Privacy Policy

This Privacy Policy describes how lumoraoutdoor (www.lumoraoutdoor.com) collects, uses, retains, and protects the personal data of customers residing in Europe who visit or make purchases through our website.

1. Data Controller

For the purposes of applicable data protection legislation, including the EU General Data Protection Regulation (GDPR) and UK GDPR, the Data Controller responsible for your personal information is:

Data Controller: lumoraoutdoor (Sole Proprietorship)
Address: 52 Bendemeer Rd, Singapore 339934
Email Support: outdoor@lumoraoutdoor.com
Telephone Support: +65 62980027

2. Personal Data We Collect

We collect only necessary personal data required to fulfill orders, process transactions, and provide customer support services. This information includes:

  • Contact & Identification Details: Full name, delivery address, billing address, email address, and telephone number.
  • Transactional Information: Items purchased, order history, purchase value, and transaction timestamps.
  • Technical & Usage Data: IP address, browser type, device information, and standard website usage logs collected through standard essential cookies.

3. Legal Basis and Purposes of Processing

We collect and process your personal data under the following legal bases:

  • Performance of Contract: Processing necessary to fulfill purchase orders, arrange international delivery, and manage customer accounts.
  • Legal Obligation: Retaining financial and transactional records to comply with applicable tax, statutory accounting, and international legal requirements.
  • Legitimate Interests: Managing customer inquiries, safeguarding website operations, and maintaining secure technical infrastructure.
  • Consent: Where applicable for optional analytical cookies or opt-in marketing communications.

4. Payment Processing & Security

All online payment transactions conducted on www.lumoraoutdoor.com are processed securely by our external payment processing partner, Stripe.

When placing an order, your payment card details are transmitted directly to Stripe via encrypted TLS/SSL protocols. We do not store, process, or hold full debit or credit card numbers on our servers. Stripe processes payment details in accordance with strict PCI-DSS Level 1 compliance and applicable regulatory standards. For further details on how Stripe manages transactional data, please refer to Stripe’s Privacy Policy.

5. Third-Party Data Sharing

We do not sell, rent, or trade your personal data to third parties. We share relevant personal information strictly with necessary third-party service providers acting on our behalf to operate our business:

  • Payment Processor: Stripe (for secure payment authorization and transaction processing).
  • Logistics & Postal Carriers: Direct parcel delivery networks and courier services solely for shipping and delivering your purchases.
  • IT & Hosting Infrastructure: Secure web hosting, data storage, and domain infrastructure providers.

6. International Data Transfers

Because our operations are headquartered in Singapore, customer data originating from the European Economic Area (EEA) or the United Kingdom is transferred and processed outside the EEA/UK. Such transfers are conducted in full compliance with GDPR mechanisms, ensuring that standard data protection clauses, contractual safeguards, or necessities for contract performance (Article 49 GDPR) are applied to maintain data security.

7. Data Retention Period

We retain personal data only for as long as required to fulfill the purposes for which it was collected, or to meet statutory, tax, and legal accounting requirements:

  • Order & Transaction Records: Retained for a standard period of 7 years from the transaction date to comply with statutory accounting and tax obligations.
  • Customer Support Communications: Retained for up to 2 years from the date of ticket resolution to ensure quality control and operational consistency.
  • Technical & Security Logs: Retained for up to 12 months for system administration, analytics, and fraud prevention purposes.

Upon the expiration of applicable retention periods, personal data is securely deleted or anonymized.

8. Data Security Measures

We implement appropriate technical and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. While we maintain encrypted SSL connections across our website, no digital transmission method over the internet can be guaranteed as completely immune. We strive to maintain robust, industry-standard protocols to safeguard customer data at all times.

9. Your Legal Data Rights

Under European and UK data protection laws, customers have specific rights regarding their personal data, including:

  • Right of Access: Requesting a copy of the personal data held by us.
  • Right to Rectification: Requesting correction of inaccurate or incomplete personal data.
  • Right to Erasure: Requesting the deletion of personal data where legal obligations permit.
  • Right to Restriction of Processing: Requesting restricted processing under specific legal conditions.
  • Right to Data Portability: Requesting transfer of submitted data in a structured machine-readable format.
  • Right to Lodge a Complaint: Filing a concern with your local European Data Protection Authority if you believe your privacy rights have been infringed.

To exercise any of these rights, please submit a written request to outdoor@lumoraoutdoor.com.

10. Contact & Enquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact our data management team at:

lumoraoutdoor
Official Website: www.lumoraoutdoor.com
Physical Address: 52 Bendemeer Rd, Singapore 339934
Email Support: outdoor@lumoraoutdoor.com
Telephone Support: +65 62980027