1. Introduction
At KOKO WAX ("KOKO WAX", "we", "us", "our"), we are committed to protecting your privacy and handling your personal data with care, transparency, and in full compliance with applicable data protection laws.
This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website kokowax.us (the "Site"), place an order, subscribe to our newsletter, or interact with our brand in any way.
By using the Site, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please do not use the Site.
2. Data controller
The entity responsible for processing your personal data is:
KOKO WAX Email: hello@kokowax.com Website: kokowax.us
For any privacy-related questions or requests, you can contact us at the email address above.
3. What information we collect
We collect different types of information depending on your interactions with the Site.
a) Information you provide directly:
- Identity information: name, surname, date of birth (if requested)
- Contact information: email address, postal address, phone number
- Payment information: card details (processed securely by our payment partners — see Section 6)
- Account information: username, password, preferences
- Customer service correspondence: emails, messages, returned product information
- Reviews and user-generated content: product reviews, photos, comments
b) Information automatically collected:
- Technical data: IP address, browser type, operating system, language, device type
- Browsing data: pages visited, time spent, referral source, search terms used
- Cookies and similar technologies (see Section 9)
- Geographic data (approximate, based on IP)
c) Information from third parties:
- Data from social media platforms when you log in or interact via these channels
- Data from advertising and analytics partners (Meta, Google, TikTok, etc.)
- Data from delivery and payment providers regarding the status of your order
4. How we use your information
We process your personal data for the following purposes, based on a legitimate legal basis (contract, consent, legitimate interest, or legal obligation):
| Purpose | Legal basis |
|---|---|
| Processing and shipping your orders | Contract execution |
| Managing your customer account | Contract execution |
| Customer service and after-sales support | Contract execution |
| Sending you our newsletter and marketing communications | Consent |
| Personalized advertising on social media and search engines | Consent |
| Site analytics and performance improvement | Legitimate interest |
| Fraud prevention and Site security | Legitimate interest |
| Compliance with legal and tax obligations | Legal obligation |
| Sending order-related notifications (confirmation, tracking, delivery) | Contract execution |
You may withdraw your consent at any time for any data processing based on consent (see Section 11).
5. Sharing your information
We do not sell your personal data. However, we share certain information with trusted partners, strictly for the purposes outlined in this Policy:
a) Service providers (data processors acting on our behalf):
- Shopify (e-commerce platform and order management)
- Payment processors (Stripe, PayPal, Shop Pay, Apple Pay, Google Pay)
- Shipping carriers (USPS, UPS, DHL, and local providers depending on destination)
- Email marketing platforms (e.g., Klaviyo, Shopify Email)
- Analytics platforms (Google Analytics, Shopify Analytics)
- Advertising platforms (Meta, Google Ads, TikTok Ads — only with your consent)
- Customer service tools (helpdesk software, chatbots)
b) Legal authorities: We may disclose your information if required by law, court order, or to protect our rights, safety, or property, or those of others.
c) In case of business transfer: If KOKO WAX is involved in a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to the same level of protection.
All our partners are contractually bound to respect the confidentiality and security of your data, and to use it strictly for the purposes for which it was provided.
6. Payment security
a) Payments on the Site are processed by secure third-party providers (Stripe, PayPal, Shop Pay, etc.) using SSL encryption and PCI-DSS compliant standards.
b) KOKO WAX does not store any credit card information on its servers. All payment data is handled directly by our payment processors.
c) For more information on the security practices of our payment partners, please consult their respective privacy policies.
7. International data transfers
a) Some of our service providers may be located outside the European Economic Area (EEA) or the United Kingdom, including in the United States and other countries.
b) When transferring your data outside the EEA/UK, we ensure that appropriate safeguards are in place to protect your data, including:
- Standard Contractual Clauses approved by the European Commission
- Compliance with frameworks such as the EU-US Data Privacy Framework (where applicable)
- Other legally recognized safeguards
c) You may request more information about these transfers at hello@kokowax.com.
8. Data retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, in accordance with applicable legal obligations:
| Data type | Retention period |
|---|---|
| Customer account data | Duration of the account + 3 years after last activity |
| Order data (invoices, transactions) | 10 years (legal accounting obligation) |
| Newsletter subscription data | Until unsubscription + 3 years |
| Browsing data and cookies | 13 months maximum |
| Customer service correspondence | 3 years after last contact |
| Marketing data (consent, preferences) | 3 years from last interaction |
After these periods, your data is either deleted or anonymized.
