E-Commerce Privacy Policy Framework (CTDPA 2023-2025 Standards)
Last Updated: February 1, 2025
1. Introduction and Scope of Applicability
This Privacy Policy Framework is established to ensure our operations as a Controller comply with the Connecticut Data Privacy Act (CTDPA), codified at Conn. Gen. Stat. § 42-515 et seq., including the 2025 legislative amendments. This policy applies to all Connecticut residents ("Consumers") whose data is processed by this business.
Pursuant to the 2025 enforcement standards, this business acknowledges its Controller status based on meeting the updated applicability thresholds: (i) processing the personal data of at least 35,000 Connecticut residents; or (ii) the processing of any sensitive data or the sale of any personal data. This policy covers all personal data collected, used, or sold across our e-commerce platform, mobile applications, and offline touchpoints.
2. Data Processing Transparency Matrix
The following matrix provides a comprehensive disclosure of our processing activities. Under the 2025 "Right to Know" standards, Consumers have the absolute right to obtain a list of the specific third-party entities to whom their data is sold.
| Category of Personal Data | Specific Purpose of Processing | Categories of Third Parties Shared With | Specific Third-Party Recipients (Sold Data)¹ |
| Identifiers (Name, IP, Email) | Order fulfillment, legal compliance, and account security. | Cloud service providers, payment processors, logistics partners. | [List specific legal names of all entities to whom data is sold] |
| Commercial Information (Purchase History) | Inventory management and personalized customer support. | Data analytics firms, CRM providers. | [List specific legal names of all entities to whom data is sold] |
| Internet/Network Activity | Website optimization and cross-contextual advertising. | Advertising networks, social media platforms. | [List specific legal names of all entities to whom data is sold] |
| Inferences (Derived Profiles) | Predicting shopping preferences and consumer behavior. | Marketing and profiling partners, AI service providers. | [List specific legal names of all entities to whom data is sold] |
| Sensitive Data (See Section 3) | Identity verification and delivery of specialized services. | Verified security providers, health/wellness partners. | [List specific legal names of all entities to whom data is sold] |
| Inferences (Derived Profiles) | Predicting shopping preferences and consumer behavior. | Marketing and profiling partners, AI service providers. | [List specific legal names of all entities to whom data is sold] |
| Sensitive Data (See Section 3) | Identity verification and delivery of specialized services. | Verified security providers, health/wellness partners. | [List specific legal names of all entities to whom data is sold] |
¹ Note: Per Conn. Gen. Stat. § 42-515, residents may access the specific names of third parties receiving data through a "Sale." Inferences derived from any category above are also subject to the Right to Access.
3. Sensitive Data & Explicit Opt-In Consent
We implement a "Privacy by Design" approach for sensitive data, including the expanded 2025 categories. We define Biometric Data as any data generated by automatic measurements of biological characteristics capable of being linked to a consumer, regardless of whether it is currently used for identification.
Protected Categories include:
- Consumer health data, genetic data, and neural data.
- Biometric data (capable of identification).
- Precise geolocation data (within a radius of 1,750 feet).
- Disability or medical treatment status.
- Status as non-binary or transgender.
- Specific financial or government identifier information.
Opt-In Consent Clause: We will not process any sensitive data category without a "clear affirmative act" signifying a freely given, specific, informed, and unambiguous agreement.
Rigorous Standard: Consent cannot be obtained through broad "Terms of Use" acceptance, silence, or deceptive "dark patterns." We maintain a mechanism to revoke consent that is at least as easy as the mechanism used to provide it. In the event of a corporate succession or bankruptcy, all sensitive data (specifically genetic and health data) remains protected under these consent terms and cannot be transferred without renewed affirmative agreement.
4. Heightened Protections for Minors (Under 18)
In accordance with Public Act 23-56 and 2025 updates, we apply absolute prohibitions to the data of Consumers known to be under 18 years of age. These are non-waivable bans, not opt-out rights.
- Prohibition on Sales and Targeted Advertising: We do not process the personal data of a minor for targeted advertising or the sale of personal data under any circumstances.
- Addictive Design Ban: We strictly prohibit system design features intended to significantly increase, sustain, or extend a minor’s time online (e.g., autoplay features or infinite scrolls without friction).
- Geolocation Limitations: We do not collect precise geolocation from minors unless "strictly necessary"—defined as essential for the core functionality of the specific service requested by the minor.
- Data Protection Assessments (DPAs): We conduct detailed DPAs for any feature offered to minors prior to launch. These DPAs analyze risks of physical, material, or developmental harm and are provided to the Office of the Attorney General (OAG) upon request.
5. Consumer Rights & Exercise Mechanisms
Connecticut residents may exercise the following rights under Conn. Gen. Stat. § 42-518:
- Right to Access: Confirm processing and access all data held, including all inferences derived from your profile.
- Right to Correction: Correct inaccuracies in personal data.
- Right to Deletion: Request deletion of data provided by or obtained about you through our "One-Stop-Shop" deletion tool.
- Right to Portability: Obtain a copy of your data in a portable, usable format.
- Right to Appeal: Contest our refusal to act on a request within the statutory timeline.
Defensibility Notice: We do not charge fees for these requests. We do not limit the Right to Access to only the last 12 months of data; we provide access to the full duration of the data retention period.
To exercise these rights: [Link to One-Stop-Shop Deletion/Rights Tool] or email [Staffed Privacy Email].
6. Opt-Out Rights and Universal Preference Signals
Consumers have the right to opt-out of the processing of their data for Targeted Advertising, Sales, and Profiling.
Universal Opt-Out Preference Signals (GPC): Our platform automatically honors Global Privacy Control (GPC) signals as a valid request to opt-out of sales and targeted advertising across all devices and mobile applications associated with a consumer's account.
Symmetrical Choice & Visual Disclosure: To avoid "Dark Patterns," our cookie banners adhere to the OAG’s "Symmetrical Choice" framework:
- The "Reject All" option is as prominent and identically formatted (size, contrast, color) as "Accept All."
- Unavoidable Disclosure: Disclosures are placed "above the fold" to ensure they are seen without scrolling.
- No Litmus Test: Privacy choices are easy, obvious, and not buried in footer links.
7. Profiling, Automated Decision-Making, and AI
We maintain a transparency-first policy regarding artificial intelligence and automated processing.
- AI/LLM Disclosure: We explicitly disclose that personal data is [OR IS NOT] used to train Large Language Models (LLMs) or other generative AI systems.
- Right to Contest: Consumers have the right to contest the results of any automated processing (not limited to "solely" automated) that produces legal or similarly significant effects.
- Impact Assessments: We conduct and document impact assessments for all profiling activities, focusing on the prevention of unlawful discrimination.
8. Staffed Privacy Contact and Response Mechanism
To avoid the "dead-end" communications criticized in OAG enforcement reports, we provide a dedicated, human-monitored channel:
- Privacy Email: babylayette@luminogroup.shop
- Response Commitment: This inbox is reviewed daily by our compliance team. We maintain a log of response times and "unresponsive" rates, which is audited quarterly to ensure we meet the 45-day statutory response window.
9. Enforcement and Appeals Process
If a request is denied, we will provide a specific justification and instructions for appeal.
- Internal Appeal: We will respond to your appeal within 60 days of receipt.
- OAG Recourse: If the internal appeal is denied, you have the right to contact the Connecticut Office of the Attorney General at [Link to OAG Complaint Portal] or via their official website (portal.ct.gov/AG).










