Privacy policy

Privacy Policy

Last Updated: April 14, 2026

1. Purpose and Scope

Welcome to Lara Orndorff LLC d/b/a Lara’s Mahjong Edit (“Company,” “we,” “us,” or “our”). This Privacy Policy (“Policy”) outlines how we collect, use, share, and protect your personal information when you visit our website larasmahjongedit.com and any related subpages (the “Website”).

This Policy applies when you:

  • Visit or browse our Website.
  • Engage with any features such as chat, user submissions, or electronic messaging on our Website.
  • Opt into email newsletters or marketing communications.
  • Purchase products, digital products, courses, or join membership programs via our Website.
  • Interact with our ads or marketing content on third-party websites or platforms.

This Policy does not cover data collected offline or via third-party websites or platforms, including affiliates or service providers.

This Policy describes our data practices. Where required by applicable law, we will obtain your consent before collecting or processing your personal information. By providing your information through forms, account registration, or purchases on our Website, you consent to the practices described in this Policy. For browsing data and cookies, please see our cookie consent preferences in Section 7.

2. Age Requirements

We do not knowingly collect or solicit personal information from anyone under the age of 16. If you are under 16, please do not submit any personal information to us. If we learn that we have inadvertently collected personal information from someone under 16, we will promptly delete it.

If you believe we have collected such information, please contact us at support@larasmahjongedit.com.

3. Legal Bases for Processing

We process your personal information only when we have a valid legal basis to do so. Depending on the circumstances, we rely on one or more of the following:

  • Contract Performance. Processing that is necessary to fulfill a contract with you, such as completing a purchase or delivering a digital product.
  • Legitimate Interests. Processing that is necessary for our legitimate business interests (such as improving our Website, marketing our services, or preventing fraud), provided those interests are not overridden by your rights.
  • Consent. Where you have given us clear, affirmative consent to process your data for a specific purpose, such as subscribing to a newsletter or opting into marketing communications. You may withdraw consent at any time.
  • Legal Obligation. Processing that is necessary for us to comply with applicable laws, regulations, or legal processes.

4. Information We Collect

We collect various types of personal information from you, which may include:

  • Personal Identifiers. Name, email address, phone number, billing/shipping address.
  • Financial Information. Payment details such as credit card or banking information (processed by our payment providers).
  • Geolocation Data. IP address, location data from your device.
  • Demographic Information. Age, gender, occupation, and similar information you choose to share.
  • Internet and Device Activity. Browser type, operating system, browsing behavior on our Website.
  • Authentication Data. Account usernames, passwords, and account security data.
  • Media. Photos, videos, or other media you may upload to the Website or submit via social media.
  • Digital Product and Course Data. Course progress, completion history, and engagement data collected when you purchase a digital product, join a course, or subscribe to a membership program.
  • Order and Transaction Information. Products or services purchased, order history, order amounts, and delivery information.
  • Customer Service Records. Records of communications with our customer support team, including chat logs and email correspondence.
  • User Preferences and Profiles. Product reviews, testimonials, and account settings.

This data is collected directly from you when you provide it (e.g., during registration or purchase) or automatically via cookies and other tracking technologies when you browse our Website.

5. Sensitive Personal Information

Some of the information we collect may be classified as “sensitive personal information” under applicable privacy laws, including:

  • Financial account information (e.g., credit card or bank account numbers combined with access credentials).
  • Precise geolocation data.
  • Account login credentials (usernames combined with passwords or security questions).

We use sensitive personal information only as necessary to provide the services you request, process transactions, ensure security, and comply with legal obligations. We do not use or disclose sensitive personal information for purposes beyond those permitted by applicable law.

If you are a California resident, you have the right to limit our use and disclosure of your sensitive personal information. To exercise this right, please see Section 10 below.

6. Sources of Information

Your personal information may be collected from the following sources, including but not limited to:

  • Directly from You. When you fill out forms, subscribe to services, create an account, or make purchases.
  • Payment Processors. When you make a purchase, we collect data via third-party payment gateways (e.g., Shop Pay, Stripe, PayPal) to process your transactions.
  • Analytics Providers. Such as Google Analytics, to monitor traffic and understand how users interact with our Website.
  • Social Media Platforms. If you interact with our content on Instagram, TikTok, Facebook, or similar platforms, those platforms may share your data with us.
  • Email Marketing Platforms. We collect data through email marketing providers (Flodesk and Klaviyo) when you subscribe to our newsletter or download resources.
  • SMS and Messaging Platforms. ManyChat is used to manage direct message automations on Instagram.
  • E-Commerce and Course Platforms. Shopify, Kajabi, and Circle process order and customer data related to purchases and memberships.
  • Affiliate Networks. ShopMy, Amazon Associates, UpPromote, GoAffPro, and Shopify Collabs track referral and commission data.
  • Advertising Networks. When you interact with our ads on third-party platforms (e.g., Meta Ads, Google Ads, Pinterest), those platforms may share information on your engagement with our advertisements.
  • Automated Data Collection. We use cookies, web beacons, and similar technologies to collect data on how you interact with our Website and ads, including your browsing behavior, device information, and IP address.

