Last updated: June 20, 2024
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
The words of which the initial letter is capitalized are defined terms. The definitions provided below apply throughout this Privacy Policy. These terms may be used interchangeably in singular or plural forms, as dictated by the context.
For the purposes of this Privacy Policy:
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
By using our Service, You expressly consent to the collection, processing, and use of Your Personal Data as described in this Privacy Policy. You have the right to withdraw Your consent at any time by contacting Us through the provided contact details.
We do not intentionally collect Sensitive Personal Information as part of Our standard data collection practices. However, to the extent that Sensitive Personal Information is inadvertently received by us (for instance, if provided by you through customer support interactions or as part of user-generated content), We are committed to treating such information with the utmost care and in accordance with the California Privacy Rights Act (CPRA).
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service.
You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close your web browser. Learn more about cookies in the "What Are Cookies" article.
We use both session and persistent Cookies for the purposes set out below:
Type: Session Cookies
Administered by: Us
Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.
Type: Persistent Cookies
Administered by: Third-Parties
Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify you as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device you use to access the Website. We may also use these Cookies to test new pages, features or new functionality of the Website to see how our users react to them.
The Company may use Personal Data for the following purposes:
We may share your personal information in the following situations:
We only collect Personal Data that is necessary for the purposes for which it is processed. We ensure that the Personal Data we collect is adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Our aim is to limit the impact on Your privacy while still providing the high-quality service you expect from Us.
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce Our legal agreements and policies. Once the retention period expires, Personal Data is securely deleted or anonymized, so it can no longer be linked to You. We may retain de-identified or aggregated data for statistical analysis and business planning, including after Your account has been closed.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
The security of Your Personal Data is important to Us, but no method of transmission over the Internet or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Service Providers have access to Your Personal Data only to perform their tasks on Our behalf and are obligated not to disclose or use it for any other purpose.
We employ third-party tracking technologies, such as Meta Pixel and Google Analytics, to analyze the behavior of users on our Service and to enhance your user experience. These technologies help us improve Our website's functionality and provide targeted advertisements based on Your browsing activities and preferences. By using Our Service, You consent to the deployment of these tracking technologies and the collection and processing of Your Personal Data as described in the privacy policies of such third-party tracking providers. You have the option to opt-out of these tracking services at any time by adjusting Your browser settings or visiting our Cookie Preferences page.
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network.
You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en
Elevar is a data collection and analytics service.
For more information on the privacy practices of Elevar, please visit their Privacy policy: https://www.getelevar.com/legal/privacy/
We may use Your Personal Data to contact You with newsletters, marketing or promotional materials and other information that may be of interest to You. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us.
We may use Email Marketing Service Providers to manage and send emails to You.
Klaviyo is an email marketing sending service.
For more information on the privacy practices of Klaviyo, please visit their Privacy policy: https://www.klaviyo.com/privacy
Attentive is an email and SMS marketing service.
For more information on the privacy practices of Attentive, please visit their Privacy policy: https://www.attentive.com/legal/privacy
The Company uses remarketing services to advertise on third party websites to You after You visited our Service. We and Our third-party vendors use cookies to inform, optimize and serve ads based on Your past visits to our Service.
Google Ads (AdWords) remarketing service is provided by Google Inc.
You can opt-out of Google Analytics for Display Advertising and customise the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads
Google also recommends installing the Google Analytics Opt-out Browser Add-on - https://tools.google.com/dlpage/gaoptout - for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en
Facebook remarketing service is provided by Facebook Inc.
You can learn more about interest-based advertising from Facebook by visiting this page: https://www.facebook.com/help/164968693837950
To opt-out from Facebook's interest-based ads, follow these instructions from Facebook: https://www.facebook.com/help/568137493302217
Facebook adheres to the Self-Regulatory Principles for Online Behavioural Advertising established by the Digital Advertising Alliance. You can also opt-out from Facebook and other participating companies through the Digital Advertising Alliance in the USA http://www.aboutads.info/choices/, the Digital Advertising Alliance of Canada in Canada http://youradchoices.ca/ or the European Interactive Digital Advertising Alliance in Europe http://www.youronlinechoices.eu/, or opt-out using your mobile device settings.
