Version 3.0 · Last updated 31 August 2026 · SeaVitalis Inc., 318 SW 76th Ter, North Lauderdale, Florida 33068, United States
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what you can do about any of it. We have tried to write it so that a person can actually read it.
1. The short version
- Right now we collect a name, an email address, and a phone number only if you offer one.
- We use it to tell you when we open. Nothing else.
- We do not sell your personal data, and we never have.
- Optional cookies stay off until you switch them on.
- We use AI tools to help write and design. A person checks everything. No machine decides anything about you.
- Email support@seavitalis.com and we will delete you on request, no questions asked.
2. Who we are
SeaVitalis Inc. is the controller of the personal data described here — we decide why and how it is processed. Post: 318 SW 76th Ter, North Lauderdale, Florida 33068, United States. Email: support@seavitalis.com, which reaches a person, not a queue.
3. What we collect
When you join the waiting list. Your name and email address, which we need in order to write to you. Your phone number, only if you choose to give it. Whether you asked for a text message. The page you signed up from, and the date and time.
When you contact us. Whatever you put in your message, and the address or number it came from.
When you order, once we open. Billing and delivery address, what you bought, and your order history. Payment is handled by Shopify and its payment processors. We never see or store your card number.
While you browse. IP address, device and browser type, operating system, screen size, referring page, pages viewed, time on page, and an approximate location derived from your IP. Some of this is collected by Shopify to run and secure the store. The rest runs only if you consent to analytics cookies.
4. What we deliberately do not collect
We do not collect health data, biometrics, race, religion, political opinions, sexual orientation, trade union membership, precise GPS location, government identifiers, or card numbers. We do not buy personal data from brokers, and we do not build profiles about you from outside sources. If you send us any of the above unprompted, we will delete it.
5. Why we use it, and our legal basis
- To tell you we have launched — your consent, which you can withdraw at any time.
- To take and fulfil an order — performance of our contract with you.
- To answer a support message — performance of our contract, or our legitimate interest in running a business that replies to people.
- To keep the site secure and prevent fraud — our legitimate interest in not being defrauded, weighed against your privacy.
- To measure how the site is used — your consent, through the cookie banner.
- To send marketing email or texts — your consent, withdrawable at any time.
- To keep tax, accounting and consent records — our legal obligations.
6. Cookies and similar technologies
Four categories. You control three of them:
- Strictly necessary — session handling, security, fraud prevention, and remembering your cookie choice. These run without consent because the site cannot work without them.
- Analytics — which pages get read, where visitors arrive from, where they give up. Off until you say yes.
- Marketing — whether an advert worked, and not showing you the same one repeatedly. Off until you say yes.
- Preferences — remembering settings like region so you do not set them twice. Off until you say yes.
Change your mind whenever you like through Cookie Settings in the footer. Switching a category off also clears the cookies it had already set. We record your choice, the date, and the policy version it applied to, and we ask again after twelve months.
Global Privacy Control. If your browser sends a GPC signal we treat it as an opt-out of marketing and of any "sale" or "sharing", automatically, and we do not show you a banner at all.
7. Artificial intelligence and automated decisions
You are entitled to know where software shapes what you see or what happens to you, so here it is plainly.
- Words and pictures. We use AI tools to help draft and edit copy for this site and our marketing, and to help produce some images and video. A person reviews and approves everything before it is published. Portraits and illustrations on this site are stylised artwork, not photographs presented as real, and where an image is materially AI-generated we say so where it appears.
- Fraud screening. Once we take orders, Shopify scores each one for fraud risk automatically. A person reviews anything flagged before we hold or cancel it. The machine does not get the final say.
- Support replies. We may use AI to help draft answers. A person reads, edits and sends every one.
- Analytics. We may group visitors into broad, non-identifying segments, such as "arrived from search". We do not score, rank or profile you as an individual.
- No automated decisions about you. We do not make decisions producing legal effects, or similarly significant effects, about you by automated means alone. If that ever changes we will update this policy and tell you before it does.
- Your data is not training data. We do not sell or supply your personal data to AI developers for model training, and where a supplier offers to use customer data to improve its own models, we switch that off. We require the same of our processors.
If you want to know how any automated process affected you, ask and we will explain it in plain language.
8. Who we share it with
Only the services that make the business work, and only what each one needs:
- Shopify — commerce platform and hosting. Holds customer, order and store analytics data.
- Payment processors — take payment and screen for fraud. They receive card details directly; we do not.
- Shipping carriers — name and delivery address, so a parcel arrives.
- Email and SMS providers — to send the messages you asked for.
- Google Analytics — only if you consent to analytics cookies.
