Privacy policy
Privacy Policy
Home Light Therapy (lighttherapy.no) — Last updated: April 2026
I run Home Light Therapy as a one-man operation from Drammen. I am not a data broker, I do not sell your information, and I collect only what I genuinely need to run this store and communicate with customers. This policy explains what I collect, why, and what your rights are under Norwegian and EU law (GDPR).
Who We Are
Home Light Therapy is a sole trader operating from Drammen, Norway. We are the data controller for all personal information collected through this website.
Business name: Home Light Therapy Org. nr: 920 058 055 MVA Address: Kjøpmann Fjeldheims vei 2, Drammen, 3023, Norway Email: admin@lighttherapy.no Phone: +47 951 47 478 (text only) Founded: 2017
What Information We Collect
Depending on how you interact with the store, we may collect the following:
- Contact details — name, email address, phone number, billing and shipping address
- Order and transaction information — what you bought, payment confirmation, order history
- Account information — if you create an account, your login credentials and preferences
- Communications — the content of any messages you send us via email or contact forms
- Device and usage data — IP address, browser type, pages visited, and how you navigate the site. This is collected automatically via cookies and analytics tools.
We do not collect sensitive personal data such as health records, and we do not knowingly collect data from children under 18.
Why We Collect It
We use your personal information for the following purposes:
- To process and fulfill your orders, including arranging shipping and handling returns
- To communicate with you about your order, account, or any questions you raise
- To send you marketing emails, if you have opted in — you can unsubscribe at any time
- To understand how people use the store so we can improve it
- To detect and prevent fraud and keep transactions secure
- To comply with our legal obligations under Norwegian and EU law
Our legal basis for processing is either the performance of a contract (your order), your consent (marketing emails, analytics cookies), or our legitimate interests (fraud prevention, store security).
Tools and Services We Use
Running this store means working with a small number of trusted third-party services.
Shopify — our store platform. Processes orders, payments, and stores customer data. Shopify is GDPR-compliant and processes data under Standard Contractual Clauses.
Google Analytics 4 — website analytics. Tracks page visits and user behaviour in anonymised form. Only fires after you give cookie consent. Data is processed by Google Ireland Ltd.
Shopify Payments and payment processors — secure payment processing. We do not store your full card details — these are handled directly by the payment processor.
Email marketing — if you subscribe to our newsletter, your email is stored securely. You can unsubscribe at any time via the link in any email we send.
Cookies
This site uses cookies. Some are strictly necessary for the store to function — cart, checkout, and session management. Others, including analytics cookies, are optional and only placed after you give consent via the cookie banner.
You can change or withdraw your consent at any time by clearing your cookies and revisiting the site, or by contacting us directly.
Who We Share Your Data With
We do not sell your personal information. We do not share it with advertisers or data brokers. We share it only in the following circumstances:
- With Shopify, to operate the store and process transactions
- With shipping carriers, to deliver your order
- With payment processors, to complete your purchase securely
- With Google, for anonymised analytics data — only with your consent
- If required by law or a valid legal request from Norwegian or EU authorities
International Transfers
Some services we use — including Shopify and Google — store and process data outside Norway and the EEA. Where this happens it is covered by the European Commission's Standard Contractual Clauses, ensuring your data is protected to EEA standards.
How Long We Keep Your Data
We keep your personal information for as long as necessary to provide the services you requested, or as required by Norwegian law. Financial and accounting records are kept for five years as required by the Norwegian Bookkeeping Act (bokføringsloven). When data is no longer needed it is deleted or anonymised.
Your Rights
Under GDPR and Norwegian data protection law you have the following rights:
- Right of access — you can ask what data we hold about you
- Right to correction — you can ask us to correct inaccurate data
- Right to deletion — you can ask us to delete your data, subject to legal retention requirements
- Right to portability — you can ask for a copy of your data in a portable format
- Right to object — you can object to processing based on legitimate interests, including direct marketing
- Right to withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing
- Right to restrict processing — you can ask us to pause processing in certain circumstances
To exercise any of these rights, contact us at admin@lighttherapy.no. We will respond within 30 days.
You also have the right to lodge a complaint with the Norwegian data protection authority: Datatilsynet — datatilsynet.no
Changes to This Policy
If we make significant changes we will update the date at the top of this page and, where appropriate, notify customers by email.
Contact
Any questions about this policy or how your data is handled — get in touch directly.
Home Light Therapy Dominic Lamb, Founder Kjøpmann Fjeldheims vei 2, Drammen, 3023, Norway Org. nr: 920 058 055 MVA Email: admin@lighttherapy.no Phone: +47 951 47 478 (text only)