Privacy policy
What's Covered in This Privacy Policy
Section 01
About This Privacy Policy
This Privacy Policy is published by FlowWells and governs how we collect, use, store, and protect the personal information of every person who visits flowwells.com, creates a customer account, or places an order. We operate exclusively within the United States and ship to all 50 states. This policy is written in plain, straightforward language — not buried in legal jargon — because we believe you deserve to know exactly what happens with your information.
This Privacy Policy applies to all personal information collected through flowwells.com, including:
All visitors to flowwells.com, whether or not they make a purchase
Registered account holders who have created a customer profile
Customers who complete a purchase through our online checkout
Individuals who contact us via email, live chat, or our contact page
Our Core Commitment: We do not sell your personal information to data brokers, advertisers, or any third party for money — and we never will. We collect only what is necessary to run our business, fulfill your order, and communicate with you. Everything we collect is described in full detail below.
Section 02
About FlowWells (The Data Controller)
FlowWells is an independently owned direct-to-consumer wellness brand headquartered in Rosemount, Minnesota. We sell the FlowWells Full-Body Shiatsu Massage Mat with Heat — an at-home massage and heat therapy device designed to bring therapist-quality relief into your daily wellness routine. Our website is built on the Shopify platform and serves customers throughout all 50 states of the United States.
Business Name
FlowWells
Mailing Address
1051 148th St W, APT 208
Rosemount, MN 55068, USA
Business Hours
Mon–Fri, 9:00 AM – 6:00 PM CST
Live Chat
Available on-site during business hours
E-Commerce Platform
Shopify Inc.
For the purposes of US data protection law, FlowWells is the entity that determines how and why your personal data is processed. We are fully responsible for the personal information we collect and are accountable for its proper handling, security, and use.
Section 03
What Information We Collect
We collect personal information in three ways: (A) information you provide to us directly, (B) information collected automatically when you use our website, and (C) information received from trusted third-party services that help us operate our store.
Information You Provide Directly
When you browse, create an account, place an order, or contact us, you may provide the following information:
Information Collected Automatically
When you visit flowwells.com, our platform (Shopify) and associated tools automatically record certain technical data. This data is necessary for the website to function and for us to understand how customers use our store:
Information We Receive from Third Parties
We receive limited, purpose-specific information from the following trusted services in connection with your use of flowwells.com:
Section 04
How We Use Your Information
We use your personal information only to operate our business and serve you as a customer. Below are every purpose for which we process your data — no hidden uses, no surprises:
Section 05
Cookies & Tracking Technologies
We use cookies and similar tracking technologies on flowwells.com to keep our website functioning, measure how it is used, and (only with your consent) support marketing activity. A cookie is a small text file stored on your device by your browser. It does not give us access to your device and cannot carry viruses.
Strictly Necessary
Required for the website to function. Enables your shopping cart, secure checkout session, and account login. These cannot be disabled without breaking core site functionality.
Analytics Cookies
Help us understand visitor behavior in aggregate — which pages are visited, how long customers stay, and where in checkout they may drop off. We use this to improve the site, not to profile individuals.
Marketing Cookies
Used to measure the effectiveness of our advertising campaigns. These cookies are only set with your explicit consent and allow ad platforms to attribute purchases to the correct campaign source.
Preference Cookies
Remember your selections such as your country/region and currency preference, so you do not have to re-enter them on each visit.
Cookie Preferences & Opt-Out: You can manage, limit, or delete cookies through your browser settings at any time. For a full list of the cookies used on flowwells.com, how long each one persists, and step-by-step instructions for managing your preferences, please visit our dedicated Cookie Policy.
Section 06
How We Share Your Information
We do not sell your personal information. We do not share it with data brokers, advertisers, or any third party for money. We share your information only to the extent necessary to operate our business and fulfill your order — as described in full below.
Recipient
Shopify Inc.
