Privacy Policy
1. Scope of This Privacy Policy
This Privacy Policy explains how HORMELIS, LLC collects, uses, stores, protects, and shares personal information when customers visit hormelis.com, place an order, contact us, use an account, request a return or refund, track a shipment, or otherwise interact with our website and services.
For purposes of applicable data protection laws, HORMELIS, LLC is the controller of personal information collected through hormelis.com, except where a third-party service provider independently determines how it processes information under its own privacy terms.
By using the website, customers acknowledge that personal information may be processed as described in this Privacy Policy and as reasonably necessary to provide the requested services.
2. WordPress and WooCommerce Platform
This website is a self-hosted store built on WordPress and powered by WooCommerce. Our website and store data are maintained within the hosting and database environment used by HORMELIS, LLC rather than operating as a store hosted directly by WordPress.com or WooCommerce.com.
WooCommerce provides the e-commerce functionality used to manage products, shopping carts, checkout, customer accounts, orders, refunds, and related store operations.
Depending on the features used by a customer, WordPress and WooCommerce may process information required to maintain shopping sessions, customer accounts, order records, security functions, and other necessary website operations.
3. Personal Information We Collect
The information we collect depends on how a customer interacts with the website. It may include the customer's name, billing address, shipping address, email address, telephone number, account information, order details, purchased products, order value, selected shipping method, and customer communications.
We may also receive technical information such as IP address, browser type, device information, operating system, session information, referring pages, access times, cookie identifiers, and basic website activity necessary for security, troubleshooting, and website functionality.
We aim to collect only information reasonably necessary for the purpose for which it is processed.
4. Information You Provide Directly
Customers provide personal information directly when placing an order, creating or managing an account, entering billing or delivery information, completing a contact form, requesting customer service, reporting a delivery problem, requesting a return or refund, or otherwise communicating with us.
Customers are responsible for providing accurate and current information. If information changes before an order has been processed or shipped, customers should contact us at [email protected] as soon as possible.
5. Order and Transaction Information
When an order is placed, we maintain information reasonably necessary to administer the transaction. This may include the order number, products ordered, quantities, prices, billing and shipping details, selected payment method, transaction status, shipping status, tracking information, refunds, returns, and communications relating to the order.
Order information is used to confirm purchases, fulfill orders, provide customer support, process returns and refunds, investigate delivery issues, maintain transaction records, prevent fraud, and respond to payment inquiries or disputes.
6. Stripe and PayPal Payment Processing
Payments available through hormelis.com are processed through independent third-party payment service providers, including Stripe and PayPal.
When a customer submits a payment, information necessary to authorize and process that transaction may be transmitted directly to Stripe, PayPal, the relevant card network, bank, digital wallet provider, or other participating financial institution.
HORMELIS, LLC does not directly process or store customers' complete card numbers, CVV or CVC security codes, bank account login credentials, PayPal passwords, or complete digital-wallet payment credentials on our website database.
Our store may retain limited transaction information returned by a payment provider, such as the payment method used, payment status, transaction reference or identifier, refund status, and other non-sensitive transaction records necessary to administer an order and document the transaction.
7. Payment Information Security
Sensitive payment credentials are handled through the applicable payment provider rather than being stored as raw payment credentials within our WooCommerce database.
Payment providers such as Stripe and PayPal maintain their own security systems and payment-processing environments. Depending on the payment method and transaction, protective technologies may include PCI-DSS compliant payment infrastructure, encrypted transmission, tokenization, fraud monitoring, authentication controls, and 3-D Secure authentication where supported.
Tokenization can replace sensitive card information with a non-sensitive reference token so that the original card information does not need to be stored by our website for transaction processing.
8. How We Use Personal Information
We may use personal information to process and fulfill orders, arrange delivery, provide tracking information, administer accounts, respond to questions, process returns and refunds, investigate damaged or missing parcels, communicate about an order, operate the website, maintain records, prevent fraud, protect the security of the store, and comply with applicable legal obligations.
We may also use relevant information to diagnose technical problems, maintain website functionality, detect unauthorized activity, enforce our policies, establish or defend legal claims, and respond to payment-provider or card-network inquiries.
