Privacy Policy
1. Who We Are
Grimm’s Apothecary LLC (“Company,” “we,” “us,” or “our”) is a single-member S-corporation incorporated in New York and operating at grimmsapothecary.net. Our principal place of business is Port Jervis, New York, United States.
We operate an e-commerce store selling herbal medicine and wellness products, a health coaching and data analysis consultation service, and a subscription-based research content platform hosted in part through Patreon. We also maintain a public health and wellness community of over 130,000 members across social platforms.
This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website, purchase from our store, engage our coaching services, subscribe to our newsletter, or access our Patreon-gated research content.
For purposes of the General Data Protection Regulation (GDPR), Grimm’s Apothecary LLC is the data controller for information collected directly on grimmsapothecary.net. Where we use third-party service providers, those providers may be independent data controllers or data processors, as described below.
2. Data We Collect
2.1 Information You Provide Directly
- Account & order information: Name, email address, billing and shipping address, phone number, order history, and purchase preferences when you create an account or complete a purchase through our WooCommerce store.
- Payment information: We do not store raw payment card data. Payment transactions are processed by our payment processor (Stripe or PayPal). We receive only tokenized payment references and transaction confirmation data.
- Health coaching data: If you engage our health coaching or data analysis consultation services, you may voluntarily provide information about your health conditions, symptoms, medications, supplements, dietary habits, and lifestyle factors. This constitutes sensitive personal information and is handled with heightened protections described in Section 15.
- Communications: Messages, emails, support enquiries, and consultation notes exchanged with us.
- Newsletter subscription: Email address and, optionally, name and health interest preferences.
- User-generated content: Comments, reviews, or forum posts you submit publicly on our website.
2.2 Information Collected Automatically
- Log and usage data: IP address, browser type and version, operating system, pages visited, time and date of visit, referring URLs, and session duration. Collected by our web server and analytics tools.
- Device data: Device type, screen resolution, and approximate geographic location derived from IP address.
- Cookies and similar technologies: See Section 8 for full details. WooCommerce uses session cookies for cart management. We may use analytics cookies (e.g., Google Analytics) and functional cookies for preferences.
- Transaction data: Purchase amounts, product selections, discount codes used, and shipping preferences.
2.3 Information from Third Parties
- Patreon: When you authenticate via “Sign in with Patreon,” Patreon’s OAuth 2.0 system provides us with your Patreon user ID, display name, email address, membership tier, pledge amount, pledge start date, and patron status. We do not receive your Patreon password. See Section 14 for full details.
- Payment processors: Transaction status, billing name, and partial card information (last four digits, card type) from Stripe or PayPal.
- Social media platforms: If you interact with our content on Instagram, Twitter/X, YouTube, or Patreon, those platforms’ privacy policies govern data collected on their platforms. We may receive aggregated analytics from these platforms.
3. How We Use Your Data
- Fulfilling orders: Processing, shipping, and confirming product purchases; handling returns and refunds.
- Delivering services: Providing health coaching consultations, data analysis, and access to Patreon-gated research content.
- Account management: Creating and maintaining your customer or member account; authenticating your identity and Patreon tier.
- Communications: Sending order confirmations, shipping notifications, support responses, and — where you have opted in — newsletter content and promotional communications.
- Analytics and improvement: Understanding how visitors use our website, identifying popular content, and improving the user experience. We use aggregated, anonymised data wherever possible for analytics.
- Security and fraud prevention: Detecting, investigating, and preventing fraudulent transactions, chargebacks, and unauthorised access to accounts.
- Legal compliance: Meeting obligations under applicable law, including tax reporting, record-keeping, and responding to valid legal requests.
- Marketing (with consent): Sending newsletters, educational content, and product announcements where you have subscribed or we have a legitimate interest based on a prior purchase relationship.
We do not sell your personal information. We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. Ever.
4. Lawful Basis for Processing — EEA & UK Residents (GDPR)
Where the GDPR applies, we process personal data on the following lawful bases:
- Contract performance (Article 6(1)(b))
- Processing necessary to fulfil your orders, deliver coaching services, provide account access, and manage the customer relationship.
- Legal obligation (Article 6(1)(c))
- Processing required to comply with tax law, accounting regulations, and valid legal requests.
- Legitimate interests (Article 6(1)(f))
- Analytics to improve our services; fraud prevention; security monitoring; and direct marketing to existing customers regarding similar products and services (you may opt out at any time).
- Consent (Article 6(1)(a))
- Newsletter subscription; non-essential cookies; and collection of sensitive health data for coaching services. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Special category data — Explicit consent (Article 9(2)(a))
- Health and medical information provided for coaching purposes. You explicitly consent to this processing when you engage our consultation services. This data is processed under Article 9 special category protections.
5. How We Share Your Data
We share personal data only as necessary to operate our business, with the following categories of recipients:
5.1 Service Providers (Data Processors)
- Payment processing: Stripe, Inc. and/or PayPal Holdings, Inc. — process transactions under their own PCI-DSS compliance frameworks.
- Web hosting: Our hosting provider stores website files and databases on servers in the United States.
- Email delivery: Our email service provider (e.g., Mailchimp, ConvertKit, or Klaviyo) transmits newsletters and transactional emails on our behalf.
- Analytics: Google Analytics (Google Ireland Limited) — we use Google Analytics with IP anonymisation enabled. You may opt out via the Google Analytics Opt-out Browser Add-on.
- Shipping carriers: USPS, UPS, FedEx, or similar carriers receive your name and shipping address to deliver products.
5.2 Patreon
When you use “Sign in with Patreon,” data flows between your browser, Patreon’s servers, and our servers as described in Section 14. Patreon is an independent data controller for data held on its platform.
5.3 Legal Requirements
We may disclose personal data if required to do so by law, court order, subpoena, or other valid legal process; to protect the rights, property, or safety of Grimm’s Apothecary LLC, our customers, or others; or to detect, prevent, or address fraud, security, or technical issues.
5.4 Business Transfers
In the event of a merger, acquisition, asset sale, or reorganisation of Grimm’s Apothecary LLC, personal data may be transferred to the relevant successor entity. You will be notified of any such transfer and any material changes to this Policy.
5.5 What We Do Not Do
- We do not sell personal data to data brokers or advertising networks.
- We do not share health coaching data with any third party without your explicit written consent, except as required by law.
- We do not use your data for automated individual decision-making or profiling with legal or similarly significant effects without offering human review.
6. Data Retention
- Order and transaction records: Retained for 7 years to meet IRS and New York State tax record-keeping requirements.
- Account data: Retained while your account is active and for 3 years after your last interaction, unless you request deletion sooner.
- Health coaching notes: Retained for the duration of the coaching relationship and for 5 years thereafter, unless you request earlier deletion and no legal obligation requires retention.
- Newsletter subscribers: Retained until you unsubscribe. Unsubscription suppression records are kept indefinitely to prevent re-subscription errors.
- Server and access logs: Retained for 90 days for security purposes, then deleted.
- Patreon OAuth tokens: Access tokens are held in encrypted server-side sessions and expire per Patreon’s token lifecycle. Refresh tokens are stored in encrypted form and rotated on use.
7. Security
We implement technical and organisational security measures appropriate to the risk of processing, consistent with the requirements of the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb) and GDPR Article 32. These include:
- TLS/HTTPS encryption for all data in transit.
- Server-side encrypted storage for OAuth tokens and sensitive user data.
- WordPress file editing disabled at the application layer (
DISALLOW_FILE_EDIT). - Web Application Firewall (WAF) and brute-force login protection.
- Two-factor authentication on all administrative accounts.
- Regular encrypted off-site backups.
- Restricted REST API user enumeration.
- HTTP security headers (X-Content-Type-Options, Referrer-Policy, Permissions-Policy).
- Payment card data never stored on our servers — handled exclusively by PCI-DSS-compliant processors.
No method of transmission or storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law (GDPR: within 72 hours of awareness; NY SHIELD Act: in the most expedient time possible).
8. Cookies & Tracking Technologies
We use cookies and similar technologies. For full details, see our standalone Cookie Policy. In summary:
- Strictly necessary cookies: WooCommerce cart session cookies, WordPress login session cookies, and security tokens. Cannot be disabled without breaking core site functionality.
- Functional cookies: Remember your preferences (currency, language, dismissed notices).
- Analytics cookies: Google Analytics (with IP anonymisation). You may opt out at any time.
- Patreon session: We store Patreon authentication state in a server-side PHP session (not in browser-accessible localStorage or cookies). Session IDs are transmitted via a secure, HttpOnly cookie.
EEA/UK users will be asked for cookie consent (beyond strictly necessary cookies) via our cookie consent tool. California users may opt out of analytics tracking via the “Do Not Sell or Share” link in our footer.
9. Your Rights — EEA, UK & Swiss Residents (GDPR / UK GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the GDPR or equivalent legislation:
Right of Access (Art. 15)
Request a copy of the personal data we hold about you and information about how it is processed.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data where it is no longer necessary, you withdraw consent, or you object and we have no overriding legitimate grounds.
Right to Restriction (Art. 18)
Request that we restrict processing of your data while a dispute is resolved.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format where processing is based on consent or contract.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including direct marketing. We will cease unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent
Withdraw consent at any time for consent-based processing, without affecting prior lawful processing.
Right to Lodge a Complaint
Complain to your national supervisory authority. UK residents: the ICO (ico.org.uk). EU residents: your Member State DPA.
To exercise any of these rights, contact us at privacy@grimmsapothecary.net. We will respond within 30 days (extendable by 60 days for complex requests with notice).
10. Your Rights — California Residents (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purposes, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected, subject to legal retention requirements.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising. You may nonetheless submit an opt-out request via Do Not Sell or Share My Personal Information.
- Right to Limit Use of Sensitive Personal Information: Request that we limit use of sensitive personal information (including health data) to purposes necessary to provide the requested services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. We will not deny goods or services, charge different prices, or provide a different quality of service based on your exercise of these rights.
To submit a verifiable consumer request: email privacy@grimmsapothecary.net with the subject line “CCPA Request.” We will respond within 45 days. You may designate an authorised agent to submit requests on your behalf.
Categories of Personal Information Collected (CCPA Categories)
- Identifiers (name, email, IP address, Patreon user ID)
- Commercial information (purchase history, products considered)
- Internet or other electronic network activity (browsing history on our site)
- Geolocation data (city/region derived from IP address)
- Health and medical information (coaching clients only — sensitive category)
- Inferences drawn from the above to create a profile (e.g. product interest categories)
11. New York Residents — NY SHIELD Act
Grimm’s Apothecary LLC, as a New York-domiciled business, complies with the Stop Hacks and Improve Electronic Data Security (SHIELD) Act (N.Y. Gen. Bus. Law § 899-bb), which requires us to implement a reasonable data security programme to protect private information of New York residents.
Our security programme includes the administrative, technical, and physical safeguards described in Section 7. In the event of a breach of private information of New York residents, we will provide notice without unreasonable delay in accordance with N.Y. Gen. Bus. Law § 899-aa.
12. Children’s Privacy
Our website, products, and services are intended for adults aged 18 and over. We do not knowingly collect personal information from individuals under the age of 18. If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately at privacy@grimmsapothecary.net and we will promptly delete such data.
Our store requires purchasers to be 18 or older. Coaching services require clients to be 18 or older, or to have verifiable parental consent.
13. International Data Transfers
Grimm’s Apothecary LLC is based in the United States. If you are located outside the United States (including in the EEA or UK), your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction.
Where we transfer personal data from the EEA or UK to the United States, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) as approved by the European Commission, the UK International Data Transfer Agreement (IDTA), and/or the EU-US Data Privacy Framework where applicable.
You may request a copy of the applicable transfer mechanism by contacting privacy@grimmsapothecary.net.
14. Patreon OAuth Integration
We offer “Sign in with Patreon” functionality to allow Patreon patrons to access tier-gated research content on our website (and subdomains). Here is how that data flow works:
- You click “Sign in with Patreon” and are redirected to Patreon’s official login page. We never see your Patreon password.
- After authenticating with Patreon, you are redirected back to our site with a one-time authorisation code.
- Our server exchanges this code with Patreon’s API for an access token.
- We use the access token to query Patreon’s API for: your Patreon user ID, display name, email address, membership tier title, pledge amount (in cents), pledge start date, and patron status (active/declined/former).
- This data is stored in an encrypted server-side session. It is not stored in browser localStorage or unencrypted cookies.
- We use this data solely to verify your eligibility for content access and to implement any drip-content time-gating based on your membership tenure.
Access tokens expire per Patreon’s token lifecycle. We store encrypted refresh tokens to silently renew access without requiring you to re-authenticate. Sessions are invalidated when you log out.
Patreon is an independent data controller for data on its platform. Its privacy practices are governed by Patreon’s Privacy Policy.
15. Sensitive Health Data
Health information is our most protected data category. If you engage our health coaching or data analysis consultation services, you may voluntarily share sensitive health information. This section describes the heightened protections we apply.
- Health data shared in consultations is used solely to provide the coaching or analysis service you have requested.
- It is never shared with third parties without your explicit written consent, except as required by applicable law.
- It is never used for marketing, advertising, or profiling.
- Consultation notes are stored in encrypted form, separate from standard customer account data.
- We communicate sensitive health information only through encrypted channels.
- We are not a HIPAA-covered entity and our services do not constitute a physician-patient relationship. See our Health & Medical Disclaimer for important scope-of-practice disclosures.
16. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will update the “Last Updated” date at the top of this page and, where the changes significantly affect how we process your data, notify you by email or by a prominent notice on our website at least 30 days before the changes take effect.
Your continued use of our website and services after the effective date of any revised Policy constitutes your acceptance of the changes.
17. Contact Us
For any questions, concerns, or to exercise your data rights:
Data Controller
Grimm’s Apothecary LLC
Port Jervis, New York, United States
Email: privacy@grimmsapothecary.net
Website: grimmsapothecary.net
We aim to respond to all privacy-related enquiries within 5 business days and will always meet applicable statutory response deadlines.
EEA residents who are not satisfied with our response have the right to lodge a complaint with the supervisory authority in their Member State. UK residents may contact the Information Commissioner’s Office at ico.org.uk.