1. Introduction & Scope
This Privacy Policy explains how SHAPERX LLC (“SHAPERX,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit, access, or make a purchase from https://www.shaperx.com (the “Site”) or interact with us through related services, including email, SMS marketing (via Klaviyo SMS), advertising platforms (such as TikTok, Meta/Facebook, and Google), and Amazon Buy With Prime (collectively, the “Services”).
By accessing or using our Site or Services, you acknowledge that you have read and understood this Privacy Policy.
1.1 Legal Applicability
This Privacy Policy is intended to comply with relevant privacy laws, including:
✅ California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
✅ General Data Protection Regulation (GDPR) & UK GDPR (where applicable)
✅ Telephone Consumer Protection Act (TCPA) for SMS marketing
✅ Children’s Online Privacy Protection Act (COPPA)
✅ CAN-SPAM Act
✅ Other U.S. state privacy laws where applicable (Virginia, Colorado, Connecticut, Utah, etc.)
While SHAPERX primarily ships within the United States (including California), EU/UK or other international visitors who access our Site are provided applicable rights under GDPR/UK GDPR where legally required.
1.2 Controller Information
When applicable under data protection laws, SHAPERX LLC is the “data controller” responsible for your personal information.
Company Name: SHAPERX LLC
Address: 732 S 6TH ST STE R LAS VEGAS, NV, 89101, USA
Email (for Privacy Requests): info@shaperx.com
1.3 Who This Policy Applies To
This policy applies to:
✅ Visitors browsing our Site
✅ Customers placing orders
✅ Individuals subscribing to SMS or email marketing
✅ Users interacting with advertisements, cookies, or tracking tools
✅ Individuals contacting us for support or marketing queries
1.4 Acceptance & Consent
By using our Site or Services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our Site.
Where legally required (such as under GDPR), we will request your explicit consent for certain processing activities, such as marketing or cookie-based tracking.
1.5 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Changes will be posted on this page with an updated “Last Updated” date.
Your continued use of our Site after such changes constitutes your acceptance of the updated policy.
2. Personal Information We Collect
We collect different types of personal information depending on how you interact with our Site and Services. “Personal Information” means any information that can identify, relate to, describe, or be reasonably associated with an individual.
We collect the following categories of Personal Information:
2.1 Information You Provide Directly
We collect information that you voluntarily provide when you take certain actions, including when you place an order, create an account, subscribe to marketing communications (including SMS), contact customer support, or participate in promotions.
This may include:
|
Data Type
|
Examples
|
|
Contact Information
|
First name, last name, email address, phone number, shipping/billing address
|
|
Order Information
|
Products ordered, purchase history, payment method (credit card, Shop Pay, Amazon Pay, PayPal, Google Pay)
|
|
Account Information (if account is created)
|
Username, password, email, preferences
|
|
Communication Preferences
|
Marketing opt-in choices (email/SMS), subscription preferences
|
|
Support Information
|
Messages, inquiries, complaints
|
⚠️ Note: Payment card information is processed securely by third-party payment providers and is not stored by SHAPERX.
2.2 Information Automatically Collected (Device & Usage Data)
When you visit our Site, we automatically collect technical and usage information through cookies, pixels, log files, web beacons, and similar technologies.
This may include:
|
Data Type
|
Examples
|
|
Device Information
|
IP address, browser type, OS, device type, time zone
|
|
Usage Activity
|
Pages viewed, time spent, referring pages/URLs, clicks, scroll behavior
|
|
Analytics Information
|
E-commerce events (add to cart, checkout, purchase), bounce rates, conversion data
|
|
Advertising Interaction Data
|
Engagement with ads on platforms such as TikTok, Meta/Facebook, Google
|
2.3 TikTok Maximum-Level Data Sharing (Pixel, Events API & Advanced Matching)
When you interact with our Site under our Maximum data sharing level with TikTok, the following categories of information may be shared with TikTok for marketing, analytics, and audience matching purposes:
✅ Events: Add Payment Info, Add to Cart, Complete Payment, Initiate Checkout, Search, View Content, Complete Registration.
✅ Identifiers: Email (hashed), Phone Number (hashed), First Name, Last Name, ZIP Code, City, State, Country/Region.
✅ Shopify API data (Order & Customer-Level Data).
