Privacy policy
Effective Date: July 1, 2025
Notice Version: 2025.07.01
Data Controller Contact Information:
Waves Labs Corp.
8401 MAYLAND DR #6338
RICHMOND, VA, 23294, USA support@waveswomen.com
Our privacy notice governs our privacy practices when you are using our websites, waveslabs.ai, & waveswomen.com, and our mobile apps, called “Waves Women”, hereinafter and collectively referred to as the services.
Our privacy notice tells you what personal data and non-personal data we collect from you, how we collect them, how we protect them, how we share them, how you can access and change them, and how you can limit our sharing of them. Our privacy notice also explains certain legal rights that you have concerning your personal data. Any capitalized terms not defined herein will have the same meaning as those defined elsewhere on our website. This privacy notice applies only to U.S. residents; we do not target or offer the services to individuals outside the United States.
Definitions
The terms “us”, “we”, and “our” refer to the owner of this Website.
‘NON-PERSONAL DATA’ (NPD) means any information that is not personally identifiable.
‘PERSONAL DATA’ (PD) means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person can be identified directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. PD is, in many ways, the same as Personally Identifiable Information (PII). However, PD is broader in scope and covers more data.
‘SENSITIVE PERSONAL DATA’ (SPD) means a consumer’s social security, driver’s license, state identification card, or passport number; a consumer’s account log-in, financial account, debit card, or credit card number in combination with any required security, access code, password, or credentials allowing access to an account; a consumer’s exact geolocation; a consumer’s ethnic or racial origin, religious or philosophical beliefs, or union membership; the contents of a consumer’s mail, text messages, and email unless the business is the intended receiver of the communication; a consumer’s genetic data; the processing of biometric data to uniquely identify a consumer; personal information collected and analyzed regarding a consumer’s health (including menstrual, hormonal, and related wellness information); sex life or sexual orientation. Sensitive personal information that is “publicly available” is not considered sensitive personal information or personal information.
Topics Covered in Our Privacy Notice
YOUR RIGHTS
INFORMATION WE COLLECT AND HOW WE COLLECT IT
HOW YOUR PD IS USED AND SHARED
RETAINING AND DESTROYING YOUR PD
PROTECTING THE PRIVACY RIGHTS OF THIRD PARTIES
DO NOT TRACK SETTINGS
LINKS TO OTHER WEBSITES
PROTECTING CHILDREN’S PRIVACY
OUR EMAIL POLICY
OUR SECURITY POLICY
USE OF YOUR CREDIT CARD
IN-APP PURCHASES
TRANSFERRING PD FROM OTHER COUNTRIES
CHANGES TO OUR PRIVACY NOTICE
YOUR RIGHTS
Contact us using the information at the top of this privacy notice to exercise any of your legal rights contained within this privacy notice. We respond within 30 days of receiving your request. Where permitted by law and if reasonably necessary, we may extend once by up to 15 additional days (for a total of 45 days) and will notify you of any extension.To protect your privacy, we verify all privacy-related requests by confirming account credentials via email or app login before fulfilling any request. In some cases, we may ask for additional confirmation.When using our services and submitting Personal Data (PD) to us, you have certain rights under privacy laws in the United States, including the California Consumer Privacy Act of 2018 (CaCPA), the California Privacy Rights Act of 2020 (CPRA), and similar U.S. state privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, Texas), as applicable to you. We do not target non-U.S. residents; references to GDPR are removed for clarity. Even if not listed here, we will make reasonable efforts to honor data subject access requests even though we may be under no legal obligation to do so. However, we reserve the right to decline any data subject access request that we are not legally obligated to comply with.
Your rights include but are not limited to the following:
- The right to equal service, price, and not being discriminated against even if you exercise your privacy rights.
- The right to one or more means where you can submit requests under this privacy notice, including (at an email address (support@waveswomen.com) and by submitting a Data Control Request Form (link to form).
