Privacy policy

MAROVIA

Privacy Policy

Effective Date: 18/08/2026

Last Updated: 19/08/2026

This Privacy Policy explains how Marovia collects, uses, discloses, and protects personal information about visitors to trymarovia.com and customers who purchase our products. It also describes the privacy rights available to you and how to exercise them.

Please read this Policy carefully. By using our website or purchasing our products, you acknowledge that you have read and understand this Policy.

1. Who We Are and How to Reach Us

Marovia sells dietary supplements directly to consumers in the United States through trymarovia.com. For purposes of applicable United States privacy laws, we are the business or controller responsible for the personal information described in this Policy.

Legal entity: Marovia

Mailing address: Ohio, United States

Privacy contact: hello@trymarovia.com

Website: trymarovia.com

We operate exclusively online and maintain a direct relationship with our customers. Email is our designated method for submitting privacy requests. This Policy is provided in a format intended to be accessible to consumers with disabilities; if you have difficulty accessing it, contact us and we will provide it in an alternative format.

2. Scope of This Policy

This Policy applies to personal information we collect:

       Through trymarovia.com and any associated ordering, checkout, or account pages;

       When you purchase products from us, including through a subscription or auto-refill plan;

       When you sign up for our email list or text message program;

       When you contact our customer support team; and

       Through cookies, pixels, and similar technologies used on our website.

This Policy does not apply to information collected by third parties that we do not control, including websites, platforms, or applications that we link to. See Section 19.

Our products are sold only in the United States, and this Policy is written for United States residents. We do not offer our products or services to individuals located in the European Economic Area or the United Kingdom.

3. Personal Information We Collect

3.1 Information you provide to us

       Identifiers and contact details — your name, email address, billing address, shipping address, and telephone number.

       Order and account information — the products you buy, order history, order value, account login credentials, and any subscription or auto-refill preferences you select.

       Payment information — payment card or payment account details, processed by our payment providers. See Section 10.

       Communications — the content of emails, contact form submissions, product reviews, survey responses, and customer support messages you send us, in each case where we are the intended recipient.

       Marketing preferences — your email subscription status, text message consent, and any preferences you set.

We do not solicit health information and do not intentionally collect it. We do not operate a health quiz, symptom questionnaire, or consultation service, and we do not ask about your medical conditions, diagnoses, treatments, or medications. Where a customer volunteers such information — for example, in a support email or a product review — we use it solely to respond to that customer and to fulfil the order. We do not use it for advertising, profiling, audience building, or sale, and we exclude those records from the marketing audiences described in Section 7.

3.2 Information we collect automatically

       Device and connection data — IP address, browser type and version, operating system, device type, screen size, and language settings.

       Usage data — pages viewed, products viewed, time spent on pages, referring website, search terms used on our site, cart activity, and click behavior.

       Cookie and identifier data — cookie IDs, advertising identifiers, and pixel data. See Section 5.

       Approximate location — a general geographic area (such as city, state, or region) inferred from your IP address. We do not collect precise geolocation.

3.3 Information we receive from third parties

       E-commerce and hosting platform — order, checkout, and fraud-screening data from Shopify, which hosts our store.

       Payment processors — confirmation that a payment succeeded or failed, the payment method type, and the last four digits of a card.

       Shipping and fulfillment partners — delivery status and tracking information.

       Advertising and analytics providers — aggregated campaign measurement data and, where you have engaged with our ads, limited attribution data.

       Social media platforms — information you make available when you interact with our pages or accounts, subject to that platform’s own privacy settings.

3.4 Categories of personal information

The table below lists the statutory categories of personal information used in United States state privacy laws, indicates which we collect, whether each is sold or shared as those terms are defined in Section 7, and how long we keep it. We have collected the categories marked "Yes" in the preceding 12 months.

