Privacy policy
Last updated: May 21, 2026
WonderBiotics ("we," "our," "us") is a brand of WONDERLAB NUTRITION LIMITED, a Delaware corporation qualified to do business in California. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit wonderbiotics.com (the "Site"), purchase our products, or otherwise interact with us. It also describes your rights and how to exercise them.
If you have any questions, contact us at contact@wonderbiotics.com with the subject line "Privacy."
Notice at Collection (Summary)
This table summarizes the categories of personal information we collect, why we collect it, how we share it, and how long we keep it. The full details are in the sections below.
| Category | Examples | Why we collect it | Shared with | Retention |
|---|---|---|---|---|
| Identifiers | name, email, phone, shipping/billing address, IP address, account credentials | Order processing, account management, communications, fraud prevention | Shopify, shipping carriers, payment processors, Klaviyo (email/SMS) | 7 years (tax/order records) or until account deletion, whichever is later |
| Commercial information | products viewed and purchased, subscription preferences | Order fulfillment, product recommendations, marketing | Shopify, Klaviyo, Appstle (subscriptions), advertising partners (see §5.2) | 7 years |
| Internet / device activity | pages viewed, clicks, session recordings, device type, browser | Analytics, Site improvement, advertising | Google Analytics, Microsoft Clarity, advertising partners (see §5.2) | 26 months (default analytics) |
| Customer communications | emails, chat messages, reviews, survey responses, adverse event reports | Customer support, quality improvement, regulatory compliance | Internal support team, Judge.me (reviews), FDA (serious adverse events only) | 3 years (general) / 6 years (adverse event reports, per FDA recordkeeping) |
| Sensitive personal information (CPRA) | account login credentials; purchase patterns that may suggest health interests | Account access, order fulfillment, product recommendations | Same as above; not used for inferring characteristics beyond product recommendations | Same as above |
Do we "sell" your personal information? No. We do not sell personal information for money. Some sharing with advertising partners for cross-context behavioral advertising may be considered "sharing" under California law — see Section 4.2 for details and Section 5.2 to opt out.
1. Information We Collect
1.1 Information you provide to us directly:
- Account and order data: name, shipping and billing address, phone number, email address, password.
- Payment information: processed by our payment providers (Shopify Payments, PayPal, Shop Pay). We do not store full card numbers on our servers.
- Customer communications: messages you send via email, chat, product reviews, surveys, or adverse event reports.
- Subscribe & Save preferences: products, cadence, shipping address, and modifications.
- Marketing preferences: email subscription, SMS opt-in (see Section 8), and your marketing consents.
1.2 Information we collect automatically when you use the Site:
- Device and usage: IP address, browser type and version, operating system, device identifiers, pages viewed, referring URL, search terms, time on page, clicks.
- Cookies and similar technologies: see Section 9.
1.3 Information from third parties: we may receive information from advertising and analytics partners, social media platforms, and identity verification services to help us prevent fraud, deliver more relevant marketing, and improve the Site.
2. Sensitive Personal Information under California Law
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), defines "Sensitive Personal Information" (SPI) to include categories such as account login credentials, precise geolocation, and information concerning health.
WonderBiotics products are dietary supplements, and your purchase choices may suggest interests related to digestive health, women's health, weight management, sleep, immunity, or other health-adjacent topics. We treat this purchase information as sensitive:
- We do not sell SPI.
- We do not share SPI with advertising networks for the purpose of inferring health-related characteristics about you.
- We use SPI internally only to fulfill your orders, provide customer support, and surface on-site product recommendations.
- You have the right to limit the use of your SPI — see Section 5.3.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- Process and ship your orders, manage your Subscribe & Save enrollments, and provide customer support.
- Send transactional communications (order confirmations, shipping updates, account changes, subscription reminders).
- Send marketing emails to subscribers and, with your express consent, SMS messages — you can unsubscribe at any time (Section 8).
- Personalize product recommendations and Site content based on the products you have viewed or purchased.
- Measure and improve Site performance, marketing effectiveness, and product quality.
- Prevent fraud, detect abuse, and protect the security of our Site and customers.
- Comply with legal obligations, including reporting serious adverse events to the U.S. Food and Drug Administration (FDA) as required by the Dietary Supplement and Nonprescription Drug Consumer Protection Act.
