LureLab Privacy Policy

Effective Date: [October 24, 2025]

1. Introduction

This Privacy Policy ("Policy") governs the collection, use, storage, protection, and disclosure of personal information (as defined below) provided by users ("User" or "You") of the HeartGreet website (the "Website"), operated by HeartGreet ("We," "Us," or "Our"). This Policy is designed to comply with applicable global privacy regulations, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant data protection laws. By accessing or using the Website, registering an account, placing an order, or submitting any information to Us, You acknowledge that You have read, understood, and agree to be bound by the terms of this Policy. If You do not agree with this Policy, please do not use the Website or provide any personal information to Us.

2. Information We Collect

2.1 Personal Information

We collect personal information that You voluntarily provide to Us in connection with Your use of the Website, including but not limited to:

  • Contact information: Full name, email address, phone number, shipping address, and billing address.
  • Account information: Username, password (encrypted), and account preferences.
  • Payment information: Credit/debit card details, bank account information, or other payment method details (processed through third-party payment processors; We do not store full payment card information).
  • Order information: Purchase history, order details, product selections, and delivery preferences.
  • Communication information: Content of emails, messages, or other communications You send to Us (e.g., customer support inquiries, feedback).
  • Personalization information: Preferences for product recommendations, marketing communications, and Website usage settings.

2.2 Non-Personal Information

We also collect non-personal information that does not identify You individually, including:

  • Technical information: IP address, browser type and version, operating system, device type, unique device identifiers, and information about how You access and use the Website (e.g., pages visited, time spent on pages, links clicked, referral source).
  • Aggregated data: Statistical data about user behavior, product popularity, and Website performance (aggregated such that it no longer identifies any individual).

2.3 Collection Methods

We collect information through the following methods:

  • Direct collection: When You register an account, place an order, subscribe to marketing communications, fill out forms, or contact Us.
  • Automated collection: Through cookies, web beacons, and other tracking technologies (see Section 2.4 for details).
  • Third-party sources: With Your consent, from trusted third parties such as payment processors, shipping providers, and social media platforms (to verify information or facilitate services).

2.4 Cookies and Tracking Technologies

We use cookies (small text files stored on Your device) and similar tracking technologies to enhance Your Website experience, analyze usage patterns, and personalize content. You can manage cookie preferences through Your browser settings, but disabling certain cookies may limit functionality of the Website. We use both session cookies (expire when You close Your browser) and persistent cookies (remain on Your device for a set period).

3. How We Use Your Information

We use Your personal information only for legitimate purposes consistent with this Policy and applicable laws, including:

  • To provide and maintain the Website and services (e.g., process orders, deliver products, manage accounts).
  • To fulfill Your requests (e.g., process returns, respond to customer support inquiries).
  • To personalize Your experience (e.g., recommend products based on purchase history or browsing behavior).
  • To communicate with You (e.g., send order confirmations, shipping updates, marketing communications with Your consent).
  • To improve the Website and services (e.g., analyze user behavior, identify areas for enhancement).
  • To ensure security and prevent fraud (e.g., verify account information, detect unauthorized access).
  • To comply with legal obligations (e.g., tax reporting, responding to legal requests).

We will not use Your personal information for purposes unrelated to those stated herein without first obtaining Your explicit consent.

4. Data Storage and Security

4.1 Storage

We store Your personal information on secure servers located in [jurisdiction] or with trusted third-party service providers. We retain personal information only for as long as necessary to fulfill the purposes outlined in this Policy, or as required by law (e.g., tax, legal, or audit obligations). After the retention period, We will securely delete or anonymize Your personal information.

4.2 Security Measures

We implement appropriate technical and organizational security measures to protect Your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit (via SSL/TLS) and at rest.
  • Access controls limiting access to personal information to authorized personnel only.
  • Regular security audits, vulnerability assessments, and employee training.
  • Firewalls, anti-malware software, and other technical safeguards.

While We strive to protect Your personal information, no security system is completely infallible. You acknowledge that there is a risk of unauthorized access to Your information despite Our best efforts.

5. Sharing and Disclosure of Your Information

We do not sell, rent, or lease Your personal information to third parties for marketing purposes without Your explicit consent. We may share Your personal information in the following limited circumstances:

  • With third-party service providers who assist Us in operating the Website or providing services (e.g., payment processors, shipping carriers, email service providers). These providers are contractually obligated to protect Your personal information and use it only to perform the services We request.
  • To comply with legal obligations, including but not limited to responding to subpoenas, court orders, or other legal processes; enforcing Our Terms of Service; or protecting the rights, property, or safety of Us, Our users, or the public.
  • In connection with a merger, acquisition, sale of assets, or other business transaction, where personal information may be transferred as part of the business assets (You will be notified of any such transfer via the Website or email).
  • With Your explicit consent or at Your direction (e.g., sharing information with a friend or family member if You request a gift delivery).

We may share non-personal or aggregated data with third parties for research, marketing, or analytical purposes, as this data does not identify any individual.

6. Your Rights Regarding Your Information

Under applicable privacy laws, You have the following rights regarding Your personal information:

  • Right to Access: Request access to the personal information We hold about You, including details of how it is collected, used, and shared.
  • Right to Correction: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of Your personal information, subject to legal or contractual obligations that require retention.
  • Right to Restriction of Processing: Request that We restrict processing of Your personal information in certain circumstances (e.g., if You dispute the accuracy of the data).
  • Right to Data Portability: Request a copy of Your personal information in a structured, machine-readable format, or request that it be transferred to another data controller (where technically feasible).
  • Right to Withdraw Consent: Withdraw consent for certain uses of Your personal information (e.g., marketing communications) at any time. Withdrawing consent will not affect the lawfulness of processing based on consent before withdrawal.
  • Right to Object: Object to processing of Your personal information for direct marketing or other purposes based on legitimate interests.

To exercise these rights, please contact Us using the information provided in Section 8. We may request additional information to verify Your identity before processing Your request, to ensure the security of Your personal information. We will respond to valid requests within a reasonable timeframe as required by law.

7. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in Our practices, legal obligations, or technological advancements. When We make material changes, We will notify You by:

  • Posting the updated Policy on the Website with a revised "Last Updated" date.
  • Sending a notification to Your registered email address (if You have an account).
  • Displaying a prominent notice on the Website homepage (for significant changes).

The updated Policy will take effect immediately upon posting, unless otherwise specified. Your continued use of the Website after the effective date constitutes acceptance of the updated Policy. We encourage You to review this Policy periodically to stay informed about how We protect Your information.

8. Contact Us

If You have any questions, concerns, or requests regarding this Privacy Policy or the processing of Your personal information, please contact Us at:

  • Email: dentory888@gmail.com

We will respond to Your inquiry within 30 days of receipt. If You are unsatisfied with Our response, You may have the right to lodge a complaint with a data protection authority in Your jurisdiction.