Privacy Policy
Last updated: 25/04/2026
A short version, in plain English
We collect what we need to ship your filter, run our business, and stay in touch about your curls — and nothing we don't need. We don't sell your personal information for cash. We do share some data with the tools that help us run HEYKURL (Shopify, Klaviyo, Meta, TikTok, Google), and we explain exactly what and why below.
If you live in California, scroll to Section 9 — you have specific rights and we want you to know them.
If you ever want to know what we have on you, change it, or delete it: email info@heykurl.com and we'll handle it. No fine print.
1. Who this applies to
This Privacy Policy describes how HEYKURL LLC ("HEYKURL," "we," "us," "our") collects, uses, and shares information when you visit heykurl.com, buy from us, sign up for emails or texts, or interact with us on social media.
Our mailing address: 30 N Gould St Ste R, Sheridan, WY 82801, USA.
2. Information we collect
From you, directly
When you place an order, create an account, or subscribe to emails/texts:
- Name
- Email address
- Phone number (if you opt into SMS)
- Shipping and billing address
- Payment information (handled by our payment processors — we never store full card numbers)
- Hair type and curl info (if you fill out a quiz or share it in customer support)
- Communications you send us (emails, chats, reviews, social comments)
Automatically, when you use our site
- Device info (browser, operating system, screen size, IP address)
- Pages you view, links you click, time on site
- How you got to our site (search, ad, social link, direct)
- General location based on IP (city/region level, not precise GPS)
This is collected through cookies and similar technologies — see Section 7.
From our partners
- Order, shipping, and payment confirmations from our processors and fulfillment partners
- Marketing performance data from ad platforms (Meta, TikTok, Google) — for example, whether you clicked an ad before buying
- Public profile info if you tag us on Instagram or TikTok
3. How we use your information
- To process and ship your order
- To send order confirmations, shipping updates, and refund notifications
- To send marketing emails and texts (only if you opted in — and you can opt out anytime)
- To run and improve our ads, including retargeting on Meta, TikTok, and Google
- To answer your questions and provide customer support
- To detect fraud, abuse, and security issues
- To improve our products, site, and content based on what's working
- To comply with laws and resolve disputes
4. Who we share it with
We don't sell your personal information for money. We do share it with the partners and tools that make HEYKURL run:
| Partner | What they get | Why |
|---|---|---|
| Shopify | Order, account, browsing data | Powers our store and checkout |
| Payment processors (Shop Pay, Stripe, PayPal, etc.) | Payment info, billing address | Process payments |
| Shipping & fulfillment partners | Name, address, order details | Deliver your filter |
| Klaviyo | Email, name, purchase history | Send marketing emails and SMS (if opted in) |
| Meta (Facebook, Instagram) | Browsing and purchase data via Meta Pixel and Conversions API | Show you our ads, measure ad performance |
| TikTok | Browsing and purchase data via TikTok Pixel | Same as above, on TikTok |
| Google (Analytics, Ads) | Browsing data | Understand how the site is used, run search/display ads |
| Customer service tools | Your messages and order info | Help us reply faster |
We may also share information when legally required (subpoena, court order, fraud investigation), or if we ever sell or merge the business — in which case we'll tell you.
Under California law, sharing data with ad platforms like Meta and TikTok for cross-context behavioral advertising counts as "sharing" — see Section 9 for how to opt out.
5. Email marketing
If you sign up for emails (at checkout, in a popup, or through a giveaway), we'll send you marketing emails — new drops, restocks, hard-water tips, and occasional offers.
You can unsubscribe anytime by clicking the link at the bottom of any email, or by emailing info@heykurl.com We'll still send you transactional emails (order confirmations, shipping updates, refund notices) because those aren't marketing — they're how we tell you what's happening with your order.
6. SMS marketing
If you opt into text messages (by checking the box at checkout or signing up through a form), here's what you're agreeing to:
- We'll send you marketing texts — restock alerts, filter replacement reminders, occasional offers
- Message frequency varies (usually no more than 4–6 per month)
- Message and data rates may apply, depending on your carrier
- Reply STOP to any message to opt out completely
- Reply HELP for help, or email info@heykurl.com
Opting in is never a condition of buying anything. You can shop, return, and contact us without ever giving us your phone number.
