Privacy Policy
We collect your email when you join the founders' list, and your payment details (handled by Stripe — we never see your card number) when you place a deposit. We use Klaviyo to send you membership updates. We use Stripe to process payments. We never sell your data. You can ask us to delete everything at any time.
1. Who is the data controller
The data controller for personal data collected through this site is Lemon Group International Limited (trading as "WYN"), company number 05807099, registered office 43 Sorrel Crescent, Didcot, England, OX11 6HQ.
For operational and manufacturing purposes, limited personal data (e.g. shipping address, order reference) is shared with our affiliate Lemon Group International L.L.C-FZ (Meydan Free Zone, Dubai, U.A.E.) acting as a processor under a written data-sharing agreement and appropriate transfer safeguards (see clause 5).
You can contact us about privacy at privacy@wynforlife.com.
2. What we collect
| Data | When | Why |
|---|---|---|
| Email address | Joining the founders' waitlist | Contact about membership, ship dates, account activation |
| Name (optional) | Account creation | Personalise communications |
| Shipping address | Activating your subscription | Deliver the product |
| Payment details | Founders' deposit and subscription | Process payment via Stripe (we do not store card details) |
| IP address, device, browser | Each site visit | Security, fraud prevention, analytics (with consent) |
| Cookies | Each site visit | See Cookie Policy |
| Health-relevant info (optional, via quiz) | Phase Quiz | Recommend the right starting phase. Not stored against your account. |
We do not knowingly collect data from anyone under 18. If you believe we hold data on a minor, contact us and we will delete it.
3. Lawful bases
We process your data under one or more of the following lawful bases under UK GDPR Article 6:
- Contract — to fulfil your founders' membership, deposit refund, or subscription delivery.
- Consent — for marketing emails, non-essential cookies, and any optional data you provide.
- Legitimate interests — to improve the site, detect fraud, and operate the business. We have assessed that our interests do not override yours.
- Legal obligation — to retain transaction records for accounting and tax law.
4. Who we share data with
We only share data with processors that are necessary to operate the business. Each processor is contractually bound to UK GDPR-equivalent standards.
| Processor | Purpose | Where data is held |
|---|---|---|
| Stripe Payments UK Ltd | Payment processing | EU / UK / US (adequacy decision + SCCs) |
| Klaviyo, Inc. | Email marketing, list management | US (UK Addendum + SCCs) |
| Lemon Group International L.L.C-FZ | Order fulfilment, manufacturing | UAE (UK Addendum + SCCs, internal group transfer) |
| Hosting / CDN provider | Site delivery | EU / US |
We do not sell your personal data. We do not share it with third parties for their own marketing purposes.
5. International transfers
Some of our processors operate outside the UK and EU. Where data is transferred outside the UK, we rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an applicable adequacy decision to ensure equivalent protection.
6. How long we keep data
| Data | Retention |
|---|---|
| Waitlist email (no deposit) | Until you unsubscribe, or 24 months of inactivity |
| Founders' deposit records | 7 years from the date of the transaction (accounting law) |
| Active subscription data | For the life of the subscription, plus 7 years for tax records |
| Quiz responses | Not stored against your profile; processed locally in your browser |
| Server logs (IP, user agent) | 90 days |
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold on you
- Rectify inaccurate data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (where consent is the lawful basis)
- Not be subject to automated decision-making with legal effect
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk)
To exercise any right, email privacy@wynforlife.com. We will respond within one month.
8. Security
We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest where supported, role-based access, audit logging, regular dependency updates. Payment data is handled solely by Stripe, a PCI-DSS Level 1 processor; we never store card numbers.
9. Marketing communications
If you join the founders' list, we will send you membership updates by email (this is "service" communication, lawful basis: contract). We will only send marketing emails outside this scope with your specific consent. You can unsubscribe at any time using the link in any email.
10. Cookies
See our Cookie Policy for details on the cookies we use and how to manage them.
11. Updates to this policy
If we make material changes, we will email registered users and post a notice on the homepage. Continued use of the site after an update constitutes acceptance.
12. How to contact us
For any privacy matter: privacy@wynforlife.com. For everything else: hello@wynforlife.com.