This policy explains what personal information LYNX collects when you use thelynxdigital.com, why we collect it, who we share it with, and how you can control it. We have tried to write it in plain language rather than legal boilerplate.
1. Who we are
LYNX ("we", "us", "our") designs and sells the LYNX X6 magnetic power bank through this website, thelynxdigital.com. For the purposes of data protection law, LYNX is the data controller for the personal information described in this policy — meaning we decide what is collected and why.
Our registered trading address is [insert your business address] and you can reach us any time at support@lynxpower.co.
2. What information we collect
Information you give us directly
Most of the information we hold is information you typed in yourself:
| When you… | We collect |
|---|---|
| Place an order | Name, email address, shipping address, city, postal code, country, and the details of what you bought |
| Pay for an order | Payment is processed by our payment provider. We receive a confirmation, the last four digits of the card and its type — never the full card number, expiry or security code |
| Email support | Your email address and whatever you choose to tell us in the message, including any order reference |
| Claim a warranty or return | Order details, proof of purchase, and a description of the fault |
Information collected automatically
This site is a set of static pages. It does not run analytics software, and it does not set cookies. However, two things happen automatically whenever anyone loads a web page, and you should know about them:
- Server logs. Our hosting provider records standard technical information for every request — your IP address, the page requested, the date and time, your browser type and operating system, and the referring page. These logs exist for security and reliability, not marketing, and we do not use them to identify individual visitors.
- Web fonts. Our pages load typefaces from Google Fonts. That request goes directly from your browser to Google's servers and, like any web request, exposes your IP address to Google. We do not send Google any other information about you. If you prefer to avoid this, browser extensions that block third-party font loading will do so without breaking the site.
What we deliberately do not collect
We do not collect or ask for your date of birth, government ID numbers, financial account details beyond what the payment provider needs, precise location data, biometric data, or any of the categories that data protection law treats as sensitive (such as health, ethnicity, religion or political opinions). We do not run advertising pixels, session recording, heatmaps, or cross-site trackers.
3. Why we collect it
We only collect information where we have a clear reason and a lawful basis for doing so. In plain terms:
| Purpose | Lawful basis (UK/EU GDPR) |
|---|---|
| To take payment and deliver the product you ordered | Performance of a contract |
| To send order confirmations, dispatch and delivery updates | Performance of a contract |
| To answer support questions and handle returns or warranty claims | Performance of a contract, and our legitimate interest in supporting customers |
| To keep tax, accounting and customs records | Legal obligation |
| To keep the website secure and prevent fraud or abuse | Legitimate interests |
| To send marketing email, if you ask us to | Consent, which you can withdraw at any time |
We do not use your information to make automated decisions that produce legal or similarly significant effects about you.
4. Cookies and tracking
This website does not currently set any cookies, and it does not use local storage, session storage, advertising pixels or analytics scripts. There is no consent banner because there is nothing to consent to.
Items you add to the shopping cart are held in your browser's memory for the duration of your visit only, and disappear when you close the tab. Nothing about your cart is transmitted to us until you complete an order.
If we introduce analytics or advertising cookies in future, we will update this policy and ask for your consent first, before any non-essential cookie is set.
5. Who we share it with
We do not sell, rent or trade your personal information. We share it only with the service providers we need in order to run the shop, and only with the minimum they need to do their job. Each is bound by contract to protect your data and to use it only on our instructions.
| Provider | What they handle |
|---|---|
| Website hosting — [e.g. GitHub Pages] | Serving the site; standard server logs including IP addresses |
| Payment processing — [insert provider] | Card details, billing address, fraud screening. They act as an independent controller for payment data under their own privacy policy |
| Shipping and fulfilment — [insert carrier] | Name, delivery address, phone or email for delivery notifications |
| Email — [insert provider] | Sending order confirmations and replying to support messages |
We may also disclose information where we are legally required to — for example in response to a valid court order, a tax authority request, or to establish or defend a legal claim. If our business is ever sold or merged, customer records may transfer to the new owner, who would remain bound by this policy or give you notice before changing it.
6. How we protect it
No system is perfectly secure, and any company that tells you otherwise is overselling. What we can tell you is what we actually do:
- Encryption in transit. The whole site is served over HTTPS with TLS, so what you send is encrypted between your browser and the server.
- We never store card numbers. Full card details go directly to our payment provider and are never written to our systems. We could not leak them, because we do not hold them.
- Data minimisation. We ask for the fewest fields that will get a parcel to your door, and we do not keep information we no longer have a reason to hold.
- Access control. Order records are reachable only by the small number of people who need them for fulfilment or support, using individual accounts with multi-factor authentication.
- Vetted processors. We use established providers for payment, shipping and email rather than building our own, and we review their security commitments before handing over any data.
- A static front end. The public site has no database and no server-side application behind it, which removes an entire category of common attack.
If a breach ever occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell you directly without undue delay.
7. How long we keep it
| Record | Kept for |
|---|---|
| Order and transaction records | Typically 6–7 years, as required by tax and accounting law |
| Warranty records | The 18-month warranty period, plus a short buffer for claims |
| Support correspondence | Up to 2 years after the conversation ends |
| Marketing contact details | Until you unsubscribe, then removed from the sending list |
| Server logs | A short rolling window set by our host, typically weeks rather than years |
When a retention period ends, records are deleted or irreversibly anonymised.
8. International transfers
We ship worldwide, and some of our providers operate outside your country — including in the United States. Where personal information is transferred out of the UK or European Economic Area, we rely on an appropriate safeguard, normally the European Commission's Standard Contractual Clauses or an adequacy decision covering the destination country. You may request a copy of the safeguard we rely on by emailing us.
9. Your rights
Depending on where you live, you have some or all of the following rights over the information we hold about you:
- Access — ask for a copy of the personal information we hold about you.
- Rectification — ask us to correct anything inaccurate or incomplete.
- Erasure — ask us to delete your information, where we have no overriding legal reason to keep it.
- Restriction — ask us to pause our use of your information while a dispute is resolved.
- Portability — receive the information you gave us in a machine-readable format, or have it sent to another provider.
- Objection — object to processing we base on legitimate interests, including any direct marketing.
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing carried out before you withdrew it.
If you are in California, the CCPA and CPRA additionally give you the right to know the categories of personal information collected and the purposes for collecting them, to request deletion or correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising any of these rights. To be explicit: we do not sell or share your personal information as those terms are defined under California law, and we have not done so in the preceding twelve months.
To exercise any right, email support@lynxpower.co. We will respond within one month (or 45 days for California requests) and will not charge you for a reasonable request. We may need to verify your identity first, usually by asking you to confirm details of a recent order.
If you believe we have handled your information badly, we would like the chance to put it right — but you also have the right to complain to your local data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the supervisory authority in your country of residence.
10. Children's privacy
This site is intended for adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, contact us and we will delete it promptly.
11. Third-party links
Our pages link out to other sites, including our Facebook and Instagram profiles. Those links are plain hyperlinks — we do not embed social widgets or tracking pixels, so nothing is shared with those platforms unless you click through. Once you do, you are on their site and their privacy policy applies, not ours.
12. Changes to this policy
We will update this page when our practices change — for example if we add analytics, launch a newsletter, or change payment provider. The "last updated" date at the top always reflects the current version. If a change materially affects your rights, we will give you clear notice rather than quietly editing the page.
13. How to contact us
For any question about this policy, or to exercise your rights:
Post: LYNX, [insert your business address]
We aim to reply to every privacy request within 30 days.