Privacy Policy

Last Updated: 2026 - 02 - 25

Introduction

This Privacy Policy explains how Velvet & Enamel (“Company”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects your personal data when you visit or make a purchase from velvet&enamel.com (the “Website”) or otherwise interact with us.

We are committed to protecting your privacy and processing your personal data in accordance with applicable laws of Sri Lanka, including the Personal Data Protection Act, No. 9 of 2022.

By accessing or using our Website and services, you agree to the terms of this Privacy Policy.


Data Controller

For the purposes of applicable data protection laws, Velvet & Enamel acts as the Data Controller of your personal data.

If you have any questions, you may contact us at:
📧 Email: contact@velvetandenamel.com


Personal Data We Collect

We collect personal data necessary to operate our WooCommerce store and provide our products and services.

Information You Provide Directly

When you use our Website, we may collect:

  • Full name

  • Billing address

  • Shipping address

  • Email address

  • Phone number

  • Order details

  • Account login details (username, password)

  • Customer support communications

  • Product reviews or user-generated content

Payment Information

Payments are processed securely via third-party payment gateways. We do not store full credit card details. Payment providers may collect:

  • Card number

  • Expiry date

  • CVV

  • Billing information

These providers process data in accordance with their own privacy policies.


Automatically Collected Data (Cookies & Analytics)

We may automatically collect:

  • IP address

  • Browser type

  • Device information

  • Pages visited

  • Date and time of access

  • Referring website

This is collected through:

  • Cookies

  • WooCommerce session cookies

  • Analytics tools

  • Tracking pixels

You may disable cookies via your browser settings, though this may affect website functionality.


Legal Basis for Processing (Sri Lanka Compliance)

We process personal data based on:

  • Your consent

  • Performance of a contract (e.g., fulfilling orders)

  • Compliance with legal obligations

  • Our legitimate business interests (e.g., fraud prevention, analytics, service improvement)

Where consent is required, you may withdraw it at any time.


How We Use Your Personal Data

We use your personal data to:

  • Process and fulfill orders

  • Manage your account

  • Provide customer support

  • Arrange shipping and returns

  • Send order confirmations and updates

  • Detect fraud or security risks

  • Improve website functionality

  • Send marketing communications (only where consent is given)


Marketing Communications

If you opt in, we may send:

  • Promotional emails

  • Special offers

  • Product announcements

You may unsubscribe at any time using the link in our emails.

We do not sell your personal data to third parties.


Disclosure of Personal Data

We may share your personal data with:

  • Payment processors

  • Shipping and logistics providers

  • IT and hosting providers

  • Analytics services

  • Legal authorities (if required by law)

All third parties are required to handle your data securely and in accordance with applicable law.


International Data Transfers

Your personal data may be transferred outside Sri Lanka (e.g., to hosting providers or payment processors).

Where such transfers occur, we ensure appropriate safeguards are in place to protect your data in accordance with Sri Lankan data protection requirements.


Data Retention

We retain personal data only as long as necessary to:

  • Fulfill contractual obligations

  • Comply with legal requirements

  • Resolve disputes

  • Enforce agreements

After this period, your data will be securely deleted or anonymized.


Your Rights Under Sri Lankan Law

Subject to applicable law, you may have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request deletion of data

  • Withdraw consent

  • Object to processing

  • Request restriction of processing

  • Request a copy of your personal data

To exercise your rights, contact:
📧 Email: contact@velvetandenamel.com

We may request identity verification before responding.


Data Security

We implement appropriate technical and organizational security measures, including:

  • SSL encryption

  • Secure hosting

  • Access controls

  • Limited data access

However, no system is completely secure, and we cannot guarantee absolute security.


Children’s Privacy

Our Website is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.

If you believe a child has provided personal data, please contact us immediately.


Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies separately.

Changes to This Policy

We may update this Privacy Policy periodically. The updated version will be posted on this page with a revised “Last Updated” date.

Continued use of the Website after changes indicates acceptance of the revised policy.


Contact Information

If you have any questions regarding this Privacy Policy or your personal data, please contact:

Velvet & Enamel

📧 Email: contact@velvetandenamel.com