Privacy &
Data Policy
Effective: January 2025. LampAndGlow is based in Karachi, Pakistan. Your data is used to fulfill your order — nothing else.
01. Data We Collect
When you place an order or create an account we collect only what's needed to serve you:
- Name & contact details
- Shipping & billing address
- Email address
- Payment reference (not card details)
- Order history
- IP address & browser type
We never collect government IDs, biometric data, or financial account details.
02. How We Use It
Order Fulfilment
Processing, packing, and shipping your order.
Customer Support
Responding to queries, claims, and return requests.
Account Management
Maintaining your account, order history, and preferences.
Marketing (opt-in)
Offers and updates only if you've subscribed. Unsubscribe anytime.
We do not sell, trade, or rent your personal data to any third party.
03. Storage & Security
Your data is stored on encrypted servers with TLS in transit and AES-256 at rest. Payment processing is handled entirely by Stripe — we never store card numbers or CVVs.
"We retain your order data for up to 5 years as required under Pakistan's tax regulations, after which it is permanently deleted."
04. International Markets
LampAndGlow ships from Pakistan to 5 active markets. When you order internationally, your data is transferred to and processed in Pakistan where our servers are located. By placing an order you consent to this.
Our Active Markets
Canada
North America
European Union
Europe
Pakistan
South Asia
UNITED KINGDOM
Europe
United States
North America
Your Rights by Jurisdiction
European Union (GDPR)
Right to access, correct, port, and erase your data. Lawful basis: contract performance. Lodge complaints with your national DPA.
United Kingdom (UK GDPR)
Same rights as EU. Complaints may be lodged with the ICO (ico.org.uk). 14-day return right on eligible goods.
United States (CCPA)
California residents may request disclosure of data collected and opt out of data sale (we do not sell data).
Pakistan (PECA / DPDP)
Our home jurisdiction. We comply with PECA 2016 and applicable data protection provisions. Contact us directly for any data request.
All Other Markets
We apply data minimisation, purpose limitation, and equivalent security standards to all customers regardless of location.
05. Your Rights
Regardless of where you're located, you may contact us at any time to:
- Access a copy of the personal data we hold about you
- Correct any inaccurate or incomplete data
- Request deletion (subject to legal retention obligations)
- Withdraw marketing consent at any time
- Request data portability in machine-readable format
Email privacy@lampandglow.com. We respond within 30 days.
Questions about your data?
We're happy to help.