Privacy Policy
Contents
1. Who We Are
LIEN GROUP ("we", "us", "our") operates the website at this domain as an international luxury goods e-commerce platform. We are the data controller for personal information collected through our website.
For any privacy matters, you may contact us at: privacy@liengroup.com
2. Data We Collect
2.1 Information You Provide
- Order information: name, email address, phone number, shipping address, postcode, country
- Account information: username, email address, password (hashed)
- Payment information: processed entirely by Stripe — we never store full card numbers on our servers
- Communications: messages sent to us via WhatsApp or email
2.2 Information Collected Automatically
- IP address and approximate location (country/region level)
- Browser type, device type, operating system
- Pages visited, time spent, referral source
- Session identifiers (stored in sessionStorage, not cookies)
2.3 Information from Third Parties
- Payment status from Stripe (no card details shared back to us)
- Delivery confirmation from shipping providers
3. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Process and fulfil your order | Name, address, email, phone, payment status | Contract performance |
| Send order confirmation and updates | Email, phone (WhatsApp) | Contract performance |
| Fraud prevention and security | IP address, order details | Legitimate interest |
| Improve our website | Anonymised analytics data | Legitimate interest |
| Marketing emails (only if opted in) | Email address | Consent |
| Legal compliance | Order & transaction records | Legal obligation |
We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following lawful bases:
- Contract (Art. 6(1)(b) GDPR): processing necessary to fulfil your purchase
- Legal obligation (Art. 6(1)(c)): retaining financial records for tax compliance
- Legitimate interests (Art. 6(1)(f)): fraud prevention, site analytics
- Consent (Art. 6(1)(a)): marketing communications — you may withdraw at any time
🇪🇺 EU/UK customers: You have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France).
5. Who We Share Your Data With
| Recipient | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA / EU (SCCs in place) |
| Shipping carriers (DHL, FedEx, etc.) | Order delivery | Global |
| Cloud hosting provider | Website & data hosting | Global (ISO 27001) |
| Email service | Transactional emails | USA / EU |
All processors are bound by data processing agreements and must maintain adequate security standards.
6. International Data Transfers
LIEN GROUP serves customers globally. When we transfer your personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs)
- Transfers only to countries with an adequacy decision where possible
7. Cookies & Tracking Technologies
What We Use
| Type | Name | Purpose | Duration |
|---|---|---|---|
| Essential | luxevault_cart | Shopping cart contents | localStorage (until cleared) |
| Essential | lg_session | Login session | localStorage (until logout) |
| Essential | lg_sid | Anonymous session ID for analytics | sessionStorage (tab close) |
| Preferences | lg_currency | Your selected currency | localStorage (until cleared) |
| Analytics | Internal page views | Anonymised traffic analytics | 30 days |
We use localStorage and sessionStorage rather than third-party tracking cookies. We do not use Google Analytics, Facebook Pixel, or other third-party advertising trackers.
You can clear stored data at any time via your browser settings (Settings → Privacy → Clear Site Data).
8. Data Retention
- Order records: 7 years (required for accounting/tax law in most jurisdictions)
- Account information: until account deletion or 2 years of inactivity
- Analytics data: 30 days, then anonymised
- Marketing consent records: until consent withdrawn + 1 year
9. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
| Right | Description | Applies To |
|---|---|---|
| Access | Request a copy of data we hold about you | GDPR, UK GDPR, CCPA |
| Rectification | Correct inaccurate personal data | GDPR, UK GDPR |
| Erasure | "Right to be forgotten" — delete your data | GDPR, UK GDPR, CCPA |
| Portability | Receive your data in a machine-readable format | GDPR, UK GDPR |
| Object | Object to processing based on legitimate interests | GDPR, UK GDPR |
| Restrict | Limit how we process your data | GDPR, UK GDPR |
| Opt-out of sale | We do not sell data — not applicable | CCPA |
| Withdraw consent | Opt out of marketing at any time | All |
To exercise any of these rights, email us at privacy@liengroup.com. We will respond within 30 days (GDPR deadline).
10. Security
We implement appropriate technical and organisational measures to protect your personal data:
- All data transmitted via HTTPS / TLS 1.3
- Payment processing via Stripe (PCI DSS Level 1 certified)
- Passwords stored as one-way hashes — never in plain text
- Access to customer data restricted to authorised personnel only
- Regular security reviews and updates
In the event of a data breach affecting your rights, we will notify you within 72 hours as required by GDPR.
11. Children's Privacy
Our website is not directed at children under 16 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.
12. Contact & Data Protection Officer
Get in Touch
📧 Privacy enquiries: privacy@liengroup.com
💬 WhatsApp: +86 16657122166
🕐 We aim to respond to all privacy requests within 5 business days and are legally required to respond within 30 days.
If you are an EU/UK resident and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority.