Privacy policy
Last updated: August 2026
People buy from us about something they find embarrassing. That shapes this policy more than anything else in it, so the short version is first: we collect what an order needs and nothing more, we do not sell your data, and nothing we send you names the product on the outside.
1. Discretion, in practice
- Outer packaging carries no branding and no description of the contents.
- Your card statement reads TENDI or TENDIHEALTH.COM, never a product name.
- Emails from us use plain subject lines. Order updates say “Your order”, not what is in it.
- We never ask for a photograph of your skin, and if you send one unprompted we delete it once the question is answered.
- We do not publish, quote or share anything you tell us about your own health.
2. What we collect
Because you gave it to us:
- Name, delivery address, email address and phone number, to fulfil an order.
- Order and refund history.
- Anything you write to support, and anything you enter in a review.
- Your email address if you ask for updates.
Because your browser sent it:
- IP address, device type, browser and operating system.
- Pages viewed, referring site, and time on site.
- Cookie and similar identifiers, covered in section 6.
What we never hold: your full card number, which goes directly to the payment processor and is never visible to us. And we do not ask for, and do not want, a diagnosis, a medical record, or a description of a specific growth.
3. Why we hold it
- To take payment, pack your order, and get it to the right address.
- To email you a confirmation, a dispatch notice and a tracking number.
- To answer you when you write to us, and to handle a return or a warranty claim.
- To prevent fraudulent orders and abusive refund patterns.
- To understand which pages of the site work and which do not.
- To send marketing email, but only if you asked for it.
- To meet tax, accounting and consumer-law obligations.
4. Who else sees it
Only the companies that make the order happen, and only the part each one needs:
- Shopify — the store and checkout platform.
- Shopify Payments and PayPal — payment processing and fraud screening.
- Carriers and our fulfillment partner — the name and address on the label.
- Email and helpdesk providers — to deliver order emails and hold your support conversation.
- Analytics and advertising platforms — site usage, subject to section 6.
Beyond that, we disclose personal information only when the law requires it, or if the business is ever transferred, in which case the buyer is bound by this policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising in the sense those terms are used under California law.
5. How long we keep it
- Order records: seven years, because tax law requires it.
- Support conversations: three years, or less if you ask us to delete them sooner.
- Marketing contacts: until you unsubscribe, plus a suppression record so we do not email you again by mistake.
- Analytics data: 26 months.
6. Cookies
We use:
- Essential cookies — the cart, the checkout and security. The site does not work without them and they cannot be switched off.
- Analytics cookies — how many people reach a page and where they leave.
- Advertising cookies — measuring whether an ad led to an order.
You can clear or block cookies in your browser settings, and you can turn on a Global Privacy Control signal, which we honor as an opt-out request where state law recognizes it. Blocking essential cookies will break the checkout.
7. Your rights
Depending on the state you live in, you may have the right to:
- Know what personal information we hold about you, and get a copy of it.
- Have it corrected.
- Have it deleted, subject to records we are legally required to keep.
- Opt out of targeted advertising, and of any sale or sharing of personal information.
- Not be treated differently for exercising any of these rights.
Email Hello@tendihealth.com and we will handle it within 45 days. We may need to confirm your identity first, which normally means replying from the address the order was placed with. If we ever decline a request, we will tell you why and how to appeal it.
8. Email from us
Order emails are part of the purchase and everyone gets them. Marketing email goes only to people who asked for it, and every one of those carries an unsubscribe link that works immediately. We do not send text messages unless you specifically opt in.
9. Security
The whole site runs over TLS. Payment data is handled entirely by PCI DSS compliant processors. Access to customer records is limited to the people who need it, and protected by two-factor authentication. No system is perfect, and we will not pretend otherwise, but if a breach ever affects your information we will tell you and the relevant authorities within the time the law allows.
10. Links to other sites
Where we link out, the other site’s privacy policy governs what happens there, not ours.
11. Children
This site is not for children, and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.
12. Where data is processed
Our providers process data in the United States and, in some cases, in Canada or the European Union. Where information moves across a border, contractual safeguards are in place with the provider concerned.
13. Changes
If this policy changes, the new version appears here with a new date. Where a change is significant, we email anyone whose information it affects.
14. Complaints
Come to us first, at Hello@tendihealth.com, and we will try to put it right. If you are not satisfied, you can raise it with the attorney general of your state, or with the Federal Trade Commission at ftc.gov.