Privacy policy
Last Updated: May 27, 2026 Effective Date: May 27, 2026
This Privacy Policy describes how WELLNESSY NUTRITION, LLC ("Wellnessy," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you visit wellnessy.co (the "Site"), purchase our joint health supplements, subscribe to our recurring delivery program, sign up for SMS or email marketing, or otherwise interact with us.
By using the Site, you agree to the collection and use of information in accordance with this Privacy Policy. The English-language version of this Privacy Policy is the controlling version regardless of any translation. If you do not agree with this Policy, please do not use the Site.
This Policy is also subject to our Terms of Service.
1. INFORMATION WE COLLECT
We collect personal information in three ways: (a) when you give it to us directly, (b) automatically when you use the Site, and (c) from third parties.
1.1 Information You Provide Directly
-
Account Information: Name, email address, phone number, password, and account preferences.
-
Order Information: Billing address, shipping address, payment information (credit/debit card numbers, PayPal, Apple Pay, Shop Pay, or other payment method details), email, and phone number when you purchase products.
-
Subscription Information: Delivery frequency (every 4, 8, or 12 weeks), payment instrument on file, and subscription preferences.
-
Communication Information: Information you provide when contacting us at info@wellnessy.co, submitting product reviews, responding to surveys, or interacting with customer support.
-
Marketing Preferences: Your SMS and email opt-in status, preferences, and engagement history.
-
User-Generated Content: Reviews, ratings, photos, testimonials, and any content you submit publicly.
1.2 Information Collected Automatically
When you visit the Site, we automatically collect:
-
Device Information: Web browser type, operating system, IP address, time zone, screen resolution, language, and unique device identifiers.
-
Usage Information: Pages and products viewed (e.g., Joint & Recovery Complex), search terms, click paths, referring URL, time on site, and how you interact with the Site.
-
Cookie and Tracking Data: Data collected via cookies, pixels, web beacons, SDKs, and similar tracking technologies (see Section 6).
-
Mobile Information: If you access the Site from a mobile device, we may collect mobile carrier information and device identifiers transmitted by your provider.
1.3 Information From Third Parties
We may receive information about you from third parties, including:
-
Marketing and advertising partners (Meta/Facebook, Google, TikTok)
-
Analytics providers
-
Payment processors confirming your transactions
-
Shipping carriers confirming delivery
-
Social media platforms when you engage with our content or take an "affinity action" (follow, like, share)
-
Public databases used for fraud prevention and identity verification
1.4 Sensitive Personal Information
We do not intentionally collect "sensitive personal information," "sensitive data," or "special category personal data" as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), GDPR, or other applicable laws. We do not collect or process precise geolocation, government identifiers, health diagnoses, biometric data, or data revealing race, religion, sexual orientation, or political opinions.
If you voluntarily share health-related information with us (e.g., describing your joint condition in a customer service email or product review), we will only use that information to respond to you and will not use it for marketing or profiling.
2. CATEGORIES OF PERSONAL INFORMATION (CCPA/CPRA)
In the past 12 months, we have collected the following categories of personal information from California residents and other users:
|
Category |
Examples |
|
General Identifiers |
Name, alias, postal address, email, phone, IP address, account name, online identifier |
|
Commercial Information |
Products purchased, considered, or returned; subscription history; payment records |
|
Internet Activity Data |
Browsing history on our Site, search history, interactions with ads |
|
Audio/Visual Data |
Customer service call recordings (where lawful), product review photos |
|
Inferences |
Profile reflecting preferences, characteristics, and predispositions drawn from the above |
|
Financial Information |
Payment card details (processed by our payment processor; we do not store full card numbers) |
We use, share, and retain each category for the business purposes described in Sections 3 and 4.
3. HOW WE USE YOUR INFORMATION
We use your personal information for the following purposes:
-
Fulfill Orders: Process payments, ship products, manage subscriptions, send confirmations and tracking updates.
-
Manage Subscriptions: Process recurring billing, send pre-shipment reminders, and allow you to modify or cancel via our Subscription Cancellation Policy.
-
Customer Service: Respond to inquiries, process returns under our 180-Day Money-Back Guarantee, and provide product support.
-
Marketing Communications: Send promotional emails, SMS, and personalized offers (only with your consent where required).
-
Site Optimization: Analyze browsing behavior, A/B test features, and improve the shopping experience.
-
Fraud Prevention & Security: Screen transactions, detect bot activity, and protect against unauthorized access.
-
Personalization: Tailor product recommendations and content to your interests.
-
Legal Compliance: Comply with applicable laws, court orders, subpoenas, and regulatory requirements.
-
Business Operations: Conduct internal analytics, generate aggregated reports, and improve products.
Legal Bases (GDPR/UK GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under one or more of the following legal bases: (a) performance of a contract (e.g., fulfilling your order), (b) your consent (e.g., marketing emails), (c) our legitimate interests (e.g., fraud prevention, improving services), and (d) legal obligation (e.g., tax recordkeeping).
