Privacy Policy

1. Introduction & Scope

This Privacy Policy explains how SHAPERX LLC (“SHAPERX,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you visit, access, or make a purchase from https://www.shaperx.com (the “Site”) or interact with us through related services, including email, SMS marketing (via Klaviyo SMS), advertising platforms (such as TikTok, Meta/Facebook, and Google), and Amazon Buy With Prime (collectively, the “Services”).

By accessing or using our Site or Services, you acknowledge that you have read and understood this Privacy Policy.

 


 

1.1 Legal Applicability

This Privacy Policy is intended to comply with relevant privacy laws, including:

California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
General Data Protection Regulation (GDPR) & UK GDPR (where applicable)
Telephone Consumer Protection Act (TCPA) for SMS marketing
Children’s Online Privacy Protection Act (COPPA)
CAN-SPAM Act
✅ Other U.S. state privacy laws where applicable (Virginia, Colorado, Connecticut, Utah, etc.)

While SHAPERX primarily ships within the United States (including California), EU/UK or other international visitors who access our Site are provided applicable rights under GDPR/UK GDPR where legally required.

 


 

1.2 Controller Information

When applicable under data protection laws, SHAPERX LLC is the “data controller” responsible for your personal information.

Company Name: SHAPERX LLC
Address: 732 S 6TH ST STE R LAS VEGAS, NV, 89101, USA

Email (for Privacy Requests): info@shaperx.com

 


 

1.3 Who This Policy Applies To

This policy applies to:

✅ Visitors browsing our Site
✅ Customers placing orders
✅ Individuals subscribing to SMS or email marketing
✅ Users interacting with advertisements, cookies, or tracking tools
✅ Individuals contacting us for support or marketing queries

 


 

1.4 Acceptance & Consent

By using our Site or Services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our Site.

Where legally required (such as under GDPR), we will request your explicit consent for certain processing activities, such as marketing or cookie-based tracking.

 


 

1.5 Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Changes will be posted on this page with an updated “Last Updated” date.

Your continued use of our Site after such changes constitutes your acceptance of the updated policy.




2. Personal Information We Collect

We collect different types of personal information depending on how you interact with our Site and Services. “Personal Information” means any information that can identify, relate to, describe, or be reasonably associated with an individual.

We collect the following categories of Personal Information:

 


 

2.1 Information You Provide Directly

We collect information that you voluntarily provide when you take certain actions, including when you place an order, create an account, subscribe to marketing communications (including SMS), contact customer support, or participate in promotions.

This may include:

Data Type

Examples

Contact Information

First name, last name, email address, phone number, shipping/billing address

Order Information

Products ordered, purchase history, payment method (credit card, Shop Pay, Amazon Pay, PayPal, Google Pay)

Account Information (if account is created)

Username, password, email, preferences

Communication Preferences

Marketing opt-in choices (email/SMS), subscription preferences

Support Information

Messages, inquiries, complaints

⚠️ Note: Payment card information is processed securely by third-party payment providers and is not stored by SHAPERX.

 


 

2.2 Information Automatically Collected (Device & Usage Data)

When you visit our Site, we automatically collect technical and usage information through cookies, pixels, log files, web beacons, and similar technologies.

This may include:

Data Type

Examples

Device Information

IP address, browser type, OS, device type, time zone

Usage Activity

Pages viewed, time spent, referring pages/URLs, clicks, scroll behavior

Analytics Information

E-commerce events (add to cart, checkout, purchase), bounce rates, conversion data

Advertising Interaction Data

Engagement with ads on platforms such as TikTok, Meta/Facebook, Google

 


 

2.3 TikTok Maximum-Level Data Sharing (Pixel, Events API & Advanced Matching)

When you interact with our Site under our Maximum data sharing level with TikTok, the following categories of information may be shared with TikTok for marketing, analytics, and audience matching purposes:

 ✅ Events: Add Payment Info, Add to Cart, Complete Payment, Initiate Checkout, Search, View Content, Complete Registration.
✅ Identifiers: Email (hashed), Phone Number (hashed), First Name, Last Name, ZIP Code, City, State, Country/Region.
✅ Shopify API data (Order & Customer-Level Data).
✅ Automatically generated device identifiers & engagement metrics.
✅ Data may be shared via TikTok Pixel, Shopify APIs, Events API, and In-App Checkout integrations.

