Privacy Policy
What data we collect, why, and how long we keep it.
Effective Date and What This Policy Covers
Effective date: 15 September 2026.
This policy explains what personal information we collect about you, why we collect it, who we give it to, how long we keep it, and what you can ask us to do with it. It applies to everyone who visits www.neyvella.com, creates an account, places an order, writes to us or receives our emails.
The company that decides why and how your information is used is Neyvella LLC.
- Name
- Neyvella LLC
- Business address
- 30 N Gould St, Ste N, Sheridan, WY 82801, United States
- State of incorporation
- WY
- contact@neyvella.com
- Phone
- +1 307-357-9680
We are a United States company. Our website, our servers and every service provider we use are located in the United States, and your information is stored and handled there.
This policy does not cover other companies’ websites that you reach through a link from ours. Once you leave www.neyvella.com, their own policies apply.
Cookies have their own page, Cookie Policy. It lists every cookie the store sets, what each one does and how long it lasts.
Notice at Collection: What We Collect and Why
You also see a short version of this notice at the moment we ask for information: at checkout, when you create an account, on the contact form and next to the newsletter box. The table below is the full version.
| Category | What is in it | Why we collect it | Sold or shared | How long we keep it |
|---|---|---|---|---|
| Identifiers | First and last name, shipping address, billing address, email address, phone number, account username, order number | To take your order, deliver it, bill it, answer your questions and let you sign in | No | Order records 6 years, account data until you delete the account |
| Customer records | Name and address tied to a purchase, order and return history, the address book saved in your account | To handle returns, refunds and warranty claims, and to keep the tax records the law requires | No | 6 years |
| Commercial information | Products you viewed, added to the cart, ordered, returned or claimed under warranty, amounts paid, payment method chosen | To fulfill the order and to know what happened if you contact us about it later | No | 6 years |
| Internet and device activity | IP address, browser, device type, operating system, pages visited, the page you came from, date and time, the identifiers in strictly necessary cookies | To keep the store running and secure and to investigate abuse | No | 12 months |
| Business information | Company name, employer identification number, resale certificate, the name and contact details of the person who orders for the company | To invoice a company and to apply a sales tax exemption when the certificate is valid | No | 6 years |
| Content you write | The text of your message to us, the text and display name of a product review | To answer you, and to publish the review you chose to publish | No | Messages 24 months, reviews as long as the product is in the catalog |
| Payment information | Whether payment succeeded or failed, the amount, the order reference, and for a bank transfer the sender name and the reference your bank sends with it | To confirm that an order is paid and to issue refunds | No | 6 years, and at least 18 months for the delivery proof attached to it |
| Records of privacy requests | Your request, the information you gave us to confirm who you are, and our answer | To handle the request and to prove that we handled it | No | 24 months |
Fields marked as required at checkout really are required. Without them we cannot form the contract or ship the package. Everything else you can leave blank.
Where the information comes from
- From you, when you order, create an account, write to us, subscribe to the newsletter or post a review.
- From your use of the store, through server logs and the strictly necessary cookies described in the Cookie Policy.
- From the carrier: package status, delivery date, the reason a delivery failed, and for a cash on delivery order the confirmation that the amount was collected.
- From our bank, when you pay by bank transfer: the sender name, the amount and the reference on the transfer.
Card data does not reach us
The store accepts cash on delivery and bank transfer. Card payment is not available yet, so we never receive a card number, an expiration date or a security code. If we add card payment, we will update this policy and describe the arrangement before the first card order is taken. See Prices and Payment for what you can pay with today.
How We Use Personal Information
- To take, pack, ship and deliver your order, and to tell you where it is.
- To collect payment, to issue invoices and to refund you.
- To handle a return inside the 30 day window and to process the refund.
- To handle a claim under the 24 month limited warranty, including repair, replacement or refund.
- To answer your questions by email, through the contact form or by phone.
- To run your account: saved addresses, order history, password reset.
- To publish the reviews you write, with the display name you choose.
- To send the newsletter, if you asked for it.
- To keep the store secure, to detect abuse and to check orders for fraud before we ship them.
- To meet legal obligations: tax and accounting records, sales tax filings, answering a valid legal request.
- To fix the store. We read server logs in aggregate to find pages that break or load slowly. That work uses counts, not your name.
We do not use your information for anything else. If we ever need to, we will say so here first.
