Privacy Policy

Last Updated: January 1, 2025

Company: 枝江市本娇商贸有限公司

Developer: Grace Root

Address: 枝江市安福寺镇市场北路67号一楼(自主申报), Yichang - 443000, China (CN)

Email: team@graceroot.mom

Phone: +1 (234) 395-0620

Website: https://www.graceroot.mom

This Privacy Policy describes how 枝江市本娇商贸有限公司 (hereinafter referred to as "Grace Root," "we," "us," or "our") collects, uses, stores, shares, and protects your personal information when you visit or interact with our website at https://www.graceroot.mom (the "Site") or use any of our services, products, or applications (collectively, the "Services"). We are committed to safeguarding your privacy and ensuring that your personal data is handled in a transparent, lawful, and secure manner. By accessing or using our Site and Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our Site and Services immediately.

This Privacy Policy is designed to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR) of the European Union, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Personal Information Protection Law (PIPL) of the People's Republic of China, and other relevant international, federal, state, and local privacy regulations. We recognize that privacy is a fundamental right, and we strive to maintain the highest standards of data protection and transparency. This policy applies to all users of our Site and Services, regardless of their geographic location, and we have implemented measures to ensure that your rights are respected and enforced.

Please read this Privacy Policy carefully. It contains important information about your rights and our obligations regarding your personal data. We may update this policy from time to time to reflect changes in our practices, legal requirements, or technological advancements. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date at the top. We encourage you to review this policy periodically to stay informed about how we are protecting your information. If you have any questions, concerns, or requests regarding your personal data, please contact us using the information provided in the "Contact" section below.


1. Introduction

Welcome to Grace Root, operated by 枝江市本娇商贸有限公司, a company registered in Yichang, China. We are a technology and e-commerce company that provides digital products, software solutions, and online services to a global audience. Our mission is to deliver innovative, user-friendly, and secure digital experiences while respecting the privacy and autonomy of every individual who interacts with our platform. This Privacy Policy serves as a comprehensive guide to how we handle personal information across all our operations, from website visits to service subscriptions, customer support interactions, and marketing communications.

At Grace Root, we believe that privacy is not just a legal obligation but a core value that underpins trust and integrity in our relationships with users, customers, partners, and stakeholders. We have designed our data processing activities to be minimal, purposeful, and transparent. We collect only the information that is necessary to provide and improve our Services, and we never sell your personal data to third parties. Our commitment to privacy extends to every aspect of our business, including product development, data storage, employee training, and vendor management. We regularly audit our practices to ensure compliance with evolving legal standards and industry best practices.

This Privacy Policy is structured to provide you with clear and detailed information about the types of data we collect, the methods we use to collect it, the purposes for which we use it, the legal bases that justify our processing, the circumstances under which we share data, the measures we take to protect it, and the rights you have to control it. We also address specific topics such as international data transfers, data retention periods, children's privacy, third-party services, and policy changes. Our goal is to empower you with the knowledge you need to make informed decisions about your privacy and to exercise your rights effectively. If you have any feedback or suggestions for improving this policy, we welcome your input at team@graceroot.mom.

2. Information We Collect

We collect various types of information to provide, maintain, and improve our Services, as well as to communicate with you and comply with legal obligations. The categories of information we collect include personal data that can identify you directly or indirectly, as well as non-personal data that does not identify you. Personal data refers to any information relating to an identified or identifiable natural person, such as your name, email address, phone number, postal address, IP address, device identifiers, and other unique identifiers. Non-personal data includes aggregated usage statistics, anonymized analytics, and other information that cannot be used to identify you.

Specifically, we may collect the following categories of personal information: (a) Contact Information: your full name, email address, phone number, billing address, shipping address, and other contact details you provide when registering an account, making a purchase, or contacting customer support. (b) Account Information: your username, password, profile picture, preferences, and other account settings you configure on our Site. (c) Payment Information: credit card numbers, debit card numbers, bank account details, PayPal or other payment processor account information, and billing history. Please note that we do not store full payment card numbers on our servers; this data is processed and stored by our secure third-party payment processors. (d) Technical Information: your IP address, browser type and version, operating system, device type, screen resolution, language preferences, time zone, referring URLs, and other technical data collected automatically when you access our Site. (e) Usage Information: pages viewed, links clicked, search queries, time spent on pages, navigation paths, download history, and other interactions with our Site and Services. (f) Communication Information: records of your correspondence with us, including emails, chat messages, phone call recordings (with your consent where required), and survey responses. (g) Marketing Preferences: your choices regarding receiving promotional communications, newsletters, and special offers, as well as your opt-in or opt-out status.

