8 Hour Energy Patches
  • Shop
  • Account
  • Comparison
  • How it works
  • What they do
  • Ingredients
  • FAQ
  • Press
  • Shipping
  • Returns
  • Wholesale
Back to home

Privacy Policy

Effective date: September 24, 2026

Also see the Terms of Service.

On this page

  1. 1. Introduction, who we are, and scope
  2. 2. Information we collect
  3. 3. Sources of information
  4. 4. How we use information (specific purposes)
  5. 5. Cookies, SDKs, local storage, and similar technologies
  6. 6. Analytics, experiments, and messaging (may use)
  7. 7. Stripe payment pass-through and other disclosures / processors
  8. 8. Retention
  9. 9. California privacy notice (CCPA / CPRA) — notice at collection and rights
  10. 10. Additional U.S. state privacy rights
  11. 11. Children (COPPA) and age
  12. 12. How to exercise your rights (phone, email, and mail)
  13. 13. Security
  14. 14. Breach notice
  15. 15. United States focus; international visitors
  16. 16. GDPR / UK GDPR information for EEA and UK visitors
  17. 17. Marketing / email (CAN-SPAM) — if and when enabled
  18. 18. Third-party links
  19. 19. Changes to this Policy
  20. 20. Contact

Effective date: September 24, 2026

1. Introduction, who we are, and scope

This Privacy Policy describes how Jolly Products (“Jolly Products,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with the 8 Hour Energy Patches website and related online storefront (the “Site”), including product pages, Account features, checkout, subscriptions, rewards features (if enabled), and customer support.

Controller / business: Jolly Products
Postal address: 2985 Piedmont Road NE, Atlanta, GA 30305, United States

Phone: 1-888-605-3062

Email: legal@eighthourenergy.com

This Policy applies to personal information we process about visitors, Account holders, and customers. The Site currently sells products for delivery within the United States only and is primarily directed at U.S. customers. If you access the Site from the European Economic Area (EEA), the United Kingdom, or elsewhere outside the United States, Sections 15–17 describe how we approach international access and data-subject rights.

By using the Site, creating an Account, or making a purchase, you acknowledge this Policy. If you do not agree, please do not use the Site.

We do not claim that this Policy alone constitutes “GDPR certification,” CCPA certification, or any other formal compliance certification.

2. Information we collect

We collect personal information in the categories below. Not every category applies to every person. We collect only what is reasonably needed for the purposes in Section 4.

2.1 Identifiers

Examples may include: name; billing and shipping address; email address; phone number; Account login identifiers (including Firebase Authentication identifiers); IP address; device or browser identifiers; cookie and similar technology identifiers; and unique customer, order, or subscription identifiers.

2.2 Commercial information

Examples may include: products viewed, added to cart, or purchased; order history; subscription status (for example, 30-Day Supply); cancellation or management actions; payment status and limited payment metadata; rewards/points activity (if a rewards program is enabled); and related transaction records.

2.3 Internet or other electronic network activity

Examples may include: pages and screens viewed; referral URLs; clicks and navigation paths; session duration; search queries on the Site (if offered); and commerce-related events such as view_item, add_to_cart, begin_checkout, and purchase (as configured in Firebase Analytics / GA4).

2.4 Device and browser information

Examples may include: browser type and version; operating system; device type; screen resolution; language settings; time zone; and similar technical attributes needed to deliver, secure, and measure the Site.

2.5 Approximate geolocation

We may derive approximate location (for example, city, region, or country level) from IP address. We do not require precise GPS location for standard Site use.

2.6 Payment information

Payments and subscriptions are processed by Stripe. We do not store full primary account numbers (full PAN) or full payment card credentials on our systems. Stripe may provide us with payment tokens, last-four digits, card brand, billing ZIP or postal code, payment method type, and transaction metadata needed to fulfill orders, manage subscriptions, issue refunds where applicable, and help prevent fraud. See Section 7 for Stripe’s dual role and links to Stripe’s own privacy and legal terms.

2.7 User content

If you submit messages, reviews, feedback, or other content to us (for example, via Account tools or support channels we enable), we collect the content you choose to provide and related metadata (such as timestamp and Account association).

