California Consumer Privacy Act (CCPA/CPRA) Policy
Last Updated: July 29, 2026
This California Consumer Privacy Act Policy applies to California residents and supplements the information contained in the MARSTEN [Privacy Policy].
MARSTEN is operated by ZENTARA BRANDS LIMITED (“MARSTEN,” “we,” “us,” or “our”).
This policy describes our practices concerning personal information and the rights available to eligible California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, collectively referred to in this policy as the “CCPA.”
The California Privacy Rights Act amended the CCPA rather than creating a separate privacy law.
This policy should be read together with our:
- [Privacy Policy]
- [Cookie Policy]
- [Do Not Sell or Share My Personal Information]
- [Your Privacy Choices]
Nothing in this policy limits any privacy right that cannot lawfully be waived or restricted.
1. Applicability
The CCPA applies only where its statutory requirements and applicability thresholds are satisfied.
The law generally applies to a for-profit business that:
- Does business in California
- Collects personal information or has personal information collected on its behalf
- Determines the purposes and means of processing that information
- Satisfies one or more applicable statutory thresholds
If MARSTEN is not legally subject to a particular CCPA requirement, we may nevertheless consider a California privacy request voluntarily where reasonably practicable.
Voluntarily responding to a request does not constitute an admission that the CCPA applies to:
- MARSTEN
- ZENTARA BRANDS LIMITED
- Every category of information
- Every consumer interaction
- Every processing activity described in this policy
Where the CCPA applies, we will process eligible requests in accordance with applicable law.
2. Scope
This policy applies to personal information collected from or concerning California residents through interactions including:
- Visiting or using [marstenhome.com]
- Browsing products or website content
- Placing or attempting to place an order
- Using checkout
- Creating or using a customer account
- Contacting customer support
- Requesting a return, refund, replacement, or store credit
- Submitting a review, photograph, video, or other content
- Subscribing to marketing communications
- Using website privacy controls
- Submitting a privacy request
- Participating in a survey or promotion
- Interacting with MARSTEN advertising
- Communicating with MARSTEN through supported channels
- Other interactions with MARSTEN
This policy does not apply to information that is exempt from or outside the scope of the CCPA.
3. Meaning of Personal Information
For purposes of this policy, personal information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked directly or indirectly with a particular consumer or household.
Personal information does not include information that is:
- Publicly available as defined by applicable law
- Lawfully made available from government records
- Deidentified
- Aggregated in a manner that cannot reasonably identify a consumer or household
- Otherwise excluded or exempt under the CCPA
Personal information includes sensitive personal information where the applicable statutory definition is satisfied.
4. Sources of Personal Information
We may collect personal information from the following categories of sources.
Directly From You
For example, when you:
- Place an order
- Create an account
- Contact customer support
- Submit a form
- Request a return or refund
- Submit a privacy request
- Subscribe to marketing
- Submit a review
- Provide photographs or videos
- Participate in a survey or promotion
Automatically Through Your Use of the Website
For example, through:
- Cookies
- Pixels
- Tags
- Local or session storage
- Device identifiers
- Advertising identifiers
- Server logs
- Analytics technologies
- Advertising technologies
- Security and fraud-prevention tools
From Service Providers and Business Partners
These may include:
- Shopify
- Payment processors
- Banks and card networks
- Digital-wallet providers
- Fraud-prevention providers
- Identity and transaction-verification providers
- Product suppliers
- Warehouses and fulfillment partners
- Shipping carriers and delivery partners
- Customer-support providers
- Analytics providers
- Advertising and marketing platforms
- Review and survey platforms
- Email and communication providers
- Technology and hosting providers
From Other Lawful Sources
These may include:
- Publicly available sources
- Social-media platforms
- Authorized representatives
- Referral partners
- Government agencies
- Law-enforcement authorities
- Professional advisers
- Other parties involved in investigating fraud, delivery issues, disputes, or legal claims
5. Categories of Personal Information
The following sections describe the categories of personal information we collect and, where applicable, have collected during the preceding 12 months.
The information collected from a particular consumer depends on how that consumer interacts with MARSTEN.