We also collect information that you voluntarily provide to us through forms, feedback, reviews, testimonials, and other interactive features. This may include your opinions, preferences, and other content you submit. In some cases, we may collect information from public sources, such as social media profiles, if you choose to connect your account with third-party platforms. We do not intentionally collect sensitive personal data, such as racial or ethnic origin, political opinions, religious beliefs, health information, or biometric data, unless you explicitly provide it and we have a lawful basis to process it. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

3. How We Collect Information

We collect information through a variety of methods, both automated and manual, to ensure that we can deliver a seamless and personalized experience while respecting your privacy. The primary methods of data collection include: (a) Direct Collection: You provide information directly to us when you fill out forms on our Site, register an account, make a purchase, subscribe to a newsletter, participate in surveys or contests, contact customer support, or otherwise interact with our Services. This is the most common way we collect personal data, and we always indicate which fields are required and which are optional. (b) Automated Collection: When you visit our Site, we automatically collect certain technical and usage information using cookies, web beacons, pixels, log files, and similar tracking technologies. These technologies help us understand how you use our Site, improve functionality, and deliver relevant content. For example, we use cookies to remember your login status, language preferences, and shopping cart items. You can control cookie settings through your browser preferences, but disabling certain cookies may affect your experience. (c) Third-Party Sources: We may receive information about you from third-party service providers, such as payment processors, analytics providers (e.g., Google Analytics), advertising networks, social media platforms (if you log in via Facebook, Google, or other OAuth providers), and data enrichment services. We ensure that these third parties have lawful bases to share your data with us and that they comply with applicable privacy laws. (d) Publicly Available Sources: We may collect information that you have made publicly available, such as social media posts, public reviews, or business listings, but only to the extent permitted by law and for legitimate business purposes. (e) Offline Collection: In some cases, we may collect information offline, such as when you attend events, trade shows, or in-person meetings, and provide us with your business card or contact details.

We also use automated decision-making and profiling techniques to analyze your behavior and preferences, but only when necessary for the performance of a contract or with your explicit consent. For example, we may use machine learning algorithms to recommend products or services based on your browsing history. You have the right to object to such processing and to request human intervention in decisions that significantly affect you. We are committed to transparency in our data collection practices and will always inform you of the methods we use and the purposes they serve. If you have questions about a specific collection method, please contact us.

4. Types of Information We Collect

To provide a comprehensive understanding of our data practices, we categorize the information we collect into several types based on its nature and sensitivity. This classification helps us apply appropriate safeguards and processing restrictions. The main types of information we collect are: (a) Personal Identifiers: This includes your name, email address, phone number, postal address, username, and other identifiers that can be used to contact or identify you directly. These are essential for account management, order fulfillment, and customer support. (b) Commercial Information: Records of products or services purchased, obtained, or considered, as well as other purchasing or consuming histories or tendencies. This includes transaction details, order history, and payment information (though we do not store full payment card numbers). (c) Internet or Other Electronic Network Activity Information: This includes browsing history, search history, and information regarding your interaction with our Site, applications, or advertisements. This data helps us optimize user experience and deliver targeted content. (d) Geolocation Data: We may collect precise or approximate location data from your IP address or device settings, but only with your consent where required by law. This information is used for fraud prevention, content localization, and analytics. (e) Professional or Employment-Related Information: If you apply for a job with us, we may collect your resume, work history, education, references, and other professional details. This data is used solely for recruitment purposes. (f) Inferences Drawn from Other Personal Information: We may create profiles or segments based on your preferences, characteristics, behavior, and attitudes to personalize our Services and marketing. These inferences are derived from the data we collect and are not used for discriminatory purposes. (g) Sensitive Personal Data: As noted, we do not intentionally collect sensitive data such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data. If such data is provided inadvertently, we will delete it unless we have a legal obligation to retain it.

We also collect aggregated and anonymized data that cannot be used to identify you. This includes statistical reports on user behavior, traffic patterns, and demographic trends. Such data is used for business analysis, product development, and reporting purposes and is not subject to the same privacy restrictions as personal data. We ensure that anonymization is irreversible and that no re-identification is possible. If you have concerns about the types of information we collect, please refer to the relevant sections of this policy or contact us for clarification.

