Privacy Policy
Effective Date: August 6, 2026
Last Updated: August 6, 2026
This Privacy Policy describes how Zengoddess Wellness, LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit zengoddesswellness.com, interact with our WooCommerce storefront, download resources, subscribe to newsletters, or utilize our SMS and related digital services.
1. Scope & Applicability
This policy applies to all visitors, registered users, and customers accessing our website, associated landing pages, WooCommerce store, email campaigns, SMS marketing channels, and digital downloads.
2. Categories of Information We Collect
- Voluntarily Provided Information: Name, billing address, shipping address, email address, phone number, payment details, purchase history, customer support records, account credentials, survey responses, and review contributions.
- Automatically Collected Information: IP address, browser type, operating system, unique device identifiers, referring URL/pages visited, clickstream data, time spent on pages, and precise/approximate location data.
- Sensitive Personal Data: If you voluntarily provide wellness preferences or health-related information through quizzes, digital journals, or customer inquiries, this is processed strictly with your explicit consent.
3. Third-Party Processors & Data Sharing
We do not sell your personal information for monetary payment. We share data with third-party service providers bound by strict contractual obligations to handle data solely on our behalf:
| Category | Service Provider(s) | Purpose of Sharing |
| E-Commerce & Hosting | WooCommerce / WordPress | Cart functionality, order processing, and account management. |
| Payment Processing | Stripe, PayPal | Secure payment transactions. (We do not store full card numbers). |
| Email Marketing | Mailchimp (or successor platform) | Dispatching transactional emails, newsletters, and promotional offers. |
| SMS Communications | SMS Gateway Provider (e.g., Twilio) | Delivering transactional and marketing text updates. |
| Analytics & Advertising | Google Analytics, Meta (Facebook Pixel), Pinterest, YouTube | Web performance analysis, conversion tracking, and retargeting ads. |
| Fulfillment & Logistics | USPS, UPS, FedEx | Printing shipping labels and fulfilling physical orders. |
4. Cookies, Analytics & Tracking Technologies
We use essential, analytical, functional, and targeting cookies, pixels, and web beacons.
- Essential Cookies: Necessary for core functionality, such as keeping items in your WooCommerce shopping cart and securing checkout.
- Analytics & Marketing Cookies: Used to evaluate site traffic and deliver tailored ads.
- Consent & Preferences: Non-essential cookies are disabled by default for visitors in applicable jurisdictions until affirmative consent is given via our Cookie Banner. You can manage or revoke cookie consent at any time through your web browser settings.
5. SMS Communications & TCPA Compliance
By opting into our SMS marketing program, you expressly consent to receive recurring automated promotional and transactional text messages at the mobile number provided.
- Opt-In: Mobile opt-in data and consent will not be sold, rented, or shared with third parties for marketing/promotional purposes.
- Conditions: Consent to receive text messages is not a condition of purchase. Message and data rates may apply. Message frequency varies.
- Opt-Out & Help: Reply STOP to any text message to opt out immediately. Reply HELP for customer support or contact us via our website.
6. Data Retention Schedule
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal/tax requirements, or resolve disputes.
| Data Category | Retention Period |
| Order & Financial Records | Retained for 7 years to satisfy tax, accounting, and legal requirements. |
| Marketing Email & SMS Contacts | Retained until you unsubscribe or opt out, plus 30 days for purge completion. |
| Customer Support Communications | Retained for 3 years following resolution. |
| Web Server Logs & Analytics Data | Retained for 14 months, then anonymized or deleted automatically. |
7. U.S. State Privacy Rights (Texas TDPSA & California CCPA/CPRA)
If you are a resident of Texas (under the Texas Data Privacy and Security Act – TDPSA) or California (under the CCPA/CPRA), you are entitled to specific privacy rights:
- Right to Know / Access: Request confirmation of whether we process your data and obtain a portable copy of it.
- Right to Correct: Request corrections to inaccurate personal data.
- Right to Delete: Request deletion of personal data provided by or obtained about you.
- Right to Opt-Out: Opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions.
- Sensitive Data Protection: Under the TDPSA, we will not process sensitive personal data (e.g., precise geolocation, health data, biometric data) without obtaining your prior explicit consent.
- Appeals Process (Texas Residents): If we refuse to take action on your consumer request, you may appeal our decision within 30 days of receipt of our response by contacting us with the subject line “Privacy Appeal.” If your appeal is denied, Texas residents may contact the Texas Attorney General.
8. International Visitors & GDPR/UK GDPR Rights
If you visit our website from the European Economic Area (EEA) or the United Kingdom (UK), our legal basis for collecting and using personal data depends on the information concerned:
- Contractual Necessity: Processing orders, digital downloads, and fulfilling agreements.
- Legitimate Interests: Fraud prevention, website optimization, and customer service.
- Consent: Email newsletters, SMS communications, and targeting cookies.
Your GDPR Rights: You have the right to access, rectify, erase, restrict processing, object to processing, and request data portability. You also have the right to lodge a complaint with your local Data Protection Authority.
9. Data Security & Data Breach Notification Obligations
We enforce appropriate administrative, technical, and physical security measures (including SSL/TLS encryption, restricted access controls, and firewall defenses) to safeguard personal data.
In the event of a security breach compromising your unencrypted personal information:
- We will notify affected individuals without unreasonable delay, in accordance with applicable laws (including Texas Business & Commerce Code § 521.053).
- If a breach impacts 250 or more Texas residents, notice will be provided to the Texas Attorney General no later than 60 days after determining the breach occurred.
10. Children’s Privacy
Our services are not directed to individuals under the age of 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we learn we have inadvertently collected data from a child without verified parental consent, we will delete it immediately.
11. Policy Revisions
We reserve the right to modify this Privacy Policy at any time. Changes will take effect immediately upon posting to the website. The updated “Last Updated” date at the top of this policy indicates the latest revision.
12. Contact Information
To submit a privacy request, opt out of marketing, or exercise your legal rights, please contact us:
- Entity: Zengoddess Wellness, LLC
- Website: zengoddesswellness.com
- Contact Page: zengoddesswellness.com/contactus
- Privacy Officer Email: hello@zengoddesswellness.com