Privacy Policy

Last updated: 04 March 2026

1. Introduction

At vanitis, trust is at the heart of everything we create. We collect only the information necessary to deliver your order, improve your experience, and operate our business responsibly. We never sell personal data.

This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you visit our website, place an order, or interact with us.

This policy aligns with:

• UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection
• International privacy best practices
• GDPR-level transparency standards for customers in the EU and UK

By using our website, you acknowledge that your personal data may be processed as described in this policy.

For general website rules please see our [Terms & Conditions].

2. Company Information

Vanitis Cosmetics Trading Co LLC
Dubai, United Arab Emirates

Email: office@vanitis.com
Website: www.vanitis.com

3. Personal Data We Collect

Information You Provide

• Full name
• Email address
• Phone number
• Billing address
• Shipping address
• Order history
• Customer service communications

Payment details are processed securely through third-party payment providers. vanitis does not store full credit card details.

Information Collected Automatically

When visiting our website we may collect:

• IP address
• Device and browser information
• Website interaction data
• Pages visited and session duration
• Cookies and tracking identifiers

4. How We Use Your Data

We use personal data for the following purposes.

Order Fulfillment

• Payment processing
• Shipping and delivery (see Shipping Policy)
• Customer service
• Fraud prevention

Business Operations

• Accounting and legal compliance
• Inventory management
• Customer relationship management (Odoo ERP system)

Marketing and Website Improvement

• Email newsletters (with consent)
• Website analytics
• Advertising performance measurement

You may unsubscribe from marketing communications at any time.

5. Legal Basis for Processing

Personal data may be processed based on:

• Contractual necessity (order fulfillment)
• Legitimate business interests (fraud prevention, analytics)
• Consent (marketing and optional cookies)
• Legal obligations

6. CRM & ERP Processing

Customer data may be processed in our Odoo ERP/CRM system, which securely stores:

• customer contact details
• order history
• transaction records
• customer service communications

Access is restricted to authorized personnel.

7. Cookies & Tracking Technologies

Our website uses cookies and similar technologies for functionality, analytics, and advertising.

Examples include:

• Google Analytics
• Google Ads
• Meta Pixel

Non-essential cookies are activated only after user consent where required by applicable law.

For detailed information please review our Cookie Policy.

8. Data Sharing

We may share personal data with trusted service providers such as:

• payment processors
• shipping carriers
• hosting providers
• advertising platforms
• IT service providers

These partners process data only to provide services on our behalf.

9. International Data Transfers

Because we operate internationally, personal data may be transferred outside your country of residence.

Where required, such transfers are protected through appropriate safeguards such as contractual protections (including standard contractual clauses), adequacy decisions, or equivalent mechanisms designed to protect personal data.

10. Data Retention

Personal data is retained only as long as necessary.

Data TypeRetention Period
Order recordstypically 5–10 years for legal/accounting requirements
Customer accountswhile active
Marketing datauntil consent withdrawn
Customer service communicationsoperational/legal purposes

Data may be retained longer where required by law or necessary for fraud prevention.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

• access personal data
• request correction of inaccurate data
• request deletion where legally permitted
• object to certain processing
• withdraw consent for marketing

Requests may be submitted to office@vanitis.com.

For security purposes we may require identity verification before processing requests.

We aim to respond within 30 days, or within the timeframe required by applicable law.

Requests may be refused where permitted by law (for example where data must be retained for legal obligations or fraud prevention).

If you are located in the EU or UK you may also lodge a complaint with your local data protection authority.

12. Data Security

We use encrypted connections (SSL), secure hosting environments, and restricted access systems to protect personal data.

13. Children’s Privacy

Our website and products are not intended for children under 18 without parental supervision.

14. Policy Updates

This Privacy Policy may be updated periodically. The latest version will always be published on our website.

15. Contact

office@vanitis.com
www.vanitis.com