GLOBAL PRIVACY & COOKIE POLICY
HERPTIVARIUS, LLC
EFFECTIVE DATE: DECEMBER 2025
LAST UPDATED: DECEMBER 2025
SUPREMACY; INCORPORATION; NO INDEPENDENT REMEDIES: THIS GLOBAL PRIVACY & COOKIE POLICY IS EXPRESSLY INCORPORATED INTO AND GOVERNED BY THE HERPTIVARIUS, LLC TERMS & CONDITIONS AND IS STRICTLY SUBORDINATE THERETO. THIS POLICY GOVERNS THE COLLECTION, USE, STORAGE, DISCLOSURE, AND PROTECTION OF PERSONAL INFORMATION AND DIGITAL DATA ASSOCIATED WITH WEBSITE VISITORS, CUSTOMERS, AND BUSINESS CONTACTS. NO PROVISION OF THIS POLICY CREATES ANY INDEPENDENT RIGHT, WARRANTY, OR REMEDY OUTSIDE THE SOLE AUTHORITY OF THE TERMS & CONDITIONS MASTER AGREEMENT. IN THE EVENT OF ANY CONFLICT, THE TERMS & CONDITIONS CONTROL.
SCOPE AND OVERVIEW: HERPTIVARIUS, LLC (“WE,” “US,” OR “OUR”) COLLECTS AND PROCESSES INFORMATION THROUGH OUR WEBSITE AND RELATED SERVICES TO OPERATE OUR BUSINESS, PROVIDE SERVICES, PROCESS TRANSACTIONS, SUPPORT CUSTOMERS, IMPROVE PERFORMANCE, MAINTAIN SECURITY, PREVENT FRAUD, AND COMPLY WITH LAW. THIS POLICY APPLIES GLOBALLY AND SHOULD BE READ TOGETHER WITH ANY OTHER PUBLISHED COMPLIANCE NOTICES. BY ACCESSING OR USING OUR WEBSITE, YOU AGREE TO THE DATA PRACTICES DESCRIBED HEREIN TO THE MAXIMUM EXTENT PERMITTED BY LAW.
INFORMATION WE COLLECT: WE MAY COLLECT PERSONAL INFORMATION YOU PROVIDE DIRECTLY, INCLUDING NAME, EMAIL ADDRESS, TELEPHONE NUMBER, SHIPPING AND BILLING ADDRESS, ORDER AND TRANSACTION DETAILS, COMMUNICATIONS SUBMITTED THROUGH FORMS OR SUPPORT CHANNELS, AND OTHER INFORMATION YOU CHOOSE TO PROVIDE. PAYMENT CARD INFORMATION IS NOT STORED BY US; PAYMENT DATA IS HANDLED BY THIRD-PARTY PAYMENT PROCESSORS AND WE MAY RECEIVE LIMITED PAYMENT CONFIRMATION OR TOKENIZED DATA WHERE APPLICABLE. WE MAY ALSO COLLECT INFORMATION AUTOMATICALLY WHEN YOU VISIT OR INTERACT WITH OUR WEBSITE, INCLUDING IP ADDRESS, DEVICE IDENTIFIERS, DEVICE TYPE, BROWSER TYPE, OPERATING SYSTEM, REFERRER/REFERRAL DATA, PAGES VIEWED, DATES AND TIMES OF ACCESS, GENERAL LOCATION INFORMATION, AND SITE INTERACTION DATA, COLLECTED THROUGH COOKIES, PIXELS, ANALYTICS TOOLS, SERVER LOGS, AND SECURITY SYSTEMS. WHERE REQUIRED BY LAW OR NECESSARY FOR COMPLIANCE, WE MAY ALSO COLLECT LIMITED REGULATORY OR COMPLIANCE-RELATED INFORMATION ASSOCIATED WITH A TRANSACTION OR INQUIRY.
METHODS OF COLLECTION: INFORMATION MAY BE COLLECTED THROUGH WEBSITE FORMS, ACCOUNT CREATION (IF OFFERED), ORDER PLACEMENT, PAYMENT PROCESSING, EMAIL OR OTHER COMMUNICATIONS, CUSTOMER SERVICE INTERACTIONS, COOKIES AND SIMILAR TRACKING TECHNOLOGIES, ANALYTICS TOOLS, SECURITY LOGGING, AND THIRD-PARTY INTEGRATIONS NECESSARY FOR OPERATIONAL FUNCTION.
