Loréva Privacy Policy
Introduction: Loréva (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our website (the “Site”). This policy applies only to Loréva’s website and not to any third-party websites or services that we do not control. By using our Site, you agree to the terms of this Privacy Policy.
What We Collect
We only collect information necessary to operate our business and provide you with our products and services. This includes:
-
Personal Information You Provide: When you create an account, make a purchase, or contact us, you may give us personal details such as your name, email address, phone number, billing/shipping address, and payment information. (Note: Payment details like credit card numbers are securely handled via Shopify; we do not store your full payment information on our servers.)
-
Order and Transaction Information: Records of the products you purchase, order dates, and transaction amounts are kept to fulfill your orders and comply with accounting/legal requirements.
-
Communications: If you contact us (via email, contact form, or phone), we may collect and retain that correspondence (including your email address or phone number and the content of your message) to address your inquiry and for our records.
-
Website Usage Data (Limited): Loréva does not engage in extensive tracking of your browsing behavior. We do not profile your detailed browsing habits on our Site or elsewhere. However, like most websites, we may automatically receive minimal technical data when you visit the Site – for example, your IP address, browser type, and general information about which pages were visited. This data is collected only to ensure the Site functions properly, for security (e.g., fraud detection), and to help us improve user experience. We do not collect detailed click-by-click behavior or any more information than necessary for basic analytics and operations. Additionally, if you subscribe to our marketing emails, our email platform may use a simple cookie to note if you visit our Site or interact with our content (see Third-Party Services below). This tracking is minimal and is used purely to help us understand engagement (for example, seeing if a newsletter leads you to our Site) for improving our services.
How We Use Your Information
We use the collected information only for legitimate business purposes and as described in this Policy. The main uses of your information include:
-
To Process Orders and Provide Services: We use your personal information to process transactions, fulfill your orders, arrange deliveries, and provide any services or products you request. For example, we need your name and address to ship your order, and your email to send order confirmations or digital receipts.
-
To Communicate with You: We may use your contact information (email or phone) to send important notices related to your orders or account (such as order confirmations, shipping updates, and customer support responses). We may also respond to your inquiries or requests using your provided contact details.
-
For Marketing (With Consent): If you have subscribed to our newsletter or otherwise opted in, we will use your name and email address to send you promotional communications about new products, special offers, or other updates. These communications are sent via our marketing platform (e.g., Klaviyo) and you can unsubscribe at any time. We do not spam, and we only send marketing content to users who have given consent (such as entering an email for newsletters).
-
To Improve Our Website and Services: We may use aggregate and anonymous usage information to understand how our Site is used and to improve its layout, content, and functionality. For instance, knowing which product pages are most visited helps us ensure we have the information users need. Importantly, this is done without profiling individual users’ behavior in detail.
-
To Ensure Security and Compliance: Basic information (like IP address or order history) may be used to protect against fraud, theft, or misuse of our Site. We may also use personal information to comply with legal obligations, such as tax reporting or responding to lawful requests by authorities.
We will not use your personal information for any purposes other than those described above without obtaining your consent, and we do not engage in any form of selling or renting your personal data.
Third-Party Services
Loréva does not share your customer data with any third parties outside of the trusted platforms we use to operate our business. In other words, we do not sell, rent, or give away your personal information to unrelated companies for their own marketing or any other independent use. However, we do rely on a few third-party service providers (platforms) to run our website and services. These providers only access your information as needed to perform tasks on our behalf, and they are contractually obligated to protect your data and use it only for our specified purposes. Below are the primary third-party services we use:
-
Shopify (Website Hosting & E-Commerce Platform): Our online store is built on the Shopify platform. Shopify provides us with the e-commerce infrastructure to display products, manage checkout, and process orders. All personal information you provide through our website (including your name, address, and purchase details) is stored securely on Shopify’s servers. Shopify stores data on secure systems protected by firewallsmorninglavender.com. Shopify also handles payment processing: when you enter payment information at checkout, it is transmitted securely to Shopify’s payment processor. Shopify is certified as a Level 1 PCI-DSS compliant service providershopify.com, which means it adheres to the highest security standards for handling credit card data. Your payment card details are encrypted and processed through Shopify; Loréva itself does not directly see or store your full credit card number or sensitive payment data. (For more information, you can refer to [Shopify’s Privacy Policy]morninglavender.com, but this reference is for transparency – our Privacy Policy governs how we use your data.)
