Privacy policy
Effective Date: January 13, 2026
Last Updated: January 13, 2026
1. INTRODUCTION AND SCOPE
This Privacy Policy governs the collection, use, disclosure, and protection of personal information by Khlorifica ("we," "us," "our," or "Company"), operating through our Shopify-powered e-commerce platform. This Policy applies to all users, customers, and visitors ("you," "your") who access or interact with our online store, purchase our plant parent indoor accessories and digital downloads, or otherwise engage with our services.
By accessing our website, creating an account, making a purchase, or otherwise providing us with your personal information, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with these terms, you must immediately discontinue use of our services.
We are committed to transparency in our data practices and to protecting your privacy rights as required under applicable United States federal and state privacy laws.
2. DATA CONTROLLER AND CONTACT INFORMATION
Khlorifica is the data controller responsible for the personal information we collect and process through our services. For any questions, concerns, or requests regarding this Privacy Policy or our data practices, you may contact us at:
Khlorifica
1005 Denver St,
Bellevue Nebraska 68005
United States
Email: khlorifica@gmail.com
Phone: 4022156746
3. CATEGORIES OF PERSONAL INFORMATION COLLECTED
We collect various categories of personal information necessary to operate our business, fulfill orders, improve our services, and comply with legal obligations. The specific categories include:
3.1 Information You Provide Directly
Account and Registration Information:
- Full name (first and last)
- Email address
- Password (encrypted and secured)
- Telephone number
- Billing and shipping addresses
- Date of birth (if voluntarily provided)
Transaction and Payment Information:
- Credit card numbers, debit card numbers, or other payment method details (processed securely through our payment processor)
- Billing address
- Purchase history and order details
- Transaction amounts and dates
Communication Data:
- Customer service correspondence
- Product reviews and ratings
- Survey responses and feedback
- Email newsletter subscriptions
- Marketing preferences
Digital Download Access Information:
- Download history
- File access records
- Digital product preferences
3.2 Information Collected Automatically
Technical and Device Information:
- IP address and approximate geographic location
- Browser type and version
- Operating system
- Device identifiers (mobile device ID, advertising ID)
- Screen resolution and display settings
Usage and Analytics Data:
- Pages visited and time spent on pages
- Products viewed and added to cart
- Search queries within our store
- Referring and exit pages
- Click-through rates and navigation patterns
- Session duration and frequency of visits
Cookie and Tracking Data:
- Session cookies for shopping cart functionality
- Persistent cookies for user preferences
- Analytics cookies (Google Analytics, Shopify Analytics)
- Marketing and advertising cookies
- Pixel tags and web beacons
3.3 Information from Third-Party Sources
- Social media profile information (if you connect your social media accounts)
- Marketing and advertising data from third-party platforms
- Fraud prevention and security data from service providers
- Publicly available information to verify identity and prevent fraud
4. LAWFUL BASIS AND PURPOSES FOR PROCESSING
We collect and process your personal information based on the following lawful grounds and for the specific purposes described below:
4.1 Contract Performance and Service Delivery
We process your information to fulfill our contractual obligations when you make a purchase:
- Processing and fulfilling orders
- Delivering physical products and providing access to digital downloads
- Managing your customer account
- Processing payments and preventing fraud
- Providing customer service and support
- Communicating order status, shipping updates, and delivery confirmations
- Handling returns, exchanges, and refunds
4.2 Legitimate Business Interests
We process certain information based on our legitimate interests in operating and improving our business:
- Analyzing customer behavior and preferences to enhance product offerings
- Conducting market research and business analytics
- Improving website functionality, user experience, and navigation
- Detecting, preventing, and addressing technical issues
- Maintaining the security and integrity of our systems
- Preventing fraud, abuse, and illegal activity
- Protecting our legal rights and property
- Managing business operations and internal record-keeping
4.3 Consent
Where required by law, we obtain your explicit consent for:
- Sending promotional emails and marketing communications
- Using non-essential cookies and tracking technologies
- Sharing information with third-party marketing partners
- Processing sensitive personal information (if applicable)
You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
4.4 Legal Compliance
We process your information to comply with legal obligations:
- Responding to lawful requests from government authorities
- Complying with court orders, subpoenas, and legal process
- Meeting tax, accounting, and regulatory reporting requirements
- Maintaining records as required by applicable law
- Cooperating with law enforcement investigations
5. DISCLOSURE AND SHARING OF PERSONAL INFORMATION
We do not sell your personal information to third parties. However, we disclose certain categories of personal information to trusted service providers and partners necessary to operate our business:
5.1 Shopify Platform Services
As a Shopify merchant, we utilize Shopify's e-commerce platform to power our online store. Shopify processes certain personal information on our behalf as a service provider, including:
- Order and transaction data
- Customer account information
- Payment processing (through Shopify Payments or third-party payment gateways)
- Hosting and data storage
- Website analytics and performance monitoring
Shopify maintains its own privacy policy governing its data practices. For more information, please review Shopify's Privacy Policy at shopify.com/legal/privacy.