5. How We Use Your Information

We use the information we collect for a variety of legitimate business purposes, all of which are aimed at providing, maintaining, and improving our Services, as well as communicating with you and complying with legal obligations. The specific purposes for which we use your personal data include: (a) Service Delivery: To process your orders, manage your account, provide customer support, deliver digital products, and fulfill contractual obligations. This includes verifying your identity, processing payments, shipping physical goods (if applicable), and providing access to purchased content. (b) Personalization: To tailor your experience on our Site by remembering your preferences, recommending products or services, displaying relevant content, and customizing user interfaces. Personalization enhances your satisfaction and helps us serve you better. (c) Communication: To send you administrative messages, such as order confirmations, account updates, password resets, and policy changes. We also send marketing communications, newsletters, and promotional offers if you have opted in. You can opt out of marketing at any time. (d) Analytics and Improvement: To analyze usage patterns, identify trends, measure the effectiveness of our marketing campaigns, and improve the functionality, performance, and security of our Site and Services. This includes conducting research, testing new features, and debugging issues. (e) Fraud Prevention and Security: To detect, prevent, and respond to fraudulent activities, unauthorized access, cyberattacks, and other security threats. We use automated systems and manual reviews to protect your data and our infrastructure. (f) Legal Compliance: To comply with applicable laws, regulations, court orders, and governmental requests. This includes responding to subpoenas, enforcing our Terms of Service, and protecting our rights and property. (g) Business Operations: To manage our business operations, including accounting, auditing, billing, record-keeping, and internal reporting. We may also use your data for mergers, acquisitions, or asset sales, but we will notify you and obtain consent if required. (h) User Feedback and Research: To solicit feedback, conduct surveys, and perform market research to understand user needs and improve our offerings. Participation is voluntary, and responses are anonymized where possible.

We do not use your personal data for purposes that are incompatible with those described in this policy unless we obtain your consent or have a lawful basis to do so. If we intend to use your data for a new purpose, we will update this policy and notify you in advance. We also implement data minimization principles, meaning we only process the data that is necessary for each specific purpose. For example, we do not use your payment information for marketing purposes, and we do not retain your data longer than needed. If you have questions about how your data is used, please contact us.

6. Legal Basis for Processing

We process your personal data only when we have a valid legal basis under applicable data protection laws. The legal bases we rely on include: (a) Consent: We may process your data based on your explicit consent, which you can withdraw at any time. This applies to activities such as sending marketing emails, placing non-essential cookies, and processing sensitive data. You provide consent by checking boxes, clicking buttons, or other affirmative actions. Withdrawal of consent does not affect the lawfulness of processing before withdrawal. (b) Contractual Necessity: We process data as necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes processing your order, delivering services, and handling payments. Without this data, we cannot fulfill our contractual obligations. (c) Legal Obligation: We process data to comply with legal obligations, such as tax laws, anti-money laundering regulations, and data breach notification requirements. This may include retaining transaction records for accounting purposes or disclosing data to law enforcement. (d) Legitimate Interests: We may process data for our legitimate interests or those of a third party, provided that your rights and interests do not override those interests. Our legitimate interests include improving our Services, preventing fraud, ensuring network security, and conducting direct marketing (where permitted). We conduct balancing tests to ensure that our interests are proportionate and that your privacy is protected. (e) Vital Interests: In rare cases, we may process data to protect your vital interests or those of another person, such as in a medical emergency. (f) Public Interest: We may process data for tasks carried out in the public interest, such as scientific research or statistical purposes, but only when authorized by law.

We document our processing activities and the legal bases we rely on to ensure accountability and transparency. If you are in the European Economic Area (EEA), the UK, or other jurisdictions with similar laws, you have the right to request information about the legal basis for processing your data. We will provide this information upon request. Note that some processing may rely on multiple legal bases, and we will identify the most appropriate one for each activity. For example, processing payment data is based on contractual necessity, while using analytics cookies may be based on consent or legitimate interests depending on the jurisdiction. We review our legal bases periodically to ensure they remain valid and appropriate.

