Privacy policy

Last updated: October 6, 2025

Cindy & Co (“Cindy & Co,” “we,” “us,” or “our”) respects your privacy and is committed to safeguarding the personal information you share with us. This Privacy Policy explains what we collect, how we use it, with whom we disclose it, and the choices you can make about your information when you visit, interact with, or make a purchase from our website and related services (collectively, the “Services”).

By using the Services, you agree to this Privacy Policy. If you do not agree, please discontinue use of the Services.

1) Scope & Audience

This Privacy Policy applies to individuals located in the United States who access our website, contact customer support, sign up for communications, or purchase our products. It also applies to information collected offline where we provide notice of this Policy. This Policy does not govern the privacy practices of any other company.

2) Information We Collect

We collect information that identifies, relates to, describes, or could reasonably be linked with you (“personal information”). The categories we may collect include:

  • Identifiers & Contact Details: name, billing and shipping address, email address, telephone number.
  • Commercial Information: products viewed, cart activity, wish lists, purchase history, returns, customer service interactions.
  • Payment Information: payment card type, tokenized payment data, transaction totals, authorization codes (we do not store full primary account numbers).
  • Device/Technical Data: IP address, device identifiers, browser type and version, operating system, language settings, pages visited, time stamps, referring/exit pages.
  • Geolocation Data: general (city/state/region) location inferred from IP address; we do not collect precise geolocation.
  • User Content & Preferences: product reviews, survey responses, communication preferences.
  • Inferences: preferences, interests, and purchase propensities derived from the above.

We do not request or intentionally collect sensitive health information. Because we sell personal care products, you may voluntarily share skin concerns or allergies; treat any such sharing as optional and do not include medical details you are uncomfortable disclosing.

3) Sources of Information

We collect personal information:

  • Directly from you (checkout, account creation, contact forms, reviews).
  • Automatically via cookies, pixels, and similar technologies when you browse or interact with the Services.
  • From service providers that support transactions, fraud prevention, analytics, marketing, fulfillment, and customer support.
  • From other parties you direct us to contact or integrate with (e.g., if you share an order as a gift recipient’s address).

4) How We Use Information (Purposes)

We use personal information for the following business purposes:

  • Order Processing & Fulfillment: process payments, manage orders, ship products, handle returns/exchanges, and provide customer support.
  • Account Management: create, maintain, and secure your account; remember preferences.
  • Safety & Fraud Prevention: authenticate transactions, monitor for suspicious activity, protect the Services, and enforce our Terms.
  • Service Improvement & Personalization: analyze usage, improve site performance, tailor product recommendations and content.
  • Marketing & Communications: send transactional messages (order confirmations, shipping updates) and—if permitted—promotional messages (offers, product launches). You may opt out of marketing at any time.
  • Legal & Compliance: maintain records, comply with applicable law, respond to lawful requests, and protect our rights and users.

5) Cookies & Similar Technologies

We use cookies and similar tools to:

  • enable core site functionality (e.g., cart, checkout, account login),
  • measure site performance (page loads, errors, analytics), and
  • support relevance (remembering items, reducing friction at checkout).

You can control cookies via your browser settings. Disabling certain cookies may affect site functionality and your ability to check out smoothly. Where legally required, we honor browser-level opt-out signals for certain advertising or sale/sharing choices.

6) How We Disclose Information

We disclose personal information only as described below and consistent with applicable law:

  • Service Providers/Contractors: payment processing, fraud prevention, fulfillment and logistics, customer support, IT/hosting, analytics, and email communications—bound by contractual obligations to use data only to provide services to us.
  • Business Transfers: as part of or during negotiations for a merger, sale of assets, financing, or acquisition.
  • Legal & Safety: to comply with law or legal process, enforce our terms, or protect the rights, property, or safety of Cindy & Co, our customers, or others.
  • Affiliates: within our corporate family for the purposes listed in this Policy.

We do not rent or sell your personal information. We may “share” personal information in the sense defined by certain state privacy laws (e.g., for cross-context behavioral advertising). See “Your State Privacy Rights” below for how to opt out.

7) Retention

We retain personal information only as long as necessary to fulfill the purposes in this Policy, including to meet legal, tax, and accounting requirements, resolve disputes, and enforce agreements. Retention periods vary by data type and legal requirements. When no longer needed, we will delete or de-identify information consistent with our data retention practices.

8) Security

We maintain administrative, technical, and physical safeguards designed to protect personal information (including encrypted transport of payment data and access controls). No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and using a unique, strong password.

9) Children’s Privacy

Our Services are intended for individuals 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can delete it.

10) Marketing Choices

  • Email: You can opt out of promotional emails by using the unsubscribe instructions in those emails or by contacting us. Transactional emails (e.g., order updates) will still be sent.
  • Cookies/Ads: Manage browser settings to limit cookies. Where required by law, we honor applicable opt-out signals for targeted advertising or sale/sharing.

11) Your State Privacy Rights (U.S.)

Depending on your state (for example, California, Colorado, Connecticut, Utah, Virginia), you may have the right to:

  • Access/Know the personal information we maintain about you.
  • Correct inaccuracies in your personal information.
  • Delete personal information, subject to legal exceptions.
  • Portability of certain personal information you provided to us.
  • Opt Out of processing for targeted advertising or certain “sharing” of personal information.

How to exercise your rights: Send your request (Access/Deletion/Correction/Portability/Opt-Out) to our support email with the subject line “Privacy Request.” We will verify your identity (e.g., by matching account details or requesting reasonable additional information). You may designate an authorized agent; we may require proof of authorization and additional verification. We will not discriminate against you for exercising privacy rights.

If we deny a request (where permitted by law), you may submit an appeal by replying to our response email with the subject line “Privacy Appeal.” We will inform you of any further options available to you under your state’s law.

12) Do Not Track

Some browsers send “Do Not Track” signals. Our Services respond to legally required signals (including applicable opt-out preference signals). Otherwise, our data practices are described in this Policy.

13) International Visitors

Our Services are directed to U.S. customers and our systems are located in the United States. If you access the Services from outside the U.S., you understand your information may be transferred to, stored, and processed in the U.S., which may have different data protection laws than your jurisdiction.

14) Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. The “Last updated” date shows the effective date. Material changes will be posted on this page.

15) Contact Us

Questions about this Privacy Policy or your personal information?

Email: cindyandcoinc@gmail.com

Location: United States