5.2 Payment Processors
We share payment information with authorized payment processors to complete transactions securely:
- Credit card networks (Visa, Mastercard, American Express, Discover)
- Payment gateways and merchant service providers
- Fraud detection and prevention services
We do not store complete credit card numbers on our servers; such information is securely processed and stored by PCI-compliant payment processors.
5.3 Shipping and Fulfillment Partners
We disclose shipping information to logistics providers to deliver physical products:
- United States Postal Service (USPS)
- UPS, FedEx, and other shipping carriers
- Third-party fulfillment centers and warehouses
- Package tracking and delivery confirmation services
5.4 Marketing and Analytics Services
We share certain information with marketing and analytics providers:
- Google Analytics (website traffic and behavior analysis)
- Facebook Pixel and Meta advertising platforms
- Email marketing services (Klaviyo, Mailchimp, or similar)
- Social media advertising platforms
- Customer relationship management (CRM) systems
5.5 Customer Service and Communication Tools
- Customer support platforms and ticketing systems
- Live chat and messaging applications
- Phone and email communication services
5.6 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal information may be transferred to the acquiring entity or successor organization. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
5.7 Legal Disclosures
We may disclose your information when required by law or to protect our rights:
- To comply with legal obligations, court orders, or government requests
- To enforce our Terms of Service and other agreements
- To protect against fraud, security threats, or illegal activity
- To defend legal claims or protect our rights and property
- To protect the safety and security of our customers and the public
6. COOKIES AND TRACKING TECHNOLOGIES
6.1 Types of Cookies Used
We use cookies and similar tracking technologies to enhance your experience and analyze website performance:
Essential Cookies (Required):
- Shopping cart functionality and session management
- Secure login authentication
- Website security and fraud prevention
- Load balancing and performance optimization
Analytics Cookies:
- Google Analytics for traffic analysis and user behavior
- Shopify Analytics for sales and conversion tracking
- Heatmap and session recording tools
Marketing and Advertising Cookies:
- Facebook Pixel for retargeting and ad optimization
- Google Ads conversion tracking
- Social media integration and sharing functionality
- Affiliate marketing tracking
Preference Cookies:
- Language and regional settings
- Display preferences and customization
- Recently viewed products
6.2 Managing Cookie Preferences
You have control over cookie usage:
- Browser Settings: Most browsers allow you to refuse cookies or receive alerts when cookies are being sent. Consult your browser's help documentation for specific instructions.
- Cookie Banner: Upon your first visit, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies.
- Opt-Out Tools: You may opt out of targeted advertising cookies through the Digital Advertising Alliance's opt-out page at optout.aboutads.info or the Network Advertising Initiative at optout.networkadvertising.org.
Please note that disabling certain cookies may limit your ability to use all features of our website, including shopping cart functionality.
6.3 Do Not Track Signals
Our website does not currently respond to "Do Not Track" (DNT) signals from web browsers. We continue to monitor developments in DNT technology and may implement response mechanisms in the future.
7. DATA RETENTION AND STORAGE
7.1 Retention Periods
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:
Account Information: Retained for the duration of your active account, plus seven years following account closure for legal and tax compliance purposes.
Transaction Records: Maintained for seven years to comply with financial record-keeping requirements and to handle potential disputes or claims.
Marketing Communications: Retained until you unsubscribe from our mailing list, plus a reasonable period to ensure preferences are honored.
Analytics and Usage Data: Typically retained for 26 months, or as configured in our analytics platforms.
Customer Service Records: Kept for three years to improve service quality and resolve ongoing issues.
Legal Holds: Information subject to legal proceedings, investigations, or regulatory requests will be retained until the matter is resolved.
7.2 Data Deletion
Upon request or after applicable retention periods expire, we securely delete or anonymize your personal information in accordance with industry best practices. However, we may retain certain information in backup systems or archives for a limited additional period for disaster recovery purposes.
8. DATA SECURITY MEASURES
We implement comprehensive technical, administrative, and physical safeguards to protect your personal information against unauthorized access, disclosure, alteration, and destruction:
8.1 Technical Security Controls
- Encryption: All sensitive data transmitted between your browser and our servers is encrypted using industry-standard SSL/TLS protocols (minimum 256-bit encryption).
- Secure Payment Processing: Payment information is processed through PCI DSS-compliant payment processors and is never stored in unencrypted form on our servers.
- Access Controls: Multi-factor authentication and role-based access restrictions limit employee access to personal information on a need-to-know basis.
- Network Security: Firewalls, intrusion detection systems, and regular security monitoring protect against cyber threats.
- Regular Updates: We maintain up-to-date security patches and software updates for all systems handling personal information.
8.2 Administrative Security Measures
- Employee training on data privacy and security best practices
- Confidentiality agreements and privacy policies for all personnel with access to personal information
- Regular security audits and risk assessments
- Incident response and data breach notification procedures
- Third-party vendor security assessments and due diligence
8.3 Physical Security
- Secure data centers with restricted physical access
- Environmental controls and redundancy systems
- Video surveillance and security personnel (where applicable)
Despite our best efforts, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security. In the event of a data breach affecting your information, we will notify you as required by applicable law.
