Privacy Policy
Last updated: 3 March 2026
This Privacy Policy explains how we collect, use, share and protect your personal data when you visit our website, make a purchase, create an account, sign up to marketing, or otherwise interact with us.
1. Who We Are
Lily and Lionel is operated by:
Vyoma Brands Ltd
Company number: 16968522
Registered office: 71–75 Shelton Street, London, United Kingdom, WC2H 9JQ
VAT number: GB510749210
In this policy, “we”, “us”, “our” refers to Vyoma Brands Ltd trading as Lily and Lionel.
If you have any questions about this Privacy Policy or your personal data, please contact:
customerservice@lilyandlionel.com
For the purposes of UK data protection law, we are the data controller of your personal data.
2. The Laws We Follow
We process personal data in accordance with:
- UK GDPR
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- Any applicable updates to UK data protection legislation
If you are located in the EEA, we also aim to meet EU GDPR standards where applicable.
3. What Personal Data We Collect
We collect different types of personal data depending on how you interact with us.
3.1 Identity and Contact Data
- Full name
- Email address
- Phone number
- Billing address
- Delivery address
3.2 Account Data
- Account login details
- Order history
- Saved items or preferences
Passwords are stored in encrypted or hashed form via our e-commerce platform.
3.3 Order and Transaction Data
- Products purchased
- Order value
- Payment status
- Delivery information
- Returns and exchanges
We do not store full payment card details. These are processed securely by our payment providers.
3.4 Marketing Data
- Newsletter subscriptions
- SMS marketing preferences (if applicable)
- Marketing engagement (opens, clicks, browsing behaviour where consented)
3.5 Technical and Usage Data
- IP address
- Browser type and version
- Device type
- Pages visited
- Time spent on pages
- Referring website
- Cookie identifiers
4. How We Collect Your Data
We collect data:
- Directly from you (when you order, create an account, contact us, or sign up to marketing)
- Automatically (via cookies, pixels and analytics tools)
- From third parties (e.g., payment providers, delivery partners, fraud prevention services)
5. How We Use Your Personal Data
We only use your data where we have a lawful basis.
5.1 To Process and Fulfil Orders
Lawful basis: Contract
- Process payments
- Dispatch orders
- Manage returns and refunds
- Send order confirmations and delivery updates
5.2 To Provide Customer Support
Lawful basis: Legitimate interests / Contract
- Respond to enquiries
- Handle complaints
- Maintain service records
5.3 To Send Marketing Communications
Lawful basis: Consent (or soft opt-in where legally permitted)
- Email newsletters
- Promotional offers
- Product launches
You can unsubscribe at any time via the link in our emails or by contacting us.
5.4 To Improve Our Website and Services
Lawful basis: Consent (for non-essential cookies) / Legitimate interests
- Website analytics
- Performance optimisation
- Understanding shopping behaviour
5.5 For Fraud Prevention and Security
Lawful basis: Legitimate interests / Legal obligation
- Detect and prevent fraud
- Secure our website and systems
5.6 To Comply with Legal Obligations
Lawful basis: Legal obligation
- Tax and accounting requirements
- Responding to lawful authority requests
6. Cookies and Similar Technologies
We use cookies and similar technologies (including pixels and tags) to:
- Enable essential website functions (cart, checkout, login)
- Remember preferences
- Analyse website traffic
- Deliver personalised advertising (where consented)
You can manage your cookie preferences via our cookie consent tool at any time.
For more information, please see our Cookie Policy.
7. Sharing Your Data
We share personal data only where necessary to operate our business. This may include:
- E-commerce platform providers (e.g., Shopify)
- Payment processors (e.g., Stripe, PayPal, Klarna, Apple Pay, Google Pay, Shop Pay)
- Delivery partners and couriers
- Marketing and email platforms
- Analytics providers (e.g., Google Analytics)
- Advertising platforms (e.g., Meta, Google) where you consent
- Professional advisers (accountants, legal advisers)
- Regulators or authorities, where required by law
We do not sell your personal data.
8. Klarna
If you choose Klarna payment options, we will share certain information (such as contact and order details) with Klarna so they can assess eligibility and provide their services. Klarna processes your data in accordance with their own privacy policy.
9. International Transfers
Some of our service providers may process personal data outside the UK or EEA (for example, in the United States).
Where this happens, we ensure appropriate safeguards are in place, such as:
- UK International Data Transfer Agreements (IDTA)
- UK Addendum to EU Standard Contractual Clauses
- The UK–US Data Bridge (where applicable)
10. How Long We Keep Your Data
We retain personal data only for as long as necessary.
Typical retention periods:
- Order and transaction records: 6–7 years (for tax and legal purposes)
- Customer service correspondence: up to 24 months
- Marketing data: until you unsubscribe
- Account data: until account closure or inactivity period
We may retain data longer where required by law or to resolve disputes.
11. How We Protect Your Data
We use appropriate technical and organisational measures to protect your personal data, including:
- Encrypted connections (HTTPS/SSL)
- Restricted access controls
- Secure hosting environments
- Supplier data protection agreements
- Monitoring and security safeguards
While no online service is completely secure, we take reasonable steps to protect your data.
12. Your Rights
Subject to applicable law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Object to processing (including marketing)
- Withdraw consent
- Request data portability
- Lodge a complaint with a supervisory authority
To exercise your rights, contact:
customerservice@lilyandlionel.com
13. Complaints
If you are unhappy with how we handle your personal data, please contact us first.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
https://ico.org.uk
14. Children
Our website is not intended for children, and we do not knowingly collect personal data from individuals under 18. If we become aware that a child has provided personal data, we will take appropriate steps to delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on our website with a revised “Last updated” date.