What We Share
Full order and customer data (name, address, email, order contents)
Purpose
Platform hosting, order management, payment infrastructure, and analytics
Recipient
Payment Processors (PayPal, Stripe, Apple Pay, Google Pay, Shop Pay, Venmo, Visa, Mastercard, Amex, Discover)
What We Share
Billing address, transaction amount, and payment authorization request
Purpose
To authorize and complete your payment transaction securely. Your full card number never reaches our servers.
Recipient
Shipping Carriers (USPS, UPS, FedEx, and other domestic carriers)
What We Share
Full name, delivery address, package weight and dimensions
Purpose
To create a shipping label, arrange pickup, and deliver your order to your door
Recipient
Legal Authorities
What We Share
Whatever is specifically required by a valid legal process
Purpose
To comply with a court order, subpoena, government investigation, or enforceable legal obligation
Recipient
Business Successors (in the event of a merger or acquisition)
What We Share
Customer and order data as part of the transferred business assets
Purpose
Only if FlowWells is sold, merged, or acquired. You will be notified in advance and the acquiring entity must honor this Privacy Policy.
Section 07
Third-Party Service Providers
The following platforms are used to operate flowwells.com. Each has its own independent privacy policy governing how it processes your data. We encourage you to review them directly:
Shopify Inc.
E-commerce platform, hosting, order management, payment infrastructure, and analytics
shopify.com/legal/privacyPayPal Holdings, Inc.
Payment processing for PayPal and Venmo transactions
paypal.com/us/legalhub/privacy-fullStripe, Inc.
Backend payment infrastructure powering Shop Pay and card transactions
stripe.com/privacyUS Shipping Carriers
USPS, UPS, and FedEx — used to deliver your order to your door within the United States
Each carrier publishes its own privacy policy on their corporate websiteSection 08
Data Retention
We keep your personal information only for as long as it is needed to serve the purpose for which it was collected and to meet our legal obligations. The specific retention periods we apply are listed below:
Retained to comply with IRS tax record-keeping requirements (26 U.S.C. § 6001) and applicable state sales tax laws. This includes your name, address, order contents, and transaction amounts.
Account data is retained while your account is active. If you submit a verified deletion request, your account data is deleted within 30 days (except for records we are legally required to retain).
Emails, chat logs, and support ticket records are retained for 3 years from the date the inquiry was resolved, to help us reference the history if you contact us again about the same issue.
Marketing consent is retained until you unsubscribe. Your unsubscribe record is kept indefinitely to prevent inadvertent re-enrollment. We honor unsubscribes within 10 business days per the CAN-SPAM Act.
We never store full credit or debit card numbers on our servers. Payment data is tokenized and managed entirely by our PCI DSS-compliant payment processors. Their data retention schedules govern payment card information.
Section 09
Data Security
Protecting your personal information is a responsibility we take seriously. We implement industry-standard technical and organizational safeguards to prevent unauthorized access, disclosure, loss, or destruction of your data.
SSL / TLS Encryption
All data transmitted between your browser and flowwells.com is encrypted using TLS 1.2/1.3 — the industry standard represented by the padlock icon in your browser's address bar.
PCI DSS Level 1 Compliance
FlowWells operates on Shopify's PCI DSS Level 1 certified infrastructure — the highest standard in the payment card industry. Your payment data is handled according to globally recognized security standards.
No Card Number Storage
We never store your full credit or debit card number on our servers. Your card is tokenized by our payment processor before it reaches our system, so we only ever see a masked reference number.
Access Controls
Only authorized FlowWells personnel with a legitimate business need may access customer data. All access is role-restricted, logged, and regularly reviewed to prevent unauthorized internal use.
Shopify Platform Security
Shopify maintains 24/7 automated threat monitoring, intrusion detection systems, and regular third-party security audits for all stores hosted on its platform, including flowwells.com.
Password Hashing
If you create a customer account, your password is stored as a one-way cryptographic hash. We never store your password in plain text and cannot retrieve it — only you know your password.
