YOUSRA JEWELRY PRIVACY POLICY
GDPR | CCPA | PIPEDA | LGPD COMPLIANT
Effective Date: 05/12/2025
Last Updated: 05/12/2025
Policy Version: 1.0
Previous Version Archive: Available upon request
Controller: FASHION YOUSRA LLC
Data Protection Officer: privacy@yousrajewelry.com
Website: https://fashionyousra.com
Jurisdiction: Nevada, United States
1.0 EXECUTIVE SUMMARY & KEY PRINCIPLES
1.1 Our Commitment
Yousra Jewelry operates on a foundation of Privacy by Design and Default. We implement the highest standards of data protection across all operations, ensuring compliance with global privacy frameworks including GDPR (European Union), CCPA/CPRA (California), PIPEDA (Canada), LGPD (Brazil), and other applicable regulations.
1.2 Core Privacy Principles
- Transparency: Clear communication about data practices
- Minimization: Collection of only necessary data
- Security: Enterprise-grade protection measures
- Control: User autonomy over personal information
- Accountability: Regular audits and compliance verification
1.3 Quick Reference Table
| Data Type | Purpose | Retention | Your Rights |
|---|---|---|---|
| Identity Data | Order processing, authentication | 7 years | Access, Correction, Deletion |
| Contact Data | Customer support, updates | Until opt-out | Access, Unsubscribe |
| Financial Data | Transaction processing | 7 years for tax | Limited access via processors |
| Technical Data | Security, analytics | 26 months | Opt-out, Object |
| Marketing Data | Personalization, ads | Until opt-out | Opt-out, Object, Portability |
2.0 SCOPE & APPLICABILITY
2.1 Geographic Coverage
This policy applies to all users globally, with specific provisions for:
- EU/EEA/UK Residents: GDPR compliance (Articles 6, 12-23)
- California Residents: CCPA/CPRA compliance (§1798.100-199)
- Canadian Residents: PIPEDA compliance (Schedule 1)
- Brazilian Residents: LGPD compliance (Articles 7-10)
- Other Jurisdictions: Highest applicable standard applied
2.2 Service Coverage
This policy governs data collection through:
- Primary website: https://fashionyousra.com
- Mobile-responsive interfaces
- Customer support channels
- Marketing communications
- Third-party integrations (payment, shipping, analytics)
2.3 Age Restrictions
STRICT 18+ POLICY
We do not knowingly collect data from individuals under 18 years of age. Accounts suspected of belonging to minors will be immediately terminated and all associated data purged.
3.0 DATA COLLECTION CATEGORIES & LEGAL BASES
3.1 Personal Identification Data
Collection Method: Direct input during account creation, checkout, or support interactions
Data Elements:
- Full legal name
- Email address (verified)
- Telephone number (optional)
- Billing address (required for transactions)
- Shipping address (including alternative recipients)
- Tax identification (for business customers)
Legal Basis (GDPR): Contract performance (Article 6(1)(b)), Legal obligation (Article 6(1)(c))
3.2 Financial Transaction Data
Collection Method: Secure payment gateway integration
Data Elements:
- Payment method type (credit card, PayPal, etc.)
- Transaction identifiers
- Authorization codes
- Partial card information (last 4 digits only)
- Currency and amount
- Billing address verification
Critical Security Note: We implement zero-knowledge architecture for payment data. Full card numbers, CVV codes, and bank account details are never stored on our servers, transmitted through our systems, or accessible to our personnel.
Legal Basis: Contract performance, Legal obligation (tax records)
3.3 Technical & Device Data
Collection Method: Automated collection via cookies, logs, and analytics
Data Elements:
- IP address (anonymized where possible)
- Device type and manufacturer
- Operating system and version
- Browser type and plugins
- Screen resolution and color depth
- Network connection type
- Page load times and errors
- Clickstream patterns and heatmaps
Legal Basis: Legitimate interest (security, fraud prevention), Consent (analytics)
3.4 Behavioral & Preference Data
Collection Method: Interaction tracking and preference centers
Data Elements:
- Product views and favorites
- Cart abandonment patterns
- Purchase history and frequency
- Communication preferences
- Marketing channel responsiveness
- Customer satisfaction feedback
- Support interaction history
Legal Basis: Legitimate interest (service improvement), Consent (personalization)
3.5 Derived & Inferred Data
Collection Method: Analytical processing and machine learning algorithms
Data Elements:
- Customer lifetime value prediction
- Churn risk assessment
- Product affinity scoring
- Next-best-offer recommendations
- Fraud risk scoring
- Engagement propensity modeling
Transparency Note: All derived data is generated internally and not shared with third parties for independent scoring purposes.
