Welcome — Ruby’s Healing Crystals (“we,” “us,” “our”) sells crystals and related products through www.rubyshealingcrystals.com (the “Site”). We respect your privacy and created this Privacy Policy to explain what personal information we collect, why we collect it, how we use and share it, and the rights you may have under applicable privacy laws (including the GDPR and various U.S. state privacy laws). This policy applies to information collected through the Site, by email, and when you interact with our customer service.


1. Information we collect

Personal information you give us

When you create an account, place an order, sign up for marketing, contact customer support, or otherwise interact with the Site, we may collect personal data such as:

  • Name, email address, phone number, billing and shipping addresses.

  • Payment information (card number, expiry) — we do not store full card numbers on our servers; payments are processed by third-party payment processors.

  • Account username and password (securely hashed), order history, loyalty or reward program data.

  • Customer notes, product reviews, and messages you send to our support team.

Information collected automatically

When you visit or use the Site we may automatically collect:

  • Device & browser information, IP address, pages visited, referral URLs, clickstream data, and other analytics data.

  • Cookies and similar technologies, and identifiers used for advertising and analytics (see Cookies & Tracking below).

Information from third parties

We may receive information about you from third-party services (payment processors, shipping carriers, analytics providers) to enable orders, fraud prevention, and marketing.


2. How we use your information (purposes and legal bases)

We use personal data for business operations and to provide services to you, including:

  • To fulfill orders: process purchases, arrange shipping, handle returns and refunds. (Contract)

  • To communicate: order confirmations, shipping notices, account messages, customer service replies. (Contract / legitimate interest)

  • To personalize & improve the Site: analytics, product recommendations, A/B testing. (Legitimate interest / consent where required)

  • For marketing: sending promotional emails and offers (we will obtain consent where required by law and provide unsubscribe options). (Consent)

  • Fraud prevention and security: to detect and prevent fraud and abuse. (Legitimate interest / legal obligation)

  • Legal compliance: to respond to legal requests and enforce our terms. (Legal obligation)

If you are an EU resident, our lawful bases for processing include performance of a contract, compliance with legal obligations, your consent (where requested), and our legitimate interests (balanced against your rights). These rights are described in Section 7 below. For the GDPR rights overview, see official summaries. 


3. Sharing your information

We may share personal data as necessary to operate the business and provide the Site’s services:

  • Service providers — payment processors (e.g., Stripe, PayPal), shipping carriers, email and SMS providers, customer support platforms, hosting, and analytics services. Payment processors may process payment card data on our behalf; we recommend using processors that support PCI standards. (See Payment Security.) 

  • Legal and safety reasons — to comply with laws, respond to court orders, or to protect the safety, rights, or property of Ruby’s Healing Crystals or others.

  • Business transfers — if we sell or restructure the business, customer data may be transferred as part of the transaction.

  • With your consent — when you explicitly allow sharing (for example if you agree to participate in third-party marketing).

We do not sell personal information for third-party direct marketing without your notice and opt-out option. Where applicable under California law, you may opt out of “sales” or “sharing” — see Section 7 (Your Privacy Rights) and our Do-Not-Sell/Share mechanisms. 


4. Cookies & tracking technologies

We and our service providers use cookies, pixel tags, local storage, and similar technologies to operate the Site, remember preferences, analyze traffic, and display targeted ads. You can manage cookies via your browser settings and (where provided) our cookie preference center. Some features require cookies to function.

We honor user-enabled global privacy controls and opt-out signals for targeted advertising as required by some U.S. state privacy laws. Controllers are required under certain state laws to honor universal opt-outs for targeted advertising and sales.


5. Payment security & cardholder data

We do not store full credit card numbers on our servers unless explicitly stated at checkout. Payments are processed by third-party payment processors (e.g., Stripe, PayPal). All payment processing is conducted in accordance with industry standards — merchants are expected to comply with PCI DSS (Payment Card Industry Data Security Standard), currently enforced in its v4.x form — and we work with processors who are compliant. For questions about payment processing and PCI, contact our support or your card processor. 


