Skip to content
Betterly Nutrition

Legal

Privacy Policy

Betterly Nutrition collects the information needed to take an order, ship it, support you afterwards, and — only if you ask for it — send you email or texts. We never exchange your personal information for money. We do share what you view and buy here with our two advertising partners, Meta and TikTok, so we can measure our advertising, and you can switch that off at any time.

Last updated

Scope and who we are

This policy explains how Betterly Nutrition LLC (“Betterly”, “we”, “us”) handles personal information on betterlynutrition.com and in the emails and text messages we send. It applies to shoppers, account holders, newsletter subscribers, and anyone who contacts our support team. It also covers the staff tools that connect our own social channels — see Our YouTube channels.

We are a United States business. We sell and ship only within the 48 contiguous United States, and the services that run this store are operated from the United States. If you are outside the US, please do not send us personal information through this site.

Our mailing address is a virtual mailbox for correspondence, not a storefront or a warehouse: 936 SW 1st Ave PMB 877, Miami, FL 33130, US.

What we collect

Four kinds of information: what you give us, what your order requires, what you consent to receive, and a small amount of usage data that tells us which pages are working.

Account information

Your email address and a password. Passwords are hashed by our authentication provider before storage — we never see, store, or have any way to recover your plaintext password. If you save a name, phone number or address to your account, we keep them on your profile until you change them or close your account. Checkout asks for the shipping address on every order, and a Subscribe & Save renewal uses the phone number on your profile.

Order information

Your shipping name and address, your phone number (our fulfilment partner requires one to create a shipping label), the items and quantities you bought, the amounts charged including sales tax and shipping, your order reference, and the tracking number the carrier gives us.

Payment information

Payment is completed on a page hosted by Stripe, our payment processor. Your full card number, expiry date and security code are never sent to, seen by, or stored on Betterly’s servers. Stripe returns a payment status and a reference so we can mark the order paid and manage subscription renewals. Stripe handles that card data under its own privacy policy.

Messages you send us

If you use the contact form we store the name, email address, subject and message you submit. If you request a return we store your email address and the reason you give, and we link it to your most recent order so we can process it. Email you send to our support addresses is stored in the mailbox it arrives in.

Marketing consent and engagement

If you subscribe to our email list we store your address, the fact that you confirmed the subscription, and when. If you opt in to text messages we store your mobile number and your consent. Our email provider reports back when a message is delivered, opened, clicked, bounced or marked as spam, and we record those events so we can stop mailing addresses that do not want to hear from us.

Cart recovery

If you enter your email address during checkout but do not finish, we store that address alongside the contents of your cart so we can send you a reminder. The prices and product names in that record are re-read from our own catalogue, never taken from your browser.

Usage analytics

Our own analytics run alongside the advertising measurement described under cookies, and they work differently. Your browser keeps two random identifiers in its local storage — not cookies: one for the browser, so we can tell a returning visitor from a new one, and one for the current visit, which ends after 30 minutes without activity. Against them we record the event name — a page view, a product view, a search and how many products it found, an add-to-cart, a checkout start, a purchase, a button click — the page path, which element you interacted with, how long the page was on screen, how far you scrolled, and a count (never the content or position) of taps, clicks and key presses, which is how we tell people from automated traffic. On a visit’s first pages we also record where it came from — the referring site without its query string, and any campaign tags on the link you followed — plus your screen size, time zone, language, and type of device, browser and operating system. With each visit we also keep your browser’s user-agent string (the line every browser sends naming itself and its operating system) and a fingerprint of the way it sets up its encrypted connection (a TLS fingerprint), which help us tell real browsers from automated traffic. When you complete a purchase, we link your order to the visit it was made in — and, through the browser identifier, to that browser’s earlier visits — so each sale can be credited to where it came from.