Category

Examples

Collected

Sold or Shared

Retention

Identifiers

Name, postal address, email, phone, IP address, account ID, cookie and advertising identifiers

Yes

Yes — advertising identifiers and IP address only

Order records [7] years; account records [24] months after last activity

Customer records

Name, address, telephone number, payment card details held by our payment providers

Yes

No

[7] years from the order

Protected classification characteristics

Age, sex, race, national origin, disability, veteran status

No

No

Not applicable

Commercial information

Products purchased or considered, order history, subscription status, cart activity

Yes

Yes

[7] years from the order

Biometric information

Fingerprints, faceprints, voiceprints

No

No

Not applicable

Internet or network activity

Browsing on our site, search terms, interactions with our ads and emails

Yes

Yes

[26] months

Geolocation data

Approximate city, state, or region from IP address. Not precise geolocation.

Yes (approx.)

Yes

[26] months

Sensory data

Audio, electronic, visual, thermal, or similar recordings

No

No

Not applicable

Professional or employment information

Job title, employer, work history

No

No

Not applicable

Education information

Records covered by FERPA

No

No

Not applicable

Inferences

Product preferences and marketing audience segments drawn from purchase and browsing activity

Yes

Yes

[26] months

Sensitive personal information

Government ID numbers, financial account log-in, precise geolocation, race or ethnicity, religion, union membership, contents of messages where we are not the recipient, genetic or biometric data, health, sex life or sexual orientation

No

No

Not applicable

We do not intentionally collect sensitive personal information as that term is defined under California, Colorado, Connecticut, Texas, or other applicable state privacy laws. We do not use or disclose sensitive personal information to infer characteristics about you.

4. How We Use Personal Information

We use personal information for the following business and commercial purposes:

       Fulfilling orders — processing purchases, taking payment, arranging shipping and delivery, and handling returns, exchanges, and refunds under our satisfaction guarantee.

       Managing subscriptions — administering auto-refill plans, processing recurring charges, sending renewal and price-change notices, and processing cancellations and skips.

       Customer service — responding to your questions, resolving problems, and communicating about your orders.

       Transactional messages — sending order confirmations, shipping notifications, delivery updates, renewal reminders, and account or security notices.

       Marketing — sending promotional emails and, if you have separately consented, promotional text messages; showing you our advertising on other websites and platforms; and measuring how our advertising performs.

       Improving our website and products — analyzing how visitors use our site, testing changes, and developing new products.

       Fraud prevention and security — verifying orders, screening for fraudulent transactions and chargebacks, protecting against abuse of promotions or our guarantee, and securing our systems.

       Legal and compliance — meeting our legal obligations, keeping records required by law, responding to lawful requests, and establishing or defending legal claims.

Transactional messages are not marketing. We send them by email while you have an active order or subscription, and unsubscribing from marketing email does not stop them. If you opt out of our text message program, we will stop sending you automated texts of every kind, including transactional ones, and will use email and your account page instead.

We will not use your personal information for a materially different purpose than those described here without first notifying you and, where required by law, obtaining your consent.

5. Cookies, Pixels, and Tracking Technologies

We and our service providers use cookies, pixels, tags, software development kits, and similar technologies on trymarovia.com. These fall into the following groups:

       Strictly necessary — required to operate the site, hold items in your cart, keep you logged in, and process checkout securely. These cannot be turned off through our site.

       Analytics and performance — help us understand which pages are viewed, how visitors move through the site, and where problems occur.

       Advertising and retargeting — set by the advertising platforms named in Section 7 to show you Marovia ads on other websites and apps, to build advertising audiences, and to measure whether an ad led to a purchase.

You can control cookies through our cookie preferences tool and through your browser settings. Blocking strictly necessary cookies will prevent parts of the site from working, including checkout.

Global Privacy Control and other universal opt-out signals. We honor opt-out preference signals, including Global Privacy Control (GPC), transmitted by your browser or a browser extension. When we detect such a signal we treat it as a request to opt out of the sale and sharing of personal information and of targeted advertising for that browser and device. Because the signal is tied to the browser, you will need to enable it on each browser and device you use. If you are logged into an account when we receive the signal, we will also apply the opt-out to that account.

