Privacy Policy
Privacy & Data Protection
Privacy Policy
We value the trust you place in Z Natural Foods. This Policy explains, as clearly as we can, how we collect, use, disclose, protect, retain, and transfer personal information across our websites, checkout, marketplaces, communications, retail and wholesale operations, shipping, pickup, apps, and service providers—and how you can reach us when you want help or wish to exercise a privacy choice.
Choose a privacy control below. Each entire box is a clickable, keyboard-accessible link that opens Your Privacy Choices.
Reading & navigation tools
Personalize this Privacy Policy for easier reading and navigation. The core controls below are native HTML/CSS controls, so they continue to work even if page-specific JavaScript is unavailable or removed. They do not store your selections or change your privacy choices.
Accessibility note: Core access and the reading presets above do not depend on JavaScript. Keyboard navigation, browser zoom, user-defined spacing, forced colors, reduced-motion preferences, and assistive technologies remain independently supported. Read-aloud and the print-dialog shortcut appear only when the browser supports and permits those optional enhancements; your browser's normal print command remains available either way.
Reading tools are ready. Default text size is 100%.
This Privacy Policy (“Privacy Policy”) is issued by Z Natural Foods LLC (“ZNF,” “we,” “us,” or “our”), a Florida limited liability company operating from West Palm Beach, Palm Beach County, Florida. We appreciate the opportunity to serve you and want our privacy practices to be understandable, practical, and easy to navigate. This Privacy Policy describes how ZNF collects, receives, uses, discloses, stores, retains, secures, transfers, and otherwise processes personal information by or on behalf of ZNF in connection with our websites, checkout flows, online storefronts, marketplaces, communications, products, services, local pickup operations, wholesale and retail transactions, and related business systems (collectively, the “Services”).
By accessing, using, visiting, interacting with, placing an order through, requesting a quote from, communicating with, or otherwise engaging with any ZNF Service, you acknowledge that you have read and understood this Privacy Policy. Your use of the Services is also subject to ZNF’s Terms of Use and the other applicable ZNF legal policies posted on ZNF’s Legal page, to the fullest extent permitted by law.
Nothing in this Privacy Policy is intended to waive, limit, narrow, restrict, or override any non-waivable right or obligation under applicable law.
1. Scope; Interpretation; Relationship to Other ZNF Policies
1.1 Scope of this Privacy Policy
This Privacy Policy applies to personal information collected, received, generated, inferred, combined, disclosed, stored, transferred, preserved, or otherwise processed by or on behalf of ZNF through or in connection with the Services.
This Privacy Policy is intended to govern ZNF’s own data practices and the data practices of service providers, processors, vendors, and other parties acting on ZNF’s behalf or under ZNF’s direction, to the extent applicable. It does not purport to replace, supersede, or control the privacy practices of third-party marketplaces, social-media platforms, payment providers, carriers, search engines, advertising platforms, or other third parties that may independently collect, control, or process information under their own terms and privacy notices.
1.2 Relationship to the ZNF Legal Policies
This Privacy Policy is part of ZNF’s broader legal framework and must be read together with our:
- Terms of Use;
- Cookie Policy;
- Your Privacy Choices / Data Sharing Opt-out Notice;
- U.S. State Privacy Addendum;
- International Privacy Addendum;
- GDPR Statement / EEA-UK-Switzerland Privacy Notice;
- Digital Advertising & Analytics Policy;
- Information Security Policy & Responsible Vulnerability Disclosure Policy;
- Mobile Terms of Service;
- Purchases, Subscriptions & Pre-Orders Policy;
- Shipping & Delivery Policy;
- Cancelations, Returns, Refunds & Title Policy;
- Content Policy;
- Product Review Guidelines;
- Accessibility Statement;
- Legal Notice, Disclaimers, Risk Allocation, & Important Consumer / Commercial Disclosures Policy;
- Agent Terms & Automated Access / Bot Policy;
- DMCA Compliance Statement & Copyright Infringement Policy; and
- any other applicable notice, disclosure, or policy posted on ZNF’s Legal page,
as each may be amended from time to time (collectively, the “ZNF Legal Policies”).
1.3 Order of precedence
If there is a direct conflict among ZNF Legal Policies on the same subject matter, the following rules apply:
- the Terms of Use control with respect to arbitration, class-action waiver, limitation of liability, governing law, venue, evidentiary standards, survival, and other general risk-allocation provisions;
- this Privacy Policy controls with respect to ZNF’s baseline personal-information practices and general privacy disclosures;
- the Cookie Policy controls with respect to cookies, pixels, tags, SDKs, similar technologies, consent tools, browser/device controls, tracker-specific disclosures, and browser/device-specific preference mechanics;
- the Your Privacy Choices / Data Sharing Opt-out Notice controls with respect to sale, sharing, targeted advertising, browser-based opt-out signals, and related privacy-choice mechanics;
- the U.S. State Privacy Addendum controls with respect to state-specific privacy rights, notices, appeals, sensitive-data rules, and state-law-specific disclosures, to the extent those laws apply;
- the International Privacy Addendum and GDPR Statement / EEA-UK-Switzerland Privacy Notice control to the extent non-U.S. privacy law validly applies to the processing at issue;
- the Information Security Policy, Mobile Terms, Digital Advertising & Analytics Policy, Purchases Policy, Shipping Policy, Returns Policy, Content Policy, Product Review Guidelines, Accessibility Statement, Agent Terms, and DMCA Policy additionally govern their own more specific subject matter.
1.4 No overstatement; no waiver; no third-party beneficiary creation
Nothing in this Privacy Policy shall be construed as:
- an admission that any particular state, federal, or foreign privacy law applies in every circumstance, transaction, channel, shipment, platform, or processing activity;
- a waiver of any exemption, threshold limitation, jurisdictional argument, defense, privilege, immunity, or lawful exception available to ZNF;
- an undertaking by ZNF to provide rights broader than those required by applicable law;
- a representation that identical rights, remedies, deadlines, complaint paths, or consent standards exist in every jurisdiction; or
- the creation of any third-party beneficiary rights except to the extent non-waivable law expressly requires otherwise;
- the creation of a private right of action or cause of action where applicable law does not independently provide one; or
- an admission of statutory coverage, or a permanent contractual expansion of rights, merely because ZNF voluntarily offers a privacy control, honors a request, provides an appeal path, recognizes a browser signal, or applies a more protective operational practice in circumstances where a statute may not otherwise require it.
1.5 Layered notices, point-of-collection disclosures, and specific consent language
ZNF may provide shorter, contextual, or just-in-time privacy notices at or near the point where personal information is collected, including at checkout, account registration, quote forms, newsletter and mobile-message enrollment, cookie or tracking interfaces, review and survey forms, customer-support tools, chat interfaces, local-pickup workflows, marketplace interactions, financing or payment flows, and other features. Those notices supplement this Privacy Policy.
If a point-of-collection notice, consent disclosure, transaction-specific notice, or jurisdiction-specific addendum is more specific than this Privacy Policy regarding a particular collection or processing activity, the more specific notice controls for that activity to the extent required by applicable law. Nothing in a short-form notice limits any non-waivable right.
2. Who We Are; Controller Identity; Contact Information
For purposes of this Privacy Policy, the primary business responsible for the Services is:
Z Natural Foods LLC5407 N Haverhill Rd Unit 336
West Palm Beach, Florida 33407
United States
General privacy contact: Privacy@znaturalfoods.com
General customer-support contact: Orders@znaturalfoods.com
Telephone: +1-888-963-6637
Where a more specific ZNF policy provides a dedicated contact point for a particular topic, that dedicated channel should be used when applicable. By way of example only:
- privacy-choice opt-outs may be submitted through the Your Privacy Choices / Data Sharing Opt-out Notice and its designated tools or request methods;
- U.S. state privacy rights may be further addressed through the U.S. State Privacy Addendum;
- EEA / UK / Switzerland privacy matters may be further addressed through the GDPR Statement / EEA-UK-Switzerland Privacy Notice;
- other international privacy matters may be further addressed through the International Privacy Addendum;
- accessibility-related requests may be directed through the Accessibility Statement;
- information-security, incident, or vulnerability matters may be governed additionally by the Information Security Policy & Responsible Vulnerability Disclosure Policy;
- mobile-message enrollment, consent, revocation, and unsubscribe rules are additionally governed by the Mobile Terms of Service; and
- copyright-specific notices are additionally governed by the DMCA Compliance Statement & Copyright Infringement Policy.
ZNF may designate additional department-specific, representative, regulator-facing, or jurisdiction-specific contact points where required or operationally appropriate, and may update those details in this Privacy Policy or another applicable ZNF notice.
Online privacy tools: You may also use the Privacy Control Center / Your Privacy Choices to manage available cookie, advertising, marketing, and privacy-rights controls.
3. Covered Channels, Transactions, and Business Contexts
This Privacy Policy applies to personal information processed by or on behalf of ZNF through or in connection with, without limitation:
- ZNaturalFoods.com and any successor domain, subdomain, mobile site, application, storefront, landing page, or checkout flow;
- website storefronts, shopping-cart functions, customer-account areas, quote workflows, subscription or recurring-order workflows, order-management functions, and customer-service interfaces;
- retail / consumer (B2C) orders placed online, by phone, by email, by chat, by SMS/MMS where permitted, or through other lawful ordering methods;
- wholesale, bulk, freight, export, and other business-to-business (B2B) transactions, including quote requests, invoice transactions, purchase-order workflows, customer shipping-account arrangements, and commercial fulfillment arrangements;
- local pickup or will-call transactions at or from ZNF’s West Palm Beach facility or another designated pickup point;
- domestic shipping and delivery operations involving carriers and logistics providers such as FedEx, USPS, UPS, DHL, LTL freight, FTL freight, customs intermediaries, freight brokers, and similar providers;
- international sales, export, import, customs, freight, brokerage, and related logistics, including transactions involving Canada and other non-U.S. destinations;
- marketplace, social-commerce, and third-party platform activity where ZNF acts as seller, merchant of record, fulfillment party, content source, publisher, contracting party, or lawful controller of the relevant interaction, including channels such as Amazon, Walmart, eBay, Etsy, TikTok Shop, Meta/Facebook/Instagram, Google, Pinterest, and comparable or successor platforms;
- customer-service communications, support tickets, surveys, reviews, testimonials, returns, refunds, safety complaints, fraud reviews, chargeback matters, shipping claims, and other post-sale interactions;
- email, phone, chat, social-media, SMS/MMS, and similar communications where permitted by law; and
- service providers, carriers, processors, marketplaces, analytics providers, advertising providers, fraud-prevention tools, hosting environments, ecommerce systems, security systems, and related business tools used to operate ZNF’s business.
3.1 Site features and customer programs
The Services may include or support, as available from time to time:
- product search, category browsing, health-concern browsing, recommendations, recently viewed products, wishlists, saved carts, and similar discovery features;
- customer registration, account authentication, saved addresses, order history, recurring deliveries, subscriptions, reorder tools, and account-management features;
- rewards points, loyalty programs, coupons, discount programs, referral or promotional offers, free-shipping offers, and other customer-benefit programs;
- product reviews, ratings, questions and answers, testimonials, images, video, surveys, feedback, and other user-submitted content;
- customer-support forms, email support, telephone support, chat, help-center tools, complaint handling, safety reporting, returns, and warranty or claim administration;
- retail checkout, wholesale and bulk quote requests, custom-blend and private-label inquiries, purchase orders, invoices, freight workflows, export documentation, and local-pickup coordination;
- newsletter, email, SMS/MMS, cart reminder, order update, review request, survey, and other communications governed additionally by the Mobile Terms and applicable consent disclosures;
- payment, digital-wallet, financing, fraud-screening, tax-calculation, carbon-offset, subscription, and similar transaction-support features; and
- embedded videos, social-media features, marketplace storefronts, analytics, advertising, accessibility-supporting tools, security controls, and integrations supplied by external providers.
