Free shipping on orders over $200 — add the Sculpt to unlock

Legal

Privacy Policy

Version 3.0Effective 1 March 2026Steinhoff Group LLC

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you can exercise — including under the GDPR, the UK GDPR and the CCPA/CPRA. Cookies and tracking technologies are covered in detail in the Cookie Policy.

1.Who We Are and Scope

1.1
Controller.Steinhoff Group LLC, a Wyoming limited liability company, trading as Radia is the controller of personal data collected through radia.company. References to we, us and our mean that entity.
1.2
What this policy covers.This policy covers personal data we process when you visit the Site, create an account, place an Order, contact us, complete a quiz, subscribe to marketing, submit a review, or interact with our advertising. It does not cover third-party sites we link to.
1.3
Contact for privacy matters.All privacy enquiries and data rights requests should be sent to privacy@radia.company. Please use this address rather than general support so that requests are logged and handled within the statutory timeframe.
1.4
Children.The Site is not directed at children under 16 and we do not knowingly collect their data. If we learn that we hold data of a child under 16 without appropriate consent we will delete it. A parent or guardian may contact privacy@radia.company to request deletion.

2.Data We Collect From You

2.1
Identity and contact data.Name, email address, postal and billing address, telephone number, and any name or message you add for a gift recipient.
2.2
Order and transaction data.Items purchased, variants, quantities, prices, discounts and promotion codes used, order reference, currency, tax and shipping amounts, delivery status, returns and claim history, and correspondence relating to an Order.
2.3
Payment data.Payment method type, the last four digits and expiry of a card, the authorisation result and a processor token. We do not receive or store full card numbers or security codes — these are captured directly by our payment processor.
2.4
Account data.Login credentials in hashed form, saved addresses, order history, preferences, and authentication tokens.
2.5
Support and correspondence data.The content of your emails, chat messages, form submissions and claim evidence, including any photographs or video you send us, together with our internal notes on the matter.
2.6
Voluntary health information.If you tell us about your skin condition, sensitivity, medication, pregnancy or a medical contraindication — for example in a quiz answer or a support enquiry — we process it only to answer you and to record the safety issue. Please do not send more health information than is necessary.
2.7
Marketing preferences.Whether you have subscribed or unsubscribed, the channel you consented to, and the date, source and evidence of consent.
2.8
User-generated content.Reviews, ratings, photographs, testimonials and any other material you choose to submit, together with the display name you give.

3.Data We Collect Automatically

3.1
Device and connection data.IP address, approximate location derived from it, browser type and version, operating system, device type, screen and viewport size, language, time zone and referring URL.
3.2
Usage data.Pages and products viewed, time on page, scroll depth, clicks, search terms, filters applied, quiz answers, cart additions and removals, checkout steps started and completed, and session duration. Sessions are tracked with a timeout and periodic heartbeat so that activity can be attributed to a single visit.
3.3
Cookies and similar technologies.Cookies, local storage, session storage and pixels. Details, categories and named technologies are in our Cookie Policy. Non-essential technologies are used only where you have given consent through the banner.
3.4
Advertising and conversion data.Where you consent, advertising technologies including the Meta pixel and its server-side conversions interface record events such as page view, product view, add to cart, checkout start, payment information added and purchase, together with event value, currency, an event identifier and hashed identifiers used for matching.
3.5
Fraud and security data.Logs of authentication attempts, IP and device signals, order-risk indicators and anomalies used to detect fraud and abuse of promotions.

4.Data From Other Sources

4.1
We may receive data from: our payment processor (authorisation results, risk scores, dispute records); carriers (tracking and delivery status, delivery exceptions, signatures or delivery photographs); advertising and analytics platforms (aggregated campaign and audience reporting); social platforms where you interact with our accounts; and fraud-prevention services.
4.2
Where a third party gives us your data — for example a gift recipient’s address — the person who provides it is responsible for having a lawful basis to do so, and we process it only to fulfil the Order.

