1. Introduction
Xephylareoshun ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website xephylareoshun.world and purchase our products.
We comply with applicable privacy and data protection laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), where applicable. Depending on where you live, you may also have additional rights under other privacy and consumer protection laws. Please read this policy carefully to understand our practices regarding your personal data.
2. Data Controller Information
The data controller responsible for your personal data is:
- Company Name: Xephylareoshun
- Address: 24 Broadway Ave #4, Red Lodge, MT 59068, United States
- Email: reachus@xephylareoshun.world
- Country: United States
3. Information We Collect
3.1 Information You Provide
We collect information that you voluntarily provide when you:
- Place an order (name, email address, phone number, shipping address, billing information)
- Create an account on our website
- Subscribe to our newsletter
- Contact us through our contact form or email
- Participate in surveys or promotions
3.2 Information Collected Automatically
When you visit our website, we may automatically collect:
- IP address and approximate location
- Browser type and version
- Operating system
- Referring website
- Pages viewed and time spent on pages
- Device identifiers
3.3 California Consumer Privacy Notice (CCPA/CPRA)
If you are a California resident, this section describes how we handle personal information under the CCPA/CPRA.
Depending on how you interact with our website, we may collect the following categories of personal information:
- Identifiers: Name, email address, phone number, account identifiers
- Commercial information: Order details, purchase history, and related billing/shipping information
- Internet or other electronic network activity: Browsing behavior, pages viewed, and time spent
- Geolocation data (approximate): Approximate location derived from IP address
- Device identifiers: Device IDs and similar identifiers
- Inferences: Inferences about preferences and interests based on usage patterns
We use these categories of personal information for the purposes described in Section 5 (“How We Use Your Information”), including providing services, fulfilling orders, communicating with you, improving our website, preventing fraud, and complying with legal obligations.
We do not sell personal information for monetary consideration. Where applicable, we may disclose personal information to service providers and other parties as described in Section 7 (“Data Sharing and Disclosure”), including for analytics and targeted advertising. See Section 9 (“Your Rights”) for details about your opt-out and other rights.
4. Legal Basis for Processing (Where Applicable)
Where required by applicable law, we process personal data based on the following grounds:
- Contract Performance: Processing necessary to fulfill your orders and provide our services
- Consent: When you explicitly agree to receive marketing communications
- Legitimate Interests: For fraud prevention, security, and improving our services
- Legal Obligation: When required by applicable laws and regulations
5. How We Use Your Information
We use the collected information for the following purposes:
- Processing and fulfilling your orders
- Communicating with you about your orders and inquiries
- Sending transactional emails (order confirmations, shipping updates)
- With your consent, sending marketing communications, and providing an unsubscribe/opt-out option in marketing emails
- Improving our website and customer experience
- Preventing fraud and ensuring security
- Complying with legal obligations
- Analyzing website usage and trends
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Order Information: 7 years for tax and accounting purposes
- Account Information: Until you request deletion
- Marketing Data: Until you unsubscribe or withdraw consent
- Website Analytics: Up to 26 months
7. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Payment processors, shipping carriers, email service providers
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets
We do not sell your personal data for monetary consideration. Where applicable, we may disclose your personal data for targeted advertising and analytics (which can be considered “sharing” under the CCPA/CPRA). You can exercise your opt-out rights as described in Section 9.
8. International Data Transfers
Your data may be transferred to and processed in countries outside your residence. When we transfer data outside your residence, we take steps to ensure an appropriate level of protection, such as through contractual or other safeguards required by applicable law.
9. Your Rights
Depending on where you live and the applicable law, you may have the following rights:
- Right to Know/Access: Request details about the categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of personal information, subject to applicable exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Data Portability: Receive certain personal information in a portable, readily usable format.
- Right to Opt Out of “Sale” or “Sharing”: If applicable, opt out of disclosures for targeted advertising and certain cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: If applicable, request limitation of our use of sensitive personal information.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Object/Restrict: Where applicable, request restriction or object to certain processing.
- Right to Appeal: Appeal certain privacy request decisions, where required by applicable law.
To exercise your rights, please contact us using the information provided below. We may need to verify your identity before processing your request. We will respond within the timeframes required by applicable law. If you are a California resident, you may submit privacy requests through an authorized agent. We will not discriminate against you for exercising your privacy rights.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption for data transmission
- Secure storage with access controls
- Regular security assessments
- Employee training on data protection
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
Where required by applicable law, we will notify affected individuals and regulators of certain security incidents without unreasonable delay.
11. Children's Privacy
Our website is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information to us, we will take steps to delete it promptly and, where applicable, notify the appropriate parties as required by law.
12. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Xephylareoshun
24 Broadway Ave #4, Red Lodge, MT 59068, United States
Email: reachus@xephylareoshun.world
We will respond to your request within 30 days.