- The right to know whether your personal data is sold, “shared” for cross-context behavioral advertising, or disclosed and to whom.
- The right to request that we do not sell or share any of your personal data . We do not sell or share your personal data as defined by CPRA. If that changes, we will provide a “Do Not Sell or Share My Personal Information” link.
- The right to request that we disclose the following personal information to you: the categories of personal information we collected about you; the categories of sources from which your personal information is collected; the business or commercial purpose for collecting, using, or disclosing your personal information; the categories of third parties to whom we disclose your personal information; the specific pieces of personal information we have collected about you.
- The right to be informed about the personal data we collect from you and how we process them.
- The right to get confirmation that your personal data is being processed and you can access your personal data .
- The right to have your personal data corrected if it is inaccurate or incomplete.
- The right to request the removal or deletion of your personal data if there is no compelling reason for us to continue processing them. However, the right to deletion is not absolute and can be overridden to continue data processing in some cases where we still have a legal ground or overriding legitimate interest to process your data.
- The right to ‘block’ or restrict the processing of your personal data . When your personal data is restricted, we are permitted to store your personal data but not to process them further.
- The right to request the personal data that you provided to us and use them for your own purposes. Upon express request, we aim to provide your data to you or another service or product provider within 30 days of your request, to the extent technically feasible and permitted by law.
- The right to object to us processing your personal data for the following reasons: Direct marketing and targeted advertising (including profiling).
- The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects regarding you or similarly significantly affects you.
- The right that we limit the collection of your personal data to that which is “adequate, relevant and reasonably necessary with the purposes for which the data is processed.
- The right that we do not process your personal data for purposes that are neither reasonably necessary nor compatible with the disclosed purposes for which such personal data is processed, as disclosed to you, unless the controller obtains your consent.
- The right to designate an authorized agent to request on your behalf. When designating an authorized agent, you must provide a valid power of attorney, the requester’s valid government-issued identification, and the authorized agent’s valid government-issued identification.
Global Privacy Control / Opt-out Preference Signals: If at any point our practices involve “selling” or “sharing” personal data as defined by CPRA, we will honor browser-based opt-out preference signals (e.g., Global Privacy Control) and treat them as a valid opt-out for that browser/device and, if known, for your account.
INFORMATION WE COLLECT AND HOW WE COLLECT IT
Generally, you control the amount and type of information you provide us when using our website. We provide this “notice at collection” describing the categories of personal data we collect, the purposes for which it is used, and retention criteria.
Categories of personal data we collect (depending on your use of the services):
- Identifiers (e.g., name, email, device identifiers);
- Commercial information (purchases, subscriptions);
- Internet/Network activity (log data, app interactions, analytics);
- Approximate geolocation (from IP);
- Inferences (to personalize content);
- Sensitive personal information (health-related information you choose to log, such as cycle stage, hormonal symptoms, related wellness inputs).
- Sources: you (in-app entries and settings), your devices, integrated platforms you authorize (e.g.health & wellness app, wearable devices, ect. ), and our service providers acting on our behalf under contract.
Purposes: to provide, secure, debug, and improve the services; personalize your experience; provide support; comply with law; and perform internal analytics.
Inferences may include app-based recommendations based on your logged health entries. These are used solely to improve your app experience and are not used for profiling or automated decision-making with legal effects.
Retention: we retain personal data only as long as reasonably necessary for the purposes described below (see “Retaining and Destroying Your personal data ”).
Sensitive Data Consent: Where required by law (e.g., Virginia, Colorado), we do not process Sensitive Personal Information— including health entries and precise geolocation—without your prior opt-in consent. You may withdraw consent at any time by emailing support@waveswomen.com . Upon withdrawal we stop processing and delete such data unless retention is legally required.