2.8 Inferences

We may create limited inferences from the information above for purposes such as understanding product interest, improving the Site experience, detecting fraud or abuse, assigning experiment cohorts, or measuring the effectiveness of Site features. We do not use this section as a blank authorization for unrestricted profiling for any purpose.

2.9 What we do not intentionally collect in the standard flow

We do not intentionally collect Social Security numbers, driver’s license or passport numbers, precise geolocation, biometric templates for identification, or health diagnoses through the standard browse/purchase flow. If you voluntarily include sensitive details in free-text support messages, we will process them only as needed to respond and as otherwise described in this Policy.

3. Sources of information

We obtain personal information from:

  1. You directly — when you browse, create an Account, place an order, manage a subscription, redeem rewards (if enabled), contact support, or otherwise interact with the Site.
  2. Automatic collection — through cookies, software development kits (SDKs), local or session storage, pixels or similar technologies, server logs, and analytics tools as described in Sections 5 and 6.
  3. Service providers / processors — including Stripe (payments, subscriptions, Customer Portal, and related payment services) and Google Firebase / Google services (Authentication, Firestore, App Hosting, Analytics / GA4, Remote Config / A-B Testing, and related tooling), which may process or return limited data so we can operate the Site.
  4. Derived data — limited inferences and experiment cohort assignments described in Sections 2.8 and 6.

We do not purchase consumer contact lists as a routine practice. If that ever changes, we will update this Policy.

4. How we use information (specific purposes)

We use personal information for the following specific purposes. We do not reserve a blank-check right to use your data for any purpose we invent later without updating this Policy where required and providing any notice or choice the law requires.

  1. Order fulfillment and customer service — process orders for SKUs offered on the Site (currently including 3-Day and 10-Day one-time purchases and 30-Day subscriptions), ship products within the United States, handle returns per our Returns page, and respond to inquiries.
  2. Accounts — create and maintain Account credentials and profiles; allow you to view order history and manage subscriptions where available.
  3. Subscriptions — enroll, bill, renew, cancel, and manage subscriptions (including via Stripe Customer Portal / Billing Portal where enabled); send related transactional notices.
  4. Payments and fraud prevention — complete payment transactions through Stripe; detect, investigate, and help prevent fraud, chargebacks, abuse, unauthorized access, and other harmful activity.
  5. Support — respond to support contacts we make available (currently phone, email at legal@eighthourenergy.com, postal mail, and Account tools where enabled).
  6. Security and integrity — maintain Site reliability and security; we may enable Firebase App Check later to help protect backends from abuse.
  7. Analytics and measurement — understand how the Site is used (including page views and commerce events); measure performance of pages, checkout, and product offerings using Firebase Analytics / GA4.
  8. A/B testing, Remote Config, and limited personalization — assign visitors or Accounts to experiment cohorts; vary Site experience (for example, layout, messaging, or feature flags) to improve usability and conversion; measure experiment results.
  9. Rewards program (if enabled) — calculate, display, and redeem promotional points or codes (including Stripe promotion codes where used); points are promotional and not cash until redeemed under program rules published on the Site.
  10. Product and Site improvement — debug issues; improve content, merchandising, and technical performance; develop new features.
  11. Legal compliance and enforcement — comply with applicable law (including tax and accounting recordkeeping), respond to lawful requests, enforce our Terms of Service, and protect our rights, customers, and the public.
  12. Transactional communications — send messages related to orders, Accounts, subscriptions, security, shipping, returns, and policy updates.
  13. Marketing communications (only if and when enabled) — if we enable a marketing email or similar channel, we will send marketing only where allowed by law and with appropriate consent or other lawful basis. You may unsubscribe from marketing as described in those messages (CAN-SPAM for U.S. commercial email) or by contacting us at legal@eighthourenergy.com or 1-888-605-3062. We do not invent a marketing channel in this draft; until a channel is enabled and disclosed, treat marketing as “may use.”

We do not use personal information for purposes that are incompatible with the purposes listed above without updating this Policy where required.

5. Cookies, SDKs, local storage, and similar technologies

We and our processors use cookies, SDKs, local storage, session storage, pixels, and similar technologies to operate the Site and measure activity.