Important Notice: Despite our best efforts, no online system is 100% immune to security risks. In the unlikely event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities as required by applicable federal and state breach notification laws. If you have security concerns, please contact us immediately at support@flowwells.com.
Section 10
Children's Privacy (COPPA)
flowwells.com is intended exclusively for adults aged 18 and older. We do not market to, or knowingly collect personal information from, children under the age of 13, in compliance with the federal Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.).
We do not knowingly collect personal information from any person under the age of 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete that information from our records.
If you believe a child has provided us with personal information: Please contact us immediately at support@flowwells.com or via our Contact Us page. We will investigate and delete the information as quickly as possible.
Section 11
Your Federal Privacy Rights
Regardless of which state you live in, the following federal laws provide you with baseline privacy and consumer protections that FlowWells fully complies with:
You have the right to opt out of commercial email marketing at any time. Every marketing email we send includes a clear, one-click unsubscribe link. We will honor all opt-out requests within 10 business days and will not send you further marketing emails after that point.
The FTC Act prohibits deceptive or unfair practices in commerce, including misrepresentation of privacy practices. FlowWells complies fully with all FTC privacy guidance for online retailers. If we make a material change to how we use your data, we will notify you clearly and in advance.
We do not intercept, monitor, or disclose the content of your electronic communications except as required by law or with your explicit consent. Your emails to us are treated as confidential communications and are only reviewed by staff handling your inquiry.
We do not knowingly collect personal information from children under 13. Our website is designed and marketed for adult consumers only. See Section 10 for our full children's privacy statement.
Section 12
State-Specific Privacy Rights
Depending on the state in which you reside, you may have additional privacy rights under your state's comprehensive consumer data protection law. FlowWells recognizes and honors these rights for all qualifying customers, regardless of whether our size technically triggers statutory compliance thresholds. We do this because it is the right way to treat our customers.
To exercise any right listed below, please submit a request through our Privacy Rights Request Form, email us at support@flowwells.com, or write to us at our mailing address in Section 16. We will verify your identity before processing any request. We will not discriminate against you for exercising any privacy right.
California Residents
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA, effective January 1, 2023), California residents have the following rights:
Right to Know: Request disclosure of the specific personal information we have collected about you, the sources, purposes, and third parties with whom it was shared in the past 12 months.
Right to Delete: Request deletion of personal information we hold about you, subject to limited legal exceptions (such as order and tax records we are required to retain).
Right to Correct: Request correction of inaccurate personal information we hold about you.
Right to Opt Out of Sale/Sharing: Request that we stop selling or sharing your personal information for cross-context behavioral advertising. See Section 13 and our dedicated Do Not Sell or Share page.
Right to Limit Use of Sensitive Personal Information: Request that we use your sensitive personal information only for the purposes specified in CPRA. FlowWells does not collect or use sensitive personal information beyond what is necessary for the transaction.
Right to Data Portability: Receive a copy of your personal information in a portable, machine-readable format.
Right to Non-Discrimination: We will not deny you service, charge you different prices, or provide a different quality of service because you exercised a CCPA/CPRA right.
Response Time: 45 calendar days (extendable by an additional 45 days with notice). You may submit up to 2 requests per 12-month period. For authorized agent requests, we require written proof of authorization.
Virginia Residents
Under the Virginia Consumer Data Protection Act (VCDPA, effective January 1, 2023), Virginia residents have the right to: access personal data we hold about them; correct inaccuracies; delete personal data; obtain a portable copy of their data; opt out of the sale of personal data; opt out of targeted advertising; and opt out of profiling in furtherance of solely automated decisions that produce significant effects. We will respond to verified requests within 45 days, with a potential 45-day extension. If we deny your request, you may appeal our decision by contacting us at support@flowwells.com. If your appeal is denied, you may contact the Virginia Attorney General at oag.state.va.us.
Response Time: 45 days (extendable to 90 days with notice). Appeal period: 60 days from our decision.
