Shipping message icon
FREE SHIPPING on all orders
My Favorites icon
We have upcoming maintenance
Xymogen.com will be down for 90 minutes tonight at 10:00 PM ET for scheduled maintenance. For further assistance, email us at info@xymogen.com, and one of our advisors will respond as soon as possible. Thank you for your understanding.

This policy was last updated November 13, 2024.

This California Privacy Policy (“Policy”) explains how XYMOGEN (“XYMOGEN,” “we,”“us,” or “our”) collects personal information (defined below) based on the interactions natural humans have with us via telephone, e-mail, or facsimile, as well as through our website, social media platforms, and mobile applications (non-exhaustive list). Furthermore, this Policy applies to XYMOGEN collection and use of California residents' personal information (defined below), including where such use or collection may be governed by the California Consumer Privacy Act(CCPA). Please be advised, some exceptions may apply. Where an exception applies to a request you submit, we will provide you with an explanation as to why.

I. PERSONAL INFORMATION COLLECTED IN THE PAST TWELVE MONTHS

For purposes of this Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal Information does not include de-identified or aggregate information, or public information lawfully available from governmental records. XYMOGEN collects, processes, and stores various types of Personal Information in connection with the products and services we provide.

The following chart describes the categories of personal information covered by this Policy that XYMOGEN may have collected in the past twelve (12) months and, for each category, where and why we collected it, as well as the categories of entities that we shared the personal information with.

Categories of Consumers' Personal InformationCategories of SourcesPurpose(s) for Collection of Consumers' Personal InformationCategories of Third Parties With Which Personal Information Was Shared for Business PurposeCategories of Third Parties to Which Personal Information Was Sold
Personal Identifiers – such as name, postal address, Internet Protocol address, email address, social security number, driver's license number, passport number, or other similar identifierConsumers directlyProviding products and services
Responding to consumer inquiries
Marketing and promotional services
Provide information about products purchased, including recalls
Security and fraud prevention
Service providers that assist us in providing a range of services including email services, marketing, data collection, data storage, data analytics, fraud prevention, and other business servicesSelect vendors
Advertising companies
Protected characteristics, such as genderConsumers directlyProviding products and servicesService providers
Commercial information – such as records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendenciesConsumersProviding products and services
Marketing
Improvements in merchandise selections, customer service and shopping experience
Service providers that assist us in providing a range of services including email services, marketing, data collection, data storage, data analytics, fraud prevention, and other business services that assist us in maximizing our business potentialSelect vendors
Advertising companies
Internet or other electronic network activity information, including browsing and search historyConsumers when visiting our website or app or while logged into their online accountMarketingService providers that assist us in providing a range of services including email services, marketing, data collection, data storage, data analytics, fraud prevention, and other business services that assist us in maximizing our business potentialSelect vendors
Advertising companies
Geolocation dataConsumers when connected to our in-store guest networkImprovements to customer service and shopping experience
Audio, electronic, visual informationConsumers who interact with our call centerProviding products and services
Responding to consumer inquiries
Security and crime prevention
Inferences drawn from any of the information identified to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behaviour, attitudes, intelligence, abilities, and aptitudes.Service providers that perform analyticsMarketing

With respect to each of the categories of data above, we may also collect and share personal information with third parties to comply with (i) legal obligations; (ii) when we believe in good faith that an applicable law requires it; (iii) at the request of governmental authorities or other third parties conducting an investigation; (iv) to detect and protect against fraud, or any technical or security vulnerabilities; (v) to respond to an emergency; (vi) or otherwise to protect the rights, property, safety, or security of our business, third parties, visitors to our websites and mobile apps, or the public. We may also share personal information with any person to whom we transfer any of our rights or obligations under any agreement, or in connection with a sale, merger or consolidation of our business or other transfer of our assets, whether voluntarily or by operation of law, or who is otherwise deemed to be our successor or transferee.

II. RIGHTS RELATED TO PERSONAL INFORMATION HELD BY US

Your Right to Request Disclosure of Information We Collect and Share About You

Curious about the Personal Information XYMOGEN is collecting from you? Contact us!

  • Call toll-free at 1 (800) 647-6100; or
  • E-mail privacy@xymogen.com (include your full name, mailing address, the e-mail address associated with your account, and whether you are a patient or a practitioner).

Your Right to Request Deletion of Personal Information We Have Collected from You

You have the right to request deletion of the Personal Information we collect from you. If you request that we delete your Personal Information, you will no longer receive marketing or other communications from us, except when necessary to provide you with a good or service that you requested; perform a contract we entered into with you; maintain the functionality or security of our systems; or comply with or exercise rights provided by the law.

Your Right to Ask Us Not to Sell Your Personal Information

Visit Do Not Sell or Share My Personal Information for more information.

California Shine the Light

California Civil Code Section 1798.83, also known as the 'Shine The Light' law, permits California residents to annually request information about the Personal Information (if any) disclosed to third parties for direct marketing purposes in the preceding calendar year, free of charge.

XYMOGEN Commitment to Honoring Your Rights

If you exercise any of the rights explained herein, XYMOGEN will continue to treat you fairly; you will not be denied, charged a different rate or price for, or be provided a lesser quality of goods and services.