5.Why We Use Your Data and Our Lawful Bases

5.1
To perform the contract.To take and fulfil Orders, take payment, arrange delivery, manage your account, provide support and administer returns, claims and warranties. Basis: performance of a contract. Without this data we cannot supply the Products.
5.2
To comply with law.To keep tax, accounting, consumer-protection, product-safety and sanctions records, to respond to lawful requests, and to record consent. Basis: legal obligation.
5.3
For legitimate interests.To prevent fraud and abuse, secure the Site, keep records for the defence of legal claims, understand and improve our products and merchandising, produce aggregate statistics, and send service messages. Basis: legitimate interests, balanced against your rights.
5.4
With your consent.For marketing email and SMS, non-essential cookies, advertising and conversion measurement, publishing your review, and processing any health information you volunteer. Basis: consent, which you may withdraw at any time.
5.5
To establish or defend claims.To retain evidence of orders, deliveries, policy acceptance, correspondence and claim evidence for use in a dispute, chargeback or proceeding. Basis: legitimate interests and, where relevant, legal obligation.
5.6
No automated decisions with legal effect.We use automated risk scoring to flag suspicious orders, but a decision to cancel an Order involves human review. We do not carry out profiling that produces a legal effect on you within the meaning of Article 22 GDPR.

6.Who We Share Data With

6.1
Payment processing.Stripe and, where applicable, wallet providers such as Apple Pay and Google Pay, to authorise and settle payments, handle refunds and manage disputes. They act as independent controllers for their own compliance and fraud purposes.
6.2
Fulfilment and delivery.Fulfilment partners, suppliers and carriers, who receive the recipient name, address, contact details and parcel contents description needed to deliver, and customs authorities where an international shipment requires it.
6.3
Technology providers.Hosting, content delivery, commerce platform, database, email delivery, error monitoring and customer support providers, acting as processors on our instructions under written terms.
6.4
Advertising and analytics.Where you consent, advertising and measurement platforms including Meta. These platforms may act as independent controllers for their own purposes, and their processing is governed by their own privacy terms.
6.5
Professional advisers and authorities.Lawyers, accountants, auditors, insurers and debt-recovery agents where necessary, and regulators, courts, law enforcement or tax authorities where we are legally required or permitted to disclose.
6.6
Corporate transactions.A prospective or actual buyer, investor or successor in connection with a merger, financing, reorganisation, insolvency or sale of assets, subject to confidentiality and to this policy continuing to apply.
6.7
No sale of personal data.We do not sell personal data for money. Sharing data with advertising platforms for measurement and audience purposes may constitute a sale or sharing under certain U.S. state laws, and you may opt out as described in Section 11.

7.International Transfers

7.1
We operate from the United States and use providers located in the United States and elsewhere. Your data may therefore be transferred to and processed in countries whose data protection law differs from that of your own country.
7.2
Where we transfer data from the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision where one applies, or otherwise on the European Commission Standard Contractual Clauses (with the UK Addendum where relevant), together with supplementary technical and organisational measures.
7.3
You may request information about the safeguards applied to a specific transfer by writing to privacy@radia.company.

8.How Long We Keep Data

8.1
Order records.Order, payment, tax and delivery records are kept for the period required by tax and accounting law, generally seven years from the end of the relevant financial year.
8.2
Account data.Kept while your account is active and for a reasonable period afterwards, then deleted or anonymised, except where retention is required for the purposes above.
8.3
Support and claims.Correspondence and claim evidence are kept for the limitation period applicable to a potential claim, and longer where a dispute is live or reasonably anticipated.
8.4
Marketing data.Consent and preference records are kept while you remain subscribed and afterwards as evidence of the consent and of your suppression from further messages.
8.5
Analytics and advertising data.Event-level data is retained for a limited period and then aggregated. Platform-side retention is governed by the relevant platform.
8.6
Security logs.Retained for a short rolling period appropriate to detect and investigate incidents.

9.Security

9.1
We use encryption in transit, access controls and least-privilege administration, hashed credentials, tokenised payments, monitoring and logging, and vendor due diligence appropriate to the risk.
9.2
No method of transmission or storage is completely secure. You are responsible for choosing a strong, unique password, keeping it confidential, and securing the email account linked to your Radia account.
9.3
Where a personal data breach is likely to result in a risk to your rights, we will notify the competent authority and, where required, you, within the applicable statutory deadline.

