LUME BASE LTD (“we,” “us,” or “our”) is committed to protecting the privacy and personal data of our customers (“you”) who use our website to purchase women’s clothing and dresses, serving regions across Europe and North America. This Privacy Policy explains how we collect, use, store, and protect your personal information, in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and relevant data protection laws in North America (e.g., California Consumer Privacy Act, CCPA). By accessing or using our website, you acknowledge that you have read, understood, and agree to the terms of this policy.
1. Information We Collect
We collect personal data that is necessary to fulfill your orders, provide customer support, and enhance your shopping experience. The types of information we gather include:
1.1 Personal Identification Information
- Contact details: Full name, email address, phone number (e.g., +44 71751626282 for our UK support line, or your local number provided at checkout), and shipping/billing addresses (including those in Europe and North America).
- Account information: If you create an account, we store your username, password (encrypted for security), and preferences (e.g., size preferences, favorite clothing categories).
1.2 Transactional Information
- Details related to your purchases: Order history, selected items (e.g., dress styles, sizes, colors), payment method details (we do not store full credit card numbers—this data is processed by trusted third-party payment providers like PayPal or Stripe, which comply with PCI DSS standards), and transaction amounts.
1.3 Non-Personal Information
- Technical data: IP address, browser type, device information (e.g., smartphone, laptop), operating system, and website usage data (e.g., pages visited, time spent on the site, products viewed). This data is collected via cookies and similar tracking technologies (see Section 5 for more on cookies).
2. How We Use Your Information
We use your personal data only for legitimate purposes outlined below, and we will never use it in ways unrelated to the scope of our business:
- Fulfill orders: Process your purchases, arrange shipping (to European and North American addresses), send order confirmations, and provide delivery updates.
- Customer support: Respond to your inquiries (via email, phone, or website messages), resolve issues (e.g., returns, exchanges), and address concerns about your orders.
- Improve our services: Analyze website usage and purchase trends to optimize our product range (e.g., expanding popular dress styles), enhance website functionality, and personalize your shopping experience (e.g., recommending items based on your browsing history).
- Compliance with legal obligations: Maintain records for tax and accounting purposes (as required by UK and EU law) and respond to lawful requests from regulatory authorities.
- Marketing (with your consent): Send you updates about new women’s clothing collections, promotions, or exclusive offers—you can opt out of marketing communications at any time (see Section 4).
3. Sharing Your Information
We do not sell or rent your personal data to third parties. We may share your information only with trusted partners who assist us in operating our business, and these partners are contractually obligated to protect your data:
- Payment processors: PayPal, Stripe, or other providers who handle payment transactions (they only receive data necessary to process payments, such as your name and billing address).
- Shipping carriers: Royal Mail (for European deliveries) and DHL/USPS (for North American deliveries), who need your shipping address and contact details to deliver your orders.
- IT service providers: Companies that maintain our website, host our data, or provide cybersecurity services—they have access to data only to perform their roles.
We may also share your data if required by law (e.g., to comply with a court order) or to protect our legal rights (e.g., investigating fraud or unauthorized use of our website).
4. Your Data Rights
Under GDPR and North American data protection laws, you have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask to update or correct inaccurate or incomplete data (e.g., a change to your shipping address).
- Erasure: Request that we delete your personal data (subject to legal obligations, such as retaining transaction records for tax purposes).
- Restriction: Ask us to limit how we use your data (e.g., if you dispute the accuracy of the information).
- Data portability: Request a copy of your data in a structured, machine-readable format (e.g., to transfer to another retailer).
- Opt-out of marketing: Unsubscribe from marketing emails by clicking the “Unsubscribe” link in any promotional message, or contact us at [email protected].
To exercise these rights, please contact our data protection team at [email protected], providing your full name and order number (if applicable) to verify your identity. We will respond to your request within 30 days (or 45 days for complex requests, as permitted by law).
5. Cookies and Tracking Technologies
Our website uses cookies (small text files stored on your device) to enhance your browsing experience. We use two types of cookies:
- Necessary cookies: Required for the website to function (e.g., remembering items in your cart, enabling checkout). These cannot be disabled.
- Analytics cookies: Used to track website usage (e.g., which pages are most visited) to improve our services. These do not collect personal data.
You can manage your cookie preferences through your browser settings (e.g., Chrome, Safari, Firefox), but disabling non-necessary cookies may limit some website features.
6. Data Security and Storage
We take robust measures to protect your personal data from unauthorized access, loss, or theft:
- Data is stored on secure servers with encryption (SSL/TLS) for data transmitted between your device and our website.
- Access to your data is restricted to authorized LUME BASE LTD employees (e.g., customer support, order processing teams) who have a legitimate need to use it.
- We retain your personal data only for as long as necessary: transaction records are kept for 7 years (to comply with UK tax law), and account data is retained until you request deletion (or 2 years of inactivity, after which we anonymize the data).
For customers in North America, please note that your data may be transferred to our UK-based servers (as our headquarters is in Kington, Herefordshire). We ensure these transfers comply with GDPR and North American data protection laws, using standard contractual clauses (SCCs) to guarantee the same level of data protection.
7. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in laws, technology, or our business practices. When we make changes, we will revise the “Last Updated” date at the top of this page and notify you via email (if you have an account) or a pop-up notice on our website. We encourage you to review this policy regularly.