✅ Automatically generated device identifiers & engagement metrics.
✅ Data may be shared via TikTok Pixel, Shopify APIs, Events API, and In-App Checkout integrations.
2.4 SMS & Email Marketing Enrollment (Klaviyo)
If you subscribe to SMS or email lists (including abandoned cart reminders), we collect:
✅ Phone number
✅ Email address
✅ Name (where provided)
✅ Engagement data (opens, clicks, replies)
✅ Purchase intent signals (e.g., abandoned cart triggers)
2.5 Information from Third Parties
We may collect information from third-party partners such as:
|
Source
|
Information Provided
|
|
Shopify (e-commerce host)
|
Order metadata, customer profile details
|
|
Payment Processors (Amazon Pay, Shop Pay, PayPal, Google Pay, credit card gateways)
|
Payment status confirmation
|
|
Analytics Providers (Google Analytics, TikTok Analytics, Meta Pixel)
|
Performance & engagement metrics
|
|
Marketing Partners (Klaviyo, TikTok Ads, Meta/Facebook Ads)
|
Attribution + engagement behavior
|
|
Amazon Buy With Prime
|
Checkout and shipping-related details
|
2.6 Shipping & Fulfillment Partners
When shipping your order, we may receive and share delivery-related information (e.g., tracking updates) with logistics providers such as USPS, UPS, FedEx, DHL, or other carriers.
2.7 Inferences
In some cases, we may generate inferred information based on browsing or purchase history, such as preferences, likely purchasing behavior, or marketing segment classification.
3. How We Use Personal Information
We use the Personal Information we collect for various business and commercial purposes in accordance with applicable privacy laws, including the GDPR, CCPA, and CPRA. Below is a detailed breakdown of our purposes:
3.1 To Process Orders and Provide Our Services
We use your Personal Information to:
✅ Process and fulfill orders
✅ Verify payment details and complete transactions
✅ Provide order confirmations, shipping updates, and digital receipts
✅ Facilitate returns, refunds, or customer service support
✅ Enable Amazon Buy With Prime checkout functionality
Legal basis (GDPR/UK GDPR):
📍 Performance of a contract; legitimate interests (customer service support)
3.2 To Manage Customer Accounts (If Applicable)
✅ Enable account creation and login
✅ Maintain account history and preferences
✅ Provide personalized dashboard access
Legal basis:
📍 Performance of a contract; legitimate interests (user convenience)
3.3 To Communicate With You
✅ Respond to inquiries and provide support
✅ Send order updates, notifications, and confirmations
✅ Deliver service-related announcements
Legal basis:
📍 Legitimate interests; performance of a contract
3.4 To Send Marketing Communications (Email & SMS via Klaviyo)
✅ Send promotional content, product launches, special offers
✅ Deliver cart abandonment reminders
✅ Track engagement with marketing messages
📌 For SMS: Consent is required under TCPA and CTIA guidelines. You can opt out at any time by replying STOP.
Legal basis:
📍 Consent (for SMS and certain email marketing under GDPR); legitimate interests (U.S. direct marketing)
3.5 To Provide Personalized Advertising & Retargeting (TikTok, Meta/Facebook, Google, etc.)
✅ Use tracking technologies (e.g., TikTok Pixel, Meta Pixel, Google Ads)
✅ Share hashed identifiers with ad platforms for audience matching
✅ Customize ads based on browsing and purchase activity
✅ Measure ad performance
📌 Under CPRA, this may be considered “sharing” of personal information for cross-context behavioral advertising. Users may opt out via the “Do Not Sell or Share My Personal Information” link.
Legal basis:
📍 Consent (Europe); legitimate interests (marketing); CPRA-compliant opt-out provisions
3.6 TikTok Maximum Data Sharing Optimization
At the “Maximum” level of data sharing, we transmit additional customer events, identifiers, and behavior data through TikTok Pixel, Events API, Advanced Matching, and Shopify APIs to improve ad delivery and campaign optimization.