 


 

2.4 SMS & Email Marketing Enrollment (Klaviyo)

If you subscribe to SMS or email lists (including abandoned cart reminders), we collect:

 ✅ Phone number
✅ Email address
✅ Name (where provided)
✅ Engagement data (opens, clicks, replies)
✅ Purchase intent signals (e.g., abandoned cart triggers)

 


 

2.5 Information from Third Parties

We may collect information from third-party partners such as:

Source

Information Provided

Shopify (e-commerce host)

Order metadata, customer profile details

Payment Processors (Amazon Pay, Shop Pay, PayPal, Google Pay, credit card gateways)

Payment status confirmation

Analytics Providers (Google Analytics, TikTok Analytics, Meta Pixel)

Performance & engagement metrics

Marketing Partners (Klaviyo, TikTok Ads, Meta/Facebook Ads)

Attribution + engagement behavior

Amazon Buy With Prime

Checkout and shipping-related details

 


 

2.6 Shipping & Fulfillment Partners

When shipping your order, we may receive and share delivery-related information (e.g., tracking updates) with logistics providers such as USPS, UPS, FedEx, DHL, or other carriers.

 


 

2.7 Inferences

In some cases, we may generate inferred information based on browsing or purchase history, such as preferences, likely purchasing behavior, or marketing segment classification.


3. How We Use Personal Information

We use the Personal Information we collect for various business and commercial purposes in accordance with applicable privacy laws, including the GDPR, CCPA, and CPRA. Below is a detailed breakdown of our purposes:

 


 

3.1 To Process Orders and Provide Our Services

We use your Personal Information to:
✅ Process and fulfill orders
✅ Verify payment details and complete transactions
✅ Provide order confirmations, shipping updates, and digital receipts
✅ Facilitate returns, refunds, or customer service support
✅ Enable Amazon Buy With Prime checkout functionality

Legal basis (GDPR/UK GDPR):
📍 Performance of a contract; legitimate interests (customer service support)

 


 

3.2 To Manage Customer Accounts (If Applicable)

 ✅ Enable account creation and login
✅ Maintain account history and preferences
✅ Provide personalized dashboard access

Legal basis:
📍 Performance of a contract; legitimate interests (user convenience)

 


 

3.3 To Communicate With You

 ✅ Respond to inquiries and provide support
✅ Send order updates, notifications, and confirmations
✅ Deliver service-related announcements

Legal basis:
📍 Legitimate interests; performance of a contract

 


 

3.4 To Send Marketing Communications (Email & SMS via Klaviyo)

 ✅ Send promotional content, product launches, special offers
✅ Deliver cart abandonment reminders
✅ Track engagement with marketing messages

📌 For SMS: Consent is required under TCPA and CTIA guidelines. You can opt out at any time by replying STOP.

Legal basis:
📍 Consent (for SMS and certain email marketing under GDPR); legitimate interests (U.S. direct marketing)

 


 

3.5 To Provide Personalized Advertising & Retargeting (TikTok, Meta/Facebook, Google, etc.)

 ✅ Use tracking technologies (e.g., TikTok Pixel, Meta Pixel, Google Ads)
✅ Share hashed identifiers with ad platforms for audience matching
✅ Customize ads based on browsing and purchase activity
✅ Measure ad performance

📌 Under CPRA, this may be considered “sharing” of personal information for cross-context behavioral advertising. Users may opt out via the “Do Not Sell or Share My Personal Information” link.

Legal basis:
📍 Consent (Europe); legitimate interests (marketing); CPRA-compliant opt-out provisions

 


 

3.6 TikTok Maximum Data Sharing Optimization

At the “Maximum” level of data sharing, we transmit additional customer events, identifiers, and behavior data through TikTok Pixel, Events API, Advanced Matching, and Shopify APIs to improve ad delivery and campaign optimization.