7. Data Sharing and Disclosure

We may share your personal data with third parties in certain circumstances, but we never sell your personal information to third parties for their own marketing purposes. We define "sale" broadly to include any exchange of data for monetary or other valuable consideration, and we comply with laws that restrict such practices. The categories of third parties with whom we may share data include: (a) Service Providers: We engage trusted third-party service providers to perform functions on our behalf, such as payment processing, cloud hosting, email delivery, analytics, customer support, fraud detection, and marketing automation. These providers are contractually bound to protect your data and use it only for the purposes we specify. We conduct due diligence to ensure they have adequate security measures. (b) Business Partners: We may share data with business partners for joint offerings, co-branded services, or affiliate programs, but only with your consent or where necessary for the service. For example, if you purchase a product through a partner link, we may share order details with that partner. (c) Legal and Regulatory Authorities: We may disclose data to law enforcement, courts, regulators, or other government entities when required by law, such as in response to a subpoena, court order, or legal process. We also may disclose data to enforce our rights, protect our property, or ensure the safety of our users. (d) Corporate Transactions: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change and ensure that the receiving entity agrees to protect your data in accordance with this policy. (e) Professional Advisors: We may share data with our legal, accounting, and other professional advisors for the purpose of obtaining advice and managing our business risks. (f) Public Forums: If you post comments, reviews, or other content on public areas of our Site, that information may be visible to other users and the public. We recommend that you do not share sensitive personal data in public forums.

We implement strict contractual and technical safeguards to ensure that any third party with whom we share data maintains confidentiality and security. We require all third parties to comply with applicable data protection laws and to notify us of any data breaches. We also limit the data we share to what is necessary for the specific purpose. For example, we share only your shipping address with our logistics provider, not your payment details. If you have questions about specific third parties we share data with, please contact us. We will provide a list of our current service providers upon request.

8. International Data Transfers

As a global company with operations in China and users worldwide, we may transfer your personal data to countries other than your own, including China, the United States, and other jurisdictions where our service providers are located. These countries may have data protection laws that differ from those in your country of residence. We take steps to ensure that your data receives an equivalent level of protection when transferred internationally, in compliance with applicable laws such as the GDPR, the PIPL, and other regulations. Specifically, we rely on the following mechanisms for lawful international transfers: (a) Standard Contractual Clauses (SCCs): We use SCCs approved by the European Commission or other relevant authorities to govern transfers of personal data from the EEA, UK, or Switzerland to third countries. These clauses provide contractual guarantees that the data importer will protect your data in accordance with European standards. (b) Adequacy Decisions: Where the European Commission or other competent authority has determined that a country provides an adequate level of data protection, we may transfer data to that country without additional safeguards. (c) Binding Corporate Rules (BCRs): We may adopt BCRs for intra-group transfers, ensuring consistent protection across our corporate group. (d) Consent: In some cases, we may rely on your explicit consent to transfer your data to a country that does not provide adequate protection. You will be informed of the potential risks before giving consent. (e) Other Legal Bases: We may also rely on other lawful bases, such as the necessity for contract performance or important reasons of public interest, to justify transfers.

We conduct transfer impact assessments to evaluate the risks associated with international data transfers and implement supplementary measures where necessary, such as encryption, pseudonymization, and access controls. We also monitor regulatory developments to ensure ongoing compliance. If you are in the EEA, UK, or other jurisdictions with transfer restrictions, you have the right to request a copy of the safeguards we use for international transfers. To exercise this right, please contact us at team@graceroot.mom. We will provide relevant information, subject to redaction of confidential business terms. We are committed to ensuring that your data remains protected no matter where it is processed.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, or as required by applicable laws. Our retention periods are based on the following criteria: (a) Contractual Necessity: We retain data for the duration of your account or the period during which we provide Services to you. For example, we keep your account information active until you close your account. (b) Legal Obligations: We retain data to comply with legal requirements, such as tax laws, accounting standards, and anti-fraud regulations. For instance, we may retain transaction records for up to seven years to satisfy tax reporting obligations. (c) Legitimate Interests: We retain data for our legitimate interests, such as fraud prevention, dispute resolution, and enforcement of our Terms of Service. The retention period for such purposes is typically shorter and based on the risk profile. (d) Consent: If we process data based on your consent, we retain it until you withdraw consent or until the consent expires, whichever is earlier. (e) Statute of Limitations: We may retain data for the duration of applicable statutes of limitations to defend against legal claims. (f) Anonymization: Where possible, we anonymize or aggregate data so that it can no longer be associated with you, and we may retain such anonymized data indefinitely for analytical and research purposes.

