1. Scope and General Framework This Privacy Policy (the "Policy") governs the privacy practices of this website (the "Platform") regarding the collection, transmission, processing, storage, and utilization of personally identifiable information ("Personal Data") provided by global users ("Users", "Customers", "you"). The Platform operations strictly align with the global digital data protection frameworks, including but not limited to the General Data Protection Regulation (GDPR) and the Sri Lanka Personal Data Protection Act No. 9 of 2022. By interacting with the Platform, initiating an order form submission, or utilizing any integrated redirect mechanisms, you hereby grant your express, unambiguous, and fully informed consent to the specific methodologies delineated herein.
2. Data Categories and Collection Methodologies The Platform collects specific datasets through explicit electronic forms and automatic background browser interactions:
Voluntary Data Inputs: This includes user-provided alphanumeric inputs captured during order processing workflows, such as structural names, secondary contact emails, physical billing vectors, shipping telemetry, and precise product option preferences.
Automated Telemetry Logs: When accessing the Platform, technical arrays are captured automatically, encompassing internet protocol (IP) structures, browser user-agents, localized timezone settings, referral uniform resource locators (URLs), system operating structures, device telemetry, and precise interaction timestamps.
3. Payment Infrastructure and Third-Party Isolation All financial payment mechanisms, transactions, and electronic fund transfers are segregated entirely from the primary hosting infrastructure of this website. Financial information, including credit card numbers, card verification values (CVV/CVC), expiration dates, and biometric verification tokens, are processed via encrypted Transport Layer Security (TLS 1.3) protocols directly by authorized financial payment gateways, specifically PayHere (Private) Limited and its licensed commercial banking partners under the regulatory supervision of the Central Bank of Sri Lanka.
At no point does the Platform, its databases, or its storage components intercept, record, view, or retain any raw financial credentials. The third-party payment gateway maintains sole liability for payment data protection compliance under the Payment Card Industry Data Security Standard (PCI-DSS).
4. Data Processing Motives and Information Retention Collected information is executed exclusively for the completion of explicitly requested transactional services, order tracking, and essential business communication. Data is stored within secured cloud servers and is systematically purged or pseudonymized once the operational, accounting, and legal requirements for the transaction have been entirely satisfied, or upon the expiration of a statutory retention window required by local tax and business laws. The Platform explicitly warrants that no personal information will be traded, rented, shared, or distributed to third-party advertising brokers or unauthorized marketing networks.