Our host tells us an approximate location — city, region and country, with map coordinates for that city-level estimate — worked out from your network’s IP address at the moment of the visit. We do not store your IP address in that log: it (for an IPv6 address, its network part) is combined with a random value that exists for one day and scrambled one way, only so that automated traffic from a single network can be spotted, and that value is deleted after two days, after which the scrambled form cannot be traced back to any address. None of this is sent to Meta or any other advertising platform. Once a day, grouped records of the day’s suspicious visits (approximate city, time zone, language, screen size, device and browser type, pages, referring sites, time spent, taps and scrolls, whether anything was added to the cart or bought, and the hour of the visit), the day’s site searches and missing-page addresses, and daily visit and sales totals — never your name, contact details, address, IP address or the contents of any order — go through an automated review run with Anthropic, to separate real visitors from bots and summarise the day for us.

Technical and security data

Our host records standard web-server data for every request, including IP address, browser type and the page requested. Public endpoints such as the newsletter form and the guest order lookup hold an IP address briefly in memory to rate-limit abuse; that value is not written to our database. When a known crawler, link-preview service or other automated fetcher requests a page, we log its name, the user-agent string it sent, its country and the page, without any query string. We keep the IP address only for crawlers whose operators publish their address ranges (Googlebot, Bingbot, GPTBot and the like), so we can check a crawler really is who it claims to be — those are companies’ servers, not people. Some link previews, such as the ones iMessage and WhatsApp show when you share a link, are fetched from your own device, and for those no IP address is kept.

Why we use it

  • To take payment, fulfil and ship your order, and give you tracking.
  • To send transactional messages — order confirmations, shipping notices, notices about subscription payments, password resets and refund or replacement updates. These are part of the service, not marketing.
  • To run Subscribe & Save: charging monthly renewals, and letting you cancel or update your card.
  • To answer your questions and handle refunds and replacements.
  • To send marketing email or texts, only where you have opted in.
  • To recover abandoned carts, where you gave us your email address during checkout.
  • To understand which pages and products people actually use, so we can improve them.
  • To measure how well our advertising works and to show our ads to people who have visited, through Meta and TikTok — unless you switch that off at your privacy choices.
  • To detect and prevent fraud, abuse and automated attacks, and to keep accounts secure.
  • To meet our tax, accounting and other legal obligations.

We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you.

How long we keep it

  • Order and payment records — for as long as tax and accounting law requires, generally at least seven years from the end of the tax year in which the order was placed.
  • Account data — until you close your account. We then delete or anonymise it within 90 days, except for the order records above.
  • Support and return messages — 24 months from your last message, so we still have the history if you write again.
  • Abandoned-cart records — 90 days, then deleted whether or not the cart was recovered.
  • Analytics events — 24 months, after which they are deleted or kept only in aggregate form that cannot be traced to a session.
  • Advertising cookies — about 90 days for Meta’s, up to 13 months from last use for TikTok’s, and 28 days for our own copy of the TikTok click id. What Meta and TikTok keep is governed by their own policies.
  • Our suppression list — kept indefinitely. If you unsubscribe, we have to remember your address in order to keep not mailing it. It holds nothing beyond the address and the reason.

Who we share it with

We share personal information only with the providers below, and only the data each one needs. Every one of them is under contract to use it only to provide its service to us — except our advertising partners, Meta and TikTok, which also use it for their own advertising systems. That is why California and other states call it a “sale or share” or “targeted advertising”, and why you can switch it off.