3.2 External applications, platforms, and changing service configurations
ZNF uses external applications and service providers to operate portions of the Services. Depending on the feature, location, device, and configuration, these may include commerce and checkout platforms such as Shopify and UltraCart; payment and financing providers such as card networks, PayPal, and Affirm; analytics, tag-management, search, advertising, and audience providers such as Google and social-media platforms; marketplaces and social-commerce channels; email, SMS, chat, support, survey, review, loyalty, wishlist, and subscription providers; sustainability or carbon-offset providers such as EcoCart; content-delivery, hosting, security, fraud-prevention, and diagnostic providers; and carriers, shipping platforms, customs intermediaries, and logistics providers.
Third-party providers, features, and configurations change over time. A provider may act as ZNF's processor, service provider, contractor, independent controller, separate business, or a combination of roles depending on the activity and applicable law. More specific information about cookies, advertising technologies, opt-out controls, and third-party processing appears in the Cookie Policy, Digital Advertising & Analytics Policy, Your Privacy Choices Notice, U.S. State Privacy Addendum, International Privacy Addendum, and GDPR Notice.
4. Territorial Reach; U.S.-Centered Operations; No Overstatement of Foreign-Law Applicability
ZNF operates primarily from West Palm Beach, Florida, United States, serves many customers located in the United States, and is principally organized around U.S.-facing ecommerce, wholesale, shipping, pickup, and customer-service operations. ZNF may also sell or ship to customers outside the United States, including in Canada and other international destinations, and may use service providers, carriers, logistics counterparties, customs intermediaries, payment processors, and marketplaces operating across multiple jurisdictions.
Accordingly:
- this Privacy Policy is designed first and foremost to address ZNF’s baseline privacy disclosures and general information practices;
- where U.S. state law validly applies to a specific interaction, transaction, person, or processing activity, ZNF may address that circumstance through this Privacy Policy, the U.S. State Privacy Addendum, the Your Privacy Choices / Data Sharing Opt-out Notice, or another legally sufficient disclosure;
- where non-U.S. law validly applies to a specific interaction, transaction, person, or processing activity, ZNF may address that circumstance through this Privacy Policy, the International Privacy Addendum, the GDPR Statement / EEA-UK-Switzerland Privacy Notice, or another jurisdiction-specific notice;
- nothing in this Privacy Policy shall be construed as an admission that every state law or every foreign privacy law applies to every ZNF interaction, platform, shipment, user, or communication;
- to the fullest extent permitted by law, ZNF reserves all lawful defenses, exemptions, threshold arguments, jurisdictional objections, and scope limitations available under applicable law; and
- where a non-waivable law grants a user a right that cannot be contractually limited, nothing in this Privacy Policy or any other ZNF Legal Policy shall be construed to waive that right.
4.1 Florida-specific scope and independent Florida obligations
ZNF is based in Florida. Florida privacy and data-security statutes do not all use the same coverage test. As of the Last Updated date, the Florida Digital Bill of Rights, Fla. Stat. §§ 501.701–501.722, uses a narrow statutory definition of “controller” that includes specific revenue and business-model criteria. ZNF’s decision to provide privacy controls, respond to requests, recognize privacy signals where appropriate, or describe privacy rights in this Policy or the U.S. State Privacy Addendum does not by itself constitute an admission that ZNF satisfies that statutory controller definition, any revenue threshold, or any other coverage element.
If a provision of the Florida Digital Bill of Rights validly applies to ZNF and the processing at issue, the mandatory statutory requirement controls to the extent of any conflict and any non-waivable right remains preserved. If it does not apply, ZNF may still voluntarily provide similar choices without creating a statutory or contractual right broader than applicable law. Separate Florida requirements may apply independently of the Florida Digital Bill of Rights, including Florida’s security-of-confidential-personal-information and breach-notification requirements in Fla. Stat. § 501.171 and the Florida Deceptive and Unfair Trade Practices Act’s prohibition on unfair or deceptive practices in Fla. Stat. § 501.204.
4.2 U.S. federal privacy, security, and communications baseline
U.S. federal privacy law is largely sector- and activity-specific. ZNF intends its privacy and security representations to be accurate and not materially misleading and administers its practices with the Federal Trade Commission Act’s prohibition on unfair or deceptive practices in mind. Other federal requirements may apply to particular activities or audiences, including, where applicable, the Children’s Online Privacy Protection Act and Rule, the CAN-SPAM Act, the Telephone Consumer Protection Act and FCC rules, the FTC Health Breach Notification Rule, and other sector-specific statutes or regulations.
Listing a federal law in this Policy is not an admission that ZNF is a regulated entity, covered provider, financial institution, consumer-reporting agency, vendor of personal health records, or other specially regulated person under that law. Applicability depends on the statutory definitions, facts, activity, and exemptions. Where a federal requirement validly applies, ZNF will administer the covered activity in accordance with the non-waivable requirements that apply to it.
5. Categories of Personal Information We Collect
Depending on how you interact with ZNF, we may collect, receive, generate, infer, combine, retain, or otherwise process one or more of the following categories of personal information. Not every category applies to every person, transaction, channel, or platform.
5.1 Identifiers and contact information
We may collect identifiers and contact information such as:
- first and last name;
- billing address;
- shipping address;
- pickup contact information;
- email address;
- telephone number;
- company name;
- account identifier, customer number, quote number, invoice number, order number, subscription identifier, marketplace order identifier, or similar commercial identifier;
- username or login identifier where account functionality is offered; and
- other similar contact or identifying information reasonably necessary to provide the Services.
5.2 Account, order, transaction, and commercial information
We may collect information relating to your commercial relationship with ZNF, including:
- products viewed, quoted, ordered, subscribed to, returned, exchanged, exported, freighted, picked up, or otherwise requested;
- quantities, prices, discounts, promotions, credits, payment status, and related order metadata;
- order history, invoice history, quote history, subscription history, reorder history, claim history, and related transaction records;
- marketplace transaction details;
- local-pickup details, freight details, and shipping preferences;
- return, refund, replacement, chargeback, dispute, and issue-resolution history; and
- other records reasonably necessary to administer B2C, B2B, wholesale, freight, export, marketplace, subscription, and pickup transactions.
5.3 Payment and anti-fraud information
We may collect or receive limited payment-related and anti-fraud information, including:
- payment status;
- payment authorizations;
- processor tokens, references, or transaction identifiers;
- billing-related information;
- fraud-screening results;
- identity- or authority-verification information;
- chargeback-related information; and
- information reasonably necessary to prevent fraud, unauthorized transactions, abuse, misuse, or commercially unreasonable conduct.
Unless expressly stated otherwise in a specific ZNF notice or transaction flow, this Privacy Policy is not intended to state that ZNF stores full payment-card numbers, CVV/CVC values, or similar full payment credentials except where lawfully handled by authorized payment processors or otherwise permitted by applicable law and payment-industry requirements.
5.4 Shipping, pickup, customs, freight, and logistics information
Because ZNF ships domestic and international orders and also offers local pickup, we may collect information reasonably necessary to coordinate, verify, document, and administer shipping, pickup, customs, freight, and related logistics, including:
- consignee and recipient information;
- delivery instructions;
- shipping method, carrier, tracking, route, and status information;
- local-pickup scheduling and release details;
- signature, authorization, and pickup-verification information;
- customs, freight, export, import, brokerage, and other logistics-related details; and
- records necessary to investigate shipping disputes, carrier claims, loss, theft, tampering, misdelivery, or related operational issues.
5.5 Device, technical, browsing, and usage information
When you use our Services, we and our service providers may collect technical, device, browsing, and usage information, including:
- IP address;
- browser type;
- device identifiers;
- operating system;
- approximate geolocation inferred from IP or device/browser context;
- referral data;
- page views;
- session activity;
- interactions with site features;
- cookie, pixel, tag, SDK, local-storage, or similar technology data;
- diagnostic, performance, security, and anti-abuse information; and
- similar usage data associated with the operation, security, protection, and improvement of the Services.
Additional detail regarding cookies and similar technologies is provided in the Cookie Policy, Digital Advertising & Analytics Policy, and Your Privacy Choices / Data Sharing Opt-out Notice.
5.6 Communications, support, and relationship information
We may collect information contained in or generated through communications with ZNF, including:
- emails;
- phone calls and voicemails;
- chats;
- contact forms;
- SMS/MMS messages;
- review requests, survey responses, and support communications;
- complaint records;
- customer-service notes; and
- other correspondence records.
To the extent ZNF offers mobile-message programs, message categories, consent mechanics, revocation rules, and operational messaging rules are additionally governed by the Mobile Terms of Service.
5.7 Marketing, preference, consent, and engagement information
Where permitted by law, we may collect marketing, preference, and engagement information such as:
- email opt-in status;
- SMS opt-in status;
- consent and privacy-choice records;
- cookie-preference and GPC-related records where applicable;
- language or communication preferences;
- saved-cart or product-interest signals;
- campaign-engagement information;
- review participation;
- survey participation; and
- similar information relating to promotional preferences and engagement with ZNF communications.
5.8 Reviews, testimonials, surveys, and user-submitted content
We may collect information you submit in connection with:
- reviews;
- ratings;
- testimonials;
- survey responses;
- support uploads;
- images or attachments you choose to provide; and
- other user-submitted content or feedback.
Such content may also be governed by the Product Review Guidelines, Content Policy, Digital Advertising & Analytics Policy, or another more specific ZNF policy where applicable.
5.9 Business, wholesale, vendor, and counterparty information
In connection with B2B, wholesale, freight, export, supplier, marketplace, and similar business operations, we may collect:
- business contact information;
- company name;
- job title or role;
- tax, resale, import/export, customs, freight, or shipping-account information where reasonably necessary;
- quote and invoice information;
- business verification information; and
- related records necessary to administer commercial relationships and operational workflows.
5.10 Compliance, legal, safety, and evidentiary information
We may collect, preserve, or generate information reasonably necessary for:
- tax, accounting, and recordkeeping compliance;
- customs and trade compliance;
- sanctions screening;
- fraud prevention;
- chargeback defense;
- product-safety review;
- recall handling;
- shipment investigations;
- pickup verification;
- dispute resolution;
- litigation defense;
- regulatory response;
- incident response; and
- protection of ZNF’s rights, personnel, customers, service providers, facilities, systems, content, and operations.
5.11 Sensitive personal information and information we do not ordinarily require
For ordinary retail and wholesale ordering activity, ZNF does not intentionally request or require users to provide medical, health, biometric, genetic, religious, political, or similarly sensitive information, nor do we intentionally require friends’ data, family-relationship data, fitness data, or unrelated social-media permission data merely to browse, place an order, request a quote, or communicate with us in the ordinary course.
However, depending on context and lawful necessity, ZNF may process limited sensitive or specially regulated information where reasonably necessary to:
- verify a local pickup or prevent fraud;
- process payment or protect account security;
- comply with tax, customs, export, sanctions, or business-verification requirements;
- investigate a chargeback, tampering, contamination, shipping, fraud, or security incident;
- evaluate a safety complaint or legally relevant adverse event;
- respond to legal process or regulatory requests; or
- comply with another lawful and reasonably necessary business or legal requirement.