A. Identifiers
Examples may include:
- Full name
- Email address
- Postal address
- Billing address
- Shipping address
- Telephone number
- Customer-account identifier
- Order number
- IP address
- Cookie identifier
- Device identifier
- Advertising identifier
- Other online identifiers
Sources: Consumers, Shopify, payment providers, website technologies, advertising providers, fraud-prevention providers, and other service providers.
Purposes: Order processing, fulfillment, customer support, account administration, communications, security, fraud prevention, analytics, marketing, and legal compliance.
Categories of recipients: Shopify, payment providers, fulfillment partners, carriers, support providers, analytics providers, advertising providers, security and fraud-prevention providers, professional advisers, and authorities where legally required.
B. California Customer-Records Information
Examples may include:
- Name
- Address
- Telephone number
- Payment-related information
- Purchase information
- Other information provided in connection with an order or customer-service request
MARSTEN does not ordinarily receive or store complete payment-card numbers or card security codes. Those details are generally processed by authorized payment providers.
Sources: Consumers, Shopify, payment providers, fulfillment providers, and customer-support providers.
Purposes: Processing payments and orders, verifying transactions, providing support, processing returns, maintaining records, and complying with legal obligations.
Categories of recipients: Shopify, payment processors, banks, card networks, fraud-prevention providers, fulfillment partners, carriers, professional advisers, and regulators.
C. Commercial Information
Examples may include:
- Products viewed
- Products purchased
- Order history
- Shopping-cart activity
- Checkout activity
- Transaction amounts
- Discounts used
- Returns
- Refunds
- Replacements
- Store credit
- Chargebacks
- Product preferences
- Customer-service history
Sources: Consumers, Shopify, payment providers, website technologies, fulfillment partners, customer-support systems, and advertising or analytics providers.
Purposes: Processing and fulfilling orders, maintaining records, providing support, personalizing the shopping experience, measuring performance, preventing abuse, and marketing.
Categories of recipients: Shopify, payment providers, fulfillment providers, carriers, analytics providers, advertising platforms, support providers, and professional advisers.
D. Internet or Other Electronic Network Activity
Examples may include:
- Browsing activity
- Search activity
- Website interactions
- Products and pages viewed
- Referral URLs
- Clickstream information
- Session activity
- Shopping-cart and checkout interactions
- Advertising interactions
- Browser type
- Device type
- Operating system
- Website errors
- Date and time of access
Sources: Cookies, pixels, server logs, Shopify, analytics platforms, advertising services, and device technologies.
Purposes: Website operation, security, analytics, personalization, troubleshooting, advertising measurement, and fraud prevention.
Categories of recipients: Shopify, hosting and security providers, analytics services, advertising platforms, technology providers, and fraud-prevention services.
E. Geolocation Information
Examples may include:
- Approximate location inferred from an IP address
- Billing region
- Shipping destination
- Delivery location
- Location information associated with carrier tracking or fraud screening
We do not ordinarily seek to collect precise geolocation through the MARSTEN storefront unless it is necessary for a feature you knowingly use or another purpose disclosed at or before collection.
Sources: Consumers, devices, IP-based technologies, carriers, Shopify, payment providers, and fraud-prevention providers.
Purposes: Shipping, regional website settings, tax calculation, security, fraud prevention, analytics, and legal compliance.
Categories of recipients: Shopify, carriers, fulfillment providers, payment providers, analytics providers, and security providers.
F. Audio, Electronic, Visual, or Similar Information
Examples may include:
- Product photographs or videos
- Damage or defect evidence
- Packaging or shipping-label photographs
- Return-condition evidence
- Delivery evidence
- Voicemail messages
- Customer-submitted images
- Communications through supported channels
We do not record live telephone calls unless appropriate notice is provided where required.
Sources: Consumers, carriers, fulfillment providers, and customer-support systems.
Purposes: Customer support, product investigation, delivery verification, return processing, fraud prevention, payment-dispute handling, and legal claims.
Categories of recipients: Customer-support providers, carriers, fulfillment partners, payment-dispute administrators, insurers, professional advisers, and authorities where appropriate.
