Privacy Policy

Privacy Policy & GDPR Compliance

SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address, and email address.

When you browse our store, we also automatically receive your computer's internet protocol (IP) address to provide us with information that helps us learn about your browser and operating system.

Email marketing (if applicable): With your permission, we may send you emails about our store, new products, and other updates.

SECTION 2 - LEGAL BASIS FOR PROCESSING DATA
Under GDPR, we process your personal data based on:

  • Consent: When you subscribe to our emails, agree to cookies, or provide marketing opt-in.
  • Contractual necessity: When processing transactions or fulfilling orders.
  • Legitimate interest: For website security, fraud prevention, and improving services.
  • Legal obligations: When required by law.

SECTION 3 - CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery, or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.

How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, or for the continued collection, use, or disclosure of your information, at any time by contacting us at info@lightmybricks.com or mailing us at:

Light My Bricks HQ
5/26 Rushdale Street
Knoxfield, VIC, 3180
Australia

SECTION 4 - DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.

SECTION 5 - PAYMENT
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.

All direct payment gateways adhere to PCI-DSS requirements as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express, and Discover.

For more insight, you may also want to read Shopify's Terms of Service or Privacy Statement.

SECTION 6 - THIRD-PARTY SERVICES
In general, third-party providers used by us will only collect, use, and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other transaction processors, have their own privacy policies in respect to the information we provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand how your personal information will be handled by these providers.

If you proceed with a transaction involving a third-party service provider, your information may become subject to the laws of the jurisdiction(s) where that provider or its facilities are located.

SECTION 7 - DATA RETENTION
We retain your personal data only as long as necessary to fulfill the purposes stated in this policy. The retention period depends on the type of data:

  • Transaction Data: Retained for tax and accounting purposes (5-7 years).
  • Marketing Data: Retained until you opt out.
  • User Account Data: Retained until you request deletion.

SECTION 8 - YOUR RIGHTS UNDER GDPR
Under GDPR, you have the following rights:
Right to Access – Request a copy of your data.
Right to Rectification – Correct inaccurate data.
Right to Erasure – Request deletion of your personal data.
Right to Restrict Processing – Limit how we use your data.
Right to Data Portability – Receive your data in a transferable format.
Right to Object – Opt-out of marketing.
To exercise these rights, contact us at info@lightmybricks.com.

SECTION 9 - DATA DELETION REQUEST
If you wish to delete your personal data, you can:

  • Visit your account settings (if applicable) and request deletion.
  • Contact us at info@lightmybricks.com with the subject "Data Deletion Request."
    We will process your request within 30 days, as required by GDPR.


SECTION 10 - COMPLIANCE FOR SPECIFIC REGIONS

California (CCPA Compliance)

  • California residents have the right to request access to their personal data, opt out of data selling (if applicable), and request deletion.
  • To exercise your rights, email us at info@lightmybricks.com.

Canada (PIPEDA Compliance)

  • Personal information may be transferred and stored outside of Canada in compliance with legal safeguards.
  • Canadian users can request access, correction, or deletion of their data by contacting us at info@lightmybricks.com.

Australia (APP Compliance)

  • We collect only the necessary personal data to provide our services.
  • Australian users can request access to or deletion of their data by contacting us at info@lightmybricks.com.

SECTION 11 - SECURITY
We implement security measures such as encryption, access controls, and secure data storage to protect your data.

SECTION 12 - COOKIES & TRACKING TECHNOLOGIES
Here is a list of cookies that we use. We’ve listed them here so that you can choose if you want to opt-out of cookies or not.

_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).

_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.

cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.

_secure_session_id, unique token, sessional storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.

SECTION 13 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.

SECTION 14 - CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

SECTION 15 - CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at:
Email: info@lightmybricks.com
Website: https://lightmybricks.com

Thank you for trusting LMB with your data!