3. Privacy Policy
Novera Luxe Inc. (“Novéra,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit noveraskincare.com (the “Site”), use our skin analysis tool (NISA), or make a purchase from us.
This policy is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) where applicable, and to reflect recognized privacy principles that apply to customers in other jurisdictions who access our Site.
3.1 Information We Collect
Information you provide to us
- Contact information: name, email address, postal address, phone number.
- Transaction information: purchases, order history, billing address, and payment card information (processed by our payment processor; we do not store full card numbers on our systems).
- Account information: if you create an account, the login credentials and preferences associated with it.
- Communications: messages you send us through email, web forms, phone calls, or social channels.
- Marketing preferences: your consent status for marketing emails and the preferences you select.
Information collected automatically
- Device and usage data: IP address, browser type, operating system, device identifiers, referring URLs, pages viewed, time spent on pages, and similar analytics data.
- Cookies and similar technologies: used to operate the Site, remember your preferences, analyze performance, and deliver relevant advertising. See Section 3.6 below.
- Location information: approximate location derived from your IP address for analytics and tax calculation.
NISA skin analysis tool
NISA is our AI-assisted skin analysis tool accessible through the Site. When you use NISA, the tool may process a facial image or other skin-related input that you provide.
Important: facial images submitted to NISA are processed transiently to generate your analysis results. Images are not stored on Novéra servers after analysis is complete, are not used for training machine learning models, and are not shared with third parties. Only the anonymized analysis results may be retained in aggregated form to improve the tool.
If our data handling for NISA changes in any way, we will update this Privacy Policy before the change takes effect and notify users who have previously used NISA where reasonably practicable.
3.2 How We Use Your Information
We use your information for the following purposes:
- To process and fulfill your orders, including payment processing, shipping, and customer support.
- To communicate with you about your order, account, or inquiries (transactional communications).
- To send marketing emails about new products, launches, and offers — only if you have given valid consent as described in Section 3.4.
- To operate, maintain, improve, and secure the Site and our services.
- To analyze customer behavior, measure advertising performance, and understand which of our products and content are of interest.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations, including tax, accounting, and consumer protection requirements.
3.3 Legal Basis for Processing
Depending on the context, we process your personal information based on:
- The performance of a contract with you (for example, fulfilling your order).
- Your consent (for example, for marketing emails or optional cookies).
- Our legitimate interests (for example, operating and improving our business, preventing fraud).
- Legal obligations imposed on us.
3.4 Marketing Communications and CASL Compliance
Novéra complies with Canada's Anti-Spam Legislation (CASL). We send commercial electronic messages (including marketing emails) only to individuals who have provided consent.
Consent is obtained through an opt-in checkbox at checkout or on our Site. The checkbox is not pre-selected; you must actively select it to consent. You may also have given consent through a separate newsletter signup form.
Every marketing email we send includes:
- Our identification as the sender.
- Our physical mailing address.
- A clear and functional unsubscribe link that takes effect within 10 business days of your request, at no cost to you.
You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by emailing support@noveraskincare.com with the subject “Unsubscribe.”
3.5 How We Share Your Information
We do not sell your personal information. We share information with service providers who help us operate our business, and only to the extent necessary for them to perform services on our behalf. These include:
- Shopify Inc. — e-commerce platform, order processing, payment processing (Shopify Payments), and store analytics.
- Brevo (formerly Sendinblue) — transactional email delivery.
- Mailchimp or similar — marketing email delivery (if used).
- Google LLC — website analytics (Google Analytics).
- Meta Platforms, Inc. — advertising pixel (Meta/Facebook Pixel) for measurement and retargeting.
- TikTok — advertising pixel for measurement and retargeting. You may choose to opt out of interest-based advertising via your browser or device settings, and through the pixel providers' own opt-out mechanisms.
- Shipping carriers — to deliver your orders (Canada Post, Purolator, UPS, FedEx, and others, depending on destination).
- Microsoft Azure — cloud infrastructure hosting the NISA skin analysis tool.
- Professional advisors — such as lawyers, accountants, and auditors, where required.
We also disclose information where required by law, legal process, or to protect the rights, property, or safety of Novéra, our customers, or others.
In the event of a merger, acquisition, financing, reorganization, or sale of assets, customer information may be transferred as part of that transaction, subject to standard confidentiality protections.
3.6 Cookies and Tracking Technologies
Our Site uses cookies and similar technologies to operate the Site, remember your preferences, measure performance, and deliver advertising.
Categories of cookies we use:
- Strictly necessary cookies: required for core functionality such as cart, checkout, and security.
- Analytics cookies: help us understand how visitors use the Site (for example, Google Analytics).
- Advertising cookies: used by Meta and TikTok pixels to measure ad performance and deliver relevant advertising.
You may control cookies through your browser settings. Blocking strictly necessary cookies may affect Site functionality. Where required by law, we request consent before setting non-essential cookies.
3.7 Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. Typical retention periods:
- Order and transaction records: seven (7) years for tax and accounting purposes, as required by the Canada Revenue Agency.
- Marketing contact information: until you unsubscribe or request deletion.
- Customer support correspondence: up to three (3) years after resolution.
- Analytics data: typically fourteen (14) to twenty-six (26) months, depending on the analytics tool.
- Facial images processed by NISA: not retained (see Section 3.1).
3.8 Your Rights
Rights of Canadian residents
Under PIPEDA and applicable provincial privacy laws, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Withdraw consent for specific uses (subject to legal and contractual restrictions).
- File a complaint with the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.
Rights of California residents
If you are a California resident, the CCPA and CPRA provide you with additional rights:
- The right to know what personal information we collect, use, disclose, or sell about you.
- The right to delete personal information we have collected from you, subject to legal exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. Novéra does not sell personal information in the traditional sense; however, certain advertising pixel activity may qualify as “sharing” under California law. You may opt out by emailing us at support@noveraskincare.com with “Do Not Sell or Share” in the subject line, or by using the opt-out link in the footer of our Site.
- The right to limit the use of sensitive personal information.
- The right to non-discrimination for exercising these rights.
Rights of residents of other jurisdictions
We recognize that privacy laws in other jurisdictions (including the European Economic Area and the United Kingdom under the GDPR and UK GDPR) may grant you additional rights, such as the right to data portability and the right to object to certain processing. We will honor such rights to the extent they apply to you and we are able to verify your identity.
How to exercise your rights
To exercise any of these rights, email support@noveraskincare.com. We will respond within thirty (30) days of receiving a verified request. We may need to verify your identity before processing the request.
3.9 Security
We use commercially reasonable administrative, technical, and physical safeguards to protect personal information. Payment processing is handled by PCI-DSS compliant providers. We use HTTPS/TLS encryption on our Site. However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
If we become aware of a data breach affecting your personal information, we will notify you as required by applicable law.
3.10 Children's Privacy
Our Site and products are not directed to children under the age of majority in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
3.11 International Data Transfers
Some of our service providers are located outside Canada, including in the United States and other jurisdictions. When your personal information is transferred internationally, we take reasonable steps to ensure it receives an adequate level of protection, consistent with Canadian privacy principles.
3.12 Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this policy indicates when it was last revised. Material changes will be communicated by email (to customers whose email we have on file) or by prominent notice on the Site before the change takes effect.
3.13 Contact Us
Privacy inquiries:
Novera Luxe Inc. — Privacy Officer
2285 Dunwin Drive, Unit 12, Mississauga, Ontario L5L 3S3, Canada
Email: support@noveraskincare.com
Phone: +1 800-721-2636