Who We Are
Lumera Crystals ("we", "our", "us") operates the storefront at lumera-crystals.polsia.app. We sell one-of-a-kind Brazilian crystal pieces shipped directly from Brazil to customers worldwide.
This Privacy Policy explains what personal information we collect when you browse or purchase from our store, how we use it, and your rights regarding that data. By using our site, you agree to the practices described here.
Information We Collect
We collect information in the following ways:
- Purchase information: When you complete a purchase, Stripe collects your name, email address, billing address, and payment details. We receive a limited confirmation (name, email, order total) to fulfill your order — we never see or store your full card number.
- Contact inquiries: If you email us or submit a contact form, we retain your name, email, and message to respond to your inquiry.
- Automatically collected data: Our server logs may record your IP address, browser type, referring URL, and pages visited to maintain site security and diagnose technical issues.
- Cookies: We use minimal functional cookies necessary for site operation (e.g., session state). We do not use advertising tracking cookies.
How We Use Your Information
We use the information we collect to:
- Process and fulfill your order, including communicating with our fulfillment partners in Brazil
- Send order confirmations and shipping notifications to your email
- Respond to customer service inquiries
- Improve site performance and diagnose errors
- Comply with legal obligations
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Third-Party Services
We work with a small number of trusted third-party services to operate our store:
- Stripe — Payment processing. Stripe is PCI DSS Level 1 certified. When you check out, you are interacting directly with Stripe's secure payment infrastructure. Stripe's privacy policy is available at stripe.com/privacy.
- Cloudflare R2 — Image and asset hosting. Product photos are served from Cloudflare's CDN. Cloudflare may log request metadata per their standard practices.
- Google Fonts — Typography. Loading this page makes a request to Google's servers to retrieve font files. Google's privacy policy applies to that request.
- Fulfillment partners — We share your name, shipping address, and order details with our fulfillment partners in Brazil to pack and ship your piece.
Cookie Usage
Our website uses cookies only for essential site functionality. We do not use advertising, retargeting, or behavioral tracking cookies.
Essential cookies may be set by our server to maintain basic session state during your visit. These expire when you close your browser or shortly thereafter.
You can disable cookies in your browser settings. Doing so will not prevent you from viewing the site or completing a purchase, as our checkout is handled by Stripe's hosted payment pages.
How Long We Keep Your Data
We retain order-related information (name, email, shipping address, order amount) for 3 years from the date of purchase to support returns, warranty claims, and legal compliance.
Contact inquiry records are retained for 12 months and then deleted.
Server logs are retained for up to 90 days for security and diagnostic purposes.
You may request deletion of your personal information at any time (see contact section below). Requests will be fulfilled within 30 days, subject to our legal obligations to retain certain records.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request your data in a machine-readable format
- Objection: Object to certain types of processing
To exercise any of these rights, contact us at the email below. We respond to all requests within 30 days.
How We Protect Your Data
We take reasonable technical and organizational measures to protect your personal information against unauthorized access, loss, or disclosure. These include:
- All payment processing is handled by Stripe — we never store card data on our servers
- Our servers communicate over TLS (HTTPS) exclusively
- Access to order data is restricted to personnel who need it to fulfill orders or provide customer support
No method of transmission over the internet is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
Children's Privacy
Our store is intended for adults. We do not knowingly collect personal information from children under the age of 13. If you believe we have inadvertently collected information from a child, please contact us immediately and we will delete it.
Updates to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be noted with a brief summary. Your continued use of our store after any change constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions, data access requests, or deletion requests:
Lumera Crystals
Email: lumera-crystals@polsia.app
We respond to all inquiries within one business day.