Privacy Policy
Last updated: 7 August 2026
LensRevive ("we", "us", "our") is committed to protecting your personal data. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1.Who we are (data controller)
Eduardo Alves da Silva, trading as LensRevive (sole trader), Co. Meath, Ireland.
Contact: contact@lensrevive.com
2.Data we collect
When you book a service, we collect:
- Identity & contact: your name, email address, phone number.
- Location: your address and Eircode (used to plan the mobile visit and confirm we cover your area). We look up the town/county from your Eircode via OpenStreetMap/Nominatim.
- Vehicle details: car make and model (used to determine headlight complexity and price).
- Booking details: chosen date/time, notes you provide, and the service tier/price.
- Payment: card payments are processed by Stripe. We do NOT store your card number — Stripe handles it. We store a payment reference and whether the deposit was paid.
When you browse the site:
- Technical data: IP address, browser/user-agent, and security cookies from Cloudflare.
- Measurement & marketing data: page views, clicks and booking steps recorded in our own database, plus Meta (Facebook) Pixel and Conversions API identifiers (_fbp, _fbc cookies), IP and user-agent, to measure ad performance. This runs for every visitor.
- Session recordings & heatmaps: Microsoft Clarity records how pages are used — mouse movement, clicks, scrolling and moves between pages — so we can see what confuses people and fix it. Text you type into forms is masked by Clarity's default settings, and we do not use these recordings to identify you. This runs on the public site only, never in our internal admin area.
3.How we use your data & legal basis
- To provide the service you booked (contact you, attend your address, process the deposit and balance) — performance of a contract.
- To send booking confirmations, reminders and service-related emails — performance of a contract.
- To prevent fraud and abuse (anti-bot checks, rate limiting) and keep the site secure — legitimate interests.
- To measure how the site is used — including session recordings and heatmaps via Microsoft Clarity — and to measure and improve our advertising via Meta Pixel/Conversions API — legitimate interests. You can object at any time using the contact details below.
- To comply with legal/accounting obligations — legal obligation.
4.Cookies & tracking
- Strictly necessary: Cloudflare (__cf_bm) for security/bot protection, and browser sessionStorage used to hold your in-progress booking. Essential; set without consent.
- Measurement & marketing: Meta Pixel and Conversions API (_fbp, _fbc), plus first-party identifiers we use to link a visit to a booking or WhatsApp conversation. These are active for every visitor — the cookie notice in the footer is informational and does not switch them off. If you want us to stop processing your data this way, contact us using the details below.
- Session recording: Microsoft Clarity (_clck, _clsk and related identifiers) records session replays and heatmaps of the public pages. It is not loaded at all in our internal admin area.
- Push notifications (staff area only): if someone on our team turns on notifications inside the internal panel, their browser creates a subscription — an address to deliver to, plus keys — which we store so new customer messages can be pushed to them. Customers are never asked for notification permission and receive nothing this way.
5.Who we share data with (processors)
We share the minimum necessary with trusted providers acting on our behalf:
- Stripe — payment processing.
- Cal.com — appointment scheduling.
- Supabase — secure database hosting (EU region).
- ZeptoMail (Zoho) — sending transactional emails (EU region).
- Cloudflare — website delivery and security.
- OpenStreetMap/Nominatim — Eircode-to-area lookup.
- Meta Platforms — advertising measurement.
- Microsoft (Clarity) — session recording and site analytics.
We never sell your personal data.
6.International transfers
Most providers process data within the EU/EEA. Where a provider (e.g. Meta, Microsoft, Stripe) processes data outside the EEA, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
7.How long we keep data
- Booking and transaction records: retained for up to 6 years to meet accounting and tax obligations.
- Abandoned/expired bookings that never completed: deleted or anonymised within 12 months.
- Measurement & marketing identifiers: Meta cookies expire according to Meta’s own cookie lifetimes; our own measurement events are kept in our database for as long as we need them to analyse how the site performs.
- Session recordings and heatmaps: kept by Microsoft Clarity under its own retention limits and deleted by Microsoft when those expire. We do not keep our own copies.
8.Your rights
Under GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time. To exercise any right, email contact@lensrevive.com. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
9.Security
We use encryption in transit (HTTPS), access controls, signed webhooks and a locked-down database. No system is 100% secure, but we take reasonable measures to protect your data.
10.Changes
We may update this policy; the "Last updated" date will change accordingly.
11.Contact
Questions about your data: contact@lensrevive.com