We do not respond to browser "Do Not Track" signals, which have no agreed industry standard. We do respond to GPC as described above.

6. How We Disclose Personal Information

We do not exchange personal information for money. In the preceding 12 months we disclosed the categories of personal information identified in Section 3.4 to the recipients below.

6.1 Service providers and processors

These recipients act on our behalf and are contractually restricted to using personal information only to perform services for us. They may not sell it or use it for their own purposes:

       Payment processors — to authorize and settle payments and to screen for fraud.

       Shipping and fulfillment providers — to pick, pack, and deliver your order, including carriers.

       Email and SMS marketing providers — to send the messages you have signed up for.

       Analytics providers — to measure and improve site performance.

       Customer support and reviews platforms — to handle your inquiries and publish reviews you choose to submit.

       Professional advisors — accountants, auditors, insurers, and lawyers, where reasonably necessary.

6.2 Independent parties

These recipients determine their own purposes for at least some of the information they receive, and the contractual restrictions above do not fully apply to them:

       Shopify — hosts our store and processes orders on our behalf, and also processes certain data for its own purposes, including payments, fraud analysis, and its own product features. Shopify’s own privacy policy governs that processing.

       Advertising platforms — receive identifiers and activity data as third parties, not as our service providers. This is why the activity described in Section 7 may constitute a "sale" or "sharing."

6.3 Legal and corporate disclosures

       Legal and safety recipients — courts, regulators, and law enforcement, where we are legally required to disclose information or where disclosure is necessary to protect our rights, your safety, or the safety of others.

       Successors in a business transaction — if Marovia is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will update this Policy and give notice where the law requires it.

7. "Sale," "Sharing," and Targeted Advertising

We do not exchange personal information for money.

However, when we use the advertising and retargeting technologies described in Section 5, identifiers and internet activity information are made available to advertising platforms so they can show you Marovia ads and measure their effectiveness. Under the California Consumer Privacy Act and several other state privacy laws, this activity may be considered a "sale" or "sharing" of personal information for cross-context behavioral advertising, or targeted advertising.

The categories of personal information involved are identifiers (cookie and advertising identifiers and IP address), commercial information (products viewed and purchased), internet or network activity, and inferences used to build advertising audiences.

The advertising platforms that receive this information are: Meta, Google, TikTok etc. We name them individually because Rhode Island law requires a website operator that sells personal information to identify the third parties to which it may be sold.

We do not sell or share, or use for targeted advertising, the personal information of any individual we know or should reasonably know is under 18 years of age.

You have the right to opt out. You can do so by:

1.       Selecting "Your Privacy Choices" or "Do Not Sell or Share My Personal Information" in the footer of every page of trymarovia.com;

2.       Enabling Global Privacy Control in your browser, which we honor automatically as described in Section 5; or

3.       Emailing hello@trymarovia.com with the subject line "Opt Out of Sale/Sharing."

We act on opt-out requests as soon as feasibly possible and no later than 15 business days after receipt.

We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use under California law.

8. Marketing Communications

8.1 Email

If you sign up for our email list or make a purchase, we may send you promotional emails about products, offers, and content. Every marketing email contains an unsubscribe link. You can also email hello@trymarovia.com to be removed. We will process your request promptly and in any event within ten business days.

8.2 Text messages

We send promotional text messages only to individuals who have given prior express written consent to receive them. Consent to receive marketing texts is not a condition of any purchase. When you opt in, you agree to receive recurring automated marketing text messages from Marovia at the number you provide. Message frequency varies. Message and data rates may apply.

