Privacy Policy
Your privacy is important to us. Therefore, we are committed to protecting your personal information and ensuring transparency in how it is used
At LevoSlim, your privacy and digital security are our foundational priorities. We are committed to protecting your personal data in strict accordance with global data protection regulations, including the European Union’s General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA). By accessing our website, interacting with our digital platforms, or purchasing our products, you consent to the practices outlined in this detailed policy.
1. Comprehensive Breakdown of Information We Collect
To provide our premium weight management products and maintain a secure digital architecture, we collect data across several categories:
- Directly Provided Identifiers: Full legal name, billing address, and shipping address. Email address and phone number (utilized for order updates and WhatsApp support API integrations).
- Technical & Network Data (Automated Collection): Your IP address, device type, operating system, and browser version. Session interaction history, including pages viewed, time on site, and “Buy Now” click tracking.
- Geolocation Data: We collect coarse location data via Cloudflare’s CF-IPCountry header to accurately route our services and display regional pricing.
- Commercial & Transactional Data: Complete purchase history and selected product variations (e.g., LevoSlim Summer Peach or Wild Strawberry). Records of customer service interactions, including WhatsApp transcripts and email logs.
- Financial Information: Payment card details are routed and processed directly by our secure, PCI-DSS certified third-party payment gateways (via WooCommerce). We do not store, process, or transmit full credit card numbers on our internal Hostinger servers.
2. Automated Decision-Making & Geo-Pricing
We utilize specialized automated processing to enhance user experience. Specifically, our proprietary Geo-Pricing engine reads your IP address dynamically (via Cloudflare edge routing) to display the correct local currency (e.g., TRY, AED, SAR, USD, EUR, etc.).
- No Permanent Storage: This location data is processed momentarily in the browser to trigger WooCommerce currency filters and is not permanently stored to your user profile.
- No Price Discrimination: This automation is solely for currency conversion convenience and does not alter the base value or discriminate against users based on location.
3. Detailed Purposes and Legal Basis for Processing
We process your data strictly under the following lawful bases:
| Processing Purpose | Legal Basis (GDPR/UK GDPR) | Data Category Used |
| Order Fulfillment: Processing secure checkouts, managing WooCommerce accounts, and coordinating global shipping. | Contractual Necessity | Identifiers, Commercial, Financial |
| Customer Communication: Sending transactional emails, tracking updates, and providing support via our WhatsApp API. | Contractual Necessity / Legitimate Interest | Identifiers, Commercial |
| Analytics & Performance: Utilizing Google Analytics 4 and Facebook Pixel to measure conversion rates and optimize our website infrastructure. | Explicit Consent | Technical & Network Data |
| Security & Fraud Prevention: Leveraging Cloudflare’s Web Application Firewall (WAF) to secure our network against malicious bot activity. | Legitimate Interest | Technical & Network Data |
4. Data Retention Schedule
We do not hold your data indefinitely. We retain personal information only for as long as necessary to fulfill the purposes outlined above:
- Transactional & Tax Data: Retained for up to 7 years to comply with international tax and corporate accounting laws.
- Customer Accounts: Retained as long as the account remains active. Inactive accounts are flagged for deletion after 36 months of zero activity.
- Marketing Data: Retained until you explicitly withdraw consent or click “unsubscribe.”
5. Third-Party Disclosures & Data Sharing
We do not, and will never, sell your personal data to data brokers. We share your data exclusively with highly vetted service providers necessary to operate our business:
- Infrastructure Providers: Hostinger (Server hosting) and Cloudflare (Edge network delivery and WAF security).
- E-Commerce & Logistics: WooCommerce (Platform) and authorized global shipping couriers.
- Analytics & Advertising: Google (GA4/Tag Manager) and Meta (Facebook Pixel) strictly for aggregated performance tracking.
- Legal & Regulatory Authorities: We may disclose data if legally mandated by a valid subpoena, court order, or to protect the safety and rights of LevoSlim and our users.
6. International Data Transfers
Because our central operations are based in Istanbul, Turkey, and our digital infrastructure utilizes global routing, your data may be transferred across borders. For users in the EEA or UK, we safeguard these transfers by relying on Standard Contractual Clauses (SCCs) and recognized adequacy decisions to ensure your data receives equivalent legal protection globally.
7. Your Comprehensive Global Privacy Rights
Depending on your jurisdiction, you have the right to:
- Right to Access & Portability: Request a structured, machine-readable copy of the personal data we hold about you.
- Right to Deletion (Right to be Forgotten): Request the permanent erasure of your personal data from our databases, subject to overriding legal and tax retention requirements.
- Right to Correction: Request the immediate update or correction of any inaccurate profile information.
- Right to Opt-Out of Sale/Sharing (CCPA/CPRA): California residents may utilize our cookie banner or “Do Not Sell or Share My Personal Information” tools to opt out of Meta/Google tracking pixels.
- Right to Non-Discrimination: You will never face retaliatory pricing, reduced product quality, or denied service for exercising these rights.
To Exercise These Rights: Email our compliance team directly at support@levoslim.com. We are committed to responding within 30 days for GDPR-related requests and 45 days for CCPA-related requests.
8. Security Measures & Data Breach Protocol
Your data is shielded by enterprise-grade security protocols:
- Encryption: All traffic is forced over secure HTTPS via SSL certificates.
- Server Hardening: Our databases run on optimized LiteSpeed environments, shielded by Cloudflare’s Edge network and WAF.
- Breach Protocol: In the highly unlikely event of a data breach compromising unencrypted personal data, LevoSlim will notify the relevant supervisory authorities within 72 hours and directly notify affected users via email, outlining the scope of the breach and immediate protective actions to take.
9. Detailed Cookie & Tracking Policy
We deploy strict consent management without the use of deceptive “dark patterns”.
- Essential Cookies: Required for basic site functionality, such as retaining items in your WooCommerce cart and maintaining Cloudflare security routing. These cannot be disabled.
- Performance Cookies: Google Tag Manager and LiteSpeed Cache protocols used to ensure our site meets high-speed Core Web Vitals.
- Marketing Cookies: Used to measure advertising efficacy and deliver targeted promotions. You can opt out of these at any time via the persistent cookie banner preferences tool.
10. Children’s Privacy
LevoSlim physical products and digital platforms are formulated and intended strictly for adults. We do not knowingly collect, process, or store personal information from any individual under the age of 18. If we become aware that we have inadvertently collected such data, it will be immediately purged from our servers.
11. Policy Updates & Contact Information
We reserve the right to update this policy periodically to align with shifting legal mandates or technological upgrades. Material changes will be clearly posted on this page with an updated “Effective Date”.
For any legal or privacy-specific inquiries, please contact our data protection team via:
Email: support@levoslim.com
Effective Date: January 15, 2025