The service providers and advertising partners Betterly Nutrition shares personal information with, what each one does, and what data it receives
ProviderWhat they doWhat they receive
StripePayments, subscription billing, sales-tax calculation, billing portalCard details entered directly on Stripe’s own page, plus billing name, email, shipping address and order amounts, and — so an order can be credited to the ad that led to it — your advertising opt-out setting and, unless advertising is off, the advertising cookies and click ids described under cookies and your browser’s user-agent string
SupabaseOur database, sign-in system and file storageYour account record, orders, addresses, support messages, marketing consent and analytics events
VercelWebsite hosting, delivery and aggregate page analyticsStandard request data — IP address, browser, page requested — and cookieless page-view counts
ResendSending transactional and marketing emailYour email address, your name, and the contents of the message we send you
TwilioSending text messages, only to numbers that opted inYour mobile number and the message text
Shopify and SuplifulOur fulfilment pipeline — picking, packing and labelling your orderYour shipping name, address, phone number, and the items you ordered
Meta (Facebook and Instagram)Advertising measurement and retargeting on Facebook and Instagram. One of our two advertising partners (with TikTok): unlike the other providers on this list, Meta also uses what we share for its own advertising systemsWhich pages and products you looked at, what you added to your cart, when you started a checkout or signed up for our emails, and what you ordered, plus your IP address, browser and device type, the advertising cookies described below, and your email address, phone number, name and address in a hashed (scrambled) form that Meta matches against its own account records
TikTokAdvertising measurement and retargeting on TikTok. Like Meta, TikTok also uses what we share for its own advertising systemsWhich pages and products you looked at, what you added to your cart, when you started a checkout or signed up for our emails, and what you ordered, plus your IP address, browser and device type, the TikTok advertising cookie (_ttp) and click id (ttclid) described below, and your email address and phone number in a hashed (scrambled) form that TikTok matches against its own accounts
AnthropicA once-a-day automated review of our own site analytics, to tell real visitors from automated traffic and summarise the day for usGrouped records of that day’s suspicious visits (approximate city, time zone, language, screen size, device and browser type, pages viewed, referring sites, time spent, how much the pages were tapped and scrolled, whether anything was added to the cart or bought, and the hour of the visit), the day’s site searches and missing-page addresses, the pages automated crawlers fetched, and daily visit and sales totals by page, product, traffic source, campaign, region and device type. Never your name, contact details, address, IP address or the contents of any order
RefersionAffiliate attribution — crediting the partner whose link sent you hereThe affiliate’s id, your order id, order total and item list, and your first name, last name and email address

Beyond those providers we may disclose information to our professional advisers, such as accountants and lawyers, where they need it to advise us; to a regulator, court or law enforcement agency where the law requires it or where it is necessary to protect our rights or someone’s safety; and to a buyer or successor if the business is sold or merged, in which case we will post notice here before your information becomes subject to a different policy.

We never exchange your personal information for money, and we do not give your email address or phone number to data brokers. We do share information with Meta and TikTok for advertising, which California and several other states treat as a “sale or share” whether or not money changes hands — so we say so plainly rather than hiding behind the word “sell”. That sharing is the Meta Pixel and the TikTok Pixel, the copies of the Meta Pixel’s page events our server sends Meta, and the order reports our server sends them both, described under cookies and analytics, and you can turn it off at your privacy choices.

Cookies and analytics

This site uses very little browser storage. One item on this list — the advertising cookies — does follow you off this site, and you can switch it off at your privacy choices.