How Long We Keep Personal Information
Every category has a number attached to it. “As long as necessary” is not a retention period, and we do not use it.
| What | How long | Why that long |
|---|---|---|
| Orders, invoices, refunds, sales tax records | 6 years after the end of the calendar year of the order | The IRS can normally review a return for 3 years after it is filed, and for 6 years when more than a quarter of gross income was left out. We keep the documents for the longer of the two so we can answer either way. |
| Proof of delivery and payment details of a transaction | Inside the order record, and never less than 18 months from delivery | A payment dispute can be raised with a bank long after the sale. If we cannot show what we shipped and when, we lose the dispute and so does the argument that you received your goods. |
| Account data: email, hashed password, saved addresses, order history | Until you delete the account. We remove it within 30 days of your request. | The account exists because you asked for it. When you stop wanting it, the reason to keep it ends, except for the sales records above. |
| Messages you send us | 24 months after the last message in the exchange | Long enough to pick up a conversation about a past order, short enough that old correspondence does not pile up. |
| Newsletter subscription | Until you unsubscribe. Your address then stays on a suppression list. | The suppression list is how we make sure you are not added again by mistake. It is used for nothing else. |
| Server logs | 12 months | Enough time to investigate an attack or a fraudulent order pattern. After that the logs are no longer useful and are deleted. |
| Fraud screening records | 18 months | The same window as a payment dispute, because that is when we are asked to explain a decision. |
| Product reviews | As long as the product is in the catalog | A review is only useful next to the product it describes. You can ask us to remove yours at any time. |
| Privacy requests and our answers | 24 months from the day we close the request | California requires a business to keep records of the requests it receives and how it responded. |
When a period ends, the data is deleted or stripped of everything that points to a person. What remains is a sales count that cannot be traced back to you.
Some records we cannot delete on request. An invoice is one of them. Tax law tells us to keep it, and a deletion request does not override that. The full list of situations where we keep information despite a deletion request is in the California section below, and we apply it to everyone, not only to Californians.
Who We Share Personal Information With
We share the minimum, with the people who need it, for the purposes listed above.
- The carrier receives your name, phone number and shipping address, and for a cash on delivery order the amount to collect. Without that the package does not reach you.
- Our bank receives the amount and the order reference when a transfer is matched to your order, and your bank details reach us the same way when we send a refund.
- Our bookkeeper and tax preparer receive billing details and amounts, so the sale is recorded and the sales tax return is filed.
- Our hosting provider runs the server the store sits on and therefore has technical access to the database. Its contract forbids it from using the data for its own purposes.
- The email delivery service receives your address and the content of the messages we send you, including order confirmations and the newsletter.
- Software vendors that keep the store working, for example the people who maintain the store platform, may see data while fixing a problem we reported.
- Lawyers and auditors, if a dispute or an audit comes up, under a duty of confidentiality.
- Government agencies and courts, including the IRS and state tax authorities, and law enforcement when it presents valid legal process. We give only what the request covers and we ask for it in writing.
- A buyer of the business, if the company or the store is ever sold or merged. We would tell you here before your information moved, and the buyer would be bound by this policy until it published its own.
Every provider on that list signs a written contract that limits them to our instructions, forbids them from selling your information, forbids them from using it for their own purposes and requires them to protect it. Those terms are a legal requirement for us, not a favor we ask.
The providers we use by name
Categories are what the law requires. Names are more useful, so here they are:
WooCommerce, the platform that runs the storeStripe and PayPal, for card and wallet payments
USPS, UPS, FedEx and DHL, for shipping
Google Analytics and Meta, for traffic measurement and advertising, only if you accept those cookies
This list changes when we change a provider. Write to contact@neyvella.com if you want the list as it stands on the day you ask, and we will send it.
We Do Not Sell or Share Personal Information
We do not sell your personal information. We do not rent it. We do not hand it to anyone for cross context behavioral advertising, which is the practice of following you from site to site to target ads.
That statement is true because of how the store is built. There is no advertising pixel on any page, no analytics tag, no remarketing tag, no lookalike or custom audience. The only cookies we set are the strictly necessary ones listed in the Cookie Policy. Nothing about your visit leaves our systems for an advertising platform, because there is no connection to one.
Several state laws count a transfer of an identifier to an advertising platform as a sale even when no money changes hands. That is exactly why we say this plainly: today there is nothing of the kind. If we ever turn such a tool on, we will update this page first, add an opt out mechanism that works without an account, and remove this section rather than leave a false sentence standing.
We also do not disclose your information to third parties for their own direct marketing.