10.Your Rights (EEA, UK and Switzerland)

10.1
The rights you hold.Subject to conditions and exemptions, you may request: access to your data and a copy of it; correction of inaccurate data; erasure; restriction of processing; portability in a machine-readable format; objection to processing based on legitimate interests; and objection to direct marketing at any time.
10.2
Withdrawing consent.Where processing is based on consent you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing already carried out.
10.3
How to exercise them.Email privacy@radia.company with the request and the email address used on your Order. We may ask for information to verify your identity. We respond within one month, extendable by two further months for complex requests, and will tell you if an extension applies.
10.4
Limits.We may decline or partly decline a request where an exemption applies, including where retention is required by law, where the data is needed to establish or defend a legal claim, or where the request is manifestly unfounded or excessive.
10.5
Complaints.You may complain to your local supervisory authority — in the UK, the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first.

11.Your Rights (California and Other U.S. States)

11.1
Rights under the CCPA/CPRA.If you are a California resident you may request: to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties to whom it was disclosed; deletion; correction; and to limit use of sensitive personal information. Comparable rights apply under the laws of Colorado, Connecticut, Virginia, Utah, Texas and other states.
11.2
Categories collected.In the past 12 months we have collected identifiers, customer records and commercial information, internet and device activity, approximate geolocation, and inferences drawn for merchandising, as described in Sections 2 and 3.
11.3
Opt out of sharing for targeted advertising.You may opt out of the use of advertising and measurement technologies by declining non-essential cookies in the consent banner, by using the Manage Cookies control in the footer at any time, or by emailing privacy@radia.company. We honour the Global Privacy Control signal where our systems receive it.
11.4
No discrimination.We will not deny you goods, charge a different price, or provide a different level of service because you exercised a privacy right.
11.5
Authorised agents.An authorised agent may submit a request with written proof of authority; we may still contact you to verify the request directly.
11.6
Timing.We confirm receipt within 10 business days and respond substantively within 45 days, extendable once where permitted.

12.Marketing Communications

12.1
We send marketing only where you have opted in, or where permitted by law on the basis of an existing customer relationship for similar products with a clear opt-out in every message.
12.2
You can unsubscribe using the link in any marketing email, by replying STOP to a marketing SMS, or by emailing privacy@radia.company. We keep a suppression record so that we do not contact you again.
12.3
Unsubscribing from marketing does not stop transactional messages about your account, Orders or security, which are necessary to perform the contract.

13.Reviews and Public Content

13.1
If you submit a review it may be published with the display name and location you provide. Do not include information you do not wish to be public, and do not include health details.
13.2
You may ask us to remove a review you submitted by writing to privacy@radia.company. We may retain an internal record of it for the defence of claims and for advertising-compliance purposes.

14.Third-Party Sites and Platforms

14.1
Our Site links to and embeds third-party services, and our profiles exist on third-party social platforms. Their processing of your data is governed by their own policies, which we do not control and for which we are not responsible.
14.2
Where an advertising platform acts as an independent controller for its own purposes, you should exercise your rights in respect of that processing directly with the platform, using the controls it provides.

15.Do Not Track and Browser Signals

15.1
There is no common industry standard for Do Not Track, and we do not respond to DNT headers. We do act on consent choices recorded through our banner and on Global Privacy Control signals where received.

16.Changes to This Policy

16.1
We may update this policy. The version number and effective date at the top of this page always reflect the current version, and material changes will be notified by a notice on the Site or by email where required.
16.2
Where a change requires consent under applicable law, we will obtain it before applying the change to data already collected.

17.Contact and Escalation

17.1
Privacy and data rights: privacy@radia.company. Legal and formal notices: legal@radia.company. Order and support enquiries: support@radia.company.
17.2
To help us respond quickly, state the right you wish to exercise, the email address used on your Order, and any order reference. Please allow one attempt at resolution with us before escalating to a regulator.
Where this policy conflicts with a mandatory data protection right available to you in your jurisdiction, that right prevails to the extent of the conflict.