The short version.
We collect the minimum needed to ship your order and stay in touch about it: name, address, email, phone (optional). Card details are processed by Stripe and never stored on our servers. We don't sell or rent your data, period. We send you transactional emails only — receipts, shipping updates, subscription reminders — never marketing unless you've explicitly opted in.
You can request deletion at any time
Email privacy@lovesave.com and we'll wipe your account and order history within 30 days, no questions asked.
What we collect.
You give us
- Order details: shipping address, billing address, email, phone (optional)
- Account credentials: email and a hashed password if you create an account
- Communication: any messages you send to support
We collect automatically
- Device info: browser type, screen size, operating system (for layout debugging)
- IP address: kept for 30 days for fraud detection, then discarded
- Page views: aggregated counts only, never associated with you personally
We never collect
- Health conditions, medications, or anything related to the reason you're buying
- Card numbers or CVV (Stripe handles all of that on its own servers)
- Location precise to within a city block
How we use it.
Only for the obvious things:
- Ship your order, send the receipt, and update you about tracking
- Send subscription reminders 7 days before each shipment
- Reply when you contact support
- Detect fraudulent orders (matching IP, address, and card patterns)
- Aggregate, anonymized analytics on what pages people read most
Cookies & tracking.
We use a small number of cookies:
- Session cookie — keeps you logged in
- Cart cookie — remembers what's in your bag if you close the tab
- Analytics cookie — anonymous page-view count, no personal data
We don't use third-party tracking pixels, Facebook Pixel, Google Analytics with PII, or any retargeting cookies.
Your rights.
Regardless of where you live, you can ask us at any time to:
- See what data we have about you
- Correct anything that's wrong
- Delete your account and all associated data
- Export a copy of your data in a portable format
If you're in California, the EU, or another jurisdiction with specific privacy laws (CCPA, GDPR, etc.), these rights are guaranteed under that law. Either way, we respond to requests within 30 days.
How long we keep it.
- Active accounts: as long as you keep the account open
- Inactive accounts (no orders, no logins for 3 years): auto-deleted after a final warning email
- Order history: 7 years (IRS / tax law requirement)
- Support messages: 2 years
- IP logs: 30 days, then discarded
Security.
Passwords are hashed with bcrypt. All connections are encrypted with TLS 1.3. We've never had a data breach, and we'll notify affected users within 72 hours if one ever happens.
Contact us.
For privacy questions, account deletion, or data export requests, email privacy@lovesave.com. We respond within 2 business days.