6. International transfers

If you are located outside the United States, personal data we collect may be transferred to, processed, and stored in the United States or other countries. We will take reasonable steps to ensure appropriate safeguards (e.g., standard contractual clauses or relying on transfer frameworks supported by our processors) are in place where required by law.


7. Your privacy rights — how to exercise them

Depending on where you live, you may have rights to access or control your personal data. Below are common rights; local laws may differ in detail:

  • Access — request copies of personal data we hold about you.

  • Correction — ask us to correct inaccurate personal data.

  • Deletion (Erasure) — request deletion of personal data subject to legal limits.

  • Portability — request a copy of your data in a structured, machine-readable format.

  • Restriction/Objection — object to certain processing (for example, direct marketing) or request limits on processing.

  • Opt-out of sale/sharing/targeted advertising — if you are a resident of California (and certain other U.S. states covered by privacy laws), you may opt out of sale or sharing of your personal information or targeted advertising. We honor consumer opt-out requests and the Global Privacy Control (GPC) where applicable. Specific state laws (e.g., California CPRA, Colorado, Virginia, Connecticut, Utah) provide consumer rights and rules for controllers — including response windows and special protections for sensitive personal information. Controllers commonly have a 45-day response period for consumer requests under several state laws. 

How to submit a request

You can exercise your rights by:

  • Emailing us at: rubyshealingcrystals@gmail.com

  • Using any privacy request forms or account settings available on the Site.
    When you make a request we may need to verify your identity to protect your privacy before responding.

We will respond to verifiable consumer requests in accordance with the law applicable to your residence. For many U.S. state laws, the standard response time is 45 days (with a possible one-time extension).


8. Children’s privacy

Our Site is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under the age of 13. If we learn we have collected such information, we will delete it in accordance with applicable law. Operators of sites directed to children must follow the Children’s Online Privacy Protection Rule (COPPA) and related updates; where applicable, we will follow those rules. If you believe we may have personal information from a child under the applicable age, contact us at privacy@rubyshealingcrystals.com


9. Data retention

We retain personal data as long as necessary to provide services, comply with legal obligations, resolve disputes, enforce agreements, and for legitimate business purposes (e.g., tax, accounting). Specific retention periods depend on the data type and legal requirements; we may retain anonymized or aggregated data indefinitely.


10. Security practices

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal data. These measures include encrypted connections (TLS/HTTPS), access controls, secure software development practices, and periodic security reviews. No website or internet transmission is completely secure — if you suspect a security breach affecting your data, contact us immediately at security@rubyshealingcrystals.com.


11. Third-party links & third-party services

The Site may contain links, widgets, or integrations with third-party websites or services. This Privacy Policy does not apply to those third parties. We recommend reviewing the privacy policies of any third-party service you use (payment providers, social media platforms, analytics providers).


12. International and US state-level compliance notes

  • European users (GDPR): You have the rights described in Section 7, including access, rectification, erasure, portability, and the right to object to processing in certain situations. We process EU personal data under appropriate lawful bases and offer mechanisms to exercise rights. 

  • California users (CPRA/CCPA): California residents have rights including access, deletion, correction, and the ability to opt out of sale/sharing of personal information and targeted advertising. We provide a Do-Not-Sell/Share mechanism and honor global privacy controls. 

  • Other U.S. privacy laws: Several states (e.g., Virginia, Colorado, Connecticut, Utah, and others) provide consumer privacy rights and require certain controller obligations (including honoring opt-outs for targeted advertising and allowing consumer requests). We follow applicable state laws for covered residents.


13. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, law, or the Site. If there are material changes we will post a prominent notice on the Site and update the Last updated date above.


14. Contact us

If you have questions about this Privacy Policy or wish to submit a privacy request, please contact:

Email: rubyshealingcrystals@gmail.com
Security incidents: security@rubyshealingcrystals.com
Mailing address: Ruby’s Healing Crystals 1501 NW 2nd Ave Ste. 3 Boca Raton, FL 33432


By using www.rubyshealingcrystals.com you consent to the terms of this Privacy Policy.