Elora Circle - Privacy Policy
This privacy policy sets out how LLA Advisor Limited (trading as Elora Circle) collects and uses your personal data through your use of this website.
Contents
• 1. Important information and who we are
• 2. The types of personal data we collect about you
• 3. How is your personal data collected?
• 4. How we use your personal data
• 5. Disclosures of your personal data
• 6. International transfers
• 7. Data security
• 8. Data retention
• 9. Your legal rights
• 10. Contact details
• 11. Complaints
• 12. Changes to the privacy policy
1. Important information and who we are
Privacy policy
This privacy policy gives you information about how Elora Circle collects and uses your personal data through your use of this website, including any data you may provide when you purchase a product, sign up to our newsletter, or contact us.
This website is not intended for children and we do not knowingly collect data relating to children.
Controller
LLA Advisor Limited is the controller and is responsible for your personal data (referred to as “Elora Circle”, “we”, “us” or “our” in this privacy policy).
If you have any questions about this privacy policy or wish to exercise your rights, please contact us using the details at section 10 below.
2. The types of personal data we collect about you
Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
● Identity Data includes first name and last name.
● Contact Data includes billing address, delivery address, email address and telephone number.
● Financial Data includes payment card details and payment method information. Payment card data is processed directly by our third-party payment providers (Shopify Payments and PayPal) and does not pass through our own systems.
● Payment: If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. For more information, please review Shopify’s Terms of Service here or Privacy Policy https://www.shopify.com/legal/terms.
● Transaction Data includes details about payments to and from you and other details of products you have purchased from us, including order history.
● Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
● Usage Data includes information about how you interact with and use our website, products and services.
● Marketing and Communications Data includes your preferences in receiving marketing from us and your communication preferences.
We also collect, use and share aggregated data such as statistical or demographic data which is not personal data as it does not directly or indirectly reveal your identity.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
● Your interactions with us. You may give us your personal data by filling in online forms or by corresponding with us by email or otherwise. This includes personal data you provide when you purchase products from us, subscribe to our newsletter, request marketing communications, or contact us. When you make a purchase from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address, and email address. When you browse our store, we also automatically receive your computer’s Internet Protocol (IP) address, which helps us learn more about the browser and operating system you are using.
● Automated technologies or interactions. As you interact with our website, we automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. Please see our Cookie Policy at https://eloracircle.com/pages/elora-circle-cookie-policy for further details.
● Third parties or publicly available sources. We receive Technical Data from analytics providers such as Google (based outside the UK). We receive Technical and Transaction Data from our payment and delivery service providers. We receive advertising and engagement data from Meta and Google advertising platforms.
4. How we use your personal data
Legal basis
The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:
● Performance of a contract with you: where we need to perform the contract we are about to enter into or have entered into with you (i.e. to process and fulfil your order).
● Legitimate interests: we may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you before we process your personal data for our legitimate interests.
● Legal obligation: we may use your personal data where it is necessary for compliance with a legal obligation that we are subject to, for example accounting and tax requirements.
● Consent: we rely on consent where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to our email or SMS newsletter.
Purposes for which we will use your personal data
We have set out below a description of all the ways we plan to use your personal data, the types of data involved, and the legal basis we rely on:
|
Purpose / Use |
Type of Data |
Legal Basis |
Retention Period |
|
To process and deliver your order, including managing payments and confirming dispatch |
Identity, Contact, Financial, Transaction |
Performance of a contract with you |
6 years from the date of transaction (for accounting/tax purposes) |
|
To manage our relationship with you, including notifying you about changes to our terms or privacy policy and handling your requests, complaints and queries |
Identity, Contact, Marketing and Communications |
Performance of a contract with you; Legal obligation; Legitimate interests (to keep records updated and manage our relationship with you) |
6 years from last interaction |
|
To administer and protect our business and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
Identity, Contact, Technical |
Legitimate interests (running our business, providing IT and security services, preventing fraud); Legal obligation |
2 years |
|
To deliver relevant website content and online advertisements to you and to measure the effectiveness of advertising we serve to you |
Identity, Contact, Profile, Usage, Marketing and Communications, Technical |
Legitimate interests (to study how customers use our products, to develop our business and inform our marketing strategy) |
2 years |
|
To use data analytics to improve our website, products, customer relationships and experiences |
Technical, Usage |
Legitimate interests (to keep our website updated and relevant and to develop our business) |
2 years |
|
To send you marketing communications by email or SMS about products and offers that may be of interest to you |
Identity, Contact, Marketing and Communications |
Consent (for new subscribers); Legitimate interests (for existing customers who have not opted out) |
3 years from last interaction, or until you opt out |
|
To carry out targeted and personalised advertising via Meta (Facebook/Instagram) and Google platforms |
Identity, Contact, Technical, Profile, Usage |
Legitimate interests (to grow our business and promote our products to relevant audiences); Consent (where required by applicable cookie/advertising law) |
2 years, or until you withdraw consent |
|
To prevent fraud and ensure the security of our website |
Identity, Contact, Technical |
Legitimate interests (to protect our business and customers from fraudulent activity) |
2 years |
|
To comply with legal obligations including accounting, tax and regulatory requirements |
Identity, Contact, Financial, Transaction |
Legal obligation |
6 years from the end of the relevant financial year |
Direct marketing
When you make a purchase or register on our website, you may be asked to indicate your preferences for receiving direct marketing communications from us. We may send you marketing communications by email and SMS if you have consented to receive them, or where we rely on our legitimate interests as an existing customer who has not opted out.
