1. Introduction and Purpose
LensiQ’s core privacy principles are transparency, minimization, security, control, and respect. This policy applies to all Platform users—browsers, registered users, purchasers, and individuals contacting support. It describes our data practices, usage, disclosures, storage, and safeguarding measures.
2. Scope and Applicability
The policy covers anyone interacting with the Platform. Third-party links or services are not governed by this policy; review their privacy statements separately. LensiQ may update this policy at any time, with material changes communicated by email, in-app alerts, or prominent notices. Continued use indicates acceptance of updates.
3. Information We Collect
3.1 Information You Provide Directly
- Account Registration: Phone number (primary identifier), OTP validation (not stored after verification), full name, and email.
- Address Information: Street address, area, landmarks, delivery notes, contact person details, and optional GPS coordinates.
- Eye Prescription Data: Sphere, cylinder, axis, doctor notes, and special requirements when voluntarily stored.
- Payment Information: Preferred method (COD, eSewa, Khalti), transaction references, payment confirmations, billing address. We do not store card or bank numbers.
- Shopping & Browsing: Products viewed, added to cart, purchased, search terms, filters used.
3.2 Information Collected Automatically
- Device type, operating system, unique identifiers, network information, language, and time zone.
- Usage analytics: pages visited, time spent, interactions, clicks, navigation paths, error logs, timestamps.
- Location data (with permission): GPS, WiFi, cell tower data, delivery addresses.
- IP address, ISP, network type, connection timestamps.
- Cookies, session identifiers, analytics tags, and device fingerprinting for security and personalization.
3.3 Information from Payment Gateways
eSewa and Khalti share transaction reference numbers, payment statuses, timestamps, amounts, and wallet identifiers. Sensitive banking details remain with the gateways.
3.4 Information from Delivery Partners
Couriers provide delivery confirmations, timestamps, recipient acknowledgments, optional photos, and delivery notes.
4. Information We Do Not Collect
Browsing without an account does not require personal details. LensiQ intentionally avoids collecting health information beyond voluntary prescriptions, biometric or genetic data, religious or political beliefs, sexual orientation, financial account numbers, government IDs, or precise real-time location without consent.
5. How We Use Your Information
- Order Fulfillment: Process, confirm, package, deliver, and manage returns or refunds.
- Account Management: Create and maintain accounts, verify identity via OTP, handle preferences, prevent fraud.
- Communications: Send order updates, delivery alerts, payment confirmations, support responses, platform updates.
- Payments: Process transactions, prevent fraud, issue invoices, manage refunds.
- Customer Support: Resolve inquiries, troubleshoot issues, follow up on concerns.
- Platform Improvement: Analyze usage patterns to enhance features, performance, and reliability.
- Security: Detect suspicious activity, enforce policies, comply with legal obligations.
- Recommendations: Offer personalized products and promotions (opt-out available).
- Legal Compliance: Meet regulatory requirements, respond to authorities, prevent illegal activities.
- Prescription Fulfillment: Manufacture lenses per saved prescriptions, ensure quality, handle related support.
6. Sharing and Disclosure of Information
LensiQ does not sell or rent personal data to third parties and does not share it with marketers, data brokers, advertising networks, social media platforms, analytics companies for independent use, financial institutions (beyond payment processing), insurance companies, healthcare providers, employers, or recruiters.
Limited sharing occurs only with internal teams, delivery partners (name, phone, address, instructions), payment gateways (transaction details), and law enforcement when legally required. All partners are bound by confidentiality agreements. During mergers or acquisitions, any successor must honor this policy and provide notice.
7. Data Security and Protection
We deploy AES-256 encryption at rest, SSL/TLS 1.2+ in transit, firewalls, intrusion detection, DDoS mitigation, secure VPN access, network segmentation, secure storage, and redundant backups. Access is role-based with multi-factor authentication, audit logs, and least-privilege principles.
Security practices include quarterly internal reviews, annual third-party audits, vulnerability assessments, penetration tests, employee training, confidentiality agreements, and incident response drills. While no system is infallible, users should maintain strong passwords, avoid sharing credentials, use secure networks, and report suspicious activity promptly.
8. Data Retention and Deletion
LensiQ retains data only as long as necessary:
- Active account data for the account lifespan plus 30 days post deletion.
- Transactions and payment records for 7 years (legal compliance).
- Marketing preferences for the relationship duration plus 12 months.
- Analytics data for 12–24 months.
- Support records for 2 years after resolution.
- Fraud investigations for the investigation duration plus 3 years.
Account deletion requests can be made via settings, email, phone, or in-app support. Credentials, addresses, prescriptions, preferences, and settings are deleted within 24 hours; personal data within 30 days. Order histories, payment records, legal documents, or anonymized analytics may be retained as required. You will receive confirmation once deletion is complete.
9. Your Privacy Rights and Choices
- Access: Request data copies via contact@lensiq.app (response within 15 business days).
- Correction: Update inaccurate data via account settings or support.
- Portability: Receive data in CSV/JSON/XML within 30 days upon request.
- Deletion: Request erasure subject to legal obligations.
