Legal
Privacy Policy
Betterly Nutrition collects the information needed to take an order, ship it, support you afterwards, and — only if you ask for it — send you email or texts. We never exchange your personal information for money. We do share what you view and buy here with our two advertising partners, Meta and TikTok, so we can measure our advertising, and you can switch that off at any time.
Last updated
Scope and who we are
This policy explains how Betterly Nutrition LLC (“Betterly”, “we”, “us”) handles personal information on betterlynutrition.com and in the emails and text messages we send. It applies to shoppers, account holders, newsletter subscribers, and anyone who contacts our support team. It also covers the staff tools that connect our own social channels — see Our YouTube channels.
We are a United States business. We sell and ship only within the 48 contiguous United States, and the services that run this store are operated from the United States. If you are outside the US, please do not send us personal information through this site.
Our mailing address is a virtual mailbox for correspondence, not a storefront or a warehouse: 936 SW 1st Ave PMB 877, Miami, FL 33130, US.
What we collect
Four kinds of information: what you give us, what your order requires, what you consent to receive, and a small amount of usage data that tells us which pages are working.
Account information
Your email address and a password. Passwords are hashed by our authentication provider before storage — we never see, store, or have any way to recover your plaintext password. If you save a name, phone number or address to your account, we keep them on your profile until you change them or close your account. Checkout asks for the shipping address on every order, and a Subscribe & Save renewal uses the phone number on your profile.
Order information
Your shipping name and address, your phone number (our fulfilment partner requires one to create a shipping label), the items and quantities you bought, the amounts charged including sales tax and shipping, your order reference, and the tracking number the carrier gives us.
Payment information
Payment is completed on a page hosted by Stripe, our payment processor. Your full card number, expiry date and security code are never sent to, seen by, or stored on Betterly’s servers. Stripe returns a payment status and a reference so we can mark the order paid and manage subscription renewals. Stripe handles that card data under its own privacy policy.
Messages you send us
If you use the contact form we store the name, email address, subject and message you submit. If you request a return we store your email address and the reason you give, and we link it to your most recent order so we can process it. Email you send to our support addresses is stored in the mailbox it arrives in.
Marketing consent and engagement
If you subscribe to our email list we store your address, the fact that you confirmed the subscription, and when. If you opt in to text messages we store your mobile number and your consent. Our email provider reports back when a message is delivered, opened, clicked, bounced or marked as spam, and we record those events so we can stop mailing addresses that do not want to hear from us.
Cart recovery
If you enter your email address during checkout but do not finish, we store that address alongside the contents of your cart so we can send you a reminder. The prices and product names in that record are re-read from our own catalogue, never taken from your browser.
Usage analytics
Our own analytics run alongside the advertising measurement described under cookies, and they work differently. Your browser keeps two random identifiers in its local storage — not cookies: one for the browser, so we can tell a returning visitor from a new one, and one for the current visit, which ends after 30 minutes without activity. Against them we record the event name — a page view, a product view, a search and how many products it found, an add-to-cart, a checkout start, a purchase, a button click — the page path, which element you interacted with, how long the page was on screen, how far you scrolled, and a count (never the content or position) of taps, clicks and key presses, which is how we tell people from automated traffic. On a visit’s first pages we also record where it came from — the referring site without its query string, and any campaign tags on the link you followed — plus your screen size, time zone, language, and type of device, browser and operating system. With each visit we also keep your browser’s user-agent string (the line every browser sends naming itself and its operating system) and a fingerprint of the way it sets up its encrypted connection (a TLS fingerprint), which help us tell real browsers from automated traffic. When you complete a purchase, we link your order to the visit it was made in — and, through the browser identifier, to that browser’s earlier visits — so each sale can be credited to where it came from.
Our host tells us an approximate location — city, region and country, with map coordinates for that city-level estimate — worked out from your network’s IP address at the moment of the visit. We do not store your IP address in that log: it (for an IPv6 address, its network part) is combined with a random value that exists for one day and scrambled one way, only so that automated traffic from a single network can be spotted, and that value is deleted after two days, after which the scrambled form cannot be traced back to any address. None of this is sent to Meta or any other advertising platform. Once a day, grouped records of the day’s suspicious visits (approximate city, time zone, language, screen size, device and browser type, pages, referring sites, time spent, taps and scrolls, whether anything was added to the cart or bought, and the hour of the visit), the day’s site searches and missing-page addresses, and daily visit and sales totals — never your name, contact details, address, IP address or the contents of any order — go through an automated review run with Anthropic, to separate real visitors from bots and summarise the day for us.
Technical and security data
Our host records standard web-server data for every request, including IP address, browser type and the page requested. Public endpoints such as the newsletter form and the guest order lookup hold an IP address briefly in memory to rate-limit abuse; that value is not written to our database. When a known crawler, link-preview service or other automated fetcher requests a page, we log its name, the user-agent string it sent, its country and the page, without any query string. We keep the IP address only for crawlers whose operators publish their address ranges (Googlebot, Bingbot, GPTBot and the like), so we can check a crawler really is who it claims to be — those are companies’ servers, not people. Some link previews, such as the ones iMessage and WhatsApp show when you share a link, are fetched from your own device, and for those no IP address is kept.
