Privacy Policy
Effective date: June 26, 2026
This Privacy Policy explains how Moringa.co (“we”, “us”) collects, uses, and shares personal information when you visit moringa.co, place an order, sign up for our newsletter, enroll in the Brand Partner program, or chat with our AI assistant.
1. Information we collect
You provide directly
- Name, email, mailing address, billing address, and phone number;
- Payment information (processed by our PCI-compliant payment processor — we do not store full card numbers);
- Account credentials and preferences;
- Brand Partner enrollment data, tax identifiers (such as W-9/W-8 information), and bank/payout details;
- Communications you send us, including chatbot and AI receptionist transcripts.
We collect automatically
- IP address, browser type, device identifiers, operating system;
- Pages visited, links clicked, time on site, referring URLs;
- Cookies, pixels, and similar technologies (see Cookie Policy).
From third parties
- Order, shipping, and returns data from fulfillment partners;
- Authentication data from sign-in providers;
- Analytics and ad-attribution data from advertising partners.
2. How we use information
- To process and ship orders and manage subscriptions;
- To operate the Brand Partner program, calculate commissions, and issue 1099/T4A or equivalent tax forms;
- To provide customer support and respond to inquiries;
- To send transactional emails (order confirmations, shipping updates, security alerts);
- With your consent, to send marketing emails — you can unsubscribe at any time;
- To detect fraud, secure our Services, and enforce our Terms;
- To comply with legal obligations.
3. AI assistant and receptionist
When you use our chatbot or AI receptionist, your messages, contact information, and conversation transcripts may be sent to our AI service provider(s) for the sole purpose of generating a response and improving the quality of our service. We do not sell transcripts. Please do not share sensitive health, financial, or identity information through these channels.
4. How we share information
- Service providers — payment processors, fulfillment partners, email providers, analytics, hosting (Vercel), and AI providers, under contract;
- Brand Partner upline — limited customer-level data necessary to administer the compensation plan (name, city/state, order timing). Brand Partners are contractually obligated to keep this data confidential;
- Legal & safety — when required by law, subpoena, or to protect rights, property, or safety;
- Business transfers — in connection with a merger, acquisition, or sale of assets.
We do not sell your personal information for monetary value.
5. Your rights
Depending on where you live, you may have the following rights:
- Access to the personal data we hold about you;
- Correction of inaccurate data;
- Deletion of your data (subject to legal retention obligations);
- Portability of your data;
- Objection to or restriction of certain processing;
- Opt-out of targeted advertising or “sale/sharing” of personal information.
To exercise these rights, email privacy@moringa.co. We will respond within the timeframe required by applicable law (typically 30–45 days). California, Colorado, Connecticut, Utah, Virginia, and EU/UK residents have additional rights — see Section 8.
6. Cookies & tracking
We use cookies and similar technologies for essential site functionality, analytics, and (with consent) ads. Manage your preferences via your browser settings and our cookie banner. See Cookie Policy for the full list.
7. Data retention
We retain personal data for as long as necessary to provide the Services and for legitimate business and legal purposes (typically 7 years for order, tax, and Brand Partner records; 2 years for chatbot transcripts; marketing data until you unsubscribe).
8. Region-specific disclosures
California (CCPA/CPRA)
California residents may request the categories of personal information collected, sold, or shared in the prior 12 months; request deletion; opt out of “sale” or “sharing” (we do not engage in monetary sale, but may share data for cross-context behavioral advertising); and limit the use of sensitive personal information. Send requests to privacy@moringa.co.
EU / UK (GDPR / UK GDPR)
We process personal data on the legal bases of contract performance, legitimate interests, consent, and compliance with legal obligations. You have the right to lodge a complaint with your local supervisory authority.
Canada (PIPEDA)
Canadian residents may request access, correction, or deletion of their personal data and may contact the Office of the Privacy Commissioner of Canada with concerns.
9. Security
We use industry-standard administrative, technical, and physical safeguards to protect your information, including encryption in transit, access controls, and regular security review. No method of transmission or storage is 100% secure.
10. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us so we can delete it.
11. International transfers
We are based in the United States and process data there. Where applicable, we use Standard Contractual Clauses or equivalent safeguards to transfer personal data from the EU/UK and other regions.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be posted with an updated Effective date and, where appropriate, communicated by email.
13. Contact
Privacy Officer · Moringa.co · privacy@moringa.co.
This document is provided for general informational purposes and does not constitute legal advice. Please have a qualified attorney review it for your business and jurisdiction before launch.