Privacy Policy – LunaSkin

Effective Date: 17 May 2025
Last Updated: 17 May 2025

LunaSkin is committed to protecting your privacy and ensuring a safe shopping and service experience. This policy outlines how we collect, use, store, and share your data when you interact with our website https://lunaskin.co.nz, purchase skincare products, or visit our cosmetic skin clinic.


1. Who We Are

LunaSkin is a female-owned and operated boutique skin clinic and skincare provider based in Half Moon Bay, Auckland.

Website: https://lunaskin.co.nz
Email: info@lunaskin.co.nz
Phone: 021 0271 7203


2. What Information We Collect

We collect personal information in the following scenarios:

When You Book Treatments or Buy Products:

  • Full name
  • Email address
  • Phone number
  • Delivery address
  • Skin concerns (optional)
  • Order details
  • Payment information (via third-party processor)

Automatically Collected:

  • IP address
  • Browser/device info
  • Website interactions (via cookies and analytics tools)

3. WooCommerce & Online Orders

Our website uses WooCommerce to manage and process online product sales. When you place an order, your data is securely stored in our database to:

  • Fulfil your order and ship products
  • Communicate order status and updates
  • Allow refunds or returns when eligible
  • Comply with tax and legal requirements

We do not store your full payment details. Payments are processed securely via Stripe, PayPal, or other PCI-compliant payment gateways.


4. Cookies & Analytics

We use cookies to enhance your shopping experience. This includes remembering your cart, saving your preferences, and analyzing how visitors use our site.

You can disable cookies through your browser settings at any time.


5. Returns & Refunds Policy

We stand behind the quality of our products and want you to be completely satisfied.

Returns:

  • Return requests must be made within 14 days of receiving your order.
  • Products must be unopened, unused, and in original packaging.
  • Contact us at info@lunaskin.co.nz to start a return.

Refunds:

  • Once your return is received and inspected, we will notify you of the approval or rejection.
  • If approved, a refund will be processed back to your original payment method.

Non-Returnable Items:

  • Used/opened skincare products
  • Gift cards
  • Sale items (unless faulty)

If you received a damaged or incorrect item, please contact us within 7 days for a replacement or refund.


6. Data Security

We use secure servers, encrypted connections (SSL), and follow best practices to protect your data. Only authorized staff have access to customer information.


7. Your Rights

Under New Zealand privacy law, you have the right to:

  • Access or correct your personal data
  • Request deletion of your data
  • Opt out of promotional communications
  • Lodge a complaint with the NZ Privacy Commissioner

You can make requests by emailing info@lunaskin.co.nz.


8. How Long We Keep Your Data

  • Customer records and order data: up to 7 years (legal requirement)
  • Email marketing data: until you unsubscribe
  • Website browsing data: typically retained for 12–26 months (analytics)

9. Embedded Content

Pages may contain embedded videos or content (e.g. YouTube, Instagram). These services may collect data from you as if you were visiting them directly.


10. Where Your Data Is Stored

Data is securely stored on trusted servers in New Zealand and with compliant international platforms (e.g., WooCommerce, Stripe, Google).


11. Policy Changes

We may occasionally update this policy. If significant changes are made, we’ll notify users via email or a site banner. Continued use of our website means you accept the revised terms.


12. Contact Us

LunaSkin
πŸ“ 3/31 Lisa Rise, Half Moon Bay, Auckland 2012
πŸ“§ info@lunaskin.co.nz
πŸ“ž 021 0271 7203

Who we are

Suggested text: Our website address is: https://lunaskin.co.nz.

Comments

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Suggested text: Visitor comments may be checked through an automated spam detection service.

Shopping cart0
There are no products in the cart!
Continue shopping
0