Privacy policy

Effective 17 September 2026  ·  Last updated 17 September 2026

At a glance

1. Controller. The store operator identified in our Legal Notice, decides how and why your personal data is processed.

2. What we collect. Contact and delivery details, order and payment records, customs identifiers where required, communications with us, and technical and usage data from this site.

3. Payment data. We never receive or store your full card number, CVV or bank details. Card data is captured directly by our PCI-DSS compliant payment processor.

4. Customs. Where you are the importer of record, your details are disclosed to carriers, customs brokers and customs authorities. This is necessary for your order to be delivered.

5. Your rights. Access, correction, deletion, portability and objection. EU/EEA rights are in Part B; US state rights in Part C; Swiss and Canadian rights in Part D.

6. Contact. Privacy requests: contact@smoothlabs.com, marked "Privacy Request".

Part A — How we process your data

1. Who we are, and the role of our platform and payment providers

1.1 Controller. The store operator identified in our Legal Notice ("we", "us", "our") is the controller of the personal data described in this policy. Our registered address is 1209 Mountain Road PL NE STE R, Albuquerque, NM 87110, United States.

1.2 Our e-commerce platform. This store is hosted and operated on a third-party e-commerce platform, identified in our Legal Notice. The platform provider processes personal data on our behalf as our processor (or, under US state privacy laws, our service provider), under its data processing terms, in order to provide the storefront, checkout and order management we use.

1.3 Payment processing. Payments are processed by our payment provider, identified in our Legal Notice, and its payment processor. The payment provider processes customer payment data on our behalf as our processor in order to provide the payment services. The payment processor may also process personal data as an independent controller for its own regulatory purposes — including know-your-customer, anti-money-laundering, sanctions screening and fraud prevention — in which case its own privacy notice applies and we are not responsible for that processing.

1.4 What we never receive. We do not receive or store full payment card numbers, CVV codes or bank account credentials. We receive the transaction record described in Section 2.

2. Personal data we collect

2.1 Data you give us

  • Identity and contact data — name, recipient name, delivery address, billing address, email address, telephone number.
  • Order data — items ordered, order value, order history, delivery preferences, correspondence about your order.
  • Payment record — payment method type, the last four digits of the card and the authorisation result.
  • Customs data — any tax or personal identification number required by the customs authority of your country for import clearance.
  • Account data — where you create an account: your account login details, saved addresses, order history.
  • Communications — messages, complaints, return requests, photographs and other material you send us.
  • Marketing preferences — your consent status and channel preferences.
  • Content you submit — reviews, ratings, photographs and other material you post or send.

2.2 Data collected automatically

  • Technical data — IP address, browser type and version, device type, operating system, language and time-zone settings.
  • Usage data — pages visited, referring pages, session duration, products viewed, cart activity, click and scroll behaviour.
  • Cookie data — as described in Section 8.

2.3 Data from third parties

  • Our payment processor — authorisation, chargeback and fraud signals.
  • Carriers and customs brokers — delivery status, clearance status, address validation.
  • Fraud prevention and address-verification providers.
  • Analytics and advertising platforms, where you have consented.

2.4 Special categories and children

We do not seek to collect special category data such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, or sexual orientation. Please do not send it to us; where you volunteer it — for example describing a skin reaction — we process it only to handle your enquiry, on the basis of your explicit consent or the establishment or defence of legal claims.

We do not knowingly collect personal data from anyone under 13. Where the GDPR applies, we do not knowingly process the personal data of anyone under 16 on the basis of consent without the consent of a parent or guardian, and orders must be placed by an adult (see our Terms of Service). If you believe a child has provided us with personal data without the required consent, contact us and we will delete it.

3. Why we process your data, and on what legal basis

Purpose Data used Legal basis (EU/EEA)
Taking, processing and fulfilling your order Identity, contact, order, payment record Performance of a contract
Customs clearance and import formalities Identity, contact, customs data, order value Performance of a contract; legal obligation
Delivery and carrier communication Identity, contact, order Performance of a contract
Returns, refunds and warranty handling Identity, order, communications Performance of a contract
Customer support Identity, order, communications Performance of a contract; legitimate interests
Fraud prevention, chargeback defence and site security Identity, order, payment record, technical Legitimate interests; legal obligation
Accounting, tax and record-keeping Identity, order, payment record Legal obligation
Establishing, exercising or defending legal claims As relevant Legitimate interests; legal obligation
Marketing email and SMS Identity, contact, preferences Consent, or legitimate interests for existing customers where permitted
Analytics and site improvement Technical, usage, cookie Consent (EU/EEA); legitimate interests elsewhere
Advertising and audience measurement Technical, usage, cookie Consent

Where we rely on legitimate interests, those interests are operating and securing our business, preventing fraud and loss, improving our products and services, and defending our legal position. You may object at any time (Part B).