We may also analyse your browsing and purchase history to personalise marketing communications and recommendations.
Third-party marketing
We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.
Opting out of marketing
You can ask us to stop sending you marketing communications at any time by following the opt-out link within any marketing communication sent to you, or by contacting us at support@eloracircle.com. If you opt out of marketing, you will still receive transactional communications that are essential for administrative or customer service purposes, such as order confirmations and shipping updates.
Cookies
For more information about the cookies we use and how to manage your cookie preferences, please see our Cookie Policy at https://eloracircle.com/pages/elora-circle-cookie-policy
Links
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
5. Disclosures of your personal data
We may share your personal data where necessary with the third-party processors listed in section 6 below and in the following circumstances:
• With third-party service providers who perform services on our behalf (see section 6 for the full list).
• With third parties to whom we may sell, transfer or merge parts of our business or assets. If a change happens to our business, the new owners may use your personal data in the same way as set out in this privacy policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes.
6. International transfers
We share your personal data with a number of service providers who process data outside the United Kingdom, in particular in the United States. Whenever we transfer your personal data out of the UK to countries which do not have laws providing the same level of data protection as the UK, we ensure a similar degree of protection is afforded to it by relying on UK-approved standard contractual clauses (International Data Transfer Agreement, or IDTA), as applicable.
Our key third-party processors and the locations in which they process data are as follows:
|
Processor |
Purpose |
Location |
Transfer Safeguard |
|
Shopify (Shopify Inc.) |
E-commerce platform, payment processing |
United States |
UK Standard Contractual Clauses (IDTA) |
|
PayPal (PayPal Holdings, Inc.) |
Payment processing |
United States |
UK Standard Contractual Clauses (IDTA) |
|
Klaviyo (Klaviyo Inc.) |
Email and SMS marketing platform |
United States |
UK Standard Contractual Clauses (IDTA) |
|
Google (Alphabet Inc.) — Analytics & Ads |
Website analytics, advertising measurement |
United States |
UK Standard Contractual Clauses (IDTA) |
|
Meta Platforms (Meta Platforms, Inc.) — Pixel & Ads |
Targeted advertising and conversion tracking |
United States |
UK Standard Contractual Clauses (IDTA) |
|
Cloudflare (Cloudflare, Inc.) |
Content delivery network, website security |
United States |
UK Standard Contractual Clauses (IDTA) |
|
AfterSell |
Post-purchase upsell and conversion |
United States |
UK Standard Contractual Clauses (IDTA) |
|
Track123 / Tracking providers |
Order tracking and shipment notifications |
Varies |
UK Standard Contractual Clauses (IDTA) where applicable |
|
Dianxiaomi |
Logistics / order fulfilment management |
China |
UK Standard Contractual Clauses (IDTA) where applicable |
|
Wetracked.io |
Server-side ad tracking & conversion attribution (Shopify / ad platforms) |
United States |
UK Standard Contractual Clauses (IDTA) |
7. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. Your data is stored on a secure server behind a firewall.
We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. Under UK GDPR, we are required to notify the Information Commissioner’s Office (ICO) of qualifying breaches within 72 hours of becoming aware of them.
8. Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.
As a general rule, we retain customer data (including Identity, Contact, Financial and Transaction Data) for six years from the date of the last transaction for tax and accounting purposes. Technical and Usage Data is retained for a shorter period, typically two years. Marketing preference data is retained for three years from the date of last interaction, or until you opt out of marketing.
In some circumstances you can ask us to delete your data: see section 9 below for further information.
In some circumstances we will anonymise your personal data for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
9. Your legal rights
You have a number of rights under UK data protection law in relation to your personal data. You have the right to:
• Request access to your personal data (a “subject access request”) - this enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
• Request correction of the personal data that we hold about you - this enables you to have any incomplete or inaccurate data we hold about you corrected.
• Request erasure of your personal data in certain circumstances - this enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it.
• Object to processing of your personal data - where we are relying on legitimate interests as the legal basis for that use of your data. You also have the absolute right to object at any time to the processing of your personal data for direct marketing purposes.
• Request restriction of processing of your personal data - this enables you to ask us to suspend the processing of your personal data in certain scenarios.
• Request the transfer of your personal data to you or to a third party - we will provide your personal data in a structured, commonly used, machine-readable format.
• Withdraw consent at any time - where we are relying on consent to process your personal data.
To exercise any of these rights, please contact us using the details in section 10 below. We try to respond to all legitimate requests within one month. We will not usually charge a fee for exercising your rights, although we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
10. Contact details
If you have any questions about this privacy policy, wish to exercise your legal rights, or have a concern about how we handle your personal data, please contact us:
Email: support@eloracircle.com
Postal address: LLA Advisor Limited, RM03, 24/F, Ho King Commercial Centre, 2-16 Fa Yuen Street, Mong Kok, Hong Kong.
11. Complaints
You have the right to make a complaint to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). However, before doing so please first raise your concern with us directly so we have the opportunity to address it. You can raise a complaint with us at the contact details above.
12. Changes to the privacy policy
We keep our privacy policy under regular review. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If our store is acquired by or merges with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
Last updated: May 19th, 2026