Our Legal Basis for Collecting and Processing Personal Data (PD)
Our legal basis for collecting and processing your personal data when you buy our products and services or fill in any of the contact forms is based on the necessity for the performance of a contract or to take steps to enter into a contract. Our legal basis for collecting and processing your personal data when you sign up for our newsletter, download free information, access free audio and videos, and use the free version of our services is based on consent. For U.S. state privacy laws that rely on opt-out frameworks, we process personal data for the purposes above as permitted by law and provide the opt-out choices described in this notice.
Automatic Information
We automatically receive information from your web browser or mobile device. This information may include the IP address of your computer/the proxy server you use to access the Internet, your Internet service provider’s name, your web browser type, the type of mobile device, your computer operating system, and data about your browsing activity when using our services. We use all this information to help improve our services.
Other Websites, Platforms, and Third-Party Fitness and Health Devices
If you link your account to third-party platforms such as Fitbit, Garmin, Google Health Connect, or Apple Health, we will receive information that you have authorized each synchronization with that platform. This information may include exercise minutes, calories expended, steps taken in a day, body weight, and other metrics you choose to share. The use of information received from Google Health Connect will adhere to the Google Health Connect Permissions policy, including the Limited Use requirements mentioned here. Use of Apple Health data will comply with applicable Apple developer terms; we will not use Apple Health data for marketing or advertising.
When Entering and Using Our Services
When you use our services you may provide us with different kinds of information such as settings, preferences, language, lifestage, cycle, health conditions, foods eaten, dietary preferences, goals etc. during your usage of our services. This information is provided via different interactive elements such as drop-downs, text-fields, toggle buttons, chatbot interactions, support interactions etc.
When you enter and use our services and agree to accept cookies, some of these cookies may contain your Personal Data (PD).
Our Use of Cookies
Our services use cookies. A cookie is a small piece of data or a text file that is downloaded to your computer or mobile device when you access certain websites. Cookies may contain text that can be read by the web server that delivered the cookie to you. The text contained in the cookie generally consists of a sequence of letters and numbers that uniquely identifies your computer or mobile device; it may contain other information as well.
By agreeing to accept our use of cookies, you are giving us and the third parties with which we partner permission to place, store, and access some or all the cookies described below on your computer and or mobile device.
- Strictly Necessary Cookies – These cookies are necessary for the proper functioning of the website, such as displaying content, logging in, validating your session, responding to your request for services, and other functions.
- Performance Cookies – These cookies collect information about the use of the website, such as pages visited, traffic sources, users’ interests, content management, and other website measurements.
- Functional Cookies – These cookies enable the website to remember users’ choices, such as their language, usernames, and other choices while using the website.
- Media Cookies – These cookies can be used to improve a website’s performance and provide special features and content. They can be placed by us or third parties who provide services to us.
- Advertising or Targeting Cookies – These cookies are usually placed and used by advertising companies to develop a profile of your browsing interests and serve advertisements on other websites that are related to your interests.
- Session Cookies – These cookies allow websites to link the actions of a user during a browser session. They may be used for remembering what a user puts in their shopping cart as they browse a website. Session cookies also permit users to be recognized as they navigate a website so that any item or page changes they make are remembered from page to page. Session cookies expire after a browser session.
- Persistent Cookies – These cookies are stored on a user’s device between browser sessions, which allows the user’s preferences or actions across a website or across different websites to be remembered. Persistent cookies may be used to remember users’ choices and preferences when using a website or target advertising to them.
We may also use cookies for the following:
- Identifying the areas of our website that you have visited;
- Personalizing the content that you see on our website;
- Our website analytics;
- Remarketing our products or services to you;
- Remembering your preferences, settings, and login details;
- Targeted advertising and serving ads relevant to your interests;
- Allowing you to share content with social networks.
Most web browsers can be set to disable the use of cookies. However, if you disable cookies, you may not be able to access features on our services correctly or at all.
We do not use cookies or other tracking technologies to profile users for targeted advertising or cross-context behavioral advertising. If that changes, we will update this notice and provide opt-out links as required.
We do not use cookies to “sell” or “share” your personal data for cross-context behavioral advertising. If our practices change, we will update this notice and provide required opt-outs.