We do not use personal information for purposes that are materially incompatible with the purpose for which it was collected unless permitted by applicable law.
9. Legal Bases for Processing
Where the General Data Protection Regulation or another law requiring a legal basis applies, we process personal information only where an appropriate legal basis exists.
Depending on the circumstances, processing may be necessary to perform a contract with the customer, take steps requested by the customer before entering into a contract, comply with a legal obligation, pursue a legitimate business interest that does not override the customer's rights, or act on the customer's consent where consent is required.
For example, order and shipping information is generally processed to fulfill a purchase, while certain fraud-prevention and transaction-security activities may be carried out to protect legitimate interests in preventing misuse and protecting customers and the store.
10. Shipping and Logistics Providers
To fulfill worldwide orders, we may provide necessary delivery information to logistics carriers, postal services, international transportation providers, customs-related services, and local last-mile delivery partners.
Information shared for delivery may include the recipient's name, shipping address, telephone number, email address where necessary, order or parcel reference, and other information reasonably required to transport, track, clear, and deliver the shipment.
We limit such sharing to information reasonably necessary for fulfillment, delivery, tracking, customs processing, delivery investigations, and related shipping services.
11. Other Service Providers and Information Sharing
We may use service providers that assist with website hosting, WordPress and WooCommerce functionality, payment processing, email delivery, website security, technical maintenance, order fulfillment, shipping, fraud prevention, and other services necessary to operate the store.
These service providers may receive only the information reasonably necessary to perform the relevant service and may be subject to their own contractual, legal, security, and privacy obligations.
We do not sell customers' complete payment credentials, and we do not disclose personal information to unrelated third parties merely for their independent use without an appropriate legal basis.
12. Cookies and Similar Technologies
hormelis.com may use cookies and similar technologies required for essential website functions such as shopping-cart operation, session management, account login, checkout, security, and remembering certain customer preferences.
Some cookies may be provided by WordPress, WooCommerce, Stripe, PayPal, or other services used by the website. The particular cookies available may depend on the features and payment options used during a visit.
Where applicable law requires consent before optional cookies are placed, customers will be provided with available choices regarding those cookies. Essential cookies required to provide requested website or checkout functionality may operate without optional consent where legally permitted.
13. Customer Accounts and Communications
If customer-account functionality is available, we may process information required to create, authenticate, secure, and administer the account and to associate eligible orders with that account.
When customers contact us, we may retain the contents of the communication, contact details, order reference, attachments, photographs, and related records where reasonably necessary to respond to the request and document its resolution.
Customer communications may also be connected with the relevant order record where doing so is necessary to address returns, refunds, delivery issues, product concerns, payment questions, or disputes.
14. Fraud Prevention, Chargebacks and Payment Disputes
We may process and preserve information reasonably necessary to prevent, detect, investigate, and respond to suspected fraud, unauthorized transactions, account misuse, chargebacks, payment disputes, or other transaction-related concerns.
If a payment dispute is initiated through Stripe, PayPal, a card issuer, bank, or card network, we may use and provide relevant documentation necessary to respond to the dispute. Such documentation may include order confirmations, transaction identifiers, billing information, shipping information, carrier tracking, delivery confirmation, customer communications, return requests, refund records, photographs, and other records directly relevant to the transaction.
This information is used to establish the history of the order and allow the applicable payment provider or financial institution to review the dispute based on available evidence.
Customers who believe there is a payment or order problem may contact us at [email protected] so that we can review the relevant records and attempt to resolve the matter.
15. Data Security Measures
We use reasonable technical and organizational safeguards designed to protect personal information against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
These measures may include HTTPS connections, SSL/TLS encryption for information transmitted between browsers and the website, access controls, restricted administrative permissions, authentication controls, strong account credentials, secure hosting practices, software and security updates, firewall and monitoring measures, protected backups, and limitation of administrative access to persons who require it for legitimate operational purposes.
For payment security, sensitive payment credentials are directed to the applicable payment provider rather than stored as complete payment credentials in our website database. Payment-provider technologies may additionally use encryption, PCI-DSS controls, tokenization, fraud-detection systems, and 3-D Secure where supported.
