Your bag

♡

Your bag is empty.

Add something from the shop.

Dimples monogram
Dimples
Lipcare
ShopRitualTrainingsContact
Book a training
Home›Privacy

Privacy policy

On this page

Last updated · February 14, 2026

In plain English: we hold the minimum data we need to run the shop. We never sell it, rarely share it, and we'll tell you the moment anything changes.

Who we are

Dimples Lipcare Ltd (“Dimples”, “we”, “us”) is a Nigerian limited company hand-pouring lipcare products from a small studio in Lagos. We're the data controller for everything you give us through this website, our Instagram and TikTok DMs, and the WhatsApp number printed on our packaging.

Our registered address is 42 Allen Avenue, Ikeja, Lagos. You can reach us at hello@dimples.co or on the phone numbers listed under Contact.

What we collect

We collect the smallest amount of data we can to actually run the shop. Specifically:

  • Account & order information — name, email, phone, shipping addresses, payment confirmation (we never see your card number — that lives with Paystack).
  • Things you tell us — replies to our emails, DMs, reviews, training applications, returns enquiries.
  • How you use the site — pages visited, products viewed, items added to bag. Used to improve the experience, not sold to anyone.
  • Marketing preferences — what you've opted in to (drops, journal, restocks), so we don't send things you didn't ask for.
What we don't collect

We don't ask for your date of birth. We don't track you across other websites. We don't sell, rent, or share your contact info with third parties.

Why we use it

Every piece of data we hold has a job. We use your information to:

  • Process your orders and send them to you.
  • Reply to your messages, returns, and training applications.
  • Send you emails you've actively opted in to (and nothing else).
  • Improve the website and the products themselves.
  • Comply with Nigerian accounting and consumer-protection law.

We don't make automated decisions that affect you legally. There's no scoring, no profiling, no advert-targeting beyond what you've explicitly opted into.

Your rights

Under the Nigerian Data Protection Act (NDPA) 2023, you have the right to:

  • Access — ask for a copy of everything we hold about you.
  • Correct — fix anything that's wrong.
  • Delete — ask us to remove your data (we keep order receipts for accounting; everything else goes).
  • Object — withdraw marketing consent at any time. There's a one-click unsubscribe in every email.
  • Port — receive your data in a usable format to take elsewhere.

To exercise any of these, email hello@dimples.co. We reply within seven working days.

Who else sees your data

A short list — every service we use, and why.

  • Paystack — processes your payment. We never see your card number.
  • GIG Logistics, Kwik — deliver your bag. They see only the address & phone.
  • Mailchimp — sends the journal & restock alerts. We export only your email.
  • Google Analytics — anonymous traffic stats. No personally-identifying data.

That's it. We don't share your data with anyone else, ever.

Cookies

We use a small number of cookies — none that track you between sites. Specifically:

  • Session — keeps you signed in.
  • Bag — remembers what's in your bag if you close the tab.
  • Preferences — your saved-for-later list, last-viewed products.
  • Analytics (anonymous) — Google Analytics, no personal identifier.

You can clear or block cookies in your browser at any time. Some features (sign in, bag persistence) won't work without them.

How long we keep things

We keep your data only as long as we need it.

  • Account & contact info — as long as your account is open. Deleted on request.
  • Order receipts — six years, as required for Nigerian tax accounting.
  • Marketing subscribers — until you unsubscribe.
  • Web analytics — 26 months, then aggregated.

How we keep it safe

We store data on servers managed by Vercel and Supabase, encrypted at rest and in transit. Only two people in the company have access to the customer database, and both use two-factor authentication. Payment data never touches our servers — Paystack handles every transaction.

If there's ever a breach, we'll email everyone affected within 72 hours and tell you exactly what happened.

Changes to this policy

If we make a meaningful change to how we handle your data, we'll email everyone with an account at least 30 days before it takes effect. Small typo fixes won't trigger a notification.

The version date at the top of this page is the source of truth.

Questions about this?

We answer everything personally. Email or call us, no robots.

Contact us →
Dimples

Hand-poured lipcare from one tiny pink studio in Lagos. Scrubs, balms, glosses, oils, and a treatment that actually works.

Shop
All productsScrubs & balmsGlosses & oilsTreatmentsGift cardsWholesale & gifting
Learn
TrainingsThe RitualJournalOur Story
Care
Contact usAccountMy ordersBagHelp & FAQ
© 2026 Dimples Lipcare · Lagos, Nigeria
PrivacyTermsInstagramTikTok