1. Introduction
Welcome to Roanga.com. Protecting your personal data is our priority. This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our website and purchase our products.
The operator of the website and the controller of your personal data is:
**For customers from the EU and the Czech Republic:
Roanga Planet s.r.o.
ID No.: [TO BE ADDED]
Registered office: [TO BE ADDED]
Registered in the Commercial Register maintained by [TO BE ADDED], Section [TO BE ADDED], File No. [TO BE ADDED]
Email: privacy@roanga.com
Phone: [TO BE ADDED]
For customers from the USA:
Roanga Planet LLC
[TO BE ADDED REGISTRATION DETAILS]
Registered office: [TO BE ADDED]
Email: privacy@roanga.com
Phone: [TO BE ADDED]
If you have any questions regarding the processing of your personal data, you can contact us at privacy@roanga.com.
2. What personal data we collect
Depending on your relationship with us and the purpose of processing, we may collect the following categories of personal data:
2.1 Data you provide directly
- - Identification data: first name, last name, username
- - Contact data: email address, phone number, delivery and billing address
- - Payment data: payment card information, banking details (processed through our payment processors)
- - Order data: purchase history, purchased products, prices, date of purchase
- - Communication: content of messages you send us (e.g., via contact form, email, or chat)
- - Account data: password (in encrypted form), account settings preferences
- - Feedback: product reviews, survey responses, ratings
2.2 Data we collect automatically
- - Device data: device type, operating system, unique device identifiers, IP address, browser
- - Activity data: pages visited, time and duration of visit, search terms, interactions with content
- - Location data: approximate geographic location determined based on IP address
- - Cookies and similar technologies: more information can be found in our [Cookie Policy](cookie-settings.html)
2.3 Data we obtain from other sources
- - Data from payment processors: payment confirmation, information about any payment issues
- - Data from delivery service providers: delivery information
- - Publicly available data: information available from public sources, if relevant to our services
2.4 Special categories of personal data
We recognize that purchase history of dietary supplements may in some cases indirectly reveal information about your health status, which is considered a special category of personal data under GDPR and sensitive data under some US laws. We process this data with utmost caution and only based on your explicit consent (in the EU) or with the option to opt out (in the USA).
3. How we use your personal data
We use your personal data for the following purposes:
3.1 Contract performance and service provision
- - Processing and delivering your orders
- - Managing your customer account
- - Providing customer support
- - Processing payments and billing
- - Communicating about your orders
Legal basis (EU/CZ): Performance of a contract (Art. 6(1)(b) GDPR)
3.2 Marketing communication
- - Sending newsletters and information about offers, discounts, and new products
- - Personalizing marketing communication according to your preferences and purchase history
Legal basis (EU/CZ): Consent (Art. 6(1)(a) GDPR) or legitimate interest (Art. 6(1)(f) GDPR) in the case of direct marketing to existing customers
3.3 Improving our services
- - Analyzing user behavior on the website
- - Conducting satisfaction surveys
- - Developing new features and products
- - Resolving technical issues
Legal basis (EU/CZ): Legitimate interest (Art. 6(1)(f) GDPR)
3.4 Compliance with legal obligations
- - Maintaining accounting and tax records
- - Processing complaints
- - Responding to requests from government authorities
Legal basis (EU/CZ): Compliance with a legal obligation (Art. 6(1)(c) GDPR)
3.5 Protection of our rights and property
- - Prevention of fraud and security incidents
- - Enforcement of our legal claims
- - Dispute resolution
Legal basis (EU/CZ)**: Legitimate interest (Art. 6(1)(f) GDPR)
4. How we share your personal data
We share your personal data only with the following categories of recipients:
4.1 Service providers
- - Payment service providers (Stripe, PayPal)
- - Delivery service providers
- - Cloud service and hosting providers
- - Email marketing providers
- - Analytics service providers
All these service providers act as data processors and process your data only based on our instructions and in accordance with relevant data processing agreements.
4.2 Affiliated companies
We may share your data between our companies (Roanga Planet s.r.o. and Roanga Planet LLC) for the purpose of providing our services and managing orders. This sharing takes place in accordance with appropriate legal mechanisms for international data transfers (see section 5).
4.3 Government authorities and other third parties
- - When required by law, court order, or other legal process
- - To protect our rights or property
- - In case of emergency situations involving the safety of persons
4.4 Business partners
With your consent, we may share your data with our business partners to offer complementary products or services that might interest you.