Colorado Residents
Under the Colorado Privacy Act (CPA, effective July 1, 2023), Colorado residents have the right to: opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects; access, correct, and delete personal data; and receive personal data in a portable format. You may designate an authorized agent to make requests on your behalf. We will respond to verified requests within 45 days, with a possible 45-day extension. If your request is denied, you may appeal within 45 days. If your appeal is denied, you may contact the Colorado Attorney General at coag.gov.
Response Time: 45 days (extendable to 90 days). Global opt-out signals (such as the Global Privacy Control) are honored.
Connecticut Residents
Under the Connecticut Data Privacy Act (CTDPA, effective July 1, 2023), Connecticut residents have the right to access, correct, delete, and obtain a portable copy of personal data we process about them. You may also opt out of the sale of personal data, targeted advertising, and profiling that produces significant legal effects. We honor opt-out signals transmitted by browser-based universal opt-out mechanisms. Appeals of denied requests must be submitted within 45 days of our decision, and if denied, you may contact the Connecticut Attorney General at portal.ct.gov/AG.
Response Time: 45 days (extendable to 90 days with notice).
Texas Residents
Under the Texas Data Privacy and Security Act (TDPSA, effective July 1, 2024), Texas residents have the right to access, correct, delete, and obtain a portable copy of their personal data. You may opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling used in significant automated decisions. We honor browser-based universal opt-out signals. Requests must be submitted through our Privacy Rights Request Form. If we deny your request, you may appeal within a reasonable time. If your appeal is denied, you may file a complaint with the Texas Attorney General at texasattorneygeneral.gov.
Response Time: 45 days (extendable by an additional 45 days with notice).
Additional State Privacy Laws
The following states have enacted comprehensive consumer privacy laws. Residents of these states have rights substantially similar to those described above (access, correction, deletion, portability, opt-out of sale and targeted advertising, non-discrimination, and the right to appeal). Submit all requests through our Privacy Rights Request Form or at support@flowwells.com.
Utah Consumer Privacy Act (eff. Dec 31, 2023). Rights to access, delete, portability, and opt out of sale and targeted advertising. Response time: 45 days.
Oregon Consumer Privacy Act (eff. July 1, 2024). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
Montana Consumer Data Privacy Act (eff. Oct 1, 2024). Rights to access, correct, delete, portability, and opt out of sale and targeted advertising. Response time: 45 days.
Delaware Personal Data Privacy Act (eff. Jan 1, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and automated profiling. Response time: 45 days.
Iowa Consumer Data Protection Act (eff. Jan 1, 2025). Rights to access, delete, portability, and opt out of sale and targeted advertising. Response time: 90 days.
Nebraska Data Privacy Act (eff. Jan 1, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
New Hampshire Privacy Act (eff. Jan 1, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
New Jersey Data Protection Act (eff. Jan 15, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
Kentucky Consumer Data Protection Act (eff. Jan 1, 2026). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
Minnesota Consumer Data Privacy Act (eff. July 31, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Response time: 45 days.
Maryland Online Data Privacy Act (eff. Oct 1, 2025). Rights to access, correct, delete, portability, and opt out of sale, targeted advertising, and profiling. Prohibits processing of sensitive data without consent. Response time: 45 days.
Rhode Island Data Transparency and Privacy Protection Act (eff. Jan 1, 2026). Requires disclosure of data collected, sold, and shared. Rights to opt out of sale and targeted advertising. Response time: 45 days.
All Other States: Even if your state has not yet enacted a comprehensive consumer privacy law, we believe in treating all customers with the same transparency and respect. If you have questions about your personal data or wish to make any request regarding your information, please contact us at support@flowwells.com. We will do our best to assist you.
Section 13
Do Not Sell or Share My Personal Information
Clear Statement: FlowWells does not sell your personal information to third parties for money — not now, and not ever. This is our unconditional commitment.
