Privacy Policy
Describe only categories actually collected by the live site.
Recipients and processors come from a maintained inventory.
Sensitive AI scenarios get a separate supplemental notice and consent layer.
User controls route through the real request and consent mechanisms.
Privacy Policy
SanYuan Herbs uses personal information to operate the website, process orders, answer questions, maintain security and provide features that a user chooses to use.
This policy describes our actual information-handling practices.
It is not intended to claim that every privacy law applies to every user.
Where a regional law applies, we provide the rights and notices required for that user and processing activity.
Privacy Contact: Not publicly specified · Privacy Contact Channel
Plain-Language Summary
Depending on how you use SanYuan Herbs, we may process information related to:
- website use;
- account;
- checkout/order;
- delivery;
- payment status;
- customer support;
- newsletter/marketing choices;
- cookie/analytics preferences;
- AI tongue/constitution features if you choose them.
We aim to collect only information reasonably necessary for the stated purpose.
Who We Are
Brand: SanYuan Herbs
Website: https://sinoherbhealth.com/
Legal Entity: Not publicly specified · Legal Entity Name
Registered Address: Not publicly specified · Registered Address
Privacy Contact: Not publicly specified · Privacy Contact Channel
The legal role under a particular law may be described as:
- controller;
- business;
- organization;
- APP entity
only when applicable.
Information We Collect
Account Information
Possible:
- name;
- email;
- account identifier;
- password hash/authentication data;
- saved addresses;
- account preferences.
Exact:
Not publicly specified · Account Data Categories
Order Information
Possible:
- products ordered;
- order number;
- billing/shipping address;
- country;
- contact details;
- fulfillment status;
- refund/return records.
Exact:
Not publicly specified · Order Data Categories
Payment Information
Payments may be processed by third-party payment services.
P055 must clearly distinguish:
SanYuan receives: Not publicly specified · Merchant Payment Data
Payment processor receives: Not publicly specified · Processor Payment Data
Never ask users to submit:
- full card number;
- CVV;
- banking password
through general contact forms.
Customer Support
Possible:
- contact details;
- order number;
- message;
- product/SKU;
- attachments.
If a user voluntarily includes sensitive information:
handle it according to the applicable privacy/safety workflow.
The ordinary Contact form should not request unrelated medical information.
Device / Technical Information
Depending on actual systems:
- IP address;
- browser/device;
- timestamps;
- security logs;
- cookie IDs;
- session/cart data;
- analytics events.
Exact:
Not publicly specified · Technical Data Categories
How We Collect Information
Potential sources:
- directly from you;
- your browser/device;
- WooCommerce/website functions;
- payment provider;
- delivery/carrier provider;
- customer-support system;
- analytics/consent systems;
- AI vendors when you use the AI feature;
- anti-fraud/security providers.
Do not list a vendor until used.
Why We Use Information
Provide the Service
- account;
- cart;
- checkout;
- fulfillment;
- support.
Security / Fraud Prevention
- authentication;
- abuse prevention;
- troubleshooting;
- logs.
Legal / Compliance
- accounting;
- tax;
- consumer claims;
- legal requests;
- required records.
Marketing
Only according to the user’s choices and applicable law.
Analytics
Only according to the actual consent/legal configuration.
AI Feature
Only for purposes disclosed at the point of collection and in P072.
Legal Bases / Privacy Grounds
For jurisdictions using legal-basis concepts, the exact basis depends on purpose.
Potential:
- contract;
- consent;
- legitimate interests where lawful;
- legal obligation;
- other lawful basis.
Purpose-to-basis matrix: Not publicly specified · Legal Basis Matrix
Do not use “legitimate interests” as a universal fallback.
Orders, Payments & Shipping
Order data may need to be provided to:
- payment processor;
- fulfillment/warehouse;
- shipping carrier;
- tax/accounting providers
where actually used.
The public policy should identify real recipient categories and, where required, specific entities.
Marketing
Marketing is separate from ordinary customer support.
A purchase or contact message does not automatically mean:
“subscribe me to all marketing.”
Marketing preferences:
Not publicly specified · Marketing Consent Model
Users should have a functional way to:
- unsubscribe;
- withdraw consent where consent is used;
- object/opt out where applicable.
Cookies & Similar Technologies
See:
Cookie Policy
P057 contains:
- cookie/storage technology;
- provider;
- purpose;
- duration;
- necessary vs optional;
- consent category.
P055 summarizes privacy implications.
For UK users, current ICO guidance reflects PECR and UK GDPR requirements; non-essential storage/access technologies generally require appropriate transparency and consent unless an exception applies.
AI Tongue & Constitution Features
Tongue images and AI-derived constitution information require a dedicated privacy treatment.
Read: AI Assessment Privacy & Consent
P072 must state:
- what image/data is collected;
- whether processing is local/server/cloud;
- vendors;
- region;
- purpose;
- retention;
- deletion;
- access;
- training choice;
- inference data;
- cross-border transfer;
- consent.
No Silent Training Assumption
Do not write:
“your images may be used to improve our models”
without a real lawful/consent model.