Purpose:
✅ Enhance performance of TikTok campaigns
✅ Increase relevance of ad targeting
✅ Improve conversion tracking

 


 

3.7 To Improve and Optimize Our Site & Services

 ✅ Analyze traffic patterns and customer behavior
✅ Identify usability trends
✅ Diagnose technical issues
✅ Enhance product offerings

Legal basis:
📍 Legitimate interests (service improvement)

 


 

3.8 To Detect Fraud and Ensure Security

 ✅ Monitor orders for fraud risk
✅ Authenticate users
✅ Detect abnormal site activity

Legal basis:
📍 Legitimate interests; legal obligations

 


 

3.9 To Comply with Legal Obligations

 ✅ Maintain tax, accounting, and audit records
✅ Respond to lawful requests (e.g., subpoenas, investigations)
✅ Comply with consumer rights requests (CPRA/GDPR)

Legal basis:
📍 Legal obligation

 


 

3.10 For Any Purpose with Your Explicit Consent

✅ Where required, we will ask for your consent before using your information for a specific purpose not covered above.

4. Cookies, Analytics, and Tracking Technologies

We use cookies, pixels, tags, web beacons, scripts, and similar tracking technologies (“Cookies”) to enhance your browsing experience, analyze website performance, customize content, and support advertising and marketing efforts across platforms such as TikTok, Meta/Facebook, Google, and Klaviyo.

 


 

4.1 What Are Cookies?

Cookies are small data files stored on your device (e.g., computer, smartphone) when you visit our Site. They allow us and third-party partners to recognize your browser and gather information about your usage patterns and preferences.

 


 

4.2 Types of Cookies We Use

Cookie Type

Purpose

Strictly Necessary Cookies

Required for core Site functionality (e.g., checkout process, page navigation).

Performance & Analytics Cookies

Collect anonymous usage data to improve functionality (e.g., Google Analytics, Shopify Analytics).

Functional Cookies

Remember user preferences such as language, region, or login details.

Advertising & Retargeting Cookies

Track browsing behavior to display personalized ads on TikTok, Meta/Facebook, Google, etc. For example, TikTok Pixel records engagement events such as Add to Cart or Complete Payment.

Social Media Cookies

Enable interactions with social media platforms (e.g., liking or sharing products).

 


 

4.3 Third-Party Tracking Technologies We Use

Provider

Purpose

Examples of Data Processed

Google Analytics

Tracks traffic & engagement

Pages visited, session duration, IP address (anonymized in some regions)

TikTok Pixel & Events API (Maximum Level)

Ad optimization & conversion tracking

Hashed email/phone, event triggers, order information

Meta (Facebook/Instagram) Pixel

Ad retargeting & lookalike audience creation

Engagements, purchases, website activity

Klaviyo (Email/SMS Analytics)

Tracks email/SMS campaign engagement

Open rate, click rate, purchase attribution

Shopify Analytics

E-commerce insights

Cart actions, checkout sessions

Amazon Buy With Prime

Enables embedded checkout functionality

Purchase flow data, customer region

 


 

4.4 How We Use Analytics

Analytics cookies help us:
✅ Understand which pages are most visited
✅ Track conversion performance (e.g., add-to-cart to purchase)
✅ Improve customer journey flow
✅ Identify technical performance issues

Depending on your region, certain analytics tools (e.g., Google Analytics 4) may be configured to anonymize or hash IP addresses as required under GDPR or similar regulations.

 


 

4.5 Targeted & Behavioral Advertising

We may use cookies and tracking tools to:
✅ Deliver personalized ads based on prior browsing/purchase behavior
✅ Retarget visitors who did not complete a purchase
✅ Create audience segments (e.g., cart abandoners, frequent buyers)
✅ Share hashed customer identifiers with advertising platforms

📌 Under CPRA, this may be considered “sharing” for cross-context behavioral advertising. You may opt out via our “Do Not Sell or Share My Personal Information” link.

 


 

4.6 How to Manage or Disable Cookies

Depending on your location, you may:
✅ Adjust cookie preferences via a popup consent banner (GDPR regions)
✅ Disable non-essential cookies in your browser settings
✅ Use opt-out tools provided by third parties (e.g., Google Analytics Opt-Out Add-on)

Browser-level controls:

  • Chrome: Settings → Privacy & Security → Cookies

  • Safari: Preferences → Privacy

  • Firefox: Preferences → Privacy & Security

Please note that disabling certain cookies may affect Site functionality, particularly during checkout.

