PRIVACY POLICY

Last updated: January 8, 2026

LUMA operates this store and website, including all related information, content, features, tools, products, and services (collectively, the “Services”) to provide you with a curated shopping experience. LUMA is an EU-based company serving U.S. customers, and the Services are powered by Shopify, which enables us to provide the Services to you.

This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction through the Services, or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy governs with respect to the collection, processing, and disclosure of your personal information.

Please read this Privacy Policy carefully. By accessing or using any of the Services, you acknowledge that you have read and understood this Privacy Policy.


Personal Information We Collect or Process

When we use the term “personal information”, we mean information that identifies, relates to, describes, or can reasonably be linked to you or another person. Personal information does not include information that is anonymized or de-identified.

Depending on how you interact with the Services, where you reside, and as permitted or required by applicable law, we may collect or process the following categories of personal information:

  • Contact details, including your name, billing address, shipping address, phone number, and email address.

  • Financial information, including payment card details, transaction data, payment confirmations, and related information (processed securely by our payment providers).

  • Account information, including usernames, passwords, preferences, and settings.

  • Transaction information, including items viewed, added to cart or wishlist, purchased, returned, exchanged, or canceled.

  • Communications, including information you provide when contacting customer support.

  • Device information, including IP address, browser type, device identifiers, and network information.

  • Usage information, including how and when you interact with the Services.


Sources of Personal Information

We may collect personal information from the following sources:

  • Directly from you, when you create an account, place an order, contact us, or otherwise provide information.

  • Automatically, through cookies, pixels, and similar technologies when you use the Services.

  • From service providers, who process information on our behalf.

  • From partners or other third parties, as permitted by law.


How We Use Your Personal Information

We may use your personal information to:

Provide, Personalize, and Improve the Services

  • Process payments and fulfill orders

  • Manage accounts and preferences

  • Arrange shipping, returns, and exchanges

  • Enable reviews and customer support

  • Personalize product recommendations and shopping experience

Marketing and Advertising

  • Send promotional communications by email, SMS, or mail (subject to your preferences)

  • Display advertisements on our website and on third-party platforms based on your interactions with the Services

Security and Fraud Prevention

  • Protect accounts, transactions, and the integrity of our Services

  • Detect and prevent fraudulent or unauthorized activity

Communication

  • Respond to inquiries and provide customer support

Legal and Compliance

  • Comply with applicable laws and regulations

  • Enforce our policies and protect our legal rights


How We Disclose Personal Information

We may disclose personal information to:

  • Shopify, service providers, and vendors performing services on our behalf (payment processing, hosting, analytics, fulfillment, customer support).

  • Advertising and marketing partners to deliver personalized and interest-based advertising.

  • Affiliates within our corporate group.

  • Authorities or legal entities, where required by law or to protect our rights.

  • Third parties, when you direct or consent to such disclosure.


Relationship with Shopify

Our Services are hosted by Shopify. Shopify processes personal information to provide and improve the Services and may combine data from interactions across merchants. Shopify acts as an independent controller for certain processing activities.

To learn more, visit the Shopify Consumer Privacy Policy and manage preferences via the Shopify Privacy Portal:
https://privacy.shopify.com/en


Third-Party Websites

The Services may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. Please review their policies independently.


Children’s Data

The Services are not intended for children. We do not knowingly collect personal information from individuals under the age of 16. We do not knowingly sell or share personal information of minors under applicable law.


Security and Retention

We implement reasonable safeguards to protect your information. However, no system is completely secure. We retain personal information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, and resolve disputes.


Your Rights and Choices

Depending on your location, you may have the right to:

  • Access / Know what personal information we hold about you

  • Delete personal information

  • Correct inaccurate personal information

  • Portability, where applicable

  • Opt out of certain marketing communications

You may unsubscribe from promotional emails at any time. Transactional emails related to orders may still be sent.


California Residents – Additional Privacy Rights

If you are a California resident, you have the right to opt out of the sale or sharing of your personal information for targeted advertising purposes under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

You may exercise this right by visiting our “Your Privacy Choices” page or by enabling a Global Privacy Control (GPC) signal in your browser. We will treat such signals as valid opt-out requests in accordance with applicable law.


International Transfers

Your personal information may be transferred, stored, and processed outside your country of residence. Where required, we rely on recognized legal mechanisms such as Standard Contractual Clauses to protect such transfers.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.


Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Email: contact@skincareluma.com
Address: 25 Le Tacret, La Bernardière, 85610, France

For purposes of applicable data protection laws, LUMA acts as the data controller of your personal information.