Privacy policy
THE RYL COMPANY LLC
PRIVACY POLICY
Effective Date: April 13, 2026
Last Updated: April 13, 2026
1. Introduction
The Ryl Company LLC ("we," "us," "our," or "The Ryl Company") respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at www.drinkryl.com (the "Site"), use our mobile applications, purchase our products, or otherwise interact with us (collectively, the "Services").
This Privacy Policy applies to all visitors, users, and customers of our Services, regardless of location. Certain sections of this Policy provide additional disclosures and rights for residents of specific states, including California, Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws.
We do not sell your personal information. We do not activate any non-essential tracking technologies on our Site until you have provided affirmative consent through our consent management platform, except for technologies strictly necessary to operate the Site.
2. Information We Collect
2.1 Information You Provide to Us
We collect information you voluntarily provide, including: your name, email address, mailing address, phone number, and payment information when you make a purchase; account registration information; communications you send us (e.g., customer support inquiries); newsletter signup information; subscription preferences (e.g., Subscribe & Save enrollment); and product reviews or feedback.
2.2 Information Collected Automatically
When you visit our Site, certain information may be collected automatically, but only after you have provided affirmative consent through our consent management platform, except for information strictly necessary to operate the Site. The categories of automatically collected information include:
Device and Browser Information: IP address (anonymized where possible), browser type and version, operating system, device identifiers, and screen resolution.
Usage Information: Pages visited, time spent on pages, click patterns, referring URLs, and search queries within the Site.
Location Information: General geographic location derived from IP address (city/state level only).
Transaction Information: Purchase history, cart contents, subscription details, and order-related data.
2.3 Cookies and Tracking Technologies
Our Site uses cookies and similar tracking technologies. We categorize these technologies as follows:
Strictly Necessary Technologies -- These are required for the Site to function and cannot be disabled. They include Shopify platform cookies for cart functionality, session management, checkout processing, and security. Subscription management functionality (Recharge) required for Subscribe & Save orders is also included in this category. These do not require your consent.
Analytics Technologies -- These help us understand how visitors use our Site (e.g., Google Analytics). These are blocked by our consent management platform and are not loaded until you affirmatively consent.
Marketing and Advertising Technologies -- These are used for targeted advertising, conversion tracking, and affiliate marketing (e.g., TikTok Pixel, Pinterest Tag, Amazon Ads, Facebook Pixel, Klaviyo, AspireIQ/Tune). These are blocked by our consent management platform and are not loaded until you affirmatively consent.
Functional Technologies -- These enable enhanced features such as product reviews, accessibility tools, and email marketing popups. These are blocked by our consent management platform and are not loaded until you affirmatively consent.
2.4 How Our Consent Mechanism Works
When you first visit our Site, a cookie consent banner will appear. This banner is powered by a third-party consent management platform ("CMP") that actively blocks all non-essential scripts, cookies, and tracking technologies from loading until you make a consent choice.
No non-essential cookies, pixels, scripts, or tracking technologies will be activated until you affirmatively click "Accept All" or select your preferences by category. You may:
- Accept all non-essential cookies and tracking technologies;
- Decline all non-essential cookies and tracking technologies;
- Customize your choices by category (Analytics, Marketing, Functional).
If you decline or close the banner without accepting, only strictly necessary technologies will operate.
You may change your preferences at any time by clearing your browser cookies and revisiting the Site, at which point the consent banner will reappear.
2.5 Consent Logging
We maintain records of all consent actions, including: the date and time consent was granted, modified, or withdrawn; the specific categories of consent granted or denied; and the version of the consent notice presented. These records are retained for a minimum of three (3) years and are available for regulatory review upon request.
3. How We Use Your Information
We use the information we collect for the following purposes: to process and fulfill your orders; to manage your subscriptions (Subscribe & Save); to communicate with you about your orders and account; to provide customer support; to send marketing communications (with your consent); to improve our Site and Services; to detect and prevent fraud; to comply with legal obligations; and to analyze Site traffic and usage patterns (with your consent).