G. Inferences
Examples may include inferences concerning:
- Product interests
- Shopping preferences
- Likelihood of purchasing
- Marketing interests
- Customer segments
- Fraud or transaction risk
Sources: Website activity, transaction history, Shopify, advertising platforms, analytics providers, and fraud-prevention providers.
Purposes: Personalization, advertising, customer analysis, website improvement, security, and fraud prevention.
Categories of recipients: Shopify, analytics services, advertising platforms, fraud-prevention providers, and technology providers.
H. Professional or Employment-Related Information
We do not ordinarily request professional or employment-related information from retail customers.
We may receive limited information of this type if a consumer voluntarily provides it through:
- A business inquiry
- Customer-support communication
- Review
- Form
- Other submission
I. Education Information
We do not ordinarily collect education records or education-related information from retail customers.
J. Sensitive Personal Information
Depending on the interaction, sensitive personal information may include:
- Customer-account login credentials
- Financial-account or payment information processed by payment providers
- Precise geolocation, if a particular feature expressly collects it
- The contents of private communications sent directly to MARSTEN
- Government identification information provided during exceptional identity or fraud verification
- Health-related information voluntarily included in a customer-support communication
- Other information that satisfies the CCPA definition of sensitive personal information
We do not intend to collect sensitive personal information that is unnecessary for the Services.
Do not send:
- Complete payment-card numbers
- Card security codes
- Banking passwords
- Customer-account passwords
- Medical records
- Government identification
- Other highly sensitive information
unless MARSTEN specifically requests limited information through an appropriate process and explains why it is reasonably necessary.
6. Business and Commercial Purposes
We may collect, use, retain, or disclose personal information for purposes including:
- Operating and maintaining the website
- Providing shopping-cart and checkout functionality
- Processing and fulfilling orders
- Processing payments
- Calculating taxes and shipping
- Providing customer accounts
- Communicating order and delivery updates
- Providing customer service
- Processing returns, refunds, replacements, and store credit
- Verifying identities and transactions
- Detecting and preventing fraud
- Investigating unauthorized purchases
- Protecting website, payment, and account security
- Maintaining transaction and customer-service records
- Improving products and website functionality
- Conducting analytics
- Measuring advertising effectiveness
- Personalizing website content
- Sending marketing communications where permitted
- Managing reviews and customer submissions
- Complying with legal and regulatory obligations
- Responding to lawful requests
- Establishing, exercising, or defending legal claims
- Enforcing our agreements and store policies
- Conducting or evaluating a merger, acquisition, financing, restructuring, or other business transaction
Our collection, use, disclosure, and retention of personal information are intended to be reasonably necessary and proportionate to the disclosed purpose or another purpose compatible with the context in which the information was collected.
We will not use personal information for a materially different, unrelated, or incompatible purpose without providing any notice or consent required by applicable law.
7. Retention of Personal Information
We retain each category of personal information only for as long as reasonably necessary and proportionate to the purposes for which it was collected or another permitted purpose.
Retention periods may depend on:
- The nature and sensitivity of the information
- The purpose for which it was collected
- The duration of the customer relationship
- Order and payment-processing requirements
- Return, refund, replacement, and chargeback periods
- Fraud-prevention and security requirements
- Accounting and tax obligations
- Contractual requirements
- Applicable limitation periods
- Legal holds
- Regulatory requirements
- The need to establish, exercise, or defend legal claims
For example, transaction records may be retained longer than advertising-cookie identifiers because transaction records may be required for:
- Tax and accounting
- Fraud prevention
- Customer support
- Payment-dispute handling
- Legal compliance
When personal information is no longer reasonably required, we may:
- Delete it
- Anonymize it
- Aggregate it
- Securely restrict its use
8. Disclosure for Business Purposes
During the preceding 12 months, we have disclosed or may have disclosed the categories of personal information described above for operational or business purposes to categories of recipients including:
- Shopify and ecommerce-platform providers
- Payment processors
- Banks and card networks
- Digital-wallet providers
- Product suppliers
- Warehouses and fulfillment providers
- Shipping carriers and delivery partners
- Fraud-prevention and security providers
- Customer-support providers
- Email and communication providers
- Analytics providers
- Advertising and marketing providers
- Review and survey platforms
- Cloud-hosting and technology providers
- Accountants, lawyers, insurers, and other professional advisers
- Government agencies, courts, regulators, and law-enforcement authorities
- Parties involved in a merger, acquisition, financing, restructuring, insolvency proceeding, or sale of business assets
Operational disclosures to a qualifying service provider or contractor are not necessarily considered a sale or sharing when the applicable contractual and legal requirements are satisfied.