4. Who we share your data with

We do not sell personal data.

  • Our e-commerce platform provider — as our processor, to host the store and process orders.
  • Our payment provider and its payment processor — to take payment, verify the payment method and handle disputes, as described in Section 1.3.
  • Our warehousing and fulfilment partners — the recipient name, delivery address and contact details necessary to prepare and ship your order.
  • Carriers, freight forwarders, postal operators and customs brokers — the data necessary to transport your order and clear it through customs.
  • Customs and tax authorities — the data required by law in the country of export and the country of import, including your name, address, any required identification number, the goods description and the order value.
  • Communications, support, review and analytics providers — subject to your cookie and marketing choices.
  • Professional advisers, accountants, insurers and, where required, regulators, law enforcement and courts.
  • A purchaser or successor — in connection with a merger, acquisition, restructuring or sale of assets.

We require our service providers to process personal data only on our instructions and to protect it appropriately.

5. International transfers

We are established in the United States, and our platform, providers, fulfilment partners and carriers may be located in the United States, in the countries where our warehouses operate, and in your own country. Your personal data will therefore be transferred to and processed in the United States, in the country from which your order is dispatched, and in your own country for delivery and customs clearance. Some of these countries are outside the EEA and have no adequacy decision.

Where personal data is transferred out of the EEA, we rely on the Standard Contractual Clauses approved by the European Commission, on an adequacy decision where one applies, or on the contractual necessity derogation — which covers the transfer of your delivery and customs data to carriers, brokers and customs authorities. A copy of the relevant safeguards is available on request.

6. How long we keep your data

Category Retention
Order, invoice and payment records The period required by tax and accounting law, and in any event not less than 7 years from the end of the tax year
Customs and import records The period required by applicable customs law
Account data While the account is active, then up to 24 months after last activity
Support correspondence Up to 36 months from the close of the matter
Marketing preferences and consent records Until you withdraw consent, plus a record of the withdrawal
Fraud and chargeback records Up to 6 years, to defend claims
Cookie and analytics data As stated in our cookie banner, and no longer than 24 months

7. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and restricting access to those who need it. Card data is handled by a PCI-DSS compliant payment processor and does not reach our systems in full.

No method of transmission or storage is completely secure. While we take security seriously, we cannot guarantee the security of data transmitted to us, and any transmission is at your own risk. You are responsible for keeping your account credentials confidential and for the security of your own devices and email account.

8. Cookies and similar technologies

We use cookies and similar technologies (pixels, tags, local storage) to operate the store, remember your cart and preferences, measure performance, prevent fraud and — where you consent — to personalise and measure advertising.

Strictly necessary cookies are required for the store to function and cannot be switched off. Analytics, functional and advertising cookies are used only where you consent, in jurisdictions where consent is required. You can change your choices at any time through the cookie settings on this site, and control cookies through your browser. Blocking some cookies will affect how the store works.

Where required by law, we honour Global Privacy Control (GPC) signals as an opt-out of sale and sharing.

9. Marketing

Where you have consented, or where permitted for existing customers, we send marketing by email and — where you opted in — SMS. You can unsubscribe at any time using the link in any marketing email, by replying STOP to any marketing SMS, or by contacting us. Transactional messages about your orders will continue, as they are necessary to perform the contract.

10. Automated decision-making

We and our providers use automated fraud, sanctions and address-verification screening at checkout, which may result in an order being delayed, refused or cancelled. No order is refused solely on the basis of automated processing without the possibility of human review. If your order is refused and you believe the screening was mistaken, contact us and a person will review it.

11. Third-party sites

This store links to third-party sites and services. This policy does not apply to them and we are not responsible for their privacy practices.

12. Changes

We may update this policy by posting a revised version with a new date. Where changes are material we will take reasonable steps to notify you. The version in force when your data is collected applies to that collection.

Part B — EU and EEA residents

This Part applies where the General Data Protection Regulation applies to the processing of your personal data. Where it conflicts with the rest of this policy, this Part prevails.

