Privacy Policy

Last Updated: October 17, 2025

🌿 Introduction

Welcome to Hudson Valley Botanicals (we, us, our). Your privacy matters. This policy explains exactly what data we collect, why we need it, how we protect it, and who we share it with. We've written this in plain Englishβ€”no legalese runaround.

TL;DR: We collect only what's needed to ship your order and send receipts. We NEVER sell your data to third parties. Payment details go straight to our processor (Waave) - we never see your card number.

πŸ“‹ What We Collect (Exact List)

When you place an order, we collect:

  • Name: To address shipping labels ("John Doe")
  • Email: Order confirmations & tracking updates
  • Shipping Address: For USPS/UPS delivery
  • Phone Number (optional): Delivery issues only
  • Order Details: Product name (e.g., "Red Bali Kratom"), quantity, total price
  • Payment Info: Handled by Waave (our payment processor) - we NEVER store credit card numbers, expiry dates, or CVV codes

Technical Data (Automatically Collected):

  • IP Address: For fraud prevention (e.g., detecting bot orders)
  • Browser Info: To optimize site performance (Chrome vs Safari display)
  • Device Type: Desktop, mobile, or tablet (for responsive design)
  • Page Views: Internal analytics onlyβ€”NO Google Analytics or third-party trackers

What We DON'T Collect:

  • ❌ Social Security Numbers
  • ❌ Driver's License / Government IDs
  • ❌ Financial Account Numbers
  • ❌ Biometric Data (fingerprints, face scans)
  • ❌ Political Opinions, Health Data, or Religious Beliefs

πŸͺ Cookies & Tracking (Full Transparency)

We use minimal cookiesβ€”only what's essential for checkout. NO tracking pixels, NO behavioral ads.

Cookie Type Purpose Lifespan Example
Essential Cart, checkout, login Session only cart_id, session_token
Preferences Dark mode, language 1 year theme_preference

Your Control: Disable cookies in Chrome Settings β†’ Privacy β†’ Cookies. Note: Disabling may break checkout functionality.

No Tracking Pixels: We do NOT use Google Analytics, Facebook Pixel, or any behavioral advertising cookies.

πŸ”’ How We Use Your Information (Detailed)

Every piece of data you provide has a specific, limited purpose. Here's exactly how we use it:

  • Order Processing (Primary Use): We use your name, address, and order total to fulfill orders through USPS or UPS. Waave processes payment separately - we never see card details. Example: "John Doe, 123 Main St, NY, $49.99" β†’ shipped via USPS Priority.
  • Shipping & Delivery: Address used only for delivery. USPS/UPS see ONLY name + address (no email/payment).
  • Payment Processing: Waave handles 100% of payments. We receive only confirmation ("Payment successful - $49.99") - never card numbers, expiry, or CVV.
  • Order Updates: Email sent to your address: "Your Red Bali Kratom shipped! Tracking #9400..."
  • Customer Support: Your message + order # used to resolve issues. Example: "Jane's White Maeng Da delayed β†’ reshipped."
  • Newsletter (Opt-in): Email used ONLY for monthly deals + new strain announcements. Unsubscribe anytime.
  • Site Improvements: No external analytics - we review internal data manually to improve user experience.
  • Fraud Prevention: IP + device fingerprint to block suspicious orders (ex: 10 orders from same IP in 1 hour).

πŸ›‘οΈ Security Measures (Technical Details)

Your data is protected by enterprise-grade security. Here's our complete protection stack:

  • SSL/TLS 256-bit: All pages encrypted (https://). Lock icon in browser = secure.
  • PCI DSS Level 1: Payments via Waave (never stored on our servers).
  • Database Encryption: AES-256 at rest. Passwords hashed with bcrypt.
  • Access Controls: 2FA for staff. Role-based access (shipping team sees addresses only).
  • Firewalls: Cloudflare WAF blocks 99.9% attacks automatically.
  • Backups: Daily encrypted backups, 30-day retention, geo-redundant storage.
  • Penetration Testing: Quarterly audits by certified ethical hackers.
  • Monitoring: 24/7 intrusion detection. Alerts within 60 seconds.
Our Record: Zero data breaches since 2020. 100% PCI compliant.