Accordingly:
- you should not submit Social Security numbers, driver’s-license numbers, passport numbers, medical information, biometric data, precise geolocation, or similar sensitive information unless ZNF specifically requests it for a lawful and limited purpose;
- if sensitive information is submitted without request, ZNF may delete, redact, restrict, segregate, suppress, preserve, or otherwise handle that information in accordance with applicable law and internal compliance needs; and
- nothing in this Privacy Policy should be interpreted as an admission that ZNF routinely collects all categories of “sensitive” data listed in the broadest possible statutory definitions.
State-specific and country-specific treatment of sensitive personal information, where applicable, may be further addressed in the U.S. State Privacy Addendum, International Privacy Addendum, GDPR Statement / EEA-UK-Switzerland Privacy Notice, and Your Privacy Choices / Data Sharing Opt-out Notice.
5.12 Facility, pickup, audiovisual, and security information
In connection with ZNF facilities, warehouse operations, shipping and receiving, local pickup, fraud prevention, product safety, and physical security, ZNF may process visitor records, pickup authorizations, signatures, vehicle or driver information, access records, delivery or release documentation, photographs, video-surveillance footage, and related security information. Telephone calls, chats, or support interactions may be monitored, transcribed, or recorded where permitted by law and where any notice or consent required by law is provided. Where Florida law governs an interception or recording, ZNF will administer the activity subject to applicable requirements of Chapter 934, Florida Statutes, including any consent requirement that validly applies. A statement that an interaction may be recorded does not mean that every interaction is recorded.
5.13 Consumer Health Data Privacy Notice
This subsection is ZNF's designated Consumer Health Data Privacy Notice. It is intended to address consumer health data laws, including Washington's My Health My Data Act, Nevada's consumer-health-data law, and analogous requirements, only to the extent such a law applies to ZNF and the processing at issue. It supplements the U.S. State Privacy Addendum and the Privacy Control Center / Your Privacy Choices.
ZNF sells foods, ingredients, botanicals, supplements, and related products; it is not acting as a healthcare provider through ordinary commerce. Ordinary ZNF records are generally not protected by HIPAA merely because they concern wellness interests. Nevertheless, broad state definitions may treat health-concern browsing, product searches or purchases, dietary preferences, survey responses, customer-support messages, safety or adverse-event reports, and inferences drawn from those activities as consumer health data.
Federal health-breach scope. This Consumer Health Data Privacy Notice does not state that ZNF is a HIPAA covered entity, business associate, vendor of personal health records, PHR-related entity, or other entity covered by the FTC Health Breach Notification Rule. If ZNF later offers or maintains a product, service, or record system that brings a particular activity within that Rule or another health-privacy law, ZNF will apply the legally required notice and breach-response duties to that covered activity.
Consumer health data categories, sources, and purposes
- Categories: health- or wellness-related browsing, searches, product interests, purchases, dietary preferences, voluntarily submitted health-related communications, safety or adverse-event information, and inferences that may identify a consumer's past, present, or future physical or mental health status.
- Sources: you; a person you authorize; your browser, device, or interactions with ZNF-controlled Services; order, account, support, review, survey, safety, and fraud systems; and service providers acting for ZNF.
- Purposes: to provide a product or service you request; administer orders, accounts, subscriptions, support, returns, recalls, and safety matters; prevent fraud and secure the Services; comply with law; establish or defend legal claims; and conduct analytics, personalization, or advertising only where the activity is lawful and any required consent has been obtained.
Consumer health data shared and recipients
Scrollable table: On smaller screens, this table can be scrolled horizontally. Keyboard users can focus the table region and use the browser's scrolling keys.
| Consumer health data category | Categories of recipients | Purpose and limitation |
|---|---|---|
| Health- or wellness-related product interests, browsing, searches, purchases, and associated identifiers | Commerce, hosting, account, search, subscription, payment, fulfillment, customer-support, security, and data-storage providers; advertising or analytics providers only where lawful and subject to any required consent | Provide requested commerce functions; maintain and secure the Services; support transactions; measure or personalize only as legally permitted |
| Dietary preferences, survey responses, support communications, and voluntarily submitted health information | Customer-support, communications, survey, review, quality, product-safety, legal, insurance, and secure-storage providers | Respond to the request; investigate safety or quality; comply with law; preserve or defend claims |
| Safety complaints, adverse-event information, recall records, and related evidence | Product-safety personnel and providers; manufacturers or suppliers; insurers, counsel, regulators, public-health or law-enforcement authorities; other recipients required or permitted by law | Safety review, adverse-event handling, recalls, regulatory reporting, investigation, and legal compliance |
| Consumer health data you direct us to disclose | The person or service you identify | Carry out your direction, subject to verification and applicable law |
Specific affiliates: As of the Last Updated date, ZNF has not identified a specific corporate affiliate in this Notice as routinely receiving consumer health data. Before beginning covered sharing with a specific affiliate, ZNF will update this Notice and obtain any affirmative consent required by applicable law.
Consent, sale, geofencing, and additional uses
Where required, ZNF will obtain affirmative consent before collecting or sharing consumer health data, except where collection or sharing is necessary to provide a product or service you requested or another statutory exception applies. ZNF will not collect, use, or share an additional category of consumer health data, or use consumer health data for an additional purpose, without first updating the disclosure and obtaining affirmative consent where required. ZNF will not sell consumer health data without a separate valid authorization that satisfies applicable law. ZNF does not use a geofence around an in-person healthcare service location to identify or track a consumer seeking or receiving healthcare where prohibited by law.
Your consumer health data rights
Depending on applicable law, you may have rights to confirm whether ZNF collects, shares, or sells consumer health data; access that data and certain recipient information; withdraw consent; and request deletion from ZNF and covered processors or other parties. Submit a request through the Privacy Control Center or email privacy@znaturalfoods.com with the subject Consumer Health Data Request. Verification, authorized-agent, appeal, exception, and response-timing rules are described in Sections 16 and 17 and the U.S. State Privacy Addendum.
Retention and security
ZNF retains consumer health data only for the period reasonably necessary for the disclosed purpose, subject to safety, recall, regulatory, legal, security, fraud-prevention, backup, and evidentiary requirements. Section 11 describes retention criteria and Section 12 describes safeguards. Please do not submit diagnosis, treatment, medication, genetic, biometric, or other sensitive health information unless it is reasonably necessary for a support or safety matter and you are authorized to provide it.
5.14 Artificial-intelligence, automated-processing, profiling, and decision-support information
ZNF and its providers may use automated or AI-enabled tools for functions such as fraud screening, account security, customer support, search, recommendations, personalization, analytics, moderation, translation, document handling, inventory or logistics support, and operational decision support. These tools may process transaction data, device and usage data, communications, prompts, responses, model outputs, risk indicators, or other information described in this Privacy Policy.
Nothing in this subsection means that every rules-based, fraud, recommendation, analytics, or security tool constitutes regulated profiling or automated decision-making. Where applicable law grants rights concerning a covered automated decision that produces legal or similarly significant effects, ZNF will provide the required pre-use notice, access, explanation, opt-out, appeal, or meaningful human-review mechanism and will conduct any required impact or risk assessment by the applicable compliance date. This includes future-scheduled requirements, such as California automated-decisionmaking obligations that apply to covered significant decisions beginning in 2027, only if ZNF and the activity are within scope.
5.15 Rewards, loyalty, wishlist, subscription, promotion, and financial-incentive information
When you participate in a rewards, loyalty, subscription, autoship, wishlist, coupon, referral, sweepstakes, discount, or similar program, ZNF may process enrollment details, account and transaction history, points, rewards, referrals, preferences, engagement, eligibility, redemption history, and related program information. Additional program terms or a notice of financial incentive may apply where required by law.
6. Sources of Personal Information
ZNF may collect personal information from one or more of the following sources:
6.1 Directly from you
We may collect information directly from you when you:
- browse or use our Services;
- place an order;
- request a quote;
- create or use an account;
- sign up for email or SMS communications;
- contact customer support;
- submit a review or survey;
- schedule a pickup;
- provide shipping or billing information;
- participate in a marketplace or social-commerce transaction involving ZNF; or
- otherwise communicate or transact with us.
6.2 From your device, browser, and interactions with the Services
We may automatically collect information from your device, browser, cookies, pixels, logs, and interactions with our websites, communications, storefronts, checkout flows, and related tools, subject to applicable law and the Cookie Policy.
6.3 From service providers and business systems
We may receive information from service providers that support our business, including, as applicable:
- payment processors;
- ecommerce platforms;
- fraud-prevention vendors;
- hosting and cloud providers;
- analytics or advertising vendors;
- communications providers;
- review or survey tools;
- customer-service systems;
- shipping or logistics tools; and
- other business-service providers engaged by or on behalf of ZNF.
6.4 From carriers, freight providers, customs intermediaries, and logistics counterparties
Because ZNF ships through carriers and may coordinate freight, customs, pickup, and international delivery workflows, we may receive information from carriers and logistics counterparties such as USPS, UPS, FedEx, DHL, LTL or freight providers, customs brokers, pickup coordinators, or similar intermediaries where reasonably necessary to administer transactions or investigate operational issues.
6.5 From business customers, authorized representatives, resellers, or counterparties
In B2B, wholesale, export, freight, or account-based transactions, we may receive information from:
- employers;
- purchasing agents;
- authorized representatives;
- freight coordinators;
- resellers;
- consignee contacts; or
- other persons acting on behalf of a business customer or counterparty.
6.6 From marketplaces, platforms, and third-party sales channels
Where ZNF sells through third-party marketplaces or social-commerce channels, we may receive order, fulfillment, customer-service, messaging, dispute-related, and performance-related information from those platforms to the extent permitted by law and platform rules.
6.7 From publicly available or lawfully obtainable sources
Where reasonably necessary for compliance, verification, fraud prevention, legal defense, security, or business administration, we may obtain information from:
- public records;
- government sources;
- public business listings;
- sanctions or compliance databases;
- carrier or customs sources; and
- other lawfully available information sources.
6.8 From advertising, analytics, social, identity, and referral partners
Where permitted by law, ZNF may receive campaign, referral, attribution, audience, conversion, social-engagement, authentication, or similar information from advertising providers, analytics providers, search engines, social networks, affiliates, referral sources, identity or login providers, and platforms with which you interact.
6.9 Information about other people that you provide
You may provide information about another person, such as a gift recipient, consignee, pickup representative, employee, purchasing contact, freight contact, or authorized agent. By doing so, you represent that you are authorized to provide the information and, where required, that you have given the person any legally required notice or obtained any legally required consent. Do not provide another person's sensitive information unless it is necessary and lawful.
6.10 Anonymous or pseudonymous interaction
You may generally browse public portions of the Services without creating an account or directly identifying yourself. Certain transactions and features—such as purchasing, shipping, pickup, subscriptions, reviews, quotes, support, privacy requests, fraud verification, and legal compliance—require accurate identifying or contact information. ZNF may permit a display name or pseudonym for a public-facing feature, but may retain account or verification information privately where lawful and reasonably necessary.
7. Purposes for Which We Use Personal Information
ZNF may use personal information for one or more of the following purposes, subject to applicable law:
7.1 To provide, operate, and administer the Services
Including to:
- operate our websites, storefronts, checkout flows, and related systems;
- create and manage accounts;
- process, fulfill, ship, deliver, export, or make available for pickup orders;
- administer subscriptions, pre-orders, quotes, invoices, and wholesale accounts;
- manage marketplace transactions; and
- provide customer-facing functionality.
