Privacy policy
1. What data we collect
When you interact with NOVU (novustores.com) we collect only what's necessary:
- Contact data: name, email, shipping address, phone.
- Payment data: we never directly see your card. PayPal processes payments with SSL encryption.
- Order data: products purchased, dates, amounts, tracking.
- Technical data: device type, browser, approximate IP, cookies (only if you accept them).
- Communications: messages you send us by email or WhatsApp.
2. How we use them
We use your data exclusively to:
- Process and deliver your orders.
- Respond to support inquiries.
- Send you the newsletter if you subscribed (cancellable at any time).
- Improve the shopping experience (anonymized analytics).
- Comply with legal obligations (billing, anti-fraud).
We don't use your data for third-party advertising without your explicit consent.
3. Who we share them with
We share minimal data only with the providers necessary to operate:
- Shopify — store platform (hosting + checkout).
- PayPal — payment processor.
- Shipping providers — your address for delivery.
- Klaviyo — only if you subscribed to the newsletter.
- Legal authorities — only if there's a verifiable legal obligation.
We never sell your personal information to third parties.
4. Cookies
We use cookies to:
- Essential: remember your cart, account session. Can't be disabled.
- Analytics: understand which pages you visit (anonymized).
- Marketing: remarketing on social media (only if you accept).
You can manage your cookie preferences from the banner that appears on your first visit.
5. Advertising and tracking technologies (TikTok, Meta, Google)
We use first- and third-party cookies and tracking technologies —including advertising pixels and SDKs— to measure store performance, optimize the experience and show you relevant ads. By using the site and accepting the cookie banner, you authorize the processing and sharing of this data with our advertising and measurement partners.
Partners we share data with: TikTok (TikTok Pixel and Events API), Meta (Meta Pixel — Facebook and Instagram) and Google (Google Analytics 4 and Google Ads).
What data is shared: cookie and device identifiers, IP address, browser/user-agent type, and interaction events (pages and products viewed, items added to cart, purchases and their value). Where applicable, email or phone are shared hashed (encrypted) to match events in a pseudonymized way. We do not share your card details.
Purpose: conversion measurement, attribution, campaign optimization and personalized advertising / retargeting.
Legal basis: your consent (manageable from the cookie banner) and/or our legitimate interest, depending on your jurisdiction (GDPR in the EU, LGPD in Brazil, CCPA in California).
Your options (opt-out): you can adjust or withdraw your consent in the cookie banner, set your browser to block cookies, and turn off personalized advertising directly on each platform: TikTok (Settings → Ads), Meta (Ad preferences) and Google (myadcenter.google.com). Write to us at help@novustores.com to exercise your rights of access, rectification or deletion.
6. Your rights
You have the right to:
- Access the data we have about you.
- Correct inaccurate data.
- Delete your account and associated data (right to be forgotten).
- Portability — export your data in a structured format.
- Object to the use of your data for marketing.
- Withdraw consent at any time.
To exercise any of these rights, write to us at help@novustores.com. We respond within 30 days.
7. Security
We protect your data with SSL encryption across the site, PCI-DSS compliant payments, restricted access to authorized staff, and continuous fraud monitoring.
If we detect a breach affecting your data, we'll notify you within 72 hours.
8. Data retention
- Order data: 5 years (accounting obligation).
- Inactive account data: until you request deletion.
- Analytics cookies: maximum 24 months.
- Newsletter: until you unsubscribe.
9. Minors
NOVU is not directed at children under 16 years old. We do not knowingly collect data from minors. If you are a parent/guardian and discover that your child has sent us data, write to us and we'll delete it immediately.
10. International transfers
Your data may be processed in countries outside your jurisdiction (US, Europe) by our providers. In all cases we ensure standard contractual clauses and an equivalent level of protection.
11. Changes to this policy
If we make substantial changes, we'll notify you by email (if you have an account) or post a prominent notice on the site.
12. Contact
For privacy questions or to exercise your rights: help@novustores.com · Subject: "Privacy - [your request]" · Max response: 30 days.