Purpose:
✅ Enhance performance of TikTok campaigns
✅ Increase relevance of ad targeting
✅ Improve conversion tracking
3.7 To Improve and Optimize Our Site & Services
✅ Analyze traffic patterns and customer behavior
✅ Identify usability trends
✅ Diagnose technical issues
✅ Enhance product offerings
Legal basis:
📍 Legitimate interests (service improvement)
3.8 To Detect Fraud and Ensure Security
✅ Monitor orders for fraud risk
✅ Authenticate users
✅ Detect abnormal site activity
Legal basis:
📍 Legitimate interests; legal obligations
3.9 To Comply with Legal Obligations
✅ Maintain tax, accounting, and audit records
✅ Respond to lawful requests (e.g., subpoenas, investigations)
✅ Comply with consumer rights requests (CPRA/GDPR)
Legal basis:
📍 Legal obligation
3.10 For Any Purpose with Your Explicit Consent
✅ Where required, we will ask for your consent before using your information for a specific purpose not covered above.
4. Cookies, Analytics, and Tracking Technologies
We use cookies, pixels, tags, web beacons, scripts, and similar tracking technologies (“Cookies”) to enhance your browsing experience, analyze website performance, customize content, and support advertising and marketing efforts across platforms such as TikTok, Meta/Facebook, Google, and Klaviyo.
4.1 What Are Cookies?
Cookies are small data files stored on your device (e.g., computer, smartphone) when you visit our Site. They allow us and third-party partners to recognize your browser and gather information about your usage patterns and preferences.
4.2 Types of Cookies We Use
|
Cookie Type
|
Purpose
|
|
Strictly Necessary Cookies
|
Required for core Site functionality (e.g., checkout process, page navigation).
|
|
Performance & Analytics Cookies
|
Collect anonymous usage data to improve functionality (e.g., Google Analytics, Shopify Analytics).
|
|
Functional Cookies
|
Remember user preferences such as language, region, or login details.
|
|
Advertising & Retargeting Cookies
|
Track browsing behavior to display personalized ads on TikTok, Meta/Facebook, Google, etc. For example, TikTok Pixel records engagement events such as Add to Cart or Complete Payment.
|
|
Social Media Cookies
|
Enable interactions with social media platforms (e.g., liking or sharing products).
|
4.3 Third-Party Tracking Technologies We Use
|
Provider
|
Purpose
|
Examples of Data Processed
|
|
Google Analytics
|
Tracks traffic & engagement
|
Pages visited, session duration, IP address (anonymized in some regions)
|
|
TikTok Pixel & Events API (Maximum Level)
|
Ad optimization & conversion tracking
|
Hashed email/phone, event triggers, order information
|
|
Meta (Facebook/Instagram) Pixel
|
Ad retargeting & lookalike audience creation
|
Engagements, purchases, website activity
|
|
Klaviyo (Email/SMS Analytics)
|
Tracks email/SMS campaign engagement
|
Open rate, click rate, purchase attribution
|
|
Shopify Analytics
|
E-commerce insights
|
Cart actions, checkout sessions
|
|
Amazon Buy With Prime
|
Enables embedded checkout functionality
|
Purchase flow data, customer region
|
4.4 How We Use Analytics
Analytics cookies help us:
✅ Understand which pages are most visited
✅ Track conversion performance (e.g., add-to-cart to purchase)
✅ Improve customer journey flow
✅ Identify technical performance issues
Depending on your region, certain analytics tools (e.g., Google Analytics 4) may be configured to anonymize or hash IP addresses as required under GDPR or similar regulations.
4.5 Targeted & Behavioral Advertising
We may use cookies and tracking tools to:
✅ Deliver personalized ads based on prior browsing/purchase behavior
✅ Retarget visitors who did not complete a purchase
✅ Create audience segments (e.g., cart abandoners, frequent buyers)
✅ Share hashed customer identifiers with advertising platforms
📌 Under CPRA, this may be considered “sharing” for cross-context behavioral advertising. You may opt out via our “Do Not Sell or Share My Personal Information” link.
4.6 How to Manage or Disable Cookies
Depending on your location, you may:
✅ Adjust cookie preferences via a popup consent banner (GDPR regions)
✅ Disable non-essential cookies in your browser settings
✅ Use opt-out tools provided by third parties (e.g., Google Analytics Opt-Out Add-on)
Browser-level controls:
-
Chrome: Settings → Privacy & Security → Cookies
-
Safari: Preferences → Privacy
-
Firefox: Preferences → Privacy & Security
Please note that disabling certain cookies may affect Site functionality, particularly during checkout.