7. Cookies, Tracking Technologies, and Affiliate Marketing

We use cookies and similar tracking technologies (e.g., web beacons, pixels) to enhance your experience and understand how you use our Website. We use the following categories of cookies:

  • Strictly Necessary Cookies. Required for the Website to function properly (e.g., session management, security, shopping cart). These cookies cannot be disabled.
  • Performance and Analytics Cookies. Help us understand how visitors interact with our Website by collecting usage data.
  • Functional Cookies. Allow us to remember your preferences and settings to personalize your experience.
  • Advertising and Targeting Cookies. Used by us and third-party advertising partners (e.g., Meta Pixel, Google Ads, Pinterest) to deliver ads relevant to your interests.

We also allow third-party cookies and tracking technologies on our Website to collect data about your browsing habits for marketing purposes, such as retargeting ads. These third-party services may collect information such as your IP address, device information, and browsing behavior.

We participate in affiliate marketing programs. When you click on affiliate links and make a purchase, we may receive a commission, and certain tracking data may be shared with our partners for this purpose.

You can manage your cookie preferences through our cookie consent tool on the Website or through your browser settings. For information on opting out of the sale or sharing of your personal information through cookies and tracking technologies, see Section 9 below.

8. How We Use Your Information

Your personal information may be used for the following purposes:

  • To personalize your experience on our Website.
  • To process your transactions, including payments and delivery of digital products.
  • To communicate with you about your account, purchases, or customer service inquiries.
  • To deliver marketing and promotional content that may interest you, including newsletters and product updates.
  • To comply with legal obligations and protect our legal rights.
  • To improve Website performance and develop products or services based on analytics.
  • To fulfill and manage your orders, including digital delivery and access to courses and memberships.
  • To prevent fraud and protect transaction security.
  • To track progress and provide feedback for online courses or membership programs.
  • To manage and administer subscription services, including billing cycles and renewals.
  • To administer surveys, quizzes, or feedback forms.
  • To facilitate affiliate marketing programs and track referrals.
  • To manage and optimize advertising campaigns across social media and search engines.
  • To generate testimonials or case studies for marketing purposes, with your consent.

9. Data Sharing, Sale, and Sharing

Your personal data may be shared with the following parties for the purposes outlined below:

Service Providers. We share your information with trusted third-party service providers who assist in the operation of our business, including:

  • Payment Processors. Shop Pay, Stripe, PayPal, and similar financial institutions.
  • E-Commerce, Course, and Membership Platforms. Shopify (website and store), Kajabi (Teacher Edit, Build Your Table), and Circle (Confidence Club, All Access).
  • Email Marketing and Automation Tools. Flodesk and Klaviyo manage email communications, deliver newsletters, and automate responses.
  • Messaging Automation. ManyChat manages Instagram direct message automations.
  • Hosting and IT Support. Shopify provides web hosting and platform security.
  • Analytics Providers. Google Analytics and Meta Pixel help us understand Website performance and user behavior.
  • Reviews and User-Generated Content Platforms. Third-party review tools that collect and display product reviews on our behalf.

Affiliates and Business Partners. We may share information with our business affiliates and partners for:

  • Affiliate Marketing Programs. ShopMy, Amazon Associates, UpPromote, GoAffPro, and Shopify Collabs track commissions and referrals.
  • Co-Branded Promotions. Collaborations for joint promotions, events, online workshops, or webinars.

Advertising Networks and Social Media Platforms. To deliver more personalized ads, we may share information (e.g., device data, browsing history) with Meta Ads, Google Ads, Pinterest, TikTok, and similar advertising networks.

Legal Authorities. We may disclose your personal information when required to do so by law, regulation, or legal process, including court orders, subpoenas, or governmental requests, and to protect our legal rights and safety.

Corporate Transactions. In the event of a merger, acquisition, restructuring, or sale of our assets, your personal information may be transferred to a third party as part of the transaction.

Non-Personally Identifiable Information. We may share aggregated or de-identified data that cannot reasonably be used to identify you.

Consent-Based Sharing. In any other situation where we need to share your personal information, we will do so only with your explicit consent.

Sale and Sharing of Personal Information

We do not sell your personal information to third parties for direct financial compensation. However, we allow certain third parties (such as ad networks or affiliate partners) to collect information about your activities on our Website through cookies or other tracking technologies. Under certain privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), this activity may be considered a “sale” or “sharing” of personal information.