Sensitive Personal Information We Do Not Collect
United States privacy laws treat a short list of data as sensitive. We collect none of it:
- Social Security number, driver’s license number, state identification card number or passport number.
- Financial account numbers, and card numbers or security codes of any kind.
- Precise geolocation, meaning your position to within about 1,750 feet. We never collect it, never derive it and never sell it. We know the shipping address you type and the rough area an IP address suggests, and nothing finer.
- Racial or ethnic origin.
- Religious or philosophical beliefs.
- Union membership.
- Health, genetic or biometric data. We do not scan faces and we do not use voice prints.
- Sex life or sexual orientation.
- Citizenship or immigration status.
- The contents of your mail, email or text messages, except the messages you send us on purpose.
Please do not send us any of this. If it arrives inside a message, we delete it from the message and tell you that we did.
Because we do not collect sensitive personal information, the right to limit how it is used has nothing to work on here. The right still exists and you can still ask.
Consumer Health Data
Washington and Nevada give consumer health data its own rules, and those rules apply to any store that sells to their residents. Here is our position.
- We do not collect health data and we do not ask health questions anywhere on the site.
- We do not infer a health condition, a diagnosis, a treatment, a pregnancy or a body measurement from what you browse or buy.
- We do not build audiences or segments out of purchases that might suggest something about a person’s health or body.
- We do not tell anyone what specific products you bought, except the people who have to see the order to pack it, deliver it, invoice it and record it, as listed above.
- We do not use bounding or geofencing around any health facility, because we do not collect location at that level at all.
If we ever start doing any of this, it would need your consent first, given separately and in advance, and this section would be rewritten before that happened.
Do Not Track Signals
Some browsers can send a Do Not Track header. There is no agreed standard for what a website must do when it receives one, so we do not respond to Do Not Track signals. We are telling you this instead of leaving the question open, because California law requires a clear answer either way.
In practice the signal has nothing to change. We do not track you over time across other websites, and we do not let any other company collect information about your browsing on our store and follow you elsewhere.
Global Privacy Control and Opt-Out Preference Signals
Global Privacy Control is a different mechanism. Some browsers and extensions send it as a request to stop selling or sharing personal information. It reaches a website as a header or as a setting your browser exposes to the page.
We do not sell or share personal information, so today there is nothing for the signal to stop. If that ever changes, we will treat the signal as a valid opt out request. We will honor it for the browser that sent it, without asking you to create an account, sign in or prove who you are, and we will show a visible confirmation on the page that the signal was received and applied.
Email and Text Message Choices
Newsletter
The newsletter box is never checked for you. You subscribe by checking it yourself or by entering your address on purpose. We do not offer a discount, free shipping or any other benefit in exchange for subscribing, so nothing is being traded for your data.
Every marketing email has an unsubscribe link in the footer. That link:
- keeps working for at least 30 days after the message was sent;
- takes you to a single page and asks nothing except a confirmation, no login, no account, no reason, no photo of an ID;
- is honored within 10 business days at the latest, and usually the same day;
- can be replaced by simply replying to the email with the word unsubscribe.
Every marketing email also carries our postal address, 30 N Gould St, Ste N, Sheridan, WY 82801, United States, which is the same address printed on this page and on Contact.
Unsubscribing stops marketing email. It does not stop messages about an order you placed: the order confirmation, the shipping notice, a delivery problem, a refund. Those are part of the sale and they keep coming while the order is open.
Your phone number
We ask for a phone number so the carrier can reach you about a delivery. That is the only reason. We do not send marketing text messages, we have no text message program, and there is no text message sign up box anywhere on the site.
If we ever start sending texts, it will be opt in first, separately from placing an order, and a reply of STOP will end them within 10 business days at the latest.
Children Under 13 and Minors Under 16
The store is meant for adults and is not directed to children. We do not sell products intended for children under 12, and we do not knowingly collect personal information from anyone under 13.
If we learn that an account or an order came from someone under 13, we delete the account and the personal information within 30 days, and we do not use it in the meantime for anything except the deletion itself.
For anyone between 13 and 16, selling or sharing personal information requires their own affirmative consent, and for anyone under 13 it requires a parent’s consent. We do not sell or share personal information at all, so we do not ask for either. If that ever changes, the consent comes first and this section changes with it.
If you are a parent or guardian and you think we hold information about your child, write to contact@neyvella.com. We will look, we will tell you what we found, and we will delete it within 30 days.
Placing an order is a contract, so you have to be 18 or older to check out. This is set out in the Terms of Sale.