  • Sign-in cookies — strictly necessary. They keep you signed in and protect the session. Block them and you will not be able to stay logged in.
  • Cart storage — your cart lives in your browser’s local storage so it survives a refresh. It stays on your device until you check out or clear it.
  • Analytics identifiers — two random values in local storage, not cookies: one for this browser and one for the current visit (it ends after 30 minutes of inactivity). They let us count returning visitors, are never shared with advertisers, and disappear when you clear this site’s data. Beside them sits a list of your last few checkout references, so reopening an order confirmation page never counts the sale twice.
  • Aggregate page analytics — our host counts page views without setting a tracking cookie and without building a cross-site profile of you.
  • Advertising cookies — set by Meta (_fbp and, if you arrived through a Facebook or Instagram link, _fbc, which our own server may set for Meta so it lasts its full 90 days) and by TikTok (_ttp, ttcsid_… and, if you arrived from one of our TikTok ads, ttclid), plus our own copy of that TikTok click id (bn_ttclid, 28 days) so an order can be credited to the ad. Meta’s script also notes the site that referred you in this browser’s local storage, and TikTok’s keeps a few working values, including that click id, in this tab’s session storage. Meta’s cookies last about 90 days and TikTok’s up to 13 months from last use. They let us measure which ads lead to orders and let Meta and TikTok show you products you looked at here, and they are the only storage on this site that follows you off it. They are set only for visitors in the US outside Washington and Nevada, based on the approximate location of your internet connection, and only once you start using a page. Opt out and we delete the ones stored on our site and stop setting them.
  • Ad click ids and the advertising check — if the link you followed carries an ad click id (fbclid or ttclid), this tab keeps a copy in its session storage (bn_ad_click) from the moment the page loads, wherever you are, unless you have opted out, so it is not lost when you move between pages. It goes to our server only once the advertising scripts are allowed to load, so the matching cookie above can be set, and it is deleted when you close the tab or opt out. Beside it, bn_ad_gate keeps this tab’s answer to whether the advertising scripts may load, so each page does not ask our server again, and, when a Global Privacy Control signal has switched advertising off, bn_ad_cleared notes that this tab has already deleted the advertising storage. None of them leaves this site.
  • Affiliate cookie — if you arrive from an affiliate’s link we store that link’s public affiliate id (rfsn_aid) for 30 days, so the affiliate is credited if you order. It holds no information about you and is read only by our own checkout.

What the Meta and TikTok Pixels do, and how to stop them

The Meta Pixel and the TikTok Pixel are small scripts from Meta (Facebook and Instagram) and TikTok. They load on the shop only for visitors in the US outside Washington and Nevada, based on the approximate location of your internet connection, only once you start using a page (a tap, click, key press or scroll wheel), and never for automated browsers we can recognise. To decide, the page asks our own server once per browser tab, and again each time a page loads while you are signed in; it looks at that location, your browser type and, if you are signed in, whether your account has advertising off, and it keeps no record of the answer. Our server makes the same check again each time it forwards one of the page events described below, and keeps no record of that answer either, apart from a short count, held in memory for a few minutes and keyed to a scrambled form of Meta’s cookie, that limits how many events one browser can forward.

They never report anything from your account and sign-in pages, checkout and order confirmation, order tracking, returns, unsubscribe, privacy or privacy-choices pages, our blog and its health guides, search results, or the pages of products and categories that could suggest a health condition — and they never load in our staff portal. Everywhere else they report which pages and products you looked at, what you added to your cart, when you start a checkout and when you sign up for our emails or our welcome offer, along with your IP address, browser and device type and the advertising cookies above. Once the Meta Pixel has sent one of those product views, cart adds, checkout starts or sign-ups, the page also tells our own server which event it was, when it happened, the page’s address and the products, quantities and prices in it, only so our server can check it against the same rules; our server then sends Meta a copy of that event, so it still counts if the script’s own report is lost on the way. The copy names no more products than the script’s report, at our catalogue price or lower, and carries the page’s address without anything after it, your browser type and Meta’s advertising cookies, but never your IP address, and Meta counts the two as one event. Your orders are reported by our own server alone, never by the scripts, so the record is complete even if a script was blocked.

With that order we send your email address and phone number in a scrambled (hashed) form, and to Meta also your name and address in hashed form. For an order that includes a product that could suggest a health condition, we report the order total but never that product, and we never report orders shipped to or billed in Washington or Nevada. We never hand Meta or TikTok any of it in readable form — but they can still match a scrambled value against an account they already have, which is exactly what makes the measurement work, so we would rather describe it plainly than call it anonymous.

