (Stripe, PayPal) for secure transactions
- Shipping Partners (e.g., Royal Mail, DHL) to deliver orders
- Marketing Platforms (e.g., Klaviyo, Mailchimp, Meta Ads)
- Analytics Providers (Google Analytics, Hotjar)
- Legal or Regulatory Authorities, if required by law
Each partner is contractually obligated to handle your data securely and confidentially, in compliance with data protection laws.
6. International Data Transfers
Your personal information may be processed in or transferred to countries outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs)
- Data processing agreements
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Order and transaction data: up to 6 years (for accounting and tax compliance)
- Customer service records: up to 2 years
- Marketing data: until you unsubscribe or request deletion
- Analytics data: typically 14 to 26 months, depending on the tool used
When no longer needed, your data is securely deleted or anonymized.
8. Data Security Measures
We implement the following measures to protect your information:
- SSL encryption across our website
- Firewalls and secure server infrastructure
- Strong password protection and 2FA (where applicable)
- Access control for sensitive information
- Staff training on data protection
Payment data is never stored on our servers. Transactions are processed via PCI-DSS–compliant platforms.
9. Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability – request a copy in a common format
- Withdraw consent at any time
- Lodge a complaint with the ICO (Information Commissioner’s Office) if you believe your rights have been violated
To make a data request, email [email protected] with the subject “Data Request.” We aim to respond within 30 days.
10. Children’s Data
We do not knowingly collect or store data of children under 13 years. If we discover such data has been collected, we will delete it immediately.
11. Cookies & Tracking Tools
Cookies are used to:
- Remember your login or cart details
- Analyze website traffic and performance
- Deliver personalized ads (with your consent)
You can manage cookies through your browser or opt out of ad tracking via the AdChoices program.
12. Updates to This Policy
We may update this Privacy Policy as needed to reflect changes in legal requirements or our practices. You will be notified via email or on our website if material changes occur.
13. Contacting Us
If you have questions, concerns, or wish to exercise your rights:
- Email: [email protected]
- Phone: +44 794442608
- Registered Office: 71-75 Shelton Street
- Covent Garden
- London
- WC2H 9JQ
Thank you for trusting Lunstra Ltd with your information. We are committed to protecting your privacy with integrity and transparency.