Automated Processing and Fraud Screening
Every order goes through automated checks before it ships. The software compares the shipping address with the billing address, looks at the size and pattern of the order, counts repeated failed deliveries or repeated refused cash on delivery packages from the same address, and flags what looks unusual.
These checks can hold an order, not cancel it by themselves. A person reviews every flagged order and makes the decision. If we decline an order, we tell you and we tell you why in plain terms, as far as we can without explaining to a fraudster how the check works.
Two limits matter here. First, this screening decides whether we accept a purchase, and nothing else. It is never used, and never given to anyone else to use, for a decision about credit, housing, education, employment, insurance or health care. Second, you can ask a person to look again. Write to contact@neyvella.com with the order number and we will review the decision by hand and answer you.
Beyond this, we do not profile you. We do not score you. We do not show one visitor a different price from another. The price of a product is the same for everyone looking at it at the same moment.
How We Protect Personal Information
- The whole store runs over an encrypted connection. What travels between your browser and our server is not readable in transit.
- Passwords are stored as salted cryptographic hashes. We cannot read your password and we cannot tell you what it is if you forget it. We can only let you set a new one.
- Full card data never enters the store, because the store does not take cards.
- Access to the admin panel is limited to the people who need it for their work, each with a separate account, and access is removed when the work ends.
- We take backups and we keep the software updated.
No system is perfectly secure, and we do not claim to be. What we claim is the list above, and you can hold us to it. On your side, the single most useful thing is a password you do not use anywhere else.
If There Is a Data Breach
If personal information is exposed by a security incident, we investigate, we close the hole, and we notify the people affected without unreasonable delay.
There is no single national deadline in the United States. Each state sets its own, and we work to the shortest one that covers anybody on the list, which means notice within 30 days for residents of Florida, Colorado and Maine and within 60 days for residents of Texas.
We also notify state authorities when the numbers require it, for example the California Attorney General when more than 500 California residents are affected, and the Texas Attorney General when more than 250 Texas residents are affected.
The notice tells you what happened, when, what categories of your information were involved, what we have done about it, and what you can do yourself. We send it by email to the address on your account, and we post it on the site when we cannot reach people individually.
How to Exercise Your Rights and How Long We Take
Two ways to reach us
- Use the form on the Contact page and write “Privacy request” in the subject.
- Email contact@neyvella.com. This address is read every business day.
You can also write to us on paper at 30 N Gould St, Ste N, Sheridan, WY 82801, United States. There is no required format. Tell us what you want and, if you know it, which order it concerns.
Reviewing and changing your information yourself
If you have an account, sign in at My Account. There you can see the information we hold about you, edit your name, addresses, phone number and email address, change your password, and review your order history. Changes you make there take effect immediately. If something is wrong in a record you cannot edit, such as the name on an old invoice, ask us and we will correct it.
How we check who you are
Before we hand over or delete personal information, we have to be reasonably sure the request comes from the person it concerns. We match what you tell us against what we already hold, usually an order number plus the email address used for it. For an account, we may ask you to confirm from the account’s email address.
We never ask for a photograph of an ID document, a Social Security number or a card number in order to process a privacy request. If a request is not verified, we tell you what is missing rather than refusing silently.
A request to stop selling or sharing is different: we do not verify it and we do not require an account for it. You do not have to prove anything to say no.
You can name someone to act for you. Send us written permission signed by you, and we may contact you once to confirm it.
Our deadlines
| Request | When we answer |
|---|---|
| Stop selling or sharing personal information | 15 business days from the day we receive it |
| Access, correction, deletion, or a portable copy | 45 calendar days, which we can extend once by another 45 days. If we extend, we tell you inside the first 45 days and we say why. |
| Appeal of a request we refused | 60 days, with a written answer that gives our reasons |
| California Shine the Light request | 30 days |
| Nevada opt out of the sale of covered information | 60 days, extendable by 30 more days when reasonably necessary, and we tell you if we extend |
| Unsubscribe from marketing email | 10 business days at the latest |
| Withdraw consent to text messages, if we ever send any | 10 business days at the latest |
| Request from someone in the EEA, the United Kingdom or Switzerland | One month, extendable by two more months for a complex request, with notice inside the first month |
Answering is free. For repeated copies of the same information we can charge a reasonable administrative fee, and we tell you the amount before doing any work.
Using any of these rights costs you nothing else. We will not charge you a different price, give you a worse discount, deliver more slowly or refuse to sell to you because you exercised a privacy right.
