Privacy policy

Last updated: 16 June 2026

This Privacy Policy describes how One More Luck (the "Site", "we", "us", or "our") collects, uses, stores, and discloses your personal data when you visit, use our services, or make a purchase from onemoreluck.com (the "Site") or otherwise communicate with us regarding the Site (collectively, the "Services").

For the purposes of this Privacy Policy, "you" and "your" means any user of the Services, including customers, website visitors, or other individuals whose personal data we process.

Please read this Privacy Policy carefully.


1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. When we do, we will update the “Last updated” date and, where required by law (including GDPR), notify you directly or request renewed consent where applicable.


2. Legal Framework (EU / EEA / UK)

Where EU/EEA or UK data protection law applies, we process your personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
  • UK GDPR (where applicable)
  • Directive 2002/58/EC (ePrivacy Directive, as implemented locally)

3. How We Collect and Use Your Personal Data

We collect personal data from you, automatically, and from third parties depending on how you interact with our Services.

We use your personal data for:

  • Providing and fulfilling our contract with you
  • Customer support and communication
  • Improving our Services
  • Marketing (where permitted by law)
  • Legal compliance and fraud prevention
  • Website security and analytics

4. Categories of Personal Data We Collect

4.1 Data you provide directly

  • Contact details (name, email, address, phone number)
  • Order details (billing/shipping information, purchase history)
  • Account credentials (username, password)
  • Customer support messages

4.2 Automatically collected data

  • IP address and approximate location
  • Device and browser information
  • Usage data (pages visited, interactions)
  • Cookies and tracking technologies

4.3 Data from third parties

  • Payment providers (payment status, billing verification)
  • Logistics and fulfillment partners
  • Analytics and advertising providers
  • Shopify and similar infrastructure providers

5. Legal Basis for Processing (GDPR Article 6)

We process personal data under one or more of the following legal bases:

  • Contract – to provide goods/services you request
  • Legal obligation – to comply with applicable laws (tax, accounting, etc.)
  • Legitimate interest – to improve services, prevent fraud, secure systems, and conduct limited marketing (balanced against your rights)
  • Consent – for marketing emails, cookies (non-essential), and certain tracking technologies

Where processing is based on consent, you may withdraw it at any time.


6. Marketing Communications (EU Rules)

We only send direct marketing communications where legally permitted:

  • Email marketing is based on your consent or, where allowed, existing customer relationship (soft opt-in rules depending on jurisdiction)
  • You may unsubscribe at any time using the link in emails or by contacting us

7. Cookies and Tracking Technologies

We use cookies and similar technologies in compliance with the ePrivacy Directive and GDPR.

We use cookies for:

  • Essential website functionality
  • Shopping cart and checkout
  • Analytics and performance measurement
  • Advertising (only with consent where required)

Non-essential cookies are only activated after your consent via a cookie banner.

You can:

  • Accept or refuse cookies
  • Modify browser settings at any time
  • Withdraw consent via cookie settings (where available)

More information: https://www.shopify.com/legal/cookies


8. How We Share Personal Data

We may share personal data with:

  • Service providers (hosting, payment processing, logistics, analytics)
  • Shopify and e-commerce infrastructure providers
  • Marketing and advertising partners (only where lawful)
  • Professional advisors (legal, accounting)
  • Public authorities when legally required
  • Business transfers (merger, acquisition, insolvency)

All third parties are required to process your data in compliance with GDPR where applicable.


9. International Data Transfers

Where personal data is transferred outside the EEA/UK, we ensure appropriate safeguards, such as:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement (IDTA) or Addendum
  • Transfers to countries deemed to provide adequate protection by the European Commission

10. Data Retention

We retain personal data only as long as necessary for:

  • Providing services
  • Legal obligations (e.g. tax laws)
  • Contractual requirements
  • Dispute resolution and enforcement

Retention periods vary depending on the type of data and legal requirements.


11. Your Rights (EU / EEA / UK)

You have the following rights under GDPR:

  • Right of access – obtain a copy of your data
  • Right to rectification – correct inaccurate data
  • Right to erasure – request deletion (“right to be forgotten”)
  • Right to restriction – limit processing
  • Right to data portability – receive your data in a portable format
  • Right to object – including objection to direct marketing
  • Right to withdraw consent – at any time
  • Right not to be subject to automated decision-making (if applicable)
  • Right to lodge a complaint with a supervisory authority

To exercise your rights, contact us at the email below.


12. Complaints

If you believe your rights have been violated, you may:

A list of EU supervisory authorities is available via the European Data Protection Board (EDPB).


13. Security of Your Data

We implement appropriate technical and organisational measures to protect personal data. However, no system is completely secure, and we cannot guarantee absolute security.


14. Children’s Data

Our Services are not intended for children under 16. We do not knowingly collect personal data from children under this age.

If we become aware that such data has been collected, we will delete it promptly.


15. Third-Party Links

Our Site may contain links to third-party websites. We are not responsible for their privacy practices. We recommend reviewing their privacy policies separately.


16. Data Controller

For the purposes of GDPR and applicable data protection laws, One More Luck is the data controller of your personal data unless otherwise stated.

Contact:
📧 contact@onemoreluck.com