5.1 Categories

TypePurpose (examples)Typical necessity
Essential / necessarySession continuity, authentication, cart/checkout integrity, security (including protections we may enable such as App Check), load balancing, fraud prevention, remembering cookie preferences if a preference tool is later addedGenerally required for the Site to function
AnalyticsFirebase Analytics / Google Analytics 4 (GA4) measurement of page_view and commerce events; traffic and engagement analysisNot strictly required for basic browsing/checkout; used for measurement
FunctionalRemember preferences; improve Account and Site experience; support features that make the Site work as intendedMay be optional depending on feature
Experiment / A-BRemote Config and A/B testing assignment so we can test Site variants and measure outcomesUsed for product improvement; not a payment requirement

We may enable Firebase Cloud Messaging (FCM) later (for example, for notifications if we offer them). Where not yet live, treat such use as “may use” and subject to this Policy as updated when enabled.

5.2 Honesty about consent UI

As of this draft, we do not claim that a full cookie-consent banner or granular cookie preference center for EEA/UK visitors is implemented on the Site. Browser controls (Section 5.3) remain available. Operationally, a consent mechanism for non-essential cookies/analytics for EEA/UK visitors may be required before relying on analytics or similar technologies for those visitors — that is a product/ops gap, not something this Policy invents as already done. See our separate compliance-gaps note for counsel and engineering.

5.3 How to control these technologies

Most browsers let you refuse or delete cookies and clear local or session storage. You can also use browser settings or extensions that limit tracking. Blocking essential technologies may prevent login, checkout, subscription management, or other Site functions from working correctly.

Google may provide additional controls for Google Analytics; see Google’s documentation for the products we enable. We do not control third-party browser or OS privacy tools.

5.4 Do Not Track

Some browsers transmit “Do Not Track” (DNT) signals. There is no uniform industry standard for responding to DNT. We do not currently respond to DNT signals in a specialized way. Separately, where California law requires recognition of opt-out preference signals such as Global Privacy Control (GPC), see Section 9.5 regarding our intent to honor GPC when technically feasible.

6. Analytics, experiments, and messaging (may use)

6.1 Firebase Analytics / GA4

We use Google Firebase Analytics and Google Analytics 4 (GA4) (or successor Google Analytics measurement) to collect and analyze Site usage. This may include page-level measurement (such as page_view) and event-level commerce measurement (such as product views, cart actions, checkout steps, and purchases), device/browser attributes, approximate location derived from IP, and identifiers associated with sessions or devices.

Google processes this information as a service provider / processor for us according to our configuration and Google’s terms for the products we enable. We use these tools for analytics, measurement, and Site improvement—not as a blank authorization for unrelated advertising uses.

Current advertising honesty: We do not presently operate third-party advertising pixels on the Site for cross-context behavioral advertising. If we later add advertising pixels, retargeting tags, or similar tools, we will update this Policy and provide any required opt-out notices (including California “sale/share” notices where applicable).

6.2 A/B testing and Remote Config

We may use Firebase Remote Config and related A/B testing features to assign you to an experiment group, deliver alternate Site experiences, and measure results. Experiment assignment may rely on device, session, or Account identifiers and is used to improve the Site experience and product offering—not to make solely automated decisions that produce legal or similarly significant effects about you without human involvement.

6.3 App Check and FCM (may use)

We may enable Firebase App Check to help protect our backends from abuse, and Firebase Cloud Messaging if we offer push or similar notifications. Those uses, if enabled, remain subject to this Policy and any in-product permission prompts required by platforms.

7. Stripe payment pass-through and other disclosures / processors

7.1 Stripe — payments, subscriptions, Customer Portal

We use Stripe to process payments, run Stripe Checkout, manage subscriptions and recurring billing, support promotion/rewards codes where configured, and provide the Stripe Customer Portal / Billing Portal for subscription management where we enable it.

  • Card data: Payment card data is handled by Stripe. We do not store full PAN on our systems.
  • Our role: For most checkout and billing data we receive back from Stripe (tokens, limited card metadata, customer and subscription identifiers, invoices), Stripe acts as our service provider / processor.
  • Stripe’s own role: Stripe may also process certain payment-related information as an independent controller under Stripe’s own privacy notice and legal terms (for example, to operate the Stripe network, meet Stripe’s compliance obligations, or prevent fraud across Stripe’s services). That processing is governed by Stripe, not solely by this Policy.
  • Your review: Please read Stripe’s materials: https://stripe.com/privacy and https://stripe.com/legal. Stripe’s terms apply to payment processing in addition to these Terms/Policy as applicable.

