Last updated June, 2025
This Privacy Policy (the "Policy") defines the practices of Aura Health LLC (the "Platform Operator," "We," "Our" or "Us") regarding the collection, use, disclosure, and protection of your personal information as a customer ("You") on this website getroota.com (the "Website"). It applies whenever You visit the Website, make a purchase, or otherwise interact with any of Our services (collectively, the "Services").
The Platform Operator provides a platform for You to purchase products from STR.VERT CONSULTANTS LTD (the "Seller"). When You complete a transaction on the Website, you enter into a binding agreement with the Platform Operator for the provision of the Services. Your use of the Services is also governed by Our Terms and Conditions (the "Terms and Conditions"), and by using the Services, You confirm Your agreement to both the Policy and the Terms and Conditions.
We are committed to protecting Your privacy and handling Your personal data in a transparent and secure manner, in full compliance with the applicable data protection and privacy laws, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), as well as other relevant state privacy regulations.
Personal Information We Collect
In the Policy, "personal information" refers to any data that identifies or can be reasonably linked to You. To provide the Services and fulfill Our contractual obligations, We collect and process the following categories of personal information:
- Your full name, shipping and billing addresses, telephone number, and email address.
- Information required to process Your payments, such as credit or debit card details, transaction records, and other billing information.
- A history of Your transactions, including products You have viewed, purchased, returned, or exchanged.
- Records of Your correspondence with Us, including customer support inquiries and feedback You provide.
- Information about the device, browser, and network connection You use to access Our Services, including Your IP address and other unique identifiers.
- Information about how You navigate and engage with Our Services, such as the pages You visit and the features You use.
We may obtain personal information from various sources, including directly from You, automatically via cookies and similar tracking technologies during Your navigation of the Website, and from third-party service providers or partners integral to the operation of Our business.
How We Use Your Personal Information
We process Your personal information for several key purposes, depending on how You interact with the Services:
To provide, customize, and improve the Services, We use Your information to fulfill Our contract with You. This includes processing Your payments, completing Your orders by sharing details with the Seller for shipping, and handling any returns, for which We use Your identity and contact data, financial and payment data, and commercial and activity data. This processing is based on contractual necessity (Art. 6(1)(b) GDPR), and data related to transactions is retained for 10 years. We also use Your data, including technical data and interaction data, to personalize Your experience, save Your preferences, and suggest products based on Your activity. This is based on Our legitimate interests (Art. 6(1)(f) GDPR) to improve and personalize the Services, and this data is retained for 1 month after Your last use of the Website.
For marketing and advertising, We may send You promotional offers and updates via email or text based on your explicit consent (Art. 6(1)(a) GDPR), using Your identity and contact data and commercial and activity data. additionally, based on Our legitimate interests (Art. 6(1)(f) GDPR), We may display advertising on the Website relevant to Your interests by using Your purchase history and browsing activity, which involves Your commercial and activity data, technical data, and interaction data. Data used for these marketing purposes is retained for 5 years from Your last interaction or until You revoke Your consent.
For risk management, and to protect the Website and Our customers, We use Your identity and contact data, financial and payment data, technical data, and interaction data to verify transactions, monitor potentially fraudulent or illegal activity, and ensure the security of Your payments. This processing is based on Our legitimate interests (Art. 6(1)(f) GDPR) to maintain a secure platform. Data used for these purposes is retained for 1 month after Your last use of the Website, while data related to any specific security incidents may be retained for up to 10 years.
For customer service and relationship management, We use Your identity and contact data, communication data, and commercial and activity data to provide customer support, respond to Your questions, and keep You informed about Your orders. Our legal basis for this processing is contractual necessity (Art. 6(1)(b) GDPR) for inquiries related to your orders, while for general inquiries, we rely on your consent when you contact us (Art. 6(1)(a) GDPR). Data used for customer service purposes is retained for 10 years from the date of Your last communication with Us.
For legal compliance and rights protection, We may process Your information to comply with applicable laws, respond to lawful requests from government authorities, and to enforce the Terms and Conditions or protect Our legal rights. This can involve any information relevant to the matter, which may include all categories of data We collect. Our legal basis is a legal obligation (Art. 6(1)(c) GDPR) when complying with the law and our legitimate interests (Art. 6(1)(f) GDPR) when protecting our rights. Data is retained for the duration required by law (such as 10 years for financial records) or for the duration of any legal proceedings and a subsequent period to account for statutes of limitation.
How We Share Your Personal Information
To operate Our business and provide the Services, We may share Your personal information with the following categories of trusted partners:
- To fulfill Your order, We provide the Seller with Your shipping and contact details. The Seller is an independent entity responsible for the products You purchase, as well as preparing and shipping Your products.
- We share necessary transaction information with secure payment service providers to authorize and process Your payments safely.
- We partner with vendors who perform services on Our behalf, such as IT management, data analytics, marketing, and customer support. We only provide the information they need to perform their specific function.
- We may share information within Our corporate family (e.g., with a parent company or subsidiaries). If We are involved in a merger, acquisition, or sale of assets, Your information may be transferred as part of that transaction.
- We may disclose information to comply with the law, enforce the Terms and Conditions, or protect the rights, property, or safety of Platform Operator, Our users, or others.
Any disclosure of personal information is conducted in adherence with the principle of data minimization. We maintain legally binding data processing agreements with Our third-party service providers to ensure the confidentiality, integrity, and security of Your data in accordance with the GDPR.
Your Rights and Choices
Pursuant to applicable data protection laws, You, as the data subject, are entitled to exercise the following rights with respect to Your personal data:
- Right to Access: You have the right to get a copy of the personal information We hold about You.
- Right to Rectification: If You notice that any of the personal data We hold about You is wrong or missing, You have the right to ask Us to correct it.
- Right to Erasure: You are allowed to ask Us to delete Your personal data.
- Right to Restriction: You have the right to limit how We use Your data without necessarily deleting it.
- Right to Data Portability: You can request to receive Your personal data in a structured, commonly used, and machine-readable format.
- Right to Object: You have the right to object to Our processing of Your personal data, especially when We are processing it based on Our legitimate interests or for direct marketing.
To submit a request to exercise any of the rights, please contact Us. We reserve the right to verify Your identity prior to processing any such request.
Use of Cookies and Other Tracking Technologies
The Website utilizes cookies and similar tracking technologies to enhance and personalize Your experience, analyze site performance, and for marketing purposes.
- Strictly Necessary Cookies: Indispensable for the operation of the Website and the provision of the Services.
- Performance and Analytics Cookies: Gather aggregated data regarding Your interaction with the Website.
- Targeting and Advertising Cookies: Designed to track Your browsing activity across websites to build a profile of Your interests.
You can manage cookie settings through Your browser settings.
Our Data Policy on Children
The Website is restricted to users 18 years of age and older. We do not knowingly collect the personal data of anyone under the age of 18.
Contact Information
For questions, concerns, or claims regarding this Privacy Policy or Your data, please contact the Platform Operator:
hello@getroota.com