This Privacy Policy describes how herbalwondershop.com (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.
We collect, store, process, and share personal data based on GDPR guidelines and complies with GDPR requirements in the following ways: — we assigned a Data Protection Officer who is in charge of the Ecwid Data Protection Policy; — we started to deliver GDPR-focused training to our key teams and personnel; — we implemented a detailed procedure to deal with all data subject access requests, deletion requests, and government access requests; — we work only with subprocessors who provide adequate protection of the personal data through robust technical and organizational measures; — we developed a reliable method to detect, report and investigate a personal data breach; — we established the necessary records of data processing activities; — we are certified under the EU - U.S. and Swiss - U.S. Privacy Shield frameworks; this arrangement calls for certified organizations to guarantee a level of security in line with EU data protection law regarding the transfer of personal data from the EEA and Switzerland to the U.S. Although we collect cookies, it does not store personal information within them. We use session-based and persistent-based cookies: — Session cookies exist only during one session. That means that they are deleted from your computer as soon as you close your browser or turn off a computer. — Persistent cookies remain on your computer after you close your browser or turn off your computer. If a customer logs out from their account in the store, we clear the local storage including any information.
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.
Device information
Order information
Customer support information
Minors
The Site is not intended for individuals under the age of 21. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address below to request deletion.
We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:
Behavioral Advertising
As described above, we may use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:
You can opt out of targeted advertising by:
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.
We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.
Lawful basis
Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.
If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.
Our processor Lightspeed uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.
Services that include elements of automated decision-making include:
CCPA
If you are a resident of California, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through email at herbalwonder@herbalwondershop.com
If you would like to designate an authorized agent to submit these requests on your behalf, please contact us at the address below.