7.2 Other categories of recipients

We disclose personal information to the following categories of recipients as needed for the purposes in Section 4:

  1. Stripe — as described above.
  2. Google / Firebase — Authentication, Firestore data storage, App Hosting, Analytics (GA4 / Firebase Analytics), Remote Config / A-B Testing, and (if enabled) App Check and Cloud Messaging.
  3. Hosting and infrastructure providers — to operate and secure the Site and related backends (including Firebase App Hosting and related Google Cloud infrastructure we configure).
  4. Fulfillment / shipping partners — name, shipping address, and order details needed to deliver products within the United States (as described on /shipping).
  5. Professional advisors — lawyers, accountants, auditors, and similar advisors under confidentiality obligations, when needed.
  6. Legal and safety — to courts, regulators, law enforcement, or other parties when we believe disclosure is required by law or necessary to protect rights, safety, or security.
  7. Business transfers — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and this Policy’s purposes where feasible.

We require processors that handle personal information on our behalf to use it only to provide services to us and to implement appropriate safeguards, consistent with our contracts and applicable law. We do not authorize processors to use your personal information for their own unrelated marketing.

8. Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to fulfill orders, maintain Accounts and subscriptions, operate rewards ledgers (if enabled), provide support, comply with legal, tax, and accounting obligations, resolve disputes, and enforce agreements.

Retention signals (illustrative, not exhaustive):

Data type (examples)Typical retention signal
Order, invoice, and tax recordsKept for the period required by tax/accounting law and ordinary business records (often multiple years)
Account profile and authenticationWhile the Account remains active, then deleted or deidentified within a reasonable period after closure unless a longer legal hold applies
Subscription billing recordsWhile the subscription is active and thereafter as needed for billing disputes, chargebacks, and legal retention
Analytics event logsShorter operational windows consistent with Google Analytics / Firebase retention settings we configure; may be aggregated or deidentified
Support notesAs needed to resolve the inquiry and for a reasonable follow-up period
Security / fraud logsAs needed for investigation and security, then deleted or minimized

When retention is no longer required, we delete or deidentify the information, subject to technical limitations (for example, backup systems) and legal holds. Exact periods may vary; contact us if you need more detail for a specific request.

9. California privacy notice (CCPA / CPRA) — notice at collection and rights

This Section applies to California residents and is intended to serve as a notice at collection under the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”), in addition to the rest of this Policy.

9.1 Categories collected; purposes; retention; disclosure

In the preceding 12 months (or in the ordinary course going forward), we have collected or may collect the categories below. Purposes are those in Section 4. Retention is described in Section 8. We disclose these categories to service providers / processors for business purposes as described in Section 7.

CCPA category (examples)Collected?Primary purposesSold for money?“Shared” for cross-context behavioral advertising?Disclosed to service providers for business purposes?
Identifiers (name, contact, IP, Account IDs)YesFulfillment, Accounts, subscriptions, support, security, analytics, legalNoNot for third-party ad networks under current practices; see §9.2Yes (e.g., Stripe, Google/Firebase, hosting, shippers)
Customer records / commercial information (orders, subscriptions, rewards activity)YesFulfillment, Accounts, subscriptions, rewards, support, analytics, legalNoSee §9.2Yes
Internet / electronic activity (page views, events)YesAnalytics, experiments, security, Site improvementNoSee §9.2Yes (e.g., Google Analytics / Firebase)
Geolocation (approximate from IP)YesAnalytics, fraud/security, Site operationNoSee §9.2Yes
Inferences (limited interest or experiment cohort)Yes, limitedAnalytics, experiments, Site improvement, fraudNoSee §9.2Yes, as needed
Payment card details (full PAN)No on our systems (processed by Stripe; we receive tokens / limited metadata)Payment, fraud preventionNoN/AProcessed by Stripe
Sensitive personal information (CPRA)Generally not collected beyond payment data handled by Stripe and Account security needsPayment, security, legalNoN/AStripe / security processors as applicable
Protected classifications; biometric identifiers; precise geolocation; health diagnosesNot collected in standard Site flowN/AN/AN/AN/A

Business or commercial purposes for collection: the purposes listed in Section 4.