4.7 “Do Not Track” Signals
Some browsers allow you to send a “Do Not Track” (DNT) signal. At this time, our Site does not respond to DNT signals due to industry-wide lack of a consistent standard. However, you can still manage tracking preferences via the options listed above.
5. TikTok Maximum-Level Data Sharing Disclosure
We use TikTok for advertising, audience targeting, and performance measurement. To optimize campaign effectiveness and reach more customers, we have enabled the Maximum data-sharing level as provided by the TikTok for Shopify integration. This setting uses multiple data transmission methods, including the TikTok Pixel, Events API, Advanced Matching, Shopify APIs, and In-App Checkout tools.
By interacting with our Site, certain Personal Information may be shared with TikTok for marketing and analytics purposes, subject to applicable privacy laws and user opt-out rights.
5.1 What Data Is Shared with TikTok at the Maximum Level?
When using the Maximum sharing option, TikTok may receive the following categories of information:
✅ Event Actions Triggered on the Site
-
Add to Cart
-
Initiate Checkout
-
Add Payment Info
-
Complete Payment (Purchase)
-
View Content (Product views)
-
Search queries
-
Complete Registration (account or subscription sign-up)
✅ Identifiers for Advanced Matching (hashed before transfer where applicable):
✅ Transactional & Behavioral Data via Shopify/Order APIs:
✅ Device & Technical Data (e.g., via Pixel and Events API):
-
IP address
-
Browser type
-
Session activity
-
User agent details
-
Clickstream data
5.2 How TikTok Uses the Shared Data
TikTok may use this information to:
✅ Deliver, personalize, and optimize ads for you and similar customers
✅ Assign conversions and measure campaign effectiveness
✅ Build audiences and lookalike segments
✅ Support e-commerce attribution and cross-device tracking
For more details on how TikTok processes data, please review TikTok’s Privacy Policy (available directly on TikTok’s official website).
5.3 User Choice and Opt-Out
Under the CCPA/CPRA, sharing personal information for cross-context behavioral advertising may be considered “sharing.” You can opt out of TikTok-based behavioral advertising at any time by using our “Do Not Sell or Share My Personal Information” link located on our Site or by contacting us at info@shaperx.com.
European visitors will only have their data used for TikTok advertising where consent has been provided in compliance with GDPR/UK GDPR rules.
5.4 Legal Basis (Where GDPR Applies)
For residents of the EEA/UK, we rely on your explicit consent (where legally required) or our legitimate interests in marketing and performance optimization, unless overridden by your privacy rights.
6. Sharing of Personal Information with Third Parties
We share Personal Information with trusted third-party service providers and partners who help us operate our business, deliver our Services, and perform specific functions on our behalf. We do not sell Personal Information for monetary value. However, under the CPRA, certain sharing of information for advertising or marketing purposes may be classified as “sharing” or “cross-context behavioral advertising.”
Below are the categories of third parties with whom we may share Personal Information:
6.1 E-Commerce & Website Hosting (Shopify)
We use Shopify to power our online store. Shopify processes customer data, including order information, checkout activity, and device analytics, to support transactions, fraud detection, and secure payment processing.
📌 Shopify Privacy Policy is available via their official website.
6.2 Marketing & Advertising Partners
We share information with marketing and ad platforms to deliver targeted advertisements and analyze advertising performance.
|
Partner
|
Purpose
|
Data Potentially Shared
|
|
TikTok (Pixel, Events API, Advanced Matching, Shopify API integrations)
|
Targeted advertising and campaign optimization
|
Events, hashed identifiers, order data, engagement activity
|
|
Meta/Facebook & Instagram (Facebook Pixel)
|
Retargeting, audience building
|
Cookies, hashed email/phone, purchase events
|
|
Google Ads & YouTube Ads
|
Ad targeting and conversion tracking
|
Search & site activity, hashed identifiers
|
|
Klaviyo (Email & SMS marketing)
|
Campaign execution, cart recovery, behavior-based messaging
|
Email, phone number, purchase history, engagement metrics
|
6.3 Analytics & Performance Tools
We use analytics partners to understand visitor behavior, site performance, and customer engagement.
