Delivering to the UK, EU, Switzerland, Norway, the US and Canada · 30-day returns

EN·USD
Lum
Bag
Legal

Privacy policy

Last updated 28 September 2026

1. Who is responsible for your data

The controller of your personal data is VASS TEXTILES LIMITED, Textile House, 11b Clarke Road, Bletchley, Milton Keynes, MK1 1LG, United Kingdom, company number 04011112 (“we”, “us”), operating the LUMISELLE shop at lumiselle.shop. For any privacy question or request, email support@lumiselle.shop or write to the address above.

We process personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018 and, where it applies to you, the EU General Data Protection Regulation (GDPR).

2. What data we collect

  • Order data: name, billing and delivery address, email address, phone number, items ordered, prices, currency and order history.
  • Payment data: payment method, payment status and transaction references. Full card details are entered directly with our payment provider and are never stored by us.
  • Account data: if you create an account, your login details and saved addresses.
  • Messages: what you send us by email, phone, the contact form or the withdrawal form.
  • Technical data: IP address, browser type, pages requested and time of access, recorded in server logs for security and to keep the website running.
  • Cookies: only those needed to run the shop — see our cookie policy.

3. Why we use it and our legal bases

PurposeLegal basis
Processing and delivering your order, handling returns, withdrawals and refundsPerformance of a contract (Art. 6(1)(b) GDPR)
Answering your questions and complaintsContract or steps before a contract (Art. 6(1)(b)); our legitimate interest in helping customers (Art. 6(1)(f))
Keeping accounting and tax recordsLegal obligation (Art. 6(1)(c))
Preventing fraud and securing the website and paymentsLegitimate interests (Art. 6(1)(f))
Managing your customer accountContract (Art. 6(1)(b))

We do not send marketing emails, we do not sell your data and we do not use advertising or analytics trackers.

4. Who we share it with

  • Payment providers — Stripe (card and wallet payments) and PayPal, when you choose these methods at checkout. They process payment data as independent controllers or processors and carry out fraud checks.
  • Delivery companies — name, address, and email or phone for delivery notifications.
  • Hosting and IT — our web hosting provider (Hostinger) and email service providers, who act on our instructions.
  • Professional advisers and authorities — accountants, legal advisers, or public authorities where we are legally required.

5. International transfers

We are based in the United Kingdom. Data transfers between the UK and the European Economic Area are covered by adequacy decisions. Some providers, such as payment processors, may process data in the United States or other countries; in these cases we rely on adequacy regulations or decisions (including the EU–US Data Privacy Framework and its UK extension where the recipient is certified) or on standard contractual clauses approved by the UK and EU authorities.

6. How long we keep it

  • Order, payment and withdrawal records: 6 years after the end of the financial year of the order, to meet UK tax and accounting rules.
  • Customer accounts: until you ask us to delete your account, or after 3 years without activity.
  • Messages and contact-form enquiries: up to 2 years after the matter is closed.
  • Server logs: up to 30 days, unless needed to investigate a security incident.

7. Your rights

You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where processing is based on consent, you can withdraw consent at any time. To exercise a right, email support@lumiselle.shop; we reply within one month.

You also have the right to complain to a data protection authority: in the UK the Information Commissioner’s Office (ico.org.uk), or the authority in the EU country where you live or work — for example Datatilsynet in Denmark, the data protection authority of your federal state in Germany, or the CNIL in France.

8. Automated decisions

We do not make decisions about you based solely on automated processing. Our payment providers may use automated fraud screening when you pay; if a payment is declined you can contact us or the provider.

9. Security

The whole website is served over an encrypted connection (TLS). Access to customer data is limited to people who need it to process orders. Payment details are handled by PCI DSS–certified providers.

10. Children

Our shop is intended for adults. We do not knowingly collect data from children under 16.

11. Changes

We may update this policy when our processing changes. The current version is always available on this page, with the date of the last update.