Updated August 31, 2022
Questions? You can reach us at:
903 NW F Street
Grants Pass OR 97526
Personal Data, Defined
- Identifiers (e.g., name, email, telephone number, address, username);
- Sensitive Personal Data (e.g., government identification number; precise geolocation; racial or ethnic origin; religious beliefs; contents of messages when we are not the recipient; in some cases, information about a known child);
- Legally protected information (e.g., race, citizenship, marital status, sex);
- Employment-related information (e.g., current or past employment);
- Non-public educational information, including information protected under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g, 34 C.F.R. Part 99);
- Biometrics (e.g., DNA, face/voice prints) and audio, electronic, visual, thermal, or olfactory information;
- Inferences drawn from Personal Data to create a profile about preferences, characteristics, trends, predispositions, behavior, attitudes, intelligence, and aptitudes;
- Commercial information (e.g., products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies); and
- Internet or other similar activity (e.g., browsing history; content interactions).
Information that is not protected as Personal Data includes publicly available information; aggregated information (meaning data summaries or reports with Personal Data removed); and anonymized information that cannot be linked back to an individual.
The Company understands the importance of protecting children online. The Site is not intended for minors. No one under the age of 18 should attempt to use the Site or provide any Personal Data to the Company. If we learn we have collected or received Personal Data from a minor, we will delete that information. If you believe we might have any information from or about a child under 18, please contact firstname.lastname@example.org.
Collection and Use of Personal Data
Over the last 12 months, we have collected Personal Data within the categories of identifiers, commercial information, and internet and similar activity.
The sources of our Personal Data collection include:
- Directly from you, with your consent: If you shop or make a purchase on the Site, we will collect your name, billing address, shipping address, email, and phone number. We use a PCI-DSS compliant payment processor to collect and process your payment information for all purchases. The Company does not collect or store payment information on our systems. We collect this information with your consent, and we use it to provide you with the products and services you request, to fulfill your order, arrange shipping, communicate with you about your order, and for our internal business purposes. With your consent, we use this information to share promotional messages with you.
If you contact us for customer support, we may collect or confirm your identifiers, past orders, shipping information, or other information you previously provided to us. If you choose to share other Personal Data with us, we will collect that information as well. We may keep a record of our correspondence with you. We collect this information with your consent, and we use it to provide you with the customer support you have requested.
In addition to the uses stated above, the Company may use this Personal Data to fulfill any purpose to which you consent, ensure security and prevent fraud, monitor your compliance with our terms and policies, for internal business purposes, to protect or assert our rights or the rights of others, to comply with a legal requirement or court order, or in relation to a business transition involving our data. We will not collect categories of Personal Data not described here, or use the Personal Data we hold for purposes that are materially different, unrelated or not reasonably necessary or compatible with the original purpose without notice and consent to you as required by law.
We do not and will not sell your Personal Data.
Sharing Personal Data for Advertising
The Company may share your Personal Data with third parties for cross-contextual behavioral advertising purposes, like showing you ads on other platforms based on your interests. For example, we use Google Analytics to help us understand how our customers use the Site. We may share data with these third parties about your content interactions and purchases on the Site. For more information about how targeted advertising works, you can visit the educational page provided by the Network Advertising Initiative.
To Opt-Out of sharing, follow the instructions at the links below:
- Bing https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads]
- Digital Advertising Alliance opt-out portal http://optout.aboutads.info/.
- Facebook https://www.facebook.com/settings/?tab=ads
- Google https://www.google.com/settings/ads/anonymous
- Google Analytics https://tools.google.com/dlpage/gaoptout
- Microsoft https://about.ads.microsoft.com/en-us/resources/policies/opt-out-of-the-microsoft-advertising-optimization-program
Disclosing Personal Data
We will only disclose Personal Data to the third parties as described in this section, with your permission, or as required by law. In the preceding 12 months, we have disclosed all Personal Data that we collected for a business purpose. Recipients of disclosed Personal Data include our service providers, which use the Personal Data to help us provide the products and services we offer to you. For example, we share data related to your purchases on the Site with our shipping partners, Amazon Pay, Klarna, Affirm Pay, PayPal, Apple Pay, and Google Pay. We also use Shopify and other eCommerce agencies to power our online store. You can read more about how Shopify uses your Personal Data here: https://www.shopify.com/legal/privacy.