Training choice:
Not publicly specified · Ai Training Policy
AI Data Retention
Not publicly specified · Ai Retention Policy
AI Deletion
Not publicly specified · Ai Deletion Process
Service Providers
Maintain a processor/vendor register.
Potential categories:
- hosting/CDN;
- ecommerce;
- payments;
- email;
- analytics;
- consent management;
- customer support;
- shipping;
- AI/cloud;
- security.
Public disclosure:
Not publicly specified · Processor Disclosure Model
The phrase “we never share data” is inaccurate if processors receive personal information.
Sale / Sharing / Targeted Advertising
The words “sell” and “share” can have specific legal meanings.
SanYuan must audit:
- analytics tags;
- ad pixels;
- remarketing;
- cross-context behavioral advertising;
- data broker relationships;
- GPC handling.
Current status:
Not publicly specified · Sale Share Status
If CCPA applies and activities trigger opt-out rights:
implement:
- notice at collection;
- privacy policy rights;
- Do Not Sell or Share process;
- GPC handling
as required.
Do not display a fake opt-out link if there is no backend.
International Transfers
Because SanYuan serves users in multiple markets and may use international providers, personal information may cross borders depending on actual architecture.
Disclose:
- relevant recipient/provider;
- destination where required/practicable;
- transfer mechanism/safeguard where applicable.
Transfer matrix: Not publicly specified · International Transfer Matrix
Retention
Do not use one vague retention sentence for every category.
Maintain:
| Data | Purpose | Retention Trigger | Period/Criteria |
|---|---|---|---|
| Account | account service | closure/inactivity | Not publicly specified · Account Retention |
| Orders | transaction/legal | order/legal period | Not publicly specified · Order Retention |
| Support | case | closure | Not publicly specified · Support Retention |
| Marketing | preference | unsubscribe/withdrawal | Not publicly specified · Marketing Retention |
| Analytics | analytics | event/cookie | Not publicly specified · Analytics Retention |
| AI image | AI feature | consent/process | Not publicly specified · Ai Image Retention |
| AI inference | result/history | feature | Not publicly specified · Ai Inference Retention |
| Security logs | security | event/log | Not publicly specified · Security Log Retention |
Retention must be implemented, not merely written.
Security
We use organizational and technical safeguards appropriate to the actual systems.
Potential controls:
- encryption in transit;
- access control;
- least privilege;
- MFA for admins;
- patching;
- backups;
- logging;
- processor contracts;
- upload scanning.
Do not claim:
“100% secure.”
Current security summary:
Not publicly specified · Security Controls
Your Privacy Rights and Choices
Rights depend on the law that applies.
Potential rights can include:
- access/know;
- correction;
- deletion;
- portability;
- withdraw consent;
- object;
- opt out of sale/sharing;
- limit certain sensitive-data uses;
- complaint;
- non-discrimination.
Request route: Not publicly specified · Privacy Contact Channel
Identity Verification
Verification must be proportionate.
Do not request a government ID by default.
United Kingdom
Where UK GDPR/PECR applies, privacy information should explain:
- controller;
- purposes/legal bases;
- recipients;
- retention;
- transfers;
- rights;
- complaint route
and provide cookie/storage controls as required.
ICO guidance emphasizes clear notices and appropriate consent for non-essential storage/access technologies, subject to current exceptions.
California / United States
The US has sector/state-specific privacy laws rather than one general federal GDPR equivalent.
If SanYuan falls within the CCPA’s scope for California consumers, current California guidance includes rights such as:
- know;
- delete;
- correct;
- opt out of sale/sharing;
- limit certain uses of sensitive personal information where applicable;
- non-discrimination.
Applicability:
Not publicly specified · Ccpa Applicability
Other state laws:
Not publicly specified · Us State Privacy Matrix
Canada
Where PIPEDA or applicable provincial privacy law applies, SanYuan should implement:
- accountability;
- meaningful consent;
- limited collection/use/disclosure;
- safeguards;
- access/correction;
- breach obligations.
Canada’s Privacy Commissioner emphasizes meaningful consent and collecting only for legitimate necessary purposes.
Australia
If SanYuan is an APP entity/otherwise subject to the Privacy Act, the APP framework requires an up-to-date, clearly expressed policy covering personal-information handling and certain overseas disclosures.
Current OAIC guidance also notes future APP 1 automated-decision privacy-policy obligations beginning 10 December 2026 for covered significant automated decisions.
P055 should prepare the data inventory now, but must not claim those future obligations already apply before their commencement or if SanYuan is not in scope.
Children
Current rule:
Not publicly specified · Children Privacy Rule
The store should not intentionally collect child-sensitive/AI image data without an approved age/parental process where required.
AI feature:
separate age gate/consent in P072.
Privacy Complaints
Use:
Not publicly specified · Privacy Complaint Process
If the applicable law provides a regulator complaint route:
state it accurately for that market.
Changes to This Policy
Update the policy when actual practices change.
Do not refresh date only for CSS/typos.
Last updated: Not publicly specified · Policy Last Updated
Material changes may require:
- new notice;
- new consent
depending on the processing/legal basis.