Data & Privacy
Data & Privacy Policy
Dilmah Ceylon Tea Company PLC — shop.dilmahtea.com
Combines: Privacy & Cookie Policy + Security Page
1. Introduction & Who We Are
This Data & Privacy Policy explains how Dilmah Ceylon Tea Company PLC ("Dilmah", "we", "us", or "our"), incorporated in Sri Lanka, collects, uses, stores, protects, and shares personal information when you visit or make a purchase through shop.dilmahtea.com (the "Site").
We are committed to protecting your privacy and handling your personal data in an open, transparent, and lawful manner. This policy also covers the security measures we apply to protect your data and payment information.
This policy applies only to this Site. Third-party websites linked from this Site have their own privacy policies, which we do not control.
By using the Site, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please do not use the Site.
2. What Data We Collect
2.1 Data You Provide Directly
- Full name
- Billing and shipping addresses
- Email address
- Phone number (including for SMS marketing, with consent)
- Payment details (entered directly on our payment gateway — not stored by Dilmah)
- Account login credentials
- Reviews, comments, and user-submitted content
- Special order requests and communication preferences
2.2 Data We Collect Automatically
- Browser type, operating system, and device information
- IP address (anonymised where required — see Section 7)
- Pages visited, time spent, and navigation paths
- Referring website or search query
- Cookie identifiers and tracking data (see Section 7)
2.3 Data from Third Parties
- Analytics and advertising data from platforms such as Google, Facebook, LinkedIn, Microsoft, and Tiktok
3. Legal Basis for Processing
| Processing Activity | Lawful Basis | Details |
|---|---|---|
| Order fulfilment | Contract performance | Necessary to process and deliver your order |
| Account management | Contract performance | Necessary to provide and manage your account |
| Email marketing | Consent | You opt in at registration or checkout |
| SMS marketing | Consent | You explicitly provide your phone number and opt in |
| Analytics | Legitimate interest | Improve site usage |
| Advertising | Consent | Via cookie consent |
| Fraud prevention | Legal obligation | Compliance and protection |
4. How We Use Your Data
- Process and fulfil orders
- Manage your account
- Send confirmations and updates
- Send marketing (if opted in)
- Send SMS marketing (if consented)
- Personalise your experience
- Improve the Site
- Display targeted ads (with consent)
- Comply with legal obligations
- Respond to enquiries
We do not sell your personal data.
5. SMS Marketing Consent
By providing your mobile number and opting in, you consent to receive marketing SMS messages.
Opt-out methods:
- Reply STOP to any SMS
- Email: orders@dilmahtea.com
6. Data Sharing & Third Parties
- Service providers (Shopify, couriers, payment processors)
- Analytics and advertising partners
- Business transfers
- Legal obligations
7. Cookies & Tracking Technologies
Cookies are small text files used to improve your experience.
Necessary Cookies
- _secure_session_id
- cart
- checkout
- secure_customer_sig
- _shopify_country
- _tracking_consent
Analytics Cookies
- _landing_page
- _orig_referrer
- _shopify_y
8. Data Retention
| Data Category | Retention |
|---|---|
| Orders | 7 years |
| Account | Duration + 2 years |
| Marketing | Until withdrawn |
| Analytics | Up to 26 months |
9. Your Data Rights
- Access your data
- Correct data
- Delete data
- Withdraw consent
- Lodge complaints
10. International Data Transfers
Your data may be processed outside your country with appropriate safeguards.
11. Data Breach Response
- Assess breach
- Notify authorities within 72 hours if required
- Notify affected individuals
12. Payment Security
- TLS encryption
- No card storage
- PCI-DSS compliant
- 3D Secure authentication
13. Children's Privacy
We do not knowingly collect data from individuals under 16.
14. Third-Party Links
We are not responsible for external websites.
15. Contact Details
Email: orders@dilmahtea.com
Address: No. 111, Negombo Road, Peliyagoda, Sri Lanka
16. Changes to This Policy
We may update this policy periodically.
Dilmah Ceylon Tea Company PLC