1. Introduction
Luvizon ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our video gift creation service.
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using Luvizon, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Personal Information
When you create an account or use our Service, we collect:
- Account Information: Full name, email address, and password
- Payment Information: Processed securely through Stripe (we do not store credit card details)
- Recipient Information: Names of gift recipients you specify
2.2 Content You Upload
- Photos: Images you upload for video compilation
- Videos: Personal video messages you record or upload
- Audio: Custom music files (if uploaded)
- Text: Custom messages and occasion details
2.3 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent on the Service
- Device Information: Browser type, operating system, IP address
- Cookies: See our Cookie Policy for details
3. How We Use Your Information
We use your information to:
- Provide the Service: Process and compile your video gifts
- Account Management: Create and maintain your account
- Payment Processing: Complete transactions through Stripe
- Communication: Send order confirmations, processing updates, and customer support
- Delivery: Share compiled videos with designated recipients via unique links
- Improvement: Analyze usage to enhance our Service
- Legal Compliance: Comply with applicable laws and regulations
4. Legal Basis for Processing (UK GDPR)
We process your personal data under the following legal bases:
- Contract Performance: To provide the video gift service you've paid for
- Consent: You've given explicit consent to process your uploaded content
- Legitimate Interests: To improve our Service and prevent fraud
- Legal Obligation: To comply with tax and financial regulations
5. How We Share Your Information
We do not sell your personal information. We share information only in these circumstances:
5.1 Service Providers
- Supabase: Database and file storage (data stored in secure cloud infrastructure)
- Stripe: Payment processing
- Resend: Email delivery service
- Hosting Providers: Vercel (frontend) and Railway (backend)
5.2 Gift Recipients
Your compiled video is shared with recipients via a unique, shareable link. Recipients can view and download the video but cannot access your account or other personal information.
5.3 Legal Requirements
We may disclose information if required by law or in response to valid legal requests.
6. Data Storage and Security
6.1 Where We Store Your Data
Your data is stored on secure cloud servers. Some of our service providers may store data outside the UK/EEA, but we ensure appropriate safeguards are in place through:
- Standard Contractual Clauses approved by the UK ICO
- Adequacy decisions where applicable
- Data processing agreements with all providers
6.2 Security Measures
We implement industry-standard security measures including:
- Encryption of data in transit (SSL/TLS)
- Secure authentication systems
- Regular security audits
- Access controls and monitoring
- Private storage buckets for sensitive content
6.3 Data Retention
We retain your data as follows:
- Account Data: Until you request deletion or 12 months of inactivity
- Uploaded Content: Until you delete it or your account is terminated
- Compiled Videos: Indefinitely unless you request deletion
- Payment Records: 7 years for tax compliance
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise any of these rights, contact us at support@luvizon.com. We will respond within 30 days.
8. Cookies and Tracking
We use essential cookies to provide the Service and analytics cookies to improve user experience. See our Cookie Policy for full details.
9. Children's Privacy
Luvizon is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
If your video gift includes images of children, you represent that you have obtained appropriate parental consent.
10. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service. The "Last updated" date at the top indicates when changes were made.
12. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact:
Data Protection Officer
Email: support@luvizon.com
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ICO Website: ico.org.uk
Helpline: 0303 123 1113
By using Luvizon, you acknowledge that you have read and understood this Privacy Policy.