For more information on the privacy practices of Facebook, please visit Facebook's Data Policy: https://www.facebook.com/privacy/explanation
We may provide paid products and/or services within the Service. In that case, we may use third-party services for payment processing (e.g. payment processors).
We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processors whose use of Your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
Their Privacy Policy can be viewed at https://stripe.com/us/privacy
Their Privacy Policy can be viewed at https://www.paypal.com/webapps/mpp/ua/privacy-full
Their Privacy Policy can be viewed at https://pay.amazon.com/help/201751600
Their Privacy Policy can be viewed at https://www.shopify.com/legal/privacy
Under this Privacy Policy, and by law if You are a resident of California, You have the following rights:
We collected the following categories of PII (A, B, D, E, F, and G) as defined in the California Consumer Privacy Act within the last twelve months. Our uses of this PII are detailed above in this Privacy Policy:
Table T.1 |
||
Category |
Examples |
Collected |
A. Identifiers |
Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers. |
YES |
B. Personal information categories listed in the California Consumer Records statute (Cal. Civ. Code § 1798.80(e)) |
Name, signature, address, telephone number, bank account number, credit card number, debit card number, or any other financial information. |
YES |
C. Characteristics of protected classifications under State or federal law |
Religious affiliation, ethnicity, etc. |
NO |
D. Commercial |
Records of products or services purchased. |
YES |
E. Biometric Data |
Fingerprints or footprints. |
NO |
F. Internet or other similar network activity |
Browsing history, search history, information on a consumer’s interaction with a Services, application, or advertisement. |
YES |
G. Geolocation data |
Physical location or movements. |
YES |
H. Audio, electronic, visual, thermal, olfactory, or similar information |
N/A |
NO |
I. Professional or employment-related information |
N/A |
NO |
J. Educational information |
N/A |
NO |
We obtain the categories of PII marked “YES” in the above table (Table T.1) directly from California residents when they complete forms through our Services or provide it to us as a part of a transaction or inquiry concerning our Services. We also obtain these categories of PII indirectly from California residents while observing their actions on our Services and from third parties or service providers that they have authorized to receive and share PII.
In order to exercise any of Your rights under the CCPA, as amended by the CPRA, and if you are a California resident, You can email us at privacy@alayanaturals.com or visit our Customer Service Request Form at https://alayanaturals.com/pages/customer-support.
The Company will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.
We do not sell personal information. However, the Service Providers we partner with (for example, our advertising partners) may use technology on the Service that "sells" personal information as defined by the CCPA, CPRA, or other applicable law.
If you wish to opt out of the use of your personal information for interest-based advertising purposes and these potential sales as defined under the CCPA, CPRA, or other applicable law, you may do so by following the instructions below.
Please note that any opt out is specific to the browser You use. You may need to opt out on every browser that you use.
You can opt out of receiving ads that are personalized as served by our Service Providers by using our CCPA/CPRA Privacy Request Form section at https://alayanaturals.com/pages/ccpa-opt-out.
The opt out will place a cookie on Your computer that is unique to the browser You use to opt out. If you change browsers or delete the cookies saved by your browser, you will need to opt out again.
Your mobile device may give you the ability to opt out of the use of information about the apps you use in order to serve you ads that are targeted to your interests:
You can also stop the collection of location information from Your mobile device by changing the prefhttps://alayanaturals.com/pages/ccpa-opt-outerences on your mobile device.
Our Service does not respond to Do Not Track signals.
However, some third party websites do keep track of Your browsing activities. If You are visiting such websites, You can set Your preferences in Your web browser to inform websites that You do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of Your web browser.
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.
Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes.
If you'd like to request more information under the California Shine the Light law, You can contact Us using the contact information provided below.
California Business and Professions Code section 22581 allow California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted.
To request removal of such data, and if you are a California resident, You can contact Us using the contact information provided below, and include the email address associated with Your account.
Be aware that Your request does not guarantee complete or comprehensive removal of content or information posted online and that the law may not permit or require removal in certain circumstances.
Colorado Residents
We do not conduct business in Colorado, control or process the personal data of 100,000 or more consumers during a calendar year, or derive revenue or receive a discount on the price of goods or services from the sale of personal data.