|
Provider
|
Purpose
|
|
Google Analytics
|
Tracks site usage, engagement metrics
|
|
Shopify Analytics
|
E-commerce reporting
|
|
TikTok & Meta Analytics
|
Ad performance attribution
|
6.4 Payment Processors & Financial Services
We share limited Personal Information as necessary to process payments securely.
|
Provider
|
Accepted Methods
|
|
Credit Card Processors (via Shopify Payments)
|
Visa, Mastercard, Amex, etc.
|
|
Shop Pay
|
Express checkout
|
|
PayPal
|
External wallet
|
|
Amazon Pay / Amazon Buy With Prime
|
Prime-enabled checkout
|
|
Google Pay
|
Digital wallet
|
📌 These services may collect your information independently in accordance with their own privacy policies.
6.5 Shipping, Fulfillment & Logistics Providers
We share delivery-related data (e.g., name, address, phone number) with shipping carriers such as USPS, UPS, FedEx, DHL, or other third-party logistics partners to fulfill your order.
6.6 Customer Support & Communication Platforms
We may share information with email or customer service tools used to
✅ send support messages,
✅ respond to inquiries,
✅ manage service tickets,
✅ trigger automated notifications.
6.7 Legal Compliance & Fraud Prevention
We may disclose Personal Information when necessary to:
✅ comply with applicable laws, regulations, subpoenas, or legal processes;
✅ protect the rights, property, or safety of SHAPERX, our customers, or others;
✅ detect, investigate, or prevent fraud or security breaches.
6.8 Business Transfers
If SHAPERX LLC is involved in a merger, acquisition, restructuring, financing, asset sale, or bankruptcy, Personal Information may be transferred to the successor entity as part of the business transaction.
7. Sale or Sharing of Personal Information Under the CPRA (California Residents)
Under the California Privacy Rights Act (CPRA), the terms “sell” and “share” have specific legal meanings that may differ from their everyday usage:
-
“Sell” means disclosing Personal Information to a third party in exchange for monetary or other valuable consideration.
-
“Share” means disclosing Personal Information to a third party for cross-context behavioral advertising, even if no money is exchanged.
7.1 Do We Sell Personal Information?
❌ We do not sell Personal Information for monetary compensation.
We do not provide customer data to third parties in exchange for direct payment.
7.2 Do We Share Personal Information for Cross-Context Behavioral Advertising?
✅ Yes. We may share Personal Information with third-party advertising partners (such as TikTok, Meta/Facebook, Google, and Klaviyo) in order to deliver personalized or targeted advertisements. Under CPRA, this activity may be considered “sharing.”
Categories of information that may be “shared” for advertising purposes may include:
✅ Identifiers (e.g., hashed email, hashed phone number, IP address)
✅ Internet or device activity data
✅ Commercial information (e.g., purchase history, cart activity)
✅ Inferred interests or preferences
7.3 Your Right to Opt Out of Sharing (CPRA)
If you are a California resident, you have the right to opt out of the “sharing” of your Personal Information for cross-context behavioral advertising.
You can exercise this right by:
✅ Clicking the “Do Not Sell or Share My Personal Information” link available on our Site, or
✅ Contacting us at info@shaperx.com
Once we receive and verify your request, we will stop sharing your Personal Information for advertising purposes as required by law.
7.4 Opt-Out for Minors
We do not knowingly “sell” or “share” Personal Information of consumers under the age of 16. If we become aware that we have inadvertently processed such data, we will take appropriate action to comply with applicable laws.
8. Your Privacy Rights (GDPR / CPRA / Other U.S. State Rights)
Depending on where you reside, you may have certain rights regarding your Personal Information under applicable laws such as the California Consumer Privacy Act (CCPA) as amended by the CPRA, the General Data Protection Regulation (GDPR), UK GDPR, and other U.S. state privacy laws (e.g., Virginia, Colorado, Connecticut, Utah).
Below is a summary of your rights and how you may exercise them.
