Privacy & Data Protection

Privacy Policy

Clear information about how Your Serenity, Inc. collects, uses, protects, retains, and shares personal information.

Effective date: September 12, 2026  •  Last updated: September 12, 2026

Your Serenity, Inc. (“Your Serenity,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information when you visit https://yourserenityinc.com/ (the “Site”), shop with us, create or use an account, contact us, or otherwise interact with us online or offline.

“Personal information” in this Policy means information that identifies you, relates to you, describes you, can reasonably be linked with you or your household, or is otherwise treated as personal data under applicable law. It does not include information that has been aggregated or de-identified so that it cannot reasonably be linked to you.

This Policy does not govern independent third-party websites, applications, or services that we do not control. Their privacy notices govern their handling of personal information.

1. Who is responsible for your information

Your Serenity, Inc. is responsible for the personal information covered by this Policy.

Privacy Officer
Your Serenity, Inc.
120 Kisco Avenue, Suite X
Mt. Kisco, NY 10594
United States
Email: info@yurkovsky.com
Phone: (914) 861-9161

For privacy requests, use the subject line Privacy Request and state your country and U.S. state or Canadian province of residence.

2. A short summary

  • We collect information you give us, including contact, account, order, delivery, and communication information.
  • We automatically receive limited device, network, usage, referral, cart, security, and analytics information when you use the Site.
  • Clover processes the card-entry fields used for online payments. We ordinarily receive limited transaction details rather than your full card number or card security code.
  • We use personal information to operate the Site, process and deliver orders, provide customer service, prevent fraud and abuse, understand Site performance, comply with law, and protect our rights.
  • We disclose information to providers that help us run the Site and fulfill orders, including payment, hosting, ecommerce, analytics, security, media, email, and delivery providers.
  • We do not sell personal information for money. Certain analytics or embedded-media disclosures may be treated as “sale,” “sharing,” or targeted advertising under some U.S. state laws, even when no money changes hands. Where applicable, you can opt out through Your Privacy Choices and Global Privacy Control.
  • We do not ask you to send medical records or other highly sensitive information through general forms, email, or order notes.
  • Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your information; withdraw consent; object or opt out of certain processing; or appeal a decision.

3. Personal information we collect

The information we collect depends on how you interact with us.

A. Information you provide directly

Contact and identity information. Your first and last name, email address, telephone number, billing address, shipping address, country, state or province, city, and postal code.

Order and commercial information. Products viewed, placed in a cart, purchased, returned, or discussed; order number; transaction date and amount; delivery details; discount or promotion information; order notes; return, warranty, and customer-service history.

Payment-related information. Payment method, payment status, transaction identifier, card brand, and limited card details such as the last digits where provided by our payment processor. Card-entry fields at checkout are hosted and processed by Clover. We ordinarily do not receive or store the full payment-card number or card security code entered into those fields.

Account information. Username, email address, password or authentication information in protected form, account preferences, and account/order history. Please keep your credentials confidential.

Communications. The subject and content of contact-form messages, emails, calls, letters, customer-service requests, and other information you choose to provide.

Site search and preferences. Search queries entered on the Site, cookie and privacy choices, and other preferences you select.

B. Information collected automatically

When you use the Site, we and our providers may automatically collect:

  • IP address and approximate location derived from it;
  • browser, device type, operating system, language, screen size, and user-agent information;
  • pages viewed, links or buttons selected, search activity, dates and times, session duration, and navigation paths;
  • referring and exit pages, campaign and UTM parameters, source/medium, and similar order-attribution information;
  • cart contents, cart and session identifiers, login state, and cookie choices;
  • media-player interactions;
  • diagnostic, security, bot-detection, fraud-prevention, and error information; and
  • analytics information about how visitors use the Site.

We collect this information through server logs, cookies, pixels, tags, local storage, embedded content, and similar technologies. See Cookies and similar technologies below.

C. Information from other sources

We may receive information from:

  • Clover and other participants in the payment-processing chain, such as payment status, transaction details, and fraud or risk signals;
  • shipping and delivery providers, such as delivery status and address corrections;
  • technology, security, hosting, support, and analytics providers;
  • referral URLs and campaign links; and
  • public authorities or other parties when reasonably necessary to prevent fraud, comply with law, or protect legal rights.

D. Sensitive and health-related information

Please do not send Social Security numbers, government identification numbers, passwords, full payment-card details, medical records, diagnoses, treatment information, or other highly sensitive information through our contact form, email, order notes, or other general communication channels.

We do not intentionally use product purchases, browsing activity, messages, or other information to diagnose a condition, create a health profile, or target advertising based on a person’s health. If you voluntarily include health-related information in a message, we will use it only as reasonably necessary to respond to your request, provide a product or service you requested, comply with law, or protect safety and legal rights. We may delete or redact information that is not needed.

If we change our services so that we intentionally collect or use consumer health data, we will provide any separate notice and obtain any consent required by applicable law before doing so.

4. How and why we use personal information

We use personal information for the purposes below. Where a law requires a legal basis, the basis may include performing a contract with you, taking steps you request before entering a contract, complying with a legal obligation, pursuing a legitimate interest that is not overridden by your rights, or obtaining your consent.

  • Operate the Site, cart, checkout, search, and account features. We use account, cart/session, device, search, and usage information. Legal basis where required: contract and legitimate interests in operating our business and Site.
  • Process payments and fulfill orders. We use contact, billing, shipping, order, transaction, and payment-related information. Legal basis where required: contract, steps requested before a contract, and legal obligations.
  • Deliver products and handle returns, warranties, recalls, and support. We use contact, delivery, order, communication, and commercial information. Legal basis where required: contract, legitimate interests, and legal obligations.
  • Respond to questions and communicate with you. We use contact and communication information. Legal basis where required: steps requested by you, contract, and legitimate interests.
  • Secure the Site and prevent fraud, spam, abuse, and unauthorized access. We use device/network, account, transaction, security, and risk information. Legal basis where required: legitimate interests and legal obligations.
  • Measure and improve Site performance and understand visitor activity. We use device, usage, referral, campaign, and analytics information. Legal basis where required: consent; otherwise legitimate interests.
  • Maintain business, tax, accounting, warranty, and compliance records. We use contact, order, transaction, support, and consent records. Legal basis where required: legal obligations, contract, and legitimate interests.
  • Establish, exercise, or defend legal claims and protect people, property, and rights. We use relevant information described in this Policy. Legal basis where required: legal obligations and legitimate interests.
  • Send marketing that you request or that applicable law permits. We use contact details and marketing preferences. Legal basis where required: consent; otherwise legitimate interests permitted by law.
  • Complete a business transaction such as a merger, financing, or asset sale. We use relevant business and customer records. Legal basis where required: legitimate interests and legal obligations.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that occurred before withdrawal. We will not use personal information for a materially different, incompatible purpose without additional notice and, where required, consent.

We do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects for you. Payment and security providers may use automated systems to identify possible fraud or abuse under their own notices.

5. Cookies and similar technologies

We use cookies and related technologies to keep the store working, protect forms and checkout, remember choices, measure performance, and display embedded media.

Strictly necessary

These technologies maintain cart and session state, authenticate accounts, provide checkout, remember security and privacy choices, and protect the Site. Examples include WooCommerce cart and session cookies such as woocommerce_items_in_cart, woocommerce_cart_hash, and wp_woocommerce_session_*. They are always active because the requested Site and ecommerce functions depend on them.

Analytics

Analytics technologies measure visits, device and browser characteristics, referral and campaign data, pages viewed, and Site interactions. Current examples include Google Analytics and Pirsch Analytics. Pirsch states that it does not use cookies, but it processes limited request information to create a short-lived pseudonymous visitor measure. Analytics is activated only with consent where required; otherwise it is controlled through Cookie Settings and browser choices.

Media and functionality

These technologies display third-party video or other embedded content and may measure interaction with it. The Site currently uses the Vimeo embedded player. These technologies are activated only with consent where required, or when you choose to load the content.

Security and fraud prevention

These technologies detect bots, spam, suspicious activity, and payment or account abuse. Current examples include Cloudflare Turnstile and Google reCAPTCHA; reCAPTCHA may set the necessary _GRECAPTCHA cookie when executed. They are used where reasonably necessary to protect forms, checkout, users, and the Site.

The complete list can change as the Site changes. Our Cookie Settings interface should show the current technologies, purposes, providers, and durations.

Your cookie and tracking choices

Where required, our consent interface allows you to Accept All, Reject Non-Essential, or Customize technologies. You can change your choice later through the Cookie Settings or Your Privacy Choices link in the Site footer. Withdrawing consent does not remove cookies already stored on your device, so you may also need to delete them through your browser settings.

Most browsers let you block or delete cookies. Blocking strictly necessary technology may prevent the cart, checkout, login, security, video, or other functions from working correctly.

Do Not Track and Global Privacy Control

Some browsers send a “Do Not Track” signal. Because there is no generally accepted standard for interpreting that signal, we do not treat Do Not Track alone as a privacy request.

Where applicable law requires it, we recognize a valid Global Privacy Control (GPC) signal as a request to opt out of sale, sharing, or targeted advertising for the browser or device that sends the signal. You may also use Your Privacy Choices or contact us to make a broader request.

6. Analytics, media, payment, and security providers

The following services are relevant to the current Site:

Google Analytics and Google Tag Manager. We use Google tools to deploy approved tags and understand Site activity. Depending on our configuration and your choices, Google Analytics may process first-party cookie identifiers, browser/device information, IP address during collection, approximate location, referrer, and Site activity. Google states that Analytics customers can control retention, advertising personalization, product linking, and data-sharing settings. Learn more in Google’s Analytics data safeguards and Google Privacy Policy.

Pirsch Analytics. We use Pirsch to measure Site traffic. Pirsch describes its service as cookie-free. It uses information including IP address, user agent, date, and a site-specific salt to create a pseudonymous daily visitor hash; Pirsch states that it does not store the IP address and cannot recognize the same visitor for more than 24 hours across that site-specific process. It may record page path, referrer, campaign parameters, time, browser, operating system, country/city, device type, and screen size. Learn more in Pirsch’s privacy documentation.

Vimeo. The Site embeds a Vimeo video player. When loaded, Vimeo may receive device, network, cookie, player, and interaction information and may place cookies or use similar technology. Learn more in Vimeo’s Privacy Policy and Cookie Policy.

Clover. Clover processes online payment-card fields and receives information needed to authorize and complete transactions, detect fraud, and comply with payment-network and legal requirements. This can include card, cardholder, transaction, merchant, device, and risk information. Clover may share transaction data with banks, card networks, and other payment-chain participants. Learn more in Clover’s Privacy Notice.

Cloudflare Turnstile. Turnstile helps distinguish legitimate visitors from automated abuse and may process device, browser, network, challenge, and security information. Cloudflare states that Turnstile does not harvest data for ad retargeting. Learn more in Cloudflare’s Privacy Policy and Turnstile overview.

Google reCAPTCHA. reCAPTCHA helps identify automated or abusive activity, particularly at checkout. Google states that reCAPTCHA sets a necessary _GRECAPTCHA cookie when executed for risk analysis. Its use is subject to the Google Privacy Policy and Terms of Service.

7. When we disclose personal information

We may disclose personal information to the following recipients for the purposes described in this Policy:

  • Website hosting, ecommerce, database, backup, maintenance, and support providers: contact, account, order, communications, device, logs, and Site content to host, secure, maintain, back up, and operate the Site and WooCommerce store.
  • Payment processors and payment-chain participants, including Clover: payment-card, cardholder, billing, transaction, device, and risk information to authorize payments, prevent fraud, process refunds or chargebacks, and comply with payment rules.
  • Shipping, logistics, and delivery providers: name, shipping address, contact details, order contents, and delivery instructions to fulfill and deliver orders and resolve delivery issues.
  • Analytics, tag-management, and performance providers, including Google and Pirsch: online identifiers, device/browser, IP or approximate location, referral, campaign, page, and interaction information to measure, attribute, secure, and improve the Site.
  • Media and embedded-content providers, including Vimeo: device/network, cookie or similar identifiers, and player interactions to display video and provide related functionality.
  • Security, spam, and fraud-prevention providers, including Cloudflare and Google: device, browser, network, request, challenge, and risk information to protect forms, checkout, accounts, transactions, and the Site.
  • Email, communications, and customer-support providers: contact information, message content, and support history to send transactional messages and respond to requests.
  • Professional advisers, insurers, auditors, and accountants: information relevant to the engagement to obtain professional services, maintain records, and protect legal rights.
  • Government authorities, courts, law enforcement, and other lawful recipients: information required or reasonably necessary to comply with law, legal process, tax duties, recalls, safety needs, or enforceable requests.
  • Parties to a business transaction: relevant business and customer records subject to appropriate safeguards to evaluate or complete a merger, acquisition, financing, reorganization, bankruptcy, or asset transfer.
  • Other recipients you direct or authorize: information covered by your direction or consent to complete the request you make.

Providers may process information in countries other than your own. They process information under their own privacy notices and, where applicable, agreements with us and legal duties appropriate to their role.

8. Sale, sharing, and targeted advertising

We do not sell personal information for money.

We may disclose online identifiers and internet or electronic activity to analytics and embedded-media providers as described above. Some U.S. state privacy laws define “sale,” “sharing,” or “targeted advertising” broadly enough to include certain disclosures made without a monetary payment. Where those laws apply, you may opt out through Your Privacy Choices, by enabling Global Privacy Control, or by contacting us.

We do not knowingly sell or share the personal information of anyone under 16 for cross-context behavioral advertising. We do not use information that reveals or concerns a person’s health for targeted advertising.

Supplemental U.S. state disclosure

For transparency, the following describes the categories of personal information relevant to the Site during the 12 months preceding the “Last updated” date. These terms may have specific meanings under applicable U.S. state privacy laws.

Identifiers and customer-record information. Examples include name, email, phone, postal address, IP address, account identifier, and username. Sources include you, your browser or device, and payment and delivery providers. We use this information for Site and account operation, orders, delivery, support, security, and records. Recipient categories include hosting/ecommerce, payment, delivery, communications, analytics, security, and advisers.

Commercial information. Examples include products viewed, carted, purchased, returned, or discussed, along with order, warranty, and support history. Sources include you, Site activity, and payment and delivery providers. We use it for fulfillment, returns, support, accounting, measurement, and fraud prevention. Recipient categories include ecommerce, payment, delivery, analytics, support, and advisers.

Internet or other electronic-network activity. Examples include page and search activity, interactions, browser/device data, referrer, campaign or UTM information, and session data. Sources include your browser or device, cookies and tags, and analytics, media, and security providers. We use it for Site operation, attribution, analytics, security, and improvement. Recipient categories include hosting/ecommerce, analytics, tag management, media, and security providers.

Approximate geolocation. Country, region, or city may be inferred from an IP address. Sources include your browser or device and analytics, payment, and security providers. We use it for localization, analytics, fraud prevention, and security. Recipient categories include hosting, analytics, payment, and security providers.

Payment and account security information. Examples include account login credentials in protected form; payment method, transaction ID, card brand, and limited card details; and full card details submitted directly to Clover. Sources include you, Clover, and the account system. We use it for authentication, payment, refunds, fraud prevention, and legal compliance. Recipient categories include ecommerce/authentication providers, Clover, banks, card networks, and fraud providers.

Communications and content you provide. Examples include contact messages, email, order notes, support requests, and any information you voluntarily include. The source is you. We use it to respond, fulfill requests, provide support, maintain records, protect safety, and protect legal rights. Recipient categories include hosting/ecommerce, forms, email/support providers, and advisers as necessary.

Limited inferences. General product or content interests may be inferred from Site activity if an approved analytics feature creates them. We use these limited inferences for Site measurement and improvement; we do not intentionally build health profiles or use these inferences for significant automated decisions. Recipient categories include analytics providers.

We have not sold these categories for money. As described above, disclosures of identifiers, internet activity, approximate location, or limited inferences to analytics or embedded-media providers may be treated as sale, sharing, or targeted advertising under some laws. We do not use sensitive personal information to infer characteristics about you beyond the limited purposes permitted by applicable law. We do not offer a data-based financial-incentive or loyalty program at this time.

9. Retention

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide requested services, maintain appropriate records, comply with legal and tax duties, resolve disputes, prevent fraud, enforce agreements, and protect rights. We then delete, anonymize, or securely dispose of it, subject to backup cycles and legal holds.

Our target retention periods are:

  • Completed orders, payments, refunds, returns, warranties, tax, and accounting records: up to 7 years after the transaction or matter closes, unless law requires longer.
  • Customer account and profile data not required as an order record: while the account is active and up to 24 months after the last account activity.
  • Contact-form, email, phone, and customer-support inquiries not part of an order record: up to 24 months after the last interaction or closure of the matter.
  • User-level or event-level analytics data: up to 14 months where the service permits; aggregate or de-identified statistics may be retained longer.
  • Routine security, diagnostic, and access logs: up to 12 months, unless needed longer to investigate an incident or protect legal rights.
  • Cookie-consent and privacy-choice records: up to 3 years or as otherwise needed to demonstrate and honor the choice.
  • Privacy-request and appeal records: at least 24 months and longer where required to document compliance or resolve a dispute.
  • Marketing subscription data: until you unsubscribe or consent is withdrawn; a limited suppression record may be retained as needed to honor the opt-out.

Actual retention can be shorter. We may retain a record longer when subject to a legal hold, an unresolved transaction or dispute, a product recall or warranty need, tax or accounting law, fraud prevention, or another lawful requirement. Backups are protected and removed on their normal rotation unless preservation is legally required.

10. Security

We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we handle. Measures may include encrypted transmission, access controls, authentication, updates and patching, backups, vendor oversight, limited employee access, and incident-response procedures.

No website, transmission method, or storage system is completely secure. We cannot guarantee absolute security. You are responsible for using a unique password, protecting your account credentials, signing out of shared devices, and notifying us if you suspect unauthorized account activity.

11. International processing

Your Serenity is located in the United States. If you visit from another country, your personal information may be transferred to, stored in, or processed in the United States and other countries where our providers operate. Privacy laws in those countries may differ from the laws where you live.

Where applicable law requires a transfer safeguard, we and our providers use an available lawful mechanism, such as contractual protections or another recognized basis. You may contact us for additional information about safeguards relevant to your information.

12. Your privacy rights and choices

Depending on where you live and subject to legal exceptions, you may have the right to:

  • confirm whether we process your personal information;
  • access or know the categories and specific pieces of personal information we hold about you;
  • learn the categories of sources, purposes, and recipients involved;
  • correct inaccurate personal information;
  • delete personal information;
  • obtain a portable copy of certain information;
  • withdraw consent where processing is based on consent;
  • object to or request restriction of certain processing;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive personal information;
  • appeal a decision we make about a request;
  • use an authorized agent where permitted; and
  • receive equal service and not be unlawfully discriminated against for exercising a privacy right.

These rights are not absolute. For example, we may need to retain order information to complete a transaction, honor a warranty or recall, detect fraud, comply with tax or other law, or establish or defend legal claims.

How to submit a request

Email info@yurkovsky.com with the subject Privacy Request, write to the Privacy Officer at the address above, or call (914) 861-9161. Tell us the right you wish to exercise and your country and state or province of residence.

We may ask for information reasonably necessary to verify your identity and match you to our records. We will use verification information only for the request. An authorized agent may be required to provide proof of authority, and we may confirm the request directly with you when permitted. Do not send a copy of government identification unless we specifically request it and provide a secure method.

We will respond within the time required by applicable law. If we deny a request, you may appeal by replying to our decision with the subject Privacy Appeal. We will explain the result and, where required, how to contact the appropriate regulator.

Marketing choices

You may unsubscribe from marketing email by using the link in the message or contacting us. An opt-out does not stop transactional or service messages, such as order, delivery, security, or policy notices. The current Site may not offer a marketing subscription; this paragraph applies if we introduce one.

Canadian residents

Subject to applicable Canadian law, you may request access to personal information we hold, ask us to correct it, withdraw consent subject to legal or contractual limits, and challenge our compliance. If you are not satisfied after contacting our Privacy Officer, you may contact the Office of the Privacy Commissioner of Canada, or the applicable provincial privacy regulator.

European Economic Area, United Kingdom, and Switzerland

Where applicable, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also complain to the data-protection authority where you live or work or where you believe a violation occurred. If we rely on legitimate interests, you may request information about the balancing of those interests. We do not currently engage in solely automated decisions producing legal or similarly significant effects as described above.

13. Children’s privacy

The Site is intended for a general adult audience and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13. If you believe a child has provided personal information to us, contact us so we can review and, where appropriate, delete it. We do not knowingly sell or share personal information of individuals under 16 for cross-context behavioral advertising.

14. Third-party links

The Site may link to third-party websites or services, including maps, manufacturers, social platforms, or other resources. Selecting a link may allow the third party to collect information directly from you. We do not control independent third parties, and this Policy does not govern them. Review their privacy notices before providing information.

15. Changes to this Policy

We may update this Policy to reflect changes in our practices, technology, services, vendors, or law. We will post the revised version on this page and update the “Last updated” date. If a change is material, we will provide additional notice appropriate to the change, such as a prominent Site notice or direct communication, and obtain consent when required.

16. Contact us

Questions, complaints, and privacy requests may be sent to:

Privacy Officer
Your Serenity, Inc.
120 Kisco Avenue, Suite X
Mt. Kisco, NY 10594
United States
Email: info@yurkovsky.com
Phone: (914) 861-9161