Last Updated: April 6, 2026
Data Controller: Forest Day
We are committed to protecting the privacy and security of all users worldwide who access and use our website (www.forestdaylife.com, hereinafter referred to as "the Website"). This Privacy Policy explains how we collect, store, use, disclose and protect your personal information, and sets out your privacy rights in accordance with applicable global data protection regulations (including EU/UK GDPR, California CCPA/CPRA, etc.). By accessing the Website, purchasing products or providing personal information, you agree to the terms of this Policy.
The Website uses cookies and similar tracking technologies. Upon your first visit, we will obtain your explicit consent before enabling non-essential cookies, in compliance with global privacy regulations.
1. Personal Information We Collect
We only collect information necessary to provide products and services, divided into information you voluntarily provide and information automatically collected. We do not actively collect sensitive personal information (religion, health, biometrics, etc.) unless you voluntarily provide it and give explicit consent.
1. Information You Voluntarily Provide
• Name, delivery address, email address, telephone number (for order processing and delivery)
• Payment information (securely processed by third-party payment providers; we do not store raw payment data)
• Personalized custom content (images, text, greetings and other custom candle details)
• Account registration information (e.g., creating an account)
• Email subscription information (for new product and promotion notifications)
• Customer service inquiry content
2. Automatically Collected Information
• IP address, device type, browser and system version
• General geographic location (determined solely by IP address)
• Website usage data (pages viewed, time spent, behavior paths, traffic sources)
• Shopping cart and order records
• Data collected via cookies and tracking technologies (see Section 6)
2. How We Use Personal Information
We only use your information within the following lawful, specific and reasonable scopes, with legal bases including: performance of a contract, legitimate interests, user consent, and compliance with legal obligations.
We may use information for:
• Processing, dispatching, delivering orders and sending logistics notifications
• Secure payment processing and resolving payment issues
• Providing candle customization services
• Account creation and management
• Responding to customer service inquiries and after-sales support
• Sending non-marketing service notifications (order updates, policy changes, etc.)
• Sending marketing communications (new products, offers) only with your explicit consent, which you may unsubscribe from at any time
• Personalized recommendations and experience optimization
• Improving products, services and website functionality
• Preventing fraud, unauthorized access and security risks
• Complying with tax, accounting and legal requirements
We will not use your information for other purposes without notice and obtaining necessary consent.
3. Information Disclosure and Sharing
We never sell, rent, trade or commercialize your personal information, nor do we sell data to advertising networks or third-party marketing agencies.
We only share information with the following trusted third-party service providers when necessary, who are required to protect data in accordance with this Policy and applicable laws:
• Payment service providers (PayPal, Stripe, etc.)
• Logistics and delivery partners
• Website hosting and technical service providers
• Data analytics providers (e.g., Google Analytics, only anonymous data)
We may also disclose information as required by law, court orders, to protect our legal rights or to safeguard security. We will not disclose information to other third parties without your explicit consent.
4. International Data Transfers
Your information may be stored and processed in any country/region where we or our partners operate (including the UK, EU, USA, etc.). For EU/UK users, we ensure transfer security through safeguards such as EU Standard Contractual Clauses (SCCs). By using the Website, you consent to such international transfers.
5. Data Retention Period
In accordance with the data minimization principle, we retain information only for as long as necessary to fulfill the purpose or comply with legal requirements, after which it is securely deleted or anonymized:
• Order and payment records: retained for 7 years (tax compliance)
• Account information: retained for the duration of the account + 12 months after account closure
• Marketing subscription information: retained until you unsubscribe (deleted within 10 working days)
• Custom content: deleted after order completion (unless you request retention)
• Website behavior data: anonymized or deleted after 180 days
• Customer service records: retained for 12 months after resolution
6. Cookies and Tracking Technologies
We use cookies to enhance user experience, ensure functionality and analyze traffic. They are categorized as:
• Necessary Cookies: Essential for core functions, cannot be disabled (shopping cart, login, security)
• Non-essential Cookies: Persistence, analytics, personalization; enabled only with your consent
• Third-party Cookies: e.g., Google Analytics, governed by their own privacy policies
You may disable non-essential cookies via browser settings, though this may affect certain features. Cookie consent records are retained for 12 months, after which consent will be requested again.
7. Data Security
We implement industry-standard technical and organizational measures to protect information, including:
• SSL/TLS encrypted transmission
• Strict access control
• Encrypted server storage
• Regular security updates and audits
No internet transmission or electronic storage is absolutely secure; we do not guarantee 100% security but make every effort to protect data. In the event of a data breach, we will notify the relevant supervisory authority and affected users in accordance with regulations (e.g., within 72 hours under GDPR).
8. Your Privacy Rights
Rights vary slightly by region; we respect and uphold the legal rights of users worldwide. To exercise your rights, please contact: privacy@forestdaylife.com (identity verification may be required). We will respond within statutory timeframes (GDPR: 1 month; CCPA: 45 days).
1. Rights for EU/UK GDPR Users
• Access: Request access to information we hold about you
• Rectification: Correct inaccurate information
• Erasure: Request deletion ("right to be forgotten", subject to legal exceptions)
• Restriction: Request restriction of processing your information
• Data portability: Obtain a structured, machine-readable copy of your data
• Objection: Object to processing based on legitimate interests or marketing
• Withdraw consent: Withdraw consent for marketing and other consents at any time
• Complaints: Lodge a complaint with your local data protection authority
2. Rights for California Residents (CCPA/CPRA)
• Know: Request details of information collected, used and disclosed
• Delete: Request deletion of information (subject to legal exceptions)
• Opt-out of sale: Confirm we do not sell your data
• Non-discrimination: No adverse treatment for exercising rights
• Limit sensitive information: Request restriction of sensitive information use
3. Global General Rights
• Unsubscribe from marketing: Opt out at any time
• Update information: Modify address, phone number, etc.
• Close account: Request account closure and information deletion
Reasonable requests are free of charge; repeated or excessive requests may incur fees.
9. Marketing Communications and Unsubscribe
We send marketing emails/notifications only with your explicit consent.
Unsubscribe options:
• Click "Unsubscribe" at the bottom of marketing emails
• Contact the privacy email address
• Modify preferences in your account
Unsubscribe takes effect within 10 working days and does not affect service-related notifications (e.g., orders).
10. Third-Party Websites
The Website may contain links to third-party websites (social media, partners, etc.). This Policy does not apply to external websites; we are not responsible for their privacy practices. Please review their policies independently.
11. Policy Updates
We may update this Policy from time to time. Material changes will be notified via email or pop-up 30 days in advance, and the "Last Updated" date will be revised. Continued use of the Website constitutes acceptance of the revised Policy.
12. Contact Us
If you have questions or requests regarding this Privacy Policy or your personal information, please contact:
Data Protection Team Email: privacy@forestdaylife.com
Data Controller: Forest Day
13. Children's Privacy
The Website and products are not intended for children under 16 (under 13 in California). We do not knowingly collect information from children. If we discover unauthorised child data without parental consent, we will securely delete it within 7 working days. Parents/guardians may contact us to address such matters.