9. Sale and Sharing of Personal Information
MARSTEN does not sell personal information in exchange for money.
However, the CCPA defines sale and sharing more broadly than ordinary commercial usage.
Certain disclosures involving:
- Advertising cookies
- Pixels
- Audience tools
- Advertising identifiers
- Analytics technologies
- Attribution services
- Advertising platforms
- Shopify advertising or enhanced-service functionality
may be considered a sale or sharing even where no money is exchanged.
Depending on the technologies enabled on our website, we may sell or share the following categories of personal information for advertising, audience, attribution, or measurement purposes:
- Identifiers
- Commercial information
- Internet or other electronic network activity
- Approximate geolocation
- Marketing-related inferences
These categories may be sold or shared with:
- Advertising networks
- Search-advertising providers
- Social-media platforms
- Analytics providers
- Marketing-technology providers
- Advertising measurement and attribution providers
- Shopify advertising or enhanced-service features
- Other providers involved in cross-context behavioral advertising
We do not knowingly sell or share:
- Complete payment-card information
- Card security codes
- Customer-account passwords
- Government identification documents
- Sensitive personal information for the purpose of inferring characteristics
- Personal information belonging to consumers under 16 without the legally required affirmative authorization
California residents may opt out as described below.
10. Right to Know and Access
Subject to applicable exceptions, an eligible California resident may request that we disclose:
- The categories of personal information we collected
- The categories of sources from which the information was collected
- The business or commercial purposes for collecting, selling, or sharing it
- The categories of third parties to whom we disclosed it
- The categories of personal information sold or shared
- The categories of personal information disclosed for business purposes
- The specific pieces of personal information we maintain about the consumer
Where required, information will be provided in a portable and, where technically feasible, readily usable format.
The CCPA may limit requests to know to two requests within a 12-month period.
We will not disclose information where doing so would create a substantial, articulable, and unreasonable risk to:
- Security
- Personal information
- Customer accounts
- Payment accounts
- Another person’s privacy
We will not disclose complete payment-card numbers, card security codes, passwords, or other credentials that would permit access to an account.
11. Right to Delete
Subject to applicable exceptions, you may request deletion of personal information collected from or concerning you.
We may retain information where reasonably necessary to:
- Complete a transaction
- Fulfill an order
- Provide a product or service requested by you
- Maintain customer support records
- Process a return, refund, replacement, store credit, or chargeback
- Detect and prevent fraud
- Protect security and system integrity
- Correct or troubleshoot errors
- Comply with legal obligations
- Exercise or defend legal rights
- Maintain an internal use reasonably aligned with your relationship with MARSTEN
- Perform another purpose permitted by applicable law
Deletion from active systems may not immediately remove information from archived or backup systems where immediate deletion is technically impracticable.
Information retained in a backup will be protected and will not be restored or used for an unrelated purpose except where permitted by law.
12. Right to Correct
You may request correction of inaccurate personal information maintained about you.
When evaluating a correction request, we may consider:
- The nature of the information
- The source of the information
- Documentation you provide
- The totality of the circumstances
- Whether the requested correction can reasonably be verified
We may ask for information reasonably necessary to demonstrate that the existing information is inaccurate.
We may deny a correction request where we determine, based on the totality of the circumstances, that the disputed information is more likely than not accurate.
13. Right to Opt Out of Sale or Sharing
You may direct us not to sell or share your personal information as those terms are defined by the CCPA.
You may submit an opt-out through:
- [Your Privacy Choices]
- [Do Not Sell or Share My Personal Information]
- [Cookie Preferences]
- A recognized Global Privacy Control signal
- Email using the contact information below
You do not need to:
- Create an account
- Place an order
- Pay a fee
- Verify your identity through an extensive process
solely to submit a browser-level opt-out request.