Additional Disclosures for California Residents
If you live in California, you have these rights over the personal information we hold about you.
- Know and access. Ask what categories we collected, where they came from, why we collected them, which categories we disclosed and to whom, and ask for a copy of the specific pieces of information we hold.
- Delete. Ask us to delete what we hold, subject to the nine situations listed below.
- Correct. Ask us to fix information that is wrong.
- Opt out of sale and sharing. We do not sell or share, so there is nothing to opt out of, and that is why you will not find a “Your Privacy Choices” link in our footer. The day we have something to opt out of, the link appears.
- Limit the use of sensitive personal information. We do not collect any, so there is nothing to limit.
- No retaliation. We will not treat you worse for using any of these rights.
The categories we have collected in the last 12 months, the reason for each and how long we keep them are in the table near the top of this page. The categories we disclosed for a business purpose in the last 12 months are the same ones, disclosed to the recipients listed under who we share with. The categories we sold or shared in the last 12 months: none.
When we keep information despite a deletion request
California law lists nine situations. We rely on them only when they actually apply, and we tell you which one we used:
- To finish the transaction, provide a product you asked for, handle a return or a warranty claim, or otherwise perform the contract between us.
- To keep the store secure, detect security incidents, and protect against fraudulent or illegal activity.
- To debug and repair errors that break how the store works.
- To exercise free speech, or to allow another person to exercise theirs, or to exercise another right the law provides.
- To comply with the California Electronic Communications Privacy Act.
- To carry out public interest research that follows research ethics and law, where deleting the information would ruin the research, and only if you consented to it.
- For internal uses that fit reasonably with what you would expect given your relationship with us.
- To comply with a legal obligation. This is the one that covers invoices and tax records.
- For other internal, lawful use that fits the context in which you gave us the information.
Everything outside those situations gets deleted when you ask.
Shine the Light
California residents can ask once a year whether a business disclosed their personal information to third parties for those third parties’ direct marketing. Our answer is no, and it has always been no. We do not make such disclosures.
The address designated for these requests is contact@neyvella.com, or by mail to 30 N Gould St, Ste N, Sheridan, WY 82801, United States, marked “Shine the Light Request”. We answer within 30 days.
Financial incentives
We do not run any program that gives you a discount, a coupon, free shipping or a better price in return for your personal information. There is no loyalty program and the newsletter carries no reward.
If you disagree with our answer
Write to us first at contact@neyvella.com and say what we got wrong. California does not run an internal appeal step, so you can also complain to the California Privacy Protection Agency or to the California Attorney General. The complaint links are below.
Additional Disclosures for Residents of Other US States
A growing number of states give their residents comprehensive privacy rights. The wording differs from state to state, the substance does not. If your state has such a law, you can ask us to:
- confirm whether we hold personal information about you and give you access to it;
- correct anything that is wrong;
- delete what we hold, subject to the same limits described above;
- give you a copy in a portable, machine readable format;
- stop targeted advertising, stop the sale of your information, and stop profiling that produces legal or similarly significant effects. None of these three happen here, so the answer will be that there is nothing to stop.
We answer within 45 days, extendable once by another 45 days with notice, as set out in the deadlines table above.
Appealing a refusal
If we refuse a request, you can appeal. Reply to our answer, or write to contact@neyvella.com with the word “Appeal” in the subject. We review the file, and within 60 days we send you a written decision that explains the reasons. This appeal right is written into the laws of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Utah.
If we refuse again, you can complain to the attorney general of your state. Search for the name of your state together with “attorney general consumer complaint”; every one of them takes complaints online. We do not link the forms here, because the addresses change and a dead link in a privacy policy is worse than no link.
If you live in a state that has no such law yet, ask anyway. We run every request through the same process, whatever the return address says.
Additional Disclosures for Nevada Residents
Nevada law lets a resident tell an online business not to sell their covered information, which means name, address, email address, phone number, account identifiers and similar details collected through the site.
We do not sell covered information and we have no plans to. You can still send the request, and we will record it so that the answer stays no if anything ever changes.
The address designated for Nevada opt out requests is contact@neyvella.com, or by mail to 30 N Gould St, Ste N, Sheridan, WY 82801, United States, marked “Nevada Opt-Out Request”. We answer within 60 days, and if we need more time we can take up to 30 additional days and we will tell you.