 


 

4.7 “Do Not Track” Signals

Some browsers allow you to send a “Do Not Track” (DNT) signal. At this time, our Site does not respond to DNT signals due to industry-wide lack of a consistent standard. However, you can still manage tracking preferences via the options listed above.

5. TikTok Maximum-Level Data Sharing Disclosure

We use TikTok for advertising, audience targeting, and performance measurement. To optimize campaign effectiveness and reach more customers, we have enabled the Maximum data-sharing level as provided by the TikTok for Shopify integration. This setting uses multiple data transmission methods, including the TikTok Pixel, Events API, Advanced Matching, Shopify APIs, and In-App Checkout tools.

By interacting with our Site, certain Personal Information may be shared with TikTok for marketing and analytics purposes, subject to applicable privacy laws and user opt-out rights.

 


 

5.1 What Data Is Shared with TikTok at the Maximum Level?

When using the Maximum sharing option, TikTok may receive the following categories of information:

Event Actions Triggered on the Site

  • Add to Cart

  • Initiate Checkout

  • Add Payment Info

  • Complete Payment (Purchase)

  • View Content (Product views)

  • Search queries

  • Complete Registration (account or subscription sign-up)

Identifiers for Advanced Matching (hashed before transfer where applicable):

  • First name, last name

  • Email address

  • Phone number

  • ZIP/postal code

  • City, state, country/region

Transactional & Behavioral Data via Shopify/Order APIs:

  • Products purchased

  • Order value

  • Checkout interactions

  • Cart abandonment behavior

  • Customer type indicators (e.g., new or returning customer)

Device & Technical Data (e.g., via Pixel and Events API):

  • IP address

  • Browser type

  • Session activity

  • User agent details

  • Clickstream data

 


 

5.2 How TikTok Uses the Shared Data

TikTok may use this information to:
✅ Deliver, personalize, and optimize ads for you and similar customers
✅ Assign conversions and measure campaign effectiveness
✅ Build audiences and lookalike segments
✅ Support e-commerce attribution and cross-device tracking

For more details on how TikTok processes data, please review TikTok’s Privacy Policy (available directly on TikTok’s official website).

 


 

5.3 User Choice and Opt-Out

Under the CCPA/CPRA, sharing personal information for cross-context behavioral advertising may be considered “sharing.” You can opt out of TikTok-based behavioral advertising at any time by using our “Do Not Sell or Share My Personal Information” link located on our Site or by contacting us at info@shaperx.com.

European visitors will only have their data used for TikTok advertising where consent has been provided in compliance with GDPR/UK GDPR rules.

 


 

5.4 Legal Basis (Where GDPR Applies)

For residents of the EEA/UK, we rely on your explicit consent (where legally required) or our legitimate interests in marketing and performance optimization, unless overridden by your privacy rights.

6. Sharing of Personal Information with Third Parties

We share Personal Information with trusted third-party service providers and partners who help us operate our business, deliver our Services, and perform specific functions on our behalf. We do not sell Personal Information for monetary value. However, under the CPRA, certain sharing of information for advertising or marketing purposes may be classified as “sharing” or “cross-context behavioral advertising.”

Below are the categories of third parties with whom we may share Personal Information:

 


 

6.1 E-Commerce & Website Hosting (Shopify)

We use Shopify to power our online store. Shopify processes customer data, including order information, checkout activity, and device analytics, to support transactions, fraud detection, and secure payment processing.

📌 Shopify Privacy Policy is available via their official website.

 


 

6.2 Marketing & Advertising Partners

We share information with marketing and ad platforms to deliver targeted advertisements and analyze advertising performance.

Partner

Purpose

Data Potentially Shared

TikTok (Pixel, Events API, Advanced Matching, Shopify API integrations)

Targeted advertising and campaign optimization

Events, hashed identifiers, order data, engagement activity

Meta/Facebook & Instagram (Facebook Pixel)

Retargeting, audience building

Cookies, hashed email/phone, purchase events

Google Ads & YouTube Ads

Ad targeting and conversion tracking

Search & site activity, hashed identifiers

Klaviyo (Email & SMS marketing)

Campaign execution, cart recovery, behavior-based messaging

Email, phone number, purchase history, engagement metrics

 


 

6.3 Analytics & Performance Tools

We use analytics partners to understand visitor behavior, site performance, and customer engagement.