For more detailed cookie information, including opt-out options contact us at support@waveswomen.com or submit a data control request.
Web Beacons
We may use a technology called web beacons to collect general information about your use of our services and your use of special promotions or newsletters. The information we collect by web beacons allows us to statistically monitor the number of people who open our emails as well as provide us with other information about your interaction with our services.
At User Registration or When Buying Products or Services
When you register as a user or when buying our products or services, we may collect some or all of the following information: height, weight, activity level, sex, date of birth, and other information you choose to provide to us. Providing health-related information is optional and controlled by you.
Survey and Interview Questions
Occasionally, we contact our users and customers to ask for feedback or testimonials. Please know that by submitting your testimonial, you are granting us the right to use, reproduce, and publicly display your comments, along with your name and any images or videos you provide, across our various marketing and promotional channels. Your personal contact information will remain confidential and will not be shared publicly. By submitting your testimonial, you are acknowledging and agreeing to these terms.
Collecting Information About Your Physical Location
When you use our services, we may collect and process information about your actual physical location. We use several technologies, such as IP tracking, to determine your location. These technologies may also give us information about nearby cell towers, Wi-Fi access points, and other devices. We do not collect precise geolocation unless you explicitly enable a feature that requires it. Regardless, we do not use geofencing around health-care facilities to collect consumer health data or to target individuals.
Google API
By using our services, you are subject to the Google Privacy Policy and Terms of Service. When collecting and processing user data, including Personal Data (PD) from Google APIs, we will follow Google API Services User Data Policy. We also require that our employees, contractors, and agents comply with the Google API Services User Data Policy.
Chat Software or Contact Forms
Our services contain chat software or contact forms that enable visitors to communicate with us online or offline by email. In some cases, visitors can communicate with us without buying our services. When you use our chat software or contact forms, we may collect some or all the following information: your email address, first name, last name, location, and any other information you willingly choose to give us. You should limit the information you give to us to one that is necessary to answer your questions.
Google Analytics
Our services use Google Analytics to collect information about the use of our services. Google Analytics collects information from users such as age, gender, interests, demographics, how often they visit our services, what pages they visit, in-app actions, and what other websites they have used before coming to our services. We use the information we get from Google Analytics to analyze traffic and improve our marketing, advertising, and services. You can prevent Google Analytics from using your information about your website visits by opting out at this link: Google Analytics Opt-out Browser Add-on Download Page.
Analytics
Our services use analytics services from several companies other than Google to collect information about the use of our services. Analytics collects information such as how often users visit our services, what pages they visit, when they do so, and their IP addresses. We use the information we get from analytics to improve our services. We also use companies like Kochava, Firebase Analytics, and OneSignal for analytics services.
What Happens If You Don’t Give Us Your Personal Data (PD)
If you do not provide us with enough personal data , we may be unable to provide you with our services.
HOW YOUR PERSONAL DATA (PD) IS USED AND SHARED
We use the information we receive from you to:
-
-
respond to any requests from you regarding sales and support;
-
contact you about any agreements or terms that you may have with us;
-
provide the product and services you have requested or purchased from us;
-
personalize and customize our content;
-
make improvements to our services;
-
contact you with updates to our products and services;
-
resolve problems and disputes;
-
contact you with products and services that we believe may be of interest to you;
-
we may share your PD with our affiliates, which include our parent company and any other subsidiaries or joint venture partners. In such cases we will require those affiliates to honor this Privacy Notice.
-
We use Sensitive Personal Information only as reasonably necessary to provide the services you request, to ensure security/integrity, for short-term transient processing, to prevent fraud, and to comply with law; we do not use Sensitive Personal Information to infer characteristics about you beyond providing the services.
Communications and Emails
When we communicate with you about our services, we will use the email address you provided when you registered as a user or customer. We may also send you emails with promotional information about our services or offers from us or our affiliates unless you have opted out of receiving such information. You can unsubscribe to these by using the link in the emails. You can also change your contact preferences at any time by writing to our customer support team or contacting us using the information at the top of this privacy notice.