HOW WE USE INFORMATION: WE USE INFORMATION FOR TRANSACTION PROCESSING, ORDER FULFILLMENT, SHIPPING COORDINATION, CUSTOMER SERVICE, COMMUNICATIONS (INCLUDING TRANSACTIONAL, ADMINISTRATIVE, AND LEGAL NOTICES), FRAUD PREVENTION, SECURITY MONITORING, ABUSE PREVENTION, REGULATORY AND LEGAL COMPLIANCE, DISPUTE HANDLING, ANALYTICS AND PERFORMANCE MEASUREMENT, WEBSITE FUNCTIONALITY AND USER EXPERIENCE IMPROVEMENT, AND MARKETING COMMUNICATIONS WHERE PERMITTED BY LAW. WE DO NOT SELL PERSONAL DATA AS A PRIMARY BUSINESS ACTIVITY.
PAYMENT PROCESSING: WE DO NOT PROCESS OR STORE PAYMENT CARD INFORMATION DIRECTLY. PAYMENTS ARE HANDLED BY THIRD-PARTY PROCESSORS (WHICH MAY INCLUDE PLATFORM OR PAYMENT PROVIDERS SUCH AS SQUARESPACE PAYMENTS, STRIPE, PAYPAL, OR SQUARE, DEPENDING ON THE CHECKOUT METHOD USED). THOSE PROVIDERS PROCESS AND SECURE PAYMENT DATA UNDER THEIR OWN POLICIES.
DISCLOSURE AND SHARING: WE MAY DISCLOSE INFORMATION TO THIRD PARTIES ONLY AS NECESSARY FOR LEGITIMATE BUSINESS OPERATIONS AND LEGAL COMPLIANCE, INCLUDING PAYMENT PROCESSORS, SHIPPING CARRIERS OR DELIVERY PARTNERS, WEBSITE HOSTING AND PLATFORM PROVIDERS, IT AND SECURITY SERVICE PROVIDERS, ANALYTICS PROVIDERS, PROFESSIONAL ADVISORS (INCLUDING LEGAL AND ACCOUNTING), AND GOVERNMENT OR REGULATORY AUTHORITIES WHEN REQUIRED BY LAW OR TO PROTECT RIGHTS, SAFETY, AND SECURITY. WE DO NOT RENT PERSONAL INFORMATION. WE MAY DISCLOSE INFORMATION WITHOUT FURTHER NOTICE WHERE REQUIRED BY LAW.
COOKIES AND TRACKING TECHNOLOGIES: WE USE COOKIES, PIXELS, AND SIMILAR TECHNOLOGIES TO ENABLE CORE WEBSITE FUNCTIONALITY, SESSION MANAGEMENT, SECURITY CONTROLS, FRAUD PREVENTION, PERFORMANCE MEASUREMENT, ANALYTICS, AND MARKETING EFFECTIVENESS MEASUREMENT WHERE USED. COOKIES MAY BE SESSION COOKIES OR PERSISTENT COOKIES. DISABLING COOKIES MAY IMPAIR WEBSITE FUNCTIONALITY, TRANSACTION PROCESSING, SECURITY FEATURES, OR USER PREFERENCES. WHERE REQUIRED BY LAW, CONSENT IS OBTAINED THROUGH CONSENT TOOLS OR BANNERS. WHERE LAW PERMITS IMPLIED CONSENT, CONTINUED USE OF THE WEBSITE AFTER NOTICE CONSTITUTES CONSENT TO THE MAXIMUM EXTENT PERMITTED BY LAW.
COOKIE CATEGORIES: WE MAY USE STRICTLY NECESSARY COOKIES FOR CORE OPERATION, SECURITY, AUTHENTICATION, AND FRAUD PREVENTION, PERFORMANCE AND ANALYTICS COOKIES TO MEASURE TRAFFIC AND IMPROVE USABILITY, FUNCTIONAL COOKIES TO REMEMBER PREFERENCES, AND MARKETING OR ADVERTISING COOKIES TO MEASURE CAMPAIGN PERFORMANCE AND SUPPORT INTEREST-BASED ADVERTISING WHERE ENABLED. SPECIFIC TOOLS MAY CHANGE OVER TIME.