Categories of third parties / service providers: payment processors (Stripe); analytics and cloud providers (Google/Firebase and related Google services we enable); hosting/infrastructure; shipping/fulfillment partners; professional advisors; and recipients required for legal compliance or business transfers as described in Section 7.

9.2 Sale and “sharing”

  • Sale for money: We do not sell personal information for monetary consideration.
  • “Sharing” under CPRA: “Sharing” can include certain disclosures of personal information for cross-context behavioral advertising. Current practices: we use first-party Firebase Analytics / GA4 for analytics and measurement. We do not presently operate third-party advertising pixels for cross-context behavioral advertising. If a regulator or counsel treats certain analytics configurations as “sharing,” California residents may still use the opt-out methods in Section 9.4. We describe our current use as measurement and analytics, not as a paid sale of personal information.
  • If our practices change (for example, adding ad pixels), we will update this Policy and provide required notices and opt-outs.

9.3 Sensitive personal information

We do not use or disclose sensitive personal information for purposes that require a “Limit the Use of My Sensitive Personal Information” link beyond the purposes permitted by CCPA/CPRA (such as performing services you request, security, and short-term transient use). Payment card data is handled by Stripe as described in Section 7. To submit a limit request if you believe one applies, use Section 12.

9.4 Your California rights

Subject to verification and exceptions, California residents may have the right to:

  1. Know / access — the categories and specific pieces of personal information we collected; categories of sources; business or commercial purposes for collecting, selling, or sharing; and categories of third parties to whom we disclosed personal information.
  2. Delete — deletion of personal information we collected from you, subject to exceptions (for example, completing a transaction, detecting security incidents, or complying with legal obligations).
  3. Correct — correction of inaccurate personal information we maintain about you.
  4. Opt out of sale or sharing — as described in Sections 9.2 and 9.5.
  5. Limit use and disclosure of sensitive personal information — as described in Section 9.3, if applicable.
  6. Non-discrimination — we will not discriminate against you for exercising CCPA/CPRA rights (for example, by denying goods or charging different prices because you exercised a right), subject to permitted differences such as loyalty or rewards program participation consistent with law.
  7. Authorized agent — you may designate an authorized agent to submit requests where permitted by law; we may require proof of authorization and direct verification from you.

9.5 How to opt out; GPC

California residents may opt out of sale or sharing (as defined under CCPA/CPRA) by:

  • Calling 1-888-605-3062; or
  • Mailing a written request to Jolly Products, 2985 Piedmont Road NE, Atlanta, GA 30305; or
  • Using Account controls where we make applicable privacy settings available.

Global Privacy Control (GPC): When technically feasible, we will honor browser-based Global Privacy Control signals as a request to opt out of sale or sharing for that browser or device, consistent with applicable law and technical capability. Wiring GPC end-to-end is an engineering/ops task; do not assume it is fully implemented solely because this Policy states our intent. You may still need to contact us or use Account tools for requests that require Account-level verification.

9.6 Shine the Light (California Civil Code § 1798.83)

We do not disclose personal information to third parties for their own direct marketing purposes in exchange for money in the manner addressed by California’s “Shine the Light” law as a routine practice. California residents may request information about any such disclosures (if any occur) by contacting us via the methods in Section 12. We will respond as required by law.

10. Additional U.S. state privacy rights

Residents of certain U.S. states (including, depending on the statute and effective date, states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others with similar comprehensive privacy laws) may have rights that are comparable in substance to those described for California, including rights to:

  • Access / confirm processing of personal data;
  • Delete personal data;
  • Correct inaccuracies;
  • Obtain a portable copy of personal data you provided to us, where required;
  • Opt out of targeted advertising, sale of personal data, and/or profiling in furtherance of decisions that produce legal or similarly significant effects, where those concepts apply under the relevant statute; and
  • Appeal a denied request, where the statute provides an appeal right.

