Privacy Policy
Last updated: March 2026
1. Introduction
YO-GEE ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website or use our services.
We operate across multiple markets including New Zealand, India, and the UAE, and comply with applicable privacy legislation in each jurisdiction, including the New Zealand Privacy Act 2020, the India Digital Personal Data Protection Act 2023, and UAE data protection regulations.
2. Information We Collect
Information you provide to us:
- Account information: Name, email address, and password when you create an account.
- Wellness quiz responses: Health-related information including body metrics, lifestyle habits, health goals, dietary preferences, and current supplement use. This data is used solely to provide personalized Ayurvedic wellness insights.
- Quiz access verification: Email address used for OTP verification to access the wellness quiz. If you opt in, this email may also be used for wellness newsletters.
- Newsletter subscription: Email address, collected only with your explicit consent (opt-in checkbox). You can unsubscribe at any time by emailing [email protected] or replying to any newsletter.
- Contact information: Any information you provide when contacting us.
Information collected automatically:
- Usage data: Pages visited, time spent, browser type, and device information.
- Campaign tracking: When you scan a QR code or follow a marketing link, we collect campaign parameters (source, medium, campaign name) to understand how you found us. These are stored alongside your quiz access record.
- Cookies & local storage: We use essential cookies for website functionality and Google Analytics cookies (only with your consent) to understand how our website is used. We also use browser local storage to remember your quiz access verification and cookie consent preferences.
3. How We Use Your Information
We use your personal information to:
- Provide personalized Ayurvedic wellness insights based on your quiz responses.
- Create and manage your account.
- Send you wellness tips, educational content, and updates (with your consent).
- Improve our website and services.
- Comply with legal obligations.
4. Health Information & Sensitive Data
We take the privacy of health-related information seriously. The wellness quiz may collect information about your body metrics, lifestyle habits, dietary preferences, current supplements and dosages, health conditions, and allergies. Under India's Digital Personal Data Protection Act 2023, this constitutes sensitive personal data requiring additional safeguards.
Your wellness quiz responses are:
- Used only to generate your personalized dosha profile and educational wellness insights.
- Stored securely with encryption in transit (HTTPS/TLS) and access controls.
- Never sold to third parties.
- Never used for advertising targeting.
- Never shared with insurance companies, employers, or data brokers.
- Accessible only to you through your account or email verification.
Important: Quiz results are for educational purposes only and do not constitute medical advice, diagnosis, or treatment. If you have health conditions, allergies, or take medications, consult a qualified healthcare provider before acting on any wellness suggestions.
5. Data Sharing & Third-Party Services
We do not sell your personal information. We may share limited data with the following service providers to operate our platform:
- Payment processors: Stripe (NZ/UAE) or Razorpay (India) receive your order amount and email to process payments. Card details are handled directly by these providers and never stored on our servers.
- Email delivery: We use third-party email services to send verification codes, order confirmations, and newsletters. Only your email address and message content are shared.
- AI chatbot: Our educational wellness chatbot is powered by Anthropic's Claude AI. When you use the chatbot, your messages and your dosha type (if available) are sent to Anthropic's servers for processing. Your name, email, health conditions, and medications are never sent to the chatbot service.
- Analytics: Google Analytics (consent-gated) collects anonymised usage data. No personally identifiable information is sent to Google.
- Error monitoring: We use Sentry for error tracking. Personal data is scrubbed from error reports before transmission.
- Media hosting: Uploaded images (avatars) may be stored on cloud services. No health data is included in uploaded files.
- Legal requirements: When required by law, court order, or governmental authority.
5a. Data Residency
We are committed to keeping your data in your region wherever possible. Each market (New Zealand, India, UAE) is served by infrastructure located in or near that region. Sensitive health data from your quiz is stored in the database serving your market and is not transferred between markets.
Some third-party services (payment processors, email delivery, AI chatbot) may process data in other jurisdictions. We minimise the data shared with these services and ensure they maintain appropriate security standards. We do not send your health conditions, medications, or allergy information to any overseas service.
6. Data Retention
We retain different types of data for different periods:
- Account data: Retained while your account is active. Deleted within 30 days of an account deletion request.
- Quiz results: Retained for 24 months to allow you to revisit your wellness profile, then automatically anonymised.
- Quiz access verification (OTP): Email address and verification records are retained for 12 months for security and analytics purposes.
- Newsletter subscriptions: Retained until you unsubscribe. To unsubscribe, email [email protected] or reply to any newsletter email.
- Order data: Retained for 7 years as required by tax and accounting regulations in New Zealand and India.
You may request deletion of your personal data at any time by emailing [email protected]. We will respond within 30 days.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information.
- Withdraw consent for marketing communications.
- Lodge a complaint with your local data protection authority.
8. Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- Authentication uses industry-standard JWT tokens with automatic expiration.
- Personally identifiable information is masked in analytics exports and server logs.
- Error reports sent to monitoring services have personal data automatically scrubbed.
- Staff access to analytics dashboards requires verified admin authentication.
- Rate limiting protects against brute-force attacks on authentication endpoints.
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
Email: [email protected]
Website: yogee.co.nz