You may revoke consent at any time and by any reasonable means. To stop messages, reply STOP to any message from us, or email hello@trymarovia.com. Reply HELP for assistance. We will honor an opt-out request as soon as practicable and no later than ten business days after receipt. A revocation applies to all automated calls and texts we would otherwise send you, including transactional messages; we will contact you by email instead. We retain a record of your consent and of any opt-out request.

We do not sell or rent telephone numbers collected for our text message program, and we do not disclose them to third parties for those parties’ own marketing.

9. Subscription and Auto-Refill Plans

If you enroll in a subscription or auto-refill plan, we retain the information needed to administer it, including your plan selection, delivery cadence, shipping address, order history, and a payment token held by our payment processor so that recurring charges can be made.

Before you enroll, we present the material terms of the plan — what you receive, how often, the amount and timing of charges, the cancellation method, and any minimum commitment — clearly and conspicuously, and we obtain your affirmative consent to those terms separately from any other terms. We send you an acknowledgment you can retain.

Cancelling. If you enrolled online, you may cancel online, immediately and without speaking to anyone, using the cancellation link in your account. You may also cancel by emailing hello@trymarovia.com. We process cancellations promptly and, where a charge has not yet been initiated, before the next scheduled charge.

Notices you will receive. We send a reminder before renewal in accordance with applicable state automatic renewal laws, an annual reminder for plans that renew for a year or more, and advance notice of between 7 and 30 days before any price increase or other material change to your plan, each in a form you can retain.

We retain records of your enrollment consent for at least three years, or one year after the plan ends, whichever is longer, and your subscription transaction records for the period stated in Section 11.

10. Payment Information

Payments are processed by third-party payment providers, including those made available through Shopify. Marovia does not receive or store your full payment card number, card verification value, or bank account credentials.

We receive and retain only limited payment details, such as the payment method type, the last four digits of the card, the expiration date, the billing address, and whether a transaction succeeded or failed. For subscription plans, our payment provider stores a token that allows us to charge your payment method for future orders without our holding the underlying card data.

Our payment providers are contractually required to maintain compliance with the Payment Card Industry Data Security Standard, and Marovia maintains the level of PCI DSS compliance applicable to a merchant that does not handle card data directly.

11. How Long We Keep Personal Information

Section 3.4 sets out our retention period for each category of personal information. Expressed by record type, our periods are:

       Order and transaction records7 years from the date of the order, to meet tax, accounting, and product liability record-keeping requirements.

       Customer account records — for as long as your account is active, and then 24 months after your last order or login, unless you ask us to delete them sooner.

       Subscription enrollment consent records — three years, or one year after the plan ends, whichever is longer.

       Marketing contact details and consent records — until you unsubscribe or opt out, and then5 years for the limited purpose of evidencing that consent was given and honored.

       Customer support correspondence36 months from the date the matter is closed.

       Website analytics and advertising data26 months from collection, or the shorter period set by the relevant provider.

       Privacy request records — at least 24 months, as required by California regulations.

       Suppression lists — indefinitely. When you unsubscribe, opt out, or ask us to delete your information, we must keep a minimal record of your email address or phone number so that we do not contact you again. This is the one record that survives a deletion request, and it is used for no other purpose.

We may retain information for longer where we are required to do so by law, or where it is necessary to establish, exercise, or defend a legal claim, or to investigate a security incident.

12. How We Protect Personal Information

We maintain a written information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, and loss. Our program is designed to reasonably conform to IST CYBERSECURITY FRAMEWORK, CIS CRITICAL SECURITY CONTROLS, OR ISO/IEC 27001, one of the frameworks enumerated in the Ohio Data Protection Act, Ohio Rev. Code § 1354.02. Our safeguards include:

       Encryption of data in transit using TLS across our website and checkout;

       Access controls that limit personal information to personnel who need it, with multi-factor authentication on administrative accounts;

       Vendor due diligence and written contractual security obligations for our service providers;

       Logging and monitoring of administrative access to our store and customer records; and

       A documented incident response procedure.

