This Privacy Policy (“Policy”) outlines the practices of dealstore.lk (“we,” “us,” or “our”) concerning the collection, use, disclosure, and protection of personal data when you (“User” or “you”) access and utilize our online store and services within Sri Lanka.

By engaging with dealstore.lk, you acknowledge and consent to the data practices described in this Policy. Our commitment is to manage your personal data with integrity and transparency, in alignment with contemporary data protection principles, including those set forth by the Personal Data Protection Act, No. 9 of 2022, of Sri Lanka.


 

1. Personal Data Collected

We collect various categories of personal data to facilitate our services, fulfill your orders, and enhance your user experience.

  • Identity and Contact Data:

    • When you create an account: Your full name, email address, and contact telephone number.

    • When you place an order: Your full name, accurate billing address, shipping address, email address, and contact telephone number.

    • When you communicate with us: Any information you voluntarily provide during inquiries, support requests, or feedback via email or telephone.

  • Financial and Transaction Data:

    • For debit or credit card payments: Your payment card details (card number, expiration date, CVV) are transmitted directly to our secure, PCI DSS compliant third-party payment gateway partners. We do not store your full payment card details on our servers.

    • For bank transfers/deposits: We collect necessary transaction verification details such as the transfer reference number, deposited amount, and date of deposit.

  • Technical and Usage Data:

    • Information related to your interaction with our Service, including your Internet Protocol (IP) address, browser type and version, device type, operating system, pages visited, time and date of visit, duration on pages, unique device identifiers, and other diagnostic data.

  • Cookies and Tracking Technologies:

    • We employ cookies and similar tracking technologies (e.g., pixels, web beacons) to monitor activity on our Service and retain specific information. Cookies are small data files placed on your device. You have the option to configure your browser to refuse all cookies or to alert you when a cookie is being sent. However, declining cookies may limit the functionality of certain parts of our Service.


 

2. Lawful Basis and Purpose of Processing

We process your personal data based on specific lawful grounds for the following purposes:

  • Performance of Contract: To fulfill our contractual obligations with you, including processing your orders, managing your account, and delivering products.

  • Legitimate Interests: To operate, maintain, and improve our Service, enhance user experience, conduct analytics, detect and prevent fraud, and ensure the security of our systems.

  • Legal Obligation: To comply with applicable laws, regulations, and legal processes in Sri Lanka.

  • Consent: Where required by law, we obtain your explicit consent for specific processing activities, particularly for direct marketing communications. You retain the right to withdraw your consent at any time.


 

3. Disclosure of Personal Data

We may disclose your personal data to specific third parties under the following circumstances:

  • Service Providers: We engage trusted third-party service providers to perform functions on our behalf, such as payment processing, product delivery (logistics partners), website hosting, data analytics, and customer support. These providers are contractually bound to process your data only for specified purposes and to maintain its confidentiality and security.

  • Legal Requirements and Law Enforcement: We may disclose your personal data if required by law, subpoena, or if we believe such action is necessary to comply with legal obligations, protect our rights or property, prevent fraud, or ensure the safety of our users or the public.

  • Business Transfers: In the event of a merger, acquisition, asset sale, or similar transaction involving dealstore.lk, your personal data may be transferred as part of the business assets. We will notify you prior to such a transfer where your personal data becomes subject to a different privacy policy.

  • With Your Express Consent: We may share your information for any other purpose when we have obtained your explicit consent to do so.


 

4. Data Security

We implement robust technical and organizational security measures designed to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to, encryption (e.g., SSL/TLS), access controls, firewalls, and regular security assessments. While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is entirely secure. Therefore, we cannot guarantee its absolute security.


 

5. Your Rights as a Data Subject

In accordance with data protection principles emerging in Sri Lanka (including the PDPA), you, as a data subject, have the following rights concerning your personal data:

  • Right of Access: You have the right to request confirmation of whether we are processing your personal data and to obtain a copy of the personal data we hold about you.

  • Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.

  • Right to Erasure: You have the right to request the deletion of your personal data under certain circumstances (e.g., if the data is no longer necessary for the purposes for which it was collected).

  • Right to Object to Processing: You have the right to object to the processing of your personal data for certain purposes, particularly direct marketing.

  • Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time.

To exercise any of these rights, please contact us using the contact details provided below. We will respond to your request in accordance with applicable laws.


 

6. Third-Party Websites

Our Service may contain links to external websites that are not operated by dealstore.lk. We do not control and are not responsible for the content, privacy policies, or practices of any third-party sites or services. We strongly advise you to review the Privacy Policy of every site you visit.


 

7. Children’s Privacy

Our Service is not directed at individuals under the age of sixteen (16) years (“Children”). We do not knowingly collect personally identifiable information from Children. If you are a parent or guardian and become aware that your Children have provided us with personal data, please contact us. If we discover that we have collected personal data from Children without verifiable parental consent, we will take immediate steps to remove that information from our servers.


 

8. Changes to This Privacy Policy

We may revise this Privacy Policy periodically to reflect changes in our practices or applicable laws. Any updates will be posted on this page, and the “Last Updated” date at the top of this Policy will be revised. We encourage you to review this Policy periodically to stay informed about how we are protecting your information. Changes become effective when they are published on this page.


 

9. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

  • By Email: hello@dealstore.lk

  • By Phone/WhatsApp: +94742617414