THIRD-PARTY COOKIES AND INTEGRATIONS: SOME COOKIES OR TRACKING TECHNOLOGIES MAY BE PLACED BY THIRD-PARTY SERVICES (SUCH AS PAYMENT PROCESSORS, EMBEDDED MEDIA, SOCIAL MEDIA INTEGRATIONS, CUSTOMER SUPPORT TOOLS, ANALYTICS, ADVERTISING TECHNOLOGY, CONTENT DELIVERY, HOSTING, OR SECURITY SERVICES). THESE PROVIDERS MAY COLLECT DATA UNDER THEIR OWN POLICIES. HERPTIVARIUS, LLC DOES NOT CONTROL THIRD-PARTY COOKIE LIFESPAN, SECURITY, OR DATA HANDLING AND DISCLAIMS RESPONSIBILITY FOR THIRD-PARTY DATA PRACTICES TO THE MAXIMUM EXTENT PERMITTED BY LAW.
COOKIE CONTROLS: YOU MAY CONTROL COOKIES THROUGH BROWSER OR DEVICE SETTINGS, BY DELETING STORED COOKIES, USING PRIVACY-FOCUSED BROWSERS OR EXTENSIONS, OR ADJUSTING CONSENT PREFERENCES WHERE AVAILABLE. SOME FEATURES MAY NOT FUNCTION PROPERLY IF COOKIES ARE DISABLED.
DO NOT TRACK SIGNALS: SOME BROWSERS OFFER “DO NOT TRACK” SIGNALS. DUE TO THE ABSENCE OF UNIVERSAL LEGAL OR TECHNICAL STANDARDS, OUR WEBSITE MAY NOT RESPOND TO OR HONOR DNT SIGNALS.
CHILDREN AND MINORS: OUR WEBSITE IS NOT INTENDED FOR CHILDREN UNDER 13, AND WE DO NOT KNOWINGLY COLLECT PERSONAL INFORMATION FROM CHILDREN UNDER 13. IF SUCH DATA IS IDENTIFIED, IT WILL BE DELETED PROMPTLY WHERE LEGALLY REQUIRED.
DATA SECURITY: WE IMPLEMENT COMMERCIALLY REASONABLE ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS DESIGNED TO PROTECT INFORMATION FROM UNAUTHORIZED ACCESS, ALTERATION, DISCLOSURE, OR DESTRUCTION. HOWEVER, NO SYSTEM IS COMPLETELY SECURE AND ABSOLUTE SECURITY CANNOT BE GUARANTEED.
DATA RETENTION: WE RETAIN PERSONAL INFORMATION ONLY AS LONG AS NECESSARY FOR BUSINESS OPERATIONS, TRANSACTION RECORDKEEPING, CUSTOMER SUPPORT, SECURITY, FRAUD PREVENTION, DISPUTE RESOLUTION, LEGAL DEFENSE, TAX AND ACCOUNTING OBLIGATIONS, AND OTHER LEGAL OR REGULATORY REQUIREMENTS. DATA MAY BE RETAINED BEYOND ACCOUNT CLOSURE OR TRANSACTION COMPLETION WHERE REQUIRED FOR THESE PURPOSES.
INTERNATIONAL USERS AND TRANSFERS: HERPTIVARIUS, LLC OPERATES FROM THE UNITED STATES. IF YOU ACCESS THE WEBSITE FROM OUTSIDE THE UNITED STATES, YOUR INFORMATION MAY BE TRANSFERRED TO, STORED IN, AND PROCESSED IN THE UNITED STATES AND OTHER JURISDICTIONS THAT MAY HAVE DIFFERENT DATA PROTECTION LAWS. BY USING THE WEBSITE, YOU CONSENT TO SUCH TRANSFERS TO THE MAXIMUM EXTENT PERMITTED BY LAW.
DATA SALES AND TARGETED ADVERTISING DISCLOSURE: HERPTIVARIUS, LLC DOES NOT SELL PERSONAL DATA AS DEFINED UNDER APPLICABLE PRIVACY LAWS. HOWEVER, CERTAIN DISCLOSURES TO ANALYTICS OR ADVERTISING PARTNERS MAY BE CONSIDERED “SHARING” FOR TARGETED ADVERTISING UNDER SOME LAWS. WHERE REQUIRED, WE PROVIDE OPT-OUT MECHANISMS THROUGH CONSENT TOOLS OR CONTACT METHODS LISTED BELOW.