No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security. We ask that you help protect your account by choosing a strong, unique password and notifying us at hello@trymarovia.com if you believe your account has been compromised.

Security incidents. If a breach of the security of the system compromises unencrypted personal information and creates a material risk of identity theft or other fraud, we will notify affected individuals without unreasonable delay and no later than the shortest deadline required by the law of your state of residence. That deadline is 45 days in Ohio under Ohio Rev. Code § 1349.19 and 30 days in several states, including California, Colorado, Florida, and Washington. We will also make any notification required to state Attorneys General and consumer reporting agencies.

13. Your Privacy Rights

If you are a resident of a state whose comprehensive privacy law applies to us, you have the rights below. If your state has no such law, or its thresholds do not reach us, we will still consider your request and will honor it wherever we reasonably can.

       Right to know or access — to confirm whether we process your personal information and to obtain a copy, together with the categories of information, sources, purposes, and recipients.

       Right to correct — to have inaccurate personal information corrected.

       Right to delete — to have your personal information deleted, subject to legal exceptions such as completing a transaction, complying with a legal obligation, or detecting security incidents. As explained in Section 11, we keep a minimal suppression record so that a deletion request does not result in your being contacted again.

       Right to data portability — to receive your personal information in a portable and, where technically feasible, readily usable format.

       Right to opt out of sale, sharing, and targeted advertising — as described in Section 7.

       Right to a list of recipients — residents of Oregon and Minnesota may request a list of the specific third parties to which we have disclosed their personal data; residents of Delaware may request the categories of third parties.

       Rights relating to profiling — to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in this type of profiling. Minnesota residents additionally have the right to question the result of any such profiling, to learn what would have produced a different outcome, and to have the data used reviewed and corrected.

       Right to limit use of sensitive personal information — available where we hold sensitive personal information about you. As stated in Section 3, we do not intentionally collect it.

       Right to non-discrimination — we will not deny you goods or services, charge you a different price, or provide you a different level of quality because you exercised a privacy right, except in connection with a financial incentive we have disclosed to you under Section 14.2.

       Right to appeal — to appeal a decision we make about your request, as described below.

13.1 How to submit a request

Submit a request by emailing hello@trymarovia.com with the subject line "Privacy Request," or by writing to us at the mailing address in Section 1. Please tell us which right you wish to exercise and the state in which you reside.

We will confirm receipt within 10 business days and respond within 45 days. If we need more time, we will tell you within that period and may extend it by up to an additional 45 days, explaining why. Opt-out requests are handled faster: we act on them as soon as feasibly possible and no later than 15 business days, and they do not require verification.

13.2 Verification

To protect your information, we must verify your identity before acting on a request to know, correct, delete, or port. We will normally ask you to confirm details already in our records, such as the email address used to place an order, and may ask for additional information for requests involving more sensitive data. We use the information you provide solely to verify you and to maintain the record of your request that the law requires us to keep. If we cannot verify you, we will tell you and explain why.

13.3 Authorized agents

You may use an authorized agent to submit a request on your behalf. We will require written permission signed by you, and we may ask you to verify your own identity directly with us. This does not apply to a request made through an opt-out preference signal such as Global Privacy Control, which we honor without requiring proof of authorization.

13.4 Appeals

If we decline your request, you may appeal by replying to our decision or by emailing hello@trymarovia.com with the subject line "Privacy Appeal" within a reasonable time. We will respond in writing within 45 days with our decision and the reasons for it. If we deny your appeal, we will provide a method for you to contact your state Attorney General to submit a complaint.

14. State-Specific Disclosures

14.1 California

This Policy serves as our notice at collection. The categories of personal information we collect, the purposes for which we use them, whether each is sold or shared, our retention periods, and the categories of recipients are set out in Sections 3.4, 4, 6, and 11. We do not intentionally collect sensitive personal information. We do not sell personal information for money, but some advertising activity may constitute a sale or sharing as explained in Section 7.

Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for those parties’ own direct marketing purposes. We do not make such disclosures. You may confirm this by emailing hello@trymarovia.com.

14.2 Financial incentives

We offer different type of discounts and offers. Participation is entirely voluntary. When you join, we collect YOUR EMAIL ADDRESS AND PURCHASE HISTORY, and you may withdraw at any time by unsubscribing or by emailing hello@trymarovia.com, without penalty to any purchase already made.

We have made a good-faith estimate that the value of the personal information involved is approximately equal to the value of the incentive offered. We offer the incentive because it supports a direct relationship with our customers, and the difference in price is reasonably related to that value.

14.3 Washington and Nevada — consumer health data

Washington’s My Health My Data Act and Nevada Revised Statutes Chapter 603A regulate "consumer health data," which can include inferences about health drawn from purchases of supplements or from browsing product pages. As stated in Section 3.1, we do not solicit health information, and we do not knowingly draw or use health-related inferences for advertising. 

Washington and Nevada residents may exercise the rights in Section 13 in relation to any consumer health data we hold, including the right to withdraw consent and the right to have the data deleted.

14.4 Nevada — opt out of sale

Nevada residents may direct us not to sell certain covered information under NRS 603A.340. We do not sell covered information as defined by Nevada law. Our designated request address for this purpose is hello@trymarovia.com. We will respond to a verified request within 60 days, and may extend that period by 30 days where reasonably necessary, in which case we will tell you.

14.5 Other states

Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — have the rights listed in Section 13, in each case as provided by and subject to the exceptions in their own state law. Use the request process in Section 13.1. Florida’s Digital Bill of Rights applies only to businesses above a revenue threshold that Marovia does not meet.

14.6 Ohio

Ohio has not enacted a comprehensive consumer privacy law. As an Ohio-based business we comply with Ohio’s data breach notification statute, Ohio Rev. Code § 1349.19, and the Ohio Consumer Sales Practices Act, Ohio Rev. Code § 1345.02. We extend the rights in Section 13 to Ohio residents as a matter of policy.

15. Children’s Privacy

Our website and products are intended for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18 years of age. We do not sell or share, or use for targeted advertising, the personal information of any individual we know or should reasonably know is under 18.

If you believe a child has provided us with personal information, please contact hello@trymarovia.com and we will delete it promptly.

Our supplements are formulated for adults. Nothing in this Policy is medical advice, and you should consult a healthcare professional before beginning any supplement.

16. Where Your Information Is Processed

We are based in Ohio, United States, and we process personal information in the United States. Some of our service providers may process or store data in other countries. Where they do, we require them by contract to protect the information consistently with this Policy and applicable law.

17. Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects about you using automated processing alone. We use automated fraud screening tools at checkout, which may flag, hold, or decline an order. If an order is declined on that basis you may contact us at hello@trymarovia.com and a member of our team will review the decision.

18. Complaints

If you are not satisfied with how we have handled your personal information or your request, contact us first at hello@trymarovia.com and we will try to resolve it. You also have the right to contact the Attorney General of your state, and Ohio residents may contact the Ohio Attorney General’s Consumer Protection Section.

19. Third-Party Websites and Platforms

Our website may link to, or embed content from, third-party websites and platforms, including social media. We do not control those third parties and are not responsible for their privacy practices. Their handling of your information is governed by their own privacy policies, which we encourage you to read.

20. Changes to This Policy

We review this Policy at least once every 12 months and update it when our practices change. When we do, we revise the Last Updated date at the top and post the new version.

If we make a material change — for example, if we begin collecting a new category of personal information, use it for a materially different purpose, or change your rights — we will post a prominent notice on our website before the change takes effect and will obtain your consent where the law requires it.

21. Contact Us

Questions or requests about this Policy or our handling of personal information:

Email: hello@trymarovia.com
Mail: Marovia, Attn: Privacy, Ohio, USA