🀝 Third Parties We Share With (Exact List)

We NEVER sell, trade, or rent your personal data to marketers. Only 2 trusted partners receive limited info:

Partner Data Shared Purpose Their Policy
Waave Card #, expiry, CVV (you enter directly) Payment processing waave.com/privacy
USPS / UPS Name, address only Delivery USPS / UPS
That's it! Only Waave + USPS/UPS. No Google Analytics, no marketing trackers, no third-party ads.

Legal Requirements: We may disclose data if required by subpoena, court order, or law enforcement (ex: fraud investigation). We'll notify you unless prohibited.

⏰ Data Retention Periods

  • Order Data: 7 years (IRS requirement)
  • Contact Info: Until you request deletion
  • Newsletter: Until unsubscribe
  • Cookies: See table above

Deletion Rights: Email staff@hudsonvalleybotanicals.com to request removal. We'll delete within 30 days (except legal requirements).

✏️ Policy Updates & Notifications

We reserve the right to update this policy. You'll be notified via:

  • Homepage Banner: 30-day notice for major changes
  • Date Stamp: Bottom of this page updated
  • Email Alert: To subscribed users for material changes
  • Footer Link: Always accessible

Your Obligation: Review periodically. Continued use = acceptance of updates.

βœ… Your Rights & Acceptance

By accessing HudsonValleyBotanicals.com, you:

  • Acknowledge reading and understanding this policy
  • Consent to data collection for stated purposes
  • Agree to receive order-related emails
  • Accept responsibility to review updates
If you disagree: Please do not use our Site. Your sole remedy is to stop using our services.

🌍 International Users

Our servers are in the United States. If you're outside the US, your data will be transferred to and processed in the US. You consent to this transfer by using our Site.

πŸ‘Ά Children's Privacy

Our Site is not intended for children under 18. We do not knowingly collect data from minors. If we discover such data, we'll delete it immediately.

πŸ“§ Contact Us

Questions about this Privacy Policy?

Email: staff@hudsonvalleybotanicals.com

X (Twitter): @GarudaKratom

Response Time: Within 24 business hours

Last Updated: October 17, 2025

Oh hi there πŸ‘‹πŸ»
Thank you for your interest in Garuda Kratom!

Sign up to receive info on discounts, sales and other important updates.

We don’t spam! Read our privacy policy for more info.

Welcome!

You must be 21+ to purchase Kratom products

I am I am not

Remember Me
Disclaimer: Kratom: Our products are not for use by or sale to persons under the age of 21 where applicable. Kratom is banned in the following areas: ALABAMA, ARKANSAS, INDIANA, RHODE ISLAND, VERMONT, LOUISIANA, CONCORDIA PARISH LA, and WISCONSIN. SARASOTA COUNTY, UNION COUNTY, MALHEUR COUNTY, DENVER CO, SAN DIEGO CA, CITY OF OCEANSIDE CA, JERSEYVILLE IL, ALTON IL, EDWARDSVILLE IL, FRANKLIN LA, RAPIDES LA, PARKER AND MONUMENT (COLORADO), ASCENSION AND GRANT PARISH (LOUISIANA), FRANKLIN (NEW HAMPSHIRE). WASHINGTON D.C., NEWPORT BEACH AND SEVERAL COUNTIES IN MISSISSIPPI. We do not ship internationally. ID verification is required for shipments to the following states: Florida, Virginia, West Virginia, Colorado, Oregon, South Dakota, Nebraska, Kentucky, Maryland, Tennessee, Mississippi, Georgia. Enhanced Kratom cannot be shipped to Tennessee and Georgia. Kratom is NOT used to treat, cure, or mitigate any disease, illness, ailment, and/or condition. Please consult your doctor before consuming any new products. Kratom has not been tested on pregnant women. Please, see the FDA alert 54-15. We make no representations as to intended use or suitability for use. This product contains chemicals known to the state of California to cause cancer, birth defects, or reproductive harm. Specifically nickel, arsenic, and lead. For more information please visit p65warnings.ca.gov. We do not ship to military bases 

WAAVE Compliance