Privacy Policy
Store and operator. WESSII Shop is operated by Wess Import Investments LLC. Privacy questions and data-rights requests may be sent to shop.support@wessii.com or through the Contact page. Corporate telephone: +1 833-544-6611.
1. Scope and current status
This draft describes information processed by the current storefront and information expected to be processed when ordering, payment, and fulfillment are activated. The local review clone does not accept live payments or live orders. A production privacy review must confirm actual providers, jurisdictions, notices, and retention obligations before launch.
2. Information we process
- Contact and support: name, email address, subject, message, and information voluntarily included in communications.
- Cart and storefront activity: cart contents, session identifiers, pages viewed during a session, referring source, campaign parameters when present, device/browser information, IP-derived technical information, and security logs.
- Accounts: name, email address, username, password hash, account preferences, addresses, and account activity when an account is created or used.
- Orders when enabled: billing and shipping names, email, phone, addresses, purchased products, quantities, prices, taxes if authorized, shipping choice, tracking and fulfillment records, order status, refunds, and customer notes.
- Payment information when enabled: transaction identifiers, payment status, fraud/risk signals, and limited payment-method details returned by the processor. The intended architecture uses third-party processors and must not store raw card numbers or card security codes on WESSII servers.
3. Why we use information
We use information to operate the storefront; preserve carts and sessions; answer questions; verify product compatibility when requested; manage accounts; process, fulfill, track, cancel, return, or refund orders when commerce is enabled; prevent fraud and misuse; maintain security; meet recordkeeping duties; and understand the source of completed orders. We do not claim uses that are not active.
4. Sharing and service providers
We share only information reasonably necessary for the relevant service. Current site software and hosting providers may process technical and account data. Contact-form and email systems process support communications. When commerce is activated, delivery information may be shared with suppliers, warehouses, third-party fulfillment providers, and carriers to quote, fulfill, or track delivery.
Stripe is the expected primary payment processor. PayPal may be offered only if separately enabled. A selected payment provider will receive transaction, billing, device, and risk information needed to process and support the payment under its own terms and privacy notice. PayPal is not represented as currently active.
We may also disclose information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction, subject to applicable requirements. We do not state that personal information is sold.
5. International and multi-origin fulfillment
An order may be fulfilled by a provider in the United States, the Dominican Republic, or another country, including an international supplier. Necessary delivery and order data may therefore be processed in a country different from the customer’s country. The production version requires provider and cross-border privacy review.
6. Cookies and similar technologies
The storefront uses essential and functional technologies for carts, sessions, accounts, language behavior, security, and WooCommerce order attribution. The clone audit did not detect active third-party marketing pixels or general audience analytics. See the Cookie Notice for the current inventory and conditional future technologies.
7. Cart-recovery processing
Cart-recovery software is active in the clone and may retain an email address and cart details after they are entered. The existing dedicated consent configuration is not enabled. Production use, lawful basis/consent, notice wording, retention, and unsubscribe behavior require human legal and business approval before launch.
8. Retention
The current WooCommerce configuration is set to remove pending and failed orders after 7 days, cancelled orders after 30 days, anonymize completed orders after 60 months, and delete inactive accounts after 24 months. These settings are technical configuration, not a final legal conclusion. Tax, accounting, chargeback, warranty, fraud, and other legal recordkeeping requirements may require different retention. Support communications and security-log periods are not yet approved. We keep information only as long as reasonably necessary for the stated purpose and applicable obligations.
9. Your choices and rights
Depending on applicable law, a person may request access, correction, deletion, restriction, portability, or information about processing. Send requests to shop.support@wessii.com. We may verify identity and may retain records when required or permitted by law, including records needed for transactions, fraud prevention, disputes, or legal obligations.
10. Security
We use administrative and technical safeguards appropriate to the information and service. No system can be guaranteed completely secure. Production review must confirm access controls, processor contracts, incident response, backups, and secure disposal.
11. Children
The intended age/eligibility rule and any child-directed-services analysis remain subject to legal review. Do not submit another person’s information without authority.
12. WESSII Connect web chat in the review clone
CONNECT_PRIVACY_SECTION = ACTIVE_IN_LOCAL_CLONE_QA / PRODUCTION_PENDING. The review clone uses WESSII Connect for web chat. Before a visitor sends a message, the integration supplies the public page path and URL, page language, source product SHOP, routing intent, and—only on a product page—the public product ID, SKU when present, and product name. The API uses the request IP transiently for security and rate limiting and binds the public widget key to the server-side tenant and the exact authorized origin. It stores an opaque anonymous chat-session value in browser local storage for up to 24 hours. If proactive chat is enabled later, dismissal state may remain for up to 7 days.
The integration does not automatically send a visitor name, email, telephone, account details, cart contents, WooCommerce session identifier, order, payment information, address, or internal fulfillment data. It processes the text a visitor intentionally enters. These statements describe only the local QA clone; production hosts, providers, retention, access, and legal basis require final review before launch.
13. Changes
We may update this policy to reflect actual practices or legal requirements. Material changes will be presented with an updated effective date and any notice or consent required by applicable law. Continued browsing alone is not treated here as consent to every material change.
Draft date: August 19, 2026. Production effective date: HUMAN_LEGAL_REVIEW_REQUIRED.
