Legal
Privacy Policy
Last updated: May 2026
1. Information we collect
When you place an order, we collect:
- Name, mobile number, and (optionally) email address
- Delivery address
- Order details (items, quantities, amounts)
- Payment method (COD or card — we do not store card details)
Card payments are processed by PayHere. We never receive or store your card number, CVV, or expiry date.
2. How we use your information
- Process and fulfil your orders
- Contact you about your delivery (via call or WhatsApp)
- Send order confirmation and status update emails (if you provided an email address)
- Resolve disputes or handle returns
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Data storage
Your order data is stored securely on servers hosted in the European Union (Neon PostgreSQL, GDPR-compliant). We retain order records for 3 years for accounting and dispute resolution purposes.
4. Cookies
We use a single browser localStorage entry (labastore_cart) to remember your shopping cart between visits. We do not use tracking cookies or third-party analytics cookies.
5. Third-party services
- PayHere — payment processing (PCI-DSS compliant)
- Resend — transactional email delivery
- Neon — database hosting
- Cloudinary — product image hosting
Each provider has its own privacy policy and data handling practices.
6. Your rights
You may request to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
To exercise these rights, contact us on WhatsApp or at hello@labastore.lk.
7. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes.
8. Contact
For privacy-related questions, contact us at hello@labastore.lk or via WhatsApp at +94 70 221 5003.