8.1 California Residents (CPRA Rights)
If you are a resident of California, you have the following rights under the CPRA:
|
Right
|
Description
|
|
Right to Know / Access
|
Request disclosure of the categories or specific pieces of Personal Information we have collected about you.
|
|
Right to Delete
|
Request deletion of Personal Information we have collected, subject to lawful exceptions.
|
|
Right to Correct
|
Request correction of inaccurate Personal Information.
|
|
Right to Opt-Out of Sharing
|
Request that we stop sharing Personal Information for targeted advertising.
|
|
Right to Limit Use of Sensitive Personal Information (if applicable)
|
Restrict use of sensitive data (we currently do not process sensitive data beyond functional purposes such as shipping and fraud detection).
|
|
Right to Non-Discrimination
|
You will not be denied services or charged different prices for exercising privacy rights.
|
8.2 EU/UK Residents (GDPR / UK GDPR Rights)
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have the following rights (subject to applicable conditions and legal limitations):
|
Right
|
Description
|
|
Right of Access
|
Obtain confirmation and a copy of your Personal Information.
|
|
Right to Rectification
|
Request correction of inaccurate or incomplete Personal Information.
|
|
Right to Erasure (“Right to Be Forgotten”)
|
Request deletion of Personal Information under certain circumstances.
|
|
Right to Restrict Processing
|
Request limitation of processing in certain cases.
|
|
Right to Data Portability
|
Request Personal Information in a structured, commonly used format.
|
|
Right to Object
|
Object to processing based on legitimate interests or direct marketing.
|
|
Right to Withdraw Consent
|
If processing is based on consent, you may withdraw consent at any time.
|
8.3 Other U.S. State Residents
Residents of certain U.S. states (such as Virginia, Colorado, Connecticut, and Utah) may have similar rights, including:
✅ Access, delete, or correct information
✅ Opt out of targeted advertising
✅ Appeal our response where applicable
8.4 How to Exercise Your Rights
You may exercise your rights by:
📩 Emailing us at: info@shaperx.com
📍 Using the “Do Not Sell or Share My Personal Information” link on our Site (for California residents opting out of sharing)
8.5 Verification Requirement
To protect your security and comply with legal requirements, we may request additional information to verify your identity before processing a rights request. If we are unable to verify your identity, we may be unable to fulfill your request.
8.6 Authorized Agents (CPRA)
California residents may designate an authorized agent to submit a request on their behalf. We may require verification of both the agent’s authority and your identity.
9. Opt-Out of Targeted Advertising and SMS Marketing
You have the right to opt out of certain types of data processing, particularly where Personal Information is used for behavioral advertising or direct marketing (such as SMS or targeted ads). Below are the ways you may exercise these rights:
9.1 Opt-Out of Cross-Context Behavioral Advertising (CPRA)
If you are a California resident, you may opt out of the sharing of your Personal Information for cross-context behavioral advertising by:
✅ Clicking the “Do Not Sell or Share My Personal Information” link located on our Site, or
✅ Emailing us at info@shaperx.com
Once your request is verified, we will stop sharing your Personal Information for targeted advertising as required under the CPRA.
9.2 Opt-Out of Targeted Advertising in the EU/UK (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we will only use your Personal Information for targeted advertising where we have obtained your consent, and you may withdraw your consent at any time by adjusting your cookie settings or contacting us at info@shaperx.com.
9.3 Opt-Out of Email Marketing
You may unsubscribe from promotional emails by clicking the “unsubscribe” link at the bottom of any email we send. Please allow a reasonable time for us to process your request. You will still receive transactional or service-related emails such as order confirmations or shipping updates.
9.4 Opt-Out of SMS Marketing (Klaviyo SMS, TCPA Compliant)
If you have opted in to receive SMS marketing messages, you may opt out at any time by replying:
📍**“STOP”** – to stop receiving SMS marketing messages
📍**“HELP”** – to receive additional guidance
Standard message and data rates may apply. Opting out of SMS marketing will not opt you out of transactional text messages (e.g., messages related to your orders or support inquiries).
9.5 Opt-Out of Cookies and Tracking Technologies
You may control tracking technologies via:
✅ Your browser settings
✅ Device-level privacy controls
✅ Cookie consent banners (where required)
✅ Third-party ad platform settings (e.g., Facebook Ad Preferences, TikTok Ad Settings, Google Ad Settings)
Note: Disabling essential cookies may affect Site functionality and your ability to complete purchases.
10. Data Retention
We retain Personal Information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or regulatory obligations).