7.2 To process payments, reduce fraud, and protect transaction integrity
Including to:
- obtain payment authorization;
- coordinate with payment processors;
- detect and prevent fraud, abuse, chargebacks, account misuse, credential misuse, or unauthorized transactions;
- verify identity or authority where appropriate; and
- support lawful security and anti-abuse controls.
7.3 To coordinate shipping, pickup, freight, customs, and related logistics
Including to:
- generate labels or shipment records;
- coordinate delivery and tracking;
- verify pickup authorization;
- administer freight and export workflows;
- support customs and import/export documentation; and
- investigate shipping, pickup, freight, tampering, theft, delay, loss, or delivery issues.
7.4 To communicate with you
Including to:
- send order confirmations;
- send order-status and shipping updates;
- provide pickup instructions;
- respond to support requests;
- send product-safety, recall, fraud, security, account, legal, or service-related notices; and
- where permitted, send marketing communications.
Where applicable, message categories, consent, revocation, and operational messaging rules are additionally governed by the Mobile Terms of Service.
7.5 To manage customer service, surveys, reviews, and relationship history
Including to:
- respond to questions, complaints, and requests;
- administer reviews, surveys, and quality-assurance interactions;
- maintain support history and dispute records;
- improve service workflows; and
- manage ongoing customer relationships.
7.6 To improve, maintain, troubleshoot, and secure the Services
Including to:
- monitor system performance;
- diagnose errors;
- improve functionality and conversion pathways;
- support security, logging, monitoring, and incident response;
- protect against scraping, bots, spoofing, abuse, phishing, malware, unauthorized automation, or other malicious activity; and
- maintain operational continuity.
These activities should also be read together with the Information Security Policy & Responsible Vulnerability Disclosure Policy and the Agent Terms & Automated Access / Bot Policy.
7.7 To conduct analytics, attribution, personalization, and advertising-related activities
Including, where permitted by law, to:
- understand traffic and user interaction;
- measure campaign performance;
- refine merchandising or audience segments;
- support remarketing, retargeting, or similar advertising practices;
- personalize certain site experiences or offers; and
- preserve privacy choices and consent records.
These activities are further described in the Cookie Policy, Digital Advertising & Analytics Policy, and Your Privacy Choices / Data Sharing Opt-out Notice, and, where applicable, the U.S. State Privacy Addendum.
7.8 To comply with law and protect legal rights
Including to:
- comply with tax, accounting, customs, sanctions, shipping, consumer-protection, privacy, security, intellectual-property, and recordkeeping obligations;
- respond to legal process, law-enforcement requests, regulators, courts, or administrative authorities;
- investigate claims, complaints, abuse, disputes, product-safety matters, returns, chargebacks, shipping claims, or copyright-related matters;
- preserve evidence;
- enforce the Terms of Use and other ZNF Legal Policies; and
- protect ZNF, its personnel, service providers, customers, products, facilities, content, systems, and operations.
7.9 For business administration and corporate transactions
Including to:
- conduct internal reporting, auditing, and recordkeeping;
- manage vendor and service-provider relationships;
- maintain insurance, compliance, and advisory relationships; and
- evaluate or complete an actual or proposed merger, financing, acquisition, restructuring, bankruptcy-related administration, or sale of assets, subject to appropriate confidentiality and legal safeguards.
7.10 To administer rewards, loyalty, subscription, wishlist, and promotional programs
Including to enroll participants, maintain points or rewards, administer referrals, remember saved products, operate autoship or recurring deliveries, deliver coupons or offers, prevent program abuse, evaluate eligibility, and comply with program-specific disclosures.
7.11 To use AI-enabled and automated tools responsibly
Including to support customer service, search, recommendations, translation, moderation, fraud detection, account security, inventory, logistics, analytics, and other operational functions. ZNF may review, override, restrict, or discontinue automated outputs and does not warrant that any automated output is complete, error-free, or suitable for independent reliance.
7.12 To address product safety, adverse events, and consumer-health-data obligations
Including to investigate safety complaints, adverse events, recalls, contamination or tampering concerns, interactions reported by customers, product misuse, regulatory reports, and other health- or safety-related matters; to preserve evidence; and to comply with consumer-health-data, product-safety, food, supplement, and regulatory obligations where applicable.
7.13 To create and use aggregated, statistical, or deidentified information
ZNF may aggregate, anonymize, or deidentify information for analytics, research, forecasting, security, product improvement, and other lawful purposes. Where applicable law requires, ZNF will take reasonable measures to prevent association of deidentified information with an individual, maintain it in deidentified form, and not attempt reidentification except as permitted by law.
8. Legal and Operational Bases for Processing
Because ZNF operates primarily in the United States but may also interact with persons in other jurisdictions, the legal basis for processing may depend on the user’s location, the channel involved, the nature of the transaction, and applicable law.
To the fullest extent permitted by law, ZNF may process personal information where one or more of the following grounds or compliance bases applies:
8.1 Contractual necessity and requested transactions
We may process information where reasonably necessary to:
- enter into or perform a transaction or contract with you;
- process and fulfill an order;
- administer an account, subscription, quote, or invoice;
- coordinate shipping, freight, export, customs, or pickup; or
- otherwise provide the goods, services, or support you request.
8.2 Compliance with legal obligations
We may process information where reasonably necessary to comply with legal, regulatory, tax, accounting, customs, sanctions, consumer-protection, shipping, recall, privacy, security, intellectual-property, or recordkeeping obligations.
8.3 Legitimate business and operational interests
Subject to applicable law, we may process information where reasonably necessary for legitimate business purposes, including:
- operating and improving the Services;
- administering business workflows;
- maintaining security and fraud controls;
- preserving evidence;
- preventing abuse;
- defending claims;
- enforcing contracts;
- managing logistics and service providers; and
- conducting proportionate marketing or customer-relationship activities not overridden by a person’s rights.
8.4 Consent or permission where required
We may rely on consent or permission where applicable law requires or favors it, including, where relevant:
- certain direct-marketing emails or SMS messages;
- certain non-essential cookies, pixels, tags, or similar technologies;
- certain review, survey, or promotional interactions; and
- other processing activities for which consent is the lawful standard.
Where processing is based on consent, you may withdraw consent using the legally available mechanism for that interaction. Withdrawal does not affect processing that was lawful before withdrawal.
8.5 Security, fraud-prevention, safety, and vital-interest circumstances
We may process information where reasonably necessary to:
- protect account integrity;
- investigate security events;
- prevent fraud or unauthorized access;
- address product-safety or recall issues; or
- protect the vital interests, safety, or rights of a natural person or of ZNF where the law permits such processing.
8.6 Jurisdiction-specific lawful-basis frameworks
For users located in jurisdictions that recognize formal lawful-basis frameworks, including jurisdictions outside the United States, this Privacy Policy should be read together with the International Privacy Addendum and, where applicable, the GDPR Statement / EEA-UK-Switzerland Privacy Notice, which provide more specific discussions of legally recognized bases for processing.
8.7 Risk assessments, data-protection assessments, and purpose compatibility
Where required by applicable law, ZNF may evaluate processing activities through privacy, security, consumer-health-data, AI, automated-decision, or data-protection assessments. ZNF may also assess whether a new use is compatible with the purpose for which information was collected and may seek additional consent or provide additional notice where required. Assessments, privileged analyses, security materials, and internal compliance records are not public unless applicable law requires disclosure.
8.8 Data minimization, purpose limitation, and secondary use
ZNF seeks to collect and process personal information that is reasonably adequate, relevant, and necessary for disclosed and lawful purposes. Where applicable law imposes a stricter rule, including a requirement that sensitive data be limited to what is strictly necessary, that rule controls. ZNF will not materially expand a collection category or use information for an incompatible new purpose without an updated disclosure, consent, or other lawful basis where required.
9. How We Disclose Personal Information
ZNF does not disclose personal information to every category of recipient in every circumstance. Depending on the channel involved, the transaction at issue, the role ZNF plays in the relevant interaction, and applicable law, we may disclose personal information to one or more of the following categories of recipients for the purposes described in this Privacy Policy.
9.1 Service providers, processors, contractors, and business vendors
We may disclose personal information to service providers, processors, contractors, and vendors that perform services on behalf of ZNF or support ZNF’s operations, including, where applicable:
- ecommerce and checkout providers;
- payment processors and payment-service providers;
- fraud-prevention, identity-verification, and chargeback-management vendors;
- hosting, cloud, CDN, infrastructure, and business-software providers;
- security, logging, monitoring, and incident-response providers;
- analytics, attribution, advertising, and consent-management vendors;
- customer-service, chat, review, survey, communications, CRM, or marketing-platform providers;
- shipping, label, freight, customs, pickup, warehouse, or logistics tools; and
- legal, accounting, tax, compliance, audit, insurance, or advisory support providers.
Where applicable, ZNF intends these recipients to act under contractual, operational, or legal restrictions appropriate to the role they perform.
9.2 Carriers, freight providers, customs intermediaries, and logistics counterparties
Because ZNF ships domestic and international orders and offers local pickup, we may disclose personal information reasonably necessary to administer shipping, delivery, pickup, freight, customs, and related logistics to carriers and logistics counterparties, including providers such as:
- FedEx;
- USPS;
- UPS;
- DHL;
- LTL or freight providers;
- freight brokers;
- customs brokers;
- pickup coordinators; and
- similar transportation or logistics intermediaries.
These disclosures may include recipient details, shipping details, order identifiers, delivery status, pickup authorization details, customs-related information, and other information reasonably necessary to transport, deliver, release, trace, investigate, or document an order or logistics event.
9.3 Payment processors and payment-service providers
ZNF may disclose billing information, payment-related information, fraud-screening data, order details, and related identifiers to payment processors and payment-service providers to authorize, process, verify, settle, secure, or investigate transactions.
9.4 Marketplaces, social-commerce channels, and third-party platforms
If you interact with ZNF through a marketplace, advertising platform, social-commerce channel, or similar third-party environment, ZNF may disclose or receive personal information to or from that platform to the extent reasonably necessary to:
- process or fulfill transactions;
- administer customer service or messaging;
- manage disputes, refunds, fraud issues, chargebacks, or claims;
- support reviews, feedback, or moderation;
- measure advertising or storefront performance; or
- otherwise conduct platform-related operations.
Depending on the platform and context, ZNF may act as the seller, merchant of record, fulfillment party, content source, or other participant, and the platform may separately collect or process information under its own terms and privacy practices. Nothing in this Privacy Policy is intended to state that ZNF controls all personal-information processing performed by third-party marketplaces, social networks, browsers, device ecosystems, or payment platforms.
9.5 Analytics, advertising, attribution, and consent-management recipients
Where permitted by law, ZNF may disclose device, browsing, cookie, marketing, audience, and related interaction data to analytics, advertising, attribution, and consent-management providers to support:
- traffic measurement;
- conversion tracking;
- audience creation or suppression;
- remarketing or retargeting;
- campaign optimization;
- privacy-choice preservation; and
- related digital-advertising or analytics functions.
Additional information about these activities is provided in the Cookie Policy, Digital Advertising & Analytics Policy, and Your Privacy Choices / Data Sharing Opt-out Notice.
9.6 Affiliates, advisors, insurers, and professional counterparties
ZNF may disclose personal information to affiliates, advisors, insurers, auditors, attorneys, accountants, lenders, investors, or similar professional counterparties where reasonably necessary for business administration, risk management, insurance, compliance, corporate governance, audit support, financing, or legal defense.