- Opt-Out: Disable marketing emails/SMS, push notifications, personalization, location tracking, or cookies.
- Restriction/Objection: Limit processing or object to automated decisions; request human review when decisions significantly affect you.
10. Information Specific to Health Data
Eye prescription data receives heightened protection: stored in encrypted, segregated databases with limited access and audit trails. It is used only for lens manufacturing, verification, and support—not shared with healthcare providers, insurers, or advertisers. Users may delete or update prescriptions anytime and request access logs. LensiQ is not liable for issues stemming from inaccurate or outdated prescriptions provided by users.
11. Cookies and Similar Technologies
Cookies enable session management, preferences, performance analysis, and limited marketing. Types include essential, performance, preference, and marketing cookies. Manage cookies via browser settings (Chrome, Safari, Firefox, Edge) or use private browsing. LensiQ respects “Do Not Track” signals by limiting non-essential tracking.
Additional tracking includes web beacons, log files, device fingerprinting, and analytics tools, all used for legitimate service improvements and security.
12. Location Information and Geolocation
Location data supports service availability checks, delivery estimates, local offers, checkout autofill, and customer support. Collection methods include GPS, cell towers, WiFi, and IP geolocation. Data is encrypted, retained for a maximum of 90 days, and never shared with marketers. You may disable location services anytime, though certain features may be limited.
13. Children’s Privacy
The Platform is intended for users 18+. We do not knowingly collect data from minors. Parents/guardians may request deletion if information was inadvertently collected.
14. International Data Transfers
Data is primarily stored in Nepal or South Asia. When transferred elsewhere (e.g., cloud backups), LensiQ ensures equivalent protection through data protection agreements, standard contractual clauses, and user consent where required.
15. Newsletter and Marketing Communications
Marketing emails/SMS require explicit opt-in (double opt-in for email). Content includes promotions, new arrivals, and exclusive offers, sent at respectful frequencies. Opt-out anytime via unsubscribe links, replying “STOP,” or updating preferences in Account Settings. Transactional messages (order updates, security alerts) continue regardless of marketing preferences.
16. Security Incident Notification
In the event of a data breach, LensiQ will investigate, contain, notify affected users within 30 days (where possible), and inform relevant authorities. Notifications include breach nature, impacted data, mitigation steps, and recommended user actions. We comply with Nepali reporting requirements and cooperate with law enforcement.
17. Third-Party Links and Services
External links (websites, payment gateways) operate under their own privacy policies. LensiQ is not responsible for their data practices. Review third-party policies before sharing information. Integrated services such as eSewa, Khalti, courier partners, analytics providers, and cloud platforms are contractually bound to protect your data.
18. Your Privacy Responsibilities
You must provide accurate information, keep account details updated, safeguard credentials, verify prescriptions, and ensure location/address details are correct. Report errors or unauthorized activity immediately.
19. Legal Basis for Data Processing
LensiQ processes data under various legal bases: contract performance (order fulfillment, account services), legal obligation (tax, regulatory compliance), legitimate interests (security, analytics, support), and consent (marketing, personalization, certain data collection). Your rights vary depending on the legal basis, including access, deletion, restriction, and objection.
20. Automated Decision-Making
Automated systems support fraud detection, product recommendations, delivery routing, spam detection, and order verification. You may request human review for significant automated decisions and opt for manual processing where feasible.
21. Compliance with Regulations
LensiQ aligns with Nepali Consumer Protection, Data Protection, E-commerce, Digital Transaction, Tax, and Labor laws, as well as international best practices (e.g., GDPR principles, ISO 27001). We also comply with Google Play and Apple App Store privacy requirements.
22. Contact Us for Privacy Matters
Privacy questions or concerns? Contact:
- 📧 Email: contact@lensiq.app (Subject: “Privacy Policy Inquiry”)
- 📞 Phone: +977 9814781036 (business hours)
- 📍 Mailing: LensiQ Pvt Ltd, Kathmandu, Nepal
- In-App Support: Accessible via the app for immediate assistance
A designated Privacy Officer oversees compliance and responses within five business days.
23. Policy Updates and Notifications
LensiQ may update this policy; significant changes trigger email and in-app notifications at least 30 days in advance when possible. The effective date and summary of changes are provided. Continued use implies acceptance; discontinue use or request deletion if you disagree.
24. Glossary of Terms
Key terms: Cookie, Data Breach, Encryption, GDPR, IP Address, OTP, Personal Information, Processing, SSL/TLS, Third Party, Tokenization. Refer to the policy text for definitions.
25. Entire Privacy Policy Agreement
This Privacy Policy, alongside LensiQ’s Terms and Conditions, constitutes the entire agreement regarding privacy practices. If any provision is invalid, remaining provisions remain effective.
26. Contact Information Summary
LensiQ Pvt Ltd • 📞 +977 9814781036 • 📧 contact@lensiq.app • 📍 Kathmandu, Nepal
27. Acknowledgment
By using the LensiQ Platform, you acknowledge that you have read and understood this Privacy Policy, consent to the practices described, and know how to exercise your rights. © 2025 LensiQ Pvt Ltd. All Rights Reserved. Your privacy is our priority.