An opt-out does not prevent disclosures reasonably necessary to:
- Fulfill an order
- Process a payment
- Provide requested support
- Maintain security
- Prevent fraud
- Remember essential preferences
- Comply with law
- Exercise or defend legal claims
- Use service providers or contractors for permitted operational purposes
Additional information is available on our [Do Not Sell or Share My Personal Information] page.
14. Global Privacy Control
Where required by applicable law and supported by our website and privacy systems, MARSTEN recognizes a valid Global Privacy Control, or GPC, signal as a request to opt out of sale or sharing.
A GPC signal generally applies to the browser and device transmitting it.
You may need to enable GPC separately on every browser and device you use.
Where you are signed into a customer account and we can reasonably associate the signal with that account, we may apply the preference more broadly where required or technically supported.
A recognized GPC signal does not require you to submit a separate website form for the browser and device transmitting it.
15. Right to Limit Use and Disclosure of Sensitive Personal Information
Where a business uses or discloses sensitive personal information for purposes beyond those permitted without a right to limit, eligible California residents may direct the business to limit that use or disclosure.
MARSTEN currently uses or discloses sensitive personal information only where reasonably necessary to:
- Provide requested products or Services
- Process payments
- Maintain customer-account access
- Provide customer support
- Process communications directed to us
- Verify transactions
- Prevent and investigate fraud
- Protect security
- Comply with law
- Establish, exercise, or defend legal claims
- Perform another purpose permitted without offering a right to limit
We do not use sensitive personal information to infer characteristics about consumers.
Based on these current practices, MARSTEN does not provide a separate Limit the Use of My Sensitive Personal Information link.
If our practices change in a way that triggers a right to limit, we will provide the required notice and method for exercising that right.
16. Automated Decisionmaking Technology
MARSTEN and its service providers may use automated technologies to assist with functions such as:
- Website security
- Fraud detection
- Transaction screening
- Payment authentication
- Order-risk review
- Advertising measurement
- Personalization
To the extent California law grants a right to receive notice, access meaningful information, or opt out of a covered use of automated decisionmaking technology, MARSTEN will provide the applicable notice and request method when legally required.
Automated tools may assist our personnel, payment providers, Shopify, or other service providers. A payment provider, bank, or independently operated service may maintain separate privacy obligations concerning its own decisions and technologies.
17. Right to Non-Discrimination
We will not unlawfully discriminate against you for exercising a CCPA right.
We will not, solely because you exercised an applicable privacy right:
- Deny products or services
- Charge a different price
- Provide a different level or quality of service
- Suggest that you will receive a different price or level of service
- Retaliate against you
This does not prohibit:
- A lawful promotion
- An ordinary discount
- A loyalty program
- A legally compliant financial incentive
- A price or service difference permitted under applicable law
18. Financial Incentives
MARSTEN does not currently operate a program that provides a financial incentive or a price or service difference in exchange for the collection, sale, sharing, or retention of personal information within the meaning of the CCPA.
Ordinary:
- Promotional codes
- Product discounts
- Free-shipping offers
- Newsletter offers
- Customer-service credits
are not necessarily financial-incentive programs under the CCPA.
If we introduce a program that qualifies as a financial incentive or price or service difference, we will provide the required notice and obtain any required opt-in consent before participation.
19. Consumers Under 16
MARSTEN is not directed to children.
We do not knowingly sell or share the personal information of consumers under 16 years of age without the affirmative authorization required by California law.
Where authorization is required:
- A parent or guardian must provide authorization for a consumer under 13.
- A consumer between 13 and 15 may provide the required authorization personally.
If you believe we have improperly collected, sold, or shared personal information concerning a person under 16, contact us promptly at [contact@marstenhome.com].