- Accountants and lawyers — bound by professional confidentiality.
- Authorities — where the law requires it, and no further than it requires.
- An acquirer — if the business is sold or merged, subject to this policy.
Each of these is bound by a written agreement limiting them to our instructions.
9. We do not sell or share your personal data
We do not sell your personal data for money, and we do not rent, trade or hand it to data brokers. Some US privacy laws define "sale" and "sharing" broadly enough to cover advertising cookies even where no money changes hands. To be unambiguous: if you consent to marketing cookies, that may amount to "sharing for cross-context behavioural advertising" under those definitions. You can withdraw at any time through Cookie Settings, or by sending a Global Privacy Control signal, which we honour automatically. We do not knowingly sell or share the data of anyone under 16.
10. Where your data goes
We are a United States company and our suppliers are largely US-based, so your data will be processed in the United States. For personal data originating in the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, together with supplementary measures where a transfer risk assessment calls for them. Where a supplier is additionally certified under the EU–US Data Privacy Framework we may rely on that as a secondary basis, but we do not treat it as our only one. Ask us which mechanism applies to a given supplier and we will tell you.
11. How long we keep it
- Waiting list — until launch and twelve months after, or until you ask us to delete it, whichever comes first.
- Orders and tax records — seven years, because tax law requires it.
- Marketing contacts — until you unsubscribe, then a minimal suppression record so we do not contact you again by mistake.
- Support correspondence — twenty-four months.
- Consent records — twenty-four months, as evidence of what you agreed to.
- Analytics — our providers' retention settings, currently a maximum of fourteen months in Google Analytics.
12. Security, and what happens if something goes wrong
The site runs over HTTPS throughout. Card data never touches our systems. Access to customer data is limited to people who need it, through named accounts with two-factor authentication. We use established processors rather than building our own storage.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your data we will notify you and the relevant regulator within the deadlines that apply to us — under Florida law, individuals within thirty days and the Attorney General where more than five hundred Floridians are affected; under the GDPR, the supervisory authority within seventy-two hours of becoming aware, and you without undue delay where the risk to you is high.
13. Your rights, wherever you live
As a matter of company policy, and regardless of whether a particular law compels us, we will honour a request from anyone to see the data we hold about them, correct it, delete it, receive a copy in a portable format, object to or restrict how we use it, or withdraw consent. Email support@seavitalis.com. We aim to acknowledge within one business day and to resolve within thirty days. We will not charge you and we will not treat you worse for asking.
14. If you are in the EEA, the UK or Switzerland
The rights above are yours under the GDPR and UK GDPR, and withdrawing consent does not affect processing already carried out. We respond within one month, extendable by two further months for genuinely complex requests, and we will tell you if we need the extension. If you are unhappy with our response you may complain to your national data protection authority, or to the Information Commissioner's Office in the United Kingdom. You do not have to come to us first, though we would rather you did.
15. If you are in the United States
Several states — California, Colorado, Connecticut, Virginia, Texas, Oregon and others — grant privacy rights to their residents once a business passes certain size or revenue thresholds. SeaVitalis does not currently meet those thresholds, so most of those statutes do not yet apply to us. We are telling you that rather than implying a coverage we do not have. The rights in section 13 are offered to you anyway, and we will comply with each statute in full as soon as it applies to us. You may use an authorised agent. If we ever decline a request we will explain why and you may appeal by replying to that decision.
16. Marketing email and text messages
We email you only if you asked us to, and every marketing email carries a working unsubscribe link and our postal address.
If you tick the SMS box, you are agreeing to receive recurring automated marketing text messages from SeaVitalis at the number you gave us. Consent to texts is never a condition of buying anything, is never pre-ticked, and is never assumed from a purchase. Message frequency varies. Message and data rates may apply. Reply STOP at any time to cancel, or HELP for help. We keep a record of when you consented and what wording you were shown, and we act on a STOP promptly.
17. Children
This site is not directed at children. We do not knowingly collect data from anyone under 16 in the EEA or UK, or under 13 in the United States. If you believe a child has given us their data, email us and we will delete it.
18. Changes to this policy
If we change this policy materially we will update the version and date above, and where the change affects you meaningfully we will email you and ask for fresh cookie consent. Earlier versions are available on request.
19. Contact and complaints
Privacy questions, data requests and complaints: support@seavitalis.com. If we cannot resolve something, you can escalate to your data protection authority in the EEA or UK, or to your state Attorney General in the United States.
This policy describes how SeaVitalis actually operates and is written to be useful rather than defensive. It is not legal advice. Before selling into the EU, the UK or California, have a qualified privacy lawyer review it against your operations.