Privacy policy
PRIVACY STATEMENT
----
SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
When you place an order within our shop, we collect personal details you submit during checkout, including your full name, delivery address and email contact, as part of commercial transaction processing.
While browsing our storefront, our system automatically captures your device’s IP address. This data helps us identify browser type and operating‑system specifications for site‑optimization purposes.
Email marketing: Subject to your explicit approval, we may deliver newsletters covering store updates, new product launches and other relevant announcements.
SECTION 2 - CONSENT
How do you get my consent?
When you hand over personal data to finalize purchases, validate card details, submit orders, arrange shipment or process product returns, your action signals implicit consent for us to use that information strictly for the stated transaction purpose.
Should we intend to utilize your details for secondary purposes such as promotional outreach, we will seek your clear affirmative permission or provide you with an opt‑out option.
How do I withdraw my consent?
If you previously opted‑in and later change your preference, you are entitled to revoke consent for future outreach, ongoing data collection, usage or disclosure at any moment. Reach us via support@leouyu.com to submit such a request.
SECTION 3 - DISCLOSURE
We may release your personal data when compelled by legal requirements, or in scenarios where you violate our Terms of Service agreement.
SECTION 4 - SHOPIFY
Our online shop runs on Shopify Inc.’s e‑commerce infrastructure. This platform supplies all technical capabilities that enable us to sell goods and services toward customers.
Customer records are preserved within Shopify’s databases and application systems. All records reside on secure firewall‑protected cloud servers.
Payment:
When you complete checkout via native payment gateways, Shopify stores your credit‑card credentials. These sensitive details are encrypted following PCI‑DSS security specifications. Payment‑related records are retained only for the duration required to finish your transaction; records get erased once the transaction concludes.
Every direct payment gateway complies with PCI‑DSS standards maintained by the PCI Security Standards Council, a collaborative body founded by Visa, MasterCard, American Express and Discover.
PCI‑DSS protocols safeguard secure handling of credit‑card information for our store and associated service partners.
For supplementary reference you may review Shopify’s Terms of Service (https://www.shopify.com/legal/terms) and Privacy Statement (https://www.shopify.com/legal/privacy).
SECTION 5 - THIRD‑PARTY SERVICES
In most circumstances, our external service providers collect, utilize and reveal personal information only to the minimal extent necessary to deliver their contracted services.
Nevertheless, certain service partners such as payment processors maintain their own independent privacy policies governing data shared for order‑related operations.
We strongly advise reading third‑party privacy documentation to fully understand how your personal data will be managed by those providers.
Keep in mind some vendors operate under jurisdictions different from yours or ours. When you complete transactions handled by external providers, your personal information may become subject to that foreign region’s local statutes.
As an illustration: if you reside in Canada yet payment processing occurs through a United States‑based gateway, your transaction‑related personal data could be subject to disclosure requirements set under U.S. federal regulations including the Patriot Act.
Once you navigate away from our store or get redirected to external websites or applications, this Privacy Statement and our Terms of Service will no longer apply.
SECTION 6 - SECURITY
We adopt reasonable safeguards and follow established industry practices to prevent personal‑data loss, misuse, unauthorized access, exposure, alteration or destruction.
Credit‑card details transmitted to us are encrypted with SSL technology and stored using AES‑256 encryption. No internet transmission or electronic storage method can guarantee absolute security. Even so, we fully satisfy PCI‑DSS obligations and implement widely‑accepted extra security controls.
SECTION 7 - COOKIES
Below you can view the cookie types deployed on our platform, to help you make opt‑in or opt‑out decisions:
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 8 - AGE OF CONSENT
By accessing our website, you confirm you hold the legal age of majority within your state or province of residence. If minor household members utilize our site under your supervision, you confirm you possess proper authority to grant such access.
SECTION 9 - CHANGES TO THIS PRIVACY POLICY
We hold authority to revise this privacy statement at any time; periodic review is recommended. Revisions and clarifications take immediate effect upon website publication. Substantial policy adjustments will be explicitly announced on this page, so you stay informed about data collection practices, usage scenarios and disclosure conditions.
Should our business get acquired or merge with another entity, user records may transfer to new controlling parties to sustain product sales services.
SECTION 10: SMS Abandoned Cart Disclosure
leouyu.com leverages cookies to track shopping‑cart contents, including abandoned cart events. This dataset determines timing for SMS cart‑recovery reminder messages.
SECTION11: SMS Third‑Party Data Sharing
The above excludes text messaging originator opt‑in data and consent; this information will not be shared with any third parties
QUESTIONS AND CONTACT INFORMATION
If you wish to access, correct, adjust or erase personal records we hold for you, submit a formal complaint, or seek further clarification, please reach our Privacy Compliance Officer via support@leouyu.com.
Last Updated: August 2026