Privacy Policy
Last updated: June 4, 2026 · Effective for visitors and customers worldwide
This Privacy Policy explains what personal information GlamEye (operated by Ealdcrest Capital LLC, New Jersey, USA) collects, how we use it, with whom we share it, and your rights. By using glameyeshop.com you consent to the practices described here.
1. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email, phone, shipping address | You provide at checkout / signup |
| Order data | Items purchased, amount, payment method (last 4 digits only) | You + Stripe / PayPal |
| Account data | Login email, password hash, preferences | You + automated |
| Usage data | Pages visited, clicks, device type, IP, referrer | Automated (analytics) |
| Communications | Support emails, chat messages, reviews | You provide |
What we do NOT collect: full credit card numbers (handled by Stripe / PayPal), Social Security numbers, government IDs, biometric data.
2. How We Use Your Information
- Process and fulfill your orders (shipping, billing, customer service)
- Communicate about your order (confirmation, shipping, delivery)
- Send marketing emails about new products and offers — only if you opt in (you can unsubscribe at any time)
- Improve the Site and develop new products (aggregate analytics)
- Prevent fraud and abuse (rate limiting, payment verification)
- Comply with legal obligations (tax records, subpoenas)
3. Sharing Your Information
We do not sell personal information. We share data only with:
- Payment processors: Stripe and PayPal (PCI-DSS compliant)
- Shipping carriers: USPS, UPS, FedEx, DHL — only the address fields needed to deliver
- Email service: Resend (transactional email delivery)
- Analytics: Google Analytics 4 (anonymized where possible)
- Hosting: Vultr (servers in the United States)
- Authorities: when required by law (subpoenas, court orders)
4. Cookies and Tracking
We use cookies and similar technologies to:
- Essential(required): keep you signed in, remember your cart, secure forms
- Analytics(optional): understand how visitors use the Site
- Marketing(optional): personalize ads we run on Meta/TikTok/Google
You can disable non-essential cookies via your browser settings. We do not respond to "Do Not Track" signals at this time but we honor GPC (Global Privacy Control) signals where required by law.
5. Your Rights — California (CCPA/CPRA), Virginia (CDPA), and Similar
If you live in California, Virginia, Colorado, Connecticut, Utah, or a similar U.S. state, you have the right to:
- Know what personal information we have about you
- Delete your personal information (with limited exceptions, e.g. tax records we must keep)
- Correct inaccurate information
- Opt out of "sale" or "share" for cross-context behavioral advertising (we do not sell personal info)
- Limit use of sensitive personal information
- Non-discrimination for exercising these rights
To exercise these rights, email privacy@glameyeshop.com from the address on file. We respond within 45 days (extendable to 90).
6. Your Rights — European Union and UK (GDPR / UK GDPR)
If you are in the EU/EEA or UK, you have the right to:
- Access, rectify, or erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability (export in machine-readable format)
- Withdraw consent for marketing at any time
- Lodge a complaint with your supervisory authority
Our legal bases for processing are: contract performance (orders), legitimate interests (analytics, fraud prevention), and consent (marketing). Email privacy@glameyeshop.com to exercise rights.
7. Data Security
We use industry-standard security:
- TLS encryption for all traffic to the Site
- Passwords stored with bcrypt hashing
- Database access restricted to a dedicated user with a randomly generated 32-character password
- Stripe webhooks signed and verified
- Rate limiting on login, signup, and order lookup endpoints
No system is 100% secure. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
8. Data Retention
We keep order records for at least 7 years for tax and accounting purposes. Account data is kept while your account is active and for up to 3 years after you delete it (in anonymized form). Marketing data is deleted within 90 days of unsubscribe.
9. Children's Privacy
The Site is not directed to children under 16. We do not knowingly collect data from anyone under 16. If you believe we have collected data from a minor, email privacy@glameyeshop.com and we will delete it.
10. International Transfers
We are based in the United States, and your data is processed there. If you are in the EU/UK we transfer data using Standard Contractual Clauses or equivalent safeguards.
11. Changes
We may update this Policy from time to time. Material changes will be highlighted on the Site or sent via email.
12. Contact
Privacy questions or requests: privacy@glameyeshop.com
Ealdcrest Capital LLC · New Jersey 07901 · USA
我们收集您下单时提供的姓名、邮箱、地址,以及您浏览网站时产生的访问数据。 我们 不卖您的个人信息。只与必要的服务商共享(Stripe、PayPal、物流、Resend 邮件、Google 分析、Vultr 主机)。 您有权要求 访问、删除、纠正 您的个人数据(美国 CCPA / 欧洲 GDPR), 退订营销邮件请访问 unsubscribe 页面或邮件底部链接。 信用卡完整号码不经我们,直接进 Stripe/PayPal。密码用 bcrypt 加密存储。 若有疑问请发邮件至 privacy@glameyeshop.com