GDPR Privacy Policy

This GDPR Policy explains how Elinmora (“we,” “us,” or “our”) may process personal data when you visit or shop at elinmora.com (the “Website”). It describes the rights available under the European Union General Data Protection Regulation (GDPR), where applicable.

Our online store is based in the United States and primarily serves customers in the United States. The GDPR does not automatically apply to every visitor simply because the Website can be accessed from the European Union. Its application depends on the circumstances and the requirements of applicable law.

This Policy should be read together with our Privacy Policy and Cookies Policy. Our actual data practices depend on the services, technologies, and processing arrangements in use.

1. Personal Data We May Process

Depending on how you use the Website, we may process the following categories of personal data:

  • Contact information: Name, email address, telephone number, billing address, and shipping address.
  • Order information: Products purchased, order status, delivery details, cancellation requests, return requests, and refund records.
  • Payment-related information: Payment status, transaction references, and information needed to process or verify payments. The payment provider and payment arrangement determine which payment details we receive or handle.
  • Technical information: IP address, browser and device information, technical identifiers, and security-related records, where generated or collected.
  • Website usage information: Browsing activity, interactions, and performance information, where relevant analytics or similar technologies are enabled.
  • Customer service information: Details you provide when contacting us about an order, complaint, return, refund, or other inquiry.
  • Preferences and marketing information: Communication preferences or subscription status, where relevant features are offered and used.

Personal data may be collected directly from you, generated through your interaction with the Website, or provided by service providers involved in your transaction. We do not necessarily collect every category listed above.

2. Purposes and Legal Bases for Processing

Where the GDPR applies, we process personal data only where an appropriate legal basis exists. Depending on the circumstances, these bases may include:

  • Contract: To process orders, arrange payment and delivery, communicate about purchases, and handle cancellations, returns, or refunds.
  • Legal obligation: To meet applicable tax, accounting, recordkeeping, and other legal requirements.
  • Legitimate interests: To operate and secure the Website, prevent misuse, resolve disputes, and establish, exercise, or defend legal claims, where our interests are not overridden by your rights and freedoms.
  • Consent: For processing activities that require consent under applicable law, such as certain nonessential cookies or marketing activities.

Where applicable, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Other legal bases under the GDPR may apply only where their specific legal conditions are met. The legal basis for each activity depends on its purpose and circumstances.

3. Sharing Personal Data

We may disclose personal data where necessary for the purposes described in this Policy, where an appropriate legal basis exists, or where disclosure is required or permitted by law.

Depending on our actual operations, recipients may include:

  • Website hosting, maintenance, and technical service providers.
  • Payment providers involved in processing transactions.
  • Shipping, delivery, and fulfillment providers.
  • Customer service or communications providers, where used.
  • Courts, regulators, law enforcement authorities, or other authorized recipients where legally required or permitted.

The role of each service provider depends on the relevant arrangement. Where required by the GDPR, appropriate contractual terms and safeguards must be in place.

We do not assume that every type of provider or service listed above is currently used. Our disclosures must reflect our actual business practices.

4. International Data Transfers

Because our store is based in the United States, personal data may be processed in the United States or other countries, depending on the systems and service providers involved.

Where the GDPR applies to an international transfer, we will ensure that the transfer meets the applicable requirements under Chapter V of the GDPR. Depending on the circumstances, this may involve an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.

The applicable safeguards depend on the actual transfer arrangements. Information about relevant safeguards will be provided where required by law.

5. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, subject to applicable legal requirements and other lawful retention needs.

Retention periods may depend on order and payment administration, delivery, returns and refunds, accounting and tax obligations, security needs, and the handling of disputes or legal claims. Different categories of data may therefore be retained for different periods.

Cookie expiration does not necessarily mean that associated personal data has also been deleted. Please refer to our Cookies Policy for further information about cookie controls and retention.

6. Data Security and Breaches

We take the protection of personal data seriously and should apply appropriate technical and organizational measures based on the nature of the data, the processing involved, and the relevant risks. No method of electronic transmission or storage can be guaranteed to be completely secure.

Where the GDPR applies, a personal data breach may trigger legal duties to document the incident, notify a supervisory authority, or inform affected individuals. For example, notification to a supervisory authority is generally required without undue delay and, where feasible, within 72 hours of becoming aware of a breach when the GDPR's notification conditions are met. Communication to affected individuals may be required where the breach is likely to result in a high risk to their rights and freedoms.

The response to any incident depends on the circumstances and applicable law.

7. Your Rights Under the GDPR

Where the GDPR applies to the relevant processing, you may have the following rights, subject to applicable conditions and exceptions:

  • Access: Request confirmation of whether we process your personal data and obtain access to it.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of personal data where the legal requirements are met.
  • Restriction: Request restriction of processing in certain circumstances.
  • Data portability: Receive certain personal data you provided in a structured, commonly used, machine-readable format, where the legal conditions are met.
  • Object: Object to processing based on legitimate interests or another applicable ground specified by the GDPR. You may object to direct marketing processing at any time where the GDPR applies.
  • Withdraw consent: Withdraw consent where processing is based on consent.
  • Automated decision-making protections: Receive the protections provided by the GDPR where a decision falls within the relevant legal provisions.
  • Lodge a complaint: Submit a complaint to a competent data protection supervisory authority where the right applies.

These rights are not absolute in every circumstance. Certain information may need to be retained to comply with legal obligations or to establish, exercise, or defend legal claims.

8. How to Submit a Privacy Request

To ask a question or exercise a privacy right, contact us at:

Email: solutions@elinmora.com

Please describe your request and provide enough information for us to understand it. We may request reasonable additional information to verify your identity or authority before responding. Do not send your full payment card number, CVV/CVC, password, or unnecessary sensitive authentication information by email.

Where the GDPR applies, we generally respond to data subject requests without undue delay and within one month of receipt. Where permitted by the GDPR, this period may be extended by up to two additional months because of the complexity or number of requests. If an extension is needed, we will provide notice and the reasons within the initial one-month period.

Requests are generally handled free of charge. The GDPR permits a reasonable fee or refusal in certain cases involving manifestly unfounded or excessive requests, subject to its requirements.

9. Cookies and Similar Technologies

Cookies and similar technologies may be used to support Website functionality, remember preferences, protect sessions, analyze performance, or support advertising, depending on our actual configuration.

Where the GDPR and applicable electronic privacy rules require consent for nonessential cookies or similar technologies, we will use an appropriate consent process. Continuing to browse the Website does not automatically constitute valid consent in every circumstance.

Where processing relies on consent, you may withdraw that consent through the applicable controls. You may also manage cookies through your browser settings, although blocking certain cookies may affect shopping cart, checkout, or other Website functions.

For further information, please read our Cookies Policy. The cookie categories and technologies described in our policies must reflect those actually in use.

10. Children's Privacy

The Website is an online furniture store and is not represented by this Policy as a service specifically directed toward children. If personal data relating to a child is processed, we will assess and address any additional requirements imposed by applicable law.

11. Changes to This Policy

We may update this GDPR Policy to reflect changes in our business practices, Website functionality, data-processing arrangements, or legal requirements. We will update the “Last Updated” date when this Policy is revised and provide any additional notice required by applicable law.

12. Contact Us

If you have questions about this Policy or our handling of personal data, please contact us:

  • Website: https://elinmora.com
  • Email: solutions@elinmora.com
  • Phone: +1 (334) 562-7149
  • Address: 159 1st Ave SE #B, Lafayette, AL 36862, United States
  • Customer Service Hours: Monday through Friday, 9:00 AM–6:00 PM

We will review privacy inquiries and respond in accordance with the requirements applicable to the request.