4. How We Share Your Information
4.1 Service Providers (Processors)
We share personal information with service providers who help us operate the business and who are contractually limited to using your information only on our behalf:
- E-commerce platform & checkout: Shopify Inc.
- Email and SMS marketing: Klaviyo, Inc.
- Subscription management: Appstle.
- Product reviews: Judge.me.
- Analytics: Google Analytics 4 (Google LLC), Microsoft Clarity (Microsoft Corporation).
- Shipping carriers: USPS, UPS, FedEx, and our shipping partners.
- Payment processors: Shopify Payments, PayPal, Shop Pay.
4.2 Advertising Partners — "Sharing" Under California Law
We work with advertising platforms that may place pixels, tags, or cookies on the Site to deliver advertising to you on other websites and apps (called "cross-context behavioral advertising"). These partners include:
- Meta (Facebook / Instagram)
- TikTok
- Google Ads
- Applovin
Under California law, this kind of disclosure of personal information may be considered "sharing," even though we do not receive money in exchange. You have the right to opt out — see Section 5.2.
4.3 Legal, Safety, and Regulatory
We may disclose information when required by law, subpoena, court order, or to protect rights, property, or safety. As required by federal law, we report serious adverse events related to our dietary supplements to the FDA; FDA submissions include the identifying information necessary for the report and exclude information that is not relevant to the event.
4.4 Business Transfers
In the event of a merger, acquisition, financing, or sale of assets, personal information may be transferred to the successor entity. We will provide notice of any such transfer in advance where practicable.
4.5 We Do Not Sell Your Personal Information
We do not sell personal information in exchange for money. In the 12 months preceding the "Last updated" date at the top of this Privacy Policy, we have not received money or other monetary consideration in exchange for personal information about consumers.
5. Your California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights with respect to your personal information.
5.1 Right to Know, Access, Correct, and Delete
- Right to know: the categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to access: a copy of the specific pieces of personal information we have collected about you in the prior 12 months.
- Right to correct: request that we correct inaccurate personal information.
- Right to delete: request that we delete personal information we have collected, subject to legal exceptions (such as completing transactions, fraud prevention, and legal compliance).
5.2 Right to Opt Out of "Sale" and "Sharing"
You have the right to opt out of the "sale" and "sharing" of your personal information, as those terms are defined under California law.
You can exercise this right in any of the following ways:
- Email us: send a message to contact@wonderbiotics.com with the subject line "Do Not Sell or Share." Tell us the email address on your account.
- Browser signal (Global Privacy Control): we honor the Global Privacy Control (GPC) signal as a valid opt-out request from California residents. If you enable GPC in your browser, we will treat your visit as an opt-out automatically — no further action is needed while using that browser. Learn how to enable GPC at globalprivacycontrol.org.
We will process your opt-out request within 15 business days. After we process it, we will stop disclosing your personal information to the advertising partners listed in Section 4.2 for cross-context behavioral advertising, and we will instruct those partners to delete information they received about you for advertising purposes, to the extent feasible.
5.3 Right to Limit the Use of Sensitive Personal Information
You have the right to direct us to limit the use of your Sensitive Personal Information (SPI) to what is necessary to provide our products and services and to perform the operationally exempt uses listed in CCPA regulations (such as security and fraud prevention).
To exercise this right, email contact@wonderbiotics.com with the subject line "Limit Use of My Sensitive Personal Information." After we process your request, we will not use your SPI for personalized product recommendations or any other non-exempt purpose.
5.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights. We will not deny you products or services, charge you different prices, or provide a different level of service.
5.5 Authorized Agents
You may use an authorized agent to submit a request on your behalf. We will require written proof of authorization (such as a signed and dated authorization, or a power of attorney) and may require you to verify your own identity directly with us before we act on the request.
5.6 How to Submit a Request and How We Verify
Submit any privacy request by email to contact@wonderbiotics.com with the relevant subject line. We will verify your identity by matching the information in your request against information we have on file (typically your email address, recent order number, or other account identifiers). For deletion requests, we will ask you to re-confirm by replying to a follow-up email.
We respond to verifiable requests within 45 calendar days. We may extend this period once by an additional 45 days where reasonably necessary, with notice to you.