YOUR RIGHTS AND REQUESTS; IDENTITY VERIFICATION: SUBJECT TO APPLICABLE LAW, YOU MAY REQUEST ACCESS TO, CORRECTION OF, OR DELETION OF CERTAIN PERSONAL INFORMATION, AND YOU MAY HAVE THE RIGHT TO RESTRICT OR OBJECT TO CERTAIN PROCESSING. WE RESERVE THE RIGHT TO VERIFY IDENTITY BEFORE PROCESSING REQUESTS, AND CERTAIN INFORMATION MAY NOT BE DELETED WHERE RETENTION IS REQUIRED BY LAW OR NECESSARY TO ESTABLISH, EXERCISE, OR DEFEND LEGAL CLAIMS. REQUESTS MAY BE SUBMITTED USING THE CONTACT INFORMATION BELOW.
REGION-SPECIFIC DISCLOSURES: CALIFORNIA RESIDENTS MAY HAVE RIGHTS UNDER CCPA/CPRA, INCLUDING RIGHTS TO KNOW, DELETE, CORRECT, OPT OUT OF SALE/SHARING, AND LIMIT USE OF SENSITIVE PERSONAL INFORMATION WHERE APPLICABLE. EU AND UK USERS MAY HAVE RIGHTS UNDER GDPR, INCLUDING ACCESS, CORRECTION, DELETION, RESTRICTION, OBJECTION, DATA PORTABILITY, AND WITHDRAWAL OF CONSENT. LEGAL BASES FOR PROCESSING MAY INCLUDE CONSENT, LEGITIMATE INTERESTS, CONTRACTUAL NECESSITY, AND LEGAL OBLIGATIONS. CANADIAN USERS MAY HAVE RIGHTS UNDER PIPEDA. AUSTRALIAN USERS MAY HAVE RIGHTS UNDER THE PRIVACY ACT 1988. BRAZILIAN USERS MAY HAVE RIGHTS UNDER LGPD. JAPANESE USERS MAY HAVE RIGHTS UNDER APPI. WHERE LOCAL LAW REQUIRES SPECIFIC PROCEDURES OR DISCLOSURES, THOSE APPLY IN ADDITION TO THIS POLICY.
EXTERNAL LINKS: OUR WEBSITE MAY CONTAIN LINKS TO THIRD-PARTY WEBSITES. WE ARE NOT RESPONSIBLE FOR THE PRIVACY PRACTICES, SECURITY, OR CONTENT OF THIRD-PARTY SITES.
DATA SECURITY INCIDENTS: IN THE EVENT OF A DATA SECURITY INCIDENT, WE WILL COMPLY WITH APPLICABLE DATA BREACH NOTIFICATION LAWS. TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM LIABILITY FOR INCIDENTS ARISING FROM THIRD-PARTY PLATFORM FAILURES, SOPHISTICATED ATTACKS, OR EVENTS BEYOND REASONABLE CONTROL.
MARKETING COMMUNICATIONS: WHERE PERMITTED BY LAW, WE MAY SEND OPERATIONAL OR PROMOTIONAL COMMUNICATIONS. OPT-OUT MECHANISMS WILL BE PROVIDED WHERE REQUIRED. TRANSACTIONAL AND LEGAL NOTICES ARE NOT SUBJECT TO MARKETING OPT-OUT.
POLICY UPDATES; MODIFICATION AUTHORITY: WE MAY UPDATE THIS POLICY PERIODICALLY TO REFLECT LEGAL CHANGES, TECHNOLOGY CHANGES, BUSINESS OPERATIONS, OR PLATFORM UPDATES. REVISIONS WILL BE POSTED WITH AN UPDATED EFFECTIVE DATE AND/OR LAST UPDATED DATE. HERPTIVARIUS, LLC RESERVES THE RIGHT TO MODIFY THIS POLICY AT ANY TIME; CONTINUED USE OF THE WEBSITE CONSTITUTES ACCEPTANCE OF REVISIONS TO THE MAXIMUM EXTENT PERMITTED BY LAW.
CONTACT: FOR QUESTIONS OR REQUESTS REGARDING PRIVACY OR COOKIE CONTROLS, CONTACT LEGAL@HERPTIVARIUS.COM