Additional Information for Individuals in the EEA, the United Kingdom and Switzerland
We ship to Europe, which means we are offering goods to people there. Article 3(2)(a) of the GDPR makes it apply to us directly, even though we have no establishment in the Union, and the UK GDPR applies the same way for the United Kingdom. This section is not a courtesy. It describes rights you can enforce against us.
Your information is stored and processed in the United States. There is no adequacy decision covering us, and we do not claim certification under the EU-US Data Privacy Framework, the UK Extension or the Swiss-US Data Privacy Framework, because we hold none. If that is not acceptable to you, please do not send us personal information.
Our representative in the Union and in the United Kingdom
Because we sell to people in the European Union and in the United Kingdom without being established there, Article 27 of the GDPR and Article 27 of the UK GDPR require us to appoint a representative in each, in writing, and to name them here. A representative is the address at which you, or a supervisory authority, can reach us without having to go to the United States.
European Union: Hyper Birotica Media SRL, Str. Albastrelelor nr. 15, Birou 2C, Brașov, Romania. Trade register J08/3560/2023, tax ID 49255015. Phone +40 736 248 888.
United Kingdom: not appointed yet.
Where no representative is listed for your country, write to us directly at contact@neyvella.com. Every right described below applies to you either way, and we answer within the same deadline.
Why we are allowed to use your information
European law requires a legal basis for each purpose. Ours are:
| Purpose | Legal basis |
|---|---|
| Taking, delivering and invoicing an order, handling returns and warranty claims, running your account | Performance of the contract with you |
| Keeping tax and accounting records | Compliance with a legal obligation |
| Sending the newsletter, publishing a review you wrote | Your consent, which you can withdraw at any time |
| Answering your questions, keeping the store secure, checking orders for fraud | Our legitimate interests in running a shop that works and does not get defrauded |
Legitimate interest means we have a practical reason to use the information and that reason does not override your rights. Here it covers two things only: being able to answer you when you write, and keeping the store safe. You can object to either, and the way to do it is below.
Your rights
- Access. Find out whether we process your data, what it is, and get a copy.
- Rectification. Have wrong or incomplete data corrected. Addresses and phone numbers you can change yourself at My Account.
- Erasure. Have data deleted, except what we are legally required to keep, such as invoices.
- Restriction. Have us freeze the use of your data, for example while we check something you contested.
- Portability. Receive the data you gave us in a structured, commonly used, machine readable file, or have it sent directly to another company when that is technically possible.
- Objection. Object to processing based on legitimate interests. Against direct marketing the objection applies immediately and needs no reason at all.
- Withdraw consent at any time, as easily as you gave it. Withdrawing does not undo what was lawfully done before.
- Not be subject to a decision made only by a machine that produces legal effects for you. Our fraud checks always end with a person, as described above, and you can ask for that review explicitly.
Write to contact@neyvella.com. We answer within one month, and for a complex request we can take up to two more months, in which case we tell you inside the first month and explain why.
Complaining to a supervisory authority
You can complain to the data protection supervisory authority of the country where you live, where you work, or where you think the problem happened. It is your authority to choose, not ours to name. In the United Kingdom it is the Information Commissioner’s Office, and in Switzerland the Federal Data Protection and Information Commissioner.
Please write to us first at contact@neyvella.com. Most situations are settled in a few days.
Business Contacts
If you order for a company, the personal information of the people involved, the buyer, the accounts payable contact, the person who signs for the delivery, is treated exactly like a consumer’s information. Every right described on this page belongs to them too. The old exemption for business to business contacts under California law expired on January 1, 2023 and was not renewed.
Information about the company itself, such as the company name, the employer identification number and a resale certificate, is not personal information, but we store it with the same care and keep it with the sales records for the same period.
Changes to This Policy
We update this policy when the law changes, when we change providers, or when the store starts doing something new with personal information. The version published here is the one in force, and the effective date at the top tells you when it started.
For a material change, meaning anything that affects what we collect, why, who gets it or how long we keep it, we do three things: we post a notice at the top of this page and on the home page for 30 days before the change takes effect, we email account holders and newsletter subscribers, and we keep the old version available on request at contact@neyvella.com.
Two changes in particular would trigger this: turning on any advertising or analytics tool, and adding card payment. Neither will happen quietly.
How to Contact Us About Privacy
For anything on this page, including requests, appeals, Shine the Light and Nevada opt outs, write to contact@neyvella.com. That mailbox is read every business day.
For anything else, including questions about an order, use contact@neyvella.com, +1 307-357-9680, or the form on the Contact page.
By mail: Neyvella LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States.
Last updated: 15 September 2026.