6. Your Privacy Rights — Other US States
Residents of other US states that have enacted comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Tennessee, and New Jersey — have rights similar to those described in Section 5. To exercise your rights, use the same email address (contact@wonderbiotics.com) and the relevant subject line. We respond within the timeframe required by your state's law (generally 45 days).
7. International Users
WonderBiotics is based in the United States and ships only to US addresses. If you access the Site from outside the US, your information will be transferred to and processed in the United States, which may not provide the same level of data protection as the laws of your country. By using the Site, you consent to this transfer.
If you are an EU, UK, or other non-US visitor and you have privacy questions, email contact@wonderbiotics.com.
8. SMS / Text Message Marketing
8.1 How You Opt In
We send SMS messages only if you have given express prior consent. You may opt in by:
- entering your mobile number and checking the SMS consent box at checkout, account creation, or in a marketing signup form on the Site; or
- texting our keyword to our short code; or
- otherwise providing express prior written consent as required by the federal Telephone Consumer Protection Act (TCPA).
8.2 What We Send and How Often
We may send: order confirmations and shipping updates, Subscribe & Save reminders, abandoned cart reminders, promotional offers, product launches, and surveys. Messages may be sent using an automated dialing system. Promotional message frequency varies but generally does not exceed 6 messages per month. Transactional messages are sent as needed.
Message and data rates may apply, charged by your mobile carrier. WonderBiotics does not charge a fee for receiving SMS messages.
8.3 How You Opt Out
Reply STOP to any message we send you to opt out. After you reply STOP, we will send one final confirmation message and will not send you any further promotional or transactional SMS, except a message confirming your opt-out. For help, reply HELP or email contact@wonderbiotics.com.
8.4 SMS Consent and Mobile Data — Not Shared with Third Parties
Mobile information that you provide to us as part of the SMS opt-in process — including your phone number and your consent to receive messages — is not shared with any third party or affiliate for their marketing or promotional purposes. The only third parties who receive your mobile number are our SMS service provider (Klaviyo) and the underlying mobile carriers, in each case solely to deliver the messages you have signed up to receive. This commitment is required under our SMS provider's 10DLC registration and is enforced by US mobile carriers under industry guidelines.
9. Cookies and Tracking Technologies
We use cookies, pixels, and similar technologies for the following purposes:
- Essential cookies: shopping cart, checkout, account login, security. The Site cannot function properly without these.
- Analytics cookies: Google Analytics 4, Microsoft Clarity. These help us understand how the Site is used.
- Advertising cookies and pixels: Meta Pixel, TikTok Pixel, Google Ads conversion tracking, Applovin. These help us deliver and measure advertising.
You can control non-essential cookies through your browser settings (most browsers let you block third-party cookies). Disabling essential cookies may break parts of the Site.
Do Not Track: our Site does not currently respond to "Do Not Track" browser headers, because there is no industry standard for how to do so. We do, however, honor the Global Privacy Control (GPC) signal for California residents as described in Section 5.2.
10. Data Retention
We retain personal information for as long as your account is active or as needed to provide our products and services. After that, we retain information as required by law (typically up to 7 years for order and tax records, and 6 years for serious adverse event reports as required by FDA recordkeeping rules). When information is no longer needed, we delete or anonymize it.
11. Data Security
We use commercially reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit, access controls, and vendor due diligence. No system is fully secure, however, and we cannot guarantee that unauthorized access will never occur. If we become aware of a security incident that affects your personal information, we will notify you as required by applicable law.
12. Children's Privacy
Under 13 (COPPA): Our Site is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information.
Under 18 (California SB-568): California residents under 18 who are registered users of the Site may request removal of content or information that they have posted on the Site by emailing contact@wonderbiotics.com. Removal of posted content does not ensure complete or comprehensive removal from the Internet.
Sale and sharing of minors' information: We do not knowingly sell or share for cross-context behavioral advertising the personal information of California residents under 16 without affirmative authorization.
If you believe a minor has provided us with personal information, please contact us at contact@wonderbiotics.com and we will investigate and delete as appropriate.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. Material changes will be communicated by email to account holders or by a prominent notice on the Site before they take effect.
14. Contact Us
For any privacy questions, requests, or to exercise your rights:
Email: contact@wonderbiotics.com
Mail: WONDERLAB NUTRITION LIMITED, Attn: Privacy, 17800 Castleton St, Ste 665, City of Industry, CA 91748, USA