Privacy Policy

At Enchanted River Bath & Body, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or make a purchase.

Effective Date: January 15, 2026

1. Information We Collect

Personal Information You Provide

When you interact with our website, we may collect the following information:

Account Information:
  • Name (first and last)
  • Email address
  • Password (encrypted)
  • Account preferences
Order Information:
  • Shipping address
  • Billing address
  • Phone number
  • Order history
  • Product preferences
Payment Information:
  • Payment method details (processed securely through PayPal)
  • Transaction history
  • Note: We do not store credit card numbers on our servers
Communication Information:
  • Customer service inquiries and responses
  • Product reviews and ratings
  • Email correspondence
  • Survey responses

Information We Collect Automatically

When you visit our website, we automatically collect certain information:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages viewed, time spent on pages, links clicked, referring website
  • Location Data: General geographic location based on IP address
  • Shopping Behavior: Products viewed, items added to cart, purchase history

2. How We Use Your Information

We use the information we collect for the following purposes:

Order Processing and Fulfillment:
  • Process and complete your orders
  • Arrange shipping and delivery
  • Send order confirmations and updates
  • Handle returns, exchanges, and refunds
  • Provide customer support
Communication:
  • Send transactional emails (order confirmations, shipping notifications)
  • Respond to your inquiries and requests
  • Send promotional emails (with your consent)
  • Notify you of product updates or new offerings
Improvement and Personalization:
  • Analyze website usage and shopping patterns
  • Improve our products and services
  • Personalize your shopping experience
  • Recommend products based on your preferences
  • Optimize website performance and functionality
Legal and Security:
  • Comply with legal obligations
  • Prevent fraud and unauthorized transactions
  • Protect our rights and property
  • Enforce our terms and conditions
  • Resolve disputes

3. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience and collect information about how you use our website.

Types of Cookies We Use:

  • Essential Cookies: Required for website functionality (e.g., shopping cart, checkout)
  • Performance Cookies: Help us understand how visitors interact with our website
  • Functional Cookies: Remember your preferences and settings
  • Targeting Cookies: Used to deliver relevant advertisements (with your consent)

Managing Cookies:

You can control and manage cookies through your browser settings. Please note that disabling certain cookies may affect your ability to use some features of our website. Most browsers accept cookies automatically, but you can modify your browser settings to decline cookies if you prefer.

4. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:

Service Providers:

We share information with third-party service providers who perform services on our behalf:

  • Payment Processors: PayPal and other payment gateways to process transactions
  • Shipping Partners: USPS, UPS, FedEx for order delivery
  • Email Service Providers: For sending order confirmations and marketing emails
  • Web Hosting: Microsoft Azure for hosting our website and database
  • Analytics Providers: To analyze website traffic and user behavior
Legal Requirements:
  • When required by law, subpoena, or court order
  • To protect our rights, property, or safety
  • To enforce our terms and conditions
  • To prevent fraud or illegal activities
Business Transfers:

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership.

With Your Consent:

We may share information with third parties when you give us explicit consent to do so.

5. Data Retention

We retain your personal information only as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account Information: Retained until you request account deletion
  • Order Information: Retained for 7 years for tax and legal purposes
  • Marketing Communications: Retained until you unsubscribe
  • Analytics Data: Anonymized and retained for statistical purposes

When we no longer need your information, we will securely delete or anonymize it in accordance with our data retention policies and applicable laws.

6. Your Rights and Choices

You have the following rights regarding your personal information:

Access and Portability:
  • Request a copy of your personal information
  • Download your data in a portable format
Correction and Updates:
  • Update or correct inaccurate information
  • Complete incomplete information
Deletion:
  • Request deletion of your personal information
  • Close your account
  • Note: Some information may be retained for legal or legitimate business purposes
Marketing Communications:
  • Opt-out of marketing emails by clicking "unsubscribe" in any promotional email
  • Manage communication preferences in your account settings
  • Note: You will still receive transactional emails (order confirmations, shipping updates)
Do Not Track:

We currently do not respond to "Do Not Track" signals from browsers. You can manage tracking preferences through cookie settings.

How to Exercise Your Rights: To exercise any of these rights, please contact us at privacy@enchantedriverbathbody.com. We will respond within 30 days.

7. Children's Privacy

Our website is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@enchantedriverbathbody.com.

If we discover that we have collected personal information from a child under 13, we will delete that information as quickly as possible.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including:

  • Using secure data transfer protocols
  • Implementing appropriate contractual safeguards
  • Ensuring compliance with applicable data protection laws

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Right to Know:
  • What personal information we collect
  • How we use your information
  • Whether we sell or share your information
  • Third parties with whom we share information
Right to Delete:

Request deletion of your personal information (subject to certain exceptions)

Right to Opt-Out:

We do not sell your personal information. If our practices change, we will update this policy and provide you with the right to opt-out.

Right to Non-Discrimination:

We will not discriminate against you for exercising your CCPA rights, including by:

  • Denying goods or services
  • Charging different prices
  • Providing a different level of service
California Residents: To submit a request under CCPA, contact us at privacy@enchantedriverbathbody.com or call us at (555) 123-4567.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing:

We process your personal information based on:

  • Contract: To fulfill our contract with you (e.g., process orders)
  • Consent: When you provide consent (e.g., marketing emails)
  • Legitimate Interests: For fraud prevention, website improvement
  • Legal Obligation: To comply with laws and regulations
Your GDPR Rights:
  • Right of Access: Request a copy of your data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion ("right to be forgotten")
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your data protection authority
EU/UK Residents: To exercise your GDPR rights, contact us at privacy@enchantedriverbathbody.com.

11. Security Measures

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

Technical Safeguards:
  • Encryption: SSL/TLS encryption for data transmission
  • Secure Storage: Encrypted database storage
  • Access Controls: Limited employee access to personal information
  • Password Protection: Strong password requirements and hashing
  • Regular Updates: Security patches and software updates
Payment Security:
  • All payments processed through PCI-DSS compliant payment processors
  • We do not store credit card information on our servers
  • PayPal provides additional security layers
Organizational Measures:
  • Employee training on data protection
  • Data breach response procedures
  • Regular security audits and assessments
  • Confidentiality agreements with service providers
Important: While we implement strong security measures, no method of transmission over the internet or electronic storage is 100% secure. Please take precautions to protect your account credentials.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Updating the "Effective Date" at the top of this page
  • Sending an email notification for significant changes (if we have your email address)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Phone:

(555) 123-4567

Mailing Address:

Enchanted River Bath & Body
Attn: Privacy Officer
123 Main Street
Sterling, CO 80751
United States

Response Time: We will respond to all privacy-related inquiries within 30 days.

Last Updated: January 15, 2026

This Privacy Policy is effective as of the date listed above and applies to all information collected through our website and any related services.