Provider

Purpose

Google Analytics

Tracks site usage, engagement metrics

Shopify Analytics

E-commerce reporting

TikTok & Meta Analytics

Ad performance attribution

 


 

6.4 Payment Processors & Financial Services

We share limited Personal Information as necessary to process payments securely.

Provider

Accepted Methods

Credit Card Processors (via Shopify Payments)

Visa, Mastercard, Amex, etc.

Shop Pay

Express checkout

PayPal

External wallet

Amazon Pay / Amazon Buy With Prime

Prime-enabled checkout

Google Pay

Digital wallet

📌 These services may collect your information independently in accordance with their own privacy policies.

 


 

6.5 Shipping, Fulfillment & Logistics Providers

We share delivery-related data (e.g., name, address, phone number) with shipping carriers such as USPS, UPS, FedEx, DHL, or other third-party logistics partners to fulfill your order.

 


 

6.6 Customer Support & Communication Platforms

We may share information with email or customer service tools used to
✅ send support messages,
✅ respond to inquiries,
✅ manage service tickets,
✅ trigger automated notifications.

 


 

6.7 Legal Compliance & Fraud Prevention

We may disclose Personal Information when necessary to:
✅ comply with applicable laws, regulations, subpoenas, or legal processes;
✅ protect the rights, property, or safety of SHAPERX, our customers, or others;
✅ detect, investigate, or prevent fraud or security breaches.

 


 

6.8 Business Transfers

If SHAPERX LLC is involved in a merger, acquisition, restructuring, financing, asset sale, or bankruptcy, Personal Information may be transferred to the successor entity as part of the business transaction.

7. Sale or Sharing of Personal Information Under the CPRA (California Residents)

Under the California Privacy Rights Act (CPRA), the terms “sell” and “share” have specific legal meanings that may differ from their everyday usage:

  • “Sell” means disclosing Personal Information to a third party in exchange for monetary or other valuable consideration.

  • “Share” means disclosing Personal Information to a third party for cross-context behavioral advertising, even if no money is exchanged.

 


 

7.1 Do We Sell Personal Information?

We do not sell Personal Information for monetary compensation.

We do not provide customer data to third parties in exchange for direct payment.

 


 

7.2 Do We Share Personal Information for Cross-Context Behavioral Advertising?

Yes. We may share Personal Information with third-party advertising partners (such as TikTok, Meta/Facebook, Google, and Klaviyo) in order to deliver personalized or targeted advertisements. Under CPRA, this activity may be considered “sharing.”

Categories of information that may be “shared” for advertising purposes may include:
✅ Identifiers (e.g., hashed email, hashed phone number, IP address)
✅ Internet or device activity data
✅ Commercial information (e.g., purchase history, cart activity)
✅ Inferred interests or preferences

 


 

7.3 Your Right to Opt Out of Sharing (CPRA)

If you are a California resident, you have the right to opt out of the “sharing” of your Personal Information for cross-context behavioral advertising.

You can exercise this right by:
✅ Clicking the “Do Not Sell or Share My Personal Information” link available on our Site, or
✅ Contacting us at info@shaperx.com

Once we receive and verify your request, we will stop sharing your Personal Information for advertising purposes as required by law.

 


 

7.4 Opt-Out for Minors

We do not knowingly “sell” or “share” Personal Information of consumers under the age of 16. If we become aware that we have inadvertently processed such data, we will take appropriate action to comply with applicable laws.

8. Your Privacy Rights (GDPR / CPRA / Other U.S. State Rights)

Depending on where you reside, you may have certain rights regarding your Personal Information under applicable laws such as the California Consumer Privacy Act (CCPA) as amended by the CPRA, the General Data Protection Regulation (GDPR), UK GDPR, and other U.S. state privacy laws (e.g., Virginia, Colorado, Connecticut, Utah).

Below is a summary of your rights and how you may exercise them.

 


 

8.1 California Residents (CPRA Rights)

If you are a resident of California, you have the following rights under the CPRA:

Right

Description

Right to Know / Access

Request disclosure of the categories or specific pieces of Personal Information we have collected about you.