4.0 DATA PROCESSING PURPOSES & LEGAL JUSTIFICATIONS
4.1 Contractual Necessity Processing
Purpose 1: Order Fulfillment
- Order validation and fraud screening
- Inventory allocation and reservation
- Manufacturing coordination (for custom pieces)
- Shipping label generation and tracking
- Customs documentation preparation
- Delivery confirmation and proof
Purpose 2: Customer Support
- Case creation and assignment
- Communication history maintenance
- Resolution tracking and escalation
- Satisfaction monitoring
- Service improvement analysis
4.2 Legitimate Interest Processing
Purpose 3: Security & Fraud Prevention
- Real-time transaction monitoring
- Device fingerprinting for authentication
- Behavioral anomaly detection
- Account takeover prevention
- Distributed denial-of-service (DDoS) mitigation
- Security incident investigation
Purpose 4: Service Optimization
- Website performance monitoring
- Bug detection and resolution
- Feature usage analysis
- Infrastructure scaling planning
- Regional performance optimization
Purpose 5: Product Development
- Feature request prioritization
- Usability testing analysis
- Market trend identification
- Competitive positioning assessment
4.3 Consent-Based Processing
Purpose 6: Marketing Communications
- Newsletter distribution (bi-weekly maximum)
- New product announcements
- Special collection previews
- Event invitations
- Customer appreciation offers
Purpose 7: Advertising & Remarketing
- Social media audience targeting (Meta, Pinterest, TikTok)
- Search engine marketing (Google Ads)
- Display network retargeting
- Lookalike audience creation
- Conversion tracking and optimization
Purpose 8: Advanced Analytics
- Cross-device tracking (with explicit consent)
- Customer journey mapping
- Attribution modeling
- Predictive analytics
- A/B testing and experimentation
5.0 PAYMENT SECURITY ARCHITECTURE
5.1 PCI-DSS Level 1 Compliance
We maintain the highest payment security certification through our partners:
Primary Processor: Stripe
- PCI-DSS Level 1 Service Provider (most stringent)
- SOC 1, SOC 2, and SOC 3 compliance
- AES-256 encryption at rest and in transit
- Tokenization replacing sensitive data
- 3D Secure 2.0 authentication
- Real-time fraud scoring with machine learning
Alternative Processor: PayPal
- PCI-DSS Level 1 Compliance
- Buyer and Seller Protection programs
- Encrypted financial tunnel technology
- Two-factor authentication options
- Dispute resolution management
5.2 Our Security Measures
Network Security:
- Web Application Firewall (WAF) with OWASP rules
- Distributed denial-of-service protection
- Intrusion detection and prevention systems
- Regular vulnerability scanning (weekly)
- Penetration testing (quarterly)
Access Control:
- Role-based access management (RBAC)
- Multi-factor authentication for all admin accounts
- Principle of least privilege enforcement
- Session timeout after 15 minutes inactivity
- Complete activity logging and audit trails
Data Protection:
- End-to-end encryption (TLS 1.3+)
- Data anonymization where possible
- Pseudonymization for analytics
- Secure key management (AWS KMS)
- Regular backup and disaster recovery testing
6.0 COOKIES & TRACKING TECHNOLOGIES
6.1 Cookie Classification Matrix
| Category | Purpose | Examples | Duration | Opt-Out Method |
|---|---|---|---|---|
| Essential | Site functionality | Session management, shopping cart, security tokens | Session | Not optional (site won’t work) |
| Performance | Analytics | Google Analytics (anonymized), heatmaps, error tracking | 26 months | Browser settings, consent manager |
| Functional | Preferences | Language, currency, login persistence, wishlist | 1 year | Browser settings, account preferences |
| Marketing | Advertising | Meta Pixel, Pinterest Tag, TikTok Pixel, Google Ads | 90 days | Consent manager, Ad settings |
| Third-Party | External services | Payment processors, shipping calculators, reviews | Varies | Source service opt-out |
6.2 Consent Management Platform
We implement OneTrust or equivalent enterprise consent management featuring:
- Granular consent categories (accept/reject by purpose)
- Geolocation detection for region-specific requirements
- Preference center for ongoing management
- Consent receipts and audit trails
- Automatic periodic renewal prompts (annual)
6.3 Do Not Track & Global Privacy Control
We respect:
- DNT (Do Not Track) browser signals
- GPC (Global Privacy Control) signals
- App Tracking Transparency (iOS)
- Android Advertising ID restrictions
When these signals are detected, we disable all non-essential tracking and honor opt-out preferences across all devices associated with your account.
