Skip to main content
Eligible orders over US$80 ship free by sea No minimum order US · UK · CA · AU
SanYuan Herbs · current evidence and product facts take priority
Privacy Canonical · Real Data Flows Only

Privacy Policy

This policy is built around the data SanYuan Herbs actually uses across WordPress, WooCommerce, payments, support, marketing, analytics, cookies and AI features—not a generic GDPR template.
P055 = site-wide privacy ownerP057 = cookies/storage detailP072 = AI tongue-photo noticeUnknown processing stays unknown
01Do not claim we never share data if service providers receive it
02Do not claim we do not use cookies before the stack is audited
03AI image retention/training statements must match the real implementation
04Rights and legal bases remain jurisdiction- and applicability-specific
DATA MAPAccount / Order / Support

Describe only categories actually collected by the live site.

PROCESSORSPayment / Hosting / Email

Recipients and processors come from a maintained inventory.

AITongue / Constitution Features

Sensitive AI scenarios get a separate supplemental notice and consent layer.

CONTROLRights / Deletion / Preferences

User controls route through the real request and consent mechanisms.

Privacy Policy

SanYuan Herbs uses personal information to operate the website, process orders, answer questions, maintain security and provide features that a user chooses to use.

This policy describes our actual information-handling practices.

It is not intended to claim that every privacy law applies to every user.

Where a regional law applies, we provide the rights and notices required for that user and processing activity.

Privacy Contact: Not publicly specified · Privacy Contact Channel


Plain-Language Summary

Depending on how you use SanYuan Herbs, we may process information related to:

  • website use;
  • account;
  • checkout/order;
  • delivery;
  • payment status;
  • customer support;
  • newsletter/marketing choices;
  • cookie/analytics preferences;
  • AI tongue/constitution features if you choose them.

We aim to collect only information reasonably necessary for the stated purpose.


Who We Are

Brand: SanYuan Herbs

Website: https://sinoherbhealth.com/

Legal Entity: Not publicly specified · Legal Entity Name

Registered Address: Not publicly specified · Registered Address

Privacy Contact: Not publicly specified · Privacy Contact Channel

The legal role under a particular law may be described as:

  • controller;
  • business;
  • organization;
  • APP entity

only when applicable.


Information We Collect

Account Information

Possible:

  • name;
  • email;
  • account identifier;
  • password hash/authentication data;
  • saved addresses;
  • account preferences.

Exact:

Not publicly specified · Account Data Categories


Order Information

Possible:

  • products ordered;
  • order number;
  • billing/shipping address;
  • country;
  • contact details;
  • fulfillment status;
  • refund/return records.

Exact:

Not publicly specified · Order Data Categories


Payment Information

Payments may be processed by third-party payment services.

P055 must clearly distinguish:

SanYuan receives: Not publicly specified · Merchant Payment Data

Payment processor receives: Not publicly specified · Processor Payment Data

Never ask users to submit:

  • full card number;
  • CVV;
  • banking password

through general contact forms.


Customer Support

Possible:

  • contact details;
  • order number;
  • message;
  • product/SKU;
  • attachments.

If a user voluntarily includes sensitive information:

handle it according to the applicable privacy/safety workflow.

The ordinary Contact form should not request unrelated medical information.


Device / Technical Information

Depending on actual systems:

  • IP address;
  • browser/device;
  • timestamps;
  • security logs;
  • cookie IDs;
  • session/cart data;
  • analytics events.

Exact:

Not publicly specified · Technical Data Categories


How We Collect Information

Potential sources:

  • directly from you;
  • your browser/device;
  • WooCommerce/website functions;
  • payment provider;
  • delivery/carrier provider;
  • customer-support system;
  • analytics/consent systems;
  • AI vendors when you use the AI feature;
  • anti-fraud/security providers.

Do not list a vendor until used.


Why We Use Information

Provide the Service

  • account;
  • cart;
  • checkout;
  • fulfillment;
  • support.

Security / Fraud Prevention

  • authentication;
  • abuse prevention;
  • troubleshooting;
  • logs.

Legal / Compliance

  • accounting;
  • tax;
  • consumer claims;
  • legal requests;
  • required records.

Marketing

Only according to the user’s choices and applicable law.

Analytics

Only according to the actual consent/legal configuration.

AI Feature

Only for purposes disclosed at the point of collection and in P072.


Legal Bases / Privacy Grounds

For jurisdictions using legal-basis concepts, the exact basis depends on purpose.

Potential:

  • contract;
  • consent;
  • legitimate interests where lawful;
  • legal obligation;
  • other lawful basis.

Purpose-to-basis matrix: Not publicly specified · Legal Basis Matrix

Do not use “legitimate interests” as a universal fallback.


Orders, Payments & Shipping

Order data may need to be provided to:

  • payment processor;
  • fulfillment/warehouse;
  • shipping carrier;
  • tax/accounting providers

where actually used.

The public policy should identify real recipient categories and, where required, specific entities.


Marketing

Marketing is separate from ordinary customer support.

A purchase or contact message does not automatically mean:

“subscribe me to all marketing.”

Marketing preferences:

Not publicly specified · Marketing Consent Model

Users should have a functional way to:

  • unsubscribe;
  • withdraw consent where consent is used;
  • object/opt out where applicable.

Cookies & Similar Technologies

See:

Cookie Policy

P057 contains:

  • cookie/storage technology;
  • provider;
  • purpose;
  • duration;
  • necessary vs optional;
  • consent category.

P055 summarizes privacy implications.

For UK users, current ICO guidance reflects PECR and UK GDPR requirements; non-essential storage/access technologies generally require appropriate transparency and consent unless an exception applies.