4. HOW WE SHARE YOUR INFORMATION
We share personal information with the following categories of third parties:
-
E-commerce Platform: Shopify (hosts our Site and processes orders).
-
Subscription Management: Recharge or Shopify Subscriptions (manages recurring billing).
-
Payment Processors: Shop Pay, Stripe, PayPal, and credit card processors (process payments; we do not store full card details).
-
Shipping & Fulfillment: Carriers (USPS, UPS, FedEx) and third-party logistics providers.
-
Email & SMS Marketing: Klaviyo, Postscript, or similar platforms (deliver email and SMS campaigns).
-
Analytics: Google Analytics, Shopify Analytics, and similar tools.
-
Advertising Partners: Meta/Facebook, Google Ads, TikTok, Pinterest, and similar platforms for retargeting and lookalike audiences.
-
Customer Support Tools: Helpdesk and live chat providers.
-
Reviews Platform: Judge.me, Yotpo, or similar (collect and display product reviews).
-
Fraud Prevention: Shopify Fraud Protect and similar services.
-
Legal & Government: Law enforcement, courts, and regulators when required by law, subpoena, or to protect rights, safety, or property.
-
Business Transfers: In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the successor.
"Sale" and "Sharing" Disclosure
Under the CCPA/CPRA and similar state laws, certain transfers of information to advertising partners for cross-context behavioral advertising (e.g., showing you ads on Meta or Google based on your activity on our Site) may be considered "selling" or "sharing" personal information.
Categories of information that may be sold or shared for advertising purposes: (1) persistent identifiers (IP address, device ID, cookies, email hash), and (2) internet activity data (pages viewed, products browsed). You have the right to opt out — see Section 7.
We do not sell or share the personal information of consumers we have actual knowledge are under 16 years of age.
5. DO NOT TRACK AND GLOBAL PRIVACY CONTROL
Certain browsers and plug-ins allow users to send signals such as Do Not Track (DNT) or Global Privacy Control (GPC).
-
DNT: We do not currently respond to DNT signals because there is no industry-wide standard.
-
GPC: We honor GPC signals as a valid request to opt out of the sale or sharing of your personal information where required by applicable law (including California, Colorado, and Connecticut).
When we receive a GPC signal, we will process it as an opt-out of any sale or sharing of personal information that occurs via cookies or similar tracking technologies on the browser sending the signal. This opt-out applies only to the specific browser or device on which the signal is sent; you may need to enable GPC on each browser and device you use.
6. COOKIES AND TRACKING TECHNOLOGIES
We use cookies, pixels, web beacons, and similar technologies for the following purposes:
-
Essential Cookies: Required for Site functionality, including shopping cart, checkout, and login.
-
Preference Cookies: Remember your language, region, and display settings.
-
Analytics Cookies: Help us understand how visitors use the Site (Google Analytics, Shopify Analytics).
-
Advertising Cookies: Deliver targeted advertising on third-party sites and measure ad performance (Meta Pixel, Google Ads, TikTok Pixel).
You can manage cookies through your browser settings. Disabling cookies may affect Site functionality, particularly checkout and account features. You can opt out of interest-based advertising through:
-
Digital Advertising Alliance: https://optout.aboutads.info
-
Network Advertising Initiative: https://optout.networkadvertising.org
-
Your Mobile Device Settings: Limit Ad Tracking (iOS) or Opt out of Ads Personalization (Android)
7. YOUR PRIVACY RIGHTS
Depending on your jurisdiction, you may have the following rights:
7.1 California Residents (CCPA/CPRA)
-
Right to Know what personal information we collect, use, disclose, sell, or share.
-
Right to Delete personal information we have collected, subject to certain exceptions.
-
Right to Correct inaccurate personal information.
-
Right to Opt Out of Sale or Sharing of personal information.
-
Right to Limit Use of Sensitive Personal Information (we do not intentionally collect this — see Section 1.4).
-
Right to Data Portability — receive a copy of your information in a portable format.
-
Right to Non-Discrimination — we will not discriminate against you for exercising your rights.
7.2 Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Delaware, and Other State Residents
If you reside in a U.S. state with a comprehensive privacy law, you have rights similar to those in Section 7.1, including the right to access, delete, correct, port, and opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects.
7.3 Right to Appeal
If we deny your privacy request, you have the right to appeal our decision. To appeal, email info@wellnessy.co with the subject line "Privacy Request Appeal" and include your original request and reason for appeal. We will respond within 45 days (or 60 days where law permits an extension).
7.4 EEA, UK, and Swiss Residents (GDPR/UK GDPR)
You have the right to: (a) access your personal data, (b) correct inaccurate data, (c) request erasure ("right to be forgotten"), (d) restrict or object to processing, (e) data portability, (f) withdraw consent at any time, and (g) lodge a complaint with your local supervisory authority.
