0
Home Shop Hotel & Banquet Chandeliers Pendants & Ceiling Lights Wall Sconces & Picture Lights Crystal Chandeliers Contact Blog Buying Guide Cart (0)
Legal

Privacy Policy

How we collect, use, and protect your personal and business information when you use staylighting.com, place an order, or send an enquiry.

Last updated · 20 August 2026

1. Who We Are

Staylighting is a B2B lighting manufacturer and exporter based in Zhongshan, Guangdong, China (the "data controller" under GDPR). For any privacy question, contact our Data Protection Officer at [email protected] or [email protected], or phone +86 159 2039 0000.

2. Information We Collect

2.1 Information you give us directly

  • Enquiry / contact forms: Name, email, company, country, approximate quantity, message.
  • RFQ / quote requests: Project type, room count, target budget, timeline, finish preferences.
  • Orders: Shipping address, billing address, payment confirmation.
  • Account login: Email + password (hashed). We never store payment card numbers — payments are processed by Stripe / T/T bank transfer.

2.2 Information collected automatically

  • Device & browser: IP address, browser type, screen size, operating system.
  • Usage: Pages viewed, time on site, referring URL (via Google Analytics 4 — you can opt out via the cookie banner).
  • Cookies: See section 4.

3. How We Use Your Information

We use the data we collect to:

  • Process and ship your orders, including customs documentation.
  • Respond to your RFQ / quote / contact requests within 1 working day.
  • Send you order status updates, tracking, and follow-up satisfaction surveys.
  • Improve our website, catalogue, and product information based on usage patterns.
  • Comply with legal obligations (export controls, customs records, tax records).

We do not sell your personal data. We do not share it with advertising networks or data brokers.

4. Cookies

We use a minimal cookie set:

  • Essential cookies: Session, cart, login state. Cannot be disabled.
  • Analytics: Google Analytics 4 (anonymised IP). Optional — opt out via the cookie banner.
  • Marketing: We do not use marketing cookies or third-party ad trackers.

You can clear cookies in your browser at any time; this will log you out of your account.

5. Sharing with Third Parties

We share data only with the operational vendors needed to serve you:

  • Brevo — transactional email (order confirmations, shipping updates).
  • Stripe & PayPal — payment processing (card data never touches our servers).
  • DHL / FedEx / UPS — shipping labels and tracking.
  • Customs brokers / freight forwarders — when you choose our freight assistance, we share shipping details needed for export/import clearance.
  • Cloudflare — DNS, CDN, DDoS protection (your IP may pass through their network).

Each vendor is bound by their own privacy policy and GDPR-compliant data processing agreements with us.

6. International Data Transfers

Your data is stored on servers in Frankfurt, Germany (via Cloudflare Workers + Hetzner) and Hong Kong (production backups). For EU/UK customers, data transfers to Hong Kong are governed by Standard Contractual Clauses (2021/914). For US customers, transfers are governed by the EU-US Data Privacy Framework where applicable.

7. Your Rights (GDPR / CCPA / UK-GDPR)

  • Access — request a copy of the personal data we hold on you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (subject to legal record-keeping obligations).
  • Restriction — limit how we process your data.
  • Portability — receive your data in a machine-readable format.
  • Object — to processing based on legitimate interest.
  • Withdraw consent — at any time, where processing is consent-based.

Email [email protected] to exercise any right. We respond within 30 days.

8. Data Retention

  • Account records: Retained for 7 years after last activity, then deleted.
  • Order records: Retained for 10 years (customs, tax, warranty obligations).
  • RFQ / quote records: Retained for 3 years.
  • Marketing email unsubscribe: Retained permanently to honour opt-out.
  • Analytics: 14 months (Google Analytics default).

9. Security

We protect your data with:

  • TLS 1.3 encryption in transit.
  • AES-256 encryption at rest in primary databases.
  • Two-factor authentication on all internal admin access.
  • Annual third-party security audit (last completed June 2026).
  • Incident response plan with 72-hour breach notification.

No system is perfectly secure. If you discover a vulnerability, please report it to [email protected] — we acknowledge within 24 hours.

10. Children's Privacy

Our site and services are B2B only. We do not knowingly collect data from anyone under 18. If you believe a minor has submitted data, contact [email protected] for immediate deletion.

11. Changes to This Policy

We update this policy when our practices change or when law requires it. Material changes are notified by email to trade-account holders at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the current version.

Privacy Questions?

Email our Data Protection Officer

For data access requests, corrections, deletions, or any privacy concern, we reply within 30 days.

[email protected]