Right to Delete

Request deletion of Personal Information we have collected, subject to lawful exceptions.

Right to Correct

Request correction of inaccurate Personal Information.

Right to Opt-Out of Sharing

Request that we stop sharing Personal Information for targeted advertising.

Right to Limit Use of Sensitive Personal Information (if applicable)

Restrict use of sensitive data (we currently do not process sensitive data beyond functional purposes such as shipping and fraud detection).

Right to Non-Discrimination

You will not be denied services or charged different prices for exercising privacy rights.

 


 

8.2 EU/UK Residents (GDPR / UK GDPR Rights)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have the following rights (subject to applicable conditions and legal limitations):

Right

Description

Right of Access

Obtain confirmation and a copy of your Personal Information.

Right to Rectification

Request correction of inaccurate or incomplete Personal Information.

Right to Erasure (“Right to Be Forgotten”)

Request deletion of Personal Information under certain circumstances.

Right to Restrict Processing

Request limitation of processing in certain cases.

Right to Data Portability

Request Personal Information in a structured, commonly used format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Right to Withdraw Consent

If processing is based on consent, you may withdraw consent at any time.

 


 

8.3 Other U.S. State Residents

Residents of certain U.S. states (such as Virginia, Colorado, Connecticut, and Utah) may have similar rights, including:
✅ Access, delete, or correct information
✅ Opt out of targeted advertising
✅ Appeal our response where applicable

 


 

8.4 How to Exercise Your Rights

You may exercise your rights by:

📩 Emailing us at: info@shaperx.com
📍 Using the “Do Not Sell or Share My Personal Information” link on our Site (for California residents opting out of sharing)

 


 

8.5 Verification Requirement

To protect your security and comply with legal requirements, we may request additional information to verify your identity before processing a rights request. If we are unable to verify your identity, we may be unable to fulfill your request.

 


 

8.6 Authorized Agents (CPRA)

California residents may designate an authorized agent to submit a request on their behalf. We may require verification of both the agent’s authority and your identity.

9. Opt-Out of Targeted Advertising and SMS Marketing

You have the right to opt out of certain types of data processing, particularly where Personal Information is used for behavioral advertising or direct marketing (such as SMS or targeted ads). Below are the ways you may exercise these rights:

 


 

9.1 Opt-Out of Cross-Context Behavioral Advertising (CPRA)

If you are a California resident, you may opt out of the sharing of your Personal Information for cross-context behavioral advertising by:

 ✅ Clicking the “Do Not Sell or Share My Personal Information” link located on our Site, or
✅ Emailing us at info@shaperx.com

Once your request is verified, we will stop sharing your Personal Information for targeted advertising as required under the CPRA.

 


 

9.2 Opt-Out of Targeted Advertising in the EU/UK (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we will only use your Personal Information for targeted advertising where we have obtained your consent, and you may withdraw your consent at any time by adjusting your cookie settings or contacting us at info@shaperx.com.

 


 

9.3 Opt-Out of Email Marketing

You may unsubscribe from promotional emails by clicking the “unsubscribe” link at the bottom of any email we send. Please allow a reasonable time for us to process your request. You will still receive transactional or service-related emails such as order confirmations or shipping updates.

 


 

9.4 Opt-Out of SMS Marketing (Klaviyo SMS, TCPA Compliant)

If you have opted in to receive SMS marketing messages, you may opt out at any time by replying:

📍**“STOP”** – to stop receiving SMS marketing messages
📍**“HELP”** – to receive additional guidance

Standard message and data rates may apply. Opting out of SMS marketing will not opt you out of transactional text messages (e.g., messages related to your orders or support inquiries).

 


 

9.5 Opt-Out of Cookies and Tracking Technologies

You may control tracking technologies via:
✅ Your browser settings
✅ Device-level privacy controls
✅ Cookie consent banners (where required)
✅ Third-party ad platform settings (e.g., Facebook Ad Preferences, TikTok Ad Settings, Google Ad Settings)

Note: Disabling essential cookies may affect Site functionality and your ability to complete purchases.

10. Data Retention

We retain Personal Information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or regulatory obligations).