5. International data transfers
Since we operate in both the EU and the USA, cross-border transfers of personal data may occur. These transfers are governed by the following mechanisms:
5.1 Transfers from the EU to the USA
For transferring personal data from the EU to the USA, we use:
- - EU-U.S. Data Privacy Framework (DPF), which provides an adequate level of protection for transferring personal data from the EU to the USA
- - In cases where the DPF does not apply, we use **Standard Contractual Clauses (SCC)** approved by the European Commission
5.2 Appropriate safeguards
When transferring data outside the EU, for 3 years from the last activity
- - Order data: 10 years for accounting and tax purposes (as required by law)
- - Marketing data: for the duration of your consent or until it is withdrawn
- - Communication data: 3 years from the last communication
- - Dispute resolution data: for the time necessary to protect our rights, usually no longer than 10 years
After the retention period expires, your personal data is securely deleted or anonymized.
7. Your rights
Depending on your location, you have the following rights regarding your personal data:
7.1 Rights under GDPR (for individuals in the EU/CZ)
- - Right of access: You have the right to obtain information about what personal data we process about you and a copy of this data.
- - Right to rectification: You have the right to correct inaccurate personal data or complete incomplete data.
- - Right to erasure: In certain circumstances, you have the right to request the deletion of your personal data (the "right to be forgotten").
- - Right to restriction of processing: In certain circumstances, you have the right to request the temporary restriction of processing of your personal data.
- - Right to data portability: You have the right to obtain your personal data in a structured, commonly used, and machine-readable format and to transfer it to another controller.
- - Right to object: You have the right to object at any time to the processing of your personal data that is based on legitimate interest or for direct marketing purposes.
- - Right to withdraw consent: If we process your personal data based on consent, you have the right to withdraw this consent at any time.
- - Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.
7.2 Rights under California laws (CCPA/CPRA)
If you are a California resident, you have the following rights:
- Right to know: You have the right to know what categories of personal information we collect about you, how we use it, with whom we share it, and why we collect it.
- - Right to access: You have the right to request access to the personal information we collect about you.
- - Right to deletion: You have the right to request the deletion of personal information we collect about you, with certain exceptions.
- - Right to correction: You have the right to request correction of inaccurate personal information.
- - Right to opt-out of sale/sharing: You have the right to opt out of the sale or sharing of your personal information for targeted advertising purposes.
- - Right to limit sensitive data: You have the right to limit the use of your sensitive personal information.
- - Right to non-discrimination: You have the right not to be discriminated against for exercising your privacy rights.
7.3 Rights under other US state laws
If you are a resident of Virginia, Colorado, Connecticut, Utah, or Nevada, you have similar rights as California residents, with certain differences according to specific state legislation.
7.4 How to exercise your rights
To exercise your rights, you can contact us:
- - By email at: privacy@roanga.com
- - By phone at: [TO BE ADDED]
- - Through the contact form on our website
- - By mail at our registered office address
We will respond to your request without undue delay, at the latest within one month of receipt. In case of more complex requests, we may extend this period by two more months, of which we will inform you.
To verify your identity, we may ask you for additional information. We do this solely to protect your data from unauthorized access.
For US residents: Toll-free phone number for exercising privacy rights: [TO BE ADDED TOLL-FREE NUMBER]
8. Children's privacy
Our website and services are not intended for individuals under the age of 16 (in the EU/CZ) or 13 (in the USA). We do not knowingly collect personal data from children. If we discover that we have collected personal data from a child without verifiable parental consent, we will take steps to remove this information from our servers.
If you are a parent or legal guardian and believe your child has provided us with personal data, please contact us at privacy@roanga.com so we can take appropriate action.
9. Data security
We have implemented appropriate technical and organizational measures to protect your personal data against accidental loss, unauthorized access, disclosure, alteration, or destruction. These measures include:
- - Encryption of data at rest and in transit
- - Regular testing, assessment, and evaluation of the effectiveness of security measures
- - Limiting access to personal data only to authorized employees and vendors
- - Regular employee training on security and data protection
- - Incident response plans to address potential security breaches
Although we strive to implement best practices in security, no system of transmission or storage can be guaranteed to be 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
10. Cookies and similar technologies
Our website uses cookies and similar technologies to improve your user experience, analyze website traffic, and personalize content and ads. Detailed information about how we use cookies can be found in our [Cookie Policy](cookie-settings.html).