Sharing Your Information When You Login Using Other Websites or Services
We may share your Personal Data (PD) with third parties such as http://google.com, http://www.apple.com, and others. If you sign into our services through a third-party service or website, your information such as name, email address, language preference, profile picture etc. might be automatically imported to our services. We do not have any control over the privacy notices and business practices of other third-party services or websites.
If you log into our services using websites and services, you agree to let us use and store your profile information from those websites to make better use of any social media features on our services. This sharing of information helps us provide you with a better experience when using our services and provides us with information such as visitor traffic. If you use any of the social sharing icons on our services to share our information, you may also be sharing your personal information through other websites.
Text Messaging, SMS, Push Notifications, and Telephone Calls
If you provide a mobile telephone number, or landline telephone number to us, you are giving your express consent and authorize us or a third-party to contact you by using any of these communication methods. You are not required to give us your consent to contact you through these communication methods. However, withholding your consent may interfere with or prevent us from providing some or all of our services to you. You can stop receiving push notifications at any time by contacting us or using one of our opt-out methods. You can stop receiving text messages, SMS, and telephone calls at any time by contacting us.Standard message and data rates may apply. You may opt out at any time via in-app settings, submitting a data control request or by contacting us at support@waveswomen.com.
Sharing Information with Third Parties
We do not sell or rent your Personal Data (PD) or Sensitive Personal Data (SPD), which includes health information, to third parties for marketing purposes. We also do not “share” your personal data for cross-context behavioral advertising (as defined by CPRA).
Vendors that we hire to provide us with various services (Service Providers) may have access to your Personal Data (PD) while they are performing their contractual obligations. These third-party service providers may include but are not limited to payment processors, web analytics companies, data management services, large language model (LLM) providers, help desk providers, accountants, law firms, auditors, shopping carts, and email service providers. We may share your Personal Data with trusted service providers, such as Google Analytics (for usage analytics), Stripe (for payment processing), and Firebase (for app performance monitoring). Each third party only receives the data necessary to perform its function, and we contractually prohibit them from using it for any other purpose.LLM providers may receive de-identified or limited user inputs solely for the purpose of supporting chatbot or helpdesk interactions. They are contractually required not to use this data for model training or profiling.We prohibit our Service Providers from selling or disclosing the Personal Data (PD) we provide. We also require all Service Providers to maintain confidentiality standards that are commercially reasonable to ensure the security of your Personal Data (PD).
We reserve the right to share or sell aggregated, anonymous or deidentified information with third parties for marketing, advertising, research or other purposes. If we disclose deidentified information, we commit to maintain and use it in deidentified form and not attempt to reidentify it, except as permitted by law. We do not limit the use of aggregated information by third parties.
Legally Required Releases of Information
We may disclose your Personal Data (PD) if such disclosure is (a) required by subpoena, law, or other legal processes; (b) necessary to assist law enforcement officials or government enforcement agencies; (c) necessary to protect us from legal action or claims from third parties, including you and or other users; or (d) necessary to protect the legal rights, personal and or real property, or the personal safety of our company, users, employees, and business partners.
Disclosures to Successors
If our business is sold or merges in whole or in part with another business that would become responsible for providing the services to you, we retain the right to transfer your Personal Data (PD) to the new business. The new business would retain the right to use your personal data according to the terms of this privacy notice as well as to any changes to this privacy notice as instituted by the new business. We also retain the right to transfer your personal data if our company files for bankruptcy and some or all of our assets are sold to another individual or company. Any successor will be bound to materially similar privacy protections or we will provide you with notice and choices required by law.
