Privacy Policy for EXO Golf

Privacy Policy

Privacy Policy

MSND USA LLC  ·  Last updated: April 17, 2026

This Privacy Policy explains how MSND USA LLC, operating as EXO Golf ("EXO Golf", "we", "us", or "our"), collects, uses, and shares information about you when you visit exo-golf.com or make a purchase from us. This policy is governed by the laws of the State of California and applicable US federal law, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

1. Who We Are

The data controller responsible for your personal information is:

MSND USA LLC

5315 Avenida Encinas, Suite 150, Carlsbad, CA 92008

hello@exo-golf.com  ·  exo-golf.com

2. Information We Collect

We collect information you provide directly to us and information collected automatically when you use our site.

Information you provide

Category Examples How collected
Identity data Name, email address Checkout, email signup
Contact data Shipping address, phone number Checkout
Payment data Payment card details (processed and stored by Shopify Payments / Stripe, not by us) Checkout
Transaction data Order history, items purchased, order value Checkout
Communications data Support emails, review submissions Email, Judge.me

Information collected automatically

Category Examples Source
Usage data Pages visited, time on site, click behaviour Google Analytics
Device data IP address, browser type, operating system Shopify, Google Analytics
Ad interaction data Ad clicks, conversions, page events Meta pixel, TikTok pixel
Cookie data Session cookies, preference cookies, tracking cookies Shopify, Google, Meta, TikTok

3. How We Use Your Information

Purpose Legal basis
Process and fulfil your order Contract performance
Send order confirmations and shipping updates Contract performance
Respond to support and return requests Contract performance
Send marketing emails (where you have opted in) Consent
Improve our website and product offering Legitimate interest
Measure advertising effectiveness and run retargeting campaigns Legitimate interest / consent
Comply with legal obligations and prevent fraud Legal obligation

4. Third Parties We Share Data With

We do not sell your personal information. We share data only with the service providers necessary to operate our business. Each provider is contractually required to protect your data and use it only for the purpose we specify.

Provider Purpose Data shared
Shopify Ecommerce platform, payment processing Order, identity, payment data
Omnisend Email marketing and automation Name, email, order data
Judge.me Product reviews platform Name, email, order data
Google Analytics Website analytics and performance Usage and device data (anonymised)
Meta (Facebook / Instagram) Ad measurement and retargeting Ad interaction and behavioural data via pixel
TikTok Ad measurement and retargeting Ad interaction and behavioural data via pixel
Shopify Network Intelligence Platform improvement, ad targeting and personalisation Aggregated and anonymised customer data used within Shopify's network as described in Shopify's Additional Services Terms. No other merchant can see your individual data.

Sharing behavioural data with Meta and TikTok for cross-context advertising constitutes "sharing" under California law. You have the right to opt out. See Section 7 below.

5. Cookies

We use cookies and similar tracking technologies to operate our site and serve relevant advertising. Cookies are small text files stored on your device.

Type Purpose Can be disabled
Essential Cart, checkout, login session No — site will not function
Analytics Site performance measurement Yes
Advertising Ad targeting and retargeting Yes — see Section 7

You can manage cookie preferences through your browser settings at any time. Note that disabling certain cookies may affect site functionality.

6. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes set out in this policy, or as required by law.

Data type Retention period
Order and transaction data 7 years (US tax law requirement)
Marketing email data Until you unsubscribe or request deletion
Support communications 3 years from last interaction
Analytics and cookie data Up to 26 months

7. Your California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Right to know Request disclosure of the categories and specific pieces of personal information we have collected about you.
Right to delete Request deletion of your personal information, subject to certain exceptions required by law.
Right to correct Request correction of inaccurate personal information we hold about you.
Right to opt out of sharing Opt out of the sharing of your personal information with Meta and TikTok for cross-context behavioural advertising. Use the link in our website footer or visit our data sharing opt-out page.
Right to limit use of sensitive data Limit our use of sensitive personal information to purposes necessary to provide our services.
Right to non-discrimination We will not discriminate against you for exercising any of your privacy rights.

To exercise your rights or opt out of data sharing:

Email: hello@exo-golf.com

Opt-out page: exo-golf.com/pages/data-sharing-opt-out

We will verify your identity and respond within 45 days as required by California law. We will not charge a fee for reasonable requests.

8. Children's Privacy

Our website is not directed at individuals under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected information from a minor, please contact us at hello@exo-golf.com and we will delete it promptly.

This site is intended for use by adults aged 16 and over in accordance with CCPA and COPPA requirements.

9. Data Security

We use commercially reasonable technical and organisational measures to protect your personal information. Our store is hosted on Shopify, which maintains PCI-DSS compliance for all payment data. All data is transmitted over encrypted HTTPS connections.

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

10. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the date at the top of this page. If changes are material, we will notify you by email or by placing a prominent notice on our website.

Your continued use of exo-golf.com after any changes constitutes acceptance of the updated policy.

Privacy questions or requests?

MSND USA LLC

5315 Avenida Encinas, Suite 150, Carlsbad, CA 92008

Contact Us