Privacy policy

Last updated: 4 Jun 2025

1. Who we are

COSMEE WORLD LLC (“COSMEE”, “we”, “our”) provides personalized skincare products and the DermAI™ diagnostic tool. This notice explains how we collect, use and protect your personal information when you visit cosmeeworld.com or interact with us in any other way.

2. What information we collect

Category Examples Legal Basis*
Account & Contact Name, email, phone, shipping address Contract
Transaction Order details, last 4 digits of card Contract / Legit. interest
DermAI™ Data Selfie, skin metrics, questionnaire responses Consent (explicit)
Device & Usage IP, browser type, pages visited, referring URL, cookies Legit. interest
Marketing Preferences Opt‑in status, engagement with emails Consent

*For EU/UK visitors. In the US aplicamos principios equivalentes.

3. How we use your data

  1. Personalize product formulas and recommendations.

  2. Process payments and deliver your orders.

  3. Communicate order status, product updates, or support.

  4. Improve our website and services via aggregated analytics.

  5. Market our products (only if you have opted‑in; you can unsubscribe any time).

4. Sharing your data

We never sell your personal information. We share only with:

  • Shopify Inc. (store platform)

  • Payment processors (e.g., Shopify Payments, PayPal)

  • Logistics partners (USPS, UPS, etc.)

  • Marketing & analytics vendors (Meta, Google Ads) — limited to hashed identifiers or cookie data

  • Legal or regulatory bodies when required by law.

All partners must sign a data‑processing agreement and apply industry‑standard security.

5. Cookies & similar tech

We use first‑party and third‑party cookies for site functionality, analytics and advertising. You may manage preferences in our cookie banner or in your browser settings. Disabling cookies may limit site features.

6. Data retention

We retain:

  • Order records – 7 years (tax & accounting).

  • DermAI™ images – 12 months, then anonymized.

  • Marketing data – until you unsubscribe or 2 years after last interaction.

  • Back‑ups are purged on a 30‑day rolling basis.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES‑256). Access is restricted by role‑based controls and MFA. No full card numbers are stored on COSMEE servers.

8. Your rights

Depending on your location, you may:

  • Access or correct your data

  • Delete your account

  • Object to or restrict processing

  • Opt‑out of marketing or “sale” of data (CCPA)
    Request via privacy@cosmeeworld.com. We will respond within 30 days.

9. Children

We do not knowingly collect data from anyone under 14. Parents who believe a child has provided data may contact us for deletion.

10. International transfers

COSMEE is US‑based. When we transfer data outside your country, we rely on Standard Contractual Clauses or equivalent safeguards.

11. Changes to this Policy

We may update this notice periodically. Material changes will be announced via email or site banner at least 10 days before they take effect.

12. Contact us

📧 info@cosmeeworld.com
📬 COSMEE WORLD LLC, 1756 Lacy Ridge Dr., Belton, TX 76513, USA.