Privacy policy
This Policy explains what we collect, how we use it, and the choices you have when you use our website and services. By using the Site, you agree to this Policy.
This Policy covers visitors, account holders, and customers. It does not apply to third-party websites linked from our Site.
1) Information we collect
2) How we use your information
Provide the Service: create/manage accounts, process orders, deliver products, and provide customer support.
Improve & secure: monitor performance, fix bugs, prevent fraud/abuse, maintain the Site.
Communicate: transactional emails (orders, shipping, account), and—if you opt in—newsletters and promotions. You can unsubscribe anytime.
Compliance: tax/accounting, legal obligations, and enforcing our terms.
3) Cookies & similar technologies
4) Data security
We use industry-standard protections including TLS/SSL encryption in transit, hardened hosting, access controls, and routine updates. No method of transmission or storage is 100% secure; if we become aware of a data incident affecting you, we will notify you and regulators as required by law.
5) When we share information
We do not sell your personal information. We share limited data with trusted service providers who help us operate the Site. They may only use it to perform services for us, and must protect it.
We may also disclose information if required by law, to protect rights/safety, or in connection with a corporate transaction (e.g., merger or acquisition).
6) Data retention
Account & order records: kept as long as your account is active and as needed for tax/accounting, fraud prevention, and legal obligations (often 5–7 years for orders/invoices).
Support messages: retained as needed to resolve issues and improve service.
Marketing data: until you unsubscribe or request deletion, or after inactivity for a reasonable period.
When data is no longer required, we delete or de-identify it.
7) Your rights & choices
8) International transfers
We are US-based and may process data in the United States and other countries. When we transfer personal data from the EU/UK/EEA to countries without an adequacy decision, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) or equivalent mechanisms.
9) Children’s privacy
Our Site is for adults (18+). We do not knowingly collect data from minors. If you believe a minor has provided information, contact us and we will delete it.
10) Changes to this policy
We may update this Policy to reflect changes to our practices or applicable laws. Updates will be posted here with a new “Last updated” date. Material changes will be highlighted or communicated where required.
11) Contact
Questions or requests? Email us at rebecca@certified-pep.com.