Below are typical retention periods:

Data Category

Typical Retention Period

Purpose

Order & transaction data

7 years

Legal, accounting & audit requirements

Customer account data

Active duration of account or until deletion request


Email/SMS marketing subscription

Until you unsubscribe or request deletion


Advertising & analytics data

Typically 12-36 months (may vary by platform)


Cookie/session data

Until expiration or browser deletion


Legal claims & fraud detection data

As required to protect legal rights


When Personal Information is no longer needed, we will delete, anonymize, or securely store it until deletion is possible.

11. Data Security

We use appropriate administrative, technical, and physical safeguards to protect Personal Information from unauthorized access, disclosure, loss, alteration, or misuse.

Security measures include:
✅ Encrypted payment processing (via PCI DSS-compliant providers)
✅ SSL/TLS encryption for Site data transmission
✅ Access control and authentication measures
✅ Secure data storage by reputable third-party providers such as Shopify
✅ Monitoring for fraudulent or suspicious activity

However, no method of transmission or storage is 100% secure. You acknowledge that transmitting data over the internet is done at your own risk. If we become aware of a data breach that affects your Personal Information, we will notify you as required by applicable laws.


12. International Data Transfers

Our company is based in the United States, and we primarily sell and ship products within the U.S. However, our Site may be accessed globally, and certain service providers may store or process Personal Information in countries outside your country of residence.

For international users, your data may be transferred to:
✅ The United States
✅ Canada
✅ European Union or United Kingdom (via Shopify’s infrastructure)
✅ Other regions where third-party providers (e.g., TikTok, Meta, Klaviyo, Google) operate

Where required by law (e.g., under GDPR/UK GDPR), we ensure such transfers are protected by appropriate safeguards such as:
✅ Standard Contractual Clauses (SCCs)
✅ Adequacy decisions
✅ Data Processing Agreements (DPAs)

By using our Site, you acknowledge that your data may be transferred and processed in jurisdictions that may have different data protection laws than your home country.


13. Children’s Privacy

Our Site and Services are not intended for individuals under the age of 16, and we do not knowingly collect or share Personal Information of children under 16 for advertising or other purposes.

  • If you are under 18, you may only use the Site with the involvement of a parent or legal guardian.

  • We do not knowingly “sell” or “share” Personal Information of consumers under 16 (as defined by CPRA).

  • If we learn that we have collected Personal Information from a child under 16 without appropriate consent, we will take steps to delete such information as required by law.

If you believe a child under 16 has provided us Personal Information, please contact us at info@shaperx.com.

 


 

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When changes are made, we will update the “Last Updated” date at the top of this page.

Your continued use of our Site or Services after any update indicates your acceptance of the revised Privacy Policy.

Where legally required, we will notify you of material changes (e.g., via email or a prominent notice on the Site).

 


 

15. Contact Information & Privacy Requests

If you have questions about this Privacy Policy, our data practices, or would like to exercise your privacy rights, you may contact us at:

SHAPERX LLC
📍 732 S 6TH ST STE R LAS VEGAS, NV, 89101, USA

 📩 Email (for Privacy Requests): info@shaperx.com

📌 California residents may also use the “Do Not Sell or Share My Personal Information” link available on our Site to opt out of data sharing for targeted advertising purposes.

 


 

16. SMS Marketing Terms (TCPA & Klaviyo Compliance)

By providing your phone number during checkout, subscribing via an opt-in form, or texting a keyword phrase, you expressly agree to receive recurring SMS messages from SHAPERX for marketing, promotional, and transactional purposes, including cart reminders and updates.

Key SMS terms:
✅ Consent is not a condition of purchase.
✅ Message frequency may vary.
✅ Message & data rates may apply.
✅ To unsubscribe, reply STOP at any time.
✅ For help, reply HELP.
✅ You may also contact us at info@shaperx.com for assistance.

We use Klaviyo SMS as our SMS service provider. Your phone number, name, purchase history, and message interaction data may be shared with Klaviyo and used to send automated marketing messages or analyze engagement performance.

For Klaviyo's privacy practices, please refer to their official privacy policy available on their website.

If you opt out of SMS marketing, you may still receive transaction-related messages (e.g., order confirmations or shipping notifications).