You can switch all of this off. Go to your privacy choices and turn advertising off: neither pixel loads, we delete the advertising cookies stored on our site, and our server stops sending Meta its copies of your page events and stops sending your orders to Meta or TikTok too. We also honour a Global Privacy Control signal from your browser as a valid opt-out request — in the browser, and whenever it reaches our server with a page event or at checkout — so you do not have to click anything, and advertising stays off unless you turn it back on yourself at your privacy choices. Even then, while your browser sends the signal our server sends Meta no copies of your page events. If you check out with advertising off by your own choice or by that signal, we remember it on your account, so later orders from any device are not reported either, and the pixels stay off the next time you visit signed in from another browser. Otherwise the choice is remembered in the browser you made it in.

Marketing and opting out

Email

Our newsletter is double opt-in: entering your address only creates a pending signup and sends a confirmation link. Nothing marketing-related goes out until you click it, which means nobody can subscribe you using your address. Every marketing email carries an unsubscribe link and a one-click unsubscribe header your mail app can act on directly. You can also opt out at any time on our unsubscribe page. Opt-outs take effect immediately.

Text messages

We text only mobile numbers that have given express written consent, and we check that consent again on every send. Reply STOP, END, CANCEL, QUIT or UNSUBSCRIBE to any message and we will stop; reply START to opt back in. Message and data rates may apply. Consent to marketing texts is never a condition of buying anything.

What you cannot opt out of

Transactional messages: order confirmations, shipping and delivery updates, notices about subscription payments, refund confirmations, password resets and security alerts. They are part of the service you asked for. Cancel your subscriptions from your subscriptions page and ask us to close the account, and those stop too.

Your privacy rights

Wherever you live in the United States, we extend the same rights to everyone rather than gating them by state:

  • Know what personal information we hold about you, where we got it, why we use it, and who we share it with.
  • Get a copy of it in a portable format.
  • Correct anything that is inaccurate.
  • Delete it, subject to the records we are legally required to keep.
  • Withdraw consent to marketing email or texts.
  • Opt out of the sale and sharing of your personal information and of targeted advertising, at your privacy choices. It takes one click and we do not ask you why.
  • Be treated the same whether or not you exercise any of these rights. We will not deny you products, charge you a different price, or give you a worse experience for asking.

California residents (CCPA/CPRA)

In the twelve months before this policy was last updated, we collected the categories of personal information described in what we collect — identifiers, customer records, commercial information, internet activity, and approximate location (city, region and country) inferred from your network’s IP address, as well as the shipping address you gave us — for the purposes listed in why we use it, and disclosed it for business purposes to the providers listed in who we share it with. We did not receive money for personal information. From 19 September 2026 we have shared, with Meta, and from 1 October 2026 with TikTok, for cross-context behavioural advertising: identifiers (advertising cookie and click ids, IP address, and hashed email address and phone number — and, with Meta, hashed name and address), internet activity (pages and products viewed, and email sign-ups) and commercial information (items added to the cart, checkouts started and orders, with their value), for people who had not opted out — which California and several other states treat as a “sale or share” whether or not money changes hands. You can opt out at any time at your privacy choices. We did not sell or share the personal information of any consumer we knew to be under 16.

We do not ask you for sensitive personal information as the CPRA defines it: no government identifiers, no precise geolocation, no biometric data, no racial or ethnic origin, no union membership, no health records, no contents of your private messages. Because we do not collect sensitive personal information as the CPRA defines it, the right to limit its use does not arise.

We would rather be plain about the edge of that, though. Your purchase history is not sensitive personal information in the statutory sense, but a list of supplements can still suggest something about your general wellness preferences — and the products you viewed and ordered are among the things we share with Meta and TikTok for advertising, as described under cookies and analytics — except products that could suggest a health condition (for example sleep, digestive, heart, bone and joint, weight, men’s health, liver, blood-sugar, eye or sexual-health products), which we never name to them, and whose pages, like our health guides, report nothing to them at all. We never exchange any of it for money, and you can stop that sharing whenever you like at your privacy choices.

You may use an authorised agent to make a request for you. We will ask the agent for written proof of your permission, and we may ask you to confirm it directly.