Specific retention periods vary by data type. For example: (i) Account information is retained until account deletion plus a short grace period for recovery. (ii) Payment information is retained only as long as necessary to process the transaction and comply with legal obligations, after which it is deleted or anonymized. (iii) Log files and analytics data are retained for up to 26 months, after which they are aggregated or deleted. (iv) Marketing preferences are retained until you opt out or unsubscribe. (v) Customer support records are retained for up to three years after the last interaction. We periodically review our data retention practices to ensure they are appropriate and compliant. When data is no longer needed, we securely delete or destroy it using methods that prevent reconstruction, such as overwriting, degaussing, or physical shredding. You have the right to request deletion of your data earlier, subject to legal exceptions. Please see the "Your Rights" section for more information.

10. Data Security

We implement a comprehensive set of technical, administrative, and physical security measures to protect your personal data from unauthorized access, disclosure, alteration, destruction, or loss. Our security program is designed to meet industry standards and regulatory requirements, and we continuously update it to address emerging threats. Key security measures include: (a) Encryption: We use Transport Layer Security (TLS) encryption to protect data transmitted between your browser and our servers. We also encrypt sensitive data at rest using strong encryption algorithms, such as AES-256. (b) Access Controls: We restrict access to personal data to authorized personnel only, based on the principle of least privilege. Access is granted on a need-to-know basis and is subject to periodic reviews. We use multi-factor authentication for administrative accounts. (c) Network Security: We deploy firewalls, intrusion detection and prevention systems, and regular vulnerability scans to protect our network infrastructure. We also conduct penetration testing by independent security firms. (d) Data Minimization: We collect and retain only the data necessary for our purposes, reducing the risk of exposure. We also pseudonymize and anonymize data where possible. (e) Employee Training: All employees and contractors receive regular training on data protection, privacy, and security best practices. We have a code of conduct that emphasizes confidentiality and ethical behavior. (f) Incident Response: We have a documented incident response plan to quickly address data breaches or security incidents. We will notify affected users and relevant authorities as required by law, including within 72 hours for GDPR-reportable breaches. (g) Physical Security: Our data centers and offices are protected by access controls, surveillance, and environmental safeguards. (h) Third-Party Audits: We require our service providers to maintain equivalent security standards and may audit them to verify compliance.

Despite our efforts, no security measure is completely infallible. We cannot guarantee absolute security, but we are committed to taking all reasonable steps to protect your data. If you suspect a security vulnerability or have concerns about the safety of your data, please contact us immediately at team@graceroot.mom. We will investigate and take appropriate action. We also encourage you to use strong passwords, enable two-factor authentication where available, and keep your software updated to enhance your own security.

11. Your Rights

Depending on your jurisdiction, you have various rights regarding your personal data. We are committed to facilitating the exercise of these rights and responding to your requests in a timely manner, typically within 30 days (or as required by law). Your rights may include: (a) Right to Access: You have the right to request confirmation of whether we process your personal data and, if so, to access that data along with information about the processing, such as the purposes, categories of data, recipients, retention periods, and your rights. We will provide a copy of the data in a commonly used electronic format. (b) Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data. We will update our records promptly upon verification. (c) Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary, you withdraw consent, or the processing is unlawful. We will comply unless we have a legal obligation or legitimate interest to retain the data. (d) Right to Restrict Processing: You have the right to request restriction of processing in certain situations, such as when you contest the accuracy of the data or object to processing. During the restriction period, we will only store the data with your consent or for legal claims. (e) Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller, where technically feasible. This right applies to data processed based on consent or contract and carried out by automated means. (f) Right to Object: You have the right to object to processing based on legitimate interests, including profiling, and to processing for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests. (g) Right to Withdraw Consent: If we process data based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal. (h) Right to Non-Discrimination: We will not discriminate against you for exercising your rights, such as by denying services, charging different prices, or providing a lower quality of service. (i) Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection authority in your country or region if you believe we have violated your privacy rights. We encourage you to contact us first so we can resolve your concerns directly.

To exercise any of these rights, please submit a request to team@graceroot.mom. We may need to verify your identity before processing your request, which may require you to provide additional information. We will respond to your request within the time frame required by law, usually 30 days, but we may extend this period for complex or multiple requests. We will inform you of any extensions. In some cases, we may charge a reasonable fee for repetitive or manifestly unfounded requests. We maintain a record of all requests and our responses for accountability purposes. If you are a California resident, you also have rights under the CCPA/CPRA, including the right to know what personal information we collect, use, disclose, and sell (we do not sell), and the right to opt out of sales (not applicable). For more information, please see our CCPA-specific notice or contact us.