9. YOUR PRIVACY RIGHTS AND CHOICES
Depending on your state of residence, you may have certain rights regarding your personal information. We are committed to honoring these rights in accordance with applicable law.
9.1 Rights Available to All U.S. Customers
Right to Access: You may request confirmation of whether we process your personal information and obtain a copy of such information.
Right to Correction: You may request that we correct inaccurate or incomplete personal information.
Right to Deletion: You may request that we delete your personal information, subject to certain exceptions for legal obligations, fraud prevention, and legitimate business purposes.
Right to Opt-Out of Marketing: You may unsubscribe from promotional emails by clicking the "unsubscribe" link in any marketing email or by contacting us directly.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
9.2 Additional Rights for California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know: You may request specific details about the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collection, and the categories of third parties with whom we share information.
Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
Right to Opt-Out of Sale/Sharing: While we do not "sell" personal information in the traditional sense, we share certain information with advertising partners that may constitute a "sale" or "sharing" under California law. You may opt out of such sharing at any time.
Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information and use it for purposes beyond those permitted by law, you may limit such uses.
Right to Correction: You may request correction of inaccurate personal information.
Right to Opt-Out of Automated Decision-Making: If we use automated decision-making that produces legal or similarly significant effects, you have the right to opt out.
Right to Designate an Authorized Agent: You may designate an authorized agent to make requests on your behalf, provided the agent has written authorization.
9.3 Additional Rights for Other State Residents
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights, including:
- Right to access personal information
- Right to correct inaccuracies
- Right to delete personal information
- Right to obtain a copy of personal information
- Right to opt out of targeted advertising
- Right to opt out of the sale of personal information
- Right to appeal denials of privacy rights requests
9.4 Exercising Your Rights
To exercise any of these rights, please submit a verifiable request by:
- Email: khlorifica@gmail.com
- Phone: 4022156746
- Mail: Khlorifica Privacy Rights Request: 1005 Denver St, Bellevue Nebraska 68005, United States
We will verify your identity before processing your request and will respond within the timeframes required by applicable law (typically 45 days, with a possible 45-day extension for complex requests).
9.5 Appeal Process
If we deny your request, you have the right to appeal our decision by contacting us using the methods above and referencing your original request. We will respond to appeals within 60 days.
10. CHILDREN'S PRIVACY
Our services are not directed to, and we do not knowingly collect personal information from, children under the age of 13. If we become aware that we have inadvertently collected personal information from a child under 13 without verified parental consent, we will take immediate steps to delete such information from our records.
If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us immediately so we can take appropriate action.
For residents of states with specific protections for minors aged 13-17, we do not sell or share personal information of such minors without affirmative authorization or consent as required by law.
11. INTERNATIONAL DATA TRANSFERS
Our services are based in and intended for residents of the United States. If you access our website from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers and service providers are located.
By using our services, you consent to the transfer of your information to the United States and acknowledge that the United States may not have the same level of data protection laws as your jurisdiction.
12. THIRD-PARTY WEBSITES AND SERVICES
Our website may contain links to third-party websites, social media platforms, or services that are not owned or controlled by Khlorifica. This Privacy Policy does not apply to such third-party sites.
We are not responsible for the privacy practices, content, or policies of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit. Links to third-party sites do not constitute an endorsement of their content or practices.
13. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify, update, or revise this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy
- Provide notice through email to registered customers (for material changes affecting your rights)
- Display a prominent notice on our website homepage for 30 days
- Obtain your consent where required by law
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our services after changes become effective constitutes acceptance of the revised Privacy Policy.
14. CALIFORNIA SHINE THE LIGHT LAW
Under California Civil Code Section 1798.83 (the "Shine the Light" law), California residents who have an established business relationship with us may request information about the types of personal information we have shared with third parties for their direct marketing purposes and the names and addresses of those third parties during the preceding calendar year.
To make such a request, please contact us using the contact information provided in Section 2 above. Please include "California Shine the Light Request" in the subject line.
15. NEVADA PRIVACY RIGHTS
Nevada residents have the right to opt out of the sale of certain covered information that we have collected or will collect about them. While we do not currently sell covered information as defined under Nevada law, Nevada residents may submit an opt-out request for the future by contacting us at the information provided in Section 2.
16. ACCESSIBILITY
We are committed to ensuring this Privacy Policy is accessible to individuals with disabilities. If you have difficulty accessing any portion of this Policy or require it in an alternative format, please contact us and we will work to provide the information in a format that meets your needs.
17. DISPUTE RESOLUTION
Any disputes arising from or relating to this Privacy Policy or our data practices shall be governed by the laws of the United States and the State of Nebraska, without regard to conflict of law principles. You agree to submit to the exclusive jurisdiction of the state and federal courts located in Bellevue, Nebraska for resolution of any disputes.
18. ACKNOWLEDGMENT AND CONSENT
BY USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS. IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, YOU MUST NOT USE OUR WEBSITE OR SERVICES.
Last Reviewed: January 13, 2026
Questions or Concerns? Contact our Privacy Team at khlorifica@gmail.com
Effective Immediately