Privacy Policy

Last updated June, 2025

This Privacy Policy (the “Policy”) defines the practices of Aura Health LLC (the “Platform Operator,” “We,” “Our” or “Us”) regarding the collection, use, disclosure, and protection of your personal information as a customer (“You”) on this website getroota.com (the “Website”). It applies whenever You visit the Website, make a purchase, or otherwise interact with any of Our services (collectively, the “Services”). The Platform Operator provides a platform for You to purchase products from STR.VERT CONSULTANTS LTD (the “Seller”). When You complete a transaction on the Website, you enter into a binding agreement with the Platform Operator for the provision of the Services. Your use of the Services is also governed by Our Terms and Conditions (the “Terms and Conditions”), and by using the Services, You confirm Your agreement to both the Policy and the Terms and Conditions.

We are committed to protecting Your privacy and handling Your personal data in a transparent and secure manner, in full compliance with the applicable data protection and privacy laws, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), as well as other relevant state privacy regulations.

Please review the Terms and Conditions and the Policy carefully before You proceed to use the Website or make a purchase.

Personal Information We Collect


In the Policy, “personal information” refers to any data that identifies or can be reasonably linked to You. To provide the Services and fulfill Our contractual obligations, We collect and process the following categories of personal information:

  • Your full name, shipping and billing addresses, telephone number, and email address.
  • Information required to process Your payments, such as credit or debit card details, transaction records, and other billing information.
  • A history of Your transactions, including products You have viewed, purchased, returned, or exchanged.
  • Records of Your correspondence with Us, including customer support inquiries and feedback You provide.
  • Information about the device, browser, and network connection You use to access Our Services, including Your IP address and other unique identifiers.
  • Information about how You navigate and engage with Our Services, such as the pages You visit and the features You use.

We may obtain personal information from various sources, including directly from You, automatically via cookies and similar tracking technologies during Your navigation of the Website, and from third-party service providers or partners integral to the operation of Our business.

How We Use Your Personal Information


We process Your personal information for several key purposes, depending on how You interact with the Services:

To provide, customize, and improve the Services, We use Your information to fulfill Our contract with You. This includes processing Your payments, completing Your orders by sharing details with the Seller for shipping, and handling any returns, for which We use Your identity and contact data, financial and payment data, and commercial and activity data. This processing is based on contractual necessity (Art. 6(1)(b) GDPR), and data related to transactions is retained for 10 years. We also use Your data, including technical data and interaction data, to personalize Your experience, save Your preferences, and suggest products based on Your activity. This is based on Our legitimate interests (Art. 6(1)(f) GDPR) to improve and personalize the Services, and this data is retained for 1 month after Your last use of the Website.

For marketing and advertising, We may send You promotional offers and updates via email or text based on your explicit consent (Art. 6(1)(a) GDPR), using Your identity and contact data and commercial and activity data. additionally, based on Our legitimate interests (Art. 6(1)(f) GDPR), We may display advertising on the Website relevant to Your interests by using Your purchase history and browsing activity, which involves Your commercial and activity data, technical data, and interaction data. Data used for these marketing purposes is retained for 5 years from Your last interaction or until You revoke Your consent.

For risk management, and to protect the Website and Our customers, We use Your identity and contact data, financial and payment data, technical data, and interaction data to verify transactions, monitor potentially fraudulent or illegal activity, and ensure the security of Your payments. This processing is based on Our legitimate interests (Art. 6(1)(f) GDPR) to maintain a secure platform. Data used for these purposes is retained for 1 month after Your last use of the Website, while data related to any specific security incidents may be retained for up to 10 years.

For customer service and relationship management, We use Your identity and contact data, communication data, and commercial and activity data to provide customer support, respond to Your questions, and keep You informed about Your orders. Our legal basis for this processing is contractual necessity (Art. 6(1)(b) GDPR) for inquiries related to your orders, while for general inquiries, we rely on your consent when you contact us (Art. 6(1)(a) GDPR). Data used for customer service purposes is retained for 10 years from the date of Your last communication with Us.

For legal compliance and rights protection, We may process Your information to comply with applicable laws, respond to lawful requests from government authorities, and to enforce the Terms and Conditions or protect Our legal rights. This can involve any information relevant to the matter, which may include all categories of data We collect. Our legal basis is a legal obligation (Art. 6(1)(c) GDPR) when complying with the law and our legitimate interests (Art. 6(1)(f) GDPR) when protecting our rights. Data is retained for the duration required by law (such as 10 years for financial records) or for the duration of any legal proceedings and a subsequent period to account for statutes of limitation.

How We Share Your Personal Information


To operate Our business and provide the Services, We may share Your personal information with the following categories of trusted partners:

  • To fulfill Your order, We provide the Seller with Your shipping and contact details. The Seller is an independent entity responsible for the products You purchase, as well as preparing and shipping Your products.
  • We share necessary transaction information with secure payment service providers to authorize and process Your payments safely.
  • We partner with vendors who perform services on Our behalf, such as IT management, data analytics, marketing, and customer support. We only provide the information they need to perform their specific function.
  • We may share information within Our corporate family (e.g., with a parent company or subsidiaries). If We are involved in a merger, acquisition, or sale of assets, Your information may be transferred as part of that transaction.
  • We may disclose information to comply with the law, enforce the Terms and Conditions, or protect the rights, property, or safety of Platform Operator, Our users, or others.

