Privacy policy

Last updated: 12 June 2026

Who I am

Lumen Maris is a handmade devotional rosary brand based in Dublin, Ireland. When you buy a rosary, sign up to my list, or get in touch, I'm the one responsible for protecting your data (Patrizia, founder of Lumen Maris). You take a moment to trust me with your address, your email, your name. I take looking after them just as seriously.

Data controller:
Lumen Maris
Owner: Patrizia Gonzalez
Sky Business Centres
57 Clontarf Road
Clontarf West
Dublin 3
D03 A7P0

Email: contact@lumenmaris.com
Sole Trader (Ireland)

What data I collect and why

When you buy a rosary from me

  • Full name
  • Shipping and billing address
  • Email address and phone number
  • Payment information (processed by our payment providers; we don't store card numbers)
  • Messages you send us by email or the contact form

Special data for spiritual services, courses and retreats:

When you book a spiritual consultation, a course or a retreat, we may ask for extra information needed for the activity: allergies, relevant medical conditions (pregnancy, injuries, ongoing treatments), dietary preferences. This data counts as "sensitive data" under GDPR and is handled with extra care: it's only used for that specific activity, kept separate from commercial data, and deleted once the activity is over, unless we're legally required to keep it.

Data we collect automatically:

  • Device and browser information (IP address, device type, operating system)
  • Pages visited, time spent on each page, traffic source
  • Cookies and similar technologies (see section 7)

3. Legal basis and purpose of processing

We process your data on the following legal bases:

  • Performance of a contract: to process orders, manage shipping, and deliver courses and services you've booked.
  • Consent: to send you marketing communications and the newsletter (always with explicit opt-in and the option to unsubscribe at any time).
  • Legitimate interest: for basic analytics, service improvement and fraud prevention.
  • Legal obligation: to keep invoices and tax records under Irish law.
  • Explicit consent (sensitive data): for the health data you give us for services and retreats.

4. Sharing data with third parties

We work with the following service providers, who may have access to some of your data in order to do their job:

  • Shopify Inc.: e-commerce platform and order processing (servers in Canada / Ireland).
  • Shopify Payments / Stripe: payment processing.
  • An Post: shipping.
  • MailerLite: email marketing (servers in Lithuania, EU).
  • Google Analytics: anonymised web analytics.
  • Pinterest, Meta: advertising tracking pixels (only if you consent to marketing cookies).

All our providers comply with GDPR or, in the case of transfers outside the EU, do so under Standard Contractual Clauses approved by the European Commission.

5. International transfers

Some of our providers may process data outside the European Economic Area (mainly the United States and Canada). In those cases, we make sure legal protection mechanisms equivalent to GDPR are in place, mainly through the European Commission's Standard Contractual Clauses.

If you place an order from outside the EU (United States, UK, Mexico, Argentina or others), your personal data will travel to your country of residence for shipping and order management purposes.

6. Retention period

  • Customer and order data: 6 years from the last transaction (Irish tax obligation).
  • Marketing data (newsletter subscription): until you unsubscribe.
  • Sensitive data from services and retreats: deleted once the activity ends, unless we're legally required to keep it.
  • Browsing and analytics data: between 14 and 26 months, depending on the provider's settings.

7. Cookies

We use technical cookies (necessary for the website and shopping cart to work) and, with your consent, analytics and marketing cookies. You can manage your cookie preferences at any time from the banner that appears when you visit the site.

8. Your rights

Under GDPR, you have the following rights over your data:

  • Access: to know what data we hold about you.
  • Rectification: to correct inaccurate data.
  • Erasure: to ask us to delete your data (the "right to be forgotten").
  • Restriction: to limit processing in certain circumstances.
  • Portability: to receive your data in a structured format.
  • Objection: to object to processing based on legitimate interest.
  • Withdraw consent: at any time, without affecting the lawfulness of processing carried out before that.

To exercise any of these rights, write to us at contact@lumenmaris.com. We'll get back to you within a maximum of 30 days.

If you feel we haven't respected your rights, you can lodge a complaint with the Data Protection Commission of Ireland (www.dataprotection.ie) or with the data protection authority in your country of residence.

9. Security

We apply reasonable technical and organisational measures to protect your data: SSL encryption across the whole site, restricted access, and providers with recognised security certifications. No system is 100% foolproof, but we do everything reasonably possible to protect you.

10. Changes to this policy

We may update this policy to reflect legal, technical or business changes. The date of the last update appears at the top. If there are significant changes, we'll let you know by email if you're subscribed.

By buying products or booking services from Lumen Maris, you accept these Terms and Conditions. Take your time to read them before placing your order.