-
Klaviyo (Email Marketing Platform): We use Klaviyo to manage our email communications and marketing campaigns. If you subscribe to our newsletter or make a purchase, your name, email address, and (in some cases) purchase history may be stored in Klaviyo. This allows us to send you tailored updates such as new product announcements or exclusive offers. Klaviyo may also implement a first-party tracking cookie on our Site (often called
__kla_id) which connects your browsing activity with your email profile in a very limited way – for example, it can tell us that an email we sent led you to visit our Site or that you viewed a certain product, so we can send a relevant follow-up (such as a reminder about an item left in your cart). This data is minimal and used only for our internal marketing insights. Klaviyo does not sell or share your personal data; it acts as a processor of the data on our behalf and is bound by strict privacy terms. We ensure that any marketing communications you receive from Loréva via Klaviyo are only sent in accordance with your preferences (and you can opt out at any time). -
Other Service Providers (Current or Future): In addition to Shopify and Klaviyo, we may use other trusted third-party services to help operate our business or improve your experience. For example, this could include couriers/shipping companies (who see your delivery address to ship your orders), payment gateways or payment processors (if we offer alternatives like PayPal, they will process your payment details), or analytics tools to understand site traffic. If we integrate any new third-party service that involves your personal data, we will update this Privacy Policy to include them. Rest assured that any such partners will be held to the same high privacy and security standards – we will only work with platforms that protect your information and use it solely for the purposes we specify.
In summary, aside from the necessary service providers listed above, we do not share your personal information with any third parties. The data you entrust to Loréva stays within our company and its service platforms for the sole purpose of serving you. We will never sell or trade your personal information to outside companies.
Data Security
We take the security of your personal information very seriously. Loréva implements a range of measures to safeguard your data from unauthorized access, alteration, disclosure, or destruction. Our security practices include:
-
Secure Infrastructure: We utilize reputable, security-focused platforms (like Shopify) to host our website and store data. Shopify maintains secure servers and infrastructure – all your data on Shopify is protected by industry-standard security measures such as firewalls and access controls morninglavender.com.
-
Encryption: Our Site is secured via SSL (Secure Sockets Layer) encryption. This means that when you provide personal information (for example, during checkout or account registration), the data is encrypted during transmission and cannot be easily intercepted by third parties. In particular, sensitive information such as payment details is transmitted securely. Shopify, which processes payments for us, is PCI DSS Level 1 compliant, indicating it meets the highest level of payment data securityshopify.com. Your credit card information is encrypted and handled following strict security standards – we never receive your full card number, and Shopify only stores payment data as needed to complete the transaction.
-
Access Control: Within Loréva, personal information is only accessible to people who need it to perform their job (for example, fulfilling your order or providing customer support). Our team members are trained on the importance of privacy and security. Administrative access to systems that contain personal data (like our Shopify store or email platform) is restricted and protected with strong passwords and, where available, two-factor authentication.
-
Monitoring and Maintenance: We keep our website software, plugins, and integrations up-to-date to protect against security vulnerabilities. We also monitor for any suspicious activity on our Site (such as repeated failed logins or unusual order patterns) and take action to prevent fraud or abuse.
-
No Guarantee (Standard Disclosure): While we strive to protect your information with stringent measures, we acknowledge that no method of data transmission or storage is 100% secure. The internet by its nature carries some inherent risks. Therefore, we cannot absolutely guarantee the security of information at all times. However, we continuously review and enhance our security practices to meet or exceed industry best practices, and in the unlikely event of a data breach that affects your personal information, we will follow all applicable laws to notify you and address the issue.
By using our Site and services, you acknowledge that you understand these security measures and limitations. If you have any questions about the security of your data, feel free to contact us (see Contact Information below).