We do not use your information to build behavioral profiles for targeted advertising without your affirmative consent. All analytics and marketing data collection requires your prior opt-in through our consent mechanism.
From time to time, we may offer you the opportunity to opt in to receive email communications from certain licensed third-party affiliates ("Licensed Affiliates"). This opt-in will be presented separately from any sign-up for Ryl communications and will clearly identify the Licensed Affiliate and link to their privacy policy.
If you choose to opt in to receive communications from a Licensed Affiliate, we will share your name and email address with that Licensed Affiliate solely for the purpose of enabling them to send you the communications you requested.
Any emails you receive from a Licensed Affiliate will be governed by that affiliate's own privacy policy, which will be linked at the point where you provide your consent.
You may withdraw your consent to receive Licensed Affiliate communications at any time by following the unsubscribe instructions in the affiliate's emails or by contacting us at legal@drinkryl.com.
We will not share your information with any Licensed Affiliate unless you have affirmatively opted in to receive their communications.
4. How We Share Your Information
We may share your personal information with the following categories of third parties:
Service Providers: Companies that help us operate our business (e.g., Shopify for e-commerce, payment processors, shipping carriers such as ShipStation and Shippo, email service providers, subscription management). These providers are contractually obligated to use your information only to provide services to us.
Analytics Providers: Companies like Google Analytics that help us understand Site usage. These providers receive data only after you consent to analytics cookies.
Advertising Partners: Advertising platforms (e.g., TikTok, Pinterest, Amazon Advertising, Facebook/Meta) that help us measure ad effectiveness. These partners receive data only after you consent to marketing cookies.
Affiliate and Influencer Platforms: Platforms such as AspireIQ, ShareASale, and GoAffPro that manage our affiliate and influencer marketing programs. These platforms receive data only after you consent to marketing cookies.
Reviews Platform: Stamped.io, which powers our product reviews. This platform receives data only after you consent to functional cookies.
Legal Requirements: We may disclose information when required by law, regulation, legal process, or governmental request.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction.
We do not sell your personal information. Under the California Consumer Privacy Act (CCPA), "sale" includes sharing personal information for monetary or other valuable consideration. We do not engage in such practices. To the extent any sharing of data with advertising partners could be construed as a "sale" or "sharing" under the CCPA, such sharing occurs only with your affirmative consent.
5. Third-Party Technologies on Our Site
The following third-party technologies may be loaded on our Site after you provide consent. None of these technologies are loaded before you interact with our consent mechanism.
MARKETING / ADVERTISING (Require Marketing Consent):
TikTok Pixel (analytics.tiktok.com) -- Advertising conversion tracking provided by TikTok/ByteDance. Purpose: To measure the effectiveness of TikTok advertising campaigns. Data collected: IP address, browser information, conversion events. Privacy policy: https://www.tiktok.com/legal/privacy-policy
Pinterest Tag (ct.pinterest.com) -- Advertising conversion tracking provided by Pinterest. Purpose: To measure the effectiveness of Pinterest advertising campaigns. Data collected: IP address, browser information, conversion events. Privacy policy: https://policy.pinterest.com/en/privacy-policy
Amazon Advertising (amazon-adsystem.com) -- Advertising platform provided by Amazon. Purpose: To measure the effectiveness of Amazon advertising campaigns. Data collected: IP address, browser information, conversion events. Privacy policy: https://www.amazon.com/gp/help/customer/display.html?nodeId=468496
Facebook/Meta Pixel (facebook.com) -- Advertising conversion tracking provided by Meta Platforms. Purpose: To measure the effectiveness of Facebook and Instagram advertising campaigns. Data collected: IP address, browser information, conversion events. Privacy policy: https://www.facebook.com/privacy/policy/
Klaviyo (klaviyo.com) -- Email marketing platform. Purpose: To deliver email marketing campaigns and track their effectiveness. Data collected: Email address (when provided), browsing activity on the Site (after consent). Privacy policy: https://www.klaviyo.com/legal/privacy
AspireIQ / Tune (go2sdk.com, aspireiq.go2cloud.org) -- Influencer and affiliate marketing tracking. Purpose: To track conversions from influencer marketing campaigns. Data collected: IP address, referral data, conversion events. Privacy policy: https://www.aspire.io/privacy-policy