20. How to Submit a California Privacy Request
You may submit a request to know, access, delete, or correct personal information through either of the following designated methods:
Email: [contact@marstenhome.com]
Subject line: California Privacy Request
Online form: [Privacy Request Form]
For sale or sharing opt-outs, use:
- [Your Privacy Choices]
- [Do Not Sell or Share My Personal Information]
- A supported Global Privacy Control signal
Your request should include:
- Your full name
- The email address associated with your interaction with MARSTEN
- Confirmation that you are a California resident
- The right you wish to exercise
- A clear description of the request
- Relevant order or account information, where applicable
Do not send:
- Complete payment-card numbers
- Card security codes
- Banking passwords
- Customer-account passwords
- One-time authentication codes
- Unnecessary government identification
- Other unnecessary sensitive credentials
through ordinary email or the contact form.
21. Verification of Requests
We may need to verify that the person submitting a request is the consumer to whom the personal information relates.
Verification may involve:
- Confirming access to an email address
- Confirming order information
- Confirming customer-account information
- Matching information provided with existing records
- Requiring reauthentication through a customer account
- Requesting a signed declaration where appropriate
- Requesting additional information proportionate to the sensitivity of the request
The verification level may depend on:
- The right being exercised
- The sensitivity of the requested information
- The risk of harm from unauthorized access, disclosure, correction, or deletion
- Whether the consumer maintains a password-protected account
We will not request more information than is reasonably necessary for verification.
Information provided for verification will be used only for:
- Verification
- Security
- Fraud prevention
- Request processing
- Legal compliance
We may deny a request if we cannot reasonably verify the consumer’s identity or authority. Where required, we will explain the basis for the denial.
We do not ordinarily require verification for a browser-level sale or sharing opt-out, although we may request limited information reasonably necessary to apply the preference accurately.
22. Requests Through Customer Accounts
Where you maintain a password-protected MARSTEN customer account, we may use existing account-authentication procedures to verify a request.
We may require you to:
- Sign into the account
- Reauthenticate
- Confirm access to the account email address
- Provide additional verification where suspicious activity is detected
If we reasonably suspect fraudulent or malicious activity associated with an account, we may require additional verification before completing a request.
23. Authorized Agents
You may designate an authorized agent to submit a privacy request on your behalf.
We may require:
- Written permission signed by you
- Evidence that the agent is registered where required
- Verification of the agent’s identity
- Direct confirmation from you that the agent has permission to act
- Verification of your identity
Where an authorized agent holds a valid power of attorney under applicable California law, we will process the request according to the applicable requirements.
A valid Global Privacy Control signal will be treated in accordance with applicable law without requiring separate proof of agency for the browser and device transmitting the signal.
24. Household Requests
Where a request concerns household-level personal information, we may require verification from each household member where reasonably necessary to protect privacy.
We may decline to provide specific pieces of household personal information if we cannot verify that each requesting person is entitled to receive it.
Aggregate household information may be handled differently where permitted by law.
25. Response Timing
For requests to know, delete, or correct, we will:
- Confirm receipt within 10 business days
- Provide a substantive response within 45 calendar days after receiving the request
Where reasonably necessary, we may extend the response period by an additional 45 calendar days.
If an extension is required, we will provide notice and explain the reason within the initial response period.
Requests to opt out of sale or sharing, or to limit sensitive-personal-information processing where applicable, will be processed as soon as reasonably feasible and no later than 15 business days after receipt.
Our ordinary customer-service response period of 24–48 business hours does not mean that a completed privacy response will be provided within that period.
26. Fees and Excessive Requests
We generally do not charge a fee for processing a verifiable consumer request.
To the extent permitted by law, we may charge a reasonable fee or refuse to act where a request is:
- Manifestly unfounded
- Excessive
- Repetitive
Before charging a fee or denying a request on this basis, we will provide any explanation required by applicable law.
27. Request Frequency
The CCPA may limit a consumer to two requests to know within a 12-month period.
Different limits may apply to:
- Deletion requests
- Correction requests
- Sale or sharing opt-outs
- Sensitive-information limitation requests
We will process requests according to the rights and limitations applicable when the request is received.
28. Appeals and Complaints
The CCPA does not generally require the same formal appeal process imposed by certain other U.S. state privacy laws.