7.0 DATA SHARING & THIRD-PARTY DISCLOSURES
7.1 Service Provider Ecosystem
Category A: Payment Processing (Data Processor Agreement Required)
- Stripe, Inc. (primary)
- PayPal Holdings, Inc. (alternative)
Category B: Order Fulfillment (Data Processing Addendum Required)
- DHL Express International
- FedEx Cross-Border
- UPS Worldwide
- USPS International (for select destinations)
- Customs brokerage partners
Category C: Marketing & Analytics (Consent/Contract Based)
- Meta Platforms, Inc. (Facebook, Instagram)
- Google LLC (Analytics, Ads)
- Pinterest, Inc.
- TikTok Limited
- Klaviyo (email marketing)
Category D: Infrastructure & Security (Binding Corporate Rules)
- Amazon Web Services (hosting)
- Cloudflare (CDN & security)
- Sentry (error tracking)
- Zendesk (customer support)
7.2 International Data Transfers
EU-US Data Privacy Framework: We self-certify compliance for all EU→US transfers
Standard Contractual Clauses: Implemented for non-adequate countries
Binding Corporate Rules: Required for all multinational service providers
Supplementary Measures: Additional encryption and access controls
7.3 Strict Prohibitions
We NEVER:
- Sell personal data (as defined by CCPA)
- Share data with data brokers or aggregators
- Permit secondary use without explicit consent
- Transfer data to high-risk jurisdictions without enhanced safeguards
- Retain data beyond operational necessity
8.0 DATA RETENTION SCHEDULE
8.1 Retention Periods by Data Category
| Data Category | Retention Period | Rationale | Deletion Method |
|---|---|---|---|
| Order Records | 7 years from transaction | Tax and legal compliance (IRS, EU) | Secure erasure with verification |
| Customer Accounts | 5 years from last activity | Business relationship maintenance | Anonymization then deletion |
| Marketing Data | 3 years from last engagement | Campaign effectiveness analysis | Complete purge with confirmation |
| Support Interactions | 2 years from resolution | Quality assurance and training | Redaction then deletion |
| Analytics Data | 26 months maximum | Trend analysis while respecting privacy | Aggregation then source deletion |
| Server Logs | 90 days | Security monitoring and debugging | Automated rotation and deletion |
| Backup Copies | 30 days maximum | Disaster recovery only | Cryptographic destruction |
8.2 Deletion Protocols
Standard Deletion: Automated process with verification audit
Right to Erasure Requests: 72-hour expedited processing
Backup Handling: Cryptographic shredding of backup references
Third-Party Notification: Automatic propagation to all processors
Deletion Certificate: Available upon request for compliance
9.0 YOUR RIGHTS & EXERCISE MECHANISMS
9.1 Global Rights Matrix
| Right | GDPR Term | CCPA Term | Exercise Method | Timeline |
|---|---|---|---|---|
| Access | Article 15 | §1798.110 | Data Subject Access Request | 30 days |
| Correction | Article 16 | §1798.105 | Account settings or request | 30 days |
| Deletion | Article 17 | §1798.105 | Deletion request portal | 45 days |
| Portability | Article 20 | §1798.100 | Export tools | 30 days |
| Opt-Out | Article 21 | §1798.120 | Preference center | 15 days |
| Restriction | Article 18 | N/A | Support request | 30 days |
| Objection | Article 21 | §1798.125 | Objection form | 30 days |
| Non-Discrimination | N/A | §1798.125 | Automatic protection | Immediate |
| Know/Sell/Share | N/A | §1798.115 | Privacy dashboard | 45 days |
9.2 Request Submission Portal
Primary Channel: privacy@yousrajewelry.com
Alternate Channel: +1 (725) 712-2572 (Verification required)
Online Form: https://fashionyousra.com/privacy-request
Postal Request: FASHION YOUSRA LLC, Attn: Privacy Officer [Address]
9.3 Identity Verification Protocol
To prevent unauthorized access, we require:
- Two-factor verification for account-associated requests
- Government ID matching for sensitive requests (partial redaction accepted)
- Previous transaction confirmation for non-account holders
- Notarized request for high-risk operations
No Fee Policy: All rights exercises are free unless manifestly unfounded or excessive.