7. Cookies and tracking technologies
Cookies are small files saved to your device when you visit a site. We use them — and similar tools like pixels and SDKs — for a few reasons:
- Necessary cookies keep the site working (cart, checkout, login)
- Analytics cookies show us what's working on the site (Google Analytics, Shopify analytics)
- Marketing cookies help us show you relevant ads on Meta, TikTok, and Google, and measure whether they work
You can manage cookie preferences through our cookie banner when you first visit, or anytime through your browser settings. Note that turning off necessary cookies will break parts of the site.
8. Your rights (everyone)
No matter where you live, you can:
- Ask us what personal information we have about you
- Ask us to correct or update it
- Ask us to delete it (with some exceptions — for example, we have to keep order records for tax purposes)
- Unsubscribe from emails and texts at any time
To exercise any of these rights, email info@heykurl.com with your request and the email address tied to your account. We'll respond within 30 days. We may need to verify your identity first — usually by sending a confirmation to the email on file.
9. California residents (CCPA/CPRA)
If you live in California, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
Right to know what personal information we've collected, where we got it, why we collected it, and who we shared it with in the last 12 months.
Right to delete the personal information we hold about you, with limited exceptions (we may have to keep order/tax records).
Right to correct inaccurate personal information.
Right to opt out of "sale" or "sharing" of your personal information. We don't sell your data for money, but our use of advertising pixels (Meta, TikTok, Google) qualifies as "sharing" under California law for cross-context behavioral advertising.
Right to non-discrimination — we won't charge you more or give you worse service for exercising your rights.
To exercise any California right, email info@heykurl.com or use the "Do Not Sell or Share My Personal Information" link in our site footer. You can also have an authorized agent submit the request — they'll need to provide proof of authorization.
We do not knowingly sell or share the personal information of anyone under 16.
Categories of personal information we've collected and shared
In the last 12 months, we've collected the following categories of personal information (as defined by California law): identifiers (name, email, IP), commercial information (purchase history), internet activity (browsing data), geolocation (general), and inferences drawn from this data (preferences, interests).
We've shared identifiers, commercial information, internet activity, and inferences with advertising partners (Meta, TikTok, Google) for cross-context behavioral advertising.
We have not sold any personal information for money in the last 12 months.
10. Other state privacy rights
If you live in Virginia, Colorado, Connecticut, Utah, Texas, or another US state with comprehensive privacy laws, you have similar rights to California residents. Email info@heykurl.com to exercise them and we'll handle it the same way.
11. Children's privacy
HEYKURL is not directed at children under 13, and we don't knowingly collect personal information from anyone under 13. If you believe we have, email info@heykurl.com and we'll delete it.
12. How long we keep your information
We keep your personal information for as long as we need it for the reason we collected it — usually:
- Order and account data: 7 years (for tax and accounting reasons)
- Marketing data: until you unsubscribe, or 2 years of inactivity
- Customer service messages: 2 years
- Analytics data: up to 26 months
After that, we delete or anonymize it. If you ask us to delete your data sooner, we will (subject to the legal exceptions noted above).
13. How we protect your information
We use industry-standard security measures: encrypted connections (HTTPS), secure payment processing through certified providers, and limited internal access on a need-to-know basis.
That said, no system on the internet is 100% secure. We can't guarantee absolute security, but we work hard to protect your data and we'll notify you if a breach ever affects you.
14. Third-party links
Our site and emails may link to third-party sites (creator pages, partner brands, articles). Once you click out, you're on their privacy policy, not ours. We're not responsible for how they handle your data.
15. International visitors
HEYKURL is based in the United States and currently ships within the US. If you visit our site from outside the US, your data will be transferred to and processed in the US, which may have different data protection rules than your country.
16. Changes to this policy
We'll update this policy when we change how we handle data, when laws change, or when we add new tools. The "last updated" date at the top will reflect any changes. If a change is significant (for example, new categories of data collection), we'll let you know by email or a banner on the site.
17. Contact us
Questions, requests, or anything privacy-related:
Email: info@heykurl.com Mail: HEYKURL LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA
A real person reads every message. We'll get back to you within one business day for general questions, and within 30 days for formal data requests.
