Privacy Policy

Last updated:

This Privacy Policy describes how Lovelyshine ("we", "us", or "our") collects, uses, stores, and protects your personal information when you visit lovelyshine.world (the "Website"). We are committed to protecting your privacy and complying with the Privacy Act 2020 (New Zealand) and its Information Privacy Principles (IPPs). Where applicable, we also respect the rights of individuals under overseas privacy laws, including the General Data Protection Regulation (GDPR) for visitors in the European Economic Area.

Agency and Contact Details

We are the agency responsible for the personal information we collect through the Website. You can contact us about privacy matters at:

Lovelyshine
179 Main Highway, Ōtaki 5512, New Zealand
Email: assist@lovelyshine.world
Phone: +64 6 364 8969

Collection Notice

When we collect personal information, we tell you what we collect, why we collect it, and what will happen if you do not provide it. The information below applies to personal information collected through the Website.

Personal Information We Collect

We may collect the following categories of personal information:

  • Contact information: name and email address provided through our contact form
  • Communication data: the content of messages you send us
  • Technical data: IP address, browser type, device information, and pages visited
  • Cookie and preference data: choices stored through our cookie consent mechanism (see our Cookie Policy)

Providing contact information through the contact form is voluntary. If you choose not to provide it, we may be unable to respond to your enquiry.

How We Collect Information

We collect personal information directly from you when you submit the contact form or contact us by email or phone. We also collect limited technical information automatically when you browse the Website, including through cookies and similar technologies where permitted.

Purposes of Collection and Use

We collect and use personal information only for purposes that are connected to our functions and activities, including to:

  • Respond to your enquiries and communicate with you
  • Operate, maintain, and improve the Website
  • Analyse Website usage when you have consented to analytics cookies
  • Comply with legal obligations under New Zealand law
  • Protect the security and integrity of the Website

We do not use your personal information for a purpose other than the purpose for which it was collected, unless an exception under the Privacy Act 2020 applies (for example, with your authorisation or where the new use is directly related to the original purpose).

Legal Basis for Processing

Under the Privacy Act 2020, we collect personal information only where it is necessary for our lawful purposes. We rely on:

  • Your consent: when you submit the contact form and agree to data processing, and when you accept non-essential cookies
  • Our legitimate business needs: to operate a secure, functional website and respond to enquiries
  • Legal obligation: when required to comply with applicable New Zealand laws

For visitors in the European Economic Area, we also rely on the legal bases set out in the GDPR where applicable.

Disclosure of Personal Information

We do not sell your personal information. We may disclose personal information to trusted service providers who assist in operating the Website, such as hosting providers, email services, and analytics providers, only to the extent necessary for them to perform those services. We require these providers to handle personal information in accordance with applicable privacy laws.

We may also disclose personal information where required or authorised by New Zealand law.

Overseas Disclosure

Some of our service providers may store or process personal information outside New Zealand (for example, hosting or content delivery networks). Before disclosing personal information overseas, we take reasonable steps to ensure that the recipient is subject to privacy safeguards that provide comparable protections to those under the Privacy Act 2020, or we rely on an authorised exception under Information Privacy Principle 12.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law:

  • Contact form submissions: up to 24 months from the date of your last communication
  • Technical and analytics data: up to 26 months, subject to your cookie preferences
  • Cookie consent records: up to 12 months

After the retention period expires, information is securely deleted or anonymised where practicable.

Security

We implement reasonable security safeguards to protect personal information from loss, unauthorised access, use, or disclosure. These measures include HTTPS encryption, access controls, and secure hosting environments. No method of transmission over the Internet is entirely secure, and we cannot guarantee absolute security.

Access and Correction

Under the Privacy Act 2020, you have the right to request access to personal information we hold about you and to request correction of any information that you believe is inaccurate, out of date, incomplete, irrelevant, or misleading.

To make an access or correction request, contact us at assist@lovelyshine.world. We will respond within a reasonable timeframe and, in any event, within 20 working days unless an extension applies under the Privacy Act 2020. We may need to verify your identity before processing your request.

Your Other Rights

Depending on your location, you may also have rights to:

  • Withdraw consent to processing based on consent (without affecting prior lawful processing)
  • Object to certain processing activities
  • Request deletion of personal information where applicable
  • Request restriction of processing or data portability (for EEA visitors under the GDPR)

Notifiable Privacy Breaches

If a privacy breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required under the Privacy Act 2020.

Direct Marketing

We do not send unsolicited commercial electronic messages. If we contact you in response to an enquiry, that communication relates to your request. Any future marketing communications, if introduced, would comply with the Unsolicited Electronic Messages Act 2007 and would include a clear means to opt out.

Children's Privacy

The Website is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can take appropriate steps.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. We encourage you to review this policy periodically.

Complaints

If you have concerns about how we have handled your personal information, please contact us first so we can try to resolve the matter. If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu):