Your privacy, plainly explained.
This Privacy Policy explains what personal information Milky Tallow collects, why we collect it, how we use and protect it, and the choices and rights you have. We keep data collection to what we genuinely need to run the business.
Last updated: June 2026
The basics.
Milky Tallow ("Milky Tallow," "we," "us," or "our") is a small-batch skincare business based in British Columbia, Canada, operating this website and online store. We are the party responsible for the personal information collected through this site. This Policy applies to information we collect on our website, through purchases, and through related communications. It does not apply to third-party websites we link to, which have their own policies.
Questions about this Policy or your information can be sent to privacy@milkytallow.com or through our Contact page.
2. Information We CollectWhat we collect — and how.
Information you give us
Your name, email address, shipping and billing addresses, phone number, account login details, order and purchase history, loyalty/rewards activity, product reviews or other content you submit, newsletter sign-ups, and the contents of messages you send us.
Handled by processors
When you pay, your card or account details are collected and processed directly by our payment providers (e.g., Stripe, PayPal). We do not store full payment card numbers on our servers — we receive only limited confirmation and transaction data.
Technical & usage data
IP address, device and browser type, operating system, referring pages, pages viewed, and similar analytics data, collected through cookies and similar technologies. See our Cookie Policy.
Service-provider data
We may receive related information from our payment processors, shipping carriers, analytics providers, and (if you engage with us there) social media platforms — used to fulfill orders and improve our service.
We do not knowingly collect sensitive personal information (such as health, biometric, or government ID data) and ask that you not send it to us.
3. Why We Use ItHow we use your information.
- Fulfill orders: process purchases, payments, shipping, returns, and confirmations.
- Accounts & rewards: create and manage your account and loyalty points.
- Customer service: respond to questions, requests, and support issues.
- Marketing (with consent): send newsletters, offers, and updates you can opt out of at any time.
- Improve our site: understand usage, troubleshoot, and develop products and features.
- Security & fraud prevention: protect our site, customers, and business.
- Legal compliance: meet tax, accounting, consumer-protection, and other legal obligations.
Our legal basis (Canada): We rely on your consent and on collection/use that a reasonable person would consider appropriate in the circumstances, as set out in Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws (including BC's PIPA). Where required, we obtain express consent (for example, for marketing emails) and you may withdraw it at any time.
4. Sharing & DisclosureWho we share it with.
We do not sell your personal information. We share it only as needed to operate the business:
- Service providers: hosting, payment processing, email/marketing, shipping, and analytics partners who process data on our behalf under confidentiality obligations.
- Legal & safety: when required by law, court order, or to protect our rights, customers, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, where your information may be transferred subject to this Policy.
| Provider | Purpose | Their policy |
|---|---|---|
| WordPress / WooCommerce | Website & store platform | Automattic |
| Stripe / PayPal | Payment processing | Stripe · PayPal |
| Email platform (Brevo / Klaviyo) | Email & newsletter delivery | Brevo · Klaviyo |
| Shipping carriers | Order delivery & tracking | Set by each carrier |
| Google Analytics | Aggregate site usage | |
| Meta (Facebook) Pixel | Ad performance (optional) | Meta |
This list may change as our tools evolve; we keep our roster of providers as lean as practical.
5. International TransfersWhere your data is processed.
We are based in Canada, but some of our service providers store or process data in other countries, including the United States. Where that happens, your information may be subject to the laws of those jurisdictions, and may be accessible to courts, law enforcement, and authorities there. We take reasonable steps to ensure providers offer a comparable level of protection. By using our site and providing information, you understand it may be processed outside your province or country.
6. Data RetentionHow long we keep it.
We keep personal information only as long as needed for the purposes described here — for example, to fulfill your order, maintain your account, honour loyalty points, and meet tax, accounting, and legal record-keeping requirements (order and transaction records are typically retained for several years as required by law). When information is no longer needed, we securely delete or anonymize it. You can ask us to delete your account information at any time, subject to records we are legally required to keep.
7. SecurityHow we protect it.
We use reasonable administrative, technical, and physical safeguards — including encryption in transit (HTTPS), access controls, and trusted, security-conscious service providers — to protect personal information against loss, theft, and unauthorized access. No method of transmission or storage is 100% secure, so while we work hard to protect your data, we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will respond in accordance with applicable Canadian breach-notification requirements.
8. Your Rights & ChoicesYour control over your data.
Access & correction
You may request access to the personal information we hold about you and ask us to correct anything inaccurate or incomplete.
Withdraw consent & opt out
You can withdraw consent or unsubscribe from marketing at any time using the link in any email or by contacting us. Some processing necessary to fulfill orders or meet legal duties may continue.
Deletion & portability
You may ask us to delete your information (subject to legal retention) and, where applicable, to provide a copy in a portable format.
Residents of other regions: If you are in the EU/UK, you may have additional rights under the GDPR/UK GDPR (such as objection and restriction). If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know and to opt out of "sale/sharing" — note that we do not sell personal information. We honour these requests where the applicable law requires.
To exercise any right, email privacy@milkytallow.com. We may need to verify your identity before responding, and we will respond within the timeframe required by law.
9. Cookies & TrackingCookies.
We use essential, functional, analytics, and (with consent) marketing cookies. You can control cookies through your browser and opt-out tools. Blocking some cookies may affect cart and checkout functionality.
10. Children's PrivacyNot directed to children.
Our products and site are intended for adults. We do not knowingly collect personal information from children under the age of majority in their province/state (and not from anyone under 13). If you believe a child has provided us information, contact us and we will delete it.
11. ChangesUpdates to this Policy.
We may update this Policy to reflect changes in our practices, technology, or legal requirements. The "Last updated" date above reflects the latest version, and material changes will be posted on this page. Your continued use of the site after an update means you accept the revised Policy.
12. Contact & ComplaintsReach us.
For any privacy question, request, or concern, contact our privacy contact at privacy@milkytallow.com or via our Contact page. We take concerns seriously and will work with you to resolve them.
If you are not satisfied with our response, Canadian residents may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca), or the applicable provincial privacy commissioner (in BC, the Office of the Information and Privacy Commissioner for British Columbia).
Also see our Terms & Conditions and Cookie Policy.