1. Information We Collect
We collect personal information only as necessary to fulfill the purposes stated below, adhering to the principle of data minimization.
1.1 Personal Information You Voluntarily Provide
-
Account Information: When creating an account, we collect your name, email address, and password.
-
Order & Payment Information: To process purchases, we collect your full name, billing address, shipping address, phone number, and payment details (e.g., credit card information). Payment details are processed and encrypted by our licensed payment service providers; we do not store or access plain-text payment data.
-
Customer Support Information: When you contact us (via email or live chat), we may collect your order number, email address, and any information you provide to resolve inquiries (e.g., product questions, return requests).
-
Marketing Consent: If you opt in to our marketing communications, we store your consent to send promotional emails about new products, discounts, and health-related content.
1.2 Automatically Collected Information
-
Device & Usage Data: We automatically collect information about your device and interaction with the Site, including your IP address, browser type, operating system, time zone, pages viewed, time spent on the Site, and referral source.
-
Cookies & Similar Technologies: We use cookies, log files, and web beacons to enhance your browsing experience, analyze Site performance, and prevent fraud. For more details, see Section 6: Cookies & Tracking Technologies.
2. How We Use Your Information
We use your personal information for the following legitimate business purposes, based on your consent, contract fulfillment, or our legal obligations:
| Purpose |
Legal Basis |
| Process and fulfill orders (e.g., payment processing, shipping, order confirmations) |
Contract fulfillment |
| Communicate with you about orders, shipping updates, and customer support inquiries |
Contract fulfillment / Legitimate interest |
| Screen orders for fraud and security risks to protect you and our business |
Legitimate interest |
| Send marketing communications (e.g., newsletters, promotions) only if you have opted in
|
Consent |
| Improve the Site’s functionality, design, and user experience |
Legitimate interest |
| Comply with legal obligations (e.g., tax reporting, responding to lawful requests) |
Legal obligation |
We will never use your personal information for purposes unrelated to those stated above without first notifying you and obtaining your consent.
3. Sharing Your Personal Information
We do not sell, rent, or trade your personal information to third parties for commercial purposes. We may share your information only in the following limited circumstances:
3.1 Service Providers
We share personal information with trusted third-party service providers who assist us in operating the Site and fulfilling orders. These providers are contractually obligated to protect your data and use it only for the purposes we specify. Examples include:
-
Payment Processors: To securely process payments (e.g., PayPal, Stripe).
-
Logistics Partners: To ship orders and provide tracking information (e.g., UPS, DHL).
-
Analytics Providers: To analyze Site usage (e.g., Google Analytics) – see Section 6 for details.
3.2 Legal Requirements
We may disclose your personal information if required to do so by law, regulation, or a valid legal request (e.g., subpoena, court order) to protect our rights, property, or safety, or the rights, property, or safety of others.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our assets, your personal information may be transferred to the acquiring entity. We will notify you of any such transfer and ensure the new entity adheres to this Privacy Policy.
4. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.
-
Order Information: Retained for 7 years from the date of the last order to comply with tax and accounting obligations.
-
Account Information: Retained until you request account deletion (see Section 5: Your Rights).
-
Customer Support Records: Retained for 2 years from the resolution of your inquiry to address potential future questions.
-
Marketing Data: Retained until you opt out of marketing communications (see Section 5: Your Rights).
Once retention periods expire, we will securely delete or anonymize your personal information to prevent unauthorized access.
5. Your Rights
Your rights regarding your personal information depend on your location, but may include the following. To exercise these rights, contact us at
[email protected] with your full name, email address, and order number (if applicable). We will respond within
30 days (or as required by law).
5.1 Global Rights
-
Right to Access: Request a copy of the personal information we hold about you.
-
Right to Correction: Request correction of inaccurate or incomplete personal information.
-
Right to Deletion: Request deletion of your personal information (subject to legal retention requirements).
-
Right to Withdraw Consent: Withdraw your consent for marketing communications at any time (see Section 7: Opt-Out of Marketing).
5.2 EU/EEA Residents (GDPR)
In addition to the above, you have the right to:
-
Restrict Processing: Request that we restrict the processing of your personal information.
-
Data Portability: Request a copy of your personal information in a structured, machine-readable format.
-
Object to Processing: Object to the processing of your personal information for legitimate business purposes.
-
Lodge a Complaint: File a complaint with your local data protection authority if you believe we have violated the GDPR.
5.3 California Residents (CCPA)
In addition to the above, you have the right to:
-
Know What Information We Collect: Request details about the personal information we collect, use, or disclose about you.
-
Non-Discrimination: We will not discriminate against you for exercising your CCPA rights (e.g., charging higher prices or providing lower-quality services).
6. Cookies & Tracking Technologies
We use cookies and similar technologies (e.g., web beacons, pixel tags) to enhance your browsing experience and analyze Site performance. Cookies are small data files stored on your device that help us recognize your browser and remember your preferences.
6.1 Types of Cookies We Use
-
Necessary Cookies: Essential for the Site to function (e.g., processing orders, managing your shopping cart). These cookies cannot be disabled.
-
Performance Cookies: Collect information about how you use the Site (e.g., pages viewed, time spent) to improve functionality. These cookies are anonymous.
-
Marketing Cookies: Used to send targeted advertisements to you (only if you have opted in to marketing communications).
6.2 Managing Cookies
You can manage or disable cookies through your browser settings. However, disabling necessary cookies may affect the functionality of the Site. For more information on managing cookies, visit your browser’s help center.
6.3 Google Analytics
We use Google Analytics to analyze Site usage. Google Analytics collects anonymous data about your interactions with the Site and may transfer this data to Google servers in the U.S. Google’s use of this data is governed by Google’s Privacy Policy. You can opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on.
7. Opt-Out of Marketing
You can opt out of receiving marketing communications from us at any time by:
- Clicking the “Unsubscribe” link at the bottom of any marketing email.
- Emailing us at [email protected] with the subject line “Unsubscribe from Marketing.”
Opting out will not affect transactional emails (e.g., order confirmations, shipping updates).
8. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
-
Encryption: All personal information transmitted via the Site is encrypted using Secure Sockets Layer (SSL) technology.
-
Access Controls: Only authorized personnel have access to personal information, and they are trained on data protection practices.
-
Regular Audits: We conduct regular security audits to identify and address potential vulnerabilities.
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we will take all reasonable steps to minimize risk.
9. International Data Transfers
If you are located outside the United States, your personal information may be transferred to and processed in the U.S. or other countries where our service providers are based. These countries may have different data protection laws than your home country.
We ensure that international data transfers comply with applicable laws by:
- Using EU-approved Standard Contractual Clauses (SCCs) for transfers to non-EEA countries.
- Relying on the Privacy Shield Framework (if applicable) or other legally recognized mechanisms.
10. Children’s Privacy
Our Site is not intended for individuals under the age of
18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will immediately delete that information. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at
[email protected].
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technology. We will notify you of any material changes by posting the updated policy on the Site with a new effective date. We encourage you to review this policy periodically to stay informed about how we protect your data.