Under California law (CCPA/CPRA) and similar state laws, the term "sharing" can also refer to making personal data available for cross-context behavioral advertising, even without direct payment. In the limited context of advertising analytics, certain identifiers (such as cookie IDs) may be made available to advertising platforms when you have consented to marketing cookies. This could constitute "sharing" under California law.
If you wish to opt out of the sharing of your information for these purposes, you have several options:
Visit our dedicated Do Not Sell or Share My Personal Information page and follow the opt-out instructions
Manage your cookie preferences through your browser settings to disable marketing cookies
Enable the Global Privacy Control (GPC) browser extension, which we recognize as a valid opt-out signal
Submit a written opt-out request to support@flowwells.com with the subject line "Do Not Share My Personal Information"
We will process your opt-out request within 15 business days. We will not discriminate against you in any way — including denying service, charging higher prices, or providing a lower quality of product — for exercising this right. Your opt-out preference will remain in effect until you affirmatively re-opt-in or change your cookie settings.
Section 14
Third-Party Links & External Websites
flowwells.com may contain links to external websites operated by third parties, such as our shipping carriers, payment processors, or partner resources. When you click on these links, you will leave flowwells.com and land on a website that is entirely outside FlowWells' control.
We are not responsible for the privacy practices, content, or security of any third-party website. We strongly encourage you to review the privacy policy of every external website you visit before sharing any personal information with them. The presence of a link on flowwells.com does not constitute our endorsement of that website's privacy or security practices.
Social Media & Review Platforms: If you interact with FlowWells on social media platforms (such as Facebook, Instagram, TikTok, or YouTube), those platforms operate under their own privacy policies. Information you share on those platforms is governed by the respective platform's terms and privacy policy — not by this Privacy Policy.
Section 15
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, the services we use, or applicable law. When we make changes, we will update the Effective Date shown at the top of this page.
If we make a material change — meaning a change that meaningfully affects how we collect, use, or share your personal information — we will notify you by:
Posting a prominent notice on flowwells.com and/or the Privacy Policy page itself
Sending a notification email to the address associated with your account (if you have one)
Providing at least 30 days' advance notice before material changes take effect, where practicable
Your continued use of flowwells.com after the updated Privacy Policy has been posted will constitute your acknowledgment of the changes. If you do not agree with an updated policy, you may discontinue using the website and contact us to request deletion of your account data.
Previous Versions: If you would like to review a prior version of this Privacy Policy, please contact us at support@flowwells.com and we will provide it upon request, to the extent practicable.
Section 16
Contact Us & How to Submit a Privacy Request
If you have any questions about this Privacy Policy, want to exercise a privacy right, wish to access or correct your personal information, or need to report a concern, please reach out to us through any of the following channels. We will respond promptly and respectfully to every inquiry.
Email Support
Fastest way to reach us for any privacy-related request or general question.
support@flowwells.comLive Chat
Available on the website. Mon–Fri, 9:00 AM – 6:00 PM CST (GMT-06:00 Central Standard Time).
Start Live ChatContact Page
Submit a message through our on-site contact page for written support.
flowwells.com/pages/contact-usMailing Address
For written privacy requests or legal correspondence:
FlowWells
1051 148th St W, APT 208
Rosemount, MN 55068
United States
Privacy Rights Request Form
Submit a formal request to access, correct, delete, or opt out of data processing.
Submit a RequestWhat to Include in Your Request
To help us verify your identity and process your request as quickly as possible, please include the following in your communication:
Your full name as used when placing an order or creating an account
The email address associated with your account or order
A clear description of your request (e.g., "I would like to delete my account and all associated data")
Your state of residence (required for state-specific rights requests)
Our Response Commitment
45
Days Maximum Response
(most requests answered sooner)
Free
All Privacy Requests
(no fees for exercising your rights)
0
Retaliation for Requests
(we never penalize customers)
2
Requests Per Year
(CCPA/CPRA maximum)
Related Policies & Pages