9.4 Appeal Process
If we deny your request:
- Detailed explanation with legal basis provided
- Internal review by Data Protection Officer within 7 days
- External mediation option (EU DPA, California AG, etc.)
- Judicial remedy information provided
10.0 CHILDREN’S PRIVACY
10.1 Strict Age Gates
- Account registration: Explicit 18+ confirmation required
- Purchase attempts: Age verification through payment processors
- Marketing lists: Age screening through third-party providers
- Social media: Audience restrictions on all platforms
10.2 Parental Controls
- Notice to parents: Immediate notification if underage use detected
- Parental consent: Required for any exception (gift purchases)
- Data deletion: Expedited 24-hour process for minors’ data
- Education: Resources for parents about online safety
11.0 SECURITY BREACH PROTOCOLS
11.1 Incident Response Timeline
0-1 Hour: Initial detection and containment
1-4 Hours: Impact assessment and notification planning
4-24 Hours: Regulatory notifications (if required)
24-72 Hours: Individual notifications (if high risk)
72+ Hours: Remediation and prevention implementation
11.2 Notification Triggers
Mandatory Notification:
- Unencrypted personal data accessed
- Credentials compromised
- Financial data exposed
- High-risk special category data (none collected)
Voluntary Notification:
- Encrypted data accessed without keys
- Low-risk incidents with no evidence of misuse
- System vulnerabilities without exploitation
11.3 Your Responsibilities
- Password hygiene: Unique, complex passwords recommended
- Device security: Regular updates and antivirus protection
- Network awareness: Avoid public Wi-Fi for sensitive operations
- Phishing vigilance: We never request passwords via email
- Account monitoring: Regular review of order history
12.0 POLICY GOVERNANCE & UPDATES
12.1 Review Cycle
- Monthly: Technical compliance check
- Quarterly: Legal and regulatory review
- Annually: Comprehensive policy audit
- Event-driven: Immediate review after regulatory changes
12.2 Update Notification Protocol
Material Changes: 30-day advance notice via:
- Website banner with summary of changes
- Email notification to all account holders
- Policy comparison tool highlighting modifications
- Archive access to previous versions
Minor Changes: Posted immediately with change log update
12.3 Compliance Certifications
We maintain:
- GDPR: Data Processing Register and Article 30 Records
- CCPA: Annual threshold assessment and disclosure readiness
- PIPEDA: Accountability framework and breach records
- LGPD: Data Protection Officer appointment and ANPD compliance
13.0 CONTACT & DISPUTE RESOLUTION
13.1 Data Protection Officer
Email: privacy@yousrajewelry.com
Phone: +1 (725) 712-2572 (Extension 2 for Privacy)
Hours: 9:00 AM – 5:00 PM PST, Monday-Friday
Response Time: 72 hours maximum for privacy inquiries
13.2 Regulatory Authorities
United States (California):
California Privacy Protection Agency
https://cppa.ca.gov
European Union (Lead Authority):
Irish Data Protection Commission
https://www.dataprotection.ie
United Kingdom:
Information Commissioner’s Office
https://ico.org.uk
Canada:
Office of the Privacy Commissioner
https://www.priv.gc.ca
13.3 Binding Arbitration Clause
Any disputes relating to privacy practices shall be resolved through binding arbitration administered by JAMS under its Comprehensive Arbitration Rules. The arbitration shall take place in Las Vegas, Nevada, and shall be conducted in English. The arbitrator’s decision shall be final and binding.
14.0 DEFINITIONS & INTERPRETATION
Biometric Data: Not collected
Genetic Data: Not collected
Health Data: Not collected
Political Opinions: Not collected
Religious Beliefs: Not collected
Sexual Orientation: Not collected
Trade Union Membership: Not collected
Consent: Freely given, specific, informed, unambiguous indication
Controller: FASHION YOUSRA LLC
Processor: Third-party service provider
Personal Data: Any information relating to an identified or identifiable person
Processing: Any operation performed on personal data
Profiling: Automated processing to evaluate personal aspects
Pseudonymization: Processing that prevents attribution without additional information
YOUSRA JEWELRY — WHERE LUXURY MEETS DIGITAL TRUST
