Legal
Privacy Policy
How Aerthera handles personal data when you browse the website, use guest checkout, and purchase from the Lemongrass Malaya collection.
Scope and responsibility
This Privacy Policy explains how Aerthera collects, uses, stores, and discloses personal data when you browse this website, add products to your cart, contact us, or complete a guest checkout.
Aerthera is a Malaysia-based business operating in connection with commercial transactions. We handle personal data in line with the Personal Data Protection Act 2010 (Act 709), including the principles relating to notice, security, retention, data integrity, and access.
Information we collect
We may collect contact details such as your name, email address, telephone number, billing address, shipping address, and company details where relevant.
When you place an order, we collect order-related information such as purchased items, quantities, pricing, delivery details, and payment status. Card details are handled directly by Stripe and are not stored on this website.
We also collect limited technical and usage information such as device/browser data, approximate location inferred from network requests, and on-site activity needed for performance, fraud prevention, and checkout reliability.
Your cart contents are stored in your browser using local storage so that your selections can persist between visits on the same device.
How we use personal data
We use personal data to operate the storefront, process and fulfill orders, arrange delivery, respond to enquiries, provide customer support, and send transaction-related communications.
We may also use personal data to detect abuse, prevent fraud, maintain the security of the website, comply with legal or accounting obligations, and improve the usability and performance of the storefront.
Sharing and third-party services
We share personal data only where necessary to run the business and complete your transaction. This can include payment processors, hosting providers, email providers, logistics or delivery partners, and professional advisers where required.
Payments are processed through Stripe Checkout. When you enter payment or billing details during checkout, that information is collected and processed by Stripe in accordance with Stripe's own terms, security controls, and privacy documentation.
We may also disclose personal data when required to comply with applicable law, lawful requests, regulatory obligations, or to establish, exercise, or defend legal claims.
Retention, security, and transfers
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, and for any longer period required to satisfy legal, tax, accounting, dispute-resolution, or fraud-prevention obligations.
We use reasonable technical and organisational measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration, and misuse. No internet-based service can guarantee absolute security, but access is limited to people and providers who need the data for legitimate business purposes.
Some service providers may process data outside Malaysia. Where this happens, we expect those providers to apply appropriate contractual, technical, and organisational safeguards.
Your choices and rights
Subject to applicable law, you may request access to personal data we hold about you and ask that inaccurate, incomplete, misleading, or outdated data be corrected.
Where processing is based on consent, you may also withdraw that consent for future processing, although this will not affect processing already carried out or any processing required to complete a transaction or comply with law.
To make a privacy request or ask a question about this policy, contact hello@aerthera.com. We may need to verify your identity before responding.