Why we use it
- To take payment, fulfil and ship your order, and give you tracking.
- To send transactional messages — order confirmations, shipping notices, notices about subscription payments, password resets and refund or replacement updates. These are part of the service, not marketing.
- To run Subscribe & Save: charging monthly renewals, and letting you cancel or update your card.
- To answer your questions and handle refunds and replacements.
- To send marketing email or texts, only where you have opted in.
- To recover abandoned carts, where you gave us your email address during checkout.
- To understand which pages and products people actually use, so we can improve them.
- To measure how well our advertising works and to show our ads to people who have visited, through Meta and TikTok — unless you switch that off at your privacy choices.
- To detect and prevent fraud, abuse and automated attacks, and to keep accounts secure.
- To meet our tax, accounting and other legal obligations.
We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you.
Our legal bases
US privacy law does not generally use the language of “legal bases”, but we set ours out anyway because it makes plain what each use of your data actually rests on.
- Performing our contract with you — taking, charging, fulfilling and supporting orders and subscriptions.
- Your consent — marketing email and text messages. You can withdraw it at any time, and withdrawing it does not affect anything we sent before.
- Our legitimate interests — securing the site, preventing fraud, measuring how the store is used, and reminding you about a cart you left behind. We rely on this only where your interests and rights do not override ours.
- Legal obligation — keeping sales and tax records, and responding to lawful requests.
How long we keep it
- Order and payment records — for as long as tax and accounting law requires, generally at least seven years from the end of the tax year in which the order was placed.
- Account data — until you close your account. We then delete or anonymise it within 90 days, except for the order records above.
- Support and return messages — 24 months from your last message, so we still have the history if you write again.
- Abandoned-cart records — 90 days, then deleted whether or not the cart was recovered.
- Analytics events — 24 months, after which they are deleted or kept only in aggregate form that cannot be traced to a session.
- Advertising cookies — about 90 days for Meta’s, up to 13 months from last use for TikTok’s, and 28 days for our own copy of the TikTok click id. What Meta and TikTok keep is governed by their own policies.
- Our suppression list — kept indefinitely. If you unsubscribe, we have to remember your address in order to keep not mailing it. It holds nothing beyond the address and the reason.
Marketing and opting out
Our newsletter is double opt-in: entering your address only creates a pending signup and sends a confirmation link. Nothing marketing-related goes out until you click it, which means nobody can subscribe you using your address. Every marketing email carries an unsubscribe link and a one-click unsubscribe header your mail app can act on directly. You can also opt out at any time on our unsubscribe page. Opt-outs take effect immediately.
Text messages
We text only mobile numbers that have given express written consent, and we check that consent again on every send. Reply STOP, END, CANCEL, QUIT or UNSUBSCRIBE to any message and we will stop; reply START to opt back in. Message and data rates may apply. Consent to marketing texts is never a condition of buying anything.
What you cannot opt out of
Transactional messages: order confirmations, shipping and delivery updates, notices about subscription payments, refund confirmations, password resets and security alerts. They are part of the service you asked for. Cancel your subscriptions from your subscriptions page and ask us to close the account, and those stop too.
Your privacy rights
Wherever you live in the United States, we extend the same rights to everyone rather than gating them by state:
- Know what personal information we hold about you, where we got it, why we use it, and who we share it with.
- Get a copy of it in a portable format.
- Correct anything that is inaccurate.
- Delete it, subject to the records we are legally required to keep.
- Withdraw consent to marketing email or texts.
- Opt out of the sale and sharing of your personal information and of targeted advertising, at your privacy choices. It takes one click and we do not ask you why.
- Be treated the same whether or not you exercise any of these rights. We will not deny you products, charge you a different price, or give you a worse experience for asking.
California residents (CCPA/CPRA)
In the twelve months before this policy was last updated, we collected the categories of personal information described in what we collect — identifiers, customer records, commercial information, internet activity, and approximate location (city, region and country) inferred from your network’s IP address, as well as the shipping address you gave us — for the purposes listed in why we use it, and disclosed it for business purposes to the providers listed in who we share it with. We did not receive money for personal information. From 19 September 2026 we have shared, with Meta, and from 1 October 2026 with TikTok, for cross-context behavioural advertising: identifiers (advertising cookie and click ids, IP address, and hashed email address and phone number — and, with Meta, hashed name and address), internet activity (pages and products viewed, and email sign-ups) and commercial information (items added to the cart, checkouts started and orders, with their value), for people who had not opted out — which California and several other states treat as a “sale or share” whether or not money changes hands. You can opt out at any time at your privacy choices. We did not sell or share the personal information of any consumer we knew to be under 16.