However, if you believe we improperly denied or restricted a request, you may ask us to reconsider by contacting:
Email: [contact@marstenhome.com]
Subject line: California Privacy Complaint – MARSTEN
Please include:
- The date of the original request
- The right exercised
- Our response
- The reason you believe reconsideration is appropriate
You may also submit a complaint to the appropriate California privacy or consumer-protection authority.
29. Shopify
MARSTEN uses Shopify to host and operate its online store.
Shopify may process personal information to provide:
- Storefront services
- Shopping-cart functionality
- Checkout
- Customer accounts
- Payment-related functions
- Security
- Fraud prevention
- Analytics
- Personalization
- Advertising or enhanced Shopify services enabled for the store
Depending on the Shopify settings and features enabled, Shopify processing may affect whether certain information is sold or shared under California law.
Information about Shopify’s practices and direct privacy request options is available through:
- [Shopify Consumer Privacy Policy]
- [Shopify Privacy Portal]
MARSTEN remains responsible for assessing its own obligations and configuring available Shopify privacy controls consistently with its disclosed practices.
30. Service Providers and Contractors
We may provide personal information to service providers or contractors for legitimate operational purposes.
Where required, these relationships are subject to contractual restrictions intended to limit how the recipient may:
- Use personal information
- Retain personal information
- Disclose personal information
- Combine personal information
- Process personal information outside the specified business purpose or direct business relationship
Service providers and contractors may assist with:
- Ecommerce hosting
- Payment processing
- Fraud prevention
- Order fulfillment
- Shipping and delivery
- Returns processing
- Customer support
- Communications
- Analytics
- Security
- Legal and professional services
A recipient may also process personal information independently where permitted or required by law and subject to its own legal responsibilities.
31. Deidentified Information
Where we maintain deidentified information, we will take reasonable measures designed to ensure that the information cannot reasonably be associated with a consumer or household.
Where required, we will:
- Maintain the information in deidentified form
- Publicly commit not to reidentify it
- Contractually require recipients not to attempt reidentification
This does not prevent lawful testing intended to confirm whether deidentification measures remain effective.
32. California “Shine the Light”
California’s separate “Shine the Light” law may allow certain California residents to request information concerning disclosures of personal information to third parties for those third parties’ own direct-marketing purposes.
MARSTEN does not intend to disclose personal information to third parties for their own direct-marketing purposes in a manner covered by that law without providing any legally required notice or choice.
Requests concerning this subject may be submitted to:
Email: [contact@marstenhome.com]
Subject line: California Shine the Light Request
33. Changes to This California Privacy Policy
We may update this policy to reflect changes to:
- Our information practices
- Website functionality
- Shopify services
- Advertising or analytics providers
- Products and services
- Applicable California law
- Regulations or regulatory guidance
We review this policy periodically and intend to update it at least once every 12 months where required.
The current version will be published on this page with a revised “Last Updated” date.
Where legally required, we will provide additional notice before materially different processing begins.
34. Related Privacy Pages
This policy should be read together with:
- [Privacy Policy]
- [Cookie Policy]
- [Do Not Sell or Share My Personal Information]
- [Your Privacy Choices]
- [Terms of Service]
- [Legal Notice]
- [Contact Information]
If this California-specific policy conflicts with our general Privacy Policy regarding a right granted under the CCPA, this California-specific policy will control for eligible California residents to the extent of that conflict.
35. Contact Information
Store Name: MARSTEN
Legal Company Name: ZENTARA BRANDS LIMITED
Company Number: 78899970
California Privacy Requests
Email: [contact@marstenhome.com]
Online form: [Privacy Request Form]
Suggested subject line: California Privacy Request
General Customer Support
Phone: [+1 (512) 631-9468]
Contact Form: [Contact Us]
Customer Service Hours
Monday–Friday: 9:00 a.m.–6:00 p.m. Eastern Time
Saturday–Sunday: Closed
Ordinary customer-service inquiries are generally answered within 24–48 hours on business days. Privacy requests may require additional time for verification and processing in accordance with applicable law.
Registered Company Address
ZENTARA BRANDS LIMITED
Unit 2A, 17/F, Glenealy Tower
No. 1 Glenealy, Central
Hong Kong