Privacy Policy

Effective Date: August 6, 2026

Last Updated: August 6, 2026

This Privacy Policy describes how Zengoddess Wellness, LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit zengoddesswellness.com, interact with our WooCommerce storefront, download resources, subscribe to newsletters, or utilize our SMS and related digital services.

1. Scope & Applicability

This policy applies to all visitors, registered users, and customers accessing our website, associated landing pages, WooCommerce store, email campaigns, SMS marketing channels, and digital downloads.

2. Categories of Information We Collect

  • Voluntarily Provided Information: Name, billing address, shipping address, email address, phone number, payment details, purchase history, customer support records, account credentials, survey responses, and review contributions.
  • Automatically Collected Information: IP address, browser type, operating system, unique device identifiers, referring URL/pages visited, clickstream data, time spent on pages, and precise/approximate location data.
  • Sensitive Personal Data: If you voluntarily provide wellness preferences or health-related information through quizzes, digital journals, or customer inquiries, this is processed strictly with your explicit consent.

3. Third-Party Processors & Data Sharing

We do not sell your personal information for monetary payment. We share data with third-party service providers bound by strict contractual obligations to handle data solely on our behalf:

CategoryService Provider(s)Purpose of Sharing
E-Commerce & HostingWooCommerce / WordPressCart functionality, order processing, and account management.
Payment ProcessingStripe, PayPalSecure payment transactions. (We do not store full card numbers).
Email MarketingMailchimp (or successor platform)Dispatching transactional emails, newsletters, and promotional offers.
SMS CommunicationsSMS Gateway Provider (e.g., Twilio)Delivering transactional and marketing text updates.
Analytics & AdvertisingGoogle Analytics, Meta (Facebook Pixel), Pinterest, YouTubeWeb performance analysis, conversion tracking, and retargeting ads.
Fulfillment & LogisticsUSPS, UPS, FedExPrinting shipping labels and fulfilling physical orders.

4. Cookies, Analytics & Tracking Technologies

We use essential, analytical, functional, and targeting cookies, pixels, and web beacons.

  • Essential Cookies: Necessary for core functionality, such as keeping items in your WooCommerce shopping cart and securing checkout.
  • Analytics & Marketing Cookies: Used to evaluate site traffic and deliver tailored ads.
  • Consent & Preferences: Non-essential cookies are disabled by default for visitors in applicable jurisdictions until affirmative consent is given via our Cookie Banner. You can manage or revoke cookie consent at any time through your web browser settings.

5. SMS Communications & TCPA Compliance

By opting into our SMS marketing program, you expressly consent to receive recurring automated promotional and transactional text messages at the mobile number provided.

  • Opt-In: Mobile opt-in data and consent will not be sold, rented, or shared with third parties for marketing/promotional purposes.
  • Conditions: Consent to receive text messages is not a condition of purchase. Message and data rates may apply. Message frequency varies.
  • Opt-Out & Help: Reply STOP to any text message to opt out immediately. Reply HELP for customer support or contact us via our website.

6. Data Retention Schedule

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal/tax requirements, or resolve disputes.

Data CategoryRetention Period
Order & Financial RecordsRetained for 7 years to satisfy tax, accounting, and legal requirements.
Marketing Email & SMS ContactsRetained until you unsubscribe or opt out, plus 30 days for purge completion.
Customer Support CommunicationsRetained for 3 years following resolution.
Web Server Logs & Analytics DataRetained for 14 months, then anonymized or deleted automatically.

7. U.S. State Privacy Rights (Texas TDPSA & California CCPA/CPRA)

If you are a resident of Texas (under the Texas Data Privacy and Security Act – TDPSA) or California (under the CCPA/CPRA), you are entitled to specific privacy rights:

  • Right to Know / Access: Request confirmation of whether we process your data and obtain a portable copy of it.
  • Right to Correct: Request corrections to inaccurate personal data.
  • Right to Delete: Request deletion of personal data provided by or obtained about you.
  • Right to Opt-Out: Opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions.
  • Sensitive Data Protection: Under the TDPSA, we will not process sensitive personal data (e.g., precise geolocation, health data, biometric data) without obtaining your prior explicit consent.
  • Appeals Process (Texas Residents): If we refuse to take action on your consumer request, you may appeal our decision within 30 days of receipt of our response by contacting us with the subject line “Privacy Appeal.” If your appeal is denied, Texas residents may contact the Texas Attorney General.

8. International Visitors & GDPR/UK GDPR Rights

If you visit our website from the European Economic Area (EEA) or the United Kingdom (UK), our legal basis for collecting and using personal data depends on the information concerned:

  • Contractual Necessity: Processing orders, digital downloads, and fulfilling agreements.
  • Legitimate Interests: Fraud prevention, website optimization, and customer service.
  • Consent: Email newsletters, SMS communications, and targeting cookies.

Your GDPR Rights: You have the right to access, rectify, erase, restrict processing, object to processing, and request data portability. You also have the right to lodge a complaint with your local Data Protection Authority.

9. Data Security & Data Breach Notification Obligations

We enforce appropriate administrative, technical, and physical security measures (including SSL/TLS encryption, restricted access controls, and firewall defenses) to safeguard personal data.

In the event of a security breach compromising your unencrypted personal information:

  • We will notify affected individuals without unreasonable delay, in accordance with applicable laws (including Texas Business & Commerce Code § 521.053).
  • If a breach impacts 250 or more Texas residents, notice will be provided to the Texas Attorney General no later than 60 days after determining the breach occurred.

10. Children’s Privacy

Our services are not directed to individuals under the age of 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we learn we have inadvertently collected data from a child without verified parental consent, we will delete it immediately.

11. Policy Revisions

We reserve the right to modify this Privacy Policy at any time. Changes will take effect immediately upon posting to the website. The updated “Last Updated” date at the top of this policy indicates the latest revision.

12. Contact Information

To submit a privacy request, opt out of marketing, or exercise your legal rights, please contact us: