Privacy policy
Privacy Policy
Effective date: October 22, 2025
This Privacy Policy (“Policy”) explains how Maeva USA Inc., a Florida corporation d/b/a “Maeva” (“Maeva,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you visit www.maeva.co, create an account, make a purchase, subscribe to autoship, contact support, or interact with our emails/SMS/ads (collectively, the “Services”).
By using the Services, you consent to the practices described here. Our Terms of Service (including Terms of Sale) govern your use of the Services: https://maeva.co/policies/terms-of-service.
If you have questions or want to exercise a privacy right, contact privacy@maeva.co.
1) Scope & Audience
This Policy applies to personal information we collect about consumers in the United States. If you are located in the EEA/UK/Switzerland, see Section 11 for additional information.
The Services are intended for individuals 18 years and older and are not directed to children under 13 (see Section 10).
2) Personal Information We Collect
We collect the categories of personal information listed below. The exact data we collect depends on how you interact with us.
- Identifiers & Contact Info. Name, email, shipping/billing address, phone number, account credentials.
- Commercial & Transaction Data. Products viewed/added/purchased, order history, subscription settings, promo redemptions.
- Payment Info. Last four digits, card type, and tokenized payment identifiers processed through our payment processors (we do not store full card numbers).
- Device/Network Activity. IP address, device/browser type, referrer, pages viewed, time on site, clicks, approximate location (city/region) derived from IP, application identifiers; collected via cookies, pixels, SDKs, and logs.
- Inferences & Preferences. Interest segments, flavor preferences, likelihood to reorder, derived from your interactions (where permitted by law).
- User Content. Reviews, ratings, photos, survey responses, customer support messages.
- Sensitive Data (limited). We do not request health/medical information. If you share healthrelated details in reviews, surveys, or support interactions, we process them only to provide the requested service and advise you not to include sensitive information unless necessary.
3) Sources of Personal Information
- You directly, when you create an account, place an order, join email/SMS, contact support, or submit reviews.
- Automatically, via cookies/pixels/SDKs when you use the Services.
- Service providers & partners, such as ecommerce, payment, fulfillment, analytics, advertising, review, and customersupport platforms.
- Social media & referral programs, when you connect or interact with our pages or use referral links.
4) How We Use Personal Information
- Provide the Services. Process orders, payments, fulfillment, account management, subscriptions, returns/exchanges, and customer support.
- Communicate. Send transactional emails/SMS (order confirmations, shipping, subscription reminders) and respond to inquiries.
- Improve & personalize. Troubleshoot, analyze usage, develop new features/products, and personalize content and offers.
- Marketing & advertising. Deliver, measure, and improve our marketing on Maeva and thirdparty sites/apps; manage promotions and referrals (where offered).
- Security & fraud prevention. Detect, prevent, and investigate fraud, abuse, or security incidents.
- Legal & compliance. Satisfy tax/audit obligations, enforce terms, and comply with law.
5) Cookies, Tracking, and Your Choices
We use cookies, pixels, tags, SDKs, and similar technologies to operate the site, remember preferences, measure performance, and provide ads/analytics. Some tracking is essential to the Services; others are optional and used for analytics/advertising.
Preferences. You can manage cookies via your browser settings and (if available) our onsite Cookie Preferences tools. You may also opt out of crosscontext behavioral advertising as described in Section 7.
Do Not Track & GPC. Do Not Track (DNT) signals are not widely honored. Where required by law, we treat a valid Global Privacy Control (GPC) signal as a request to opt out of “sale”/“sharing”/targeted advertising for that browser.
6) How We Disclose Personal Information
We disclose personal information to:
- Service providers/contractors who perform services on our behalf (e.g., ecommerce hosting, payments, fulfillment/3PL, customer support, email/SMS, analytics, advertising, reviews, fraud prevention). We contractually restrict their use of personal information.
- Advertising/analytics partners to measure performance and deliver ads. This may be considered a “sale”/“sharing” or “targeted advertising” under certain state laws (see Section 7).
- Legal/safety. To comply with law, protect rights, or respond to lawful requests.
- Business transfers. In connection with a merger, acquisition, or asset sale.
We do not provide personal information to third parties for their own direct marketing without your consent.
7) Your Privacy Choices (U.S.)
Depending on your state, you may have rights to access, delete, correct, opt out of sales/sharing/targeted advertising, and port your data. To exercise a right or submit an optout request:
- Email: privacy@maeva.co
- We honor Global Privacy Control (GPC) signals for the browser where the signal is present.
We will verify your request (e.g., by email link or known account information) and respond within the timeframe required by law. You may designate an authorized agent (California) to make certain requests on your behalf; we may require proof of identity and authorization.
Nondiscrimination. We will not discriminate against you for exercising your privacy rights.
Appeals. If we deny your request, you may appeal by replying to our decision email or writing to privacy@maeva.co with “Privacy Appeal” in the subject. We will respond within the period required by applicable law.
Financial incentives. If we offer loyalty/rewards that involve personal information, we will provide a separate Notice of Financial Incentive describing the material terms. Participation is always optional and you can withdraw at any time.
8) California Notice at Collection
We provide this summary of the categories of personal information we collect, the purposes, whether we “sell”/“share,” and typical retention periods. “Sell”/“share” are defined by California law and may include certain advertising/analytics disclosures.
|
Category |
Examples |
Purpose of Use |
Disclosed to |
Sold/Shared? |
Typical Retention |
|
Identifiers & Contact |
name, email, address, phone, IP |
accounts, orders, support, marketing, security |
service providers; advertising/analytics |
Shared for ads/analytics; not sold for money |
account life + up to 3 years after last activity |
|
Commercial Data |
purchases, preferences, promo usage |
fulfill orders, customer service, personalization, analytics |
service providers; analytics |
Shared for analytics |
order life + 7 years (tax/audit) |
|
Payment Data |
tokenized card ID, last four, card type |
process payments, prevent fraud |
payment processors |
No |
per processor terms; we do not store full card numbers |
|
Device/Network Activity |
IP, device/browser, pages, events |
site operations, security, analytics, ads |
service providers; analytics/ads |
Shared for ads/analytics |
24–26 months (typical analytics window) |
|
Inferences/Preferences |
segments, reorder likelihood |
personalization, marketing |
service providers; analytics/ads |
Shared for ads/analytics |
up to 24 months |
|
User Content |
reviews, photos, messages |
publish reviews, support, moderation |
service providers (UGC, support) |
No |
for life of content + backups |
|
Sensitive (limited) |
health info you choose to share |
support request context only |
support tools |
No (we advise you not to submit) |
as needed for the request then delete/ redact |
You can opt out of sale/sharing/targeted advertising via privacy@maeva.co or our Privacy Choices page (if enabled). We honor GPC signals.
9) Data Security
We implement technical and organizational measures designed to protect personal information (e.g., access controls, encryption in transit, network monitoring). No system is perfectly secure; we cannot guarantee absolute security.
10) Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided personal information, contact privacy@maeva.co and we will take appropriate steps.
11) Rights for EEA/UK/Swiss Residents (If Applicable)
If you are in the EEA/UK/Switzerland, Maeva is the controller of your personal data processed via the Services. Legal bases for processing may include: contract (to fulfill orders), legitimate interests (improve and secure the Services, prevent fraud), consent (email/SMS marketing where required), and legal obligation (tax/accounting). You have rights to access, rectify, erase, restrict, object, portability, and to withdraw consent. You may lodge a complaint with your local data protection authority.
International transfers may occur (e.g., to the U.S.). Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses). To exercise EU/UK rights, email privacy@maeva.co.
12) Data Retention
We retain personal information for as long as necessary to provide the Services and for other legitimate purposes (e.g., tax/audit, security, dispute resolution), then delete or deidentify it. Typical periods include: orders: 7 years; support records: 3 years; analytics/ads signals: 24–26 months; marketing suppression: indefinitely (to honor optouts).
13) International Transfers
Depending on your location, personal information may be processed in the United States and other countries, which may have different dataprotection laws than your country of residence.
14) ThirdParty Sites & Services
We may link to or integrate thirdparty services (e.g., payment processors, shipping providers, analytics, advertising, review platforms). Their use of your information is governed by their privacy policies and terms. We are not responsible for their privacy practices.
15) Changes to This Policy
We may update this Policy from time to time. When we do, we will change the Effective date above. Material changes will be posted on the Services and/or sent to your account email where required. Your continued use of the Services after changes means you accept the updated Policy.
16) Contact Us
Maeva USA Inc.
2901 Clint Moore Rd Suite 115
Boca Raton, FL 33496
Email: privacy@maeva.co