Your information
Privacy & data use
How Loveli Luxury International intends to collect, use, protect, retain, and respond to requests about personal information.
Draft for legal review only. This policy has been prepared to establish a clear customer-facing standard. It must be reviewed and approved by Kenyan legal counsel before publication or contractual reliance.
01
What we collect
We collect only information needed to provide an account, deliver an order, process payment, support a customer request, prevent fraud, or meet a legal obligation. Depending on the service used, this may include contact, delivery, order, account, payment-reference, verification, and support information.
- Account and contact details provided by you.
- Delivery and order information needed to fulfil a purchase.
- Payment references and status information from approved payment providers; Loveli Luxury should not store card security codes.
- Security and service records needed to prevent fraud, protect the service, and investigate incidents.
02
Why we use it
Personal information should be used only for the stated transaction or service purpose, legitimate security and fraud-prevention needs, legal obligations, customer support, and any separate marketing activity for which an appropriate lawful basis and notice exist.
- To create and protect accounts, confirm orders, and deliver products.
- To process, reconcile, refund, and evidence legitimate payments.
- To prevent abuse, verify webhook events, rate-limit sensitive requests, and investigate suspected fraud.
- To respond to customer questions, refunds, complaints, and data-subject requests.
03
Sharing and international processing
Where service providers process information for hosting, authentication, payment, email, monitoring, or analytics, Loveli Luxury should document the provider, purpose, security obligations, retention, and any transfer safeguards before information is shared or processed outside Kenya.
- Do not sell personal information.
- Use processors only where a documented business purpose and appropriate safeguards exist.
- Publish and maintain a current processor and international-transfer record after counsel review.
04
Retention, security, and your requests
Information should be retained only for as long as necessary for the stated purpose, legal obligations, fraud prevention, financial records, or dispute evidence. Customers should be able to request access, correction, deletion where applicable, or a review of how their information is handled through a published contact route.
- Use HTTPS, restricted access, role permissions, audit trails, and security monitoring.
- Maintain an approved retention schedule for account, order, payment, verification, support, and security records.
- Publish an approved privacy contact and complaint/escalation route before this page goes live.