“Sharing” under the CCPA/CPRA means disclosing personal information to a third party for cross-context behavioral advertising purposes, whether or not for monetary consideration. Because we use third-party advertising pixels, retargeting tools, and similar technologies, some of our data practices may constitute “sharing” under this definition.

How to Opt Out of Sale, Sharing, and Targeted Advertising

You may opt out of the sale and sharing of your personal information and manage your data sharing preferences through any of the following methods:

  • Click the “Do Not Sell or Share My Personal Information” link on our Website.
  • Enable a Global Privacy Control (GPC) signal in your browser. We honor GPC signals as a valid opt-out request (see Section 11 below).
  • Adjust your cookie preferences via our cookie consent tool or your browser settings.
  • Opt out of targeted advertising by visiting https://optout.networkadvertising.org/?c=1.
  • Opt out of marketing communications via the unsubscribe link in any of our emails.
  • Contact us directly at support@larasmahjongedit.com to opt out of specific types of data sharing.

Please note that once your data is shared with a third-party service provider or partner, their privacy practices and policies will apply. We encourage you to review the privacy policies of any third-party websites or services you engage with.

10. Consumer Rights

You have certain rights regarding your personal data under applicable privacy laws. The specific rights available to you depend on your jurisdiction.

Rights Available to All Users

  • Right to Access. Request access to the personal data we hold about you.
  • Right to Correction. Request correction of inaccurate or incomplete data.
  • Right to Deletion. Request the deletion of your personal data (subject to legal exceptions).
  • Right to Opt-Out. Opt out of the sale or sharing of your data or targeted advertising.
  • Right to Data Portability. Request transfer of your data to another provider in a commonly used format.

Additional Rights for California Residents (CCPA/CPRA)

  • Right to Know. Request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your data.
  • Right to Limit Use of Sensitive Personal Information. Direct us to limit the use and disclosure of your sensitive personal information.
  • Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights.
  • Right to Opt Out of Sale and Sharing.

Additional Rights for EU/UK Residents (GDPR/UK GDPR)

  • Right to Restrict Processing.
  • Right to Object. Object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent.
  • Right to Lodge a Complaint with your local data protection supervisory authority.

How to Exercise Your Rights

To exercise any of these rights, please contact us at support@larasmahjongedit.com. We will respond to verifiable requests within the timeframes required by applicable law (generally 45 days for CCPA/CPRA requests and 30 days for GDPR requests, with extensions permitted where necessary).

We may need to verify your identity before processing your request. If you use an authorized agent to submit a request on your behalf, we may require proof of authorization.

Right to Appeal

If we decline to take action on your request, you have the right to appeal our decision. To submit an appeal, contact us at support@larasmahjongedit.com with the subject line “Privacy Rights Appeal.” If your appeal is denied, you may contact your state attorney general or applicable data protection authority.

11. Do Not Track and Global Privacy Control (GPC)

Our Website honors Global Privacy Control (GPC) signals. When we detect a GPC signal from your browser, we will treat it as a valid opt-out request for the sale and sharing of personal information associated with that browser, as required by applicable law.

With respect to Do Not Track (DNT) browser signals, there is currently no industry-wide standard for how websites should respond to DNT signals. We will update this Policy if a uniform standard is adopted.

For more details on GPC, visit https://globalprivacycontrol.org.

12. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected:

  • Account and transaction data: Retained for the duration of your account or business relationship, plus 7 years to comply with tax, accounting, and legal obligations.
  • Marketing data: Retained until you unsubscribe or request deletion.
  • Analytics and cookie data: Retained for up to 24 months.
  • Legal and compliance records: Retained as required by applicable law.

After the applicable retention period, we will securely delete or anonymize your personal data unless retention is required by law. You can request deletion of your data by contacting us, except where retention is required by law.

13. Data Security

We implement appropriate technical and organizational security measures to protect your data from unauthorized access, loss, or misuse, including encryption, access controls, and secure data storage. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee the absolute security of your data.

You are responsible for keeping your account credentials secure. We are not liable for any unauthorized access resulting from your failure to safeguard your login information.

14. International Data Transfers

If you are located outside the United States, your personal data may be transferred to and processed in the United States or other countries where our third-party service providers operate. We take steps to ensure such transfers comply with applicable data protection laws, such as the GDPR, by implementing standard contractual clauses or similar legal mechanisms.

15. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal obligations. The “Last Updated” date at the top of this page reflects the latest version. If material changes are made, we will notify you via email or post a notice on our Website. Your continued use of the Website following such changes indicates your acceptance of the updated Policy.

16. Contact Us

If you have any questions, concerns, or would like to exercise your privacy rights, you can reach us using the following contact methods:

Email: support@larasmahjongedit.com

Mail:
Lara Orndorff LLC d/b/a Lara’s Mahjong Edit
3735 Scotland Rd, PO Box 180
Scotland, PA 17254