Privacy Policy
Last Updated: November 17, 2025
Effective Date: November 1, 2025
Nostra Peak (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and safeguard your information when you interact with our products, services, websites, ordering platforms, AI/GPT-powered systems, and any other tools or applications operated by Nostra Peak (collectively, the “Services”).
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of our Services.
1. Information We Collect
We may collect the following categories of information:
1.1 Personal Information
Data that identifies or can reasonably identify an individual, including:
-
Full name, shipping/billing addresses, email address, phone number
-
Account login details
-
Payment and transaction information (processed through third-party providers; we do not store full payment card numbers)
1.2 Usage Data & Device Information
Information automatically collected, including:
-
IP address, browser type, device identifiers
-
Interaction data, referring URLs, pages viewed, access times
-
Cookies, pixels, tags, and similar technologies
1.3 User-Submitted Content
Data voluntarily provided, including:
-
Messages, product inquiries, support tickets
-
Testimonials or product reviews
-
Photos, videos, and uploaded files
1.4 AI/GPT Agent Data
When you interact with our AI assistant (the “Nostra Peak GPT Agent”), we may collect and process:
-
Chat messages, prompts, and conversation history
-
Inputs used to personalize assistance
-
AI-generated responses and guidance provided to you
Important: AI conversations may be reviewed for safety, quality improvement, and compliance with our Terms.
1.5 Sensitive Information (Limited Use)
Sensitive data is only collected if voluntarily provided and only when necessary for safety or legal compliance (e.g., allergy information for customer safety).
2. How We Use Your Information
Nostra Peak may use collected data for:
2.1 Service Operation
-
Processing orders, payments, shipping, and fulfillment
-
Account management and authentication
-
Customer service and dispute resolution
2.2 AI/GPT Agent Functionality
-
Providing product guidance and personalized recommendations
-
Responding to questions and support requests
-
Improving AI accuracy, safety, and performance
2.3 Business & Product Development
-
Enhancing formulations, packaging, and digital platforms
-
Analyzing market and product performance
-
Improving marketing and customer experience
2.4 Legal, Security & Compliance
-
Preventing fraud or unauthorized access
-
Protecting rights, safety, and enforcing our Terms
-
Complying with laws, regulations, and legal processes
3. Sharing & Disclosure of Information
We do not sell your personal information.
We may share information only as necessary with:
3.1 Service Providers
Examples include:
-
Payment processors
-
AI platform technology providers
-
Shipping, fulfillment, and logistics services
-
CRM, marketing, and analytics tools
-
Customer communication platforms (email, SMS, chat)
3.2 AI/GPT Provider Data Processing
To generate responses from our AI systems, user interactions may be transmitted to our AI model provider(s) for:
-
Text processing and response generation
-
System safety, debugging, and performance improvement
3.3 Legal Requirements
We may disclose information if required:
-
By law, regulation, subpoena, or lawful request
-
To protect the safety, rights, or property of customers or Nostra Peak
3.4 Business Transfers
If all or part of Nostra Peak is involved in a merger, acquisition, financing, or asset sale, information may be transferred with confidentiality protections.
4. Data Retention
We retain information only as long as necessary for:
-
Order fulfillment and accounting requirements
-
Customer support and service improvement
-
AI system refinement and abuse prevention
-
Legal or regulatory obligations
Users may request deletion (see Section 8).
5. Data Security
We implement reasonable administrative, technical, and physical security measures including:
-
Encryption where appropriate
-
Access controls
-
System monitoring and secure data centers
No method of data transmission is 100% secure and we cannot guarantee absolute security.
6. Children’s Privacy
Our Services are not intended for individuals under 13 years old (or the age required by local law). We do not knowingly collect data from children. If such data is discovered, it will be deleted.
7. International Data Transfers
If you are located outside the United States, your information may be transferred and processed in jurisdictions with different privacy laws. We use appropriate safeguards for such transfers.
8. Your Privacy Rights
Depending on your location, you may have the right to:
-
Access, correct, or update your data
-
Request deletion of personal information
-
Object to or restrict processing
-
Opt out of marketing communications
-
Request a portable copy of your data
To exercise rights, contact us at:
📧 [Insert Privacy Email]
We may need to verify your identity before fulfilling a request.
9. Cookies & Tracking Technologies
We use cookies and similar tools for:
-
Session management and security
-
Analytics and site performance
-
Personalized content and advertising
You may manage cookie preferences through browser settings.
10. Third-Party Links
Our Services may link to third-party platforms. We are not responsible for their privacy practices. Please review the policies of those sites separately.
11. AI Limitations & User Responsibilities
The Nostra Peak GPT Agent:
-
May generate incomplete, incorrect, or outdated information
-
Should not be used for medical, legal, or health-critical decisions
-
Stores conversation logs for safety and improvement
Users agree not to submit:
-
Illegal, abusive, or harmful content
-
Highly sensitive personal information unless necessary
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes take effect when posted with a revised “Last Updated” date. Continued use of our Services confirms acceptance.