We may also disclose Personal Data to law enforcement or governmental agencies as required or permitted by law. If we go through a business transition (e.g., merger, acquisition, or sale of a portion of our assets), need to comply with a legal requirement or a court order, to exercise or defend our legal claims, or if we believe it is appropriate in order to take action regarding illegal activities or prevent fraud or harm to any person, we may disclose Personal Data as needed for those purposes. We will also make disclosures with your consent.
Aggregated and Deidentified Information
We reserve the right to share aggregated, anonymized, or deidentified information about any individuals with nonaffiliated entities for marketing, advertising, research or other purposes, without restriction.
We only retain Personal Data for the minimum period necessary to provide our Services or achieve our business goals. When you place an order through the Site, we will retain your Personal Data for our records unless and until you ask us to erase this information. For more information on your right to delete, please see Your Privacy Rights below. We reserve the right to retain data for longer periods as required by law or court order or if doing so is critical to our business. We securely delete data at the conclusion of the applicable retention period.
International Data Transfers
The Company is owned and operated in the United States using technical infrastructure in the United States. Our products and services are marketed to consumers in the United States and Canada, but we will make efforts to fill orders and respond to inquiries from elsewhere.
If you access the Site from outside the United States, please be aware that your Personal Data may be transferred to, processed, stored, and used in the United States or other jurisdictions. When your information is moved from your home country to another country, the laws and rules that protect your Personal Data in the country to which your information is transferred may be different from those of the country where you live. For example, if your information is in the United States, it may be accessed by government authorities under United States law. You are solely responsible for determining whether the Site and our products and services are lawful where you are located. By allowing us to collect Personal Data about you, you consent to the transfer and processing of your Personal Data as described in this section.
We offer you a variety of methods and options to directly control how we collect and use your Personal Data.
- Your Customer Account: You have the option to access, correct or update, or delete certain Personal Data through your customer account on the Site. If you require assistance, please contact us at email@example.com.
- Email: If you give us your email address, we may send you informational or support emails related to the Sites. If you opt-in for promotional emails, we may send those as well. If you do not wish to receive emails from us, you can unsubscribe or change your preferences via the links provided in the emails or send a request to firstname.lastname@example.org. Note that if you opt-out of promotional emails, we may still send you non-promotional emails related to your use of the Site or our ongoing business relations.
- Text: If you give us your wireless phone number, you consent to the Company sending you text messages. The number of texts you receive will depend on the Site you use and the information you request from us. Messaging and data charges may apply to any text message you receive or send. Please contact your wireless carrier if you have questions about messaging or data charges. You can unsubscribe from our text messages by replying STOP or UNSUBSCRIBE to any of these text messages. Because our Services are provided to Patients via SMS text message, you will not have access to our Services if you opt-out.
- Privacy Requests: If you wish to exercise your rights under your applicable privacy laws beyond the methods described above, or if you want to express concerns, revoke your consent, lodge a complaint, or request information, please contact email@example.com. We can only assist with or fulfill a privacy request when we have sufficient information to verify that the requester is the person or an authorized representative of the person about whom we have collected Personal Data, and to properly understand, evaluate, and respond to the request. We do not charge a fee to process or respond to a verifiable request unless we have legal grounds to do so. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. We endeavor to respond to privacy requests in accordance with the requirements of the law applicable to your jurisdiction. If we do not fulfill your request within the legally required timeline, you can appeal our response by contacting firstname.lastname@example.org.
- Device Settings: You can control the data we collect through cookies and related technologies by adjusting your device settings or your cookie preferences on our website.
- Do Not Track: Do Not Track signals are signals sent through a browser informing us that you do not want to be tracked. Currently, our systems do not recognize browser “do-not-track” requests.
Your Privacy Rights
Depending on where you live or are located, you may have certain rights over your Personal Data that we collect and retain.
