Privacy Policy
How Casila collects, uses, protects and shares data across retail and flower-trade services.
01
Who is responsible for your data
CASILA FLOWER LIMITED operates Casila and controls the personal data described in this policy. Privacy questions and rights requests may be sent to [email protected].
02
Data we collect
We collect information you provide, including your name, email address, phone number, password hash, delivery address, order notes, account consents, product selections and order history. We do not store bank-account credentials or card details on this website.
We may also receive technical information such as browser type, device type, IP address, pages viewed and security logs when the site is hosted with standard web infrastructure.
03
How we use data
We use personal data to create and secure accounts; price, confirm and fulfil orders; arrange cross-border shipping and customs documentation; handle flower-care, returns and support; detect fraud; comply with law; and improve the website.
Where you explicitly tick the SMS consent box, we may send order, delivery and occasional promotional text messages. You may withdraw promotional SMS consent by contacting support or following an opt-out instruction. Transactional messages needed to fulfil an open order may still be sent where permitted.
04
Legal grounds
Depending on where you live, we process data to perform a contract with you, take steps before entering a contract, comply with legal obligations, pursue legitimate interests such as security and service improvement, or act on your consent.
05
When data is shared
We may share only the data needed with hosting and security providers, carriers, customs and import agents, payment and banking partners, flower growers, workshops, event installers and professional advisers. We do not sell personal data.
06
International transfers
Casila conducts cross-border trade. Your data may be processed in Hong Kong and in delivery, production or service-provider locations outside your home country. We use contractual and operational safeguards appropriate to the transfer where required.
07
Storage and security
Account passwords are stored using a one-way salted password derivation function. Sessions use secure, HTTP-only cookies in production. We restrict data access and use reasonable technical and organisational safeguards, but no internet service can guarantee absolute security.
08
Retention
We retain account data while an account remains active, order records for the periods required by tax, customs, accounting and consumer law, and support correspondence as needed to resolve a matter. Data is deleted or de-identified when it is no longer reasonably required.
09
Your choices and rights
You may ask to access, correct or delete personal data, object to or restrict certain processing, withdraw consent, or request a portable copy where applicable. We may need to verify your identity and may retain data where law requires it.
10
Cookies
The site uses an essential session cookie when you sign in and browser storage to keep your shopping bag on your device. These are needed for account and shopping functions. We do not currently use third-party advertising cookies.
11
Policy changes
We may update this policy when our services or legal obligations change. The date at the top identifies the current version. Material changes will be communicated through the website or available account contact details where appropriate.