LankaTreats

Privacy Policy

Last updated: 04 May 2026

1. Introduction

LankaTreats ("we", "us", or "our") operates an online platform offering customized candy boxes and related services. We are committed to protecting your personal data and handling it responsibly in accordance with applicable data protection laws in Sri Lanka.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

By using our website, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

2.1 Personal Information

We may collect the following information when you use our services:

  • Name, email address, phone number
  • Billing and shipping addresses
  • Account credentials (username, password)
  • Payment information (processed securely through PayHere)
  • Order details and preferences
  • Communication preferences

2.2 Automatically Collected Information

We automatically collect certain data, including:

  • IP address and approximate location
  • Browser type and version
  • Device information (type, operating system)
  • Pages visited, time spent, and interactions
  • Referral sources

2.3 Cookies and Tracking Technologies

We use cookies and similar technologies to enhance functionality and analyze website usage. You can manage cookie preferences through your browser or our cookie banner. For detailed information about our cookie practices, please review our Cookie Policy.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract: To process and deliver your orders and provide services
  • Consent: For marketing communications and optional tracking
  • Legal Obligation: To comply with applicable laws and regulations
  • Legitimate Interest: To improve our services, prevent fraud, and ensure security
4. How We Use Your Information

We use your data to:

  • Process and fulfill orders
  • Manage your account and subscriptions
  • Send order confirmations and delivery updates
  • Provide customer support
  • Improve and optimize our website
  • Personalize your experience
  • Send marketing communications (only where you have opted in)
  • Detect and prevent fraud
  • Comply with legal requirements
5. Marketing Communications

We will only send promotional communications where you have explicitly opted in. You can withdraw your consent at any time by:

  • Clicking the "unsubscribe" link in emails
  • Contacting us directly
6. Sharing Your Information

We do not sell, trade, or rent your personal information to third parties. We may share your information with:

  • Payment processors (e.g., PayHere)
  • Delivery and logistics providers
  • Hosting and analytics providers (e.g., Google Analytics, Firebase)
  • Service providers who support our operations
  • Payment processors, shipping carriers, and other vendors who help us operate our business

We may also disclose information:

  • To comply with legal obligations
  • To protect our rights, safety, users, or services
  • In connection with a business transfer (e.g., merger, sale, or acquisition)
  • With Your Consent: When you explicitly authorize us to share your information
7. International Data Transfers

Some of the third-party services we use may process your data outside Sri Lanka (e.g., Google Analytics, Firebase). Where this occurs, we ensure appropriate safeguards are in place to protect your personal data.

8. Data Retention

We retain personal data only as long as necessary:

  • Order and transaction data: up to 5 years for legal and accounting purposes
  • Account data: until account deletion or prolonged inactivity
  • Marketing data: until you unsubscribe or withdraw consent
9. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • SSL (Secure Socket Layer) encryption for data transmission
  • Encrypted storage of sensitive information
  • Secure payment processing via PayHere gateway
  • Firebase Authentication for account security
  • Access controls and authentication mechanisms
  • Regular security audits and updates

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

10. Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent at any time
  • Object to certain types of processing
  • Request data portability
  • Unsubscribe from marketing emails at any time

To exercise your rights, contact us at: support@lankatreats.com

We will respond to requests within 30 days, as required by applicable law.

11. Children's Privacy

Our services are not intended for individuals under the age of 13. We do not knowingly collect personal data from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

LankaTreats Sri Lanka

Email: support@lankatreats.com

Stay in the Sweet Loop

Get new box alerts & exclusive discounts. No spam promise!