Skip to content

Cart

Your cart is empty

Privacy Policy

This Privacy Policy describes how we collect, use, disclose and protect personal information when you use https://malvori.com/ (the “Site”) and when you purchase our products or interact with our services (the “Services”).

1. Information We Collect
When you make a purchase, we collect the personal details you provide as part of the ordering process, including your name, billing and delivery address, email address and phone number. When you browse the Site, your device’s IP address and basic technical information (such as browser and operating system) are automatically collected. With your permission, we may also collect your email address for updates about our store, new products and other communications.

2. Consent
By giving personal information to complete a transaction (such as verifying your payment method, placing an order, arranging a delivery or processing a return), you consent to our collecting and using that information for that specific purpose. If we request personal information for an additional purpose (such as marketing), we will either ask directly for your express consent or provide a clear option to decline.

Withdrawing consent: If you change your mind after opting in, you may withdraw your consent for us to collect, use or disclose your information at any time by contacting us using the details provided in the “Contact Us” section.

3. Disclosure
We may disclose your personal information if required by law or if you violate our Terms of Service.

4. Platform Hosting (Shopify)
Our store is hosted on Shopify, which provides the e-commerce platform used to sell our products and services. Your data may be stored through Shopify’s data storage, databases and the general Shopify application on secure servers protected by a firewall.

Payments: If you choose a direct payment gateway, your payment card information may be stored by Shopify in accordance with PCI-DSS requirements. Transaction data is kept only as long as needed to complete your purchase and is deleted once completed.

For more details, please refer to the official Shopify policies:

Shopify Privacy Policy
Shopify Terms of Service

5. Third-Party Service Providers
We may share information with third-party service providers (such as payment gateways, fraud prevention tools or delivery partners). These providers will collect, use and disclose information only as necessary to perform their services for us. Each provider has its own privacy policy governing the information we must provide to complete purchase-related transactions, and we recommend reviewing their policies to understand how your data is managed by them.

Certain providers may be located in, or operate from, a different country than you or us. If you proceed with a transaction involving such a provider, your information may become subject to the laws of the jurisdiction(s) in which that provider operates.

When you leave our Site or are redirected to a third-party site or application, this Privacy Policy no longer applies. We encourage you to read the privacy policies of other websites you visit.

6. Analytics and Cookies
We use cookies and similar technologies to operate and improve the Site, remember preferences and run analytics (such as understanding page views and traffic). Some cookies may be placed by third parties to tailor products, services or advertising on this and other websites.

Managing cookies: Most browsers accept cookies automatically. You may configure your browser to remove or block cookies; however, this may affect how the Site functions. You may also adjust cookie preferences through our cookie banner when first visiting the Site.

For more information on Shopify’s cookie practices, please refer to the Shopify Cookie Policy.

7. Security
We apply reasonable safeguards and follow industry-standard practices to protect personal information against loss, misuse, unauthorized access, disclosure, alteration or destruction. When payment card information is submitted, it is encrypted during transmission (such as SSL/TLS). While no system can guarantee 100% security, we comply with PCI-DSS and other recognized standards.

8. Lawful Bases (UK GDPR)
We process personal data under one or more lawful bases, including: (a) performing a contract (e.g., fulfilling an order); (b) legitimate interests (e.g., improving the Site, preventing fraud); (c) consent (e.g., marketing communications); and/or (d) legal compliance.

9. Your Rights (UK)
Subject to applicable law, you may have rights to: access, correct, delete, restrict, transfer or object to certain uses of your personal data. Where processing is based on consent, you may withdraw consent at any time. To exercise your rights, please contact us using the details below. You also have the right to file a complaint with the UK Information Commissioner’s Office (ICO).

10. Data Retention
We retain personal information only as long as necessary to provide the Services, comply with legal and accounting requirements, resolve disputes and enforce our agreements. Retention periods may differ depending on the type of data and its purpose.

11. International Transfers
Where personal data is transferred outside the UK (such as to service providers), we ensure that appropriate safeguards (including standard contractual clauses or equivalent measures) are in place to protect your data in line with UK GDPR.

12. Children’s Data
Our Services are not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe that a child has provided us with personal information, please contact us so we can take appropriate action.

13. Changes to This Policy
We may update this Privacy Policy occasionally. Changes take effect once posted on the Site. If significant updates are made, we will highlight them on this page to keep you informed about what information we collect, how we use it and when we disclose it.