Privacy Policy
Herb To Body
Effective Date: September 3, 2020 • Last Updated: March 3, 2026
This Privacy Policy describes how Herb To Body (“we,” “us,” or “our”) collects, uses, shares, and protects information about you when you visit herbtobody.com or purchase our products. Please read this policy carefully. By using the Site, you agree to the practices described here.
Table of Contents
- Who We Are
- Scope
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Cookies & Tracking Technologies
- Embedded Content
- Data Retention
- Your Rights Over Your Data
- Legal Basis (GDPR)
- Data Security — NY SHIELD Act
- Data Breach Notification
- SMS/MMS Communications
- Ordering & Payment Security
- Children’s Privacy (COPPA)
- Third-Party Links
- International Users
- Changes to This Policy
- Governing Law
- Contact Us
1. Who We Are
Herb To Body is a wellness brand offering high-quality natural herbal supplement products. Our address is PO Box 1087, Yonkers, NY 10703. Our website is herbtobody.com.
You can reach our privacy team at [email protected] or 914-713-5226. We aim to respond to all privacy inquiries within five (5) business days.
2. Scope of This Policy
This Privacy Policy applies to all personal information collected through the Site, by email, by phone, and through any other interactions you have with Herb To Body. It does not apply to third-party websites linked from our Site; those sites are governed by their own privacy policies.
3. Information We Collect
We collect the following categories of personal information:
A. Information You Provide Directly
- Name, email address, billing and shipping addresses, and phone number when you create an account or place an order
- Payment information submitted at checkout (we do not store full card numbers; see Section 14)
- Communications you send us via email, phone, or customer support channels
- SMS/text opt-in consent (see Section 13)
B. Information Collected Automatically
- IP address, browser type, device type, and operating system
- Pages visited, session duration, clicks, referring URLs, and purchase behavior
- Cookie identifiers and advertising pixel data (see Section 6 for a full list of technologies deployed)
C. User-Generated Content
- Product reviews, comments, or uploaded media, along with the associated IP address and timestamp
4. How We Use Your Information
We use your information only for the following specific purposes. We will not use your information for any purpose that is materially different from what is described here without obtaining your consent or updating this policy.
- Order fulfillment: processing payments, arranging shipping, handling returns and exchanges
- Account management: maintaining your purchase history and preferences
- Customer communications: sending order confirmations, shipping notifications, and support responses
- Marketing (opt-in only): sending promotional emails or SMS messages to customers who have affirmatively opted in
- Site improvement: analyzing traffic patterns and user behavior using analytics tools to improve our products and website
- Advertising: serving targeted advertisements to visitors through third-party platforms (see Section 5)
- Fraud and security: detecting and preventing fraudulent transactions, unauthorized access, and other harmful activity
- Legal compliance: meeting our obligations under applicable law, including tax, accounting, and consumer protection requirements
5. How We Share Your Information
A. Named Service Providers
We share your information with the following categories of service providers who process it on our behalf, subject to written data protection agreements:
- Payment processing: Stripe, Inc. (stripe.com/privacy)
- Shipping and fulfillment: UPS, USPS, FedEx, and other carriers as needed
- Email marketing: Klaviyo, Inc. (klaviyo.com/legal/privacy-policy)
- SMS marketing: Postscript or equivalent TCPA-compliant platform (postscript.io/privacy)
- Website analytics: Google Analytics — we use IP anonymization (policies.google.com/privacy)
- Advertising and remarketing: Meta (Facebook) Pixel and Google Ads conversion tracking
- E-commerce platform: WooCommerce, hosted on our managed server (automattic.com/privacy)
B. Business Transfers
If Herb To Body is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you at least thirty (30) days before any such transfer.
C. Legal Disclosures
We may disclose your information when required by law, subpoena, court order, or governmental authority, or when reasonably necessary to protect the rights, property, or safety of Herb To Body, our customers, or others.
D. Aggregated / De-identified Data
We may share aggregated or de-identified data that cannot reasonably be used to identify you with business partners or for public reporting.
6. Cookies and Tracking Technologies
We deploy the following specific tracking technologies on the Site:
- Strictly Necessary Cookies: Cannot be disabled. Required for shopping cart, checkout, and login sessions.
- Functional Cookies: Remember your preferences such as language, region, and recently viewed items.
- Analytics — Google Analytics: Tracks aggregate traffic and behavior with IP anonymization.
- Marketing — Meta (Facebook) Pixel: Tracks conversions and enables custom audience targeting.
- Marketing — Google Ads: Tracks conversions and enables remarketing on Google’s network.
You may manage cookie preferences through your browser settings. EEA/UK visitors will be asked for explicit consent before non-essential cookies are placed.
7. Embedded Content from Third Parties
Our Site may display embedded content from YouTube, Instagram, or other third-party services. When you interact with this content, those third parties may collect data and set cookies independently. We are not responsible for their privacy practices.