United States Consumers
In the United States, consumer privacy is governed by federal privacy laws covering specific industries or data uses and state privacy laws providing with general consumer privacy rights. This section provides informational notices for state privacy laws applicable in California, Colorado, Connecticut, Nevada, Utah, Virginia, and other states that require companies to inform consumers about their privacy rights and provide a method to exercise those rights. Residents of states offering privacy protections (each a “Consumer”) can exercise their privacy rights by submitting a Privacy Request. Some of these laws may not apply to our Services, in which case these notices are offered as a courtesy to those Consumers.
- Right to Correct. You have the right to request that we correct inaccurate Personal Data about you on our systems. If you become aware that the Personal Data that we hold about you is incorrect, or if your information changes, please inform us and we will update our records.
- Right to Deletion. You have the right to request that we delete your Personal Data that we collected and retained, with certain exceptions. the Company may permanently delete, de identify, or aggregate the Personal Data in response to a request for deletion.
- Right to Access. You have the right to request confirmation that we have collected Personal Data about you and that we provide you with access to that Personal Data. If you submit an access request, we will provide you with copies of the requested pieces of Personal Data in a portable and readily usable format. Please note that the Company may be prohibited by law from disclosing certain pieces of Personal Data, and we may be limited in the number or frequency of requests we must fulfill.
- Right to Disclosure. You may request that we disclose information to you about our collection and use of your Personal Data, such as: (a) the categories of Personal Data we have collected about you; (b) the categories of sources for the Personal Data we have collected about you; (c) our business purpose for collecting, using, processing, sharing or selling that Personal Data, as applicable; (d) the categories of third parties with whom we share that Personal Data; and (e) if we sold or shared your Personal Data under the CCPA, two separate lists stating: (i) sales or sharing, identifying the Personal Data categories that each category of recipient purchased; and (ii) disclosures for a business purpose, identifying the Personal Data categories that each category of recipient obtained. Certain laws may limit the number or frequency of requests we must fulfill.
- Opt-Out of Selling and Sharing. Some states entitle consumers to opt-out of the sale or sharing of Personal Data or targeted advertising practices. We do not sell your Personal Data, but we may share your Personal Data with third parties for cross-contextual behavioral advertising purposes. To opt-out of sharing, please follow the instructions under Sharing Personal Data for Advertising.
- Right to Opt-Out of Profiling. You have the right to opt-out of automated profiling. the Company does not process your Personal Data to evaluate, analyze, or predict your interests and preferences or otherwise use automated profiling to produce significant effects that concern you. To opt-out, please follow the instructions under Sharing Personal Data for Advertising.
- Right to Nondiscrimination. We will not discriminate against you for exercising your privacy rights. For example, unless permitted by law we will not: (i) deny you goods or services; (ii) charge you different prices or rates for goods or services; (iii) provide you a different level or quality of goods or services; (iv) retaliate against you as an employee, applicant for employment, or independent contractor for exercising your privacy rights; or (v) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services, because you exercised a right under applicable privacy laws.
- Right to Disclosure of Marketing Information. California’s Shine the Light Act (Civil Code sections 1798.83-1798.84) entitles California residents to request certain disclosures regarding Personal Data sharing with affiliates and/or third parties for marketing purposes.
Only you or someone legally authorized to act on your behalf may make a verifiable Privacy Request related to your Personal Data. You may also make a verifiable Privacy Request on behalf of your minor child. You may designate a third party to exercise your rights – an authorized agent – however we will require written proof of the authorization and potentially proof of your identity.
Privacy Rights for the European Economic Area and United Kingdom
The Company does not market products or services in the European Economic Area (“EEA”) or the United Kingdom, but residents of the EEA or UK (“Data Subjects”) may find the Site or place an order with us. For this reason, we offer this section as a courtesy notice to Data Subjects that may interact with the Site. Data Subjects can exercise the rights provided under the General Data Protection Regulation (“GDPR”) and its counterpart in the United Kingdom by submitting a Privacy Request, subject to applicable exceptions and limitations. Data Subjects have the following rights over their Personal Data, subject to applicable limitations:
- Right to access your Personal Data. Upon request, we will provide you with a copy of your Personal Data and details about the types of Personal Data we process, why we process it, and any third parties we work with to collect Personal Data on our behalf. We may have one or more legally valid reasons to refuse your request in whole or in part, for example, to protect the rights of other individuals.