Community Discussion Boards, Blogs, or Other Mechanisms
Our services may offer the ability for users to communicate through online community discussion boards, blogs, or other mechanisms. If you choose to post on these discussion mechanisms, you should use care when exposing any Personal Data (PD), as such information is not protected by our privacy notice, nor are we liable if you disclose your PD through such postings. Also, PD, which you post on our services for publication, may be available worldwide on the Internet. We cannot prevent the use or misuse of such information by others.
RETAINING AND DESTROYING YOUR PERSONAL DATA (PD)
We retain your PD if it is necessary to provide our services and or products to you and to fulfill the purposes outlined in our privacy notice, subject to any legal obligations that may require a longer retention period. PD associated with your account will be kept until it is no longer necessary to provide our services and or products or until you ask us to delete it.
The criteria used to determine our retention periods include:
-
The length of time we have a continuing relationship with you and provide the services and or products to you that you requested.
-
Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them).
-
Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation, or regulatory investigations).
For example, health entries are retained for as long as your account is active and then deleted within 30 days of account deletion. Billing records are retained for up to 7 years to comply with financial regulations.
De-identified or aggregated data:. When personal data is no longer necessary to provide the Services, we may de-identify or aggregate it and use or share the resulting information to generate insights (e.g., usage statistics). If we disclose de-identified data, we take reasonable measures to prevent reidentification, contractually require recipients to do the same, and do not attempt to reidentify the data except as permitted by law to test de-identification.
PROTECTING THE PRIVACY RIGHTS OF THIRD PARTIES
If you make any postings on our services that contain information about third parties, you agree that you have permission to include that information. While we are not legally liable for the actions of our users, we will remove any postings about which we are notified if such postings violate the privacy rights of others.
DO NOT TRACK SETTINGS
Some web browsers have settings that enable you to request that our services not track your movement within our services. While “Do Not Track” (DNT) signals are not standardized, if applicable we will honor browser-based opt-out preference signals related to “sale” or “sharing” of personal data(e.g.Global Privacy Control) as described above.
LINKS TO OTHER WEBSITES
Our services may contain links to other websites. These websites are not under our control and are not subject to our privacy notice. We have no responsibility for these websites, and we provide links to these websites solely for your convenience. You acknowledge that your use of and access to these websites are solely at your risk.
PROTECTING CHILDREN’S PRIVACY
Our services are not designed for use by anyone under the age of 18. We do not knowingly collect Personal Data (PD) from children under the age of 18. If you are a parent or guardian and believe that your child is using our services and they are under the age of 18, please contact us. Before we remove any information, we may ask for proof of identification to prevent malicious removal of account information. If we discover that a child under the age of 18 is accessing our services, we will delete their information within a reasonable period of time. You acknowledge that we do not verify the age of our users nor have any liability to do so. Because our services are 18+, CPRA’s under-16 opt-in for “sale/share” does not apply.
OUR EMAIL POLICY
You can always opt-out of receiving email correspondence from us or our affiliates. We will not sell, rent, or trade your email address to any unaffiliated third-party without your permission except in the sale or transfer of our company or if our company files for bankruptcy as described in the section Disclosures to Successors.
OUR SECURITY POLICY
We have built our services and services using industry-standard security measures and authentication tools to protect the security of your Personal Data (PD). We and the third parties who provide services to us also maintain technical and physical safeguards to protect your PD. Unfortunately, we cannot guarantee the prevention of loss or misuse of your PD or secure data transmission over the Internet because of its nature. We strongly urge you to protect any password you may have for our services and not share it with anyone. We implement role-based access controls, encryption in transit, and vendor due diligence appropriate to the sensitivity of your personal data , including health-related information. In the event of a data breach affecting your personal data, we will provide notifications as required by applicable U.S. law. If an incident involves PHR identifiable health information as defined by the FTC’s Health Breach Notification Rule (HBNR), we will notify affected individuals, the FTC, and, where required, the media, within HBNR timelines and with required content.