We do not ask you for sensitive personal information as the CPRA defines it: no government identifiers, no precise geolocation, no biometric data, no racial or ethnic origin, no union membership, no health records, no contents of your private messages. Because we do not collect sensitive personal information as the CPRA defines it, the right to limit its use does not arise.
We would rather be plain about the edge of that, though. Your purchase history is not sensitive personal information in the statutory sense, but a list of supplements can still suggest something about your general wellness preferences — and the products you viewed and ordered are among the things we share with Meta and TikTok for advertising, as described under cookies and analytics — except products that could suggest a health condition (for example sleep, digestive, heart, bone and joint, weight, men’s health, liver, blood-sugar, eye or sexual-health products), which we never name to them, and whose pages, like our health guides, report nothing to them at all. We never exchange any of it for money, and you can stop that sharing whenever you like at your privacy choices.
You may use an authorised agent to make a request for you. We will ask the agent for written proof of your permission, and we may ask you to confirm it directly.
Other states
If you live in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, among others — you have substantially the same rights, plus a right to appeal if we refuse a request. To appeal, reply to our decision with “Appeal” in the subject line. We will review it and give you a written answer with our reasoning.
How to exercise them
There is one path, and it is short. Email support@betterlynutrition.com with “Privacy request” in the subject line, and tell us:
- Which right you want to exercise — a copy, a correction, or deletion.
- The email address you ordered or signed up with, so we can find your records.
- The state you live in, if you want us to apply a specific state law.
We verify requests by matching them to the email address on your account or orders, and by replying to that address; for a deletion request we may ask you to confirm from that inbox. We will not ask you for a government ID or for any information we do not already hold just to prove who you are.
We acknowledge requests within 10 business days and answer them within 45 calendar days. If a request is genuinely complex we may take a further 45 days, and we will tell you why before the first period runs out. There is no charge unless a request is repetitive or excessive, and we will tell you before doing anything on that basis.
Much of this you can do yourself, instantly: view and update your details, see your orders, and manage or cancel subscriptions from your account; check an order without signing in at order tracking; and switch marketing off at our unsubscribe page.
Children’s privacy
This site is intended for adults. Our terms of service require purchasers to be at least 18. We do not direct this site to children under 13 and we do not knowingly collect their personal information. If you believe a child has given us information, email support@betterlynutrition.com and we will delete it and close any associated account. Supplements should be kept out of reach of children, and should not be given to a child without advice from a healthcare provider.
How we protect data
- Traffic to and from this site is encrypted in transit, and our database provider encrypts data at rest.
- Card data never touches our servers — it goes from your browser straight to our payment processor.
- Account data is protected by database-level access rules, so a signed-in customer can read their own records and nobody else’s.
- Incoming webhooks from our payment, email, SMS and fulfilment providers are signature-verified before we act on them, so a forged request cannot alter an order or change your consent.
- Unsubscribe links are cryptographically signed, so one cannot be guessed or forged to opt someone else out.
- Public endpoints are rate-limited to blunt automated abuse, and staff access to customer data is limited to the people who need it.
No system is perfectly secure, and we will not tell you otherwise. If we discover a breach affecting your personal information, we will notify you and the relevant authorities as the law requires.
Our YouTube channels
Our staff tools use YouTube API Services to connect Betterly Nutrition’s own YouTube channels, through our own Google developer project. This is not something customers use or sign in to, and it involves no customer data. Use of YouTube is governed by the YouTube Terms of Service, and Google’s handling of data is described in the Google Privacy Policy.
- What we access: the name, channel id and handle of the channel being connected, so our tools can confirm which channel they reach, and permission to post to that channel. We use it only to upload videos our staff have approved, with their titles, descriptions, tags and cover images. We do not read viewers’ data or anyone else’s videos.
- What we store: the channel id and handle, when it was connected, the ids and links of the videos we post, and Google’s access tokens, which are encrypted before they are saved.
- Sharing: none. We do not sell, share or use this information for advertising.
- Revoking access: the account owner can withdraw our access at any time from Google’s security settings. To have the stored tokens deleted, email support@betterlynutrition.com.
Changes to this policy
We update this policy when what we do with data changes — for example if we add a service provider. The “last updated” date at the top of the page always reflects the current version. If a change materially affects your rights or how we use information you have already given us, we will say so prominently here and email account holders and subscribers before it takes effect.
Contact us
Privacy questions and requests: support@betterlynutrition.com. Questions about a specific order: support@betterlynutrition.com. You can also write to us through our contact form.
Betterly Nutrition LLC936 SW 1st Ave PMB 877
Miami, FL 33130, USA virtual mailbox for correspondence. It is not a storefront, a warehouse, or a returns address — please do not send products here without contacting us first.
See also our terms of service and our accessibility statement.
This policy describes our actual practices and is published in good faith, but it is not legal advice and has not been reviewed by counsel. It should be reviewed by a qualified attorney before anyone relies on it.