8. HOW TO EXERCISE YOUR PRIVACY RIGHTS
To submit a privacy request, contact us:
-
Email: info@wellnessy.co (subject line: "Privacy Request")
-
Mail: WELLNESSY NUTRITION, LLC, 8 The Green Ste A, Dover, DE 19901
Identity Verification
To protect your information, we will verify your identity before processing your request. We may ask you to confirm information we already hold about you (such as your email, order number, or shipping address). For sensitive requests, additional verification may be required. If we cannot verify your identity, we may deny your request.
Authorized Agents
You may designate an authorized agent to submit requests on your behalf. We require: (a) written authorization signed by you, (b) verification of the agent's identity, and (c) direct verification of your identity. Authorized agents acting under a valid power of attorney are exempt from item (c).
Response Time
We will respond to verifiable requests within 45 days under CCPA/CPRA and within 30 days under GDPR. We may extend the period by an additional 45 days (CCPA) or 60 days (GDPR) when reasonably necessary, with notice to you.
9. SMS / TEXT MESSAGE PROGRAM
By providing your phone number and opting in to our SMS program, you give express written consent for Wellnessy and our service providers to send you marketing and transactional text messages, including via automated technology (autodialers, programmable dialers).
-
Consent is not a condition of purchase.
-
Message frequency varies. Up to 10 messages per month.
-
Message and data rates may apply. You are responsible for all charges billed by your mobile carrier.
-
Carrier disclaimer: Carriers (AT&T, Verizon, T-Mobile, and others) are not liable for delayed or undelivered messages.
How to Stop or Get Help
-
To unsubscribe: Reply STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message from us. You will receive one final confirmation message.
-
For help: Reply HELP or contact info@wellnessy.co.
Sharing of SMS Data
We share your phone number and opt-in status with SMS platform providers (such as Postscript, Klaviyo SMS, or Attentive), mobile carriers, and other vendors strictly to deliver your messages. We do not sell your phone number or SMS opt-in data, and we do not share it with third parties for their own marketing.
Email Unsubscribe
To stop marketing emails, click the "unsubscribe" link at the bottom of any email or contact us. Transactional emails (order confirmations, shipping notices, subscription reminders) will continue.
10. DATA SECURITY
We implement reasonable administrative, technical, and physical safeguards to protect your personal information, including:
-
TLS/SSL encryption during data transfer
-
PCI-DSS compliant payment processing (we do not store full credit card numbers)
-
Access controls and authentication for our staff
-
Vendor due diligence and contractual data protection obligations
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
11. DATA RETENTION
We retain your personal information only as long as necessary for the purposes described in this Policy. Retention periods are determined based on:
-
How long the information is needed to provide products and services (e.g., subscription customers — for the duration of the subscription plus a reasonable period after cancellation).
-
The type of information collected (e.g., transaction records retained for 7 years for tax and accounting purposes).
-
Legal, contractual, or regulatory obligations (e.g., dispute resolution, fraud prevention, government orders).
When retention is no longer necessary, we securely delete or anonymize your information.
12. INTERNATIONAL DATA TRANSFERS
Wellnessy is based in the United States, and our servers and service providers are located in the U.S. and other countries. If you access the Site from outside the U.S., your personal information will be transferred to, stored in, and processed in the United States.
For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards including the latest revision of the Standard Contractual Clauses (SCCs) issued by the European Commission, supplemented by additional technical and organizational measures where necessary.
By using the Site, you acknowledge that your information may be transferred to and processed in jurisdictions that may have data protection laws different from those of your country.
13. CHILDREN'S PRIVACY
The Site and our products are intended for adults aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18, and we do not direct our marketing to children.
Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under the age of 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, contact us at info@wellnessy.co and we will take steps to delete the information.
14. THIRD-PARTY LINKS AND SOCIAL MEDIA
The Site may contain links to third-party websites, plug-ins, or applications. We are not responsible for the content or privacy practices of those third parties. We maintain a presence on social media platforms (Instagram, Facebook, TikTok, YouTube). Your interactions with those platforms are governed by their privacy policies, not ours.
15. HEALTH-RELATED DISCLAIMER
Wellnessy products are dietary supplements. Statements about our products have not been evaluated by the Food and Drug Administration. Our products are not intended to diagnose, treat, cure, or prevent any disease. Information you share with us about your health is not used for marketing or profiling and is processed only to respond to your inquiry.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Material changes will be communicated by email (if you have an account) or by prominent notice on the Site. Continued use of the Site after changes take effect constitutes acceptance of the updated Policy.
17. CONTACT US
For questions about this Privacy Policy, to exercise your privacy rights, or to submit an appeal, contact us:
WELLNESSY NUTRITION, LLC 8 The Green Ste A Dover, DE 19901
Email: info@wellnessy.co Contact Page: https://www.wellnessy.co/pages/contact
For privacy-specific requests, please use the subject line "Privacy Request" so we can route your inquiry promptly.