B.1 Controller and representative

The store operator identified in our Legal Notice is the controller. We have not appointed a representative under Article 27 GDPR; where one is required and appointed, its details will be published here.

B.2 Your rights

You have the right to access your data and receive a copy; to rectification; to erasure where a ground in Article 17 applies; to restriction of processing; to data portability; to object to processing based on legitimate interests on grounds relating to your particular situation, and to object to direct marketing at any time, absolutely; to withdraw consent at any time without affecting prior processing; and not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.

B.3 Exercising your rights

Send a request to contact@smoothlabs.com, marked "Privacy Request". We will respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month. We may ask you to verify your identity, and may decline or charge a reasonable fee for manifestly unfounded or excessive requests.

B.4 Limits on erasure

We cannot delete data we are required to retain, in particular order, invoice, payment, customs and tax records, or data needed to establish, exercise or defend legal claims. Where erasure is refused on that basis, we will restrict processing to those purposes instead.

B.5 Complaints

You may lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work or the place of the alleged infringement. We would appreciate the opportunity to address your concerns first.

Part C — United States state privacy rights

This Part applies to residents of California and other US states with comprehensive privacy laws, to the extent those laws apply to us.

C.1 Categories collected and disclosed

In the twelve months before the date of this policy we collected the categories described in Section 2, corresponding under the California Consumer Privacy Act as amended to: identifiers; customer records information; commercial information; internet or other electronic network activity information; geolocation data (approximate, derived from IP address); and inferences drawn from the above. Each category is collected for the purposes in Section 3 and disclosed for a business purpose to the recipients in Section 4.

We do not sell personal information for monetary consideration. Where advertising or analytics cookies are used with your consent, that use may constitute a "sale" or "sharing" for cross-context behavioural advertising under California law. You can opt out through the cookie settings on this site, through the "Do Not Sell or Share My Personal Information" link, or by transmitting a Global Privacy Control signal. We do not knowingly sell or share the personal information of consumers under 16.

C.2 Your rights

Subject to verification and applicable exemptions, you have the right to know what we collect, use, disclose and sell or share and to obtain a copy; to delete personal information collected from you; to correct inaccurate personal information; to opt out of sale, sharing and targeted advertising; to limit the use of sensitive personal information (we do not use it for purposes requiring a limitation right); and to be free from discrimination for exercising these rights.

C.3 How to exercise them

Send a request to contact@smoothlabs.com, marked "Privacy Request". We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days where reasonably necessary. We will verify your identity by matching your request against the information we hold, typically the email address and order number used at purchase. An authorised agent may submit a request with written permission signed by you.

C.4 Other states and appeals

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have comparable rights and, where their law provides, a right to appeal a refusal. To appeal, resubmit your request marked "Privacy Appeal", and we will respond within the period required by your state's law.

C.5 Shine the Light

California residents may request information about disclosures of personal information to third parties for those parties' own direct marketing purposes under Cal. Civ. Code § 1798.83. We do not make such disclosures.

Part D — Switzerland and Canada

D.1 Switzerland

This Part applies where the Swiss Federal Act on Data Protection (FADP) applies to the processing of your personal data. The store operator identified in our Legal Notice is the controller. You have the right to access your data, to rectification, to erasure, to object to processing, to data portability in the cases provided by the FADP, and to withdraw consent at any time. Where your data is transferred to a country without adequate protection as determined by the Swiss Federal Council, we rely on the Standard Contractual Clauses recognised in Switzerland, with the adaptations required by Swiss law, or on the contractual necessity exception. Send requests to contact@smoothlabs.com, marked "Privacy Request". You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC). Switzerland is not a member of the EU or EEA, so Part B does not apply to you.

D.2 Canada

This Part applies where the Personal Information Protection and Electronic Documents Act (PIPEDA) or substantially similar provincial law applies. We collect, use and disclose personal information for the purposes described in Section 3, with your consent where required, and we may transfer it to service providers outside Canada, including in the United States, where it is subject to the laws of those countries. You have the right to access your personal information, to challenge its accuracy, and to withdraw consent subject to legal or contractual restrictions. Send requests to contact@smoothlabs.com, marked "Privacy Request". Complaints may be made to the Office of the Privacy Commissioner of Canada or, for Quebec residents, to the Commission d'accès à l'information du Québec. Quebec residents also have the rights provided by the Act respecting the protection of personal information in the private sector, including the right to be informed of, and to comment on, a decision based exclusively on automated processing.