ANALYTICS (Require Analytics Consent):
Google Analytics 4 (analytics.google.com) -- Web analytics service provided by Google LLC. Purpose: To understand how visitors use our Site. Data collected: Anonymized IP address, pages visited, session duration, browser/device information. Privacy policy: https://policies.google.com/privacy
Bugsnag (bugsnag.com) -- Error monitoring service provided by SmartBear Software. Purpose: To identify and fix website errors to improve user experience. Data collected: Browser/device information, error logs, page URLs. Privacy policy: https://smartbear.com/privacy/
FUNCTIONAL (Require Functional Consent):
Stamped.io (stamped.io, powl.io) -- Product reviews platform. Purpose: To display and collect product reviews. Data collected: Name, email, review content, browsing activity. Privacy policy: https://stamped.io/privacy
AccessiBe (acsbapp.com) -- Web accessibility platform. Purpose: To provide accessibility tools and compliance features for users with disabilities. Data collected: Accessibility preferences, browser/device information. Privacy policy: https://accessibe.com/privacy-policy
DATA PIPELINES (Require Analytics Consent):
Fivetran (webhooks.fivetran.com) -- Data pipeline service. Purpose: To sync business data for internal analytics and reporting. Data collected: Anonymized transaction and event data. Privacy policy: https://www.fivetran.com/legal/privacy
STRICTLY NECESSARY (No Consent Required):
Shopify (cdn.shopify.com, sessions-production.shopifysvc.com, monorail-edge.shopifysvc.com) -- E-commerce platform. Purpose: Core site functionality including cart, checkout, session management, and platform telemetry. Data collected: Session data, cart contents, device information.
Recharge (rechargecdn.com) -- Subscription management. Purpose: To manage Subscribe & Save orders and recurring billing. Data collected: Subscription preferences, order data. Privacy policy: https://rechargepayments.com/privacy-policy
6. Your Privacy Rights
Depending on your state of residence, you may have the following rights regarding your personal information:
6.1 Rights for California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides you with the following rights:
Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share your information.
Right to Delete: You may request that we delete your personal information, subject to certain exceptions (e.g., completing a transaction, detecting security incidents, complying with legal obligations).
Right to Correct: You may request that we correct inaccurate personal information we maintain about you.
Right to Opt-Out of Sale/Sharing: You may opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information. Any sharing with advertising partners requires your prior affirmative consent.
Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information to purposes necessary to provide our Services.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, see Section 6.7 below.
6.2 Rights for Virginia Residents (VCDPA)
Virginia residents have rights to access, correct, delete, obtain a copy of their personal data in a portable format, and opt out of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
6.3 Rights for Colorado Residents (CPA)
Colorado residents have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, or certain profiling. You may designate an authorized agent to exercise your rights on your behalf.
6.4 Rights for Connecticut Residents (CTDPA)
Connecticut residents have rights to access, correct, delete, obtain a portable copy of their personal data, and opt out of targeted advertising, sale of personal data, or profiling.
6.5 Rights for Texas Residents (TDPSA)
Texas residents have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, or profiling. The Texas Data Privacy and Security Act provides additional protections for sensitive data and data concerning minors.
6.6 Rights for Residents of Other States
Additional states including Oregon, Montana, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Nebraska, Delaware, Maryland, Minnesota, and others have enacted comprehensive privacy laws. We extend the core rights of access, correction, deletion, data portability, and opt-out of targeted advertising and sale to all U.S. residents regardless of state, to the extent required by applicable law.
6.7 How to Exercise Your Rights
To exercise any of the rights described above, you may:
- Email us at legal@drinkryl.com with the subject line "Privacy Rights Request";
- Write to us at The Ryl Company LLC, Attn: Privacy Compliance, 4 East Frederick Place, Building L, Cedar Knolls, NJ 07927;
- Use the cookie consent banner on our Site to manage cookie and tracking preferences;
- Use our "Do Not Sell or Share My Personal Information" page accessible from the footer of our Site.