12. Children's Privacy

Our Site and Services are not directed to children under the age of 16 (or the age of majority in your jurisdiction), and we do not knowingly collect personal data from children without verifiable parental consent. We define "children" as individuals under 16 years old, unless a different age is specified by applicable law (e.g., 13 in the United States under COPPA, or 18 in some jurisdictions). If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take immediate steps to delete that data and terminate the child's account, if any. We encourage parents and guardians to monitor their children's online activities and to educate them about privacy and safety. If you believe that your child has provided us with personal data without your consent, please contact us immediately at team@graceroot.mom so we can investigate and take action.

We do not offer services that are specifically designed to attract children, and we do not use targeted advertising directed at children. Our content is intended for a general audience, and we do not knowingly profile children for marketing purposes. In the event that we need to collect data from a child for a specific purpose (e.g., educational services), we will obtain verifiable parental consent in accordance with applicable laws, such as COPPA or the GDPR's parental consent requirements. We will also provide parents with the ability to review, update, or delete their child's data. We are committed to protecting children's privacy and complying with all relevant regulations. If you have any concerns about children's privacy on our Site, please contact us.

13. Third-Party Services

Our Site may contain links to third-party websites, applications, plugins, or services that are not owned or controlled by Grace Root. This includes social media buttons, payment gateways, analytics tools, and advertising networks. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies before providing them with your personal data. When you click on a third-party link, you will be directed to that third party's site, and any information you provide to them is subject to their own privacy practices. We do not endorse or guarantee the security of third-party services, and we disclaim any liability for their actions or omissions.

We use the following categories of third-party services on our Site: (a) Analytics: We use Google Analytics and other analytics providers to collect usage data and generate reports. These providers may use cookies and similar technologies to track your interactions. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on. (b) Payment Processing: We use third-party payment processors such as Stripe, PayPal, and others to handle transactions. These processors are PCI-DSS compliant and have their own privacy policies. We do not store full payment card numbers. (c) Email Marketing: We use services like Mailchimp or SendGrid to send newsletters and promotional emails. These providers have access to your email address and preferences. (d) Social Media: Our Site includes social media sharing buttons and widgets from platforms like Facebook, Twitter, Instagram, and LinkedIn. These platforms may collect data about your interactions, even if you do not click the buttons. (e) Content Delivery Networks (CDNs): We use CDNs to deliver content efficiently, which may involve data transfers to their servers. (f) Customer Support: We use third-party platforms for live chat, ticketing, and knowledge bases. These platforms may store your communications and account details. (g) Advertising: We may use third-party advertising networks to display ads on our Site or on other sites. These networks may use cookies to serve targeted ads based on your browsing behavior. You can opt out of interest-based advertising through the Digital Advertising Alliance or your browser settings.

We require all third-party service providers to enter into data processing agreements that obligate them to protect your data and comply with applicable laws. However, we cannot control how they use your data once it is in their possession. We recommend that you review the privacy policies of any third-party services you use. If you have questions about a specific third-party service we use, please contact us for more information.

14. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or technological developments. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Last Updated" date, and we may also send you an email notification or display a prominent notice on our Site. We encourage you to review this policy periodically to stay informed about how we are protecting your information. Your continued use of our Site and Services after any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should discontinue use of our Services and delete your account.

We will not make retroactive changes that reduce your privacy rights without your explicit consent, unless required by law. If we make a significant change, such as a new purpose for processing your data or a new data sharing practice, we will obtain your consent where required. We maintain a version history of this policy and can provide previous versions upon request. To request a copy of a previous version, please contact us at team@graceroot.mom. We are committed to transparency and will always communicate changes clearly and in a timely manner. If you have any questions about a change, please contact us before accepting the updated policy.

15. Contact Information

If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us. We are committed to addressing your inquiries promptly and effectively. You can reach us through the following channels:

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our compliance with data protection laws. You can contact our DPO directly at the email address above. If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can resolve any issues informally. We will acknowledge receipt of your request within 5 business days and respond within 30 days, or as required by law. For complex requests, we may extend this period, but we will inform you of the reason and expected timeline. We are dedicated to protecting your privacy and ensuring that your rights are respected. Thank you for trusting Grace Root.

This Privacy Policy was developed by Grace Root, the developer of this Site, in collaboration with legal advisors to ensure comprehensive coverage of applicable laws and best practices. We are grateful for your trust and are committed to maintaining the highest standards of privacy and data protection.


© 2025 枝江市本娇商贸有限公司 (Grace Root). All rights reserved. This document is for informational purposes and does not constitute legal advice.