9.7 Legal, regulatory, law-enforcement, and protection-related disclosures
ZNF may disclose personal information where reasonably necessary to:
- comply with applicable law, regulation, legal process, subpoena, court order, or governmental request;
- respond to law-enforcement, customs, sanctions, tax, consumer-protection, privacy, security, or other regulatory authorities;
- protect ZNF’s rights, property, personnel, customers, service providers, facilities, content, systems, or operations;
- investigate fraud, abuse, security incidents, product tampering, shipping disputes, returns disputes, chargebacks, copyright complaints, or legal claims;
- preserve evidence; or
- enforce the Terms of Use or another ZNF Legal Policy.
9.8 Corporate transactions and changes of control
ZNF may disclose personal information as part of an actual or proposed merger, acquisition, financing, restructuring, bankruptcy administration, sale of assets, or similar transaction, subject to appropriate confidentiality and legal safeguards.
9.9 At your direction or with your intentional interaction
ZNF may disclose personal information where you direct us to do so, intentionally interact with a third-party feature, request a specific disclosure, authorize a representative, or otherwise instruct us to disclose information in a manner permitted by law.
9.10 External applications and service-provider categories
The following table summarizes service categories that may process personal information in connection with the Services. The table is illustrative rather than a representation that every named example is active for every user, page, or transaction.
Scrollable table: On smaller screens, this table can be scrolled horizontally. Keyboard users can focus the table region and use the browser's scrolling keys.
| Service category | Examples or functions | Typical information |
|---|---|---|
| Commerce and checkout | Shopify, UltraCart, storefront, cart, checkout, account, subscription, and order-management tools | Identifiers, contact, cart, order, account, device, and transaction information |
| Payments and financing | Card networks, payment gateways, PayPal, Affirm, fraud and payment-verification providers | Billing, transaction, token, authorization, fraud, and financing-application information handled under the provider's terms |
| Analytics, tags, and advertising | Google Tag Manager, analytics and advertising platforms, Meta, TikTok, Pinterest, and comparable providers | Device, browser, cookie, event, conversion, audience, attribution, and engagement information |
| Communications and customer relationship tools | Email, SMS/MMS, CRM, forms, chat, help-center, survey, and customer-support providers | Contact details, consent, communication history, support content, preferences, and engagement |
| Reviews and user content | Review widgets, ratings, Q&A, testimonials, image/video upload, moderation, and verification providers | Display name, review content, order verification, media, device, and moderation information |
| Rewards, wishlists, subscriptions, and promotions | Points, loyalty, referral, coupon, saved-product, recurring-delivery, and promotion tools | Account, purchase history, preferences, points, eligibility, redemption, and engagement data |
| Marketplaces and social commerce | Amazon, Walmart, eBay, Etsy, TikTok Shop, Meta/Facebook/Instagram, Google, Pinterest, and comparable platforms | Orders, messages, fulfillment, disputes, reviews, platform identifiers, and advertising data |
| Shipping, customs, and logistics | FedEx, USPS, UPS, DHL, shipping software, freight providers, brokers, warehouses, and customs intermediaries | Recipient, address, contact, order, customs, tracking, signature, pickup, and claim information |
| Infrastructure, security, and diagnostics | Hosting, CDN, DNS, firewall, bot-management, fraud, logging, monitoring, error-reporting, and backup providers | IP address, device, network, log, authentication, security-event, diagnostic, and account data |
| Embedded content and social features | Video, social buttons, feeds, media, maps, widgets, and external content providers | Device, browser, usage, cookie, account, and interaction information subject to provider settings |
| Sustainability and optional transaction features | EcoCart or similar carbon-offset and optional checkout services | Order, transaction, selection, and related device or attribution information |
Each provider may change its products, corporate identity, sub-processors, and privacy practices. ZNF may add, replace, suspend, or remove providers as business, security, legal, or technical needs change. Material changes to ZNF's own processing will be reflected in this Privacy Policy or an applicable notice as required by law.
10. Sale, Sharing, Targeted Advertising, and Privacy Choices
10.1 Operational disclosures and regulated advertising disclosures
Certain privacy laws define “sale,” “sharing,” “targeted advertising,” “cross-context behavioral advertising,” or similar terms broadly. ZNF does not treat every disclosure of personal information to a third party as falling into those categories. Many disclosures are operational and are intended to support activities such as payment processing, order administration, shipping, pickup, fraud prevention, security, customer service, analytics performed on ZNF’s behalf, hosting, storage, and similar business purposes.
However, where ZNF uses cookies, pixels, tags, SDKs, or similar technologies for audience-building, remarketing, retargeting, attribution, campaign measurement, personalization, or cross-context behavioral advertising, some resulting disclosures may, depending on the facts and applicable law, be treated as a sale, sharing, targeted advertising, or similar regulated activity.
For additional information about how ZNF interprets and offers choices with respect to those activities, please review:
- the Cookie Policy;
- the Digital Advertising & Analytics Policy;
- the Your Privacy Choices / Data Sharing Opt-out Notice; and
- where applicable, the U.S. State Privacy Addendum.
Where required by applicable law, ZNF will process recognized browser-based opt-out signals, including Global Privacy Control (“GPC”), as requests to opt out of covered sale or sharing activity for the browser or device that transmitted the signal, subject to the technical, browser-, device-, account-, and context-specific limitations described in the Your Privacy Choices / Data Sharing Opt-out Notice and the Cookie Policy.
10.2 Your Privacy Choices and recognized preference signals
Where applicable law provides a right to opt out of sale, sharing, targeted advertising, cross-context behavioral advertising, or qualifying profiling, you may use ZNF's Your Privacy Choices controls, cookie preference interface, designated request methods, or a legally recognized universal opt-out signal. ZNF will process a valid Global Privacy Control or successor signal as required by applicable law and as described in the Your Privacy Choices Notice.
A browser- or device-level signal usually applies only to the browser, device, profile, or context that transmits it. ZNF may apply a signal to an identifiable account when required by law and technically feasible. Necessary processing for security, fraud prevention, transaction completion, preference storage, legal compliance, recalls, and other permitted purposes may continue.
10.3 Legacy “Do Not Track” signals
Some browsers transmit legacy “Do Not Track” signals that are not standardized and may not communicate a legally recognized choice. Unless applicable law requires otherwise, ZNF does not treat a legacy Do Not Track signal as a substitute for the controls described in the Your Privacy Choices Notice. ZNF does, however, honor legally recognized signals such as GPC where required.
10.4 Sensitive personal information and consumer health data
A general advertising opt-out does not replace any separate consent, express consent, authorization, or deletion mechanism required for sensitive personal information or consumer health data. Section 5.13 of this Privacy Policy is ZNF's designated Consumer Health Data Privacy Notice. Use the Privacy Rights Request method in the Privacy Control Center / Your Privacy Choices for an applicable sensitive-data or consumer-health-data request.
10.5 Marketing communications
Cookie and advertising choices do not automatically unsubscribe you from email, SMS/MMS, or other direct-marketing programs. Use the unsubscribe link in a marketing email, reply with a recognized revocation term to a covered marketing text, use an available marketing-preference center, or contact ZNF. Transactional, safety, account, security, order, shipping, pickup, legal, or other non-marketing communications may continue where permitted by law.
10.6 Loyalty programs, discounts, individualized pricing, and notices of financial incentive
ZNF may offer rewards, discounts, coupons, referrals, subscriptions, free shipping, or other programs that involve personal information. Where applicable law characterizes a program as a financial incentive or price or service difference, ZNF may provide a separate notice describing the material terms, the categories of personal information involved, how the value of the information is reasonably related to the benefit, and how to opt in or withdraw. Participation is voluntary and subject to program terms. ZNF will not use sensitive personal information or consumer health data to set or increase an individualized price in a manner prohibited by law. Any covered personalized-pricing practice will be subject to the disclosure, consent, and substantive limits required by applicable law.
11. How Long We Retain Personal Information
ZNF retains personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law, contract, evidentiary need, safety need, or operational necessity.
Retention periods may vary based on factors such as:
- whether the information is needed to complete or administer a transaction;
- whether the information relates to an account, quote, subscription, return, pickup, shipping event, freight matter, customs issue, safety issue, or dispute;
- whether ZNF must retain records for tax, accounting, legal, regulatory, customs, sanctions, shipping, consumer-protection, intellectual-property, or recordkeeping purposes;
- whether the information is needed for fraud prevention, chargeback defense, evidence preservation, recall handling, tampering investigation, abuse prevention, or security review;
- whether the information is subject to a litigation hold, legal process, internal investigation, or regulatory inquiry;
- the sensitivity of the information; and
- whether retention remains reasonably necessary and proportionate to the context in which the information was collected.
11.1 Category-specific retention criteria
The following criteria describe the intended retention period for each principal category. A shorter or longer period may apply where required or permitted by law, or where a legal hold, safety matter, recall, fraud investigation, dispute, security incident, contract, or similar necessity applies.
Scrollable table: On smaller screens, this table can be scrolled horizontally. Keyboard users can focus the table region and use the browser's scrolling keys.
| Category | Retention criterion |
|---|---|
| Identifiers, contact details, accounts, and customer relationships | For the account or relationship lifecycle and thereafter only as needed for transactions, support, security, suppression, tax, claims, or legal compliance. |
| Orders, payments, commercial, shipping, pickup, customs, and freight records | For transaction completion and the applicable tax, accounting, chargeback, warranty, recall, customs, limitation, audit, and recordkeeping periods. |
| Device, browsing, cookie, analytics, advertising, and diagnostic data | For the cookie, log, campaign, security, or vendor-configured duration described in the Cookie Policy, then deleted, aggregated, or deidentified unless needed for security, consent proof, or legal compliance. |
| Communications, support, complaints, reviews, surveys, and user content | Until the interaction or publication purpose is complete and thereafter for quality, moderation, dispute, safety, evidentiary, or legal needs; public content may remain until removed or the feature is retired. |
| Marketing, consent, opt-out, loyalty, wishlist, subscription, and preference records | While the program, preference, or consent remains active and thereafter as needed to honor withdrawals, suppress future contact, demonstrate compliance, resolve disputes, or prevent fraud. |
| Business, wholesale, vendor, and counterparty records | For the commercial relationship and the applicable contract, tax, accounting, trade, claims, audit, and limitation periods. |
| Security, fraud, abuse, legal, regulatory, and evidentiary records | For the investigation, enforcement, audit, legal-hold, limitation, regulatory, or security lifecycle and any period reasonably necessary to prevent recurrence or defend rights. |
| Sensitive personal information and consumer health data | Only for the limited disclosed purpose and as short as reasonably practical, subject to consent withdrawal, deletion rights, safety, recall, fraud, legal, regulatory, backup, and evidentiary requirements. |
| Facility, pickup, call, chat, photograph, audio, and video records | For the shortest practical operational or security period, extended only when connected to a pickup, transaction, incident, complaint, investigation, consent record, or legal requirement. |
When personal information is no longer reasonably necessary for the relevant purpose, ZNF may delete it, deidentify or anonymize it where appropriate, aggregate it, or retain it in a restricted archival form where lawful and reasonably necessary for compliance, security, evidentiary preservation, recall support, or defense of rights.
Additional jurisdiction-specific retention disclosure, where required, may be provided in the U.S. State Privacy Addendum, International Privacy Addendum, or GDPR Statement / EEA-UK-Switzerland Privacy Notice.
11.2 Suppression, consent, preference, and compliance records
ZNF may retain limited records of consent, withdrawal, opt-out, suppression, request completion, identity verification, complaint handling, and related compliance events for as long as reasonably necessary to honor choices, prevent re-enrollment, demonstrate compliance, prevent fraud, and defend legal claims.