We will verify your identity before processing your request. We will respond to verifiable consumer requests within 45 days (or 30 days where required by applicable state law). We may extend this period by an additional 45 days where reasonably necessary, with notice to you.
If we deny your request, you may appeal by contacting us at legal@drinkryl.com with the subject line "Privacy Rights Appeal." We will respond to appeals within 60 days (or such shorter period as required by applicable state law). If your appeal is denied, you may contact your state's attorney general.
7. California Invasion of Privacy Act (CIPA) Compliance
We are committed to compliance with the California Invasion of Privacy Act (Cal. Penal Code Sections 630 et seq.), including provisions relating to pen registers, trap and trace devices, and wiretapping.
7.1 No Pre-Consent Tracking
Our Site does not install, use, or cause the installation or use of any pen register or trap and trace device (as defined in Cal. Penal Code Section 638.50) without the informed, specific, and affirmative consent of the user. All non-essential tracking technologies that may capture addressing, routing, signaling, or content information are affirmatively blocked by our consent management platform from loading until the user provides express consent.
7.2 No Interception of Communications
Our Site does not intercept, read, or attempt to read the contents of any electronic communication in transit without the consent of all parties to the communication. Third-party scripts that may process user communications (such as search queries, form inputs, or chat messages) are not activated until the user provides consent.
7.3 Technical Implementation
We use a consent management platform that employs script-blocking technology to prevent all non-essential third-party scripts, pixels, and tracking technologies from loading or executing until the user has provided affirmative consent. This blocking occurs at the browser level before any data is transmitted to third-party servers. Our implementation is regularly tested and verified to ensure no non-essential data collection occurs prior to consent.
7.4 Consent Mechanism
Consent is obtained through a clearly visible banner presented on the user's first visit to the Site. The banner requires an affirmative action (clicking "Accept All" or selecting specific categories) before any non-essential technologies are activated. Dismissing the banner, scrolling, or continuing to browse does not constitute consent. Only strictly necessary technologies (as defined in Section 2.3) operate prior to consent.
8. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Specifically:
- Order and transaction data: retained for 7 years for tax and legal compliance.
- Account information: retained for the duration of your account plus 30 days after deletion request.
- Subscription data: retained for the duration of your subscription plus 1 year after cancellation.
- Marketing and analytics data collected through cookies: retained for no more than 13 months from collection.
- Consent records: retained for a minimum of 3 years.
- Customer support communications: retained for 3 years.
- Data subject request records: retained for 3 years.
When retention periods expire, personal information is securely deleted or anonymized.
9. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information, including:
- SSL/TLS encryption for all data in transit;
- Payment information processed by PCI-DSS compliant payment processors (payment card data is never stored on our servers);
- Access controls limiting employee access to personal information on a need-to-know basis;
- Regular security assessments of our third-party service providers.
However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
10. Children's Privacy
Our Services are not directed to individuals under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at legal@drinkryl.com and we will promptly delete such information.
11. International Users
Our Site is operated in the United States. If you are located outside the United States, please be aware that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our Services, you consent to this transfer. We do not specifically target or market to individuals outside the United States.
12. Do Not Track / Global Privacy Control
We honor Global Privacy Control (GPC) signals. When we detect a GPC signal from your browser, we treat it as a valid opt-out of the sale or sharing of your personal information and of targeted advertising, as required by applicable law including the CCPA/CPRA.
We also respect "Do Not Track" browser signals by not loading non-essential tracking technologies for users who have enabled this setting.
13. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you without human involvement. Any personalization of your experience (such as product recommendations) is based on general browsing behavior and does not constitute profiling as defined under applicable privacy laws.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy;
- Post a notice on our Site;
- Where required by law or where changes affect how we process your personal information, notify you by email;
- Where changes affect our cookie or tracking practices, reset consent preferences so you can make a new informed choice.
We encourage you to review this Privacy Policy periodically.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us:
The Ryl Company LLC
Attn: Privacy Compliance
4 East Frederick Place, Building L
Cedar Knolls, NJ 07927
Email: legal@drinkryl.com