Last Updated: January 1, 2025
At Tropix, we are committed to protecting your privacy and ensuring transparency in how we handle your personal data. This Privacy Policy explains how Tropix (“we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you visit our website, tro-pix.com, or purchase our products, including our premium cannabis-infused gummies. We use Stripe, a third-party payment processor, to securely handle transactions, and this policy ensures compliance with Stripe’s requirements as well as applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and U.S. Data Privacy Framework.
1. Information We Collect
We collect personal data to provide our services, process your orders, and improve your experience. The types of information we collect include:
- Personal Information You Provide: When you place an order, create an account, or contact us, we may collect your name, email address, phone number, billing and shipping address, and payment information (such as credit card details). We do not store your full payment details directly; these are securely handled by Stripe, our payment processor.
- Transaction Data: When you make a purchase, we collect details about the transaction, including the products purchased, order amount, and date of purchase. Stripe also collects transaction-related data to process your payment and prevent fraud.
- Automatically Collected Information: We may collect information about your device and browsing activity, such as your IP address, browser type, device identifiers, and pages visited, using cookies and similar technologies. For more details, see our Cookie Policy below.
- Communication Data: If you contact us via email or through our website, we collect the information you provide, such as your message content and contact details.
2. How We Use Your Information
We use your personal data for the following purposes:
- Order Processing and Fulfillment: To process your purchases, ship products, and provide customer support.
- Payment Processing: We share necessary payment information with Stripe to facilitate secure transactions. Stripe may use your data to authenticate transactions, prevent fraud, and comply with financial regulations.
- Communication: To send you order confirmations, shipping updates, and respond to your inquiries.
- Improving Our Services: To analyze website usage and improve our products and user experience.
- Legal Compliance: To comply with federal regulations, including ensuring our products meet the 0.3% Delta-9 THC limit on a dry weight basis as required by the Agricultural Improvement Act of 2018, and to fulfill other legal obligations, such as anti-money laundering (AML) and know-your-customer (KYC) requirements.
- Marketing (Optional): With your consent, we may send you promotional emails about new products or offers. You can opt out at any time by clicking the “unsubscribe” link in our emails.
3. How We Share Your Information
We do not sell your personal data. We share your information only as necessary to provide our services or comply with legal obligations:
- With Stripe: When you make a payment, we share your name, contact information, payment method details, and transaction data with Stripe to process your payment. Stripe may share this data with banks, payment method providers, and fraud prevention services to authenticate transactions and prevent unauthorized purchases. For more details on how Stripe handles your data, please review Stripe’s Privacy Policy.
- Service Providers: We may share your data with trusted third-party vendors who assist with order fulfillment, shipping, or website hosting. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
- Legal Obligations: We may disclose your information to comply with applicable laws, regulations, or legal processes, such as responding to subpoenas or law enforcement requests.
- Business Transfers: If Tropix is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction, but we will notify you of any changes in ownership or use of your data.
4. Stripe Payment Processing and Compliance
Tropix uses Stripe to securely process all payments on tro-pix.com. Stripe acts as a data processor for your payment-related information, and we ensure compliance with Stripe’s requirements:
- Data Sharing with Stripe: When you make a purchase, Stripe collects and processes your payment method details, transaction data, and other identifiable information (such as your name and billing address) to process payments and prevent fraud. Stripe may share this data with third-party security and risk providers to ensure transaction safety.
- PCI Compliance: Stripe is certified as a PCI Level 1 Service Provider, adhering to the Payment Card Industry Data Security Standard (PCI DSS). We do not store your full credit card information on our servers, minimizing our PCI compliance obligations. By using Stripe’s secure payment integrations, we ensure that your payment data is transmitted and processed securely.
- Stripe’s Role: As a data processor, Stripe processes your personal data on our behalf in accordance with our instructions and their privacy policy. We have a Data Processing Agreement (DPA) with Stripe that ensures compliance with applicable data protection laws, including GDPR and CCPA.
5. Your Rights and Choices
You have rights regarding your personal data, depending on your location and applicable laws:
- Access and Correction: You can request access to or correction of your personal data by contacting us at [email protected].
- Deletion: You may request deletion of your personal data, subject to legal retention requirements (e.g., for financial record-keeping). To request deletion, email us at [email protected] with the subject line “DATA RIGHTS.”
- Opt-Out of Marketing: You can opt out of marketing communications by following the unsubscribe instructions in our emails.
- Cookies: You can manage your cookie preferences through your browser settings or our Cookie Policy settings.
- CCPA Rights (California Residents): If you are a California resident, you have the right to request disclosure of the categories of personal data we collect, the purposes for which we use it, and the third parties with whom we share it. You also have the right to opt out of the sale of your personal data (we do not sell your data) and request deletion.
- GDPR Rights (EU/UK Residents): If you are in the EU or UK, you have the right to object to certain uses of your data, restrict processing, and request data portability.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days, as required by law.
6. International Data Transfers
Tropix is based in the United States, and your personal data is processed in the U.S. When you make a payment, Stripe may transfer your data to jurisdictions where their affiliates or sub-processors operate, such as the U.S. or other countries, to provide payment processing services. Stripe complies with the U.S. Data Privacy Framework (EU-U.S. DPF, UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF) to ensure lawful data transfers. We have a Data Processing Agreement with Stripe that includes Standard Contractual Clauses to safeguard your data during international transfers.
7. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by law. For example:
- Transaction data is retained for 7 years to comply with financial and tax regulations.
- Account information is retained until you request deletion, unless we are required to keep it for legal purposes.
- Automatically collected data (e.g., IP addresses) is retained for up to 12 months for analytics purposes.
8. Security
We implement reasonable technical and organizational measures to protect your personal data from unauthorized access, loss, or disclosure. This includes using secure servers, encryption for data transmission, and access controls. Stripe also employs robust security measures, such as encryption and PCI DSS compliance, to safeguard your payment information.
9. Cookie Policy
We use cookies and similar technologies to enhance your experience on tro-pix.com:
- Essential Cookies: Necessary for the website to function, such as maintaining your session during checkout.
- Analytics Cookies: Help us understand how visitors interact with our site, such as which pages are most visited.
- Marketing Cookies: Used to deliver relevant advertisements, if you consent.
If you are in the EU or UK, we will obtain your opt-in consent before using non-essential cookies, in compliance with the GDPR and ePrivacy Directive. You can manage your cookie preferences through your browser settings or our cookie consent tool. Stripe may also use cookies to facilitate payment processing and fraud prevention, as outlined in their privacy policy.
10. Third-Party Links
Our website may contain links to third-party sites, such as Stripe’s privacy policy page. We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies before providing any personal information.
11. Children’s Privacy
Our products and services are not intended for individuals under the age of 21. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 21, we will delete it immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on our website with a new “Last Updated” date. We encourage you to review this policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding your personal data, please contact us at:
Tropix
Email: [email protected]