USE OF YOUR CREDIT CARD
You may have to provide a credit or debit card to buy products and services from our services. We use third-party billing services and have no control over them. We use commercially reasonable efforts to ensure that your credit card number is kept strictly confidential by using only third-party billing services that use industry-standard encryption technology to protect your credit card number from unauthorized use. However, you understand and agree that we are in no way responsible for any misuse of your credit card number.
IN-APP PURCHASES
“Waves Women” does not directly collect or store your payment information. Payments are processed either by way of the Apple Store or Google Play or by our service provider(s) when you make purchases directly within the app. Payment processors act as independent controllers of your payment information under their own privacy terms.
YOUR STATE PRIVACY RIGHTS & OPT-OUT PREFERENCES
You may submit privacy requests (access, correction, deletion, portability) by emailing support@waveswomen.com. If our practices ever involve “selling” or “sharing” personal data , we will provide a clear “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control signals. We do not engage in targeted advertising based on your health entries.
CONSUMER HEALTH DATA (WA & NV) NOTICE
Consumer Health Data (Washington & Nevada). We collect consumer health data (e.g., menstrual, hormonal, and related wellness entries) only with your affirmative consent and separate consent to share with processors for security, debugging, fraud prevention, support, or analytics calibration. We do not sell consumer health data and do not use geofencing around health-care facilities. WA/NV residents may exercise access, deletion, and appeal rights via reaching out to our support team (support@waveswomen.com). We keep internal records of consents (timestamp, scope, notice version).
LIMITING USE OF SENSITIVE PERSONAL INFORMATION
We collect Sensitive Personal Information you choose to provide (e.g., health-related entries) solely to deliver the services you request. We do not use Sensitive Personal Information for additional purposes (e.g., marketing, profiling) and therefore the CPRA “right to limit” does not apply. We do not use Sensitive Personal Information to infer characteristics, profile you, or for any secondary marketing purposes. Therefore, the CPRA’s ‘right to limit’ does not apply. If this changes, we will notify you and honor your right to limit such use.
HIPAA Notice: We are not a HIPAA “covered entity” or “business associate.” Information you provide to us is not “protected health information (PHI)” under HIPAA; it is governed by this privacy notice and applicable state privacy laws.
APPEALS OF DENIED REQUESTS
If we deny your privacy request, you may appeal by replying to our decision email or by emailing support@waveswomen.com with “Privacy Request Appeal” in the subject. Residents of Virginia, Colorado, and Connecticut have the right to appeal our denial of privacy rights. We will inform you in writing of any action taken or not taken in response to the appeal and the reasons, including how to contact your state attorney general, where applicable.
TRANSFERRING PERSONAL DATA (PD) FROM OTHER COUNTRIES
We operate in the United States and do not target individuals outside the U.S. personal data that we collect from you may be stored, processed, and transferred among any countries in which we operate. If you are located outside the U.S. and choose to use the services, you understand your PD will be transferred to the U.S. and processed under U.S. law.
CHANGES TO OUR PRIVACY NOTICE
We reserve the right to change this privacy notice at any time. If our company decides to change this privacy notice, we will post those changes on our services so that our users and customers are always aware of what information we collect, use, and disclose. If at any time we decide to disclose or use your Personal Data (PD) in a method different from that specified at the time it was collected, we will provide advance notice by email sent to the email address on file in your account or notify you with an in-app notice. Otherwise, we will use and disclose our users’ and customers’ personal data in agreement with the privacy notice in effect when the information was collected. In all cases, your continued use of our services and products after any change to this privacy notice will constitute your acceptance of the change. If you have questions about our privacy notice, please contact us through the information at the top of this privacy notice.If material changes affect how we use your personal data , we will provide prominent in-app notice and, where required, obtain consent.
Copyright © – This document or any portion of it may not be copied or duplicated in any way without a license.
Contact us
support@waveswomen.com
Explore
Waves Women app
About
Privacy policy
Terms of service
Waves labs corp
Headquarters
Waves Labs Corp.
8401 MAYLAND DR #6338
RICHMOND, VA, 23294, USA
© 2025 Waves Women. All rights reserved