Privacy policy

1. What We Do with Your Information

When you purchase something from our online shop, we collect the personal data you provide (e.g., name, address, email address) as part of processing your order.
When you visit our shop, we also automatically collect certain technical data such as your device’s IP address, browser type, and operating system, in order to help us improve our services.
Email Marketing (if applicable): With your explicit consent, we may send you information about our shop, new products, and updates. You may unsubscribe at any time by using the unsubscribe link in our emails.
SMS Marketing & Notifications (if applicable): If you provide your phone number during checkout and complete a purchase, you may—only with your prior consent—receive SMS messages about your order status (e.g., cart reminders) or promotional offers. You can opt out at any time by replying “STOP” (standard messaging rates from your provider may apply).
Legal Basis: We process your data to fulfill contracts (such as completing purchases), comply with legal obligations, protect our legitimate business interests (such as ensuring the secure operation of our shop), and on the basis of your consent for specific activities like marketing.

2. Consent

How do we obtain your consent? When you provide personal data to complete a transaction, verify your payment method, place an order, arrange delivery, or process a return, we consider this as consent to use your data for that specific purpose. For any other purpose (e.g., marketing), we will ask you for your explicit consent.
How do I withdraw consent? You can withdraw your consent at any time by contacting us at support@elyssencederma.com. Withdrawal of consent will not affect data processing that has already occurred.

3. Disclosure of Information

We may disclose your personal data if required by law or if you violate our Terms and Conditions.

4. Our Shop Platform

Our shop is hosted by Shopify Inc. (or another e‑commerce platform provider). The platform provides us with the online store infrastructure to sell our products and services.
  • Data Processing: Your data may be stored on secure servers protected by firewalls.
  • Payments: We do not store complete credit card details. Payment transactions are encrypted and processed in compliance with recognized payment industry standards (e.g., PCI DSS).
  • International Transfers: Depending on your location, your data may be processed in other countries. The platform provider uses recognized safeguards to protect your information during such transfers. Please refer to Shopify’s Terms of Service and Privacy Policy for details.

5. Third-Party Services

Third-Party Service Providers
The third-party providers we engage will only collect, use, and disclose your personal information to the extent necessary to allow them to perform the services we require (for example, payment gateways, shipping partners, and analytics providers).

Each provider is independently responsible for its own processing activities and maintains its own privacy policy. We recommend that you review those policies to understand how your personal data may be used.

Please note that your information may be processed and stored in the jurisdictions in which these providers operate. This means your data may be subject to the laws and lawful access requests of authorities in those jurisdictions. Where reasonably practicable, we seek to ensure that appropriate safeguards are in place to protect your personal information in accordance with UK GDPR requirements.

External Links
When you click on links in our shop, you may be redirected to external websites. We are not responsible for the privacy practices or content of such third-party sites. We encourage you to read their privacy notices before providing any personal information.

6. Security

We use appropriate technical and organizational measures to protect your personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. All payment information is encrypted (e.g., SSL and AES‑256).
Although no method of electronic transmission or storage is 100% secure, we comply with industry best practices and standards to protect your information.

7. Cookies

We use cookies to enable the functionality of our shop, analyze traffic, and (with your consent) for marketing purposes.
  • Strictly necessary cookies: Required to operate the website (e.g., saving cart content).
  • Performance/Analytics cookies: Help us improve usability and content.
  • Marketing cookies: Used to provide relevant advertising.
  • Cookie Management: You can view all cookies in use and manage your preferences through our cookie banner or browser settings.
A full list of cookies used by Shopify (or our shop platform) is available in the “Manage Cookie Settings” section of our website. Please note the list may vary depending on your shop configuration.

8. Minimum Age and Consent

By using this website, you confirm that you are at least the age of majority in your place of residence, or that you have obtained consent from your parent or guardian to allow your minor dependents to use this website.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will take effect upon being posted on this website. In the event of a business transfer, merger, or acquisition, your personal data may be transferred so that we can continue to serve you.

10. Contact & Your Rights

If you would like to access, correct, update, or delete the personal information we hold about you, or if you have questions or complaints, please contact us at: support@elyssencederma.com.
Depending on your place of residence, you may have certain legal rights over your personal data, such as:
  • Access and correction
  • Deletion or restriction of processing
  • Data portability
  • Objecting to certain processing activities
  • The right to lodge a complaint with your local supervisory authority (where applicable)