No internet transmission or storage system can be guaranteed to be completely secure. We therefore review and maintain safeguards appropriate to the nature of the information and the services being provided.
16. Data Minimization and Access Controls
We seek to limit the collection of personal information to information reasonably necessary for order administration, customer service, payment verification, delivery, returns, refunds, fraud prevention, legal compliance, and operation of the website.
Access to customer and order information is restricted to authorized personnel and service providers who require access for legitimate operational purposes. Administrative access should be limited according to role and operational need.
We do not request customers to send complete card numbers, CVV or CVC codes, account passwords, or other sensitive payment credentials to us by email or ordinary customer-service messages.
17. Data Retention
Unless a longer period is required or permitted by applicable law, personal information associated with routine customer and order administration is generally retained for up to one year from the point at which it is no longer actively required for the relevant transaction or service.
Certain information may need to be retained for a longer period where necessary to comply with tax, accounting, regulatory, fraud-prevention, chargeback, legal, or dispute-resolution obligations, or to establish, exercise, or defend legal claims.
When information is no longer reasonably required and no applicable legal or operational requirement justifies continued retention, it may be deleted, anonymized, or otherwise securely removed in accordance with our applicable procedures.
18. European Economic Area and GDPR Rights
Where the European Union General Data Protection Regulation (GDPR) applies, individuals may have rights regarding their personal information, subject to applicable conditions and legal exceptions.
These rights may include the right to be informed, right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object to certain processing, and rights relating to qualifying automated decision-making and profiling.
Where processing is based on consent, individuals may also withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
We process personal information according to relevant principles including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability where the GDPR applies.
19. GDPR Requests and Supervisory Authority Rights
Customers seeking to exercise an applicable GDPR privacy right may contact HORMELIS, LLC at [email protected]. Please describe the request clearly and provide sufficient information for us to identify the relevant records.
We may request reasonable information to verify identity before providing, changing, exporting, or deleting personal information. This safeguard is intended to prevent unauthorized persons from accessing or altering another individual's information.
Requests will be handled within the period required by applicable law. Under the GDPR, qualifying requests are generally addressed without undue delay and normally within one month, subject to circumstances in which the law permits additional time.
Individuals covered by the GDPR also have the right to lodge a complaint with an applicable data protection supervisory authority if they believe their personal information has been processed in violation of applicable data protection law.
20. International Data Transfers
Because hormelis.com provides worldwide services and uses service providers that may operate in different countries, personal information may be processed or transferred outside the country or region in which the customer resides.
Where the GDPR or another applicable privacy law requires safeguards for international transfers, we seek to rely on legally recognized transfer mechanisms where applicable, such as an adequacy decision, appropriate contractual safeguards, Standard Contractual Clauses, or another mechanism permitted by law.
The privacy and security practices of independent service providers, including payment and logistics providers, may also be governed by their own privacy notices and applicable legal obligations.
21. Children's Privacy and Policy Updates
Our store is intended for customers capable of entering into online purchase transactions under applicable law. We do not knowingly seek to collect personal information from children for purposes unrelated to providing lawful store services.
If we become aware that personal information has been submitted by a child in circumstances where valid parental or guardian authorization is legally required and has not been provided, we may take reasonable steps to remove or appropriately restrict the information.
We may update this Privacy Policy when our services, website functionality, payment systems, service providers, legal obligations, or privacy practices change. The version published on hormelis.com will represent the current version of this policy.
22. Contact Information and Related Policies
If you have questions about this Privacy Policy, personal information held by us, a privacy request, or the security of your information, please contact:
HORMELIS, LLC
Address: 1250 N Mill St, Ste 105, Naperville, IL 60563, US
Email: [email protected]
Phone: +1 (630) 646-8120
For information about payment processing and refunds to the original payment method, please review our Payment Policy.
For information about worldwide delivery, logistics carriers, tracking, customs, and damaged parcels, please review our Shipping Policy.
For information about the 30-day return period, return eligibility for home textile products, return shipping costs, and refund processing, please review our Refund and Returns Policy.