11. Third-party analytics and marketing tools
11.1 Google Analytics
We use Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies to analyze how users use our site. The information generated by the cookies about your use of our website is generally transmitted to and stored on Google's servers in the USA.
We have implemented the following measures to protect your privacy:
- - We have activated IP address anonymization
- - We have concluded a data processing addendum with Google
- - We obtain your consent before activating analytics cookies (for users from the EU/CZ)
- - We respect the Global Privacy Control signal and your choices to opt out of tracking
11.2 Facebook Pixel (Meta Pixel)
We use Facebook Pixel, an analytics tool provided by Meta Platforms, Inc., which helps us measure the effectiveness of our advertising campaigns and better understand the actions that users take on our website.
For users from the EU/CZ, we activate Facebook Pixel only with your explicit consent. For users from the USA, we respect your right to opt out of the sale or sharing of your personal information through the "Do Not Sell or Share My Personal Information" link in the footer of our website.
12. Links to other websites
Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
13. Changes to this privacy policy
We may update this privacy policy from time to time to reflect changes in our data processing practices or for other operational, legal, or regulatory reasons.
We will notify you of any changes by posting the new privacy policy on this page and, in case of significant changes, we will inform you via email or through a notice on our website before the change becomes effective.
We encourage you to review this privacy policy periodically to stay informed about how we protect your data.
14. Contact information
If you have any questions about this privacy policy or our privacy practices, please contact us:
For customers from the EU and the Czech Republic:
Roanga Planet s.r.o.
Address: [TO BE ADDED]
Email: privacy@roanga.com
Phone: [TO BE ADDED]
For customers from the USA:
Roanga Planet LLC
Address: [TO BE ADDED]
Email: privacy@roanga.com
Phone: [TO BE ADDED]
15. Additional information for California residents
15.1 Categories of personal information collected
In the last 12 months, we have collected the following categories of personal information from consumers:
- - Identifiers (e.g., name, email address, IP address)
- - Personal information listed in the California Customer Records statute (e.g., address, phone number)
- - Commercial information (e.g., purchase history)
- - Internet or other electronic network activity information (e.g., browsing history)
- - Geolocation data
- - Inferences drawn from the above information
15.2 Sources of personal information
We collect personal information directly from you, automatically through your use of our services, and from third parties as described in Section 2 of this policy.
15.3 Business or commercial purposes for collecting personal information
We collect personal information for the business purposes described in Section 3 of this policy.
15.4 Sharing of personal information
In the last 12 months, we have shared personal information with the categories of third parties listed in Section 4 of this policy.
15.5 Sale or sharing of personal information
Under the California Consumer Privacy Act (CCPA/CPRA), the use of certain third-party tracking technologies may be considered a "sale" or "sharing" of personal information.
In the last 12 months, we have "sold" or "shared" the following categories of personal information to third parties such as advertising and analytics service providers:
- - Identifiers (e.g., online identifiers, IP addresses)
- - Internet or other electronic network activity information
We do not sell or share personal information of individuals we know are under 16 years of age.
15.6 Your rights under CCPA/CPRA
As a California resident, you have the rights described in Section 7.2 of this policy. To exercise your rights, contact us using the methods listed in Section 7.4.
We will not discriminate against you for exercising your rights under the CCPA/CPRA.
16. Additional information for EU/CZ residents
16.1 Legal bases for processing
As mentioned in Section 3, we process your personal data based on the following legal bases under GDPR:
- - Performance of a contract (Art. 6(1)(b) GDPR): When we process your data for the purpose of fulfilling our contractual obligations to you.
- - Legal obligation (Art. 6(1)(c) GDPR): When we process your data to comply with legal obligations.
- - Legitimate interests (Art. 6(1)(f) GDPR): When we process your data based on our legitimate interests that do not override your fundamental rights and freedoms.
- - Consent (Art. 6(1)(a) GDPR): When we process your data based on your voluntary consent.
16.2 Automated decision-making and profiling
We do not carry out any automated decision-making that produces legal or similarly significant effects without human intervention. However, we may use profiling for marketing purposes to provide you with personalized offers, content, and advertisements based on your preferences and behavior.
16.3 Supervisory authorities
If you are located in the EU or CZ and have concerns about our processing of your personal data that we have not been able to resolve, you have the right to lodge a complaint with the relevant supervisory authority:
For the Czech Republic:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
www.uoou.cz
For other EU countries:
The relevant supervisory authority in your country of residence or workplace.
---
This Privacy Policy was last updated on September 5, 2025, and is effective as of this date.