Rock & Herb Private Limited (“we, us or our”) takes your privacy seriously and values the relationship we have with you.
This Privacy Policy describes how www.rockandherb.com (the “Site” or “we”) collects, uses, and discloses your Personal Information that you provide to us through our digital platform, such as website, mobile applications and social media network when you visit or make a purchase from the Site.
This Privacy Policy may be updated periodically and without prior notice to you to reflect changes in our personal information practices. Therefore, we recommend that you take a moment to read this privacy policy.
Last updated: 17th August 2021
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support.
In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.
Device information
Examples of Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
Order information
Examples of Personal Information collected: name, age, date of birth, billing address, shipping address, payment information (including credit card numbers), email address, phone number, nationality, preferred language, purchase history, your physical characteristics and skin concerns.
Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
Source of collection: collected from you.
Customer support information
Examples of Personal Information collected: name, age, date of birth, billing address, shipping address, payment information (including credit card numbers), email address, phone number, nationality, preferred language, purchase history, your physical characteristics and skin concerns.
Purpose of collection: to provide customer support.
Source of collection: collected from you.
We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above.
We may share generic aggregated demographic information not linked to any personal identification information regarding visitors and users with our business partners, trusted affiliates and advertisers for the purposes outlined above.
We may use third party service providers to help us operate our business and the Site or administer activities on our behalf, such as sending out newsletters or surveys. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
We use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
We use FB advertising to help us build brand awareness, reach out to interested customers and understand how our customers use the Site -- you can opt out of the targeted marketing here: https://www.facebook.com/settings/?tab=ads
We will share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights. We may share your information with these third parties for those limited purposes if you have given us your permission.
We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.
We respect your personal information and take steps to ensure that your personal data is protected against unauthorized or unlawful processing and against accidental loss, damage or destruction or disclosure and we limit access to your personal data to persons who reasonably need access to it, to provide products or services to you.
Our platforms may contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies or how those third parties may use your personal data. Please check these policies before you submit any personal data to these websites.
If you create an account with us, you will be asked to provide an account user name and password as part of our security procedures. You must treat such information as confidential and you must not disclose it to any third party.
Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:
When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.
If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.
We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.
Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.
Services that include elements of automated decision-making include:
Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.
The right to be provided with a copy of your personal data.
In accordance with the applicable data protection laws, you can, at any time, request access, rectification, erasure and portability of your personal data or restrict and object to the processing of your personal data. A summary of these rights is provided below:
The right to be provided with a copy of your personal data.
The right to require us to correct any mistakes in your data or to complete your information.
The right to require us to delete your personal data – in certain situations.
The right to require us to restrict processing of your personal data.
The right to withdraw your consent for the collection, use and/or disclosure of your personal data in our possession by submitting your request to admin@rockandherb.com.
The right to stop receiving our marketing communication
If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us via admin@rockandherb.com
Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.
If you are a resident of California, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us via admin@rockandherb.com
A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.
We use the following cookies to optimize your experience on our Site and to provide our services.
Cookies Necessary for the Functioning of the Store
Name |
Function |
_ab |
Used in connection with access to admin. |
_secure_session_id |
Used in connection with navigation through a storefront. |
cart |
Used in connection with shopping cart. |
cart_sig |
Used in connection with checkout. |
cart_ts |
Used in connection with checkout. |
checkout_token |
Used in connection with checkout. |
secret |
Used in connection with checkout. |
secure_customer_sig |
Used in connection with customer login. |
storefront_digest |
Used in connection with customer login. |
_shopify_u |
Used to facilitate updating customer account information. |
Reporting and Analytics
Name |
Function |
_tracking_consent |
Tracking preferences. |
_landing_page |
Track landing pages |
_orig_referrer |
Track landing pages |
_s |
Shopify analytics. |
_shopify_fs |
Shopify analytics. |
_shopify_s |
Shopify analytics. |
_shopify_sa_p |
Shopify analytics relating to marketing & referrals. |
_shopify_sa_t |
Shopify analytics relating to marketing & referrals. |
_shopify_y |
Shopify analytics. |
_y |
Shopify analytics. |
The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.
You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.
Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org.
Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.
We have also implemented Google Analytics Advertising feature for our websites. Advertising features include: 1) Re-marketing with Google Analytics, 2) Google Display Network Impression reporting, 3) Google Analytics Demographics and Interest Reporting, and 4) Integrated services that require Google Analytics to collect data about your traffic via google advertising cookies and identifiers. The data collected is solely for the purpose of marketing and provided value added services for our users.
You can opt-out of the Google Analytics Advertising Feature you use, including Ads settings, Ad settings for mobile apps or any other available means. You can opt out at https://tools.google.com/dlpage/gaoptout/
Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at admin@rockandherb.com