How we apply this section (unified approach): Without overclaiming that every state’s statute is identical, we will treat authenticated requests from residents of states with applicable comprehensive privacy laws in good faith under the comparable access, deletion, correction, and opt-out rights described above, using the submission methods in Section 12. Where a statute requires an appeal process, you may appeal by contacting us again at legal@eighthourenergy.com, 1-888-605-3062, or by mail and stating that you are appealing; we will respond within the timeframe the applicable law requires.

Targeted advertising / sale / profiling — current practices: We do not sell personal data for money. We do not presently run third-party advertising pixels for cross-context / targeted advertising as described in Section 9.2. Limited analytics and A/B experimentation are described in Sections 5–6. If you wish to opt out of targeted advertising or sale to the extent those terms could apply to future configurations, use Section 12.

This Section does not create rights beyond those provided by applicable law, and exceptions under those laws still apply.

11. Children (COPPA) and age

The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). Purchases and Accounts require that you be at least 18 years of age (see our Terms of Service). If you believe we have collected personal information from a child under 13, please email legal@eighthourenergy.com, call 1-888-605-3062, or write to the postal address in Section 20 so we can take appropriate steps to delete it.

12. How to exercise your rights (phone, email, and mail)

To submit requests under California law, other applicable U.S. state privacy laws, or GDPR/UK GDPR (where they apply to you), contact us by:

  1. Email legal@eighthourenergy.com; and/or
  2. Call 1-888-605-3062; and/or
  3. Mail a written request to: Jolly Products, 2985 Piedmont Road NE, Atlanta, GA 30305.

You may also use Account tools where enabled. Please include enough detail for us to locate your information (for example, the email used at checkout or your Account identifier) and state which right you are exercising.

13. Security

We implement commercially reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure. We do not promise absolute security. Please use a strong password for your Account and notify us promptly if you suspect unauthorized access.

14. Breach notice

If we experience a security incident involving personal information that triggers a legal obligation to notify affected individuals or regulators, we will provide notice as required by applicable law. Notice may be provided by Site posting, Account message, email, phone, postal mail, or other methods permitted by law, depending on the circumstances and contact information we have.

15. United States focus; international visitors

Jolly Products is based in the United States. We process personal information primarily in the United States. The Site currently sells for U.S. delivery only and is primarily directed at U.S. customers.

If you access the Site from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country. Where consent is a valid mechanism under applicable law, by using the Site you consent to that transfer and processing as described in this Policy. Where another legal basis is required (for example, under GDPR/UK GDPR), see Section 16.

We do not claim an EU or UK establishment, EU Article 27 representative, or UK representative in this draft. We have not invented an EU subsidiary, adequacy decision reliance we do not have documented, or a geo-block of EU checkout unless product/ops separately implements one.

16. GDPR / UK GDPR information for EEA and UK visitors

This Section is for individuals in the EEA or United Kingdom whose personal data we process when they visit or use the Site, even though sales are U.S.-delivery-focused. It does not mean we target the EEA/UK for sales or that we have appointed an EU/UK representative.

16.1 Controller

Jolly Products, 2985 Piedmont Road NE, Atlanta, GA 30305, United States; phone 1-888-605-3062, email legal@eighthourenergy.com, is the controller of personal data described in this Policy (except where Stripe or another provider acts as an independent controller for its own processing, as noted in Section 7).

16.2 Legal bases

Depending on the processing activity, we rely on one or more of the following:

Activity (examples)Typical legal basis
Creating an Account; fulfilling an order; managing a subscription; providing Customer Portal access; customer support for a purchaseContract (performance of a contract with you) or steps prior to entering a contract
Fraud prevention; securing the Site; network security; limited analytics needed to keep the Site reliable; enforcing Terms; keeping tax/business recordsLegitimate interests (examples: protecting the business and customers from fraud/abuse; operating and securing a commercial website; improving Site reliability). You may object as described below
Non-essential cookies / analytics / A-B testing where consent is required under ePrivacy/cookie rulesConsent (where we implement a consent mechanism; see Section 5.2 honesty note)
Marketing emails (only if/when enabled)Consent or other lawful basis permitted in your jurisdiction
Legal compliance (e.g., responding to lawful requests; mandatory recordkeeping)Legal obligation

16.3 Purposes and processors

Purposes are those in Section 4. Processors / recipients are those in Section 7 (notably Stripe and Google/Firebase). We do not use personal data for purposes incompatible with those stated without a new legal basis and any required notice.

