Last updated: 31 May 2026.
Who we are
Lustra (“we”, “us”) operates the online store at getlustra.store, hosted on the Shopify platform. We are based in Italy and ship worldwide. The data controller is [legal name], [business address, Italy]. For any privacy question, email support@getlustra.store.
This policy explains how we process personal data in line with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
Data we collect
- Order and contact data: name, email, shipping and billing address, and phone number when provided.
- Payment data: payments are processed by Shopify Payments and the relevant card networks. We do not see or store full card numbers.
- Usage data: device, browser, pages viewed and similar information collected through cookies and analytics.
- Communications: messages you send us by email or through forms.
How we use your data
- To process, fulfil and deliver your orders.
- To provide customer support and handle returns or claims.
- To prevent fraud and keep the store secure.
- To meet legal and tax obligations.
- With your consent, to send occasional marketing emails (you can opt out at any time).
Legal bases (GDPR)
We rely on performance of a contract (to fulfil your order), legitimate interests (to run and improve the store securely), consent (for marketing and non-essential cookies) and legal obligation (for accounting and tax).
Sharing your data
We share data only as needed to run the store: with Shopify (our platform and payments provider), payment processors, and the shipping carriers and fulfilment suppliers who pack and deliver your order. Because some products ship from partners outside the EU, your delivery details may be shared with suppliers abroad. We may also disclose data where required by law. We do not sell your personal data.
International transfers
As we ship worldwide and work with international suppliers, your data may be transferred outside the European Economic Area. Where it is, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Retention
We keep order data for as long as needed to provide the service and to satisfy legal, accounting and tax requirements, then delete or anonymise it.
Your rights
Under the GDPR you can request access to, correction or deletion of your data, restrict or object to processing, ask for portability, and withdraw consent at any time. You can also complain to your local data protection authority. Under the CCPA, California residents can request to know or delete their data and opt out of any sale of personal information (we do not sell it), without being discriminated against. To exercise any right, email support@getlustra.store.
Cookies
We use essential cookies to run the store and analytics cookies to understand usage. You can manage cookies through your browser settings.
Security and children
We use reasonable technical and organisational measures to protect your data. Our store is not directed at children under 16, and we do not knowingly collect their data.
Changes
We may update this policy from time to time. The latest version will always be posted on this page.