AI Tongue & Constitution Features

Tongue images and AI-derived constitution information require a dedicated privacy treatment.

Read: AI Assessment Privacy & Consent

P072 must state:

  • what image/data is collected;
  • whether processing is local/server/cloud;
  • vendors;
  • region;
  • purpose;
  • retention;
  • deletion;
  • access;
  • training choice;
  • inference data;
  • cross-border transfer;
  • consent.

No Silent Training Assumption

Do not write:

“your images may be used to improve our models”

without a real lawful/consent model.

Training choice:

Not publicly specified · Ai Training Policy

AI Data Retention

Not publicly specified · Ai Retention Policy

AI Deletion

Not publicly specified · Ai Deletion Process


Service Providers

Maintain a processor/vendor register.

Potential categories:

  • hosting/CDN;
  • ecommerce;
  • payments;
  • email;
  • analytics;
  • consent management;
  • customer support;
  • shipping;
  • AI/cloud;
  • security.

Public disclosure:

Not publicly specified · Processor Disclosure Model

The phrase “we never share data” is inaccurate if processors receive personal information.


Sale / Sharing / Targeted Advertising

The words “sell” and “share” can have specific legal meanings.

SanYuan must audit:

  • analytics tags;
  • ad pixels;
  • remarketing;
  • cross-context behavioral advertising;
  • data broker relationships;
  • GPC handling.

Current status:

Not publicly specified · Sale Share Status

If CCPA applies and activities trigger opt-out rights:

implement:

  • notice at collection;
  • privacy policy rights;
  • Do Not Sell or Share process;
  • GPC handling

as required.

Do not display a fake opt-out link if there is no backend.


International Transfers

Because SanYuan serves users in multiple markets and may use international providers, personal information may cross borders depending on actual architecture.

Disclose:

  • relevant recipient/provider;
  • destination where required/practicable;
  • transfer mechanism/safeguard where applicable.

Transfer matrix: Not publicly specified · International Transfer Matrix


Retention

Do not use one vague retention sentence for every category.

Maintain:

DataPurposeRetention TriggerPeriod/Criteria
Accountaccount serviceclosure/inactivityNot publicly specified · Account Retention
Orderstransaction/legalorder/legal periodNot publicly specified · Order Retention
SupportcaseclosureNot publicly specified · Support Retention
Marketingpreferenceunsubscribe/withdrawalNot publicly specified · Marketing Retention
Analyticsanalyticsevent/cookieNot publicly specified · Analytics Retention
AI imageAI featureconsent/processNot publicly specified · Ai Image Retention
AI inferenceresult/historyfeatureNot publicly specified · Ai Inference Retention
Security logssecurityevent/logNot publicly specified · Security Log Retention

Retention must be implemented, not merely written.


Security

We use organizational and technical safeguards appropriate to the actual systems.

Potential controls:

  • encryption in transit;
  • access control;
  • least privilege;
  • MFA for admins;
  • patching;
  • backups;
  • logging;
  • processor contracts;
  • upload scanning.

Do not claim:

“100% secure.”

Current security summary:

Not publicly specified · Security Controls


Your Privacy Rights and Choices

Rights depend on the law that applies.

Potential rights can include:

  • access/know;
  • correction;
  • deletion;
  • portability;
  • withdraw consent;
  • object;
  • opt out of sale/sharing;
  • limit certain sensitive-data uses;
  • complaint;
  • non-discrimination.

Request route: Not publicly specified · Privacy Contact Channel

Identity Verification

Verification must be proportionate.

Do not request a government ID by default.


United Kingdom

Where UK GDPR/PECR applies, privacy information should explain:

  • controller;
  • purposes/legal bases;
  • recipients;
  • retention;
  • transfers;
  • rights;
  • complaint route

and provide cookie/storage controls as required.

ICO guidance emphasizes clear notices and appropriate consent for non-essential storage/access technologies, subject to current exceptions.


California / United States

The US has sector/state-specific privacy laws rather than one general federal GDPR equivalent.

If SanYuan falls within the CCPA’s scope for California consumers, current California guidance includes rights such as:

  • know;
  • delete;
  • correct;
  • opt out of sale/sharing;
  • limit certain uses of sensitive personal information where applicable;
  • non-discrimination.

Applicability:

Not publicly specified · Ccpa Applicability

Other state laws:

Not publicly specified · Us State Privacy Matrix


Canada

Where PIPEDA or applicable provincial privacy law applies, SanYuan should implement:

  • accountability;
  • meaningful consent;
  • limited collection/use/disclosure;
  • safeguards;
  • access/correction;
  • breach obligations.

Canada’s Privacy Commissioner emphasizes meaningful consent and collecting only for legitimate necessary purposes.


Australia

If SanYuan is an APP entity/otherwise subject to the Privacy Act, the APP framework requires an up-to-date, clearly expressed policy covering personal-information handling and certain overseas disclosures.

Current OAIC guidance also notes future APP 1 automated-decision privacy-policy obligations beginning 10 December 2026 for covered significant automated decisions.

P055 should prepare the data inventory now, but must not claim those future obligations already apply before their commencement or if SanYuan is not in scope.


Children

Current rule:

Not publicly specified · Children Privacy Rule

The store should not intentionally collect child-sensitive/AI image data without an approved age/parental process where required.

AI feature:

separate age gate/consent in P072.


Privacy Complaints

Use:

Not publicly specified · Privacy Complaint Process

If the applicable law provides a regulator complaint route:

state it accurately for that market.


Changes to This Policy

Update the policy when actual practices change.

Do not refresh date only for CSS/typos.

Last updated: Not publicly specified · Policy Last Updated

Material changes may require:

  • new notice;
  • new consent

depending on the processing/legal basis.