Below are typical retention periods:
|
Data Category
|
Typical Retention Period
|
Purpose
|
|
Order & transaction data
|
7 years
|
Legal, accounting & audit requirements
|
|
Customer account data
|
Active duration of account or until deletion request
|
|
|
Email/SMS marketing subscription
|
Until you unsubscribe or request deletion
|
|
|
Advertising & analytics data
|
Typically 12-36 months (may vary by platform)
|
|
|
Cookie/session data
|
Until expiration or browser deletion
|
|
|
Legal claims & fraud detection data
|
As required to protect legal rights
|
|
When Personal Information is no longer needed, we will delete, anonymize, or securely store it until deletion is possible.
11. Data Security
We use appropriate administrative, technical, and physical safeguards to protect Personal Information from unauthorized access, disclosure, loss, alteration, or misuse.
Security measures include:
✅ Encrypted payment processing (via PCI DSS-compliant providers)
✅ SSL/TLS encryption for Site data transmission
✅ Access control and authentication measures
✅ Secure data storage by reputable third-party providers such as Shopify
✅ Monitoring for fraudulent or suspicious activity
However, no method of transmission or storage is 100% secure. You acknowledge that transmitting data over the internet is done at your own risk. If we become aware of a data breach that affects your Personal Information, we will notify you as required by applicable laws.
12. International Data Transfers
Our company is based in the United States, and we primarily sell and ship products within the U.S. However, our Site may be accessed globally, and certain service providers may store or process Personal Information in countries outside your country of residence.
For international users, your data may be transferred to:
✅ The United States
✅ Canada
✅ European Union or United Kingdom (via Shopify’s infrastructure)
✅ Other regions where third-party providers (e.g., TikTok, Meta, Klaviyo, Google) operate
Where required by law (e.g., under GDPR/UK GDPR), we ensure such transfers are protected by appropriate safeguards such as:
✅ Standard Contractual Clauses (SCCs)
✅ Adequacy decisions
✅ Data Processing Agreements (DPAs)
By using our Site, you acknowledge that your data may be transferred and processed in jurisdictions that may have different data protection laws than your home country.
13. Children’s Privacy
Our Site and Services are not intended for individuals under the age of 16, and we do not knowingly collect or share Personal Information of children under 16 for advertising or other purposes.
-
If you are under 18, you may only use the Site with the involvement of a parent or legal guardian.
-
We do not knowingly “sell” or “share” Personal Information of consumers under 16 (as defined by CPRA).
-
If we learn that we have collected Personal Information from a child under 16 without appropriate consent, we will take steps to delete such information as required by law.
If you believe a child under 16 has provided us Personal Information, please contact us at info@shaperx.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When changes are made, we will update the “Last Updated” date at the top of this page.
Your continued use of our Site or Services after any update indicates your acceptance of the revised Privacy Policy.
Where legally required, we will notify you of material changes (e.g., via email or a prominent notice on the Site).
15. Contact Information & Privacy Requests
If you have questions about this Privacy Policy, our data practices, or would like to exercise your privacy rights, you may contact us at:
SHAPERX LLC
📍 732 S 6TH ST STE R LAS VEGAS, NV, 89101, USA
📩 Email (for Privacy Requests): info@shaperx.com
📌 California residents may also use the “Do Not Sell or Share My Personal Information” link available on our Site to opt out of data sharing for targeted advertising purposes.
16. SMS Marketing Terms (TCPA & Klaviyo Compliance)
By providing your phone number during checkout, subscribing via an opt-in form, or texting a keyword phrase, you expressly agree to receive recurring SMS messages from SHAPERX for marketing, promotional, and transactional purposes, including cart reminders and updates.
Key SMS terms:
✅ Consent is not a condition of purchase.
✅ Message frequency may vary.
✅ Message & data rates may apply.
✅ To unsubscribe, reply STOP at any time.
✅ For help, reply HELP.
✅ You may also contact us at info@shaperx.com for assistance.
We use Klaviyo SMS as our SMS service provider. Your phone number, name, purchase history, and message interaction data may be shared with Klaviyo and used to send automated marketing messages or analyze engagement performance.
For Klaviyo's privacy practices, please refer to their official privacy policy available on their website.
If you opt out of SMS marketing, you may still receive transaction-related messages (e.g., order confirmations or shipping notifications).