- Home
- Policy
Privacy Policy
Effective date: 28 August 2025
Who we are: Zayla (“we”, “us”, “our”) — an online store offering the book Zayla’s Starlight Home and related information.
Website: https://www.zayla.my
Contact: hello@zayla.my
We respect your privacy and are committed to protecting your personal data. This Policy explains what we collect, how we use it, the choices you have, and your rights.
1) What we collect
We collect only what’s needed to operate the store, fulfil orders, and support you.
Information you provide
-
Account & checkout: name, billing/shipping address, email, phone, order notes.
-
Communications: messages you send via forms or email, and any files you attach.
-
Newsletter/updates (optional): your email and preferences.
-
Support/returns: details you share so we can help.
Information collected automatically
-
Store/session data (cookies): to remember your cart, keep you logged in, and measure basic performance.
Typical WooCommerce cookies include:-
woocommerce_cart_hash
,woocommerce_items_in_cart
(cart state) -
wp_woocommerce_session_*
(anonymous session id)
-
-
Device & usage: IP address, browser type, pages viewed, timestamps, and referral URLs.
-
Analytics (if enabled): [Google Analytics/Meta Pixel/etc.] collect pseudonymous usage data. Disable or list any that don’t apply.
Payment information
-
Payments are processed by third-party providers [Stripe / CommercePay]. We do not store full card or bank details on our servers. Providers may collect and process your payment data under their own privacy policies.
2) How we use your information
-
To run the store: process and deliver orders, provide invoices, manage returns/refunds, and maintain your account.
-
Customer support: respond to questions and troubleshoot issues.
-
Communications: send order confirmations, shipping updates, service notices, and (if you opt in) newsletters or product updates.
-
Security & fraud prevention: verify account and payment activity.
-
Legal/compliance: maintain records as required by law and tax authorities.
-
Analytics & improvements: understand how the site is used and improve performance and content.
Legal bases (where applicable)
-
Contract performance (fulfilling orders),
-
Legitimate interests (site security, analytics, customer support),
-
Consent (marketing emails, optional cookies),
-
Legal obligations (tax/accounting).
3) Sharing your information
We share data only with trusted providers who help us operate the site, each bound by confidentiality and data-protection obligations:
-
E-commerce platform: WordPress & WooCommerce.
-
Payments: [Stripe & CommercePay].
-
Analytics/measurement: [Google Analytics & Meta].
-
Compliance: professional advisers and authorities where required by law.
We do not sell your personal information.
4) International transfers
Our service providers may process data in countries outside Malaysia or Singapore. Where required, we implement safeguards (e.g., contractual clauses) to protect your data consistent with applicable laws.
5) Data retention
-
Orders & accounting records: kept for 7 years (or as required by law).
-
Customer accounts: retained while active; deleted or anonymized after 24 months of inactivity.
-
Support emails/form submissions: up to 24 months.
-
Marketing lists: until you unsubscribe or request deletion.
-
Cookies: see durations in your browser; session cookies expire when you close the browser.
6) Your rights
Depending on where you live (e.g., Malaysia PDPA, Singapore PDPA, GDPR/UK GDPR), you may have rights to:
-
Access, correct, or delete your personal data.
-
Object to or restrict certain processing.
-
Withdraw consent (e.g., marketing) at any time.
-
Port your data (where applicable).
-
Lodge a complaint with your data-protection authority.
To exercise these rights, email hello@zayla.my. We’ll respond within a reasonable time.
7) Cookies & similar technologies
Cookies help the site function (e.g., cart, login), remember preferences, and—if enabled—provide analytics. You can control cookies via your browser settings and, where offered, our cookie banner/preferences tool.
If you disable essential cookies, some features (checkout, account) may not work properly.
8) Children’s privacy
Our site and store are intended for adults/parents. We do not knowingly collect personal information from children under 13 (or the age defined by your local law). If you believe a child has provided us data, contact us to remove it.
9) Links to external resources
We link to independent resources such as CBSS.sg and a private Facebook group for bereaved parents. Their content and privacy practices are outside our control and governed by their own policies. Please review those policies before sharing information there.
10) Security
We use reasonable technical and organisational measures—such as HTTPS/TLS encryption, access controls, and regular updates—to protect your data. No method of transmission or storage is 100% secure; we work to keep risks low.
11) Changes to this Policy
We may update this Policy to reflect changes in laws, services, or practices. We’ll post the new version with a revised Effective date. Material changes may be highlighted on the site.
12) How to contact us
-
Email: hello@zayla.my]