9. Cookies and similar technologies
a) Our Site uses cookies and similar technologies to ensure proper functioning, analyze traffic, personalize content, and serve targeted advertising.
b) Types of cookies we use:
- Essential cookies: necessary for the Site to function (cart, login session, security). Cannot be disabled.
- Analytics cookies: measure traffic and improve user experience (Google Analytics, Shopify Analytics)
- Advertising cookies: enable personalized advertising (Meta Pixel, Google Ads, TikTok Pixel)
- Functional cookies: remember your preferences (language, currency, display)
c) Cookie management:
- A consent banner is displayed on your first visit, allowing you to accept, decline, or customize your preferences
- You can modify your choices at any time via the "Cookie preferences" link in the Site footer
- You can also configure your browser to block or delete cookies. However, this may affect Site functionality.
d) For more details, please consult our [Cookie Policy →] (if you have a separate page).
10. Data security
a) We implement appropriate technical and organizational measures to protect your personal data against loss, theft, unauthorized access, alteration, or disclosure.
b) These measures include in particular:
- SSL/TLS encryption of data in transit
- Restricted access to data on a need-to-know basis
- Regular updates of our systems and software
- Continuous monitoring of suspicious activity
- Internal staff training on data protection
c) Despite these measures, no transmission method via the internet is 100% secure. We cannot guarantee absolute security but commit to notifying you in case of a security breach affecting your data, in accordance with applicable law (within 72 hours where required by GDPR).
11. Your rights
In accordance with applicable data protection laws (GDPR, CCPA, and others), you have the following rights regarding your personal data:
a) Right of access: You may request a copy of the personal data we hold about you.
b) Right of rectification: You may request the correction of inaccurate or incomplete data.
c) Right of erasure ("right to be forgotten"): You may request the deletion of your data, subject to legal retention obligations.
d) Right to restriction of processing: You may request that we limit the use of your data in certain circumstances.
e) Right to data portability: You may request to receive your data in a structured, commonly used, and machine-readable format.
f) Right to object: You may object to the processing of your data for legitimate reasons, particularly for direct marketing.
g) Right to withdraw consent: You may withdraw your consent at any time for data processing based on consent (e.g., newsletter, advertising).
h) Right to lodge a complaint: You have the right to file a complaint with the competent data protection authority (e.g., the CNIL in France, the ICO in the UK, your state's Attorney General in the US).
To exercise these rights, please contact us at hello@kokowax.com, specifying the nature of your request and providing proof of identity. We will respond within 30 days.
12. Specific rights for California residents (CCPA / CPRA)
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
a) Right to know: You may request information about the categories of personal data collected, the sources, purposes, and third parties with whom it is shared.
b) Right to delete: You may request the deletion of your personal data.
c) Right to opt-out of the sale or sharing of your data: Although we do not sell personal data in the traditional sense, you may opt-out of the sharing of your data with advertising partners.
d) Right to non-discrimination: You will not receive different treatment if you exercise these rights.
e) Right to correct: You may request the correction of inaccurate data.
To exercise these rights, please contact us at hello@kokowax.com with the subject line "California Privacy Rights".
13. Children's privacy
a) Our Site and products are not intended for individuals under 18 years of age.
b) We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data without parental consent, please contact us at hello@kokowax.com so that we can promptly delete it.
c) For users in California subject to specific protections regarding minors (CalOPPA), additional rights apply. Please contact us for details.
14. Marketing communications
a) When you create an account or subscribe to our newsletter, you may receive marketing communications (newsletter, special offers, new products) from KOKO WAX.
b) You can unsubscribe at any time by:
- Clicking the "Unsubscribe" link at the bottom of each marketing email
- Modifying your preferences in your customer account
- Contacting us at hello@kokowax.com
c) Even after unsubscribing, you will continue to receive transactional emails (order confirmation, shipping, customer service), as these are necessary for the execution of our contract.
15. Third-party links
The Site may contain links to third-party sites or platforms (social media, payment partners, etc.). KOKO WAX is not responsible for the privacy practices of these third parties. We encourage you to consult their respective privacy policies before sharing any personal information.
16. Modifications to this Privacy Policy
a) KOKO WAX reserves the right to modify this Privacy Policy at any time to reflect changes in our practices, applicable laws, or services offered.
b) The most recent version is always accessible on this page, with the date of the last update indicated at the top.
c) In case of substantial changes, we will inform you in advance via email or through a prominent notice on the Site.
17. Contact
For any questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data, please contact us:
KOKO WAX — Data Protection Email: hello@kokowax.com Response time: within 30 days