11.3 Backups, archives, and legal holds
Deletion from active systems may not result in immediate deletion from backups, disaster-recovery systems, immutable logs, or restricted archives. Information may remain until the applicable system is overwritten or retired, subject to access restrictions and no further active use except for restoration, security, legal compliance, or defense of rights. Litigation holds, regulatory preservation duties, recalls, safety matters, and other legal obligations may extend retention.
12. Data Security and Safeguards
ZNF maintains and may modify from time to time a commercially reasonable, risk-based information-security program designed to protect personal information, systems, records, content, facilities, and operations against unauthorized access, disclosure, misuse, alteration, destruction, fraud, abuse, tampering, or other compromise.
Depending on the context, such safeguards may include administrative, technical, physical, contractual, and procedural controls such as:
- role-based access limitations;
- credential and authentication controls;
- payment and fraud safeguards;
- monitoring, logging, and alerting;
- vendor and service-provider controls;
- patching and maintenance;
- backup and recovery measures;
- secure transmission methods where commercially reasonable;
- pickup verification procedures;
- shipping and logistics controls;
- anti-bot, anti-scraping, anti-abuse, and anti-spoofing controls;
- evidence-preservation and incident-escalation procedures; and
- other reasonable controls appropriate to the nature, volume, sensitivity, and business use of the information.
ZNF may rely on third-party service providers, processors, platforms, marketplaces, carriers, infrastructure vendors, payment providers, and other counterparties for portions of its security program. Nothing in this Privacy Policy shall be construed as a representation that any particular safeguard is always in place, always available, or always effective in every context.
Notwithstanding the foregoing, no data-security program, transmission method, storage environment, carrier network, third-party platform, or external system can be guaranteed to be completely secure, uninterrupted, or immune from all threats, and ZNF does not make any warranty of absolute security.
12.1 Working together to protect accounts and communications
Security works best when we work together. We ask you to use reasonable care to protect account credentials, devices, one-time codes, and communications; provide accurate information; promptly tell ZNF if you suspect unauthorized access; and avoid sending sensitive information through insecure or unintended channels. To the fullest extent permitted by law, ZNF is not responsible to the extent a compromise results solely from a user's failure to use reasonable safeguards. Nothing in this paragraph limits any non-waivable right or duty imposed by applicable law.
12.2 Service-provider and platform security
ZNF may require or seek contractual, technical, or organizational safeguards from providers where appropriate. Nevertheless, third-party systems remain subject to independent risks, outages, vulnerabilities, and legal obligations. No contractual or technical control eliminates all risk.
12.3 Privacy governance, assessments, and provider oversight
Where required by applicable law, ZNF will conduct and document data-protection, privacy-risk, cybersecurity, consumer-health-data, or automated-decisionmaking assessments before or during covered higher-risk processing; maintain required records or certifications; and use contracts or other controls appropriate to the role of a processor, service provider, contractor, or third party. These are operational obligations and are not satisfied by policy language alone.
13. Security Incidents and Breach Response
If ZNF becomes aware of a suspected or actual security incident, breach, misuse event, or other compromise, we may take the steps we reasonably determine are appropriate to protect affected people, ZNF, and the integrity of our Services, including, without limitation:
- investigating and containing the issue;
- engaging internal personnel, service providers, insurers, counsel, forensic specialists, or other responders;
- preserving logs, records, communications, and evidence;
- suspending or restricting affected systems, workflows, or access;
- coordinating with carriers, payment processors, marketplaces, customs intermediaries, service providers, law enforcement, or other relevant counterparties;
- taking corrective, mitigating, or protective action; and
- providing notice to affected persons, regulators, or authorities where required by applicable law.
To the extent Fla. Stat. § 501.171 applies to an incident, ZNF will administer the covered response in accordance with that statute, including its requirements concerning reasonable protection of personal information; notice to the Florida Department of Legal Affairs when the statutory threshold is met; notice to affected Florida individuals without unreasonable delay and within the statutory period; and any available law-enforcement delay, waiver, substitute-notice, extension, recordkeeping, or other statutory provision. This summary is not intended to expand the statute or waive any exception or defense available under it.
If the FTC Health Breach Notification Rule or another federal or state health-data breach rule applies to a particular ZNF activity, ZNF will provide the notices required for that covered activity. Nothing in this Section is an admission that every incident, dataset, or ZNF service is governed by such a rule.
Nothing in this Privacy Policy obligates ZNF to publicly disclose information that would itself compromise security, reveal proprietary information, disclose trade secrets, prejudice an active investigation, or otherwise create avoidable legal or operational risk, except to the extent required by applicable law.
14. Children, Minors, and Age-Related Privacy
14.1 General-audience services; not directed to children under 13
ZNF’s Services are intended for a general audience and are not directed to children under 13 years of age. ZNF does not knowingly collect personal information online from a child under 13 without providing the notice and obtaining the verifiable parental consent required by applicable law. If COPPA applies, ZNF will also obtain any separate parental consent required before covered disclosure to a third party for targeted advertising or another non-integral purpose, limit retention to what is reasonably necessary, and provide legally required parental access and deletion controls. For any ZNF service that becomes subject to COPPA, ZNF will maintain the written child-data retention and information-security measures required by the Rule, including purpose-specific retention limits, secure deletion, and legally required safeguards or written assurances applicable to service providers or third parties.
14.2 If we learn we collected data from a child under 13 or another protected minor category in a manner requiring special handling
If ZNF learns that it collected personal information from a child under 13, or from another protected minor category in circumstances requiring special handling under applicable law, ZNF may delete, restrict, suppress, segregate, preserve, or otherwise remediate the information and take any additional action reasonably necessary to comply with law, protect the child, and reduce legal or operational risk.
14.3 Minors above 13; purchases and use of Services
ZNF products and Services are generally intended to be ordered and used by adults or by persons acting with lawful authority. To the fullest extent permitted by law, if you are under the age of majority in your jurisdiction, you should use the Services only with the involvement, supervision, and approval of a parent, guardian, or other legally authorized adult. Nothing in this Privacy Policy alters any product-, checkout-, payment-, shipping-, pickup-, or contract-capacity terms contained elsewhere in the ZNF Legal Policies.
14.4 State- or country-specific minor protections
Where applicable state law or non-U.S. law imposes special rules concerning children, teens, or sensitive data of minors, those requirements may be further addressed in the U.S. State Privacy Addendum, the International Privacy Addendum, the GDPR Statement / EEA-UK-Switzerland Privacy Notice, or another applicable notice.
14.5 Teen privacy and age thresholds above 13
Some jurisdictions provide heightened protections to teenagers or define a child as a person under 16, under 18, or another age. Where applicable, ZNF will obtain any consent or authorization required for covered sale, sharing, targeted advertising, profiling, sensitive-data processing, or other regulated activity involving a minor. ZNF does not knowingly use a minor's personal information in a manner prohibited by applicable law.
14.6 Parental and guardian requests
A parent, guardian, or other legally authorized representative may submit a request concerning a child through the privacy-request methods described below. ZNF may verify the adult's identity, authority, and relationship to the child and may decline to disclose information where verification is insufficient or disclosure could create a safety, security, or privacy risk.
15. International Transfers and Cross-Border Processing
ZNF is headquartered and operates primarily in the United States, including from West Palm Beach, Florida, but may sell or ship products internationally, including to Canada and other non-U.S. destinations, and may use service providers, carriers, customs intermediaries, marketplaces, payment processors, or technical providers located in or operating from multiple countries.
Accordingly, personal information may be processed in the United States and in other jurisdictions where ZNF, its service providers, carriers, customs brokers, payment processors, marketplaces, or other counterparties operate. If you are located outside the United States, your information may be transferred to, stored in, or accessed from a jurisdiction that may not provide the same level of legal protection as your home jurisdiction.
Where non-U.S. law validly applies, additional information may be provided in the International Privacy Addendum and, where applicable, the GDPR Statement / EEA-UK-Switzerland Privacy Notice. Those documents are intended to supplement, not replace, this Privacy Policy.
Depending on territorial scope and the processing at issue, the supplemental notices may address the EU GDPR and ePrivacy rules; the UK GDPR, Data Protection Act 2018, and Privacy and Electronic Communications Regulations as amended, including changes made by the UK Data (Use and Access) Act 2025, whose data-protection provisions were fully in force by June 19, 2026; the Swiss Federal Act on Data Protection; Canada's PIPEDA and substantially similar provincial privacy laws where applicable; Brazil's LGPD; the Australian and New Zealand privacy frameworks; and other mandatory international laws. Where PIPEDA validly applies, ZNF's framework is intended to address its core principles of accountability, identified purposes, meaningful consent, limited collection/use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. The more specific addendum controls where it grants a mandatory right or provides a required local procedure.
Nothing in this section shall be construed as an admission that every foreign privacy law applies to every ZNF interaction, transaction, shipment, or communication.
15.1 Transfer safeguards and local requirements
Where required, ZNF may rely on standard contractual clauses, adequacy decisions, recognized certifications or frameworks, contractual protections, consent, necessity for contract performance, legal claims, or another lawful transfer mechanism. ZNF may appoint a representative, privacy contact, or data-protection officer only where legally required and will publish the applicable details in the relevant addendum.
Nothing in this Privacy Policy constitutes a commitment to local hosting, local storage, data localization, local-language administration, or a local establishment unless mandatory law requires it for the processing at issue.
16. U.S. Privacy Rights — General Framework
Depending on your U.S. state of residence and whether the applicable statute covers ZNF and the particular processing activity, you may have one or more privacy rights under applicable law, which may include rights relating to access, confirmation, correction, deletion, portability, appeal, non-discrimination, sensitive-data processing, sale, sharing, targeted advertising, profiling, or browser-based privacy signals.
Rather than repeating every state-specific rule in this main Privacy Policy, ZNF addresses those rights through:
- this main Privacy Policy for baseline disclosure;
- the U.S. State Privacy Addendum for state-specific rights, notice content, appeals, and similar requirements; and
- the Your Privacy Choices / Data Sharing Opt-out Notice for sale, sharing, targeted advertising, browser-based opt-out signals, and related choice mechanisms.
To the fullest extent permitted by law, nothing in this section is intended to promise every statutory right to every person in every state regardless of legal thresholds, exemptions, or scope limitations. The more specific state-law mechanisms, including opt-out rights and GPC treatment where applicable, are addressed in the separate state-law documents.
16.1 Rights that may be available
Depending on applicable law, rights may include confirmation, access, correction, deletion, portability, restriction, objection, consent withdrawal, non-discrimination, appeal, a list of certain recipients, limitation of sensitive-data use, opt-out of sale or targeted advertising, and rights concerning profiling or automated decisions. The scope, exceptions, and response period differ by jurisdiction.
16.2 State-specific and international notices control
The U.S. State Privacy Addendum, International Privacy Addendum, and GDPR Notice provide the more specific rights, complaint paths, and jurisdictional limitations. Those notices control where they provide a mandatory right or procedure not stated in this baseline policy.
16.3 California / CCPA transparency summary for the preceding 12 months
If the CCPA applies to ZNF and the processing at issue, the following summary supplements Sections 5 through 11. It describes the categories ZNF collected during the preceding 12 months, the principal sources and purposes, and the categories disclosed for business purposes or sold/shared as those terms are broadly defined. Not every example applies to every person.
