Effective date: 08.12.2026

Privacy policy

  1. Purpose

This Privacy Policy explains how BORN, operating within the AUTHA Private Members Association, collects, uses, stores, and discloses personal information through the private BORN member portal and related member transactions.

This Policy applies to information handled through the portal. Additional confidentiality duties between members are governed by the PMA Governing Documents and Member Non-Disclosure Agreement.

  1. Information We Collect

Depending on how a member uses the portal, BORN may collect:

  • Identity and membership information: name, member status, account identifier, and access permissions.

  • Contact information: email address, telephone number, billing address, shipping address, and communication preferences.

  • Order information: products or services selected, transaction history, fulfillment details, returns, refunds, and support requests.

  • Payment information: payment status and limited transaction information received from payment processors. Full payment-card details are generally handled by the applicable payment provider rather than stored directly by BORN.

  • Portal and device information: IP address, browser type, device information, login activity, pages viewed, timestamps, cookies, and similar technical information.

  • Communications: messages, feedback, forms, and other information a member chooses to provide.

Members should not submit medical, health, or other highly sensitive information through general portal forms unless BORN specifically requests it through an appropriate secure process.

  1. How We Use Information

BORN may use personal information to:

  • confirm membership and manage portal access;

  • process payments, orders, deliveries, returns, and refunds;

  • provide member support and respond to communications;

  • deliver member resources, programs, and services;

  • maintain portal security and prevent unauthorized access or misuse;

  • improve portal functionality and understand how member services are used;

  • maintain internal records and fulfill accounting, tax, governance, and legal obligations;

  • communicate operational notices, policy updates, and information about member offerings; and

  • protect the rights, safety, confidentiality, and integrity of members, BORN, AUTHA, and the PMA.

BORN will use personal information only for the purposes identified at collection, purposes reasonably connected to them, or other purposes authorized or required by law.

  1. Consent and Other Bases for Processing

Where required, BORN collects, uses, or discloses personal information with the member's consent. Depending on the circumstances and applicable law, information may also be processed when necessary to fulfill a member transaction, administer the member relationship, meet a legal obligation, protect legitimate security interests, or respond to an emergency.

Members may withdraw consent to optional uses, subject to reasonable notice and any legal or contractual restrictions. Withdrawal may affect BORN's ability to provide a service that depends on the information.

  1. How Information Is Shared

BORN may disclose only the information reasonably necessary to:

  • authorized PMA personnel who require it for their responsibilities;

  • payment processors and financial service providers;

  • hosting, account, security, communications, and technical service providers;

  • shipping carriers, fulfillment partners, and product suppliers involved in an order;

  • accountants, legal advisers, insurers, and other professional advisers;

  • government, regulatory, or law-enforcement authorities when disclosure is authorized or required by law; or

  • another party in connection with an organizational restructuring, provided appropriate confidentiality and privacy safeguards apply.

Service providers are expected to handle information only for the services they provide and to use appropriate safeguards.

BORN does not disclose confidential member information outside the association except as authorized by the member, permitted under the PMA Governing Documents, necessary to provide a requested service, or required or permitted by law.

  1. Cookies and Analytics

The portal may use essential cookies needed for login, security, checkout, preferences, and core functionality. It may also use limited analytics or performance technologies to understand portal use and improve reliability.

Members can control non-essential cookies through available consent tools or browser settings. Disabling essential cookies may prevent parts of the portal from functioning properly.

  1. Cross-Border Processing

Some service providers may process or store information in Canada, the United States, or another jurisdiction. Information processed outside a member's home jurisdiction may be subject to the laws and lawful access requirements of the place where it is processed.

BORN takes reasonable steps to select appropriate providers and protect information when it is transferred or processed across borders.

  1. Retention

BORN retains personal information only as long as reasonably necessary for the purpose for which it was collected, for legitimate PMA administration, or to satisfy accounting, tax, dispute-resolution, security, and legal requirements.

When information is no longer required, BORN will delete, anonymize, or securely dispose of it, subject to applicable record-retention obligations.

  1. Security

BORN uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information, which may include role-based access, account controls, encryption, secure service providers, backups, and access monitoring.

No system can guarantee absolute security. Members also have a responsibility to use strong credentials, protect their devices, and promptly report suspected unauthorized access.

  1. Member Privacy Rights

Subject to applicable law and limited exceptions, members may request:

  • access to personal information held about them;

  • correction of inaccurate or incomplete information;

  • information about how their personal information has been used or disclosed;

  • withdrawal of consent for optional processing;

  • deletion or restriction of certain information; or

  • review of a concern about BORN's privacy practices.

BORN may need to verify identity before responding. Some records may need to be retained where required for legal, accounting, security, governance, or transaction purposes.

Privacy requests may be sent to hello@bornsoverign.me.

  1. Communications

BORN may send communications necessary to administer membership, portal access, orders, security, policies, or requested services. Where required, promotional communications will be sent with consent and will include an available method to unsubscribe.

Unsubscribing from promotional messages does not stop essential administrative or transactional communications.

  1. Privacy Incidents

f BORN becomes aware of unauthorized access, loss, or disclosure of personal information, it will assess the incident, take reasonable containment and remediation steps, and provide notifications where required by applicable law.

Members should report suspected privacy or security incidents to hello@bornsoverign.me.

  1. Changes to This Policy

BORN may update this Privacy Policy as portal operations, service providers, or applicable requirements change. Material changes will be communicated through the portal, by email, or through another reasonable member communication channel. The effective date above will identify the current version.

  1. Contact

Privacy questions, requests, or concerns may be sent to:

Privacy Contact — BORN / AUTHA Private Members Association
Email: hello@bornsoverign.me

Stay in the loop

Be the first to know about new collections and exclusive offers.

Stay in the loop

Be the first to know about new collections and exclusive offers.

Stay in the loop

Be the first to know about new collections and exclusive offers.