Other states

If you live in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, among others — you have substantially the same rights, plus a right to appeal if we refuse a request. To appeal, reply to our decision with “Appeal” in the subject line. We will review it and give you a written answer with our reasoning.

How to exercise them

There is one path, and it is short. Email support@betterlynutrition.com with “Privacy request” in the subject line, and tell us:

  • Which right you want to exercise — a copy, a correction, or deletion.
  • The email address you ordered or signed up with, so we can find your records.
  • The state you live in, if you want us to apply a specific state law.

We verify requests by matching them to the email address on your account or orders, and by replying to that address; for a deletion request we may ask you to confirm from that inbox. We will not ask you for a government ID or for any information we do not already hold just to prove who you are.

We acknowledge requests within 10 business days and answer them within 45 calendar days. If a request is genuinely complex we may take a further 45 days, and we will tell you why before the first period runs out. There is no charge unless a request is repetitive or excessive, and we will tell you before doing anything on that basis.

Much of this you can do yourself, instantly: view and update your details, see your orders, and manage or cancel subscriptions from your account; check an order without signing in at order tracking; and switch marketing off at our unsubscribe page.

Children’s privacy

This site is intended for adults. Our terms of service require purchasers to be at least 18. We do not direct this site to children under 13 and we do not knowingly collect their personal information. If you believe a child has given us information, email support@betterlynutrition.com and we will delete it and close any associated account. Supplements should be kept out of reach of children, and should not be given to a child without advice from a healthcare provider.

How we protect data

  • Traffic to and from this site is encrypted in transit, and our database provider encrypts data at rest.
  • Card data never touches our servers — it goes from your browser straight to our payment processor.
  • Account data is protected by database-level access rules, so a signed-in customer can read their own records and nobody else’s.
  • Incoming webhooks from our payment, email, SMS and fulfilment providers are signature-verified before we act on them, so a forged request cannot alter an order or change your consent.
  • Unsubscribe links are cryptographically signed, so one cannot be guessed or forged to opt someone else out.
  • Public endpoints are rate-limited to blunt automated abuse, and staff access to customer data is limited to the people who need it.

No system is perfectly secure, and we will not tell you otherwise. If we discover a breach affecting your personal information, we will notify you and the relevant authorities as the law requires.

Our YouTube channels

Our staff tools use YouTube API Services to connect Betterly Nutrition’s own YouTube channels, through our own Google developer project. This is not something customers use or sign in to, and it involves no customer data. Use of YouTube is governed by the YouTube Terms of Service, and Google’s handling of data is described in the Google Privacy Policy.

  • What we access: the name, channel id and handle of the channel being connected, so our tools can confirm which channel they reach, and permission to post to that channel. We use it only to upload videos our staff have approved, with their titles, descriptions, tags and cover images. We do not read viewers’ data or anyone else’s videos.
  • What we store: the channel id and handle, when it was connected, the ids and links of the videos we post, and Google’s access tokens, which are encrypted before they are saved.
  • Sharing: none. We do not sell, share or use this information for advertising.
  • Revoking access: the account owner can withdraw our access at any time from Google’s security settings. To have the stored tokens deleted, email support@betterlynutrition.com.

Changes to this policy

We update this policy when what we do with data changes — for example if we add a service provider. The “last updated” date at the top of the page always reflects the current version. If a change materially affects your rights or how we use information you have already given us, we will say so prominently here and email account holders and subscribers before it takes effect.

Contact us

Privacy questions and requests: support@betterlynutrition.com. Questions about a specific order: support@betterlynutrition.com. You can also write to us through our contact form.

Betterly Nutrition LLC
936 SW 1st Ave PMB 877
Miami, FL 33130, USA virtual mailbox for correspondence. It is not a storefront, a warehouse, or a returns address — please do not send products here without contacting us first.

See also our terms of service and our accessibility statement.

This policy describes our actual practices and is published in good faith, but it is not legal advice and has not been reviewed by counsel. It should be reviewed by a qualified attorney before anyone relies on it.