California regulatory update. California regulations adopted in 2025 became effective January 1, 2026 and address, among other topics, privacy risk assessments, cybersecurity audits, and automated decisionmaking technology. Compliance dates vary by requirement. Covered ADMT requirements for significant decisions begin January 1, 2027. ZNF will implement a requirement only to the extent ZNF and the processing activity are within its lawful scope, while preserving all applicable exemptions, thresholds, transition periods, and other protections.
Scrollable table: On smaller screens, this table can be scrolled horizontally. Keyboard users can focus the table region and use the browser's scrolling keys.
| California category and examples | Sources and business/commercial purposes | Disclosed for business purposes to | Sold or shared for cross-context advertising |
|---|---|---|---|
| Identifiers and customer-record information: name, alias, postal or email address, phone, IP address, account or device identifiers, signature, and payment-related identifiers | You, devices, platforms, providers, authorized persons; commerce, accounts, payments, support, security, shipping, marketing, and compliance | Commerce, payment, fraud, support, communications, hosting, security, professional, shipping, marketplace, and legal recipients | Device, cookie, advertising, and similar identifiers may be sold/shared through covered advertising integrations; direct contact and payment credentials are not authorized for that purpose |
| Commercial information: products viewed, considered, purchased, returned, reviewed, subscribed to, or saved; transaction, loyalty, and preference history | You, accounts, transactions, marketplaces, devices, providers; fulfillment, support, analytics, personalization, advertising, safety, and business administration | Commerce, payment, subscription, loyalty, review, support, analytics, shipping, marketplace, professional, and legal recipients | Selected product-interest, conversion, audience, or transaction-event information may be sold/shared for covered advertising or measurement |
| Internet or electronic-network activity: browsing, searches, interactions, referral data, cookies, logs, diagnostics, and ad engagement | Browsers, devices, cookies, analytics, advertising, security, and platform providers; operation, security, analytics, personalization, attribution, and advertising | Hosting, security, diagnostics, consent, analytics, advertising, platform, and professional recipients | Yes, where covered advertising, analytics, audience, attribution, or social integrations constitute sale/sharing |
| Approximate geolocation: location inferred from IP address or shipping region | Devices, browsers, address and fraud systems; localization, shipping, tax, security, fraud, analytics, and advertising | Commerce, tax, fraud, security, shipping, analytics, and advertising recipients | May be sold/shared when used in covered advertising; ZNF does not intentionally use precise geolocation for advertising without any required consent |
| Audio, visual, or similar information: support recordings, photographs, facility or pickup video, and submitted media | You, support channels, facilities, carriers, providers; support, pickup, security, quality, safety, claims, and legal compliance | Support, security, carrier, insurer, legal, regulatory, and professional recipients as needed | No, unless you intentionally direct a disclosure or a specific lawful notice states otherwise |
| Professional or employment-related information: business role, employer, purchasing authority, wholesale/vendor details | You, employers, business counterparties, public business sources; B2B relationships, verification, contracts, support, and compliance | Commerce, verification, communications, professional, logistics, and legal recipients | Not ordinarily sold/shared for cross-context advertising |
| Inferences: interests, preferences, audience segments, fraud or security indicators, and product recommendations | Derived from the categories above; personalization, recommendations, security, fraud prevention, analytics, and advertising | Commerce, security, fraud, analytics, advertising, support, and platform recipients | Interest, audience, and advertising inferences may be sold/shared through covered advertising integrations |
| Sensitive personal information or consumer health data: limited account credentials, payment/security data, precise location if specifically enabled, health-related interests or voluntarily submitted information, and government identifiers if lawfully required | You, authorized persons, transactions, devices, support and safety channels; authentication, requested services, safety, fraud prevention, legal compliance, and the limited purposes in Section 5.13 | Necessary processors, safety, security, payment, professional, legal, and regulatory recipients; other recipients only as permitted and disclosed | ZNF does not authorize sale/sharing of sensitive personal information or consumer health data for prohibited advertising or inference purposes; any covered activity requires the consent, limit mechanism, or authorization required by law |
ZNF does not sell personal information in exchange for money. Because California defines “sale” and “sharing” broadly, the advertising-related disclosures identified above are treated conservatively as sale/sharing where the legal definition is met. ZNF does not have actual knowledge that it sold or shared the personal information of consumers under 16 during the preceding 12 months. California consumers may use the Privacy Control Center / Your Privacy Choices and the rights methods in Section 17. Category-specific retention criteria appear in Section 11.
17. How to Exercise Privacy Rights; Verification; Authorized Agents
ZNF currently provides multiple channels for privacy questions and, where applicable law grants a right, privacy-rights requests. You may use the method that is appropriate for your request:
- Online: Privacy Control Center / Your Privacy Choices;
- Email: privacy@znaturalfoods.com;
- Telephone: 1-888-963-6637;
- Mail: Z Natural Foods LLC, 5407 N Haverhill Rd Unit 336, West Palm Beach, Florida 33407, United States; and
- Browser/device signal: a legally recognized opt-out preference signal, including GPC, where applicable law requires ZNF to recognize that signal for the covered activity.
Providing these channels does not mean every request is a statutory request in every jurisdiction, does not waive any threshold, exemption, verification requirement, or defense, and does not require ZNF to use a particular channel where applicable law permits or requires another method. ZNF may add, replace, or consolidate request methods so long as the methods required by applicable law remain available.
We are happy to help. If you are unsure which request type fits your concern, use the Privacy Control Center or contact us. We will work with you to identify the appropriate path. ZNF will not unlawfully discriminate or retaliate against you solely for exercising a privacy right that applicable law grants you.
Before acting on a request to know, access, correct, delete, port, or otherwise act on personal information, ZNF may take commercially reasonable steps to verify the identity of the requester, confirm that the request relates to information in ZNF’s possession, and confirm that the request falls within the rights available under the law that applies.
Verification steps may vary depending on the nature and sensitivity of the request, the risk of unauthorized disclosure or deletion, the type of information requested, whether the request concerns an account, order, subscription, pickup, shipping, payment, marketplace record, or safety issue, and whether the request is submitted by an authorized agent.
Where permitted by applicable law, you may designate an authorized agent to submit a privacy request on your behalf. ZNF may require the agent to provide proof of authority and may also require you to verify your identity directly with ZNF or otherwise confirm the agent’s authority, to the extent permitted by law.
We want to honor valid privacy requests while protecting your information and the rights of others. If ZNF cannot safely or lawfully fulfill all or part of a request, ZNF may, to the extent permitted by applicable law, deny, limit, delay, or decline that portion of the request when it is incomplete, unverifiable, fraudulent, abusive, duplicative, technically infeasible, inconsistent with applicable law, or subject to a lawful exemption or exception. Where applicable law requires an explanation, appeal opportunity, or additional response, ZNF will provide it.
Additional detail regarding rights, appeals, recognized opt-out signals, and state- or country-specific request rules may be provided in the U.S. State Privacy Addendum, International Privacy Addendum, GDPR Statement / EEA-UK-Switzerland Privacy Notice, and Your Privacy Choices / Data Sharing Opt-out Notice.
17.1 Opt-outs that ordinarily do not require identity verification
For an ordinary browser- or device-level opt-out of sale, sharing, or targeted advertising, ZNF will not require unnecessary identity verification. Access, deletion, correction, portability, account-level application, or another request that could expose, alter, or delete personal information may require verification proportionate to the risk.
17.2 Appeals
Where applicable law grants an appeal right, you may appeal by replying to the denial notice or emailing privacy@znaturalfoods.com with the subject line Privacy Appeal. Include information sufficient to identify the original request and explain why you believe the decision should be reconsidered.
17.3 Privacy complaints and regulators
You may submit a privacy complaint by emailing privacy@znaturalfoods.com with the subject Privacy Complaint. Please identify the practice or response at issue and the outcome requested. ZNF will acknowledge, investigate, document, and respond within the period required by applicable law, including any applicable UK data-protection complaint-process requirement. Nothing in this Privacy Policy restricts a non-waivable right to complain directly to a state attorney general, privacy commissioner, supervisory authority, consumer-protection agency, or other competent regulator. The applicable addendum identifies jurisdiction-specific complaint paths where required.
17.4 Request integrity, security, and rights of others
We aim to make legitimate requests straightforward while also protecting you, other people, and our systems. Where permitted by law, ZNF may deny, narrow, delay, or request clarification of a request that is fraudulent, abusive, excessive, repetitive, technically infeasible, impossible to verify, likely to compromise security, likely to disclose another person's information, inconsistent with legal retention duties, or subject to a statutory exemption. ZNF may retain records reasonably necessary to document suspected request fraud, abuse, verification, or compliance.
18. Accessibility, Effective Communication, and Privacy-Request Support
We want this Privacy Policy, the related privacy-choice tools, and the complete privacy-request process to be usable by as many people as possible. For ZNF-controlled digital content, WCAG 2.2 Level AA is our principal current technical benchmark and improvement target. Accessibility law is broader than a checklist or automated score, so we also consider effective communication, reasonable modifications or adjustments, accessible alternatives, third-party dependencies, and jurisdiction-specific requirements where they validly apply.
18.1 Accessibility features built into this page
This fragment uses a declared English language, semantic headings and lists, descriptive underlined links, a keyboard-accessible skip link with focus transfer, a native details/summary section guide, a high-contrast two-color keyboard focus indicator, logical reading order, responsive reflow, browser zoom and text-resizing support, long-string wrapping, touch-friendly controls, reduced-motion support, reduced-transparency support where recognized by the browser, increased-contrast support, forced-colors support, print styling, immediate accessibility-help contact information, and keyboard-focusable horizontally scrollable tables with captions, column headers, row headers, and visible scroll guidance. Section headings retain stable IDs for direct linking without adding redundant heading-permalink controls to the keyboard or screen-reader reading order. No privacy disclosure is intentionally hidden behind a JavaScript-only control, and the closed section guide does not narrow or remove the article. This fragment does not require page-specific JavaScript, dragging, path-based gestures, motion activation, timers, auto-refresh, flashing content, images, audio, video, frames, authentication, or modal dialogs for its essential content, navigation, or core reading controls. Native radio, checkbox, link, details/summary, and reset controls remain usable when page-specific JavaScript is unavailable; JavaScript is reserved for optional enhancements such as read-aloud, the print-dialog shortcut, section filtering, and current-section highlighting.
18.2 Accessibility App and optional tools
ZNF may provide an optional Accessibility App or other personalization tools. Those tools supplement—not replace—accessible design, testing, remediation, browser and operating-system features, assistive technology, and individualized assistance. You never have to use an accessibility overlay or app as the only way to receive information, exercise a privacy choice, obtain customer service, or communicate with us.
18.3 Third-party services and accessible alternatives
Parts of the privacy and customer experience may depend on Shopify, payment processors, consent-management providers, analytics or advertising tools, communications platforms, review services, carriers, marketplaces, embedded content, or other independent providers. We work to reduce barriers within the parts of the experience we control, but ZNF cannot guarantee the accessibility, uptime, compatibility, security, or legal compliance of every independent third-party system. That limitation is not intended to waive any accessibility or privacy duty that applicable law places on ZNF.
If a third-party feature creates a disability-related barrier to a ZNF-controlled privacy choice, request, policy, good, service, or communication, please tell us. We will review the issue in good faith and, where required and reasonably available, work with you on an effective alternative method, human-assisted route, accessible format, or vendor remediation while maintaining appropriate identity-verification, privacy, security, and fraud-prevention safeguards.
