Legal
GDPR, Data Protection Notice
How we handle personal data belonging to visitors and customers in the EEA, the United Kingdom and Switzerland, and how to exercise your rights.
Hello Goodies LLC
108 Lakeland Ave, Dover, Delaware 19901
About this notice
This notice explains how Hello Goodies LLC(“we,” “us,” “our”) collects, uses, stores and protects the personal data of visitors and customers in the European Economic Area, the United Kingdom and Switzerland, in line with the EU General Data Protection Regulation 2016/679 and equivalent UK and Swiss law. It supplements our Privacy Policy.
1. Data controller
The controller responsible for your personal data is:
Hello Goodies LLC
108 Lakeland Ave, Dover, Delaware 19901
Email: support@hellogoodiesdaily.com
2. What personal data we collect
We collect and process the following categories of personal data:
- Identity data: first name, last name.
- Contact data: billing address, shipping address, email address, telephone number.
- Transaction data: the products you have ordered, order and shipment history, and a token or fingerprint identifying the payment method. We do not store your full card number; card data is handled by the PCI-DSS-compliant payment providers named in section 7.
- Technical data: IP address, browser type and version, device identifier, time zone, operating system, referring URL.
- Usage data: how you use the website, including pages viewed, links followed and session duration.
- Communication data: the messages you send us through a contact or cancellation form, and your preferences for receiving communications from us.
3. Lawful basis for processing
Under Article 6 GDPR we process personal data only where at least one lawful basis applies:
- Performance of a contract: processing needed to take your order, deliver it, bill a subscription you chose, the same price every 32 days until you cancel, and handle returns and cancellations.
- Consent: non-essential cookies and electronic marketing, where you have opted in.
- Legal obligation: tax, accounting, fraud prevention and other compliance duties.
- Legitimate interests: keeping the website and our payments secure, preventing abuse, and contacting existing customers about their orders, subject to your right to object.
4. Your rights as a data subject
Under Articles 15–22 GDPR you have the rights below in relation to your personal data. Exercise any of them free of charge by emailing support@hellogoodiesdaily.com. We respond within 30 days of receiving your request, which is inside the deadline GDPR sets for a data subject request.
- Right of access, request a copy of the personal data we hold about you.
- Right to rectification, ask us to correct data that is inaccurate or incomplete.
- Right to erasure, ask us to delete your personal data where there is no overriding reason for us to keep processing it.
- Right to restrict processing, ask us to suspend processing in certain circumstances.
- Right to data portability, receive your data in a structured, commonly used, machine-readable format, and have it sent to another controller where that is technically feasible.
- Right to object, object to processing based on legitimate interests, including direct marketing.
- Rights concerning automated decisions, not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- Right to withdraw consent, where processing rests on consent, withdraw it at any time, without affecting processing carried out before you did.
A data request is not a cancellation. To stop future shipments and charges, use the cancellation page or the channels listed in our Subscription Policy.
5. Data retention
We keep personal data only as long as needed for the purpose it was collected for, including to satisfy legal, accounting and reporting requirements. Order and transaction records are typically kept for seven (7) years to comply with tax and accounting law. Marketing preferences are kept until you withdraw consent or object.
6. International data transfers
Hello Goodies LLCis established in the United States, so providing our services involves transferring personal data outside the EEA, the UK and Switzerland. Where we do so we rely on a safeguard permitted by Chapter V GDPR, including the European Commission’s Standard Contractual Clauses and, where appropriate, supplementary technical and organisational measures.
7. Who we share data with
We share personal data with processors that act on our behalf and only on our documented instructions. Each is bound by contract to protect your data and to use it only for the purpose we specify. The recipients are:
- Woosa Payments (Woosa B.V., KvK 71751513, Zwolle, the Netherlands), our payment platform. Its privacy statement is at woosa.com/privacy.
- Adyen N.V., the licensed payment institution that processes and settles the payment, supervised by De Nederlandsche Bank.
- Order management and fulfilment providers, the platform that records your order and the warehouse and carrier (USPS) that pick, pack and deliver it.
- Fraud prevention, hosting and email providers , the infrastructure that runs the website and delivers our transactional email.
- Professional advisers and authorities, where disclosure is required by law or needed to establish, exercise or defend a legal claim.
We do not sell personal data.
8. Cookies
We use strictly necessary cookies to operate the website, the cart and the checkout, and, with your consent, analytics cookies to understand how the site is used. You can manage cookie preferences in your browser settings; blocking strictly necessary cookies will prevent an order from being completed.
9. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. Card data is transmitted over TLS-encrypted connections and handled by the PCI-DSS-compliant providers named in section 7.
10. Right to lodge a complaint
If you believe our processing of your personal data infringes GDPR, you may lodge a complaint with the supervisory authority of the EU or UK member state where you live, where you work, or where the alleged infringement took place. A list of EU authorities is published at edpb.europa.eu. In the UK, contact the Information Commissioner’s Office at ico.org.uk. We would rather hear from you first, so please write to us as well.
11. Changes to this notice
We may update this notice from time to time. The version published on this page is always the current one, and material changes will be announced on the website.
12. Contact
For any question about this notice, to exercise a right, or to raise a data protection complaint with us directly, email support@hellogoodiesdaily.com or write to Hello Goodies LLC, 108 Lakeland Ave, Dover, Delaware 19901.