Your Rights
You have rights and choices regarding your personal information. Loréva respects your control over your data, and you may exercise the following rights at any time:
-
Access and Transparency: You have the right to request a copy of the personal information we hold about you. We will provide you with details of the data we have, the purposes for which it is used, and the third parties (service providers) with whom it may be shared.
-
Rectification (Correction): If any of your personal details we have are inaccurate or outdated, you have the right to ask us to correct or update them. For example, if you change your email address or find a spelling error in your name, let us know and we will fix it.
-
Deletion (Right to be Forgotten): You may request that we delete your personal information. For instance, if you have created an account with us and wish to close it, or if you no longer want us to have your information, you can ask us to remove your data from our records. Do note that we might be required to retain certain information for a period of time for legal or transactional record-keeping (e.g., we may keep a record of your purchase for warranty or tax purposes), but we will inform you if such a situation applies.
-
Withdrawal of Consent / Opt-Out: If you have given consent for any optional data uses, such as receiving marketing emails, you can withdraw that consent at any time. Every marketing email from Loréva includes an “Unsubscribe” link at the bottom – clicking that will stop further promotional emails. You can also contact us directly to be removed from our mailing list. Similarly, if we ever rely on your consent for any other data processing, you can revoke your consent and we will stop that processing.
-
Objection to Processing: You have the right to object to certain types of processing of your information, such as data analysis or marketing, if you feel it impacts your rights. In practice, Loréva does not engage in intrusive data processing, but if you have any concerns, please let us know.
-
Data Portability: If applicable, you can request that we provide your personal data to you (or to a nominated third party) in a structured, commonly used, machine-readable format. This is typically relevant if you want to transfer your data to another service.
-
Cookies & Tracking Choices: As mentioned, our use of cookies and tracking is minimal. However, you do have choices: most web browsers allow you to refuse or delete cookies. If you prefer, you can set your browser to reject cookies or alert you when cookies are being used. Keep in mind that certain features of our Site (like keeping items in your cart) might rely on cookies, so disabling them could affect functionality. Nevertheless, you are free to manage cookies as you see fit. We do not currently respond to “Do Not Track” signals, but as noted, we also do not perform robust cross-site tracking of users.
-
California / GDPR Rights: If you are a resident of certain jurisdictions like the European Economic Area (under the GDPR) or California (under CCPA/CPRA), you may have additional privacy rights under those laws. These can include rights such as not being discriminated against for exercising privacy rights, or the right to lodge a complaint with a supervisory authority. Loréva’s policy is to respect all applicable privacy laws. This means if those laws apply to you, we will ensure your rights under those regimes are also honored. For example, European users can object to processing based on legitimate interests, and California users can request information about any data “sharing” (however, as noted, we do not share your data beyond our service providers).
To exercise any of your rights, please contact us using the information in the Contact Information section below. We will verify your identity (to protect your privacy) and respond to your request within the timeframe required by law (or otherwise as promptly as possible). There is no fee for making such requests, though in rare cases if a request is unfounded or excessive, we might charge a reasonable fee or decline, as permitted by law – but we will explain why if that happens.
Changes to This Policy
We may update or modify this Privacy Policy from time to time to reflect changes in our practices, accommodate new services, or comply with legal requirements. When we make changes, we will post the updated Privacy Policy on this page and update the “Effective Date” (or “Last Updated” date) at the top or bottom of the policy. Changes will become effective immediately upon posting the revised policy on our website, unless stated otherwise.
If the changes are material (significant), we may provide a more prominent notice or reach out to you by email or a website notification. However, we encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your information.
Your continued use of the Loréva Site after any changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with any update, you should stop using our Site and services, and you may request that we remove your personal information as per Your Rights above.
Contact Information
Your feedback and questions about privacy are important to us. If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
-
By Email: You can reach our privacy team at info@loreva.com.
We will do our best to respond promptly to your questions or concerns. If you contact us to exercise your privacy rights, we may need to ask you for certain information to verify your identity (to ensure we don’t disclose your data to someone else). We appreciate your trust in Loréva and are committed to honoring that trust by treating your personal information with care and respect.