18.4 Accessible privacy requests and alternative formats
If a disability affects your ability to read this Policy, use a privacy control, submit or verify a request, or understand a response, email accessibility@znaturalfoods.com, call 1-888-963-6637, or review our Accessibility Statement. You may request an accessible format, communication accommodation, help completing a request, or another reasonable method where required by applicable law.
Please describe the barrier and the assistance requested; you do not need to disclose a diagnosis or provide unrelated medical information. Where applicable law requires an accessible format, auxiliary aid or service, effective communication measure, or reasonable modification without an added disability-related surcharge, ZNF will follow that requirement.
Identity, authority, payment-security, fraud-prevention, and privacy safeguards still apply, but we will seek an accessible way to complete them. Where a disability-related barrier affects a legal deadline or request method, ZNF will provide any adjustment or alternative required by applicable law. Accessibility-related communications and accessibility-tool preferences may themselves involve personal information and are handled under this Privacy Policy.
18.5 U.S., EU, UK, Canada, and evolving accessibility standards
United States. U.S. Department of Justice guidance states that Title III of the Americans with Disabilities Act applies to the goods, services, privileges, and activities that public accommodations offer on the web and requires covered businesses to provide full and equal enjoyment, effective communication, and reasonable modifications where required. DOJ has not adopted one WCAG version as an exclusive private-sector Title III web standard, so ZNF uses WCAG 2.2 Level AA as a strong technical benchmark while separately addressing the legal duties that validly apply. Florida Statutes section 760.08 separately provides full and equal enjoyment of covered public accommodations without discrimination on the ground of handicap, among other protected grounds. Other state or local disability, public-accommodation, consumer-access, and communications laws may also apply depending on the facts.
European Union. Directive (EU) 2019/882, the European Accessibility Act, includes consumer e-commerce services within its scope for covered services provided after June 28, 2025, subject to national implementation, exemptions, transition provisions, disproportionate-burden or fundamental-alteration rules, and other lawful limitations. Covered e-commerce functions include accessible identification, security, electronic-signature, and payment functionality when provided as part of the service. ZNF also considers EN 301 549 as an important technical reference for accessible information and communications technology where relevant; W3C notes that the current EN 301 549 web provisions use WCAG 2.1 and that a future revision is expected to incorporate WCAG 2.2.
United Kingdom and Canada. UK disability-access obligations may arise under the Equality Act 2010 and related rules or guidance applicable to service providers, including duties concerning reasonable adjustments where they validly apply. Canada's Accessible Canada Act and Accessible Canada Regulations principally govern federally regulated organizations, while provinces and territories may impose separate accessibility and human-rights duties. For example, Ontario's AODA website rules apply to designated public-sector organizations and to Ontario businesses or nonprofits with 50 or more employees, subject to the regulation's scope and exceptions. ZNF evaluates the law that actually governs the particular service, market, organization, and interaction rather than assuming identical obligations worldwide.
WCAG 3 draft status. W3C describes WCAG 3 as an incomplete, in-progress Working Draft whose final requirements will differ from the current draft. ZNF does not claim WCAG 3 conformance. We may consider mature WCAG 3 concepts and emerging accessibility practices for future-readiness, but WCAG 2.2 Level AA remains the principal current benchmark for this page unless a different mandatory requirement validly applies.
Non-waivable rights and future law. Nothing in this section limits a disability-related right, remedy, effective-communication obligation, reasonable-adjustment duty, or other protection that applicable law makes non-waivable. No static page can guarantee compliance with a future law before it is enacted, finalized, interpreted, and made applicable. If a later mandatory accessibility requirement validly applies before this page is updated, that requirement controls to the extent of any conflict, subject to any lawful transition period, exemption, defense, alternative-compliance method, or scope limitation.
Official accessibility resources: U.S. DOJ Web Accessibility Guidance; W3C WCAG 2.2; W3C WCAG 3 Draft Status; W3C WCAG / EN 301 549 overview; European Accessibility Act; Accessible Canada Act summary; and Ontario AODA website accessibility guidance.
19. Additional Legal Process, Rights Protection, and Investigative Use
ZNF may preserve, review, use, and disclose personal information, logs, communications, transactional records, technical records, and related materials where reasonably necessary to:
- establish, exercise, or defend legal claims;
- investigate fraud, abuse, chargebacks, product tampering, contamination, shipping disputes, pickup disputes, customs issues, copyright complaints, unauthorized automated access, or security incidents;
- enforce the Terms of Use or another ZNF Legal Policy;
- preserve evidence;
- respond to subpoenas, court orders, legal process, regulatory inquiries, or governmental demands;
- cooperate with regulators, law enforcement, customs authorities, carriers, marketplaces, payment providers, insurers, or other governmental or quasi-governmental bodies where lawfully required or reasonably appropriate; or
- protect ZNF, its personnel, service providers, customers, facilities, systems, content, records, and operations.
Nothing in this Privacy Policy limits ZNF’s right to use or disclose information where authorized or required by applicable law, legal process, or a valid protective, regulatory, security, fraud-prevention, customs, shipping, intellectual-property, or evidentiary purpose.
This section is intended to work together with ZNF’s Terms of Use, Information Security Policy & Responsible Vulnerability Disclosure Policy, DMCA Compliance Statement & Copyright Infringement Policy, Agent Terms & Automated Access / Bot Policy, Shipping & Delivery Policy, and Purchases, Subscriptions & Pre-Orders Policy.
20. No Waiver; No Admission; Preservation of Non-Waivable Rights
Our goal is to provide transparent, useful, and operationally accurate information while describing the legal scope of this Privacy Policy carefully. To avoid unintentionally expanding or narrowing rights beyond what applicable law provides, this Privacy Policy is not intended to:
- admit that any law applies in every circumstance, transaction, channel, jurisdiction, or platform;
- waive any defense, threshold requirement, exemption, privilege, immunity, limitation, safe harbor, statutory exception, or lawful argument available to ZNF under applicable law;
- expand any legal duty beyond what applicable law requires;
- limit ZNF’s right to revise, supplement, narrow, clarify, or correct its privacy disclosures in a lawful manner; or
- waive any non-waivable right or remedy held by any user under applicable law; or
- convert a voluntarily offered privacy choice, accommodation, response, appeal path, browser-signal treatment, or customer-service practice into a broader or permanent contractual obligation where applicable law does not require it.
If any provision of this Privacy Policy is determined to be invalid, illegal, unenforceable, or inapplicable in a particular jurisdiction or circumstance, that provision shall be interpreted or limited only to the extent necessary to make it enforceable or applicable, and the remaining provisions shall continue in full force to the fullest extent permitted by law.
This Privacy Policy must be read in harmony with the ZNF Legal Policies as a coordinated legal framework and not in isolation.
21. Changes to This Privacy Policy
ZNF may revise, supplement, restate, or otherwise update this Privacy Policy from time to time to reflect changes in:
- law or regulation;
- governmental guidance;
- court decisions;
- ZNF’s services, channels, technologies, vendors, or marketplaces;
- cookies, analytics, advertising, or privacy-choice mechanisms;
- security, incident-response, or abuse-prevention practices;
- operational workflows, including shipping, pickup, freight, marketplace, mobile, support, or wholesale processes; or
- other lawful business needs.
When ZNF updates this Privacy Policy, ZNF may do so by posting the revised version on the applicable website, legal page, checkout flow, or other relevant Service and updating the “Last Updated” date. Where required by applicable law, ZNF may also provide additional notice through email, banners, consent tools, privacy-choice interfaces, account communications, or other reasonable methods.
To the fullest extent permitted by law, the revised Privacy Policy will become effective when posted or otherwise communicated, unless a later effective date is stated. However, if applicable law requires a different form of notice, consent, or timing for a specific category of change, ZNF will follow the law that validly applies to that change.
Posting a revised Privacy Policy does not, by itself, authorize a materially different use or disclosure of personal information previously collected where applicable law, a binding prior representation, or the consent framework governing that information requires additional notice, consent, or another step. In that circumstance, ZNF will provide the legally required notice or obtain the legally required consent before the materially different use applies to the affected information.
We encourage you to review this Privacy Policy from time to time so you can stay informed about our current practices and available privacy choices.
21.1 Material changes, new services, and future laws
ZNF will review this Privacy Policy as practices, services, providers, and legal requirements evolve. The addition of a material new data use or external service may be addressed by updating this Privacy Policy, a point-of-collection notice, the Cookie Policy, the applicable addendum, or another legally sufficient notice. Where a future law, amendment, regulation, or recognized privacy signal validly applies and requires additional rights, notices, consent, or controls, ZNF intends to implement the required measures by the applicable compliance date.
No privacy policy can guarantee compliance with every future law before that law is enacted, finalized, interpreted, and made applicable. This provision is intended to preserve flexibility while requiring ZNF to follow mandatory future requirements that validly apply.
22. Contacting ZNF About Privacy Matters
We welcome good-faith privacy questions and requests. If you would like to submit a privacy request, need help understanding a disclosure, need an accessible way to communicate, or simply want to ask how a practice applies to you, please use the channel that is most convenient and appropriate below. We will review the available information and work with you toward a practical, lawful response:
Z Natural Foods LLC5407 N Haverhill Rd Unit 336
West Palm Beach, Florida 33407
United States
Privacy requests and general privacy questions: Privacy@znaturalfoods.com
General support and order-related matters: Orders@znaturalfoods.com
Telephone: +1-888-963-6637
Online: Privacy Control Center / Your Privacy Choices
privacy@znaturalfoods.com
GDPR@znaturalfoods.com
accessibility@znaturalfoods.com
DMCA@znaturalfoods.com
Where a more specific contact channel is identified in another applicable ZNF Legal Policy or notice, including for GDPR-related matters, accessibility matters, mobile-message matters, DMCA notices, security reports, or Your Privacy Choices / Data Sharing Opt-out requests, ZNF may direct you to that channel for faster and more accurate handling.
To help ZNF respond efficiently and securely, please include, where applicable:
- your name and preferred contact method;
- the nature of your request or question;
- the order number, account information, or transaction details involved, if relevant;
- the jurisdiction or state whose privacy law you believe applies, if relevant; and
- sufficient information for ZNF to verify your identity or authority where verification is required.
If we need additional information, verification, or a different request channel to handle your request securely and accurately, we may ask you to supplement or redirect it. To the extent permitted by applicable law, ZNF may delay, limit, or decline a request that remains incomplete or unverifiable, is abusive, duplicative, or fraudulent, or is submitted through a channel that cannot reasonably or securely process the request. Where applicable law requires an explanation, appeal path, or alternative method, ZNF will provide it.
23. Definitions
For purposes of this Privacy Policy:
- “Personal information,” “personal data,” or “information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable person or household, as defined by applicable law.
- “Processing” means any operation performed on personal information, including collection, use, storage, analysis, inference, disclosure, transfer, deletion, or destruction.
- “Sensitive personal information,” “sensitive data,” and “consumer health data” have the meanings provided by the law applicable to the processing at issue.
- “Sale,” “sharing,” “targeted advertising,” and “profiling” have the meanings provided by applicable law and do not necessarily include ordinary disclosures to service providers or processors acting under qualifying restrictions.
- “Service provider,” “processor,” “contractor,” “third party,” and “controller” have the meanings provided by applicable law and may describe different roles for different processing activities.
24. Effective Date; Canonical and Controlling Version
This Privacy Policy is effective as of the “Last Updated” date shown above. For clarity and consistency, the version published in ZNF's Legal section is the canonical version. Cached, archived, translated, syndicated, marketplace-displayed, or third-party copies may be provided for convenience and may become outdated. To the fullest extent permitted by law, the current version on ZNF's Legal page controls in the event of a discrepancy.