8. Data Retention
We retain personal information for the following specific periods:
- Order and transaction records: 7 years (tax and accounting compliance)
- Customer account information: while active, plus 2 years after last login or purchase
- Email marketing consent records: 5 years
- SMS opt-in and opt-out records: 4 years (TCPA compliance)
- Customer support communications: 3 years from resolution
- Analytics and behavioral data: up to 26 months, then deleted or anonymized
- Security and access logs: 12 months
9. Your Rights Over Your Data
All Customers
- Access: Request a copy of the personal information we hold about you
- Correction: Ask us to correct inaccurate or incomplete data
- Deletion: Request deletion of your personal information (subject to legal retention obligations)
- Restriction: Ask us to limit how we process your data
- Objection: Object to processing based on our legitimate interests
- Portability: Request your data in a portable, machine-readable format
California Residents (CCPA/CPRA)
California residents have the right to: (a) know what personal information we collect, use, and disclose; (b) delete personal information; (c) correct inaccurate information; (d) opt out of the sale or sharing of personal information; and (e) non-discrimination. To submit a CCPA request, email [email protected] with subject line “California Privacy Request.”
Note: We do not currently meet the CCPA revenue or data volume thresholds. We nonetheless voluntarily honor CCPA-style requests from all customers.
EEA / UK Residents (GDPR)
If you are in the EEA or UK, you have all rights listed above under GDPR, plus the right to lodge a complaint with your local supervisory authority.
10. Legal Basis for Processing (GDPR)
For EEA and UK residents, we process your personal data under the following legal bases:
- Contract (Art. 6(1)(b)): Processing necessary to fulfill your order and provide customer support
- Legitimate Interests (Art. 6(1)(f)): Fraud prevention, security, and analytics
- Consent (Art. 6(1)(a)): Marketing emails, SMS, and non-essential cookies — withdrawable at any time
- Legal Obligation (Art. 6(1)(c)): Tax and consumer protection compliance
11. Data Security — NY SHIELD Act Compliance
Administrative Safeguards
- A designated employee oversees our data security program
- Periodic risk assessments to identify and address vulnerabilities
- Employee training on data privacy and security practices
- Vendor due diligence: service providers contractually agree to maintain appropriate security
Technical Safeguards
- SSL/TLS encryption for all data transmitted through the Site
- Encrypted storage of personal data on secure, managed servers
- Firewall and anti-malware protections
- PCI DSS-compliant payment processing through Stripe
- Access controls limiting personal data access to authorized personnel only
Physical Safeguards
- Secure server hosting with physical access controls
- Secure disposal of any physical records containing personal information
Despite these measures, no method of transmission over the internet is completely secure.
12. Data Breach Notification
In the event of a security breach affecting New York residents, we will notify affected individuals within thirty (30) days of discovery, consistent with the December 2024 amendment to the NY SHIELD Act. Notifications will include: (a) what happened; (b) categories of information involved; (c) steps we are taking; and (d) contact information for questions. We will also notify the New York Attorney General and other regulatory bodies as required by law.
13. SMS/MMS Communications — TCPA Compliance
With your prior express written consent, we may send you automated text messages (SMS/MMS) regarding order updates, account activity, and promotional offers.
By opting in, you acknowledge:
- Message and data rates may apply depending on your mobile carrier and plan
- Marketing messages are sent only between 8:00 AM and 9:00 PM in your local time zone (TCPA quiet hours)
- Message frequency varies based on account activity and promotions
- Opt out at any time by replying STOP. We will process your opt-out within 24 hours
- Reply HELP for assistance, or contact [email protected]
We retain SMS opt-in and opt-out records for 4 years (TCPA compliance). We do not share your mobile number with unaffiliated third parties for marketing purposes.
14. Ordering and Payment Security
All order data is transmitted using SSL/TLS encryption. We process payments through Stripe, Inc., a PCI DSS Level 1 certified payment processor. We do not store your full credit card number; only the last four digits are retained for reference. Stripe’s privacy policy: stripe.com/privacy.
15. Children’s Privacy — COPPA Compliance
This Site is not directed to children under thirteen (13) and we do not knowingly collect personal information from children under 13, in compliance with COPPA. If you believe your child has provided us with personal information, contact us at [email protected] and we will promptly delete it.
16. Links to Third-Party Websites
The Site may contain links to third-party websites not owned or controlled by Herb To Body. This Privacy Policy applies only to our Site. We encourage you to review the privacy policies of any third-party sites you visit.
17. International Users
The Site is operated from the United States. If you access the Site from outside the U.S., your information will be transferred to and processed in the United States. By using the Site, you consent to this transfer. Where required, we implement appropriate safeguards for international data transfers.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date, post a prominent notice on the Site, and where required notify affected customers by email. Changes take effect thirty (30) days after posting.
19. Governing Law
This Privacy Policy is governed by the laws of the State of New York. Any dispute arising under this policy shall be subject to the exclusive jurisdiction of the courts located in Westchester County, New York, without regard to conflict of law provisions.
20. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

