Any disclosure of personal information is conducted in adherence with the principle of data minimization. We maintain legally binding data processing agreements with Our third-party service providers to ensure the confidentiality, integrity, and security of Your data in accordance with the General Data Protection Regulation (GDPR).

Your Rights and Choices


Pursuant to applicable data protection laws, You, as the data subject, are entitled to exercise the following rights with respect to Your personal data:

Right to Access: You have the right to get a copy of the personal information We hold about You. This allows You to check what data We have and make sure We are processing it legally. You can request this information to understand exactly what We have collected, such as Your name, email, purchase history, or any other data you’ve provided.

Right to Rectification: If You notice that any of the personal data We hold about You is wrong or missing, You have the right to ask Us to correct it. For example, if Your address is spelled incorrectly or Your phone number has changed, You can request that We update Our records.

Right to Erasure: You are allowed to ask Us to delete Your personal data. This right applies in specific situations, such as when the data is no longer necessary for the purpose it was collected, or when You withdraw Your consent and there is no other legal basis for Us to process it.

Right to Restriction: You have the right to limit how We use Your data without necessarily deleting it. This right can be exercised when the data’s accuracy is contested, or when the processing is unlawful, but You do not want the data to be deleted. We can still store Your data but cannot use it for other purposes.

Right to Data Portability: You can request to receive Your personal data in a structured, commonly used, and machine-readable format, making it simple to move Your data from one service to another.

Right to Object: You have the right to object to Our processing of Your personal data, especially when We are processing it based on Our legitimate interests. If You object, We must stop processing Your data unless We can demonstrate compelling legitimate grounds that override Your rights, or for the establishment, exercise, or defense of legal claims. This right also allows You to object to Your data being used for direct marketing.

To submit a request to exercise any of the rights, please contact Us via the methods provided in Section 12 of this Policy. We reserve the right to verify Your identity prior to processing any such request to ensure the security of Your personal information.

You may manage Your preferences for marketing communications at any time. All promotional emails sent by Us include an unsubscribe mechanism by which You may opt out of future correspondence.

Complaints


If You have a complaint regarding how We handle Your personal information, We encourage You to first contact Us directly using the contact details provided in Section 12 to allow for a timely resolution. You always have the right to lodge a complaint with Your local data protection authority. Additionally, depending on Your jurisdiction, You may have the right to appeal our decision regarding Your complaint by contacting Us.

Use of Cookies and Other Tracking Technologies


The Website utilizes cookies and similar tracking technologies to enhance and personalize Your experience, analyze site performance, and for marketing purposes. A cookie is a small data file placed on Your device that allows Our servers to identify Your browser and device upon subsequent visits.

Types of Cookies We Use:

Strictly Necessary Cookies – these cookies are indispensable for the operation of the Website and the provision of the Services. They facilitate core functionalities such as Your authentication, session management, and secure transactions. Pursuant to applicable law, these cookies do not require Your prior consent.

Performance and Analytics Cookies – These cookies gather aggregated data regarding Your interaction with the Website, such as page visits and traffic sources, for the sole purpose of improving the Website’s functionality. The legal basis for the deployment of these cookies is Your explicit consent.

Targeting and Advertising Cookies – These cookies are designed to track Your browsing activity across websites to build a profile of Your interests and display targeted advertising. Their use is subject to Your explicit prior consent.

You can manage cookie settings through Your browser settings. For further instructions, please refer to the help pages of browsers such as Chrome, Firefox, or Safari.

Security and Retention of Your Information


We have implemented and maintained appropriate technical and organizational security measures designed to safeguard Your personal data against accidental or unlawful destruction, loss, alteration, or unauthorized access. Nevertheless, no method of transmission over the Internet or method of electronic storage is completely secure.

We shall retain Your personal data only for the duration necessary to fulfill the purposes for which it was originally collected, including for the purposes of satisfying any legal, accounting, or reporting requirements or to resolve disputes.

Our Data Policy on Children


The Website is restricted to users 18 years of age and older. We are not responsible for any data collection from underage individuals who do not comply with this restriction. We do not knowingly collect the personal data of anyone under the age of 18.

Third-Party Websites


The Website may provide links to external websites for Your convenience. We do not endorse, and assume no liability for, the content, security, or privacy practices of such third-party sites. Accessing any third-party website is done at Your own risk, and We encourage you to review their respective policies.

Amendments to The Policy


We reserve the right to amend this Privacy Policy at any time to reflect changes in Our practices or for other operational, legal, or regulatory reasons. The revised Policy will be posted on this page along with the updated effective date. Your continued use of the Website following the posting of changes constitutes Your acceptance of such revised Privacy Policy.

Contact Information


For questions, concerns, or claims regarding this Privacy Policy or Your data, please contact the Platform Operator:

hello@getroota.com