Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your personal information when you shop with Lilly.
1. Information We Collect
When you interact with Lilly Store — whether browsing, creating an account, or placing an order — we may collect the following types of information:
- Personal details: name, email address, phone number, and date of birth (if provided)
- Delivery information: shipping address and any delivery preferences
- Payment information: billing details processed securely through our payment provider (we do not store card numbers)
- Account data: username, password (encrypted), and order history
- Usage data: pages visited, products viewed, time spent on site, and device/browser information
2. How We Use Your Information
We use the information we collect to:
- Process and fulfil your orders, and send order confirmations and updates
- Provide customer support and respond to your enquiries
- Send you relevant promotions, offers, and product updates (only if you've opted in)
- Improve our website, product range, and overall shopping experience
- Detect and prevent fraud or unauthorised account activity
- Comply with legal obligations applicable in Qatar
We will never use your data for purposes beyond what is described here without your explicit consent.
5. Data Security
We take the security of your personal data seriously. We implement industry-standard measures including:
- SSL encryption on all pages where data is transmitted
- Secure, encrypted storage for sensitive account information
- Restricted access — only authorised team members can access customer data
- Regular security reviews of our systems and infrastructure
While we strive to protect your data, no method of transmission over the internet is 100% secure. If you suspect any unauthorised use of your account, please contact us immediately.
6. Your Rights
You have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: ask us to correct any inaccurate or incomplete data
- Deletion: request that we delete your personal data, subject to legal requirements
- Opt-out: unsubscribe from marketing emails at any time via the link in any email
- Portability: request your data in a structured, machine-readable format
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes it was collected for, including legal, accounting, or reporting requirements.
- Active account data is kept for the duration of your account
- Order records are retained for up to 5 years for financial compliance
- Marketing preferences are stored until you opt out or request deletion
When data is no longer needed, it is securely deleted or anonymised.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will revise the "Last updated" date at the top of this page.
We encourage you to review this page periodically. Continued use of our website after any changes constitutes your acceptance of the updated policy.
Questions about your privacy?
We're happy to clarify anything in this policy — get in touch and we'll respond within 24 hours.