III. EXERCISING YOUR RIGHTS AND HOW WE WILL RESPOND

To exercise any of the rights explained herein, or to ask a question, contact us by telephone at 1(800) 647-6100 or by e-mail at privacy@xymogen.com. When e-mailing us, please provide your full name, mailing address, the e-mail address associated with your account, and whether you are a patient or a practitioner. For requests for access or deletion, we will provide a substantive response to your request as soon as possible, but generally within thirty (30) business days from when we received your request. However, under certain circumstances we may be permitted to take longer; if this is the case, we will let you know. Please be advised: The law may allow us to refuse to act on certain requests; if this is the case, we will let you know. While most requests can be fulfilled free of charge, please be advised that certain requests may incur a reasonable fee to cover any administrative costs associated with providing the information requested.

IV. VERIFICATION OF IDENTITY

Requests for Specific Pieces of Personal Information

If you make a request for specific pieces of Personal Information, or if you are requesting for us to delete your Personal Information, we have the right to verify your identity by making you answer a series of questions, including, but not limited to: Your full name, mailing address, e-mail address, telephone number, account type (i.e., patient or practitioner), and the details from your most recent order. If we are unable to verify your identity with the degree of certainty required, we will not be able to respond to the request. We will notify you to explain the basis of the denial.

Authorized Agents

You may designate an agent to submit requests on your behalf. The agent can be any natural person or business entity that is registered with the California Secretary of State. Additionally, we will require that you provide us with written confirmation that you have authorized an agent to act on your behalf, and the scope of that authorization. Moreover, the agent will be required to provide us with proof of an agency relationship, which may be a declaration attesting to the agent's identity and authorization by you to act on your behalf, signed under penalty of perjury. If the agent is a business entity, it will also need to submit evidence that it is registered and in good standing with the California Secretary of State. Information to identify and verify your agent can be submitted through the same mechanism and at the same time that you submit information to verify your identity.

Please be advised: This subsection does not apply when an agent is authorized to act on your behalf pursuant to a valid power of attorney. Any such requests will be processed in accordance with California law pertaining to powers of attorney.

Requests for Household Information

For purposes of this Policy, a “Household” means a group of people living together in a single dwelling. There may be some types of personal information that can be associated with a household. Requests for access or deletion of household Personal Information must be made by each member of the household. We will verify each member of the household using the verification criteria explained above. If we are unable to verify each identity in the household with the degree of certainty required, we will not be able to respond to the request. We will notify you to explain the basis of the denial.

V. DO NOT TRACK SIGNALS

'Do Not Track' is a privacy preference that users can set in certain web browsers. We do not respond to browser or do not track signals.

VI. DIGITAL MARKETING

Visit Do Not Sell or Share My Personal Information for more information.

VII. PERSONAL INFORMATION OF MINORS

XYMOGEN believes protecting children's privacy is important. Our website is a general audience site. XYMOGEN does not knowingly collect, maintain, and/or share Personal Information from those minors we actually know to be under thirteen (13) years of age. Additionally, no part of our website (including social media platforms) has been created to target and attract minors under thirteen (13) years of age. If we actually know a minor is less than thirteen (13) years of age, we will obtain authorization from their parent or legal guardian. If the minor is between the ages of thirteen (13) and sixteen (16), we will obtain authorization from the minor. Please be advised: Children under thirteen (13) years of age should always ask their parents or legal guardians for permission before providing any Personal Information to anyone online, including XYMOGEN.com. We urge parents and legal guardians to participate in their children's online activities and use parental controls or other web filtering technologies to supervise their children's access to the internet.

VIII. HOW WE KEEP YOUR PERSONAL INFORMATION SECURE

XYMOGEN continues implementing and maintaining reasonable security measures appropriate to the nature of the personal information we collect, use, retain, transfer, or otherwise process. Our reasonable security program is implemented and maintained in accordance with applicable law and relevant standards. According to the California Department of Justice’s “California Data Breach Report”(February 2016), “there is no perfect security,” and reasonable security is a process that involves risk management rather than risk elimination. While XYMOGEN is committed to developing, implementing, maintaining, monitoring, and updating its reasonable security program, no such program can be perfect and not all risk can be reasonably eliminated. Data security incidents and breaches can occur due to vulnerabilities, criminal exploits, or other factors that cannot be reasonably prevented. Accordingly, while our reasonable security program is designed to manage data security risks and, thus, help prevent data security incidents and breaches, it cannot be assumed that the occurrence of any given incident or breach results from our failure to implement and maintain a reasonable security program for protecting your Personal Information.

IX. CHANGES TO THIS POLICY

We will review and update this Policy as required to keep current with rules and regulations, new technologies, and security standards. See the top of this page for the date of the most recent update. In certain cases, and if the changes are material, you will be notified via e-mail or by a notice conspicuously posted on our website.

X. ACCESSIBILITY

We are committed to ensuring that our communications are accessible to people with disabilities.

XI. CONTACT US

Contact our privacy team by:

  • Calling toll-free at 1 (800) 647-6100;
  • E-mail privacy@xymogen.com (include your full name, mailing address, the e-mail address associated with your account, and whether you are a patient or a practitioner); or
  • Sending mail to: XYMOGEN c/o Privacy Team 6900 Kingspointe Parkway, Orlando, FL 32819.