Connecticut Residents
During the preceding calendar year, we did not control or process the personal data of at least 100,000 consumers or derive more than 25% of our gross revenue from the sale of personal data.
Montana Residents
We do not control or process the personal data of 50,000 or more Montana residents during a calendar year or derive over 25% of its revenues from the sale of personal data and control or processing of personal data of 25,000 or more Montana residents. Therefore, the Montana Consumer Data Privacy Act does not apply to our collection or use of PII.
Nevada Residents
If you are a resident of Nevada, you may provide notice to us to limit the sale of your PII to third parties for resale or licensing purposes. However, we do not sell your PII for such use. To notify us that you wish to limit the sale of your PII to third parties for resale or licensing purposes, you may contact us at privacy@alayanaturals.com. In your submission, please include the statement “Nevada Do Not Sell Request,” along with your name, address, and user account information.
Tennessee Residents
We do not exceed $25 million in annual revenue, control or process the personal information of 175,000 or more Tennessee consumers, or control or process the data of 25,000 consumers while deriving more than 50% of its gross revenue from the sale of personal information.
Texas Residents
We are considered a small business as defined by the Small Business Administration and, therefore, is exempt from the Texas Data Privacy and Security Act. However, we generally collects and processes PII only to the extent that it is adequate, relevant, and reasonably necessary for the purposes disclosed in this Privacy Policy. The categories of PII collected by us are disclosed within this Privacy Policy, in particular in Table T.1 above, and Texas residents may request, free of charge, information of the PII collected from them twice annually.
Utah Residents
We do not have annual revenues of $25,000,000 or more and control or process the PII of 100,000 or more consumers. Therefore, the Utah Consumer Privacy Act does not apply to our collection and use of PII.
Virginia Residents
We do not control or process the personal data of at least 100,000 Virginia residents or control or process the personal data of at least 25,000 Virginia residents and derive more than 50% of its gross revenue from the sale of personal data. For these reasons, the Virginia Consumer Data Protection Act (VCDPA) does not apply to our collection and use of PII.
Rights of European Citizens
We adhere to the EU-U.S. Data Privacy Framework (“DPF”) Principles, including the DPF’s Supplemental Principles, and we comply with the Principles in handling all data from EU-citizens. We are subject to the enforcement powers of the United States Federal Trade Commission (“FTC”) in relation to its handling of user data. We are not certified under the DPF by the FTC or any other regulatory body but we adhere to the Principles in handling all data from EU-citizens to the best of its abilities.
If you are a European citizen, you are entitled to certain rights regarding the protection of your Personally Identifiable Information and Personal Data, which are subject to limitations set forth in the EU GDPR and its applicable case law. These rights are:
To exercise these rights, you may either opt out of receiving communications from us by unsubscribing to our e-mails or by contacting us at privacy@alayanaturals.com. You do not need to pay a fee to exercise these rights, however, we reserve the right to charge a reasonable fee if your request is unreasonable or excessive. To confirm your request, we may need to request specific information from you as a security measure to ensure that personal data is not disclosed to an unauthorized third party. We will attempt to respond to all legitimate requests within thirty (30) days.
For further information regarding your privacy rights as a citizen of the EU, please visit the U.S. Department of Commerce’s Services at https://www.commerce.gov/ and the DPF overview webpage at https://www.dataprivacyframework.gov/s/program-overview.
We do not yet recognize Global Privacy Control signals, but we strive to comply with any requests to opt out from the collection and use of PII. Should you wish to opt out from the collection and use of your PII, please contact our Data Protection Officer through the contact information provided in this Privacy Policy.
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
We may update our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
This Privacy Policy is part of and incorporated by reference into the Terms of Service that govern your use of our Service. By accessing and using our Service, you agree to be bound by the terms and conditions outlined in our Terms of Service and this Privacy Policy. If you have not yet reviewed the Terms of Service applicable to our Service, please do so here: https://alayanaturals.com/pages/terms-of-service. Your continued use of our Service constitutes your acceptance of these terms and any updates that we may make to them in the future.
If you have any questions about this Privacy Policy, You can contact our Data Protection Officer (DPO) at: