Privacy Policy
Effective Date: September 03, 2025
1. Introduction
At LumbarPillow (“we,” “us,” “our”), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website (lumbarpillow.co) or purchase our products.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password
- Order Information: Billing address, shipping address, phone number
- Payment Information: Credit card details (processed securely by payment processors)
- Communications: Messages, reviews, feedback, survey responses
- Preferences: Product preferences, communication preferences
2.2 Information Automatically Collected
- Device Information: IP address, browser type, operating system
- Usage Data: Pages visited, time spent, click patterns
- Cookies: Session cookies, preference cookies, analytics cookies
- Location Data: General geographic location based on IP address
2.3 Information from Third Parties
- Social media platforms (if you connect accounts)
- Payment processors (transaction confirmations)
- Shipping carriers (delivery confirmations)
- Marketing partners (with your consent)
3. How We Use Your Information
3.1 Order Processing
- Process and fulfill orders
- Send order confirmations and updates
- Process payments and refunds
- Communicate about your orders
3.2 Customer Service
- Respond to inquiries and support requests
- Handle returns and warranty claims
- Provide product information
- Resolve disputes
3.3 Marketing and Communications
- Send promotional emails (with consent)
- Personalize shopping experience
- Notify about new products or features
- Send abandoned cart reminders
3.4 Improvement and Analytics
- Analyze website usage patterns
- Improve products and services
- Conduct market research
- Test new features
3.5 Legal and Security
- Comply with legal obligations
- Prevent fraud and abuse
- Protect rights and property
- Enforce terms of service
4. How We Share Your Information
4.1 Service Providers
We share information with trusted third parties who help us operate our business:
- Payment processors (Stripe, PayPal)
- Shipping carriers (USPS, FedEx, UPS)
- Email service providers
- Customer support tools
- Analytics providers
4.2 Legal Requirements
We may disclose information when required by:
- Court orders or subpoenas
- Government requests
- Law enforcement investigations
- Legal proceedings
4.3 Business Transfers
In case of merger, acquisition, or sale of assets, your information may be transferred to the successor entity.
4.4 With Your Consent
We may share information for other purposes with your explicit consent.
5. Cookies and Tracking Technologies
5.1 Types of Cookies We Use
- Essential Cookies: Required for website functionality
- Analytics Cookies: Help us understand website usage
- Marketing Cookies: Enable personalized advertising
- Preference Cookies: Remember your settings
5.2 Managing Cookies
- Browser settings to block or delete cookies
- Opt-out links in cookie banner
- Google Analytics opt-out browser extension
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- SSL/TLS encryption for data transmission
- Secure payment processing (PCI-DSS compliant)
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
7. Data Retention
We retain your information for as long as necessary to:
- Fulfill orders and provide services
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
Typical retention periods:
- Order information: 7 years for tax purposes
- Account information: Until account deletion
- Marketing data: Until opt-out or 3 years of inactivity
8. Your Rights and Choices
8.1 Access and Portability
You can request a copy of your personal information in a structured, machine-readable format.
8.2 Correction
You can update or correct your information through your account or by contacting us.
8.3 Deletion
You can request deletion of your personal information, subject to legal requirements.
8.4 Opt-Out
- Marketing emails: Unsubscribe link in emails
- SMS: Text STOP to opt-out
- Cookies: Browser settings or cookie banner
8.5 Do Not Sell
We do not sell personal information. You can opt-out of certain sharing for advertising purposes.
9. Children’s Privacy
Our website is not intended for children under 18. We do not knowingly collect information from children. If we become aware of collected information from a child, we will delete it immediately.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
11. California Privacy Rights (CCPA)
California residents have additional rights:
- Right to know categories and specific pieces of personal information
- Right to delete personal information
- Right to opt-out of sale (we don’t sell data)
- Right to non-discrimination
- Right to correct inaccurate information
12. European Privacy Rights (GDPR)
EU residents have rights including:
- Right to access
- Right to rectification
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
13. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies.
14. Updates to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated effective date. Material changes will be notified via email or website notice.
15. Contact Us
For privacy-related questions or to exercise your rights:
Data Protection Officer
- Email: info@lumbarpillow.co
Response Time
We will respond to your requests within 30 days, or as required by applicable law.
16. Supervisory Authority
If you’re unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
17. Marketing Communications
17.1 Email Marketing
- Only with explicit consent or existing customer relationship
- Easy unsubscribe in every email
- Preferences manageable in account settings
17.2 SMS Marketing
- Only with explicit opt-in
- Standard message and data rates apply
- Text STOP to unsubscribe
18. Analytics and Advertising
We use:
- Google Analytics for website analytics
- Facebook Pixel for advertising
- Google Ads for remarketing
You can opt-out through:
- Google Ad Settings
- Facebook Ad Preferences
- Digital Advertising Alliance opt-out
Your privacy matters to us. If you have any questions or concerns about this Privacy Policy or our practices, please contact us.
Last Updated: September 03, 2025