- Right to restrict processing of your Personal Data. You can request that we restrict the processing of your Personal Data if: (a) the data is inaccurate; (b) the processing is unlawful; (c) we no longer need the Personal Data; or (d) you exercise your right to object.
- Right to rectify your Personal Data. If you become aware that the Personal Data that we hold about you is incorrect, or if your information changes, please inform us and we will update our records.
- Right to data portability. In some circumstances, we are required to provide your Personal Data to another organization at your request and in a structured, commonly used and machine-readable format.
- Right to erasure (a.k.a. the “right to be forgotten”). Upon your request, we must delete your Personal Data in certain circumstances and where required by law. This right is not absolute, and we may be entitled to retain and process your Personal Data despite your request. If you make this request, we balance certain legal, contractual, and business interests against your right to request the deletion of your Personal Data.
- Right to object to certain processing of your Personal Data. Upon your request, we will limit our processing of your Personal Data as you request in certain circumstances and where we are required to do so by law.
- Right not to be subject to automated decision-making. We do not use automated decision-making as part of your use of the Site or our products or services. If this changes in the future, we will update this posting to describe our use of automated decision-making and your options to exercise your privacy rights related to your Personal Data processed using automated decision-making.
- Right to lodge a complaint with a supervisory authority. Data Subjects can submit requests, questions, or complaints to the Company using the methods described under Privacy Requests. If, after contacting us, you feel a privacy issue has not been resolved, you have the right to file a complaint with a supervisory authority. We suggest the Data Protection Commissioner of Ireland.
Canadian Privacy Rights
This section provides the disclosures and notices required under Canada’s Personal Data Protection and Electronic Documents Act (“PIPEDA”) and solely to residents of Canada where PIPEDA applies (“Canadian Consumers”). PIPEDA gives Canadian Consumers specific rights regarding Personal Data offering details on an identifiable person without the inclusion of name, title, telephone number, and business address of an employee of a business or organization. The rights afforded under PIPEDA are described below.
- Right to accuracy of your Personal Data. We take steps to reasonably ensure that your Personal Data we are using is accurate. If you become aware that the Personal Data that we hold about you is incorrect, or if your information changes, please inform us and we will update our records.
- Right to access your Personal Data. Upon written request and identity authentication, we will provide you with your Personal Data under our control, information about the ways in which that information is being used and a description of the individuals and organizations to whom that information has been disclosed. We will make the information available within 30 days or provide written notice where additional time is required to fulfil the request. We may not be able to provide access to some or all of the Personal Data you request if limited by law or potential infringement of another’s privacy rights. If we must refuse an access request, we will notify you in writing, document the reasons for refusal, and outline further steps that are available to you.
Canadian Consumers may exercise these rights by submitting a Privacy Request.
Most browsers automatically accept cookies, but you can choose whether to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. Alternatively, you can install a third-party plugin to block cookies or alert you when a cookie is set. Removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org.
The Company has implemented and maintains reasonable security measures to secure your Personal Data from accidental loss and unauthorized access, use, alteration, and disclosure. Our security measures are appropriate to the volume, scope, and nature of the Personal Data processed and designed to meet our duty of care with respect to your Personal Data. However, please remember that no submission of data over the internet is entirely secure. You are responsible for keeping your device access and login confidential. You are also encouraged to install anti-virus and anti-malware software on your devices and keep all software updated to avoid security risks. We cannot guarantee the security of information you submit via our Site while it is in transit over the Internet, and any such submission is at your own risk.
The Site may offer links to websites or platforms operated by third parties. The Company has no control over these websites or platforms, and you use them at your own risk. You should exercise caution when deciding to disclose your Personal Data to anyone online.