16.4 International transfers

Personal data is processed in the United States. When we use Stripe, Google, or other providers that transfer personal data internationally, we rely on the transfer mechanisms those providers make available under their terms — commonly including Standard Contractual Clauses (SCCs) and, where applicable, other lawful transfer tools described in the provider’s documentation. We do not invent a specific adequacy decision or certification (for example, we do not claim “we are Privacy Shield certified” or invent an adequacy finding we have not verified in our contracts). Review Stripe’s and Google’s privacy/transfer documentation for details of their mechanisms.

16.5 Your data-subject rights

Subject to conditions and exceptions in GDPR / UK GDPR, you may have the right to:

  1. Access your personal data;
  2. Rectify inaccurate data;
  3. Erase data (“right to be forgotten”) in certain cases;
  4. Restrict processing in certain cases;
  5. Data portability for data you provided, where processing is based on consent or contract and carried out by automated means;
  6. Object to processing based on legitimate interests (including profiling based on those grounds), and to object to direct marketing if we enable it;
  7. Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
  8. Lodge a complaint with a supervisory authority in your EEA member state or with the UK Information Commissioner’s Office (ICO), as applicable.

To exercise rights 1–7, use Section 12 (email, phone, or postal mail). We may need to verify your identity.

16.6 No EU/UK representative claimed

We have not appointed an EU Article 27 representative or UK representative in this draft. If counsel later advises appointment, we will update this Policy with accurate details — we will not invent a representative.

16.7 Practical note on EU/UK visitors

Because the Site ships only to the U.S. and is primarily U.S.-directed, product and counsel may decide to geo-limit checkout or reduce non-essential tracking for EEA/UK visitors. Those are operational decisions; this Policy describes rights if personal data of EEA/UK visitors is nonetheless processed.

17. Marketing / email (CAN-SPAM) — if and when enabled

Transactional messages about orders, Accounts, subscriptions, security, and policy updates are not marketing.

If and when we enable commercial marketing email (or a similar channel):

  • We will identify the message as from Jolly Products / 8 Hour Energy Patches as required;
  • U.S. commercial email will include a clear unsubscribe mechanism consistent with CAN-SPAM;
  • We will honor opt-outs within the timeframes required by law;
  • Operational contact for privacy and legal notices is legal@eighthourenergy.com. When a marketing channel goes live, message footers will also disclose how to unsubscribe.

Until a marketing channel is enabled and disclosed, assume we are not actively running a marketing email list under this draft.

18. Third-party links

The Site may link to third-party websites or services that we do not control (including Stripe-hosted Checkout or Customer Portal pages, and provider documentation). Their privacy practices are governed by their own policies. We are not responsible for the content or privacy practices of those third parties. Review their policies before providing personal information.

19. Changes to this Policy

We may update this Privacy Policy from time to time. The Effective date at the top will change when we post a material update. For material changes, we may provide additional notice (for example, a Site banner or Account notice) as appropriate. Continued use of the Site after the updated Effective date constitutes acceptance of the revised Policy, except where applicable law requires a different form of consent or notice.

20. Contact

Jolly Products
2985 Piedmont Road NE

Atlanta, GA 30305

United States

Phone: 1-888-605-3062

Email: legal@eighthourenergy.com

For privacy requests, use the methods in Section 12, including legal@eighthourenergy.com.

8 Hour Energy Patches

Plant based energy patches. 0 calories. 0 sugar.

Jolly Products

2985 Piedmont Road NE

Atlanta, GA 30305

1-888-605-3062

  • Instagram
  • TikTok
  • Facebook

Shop

  • All products
  • 3 Day Supply
  • 10 Day Supply
  • 30 Day Supply
  • Wholesale

Learn

  • How it works
  • Ingredients
  • FAQ
  • How to apply

Press

  • All press
  • Ryan Seacrest
  • Discovery · Trending Today

Policies

  • Shipping
  • Returns
  • Privacy
  • Terms

© 2026 Jolly Products. All rights reserved.

These statements have not been evaluated by the FDA. This product is not intended to diagnose, treat, cure, or prevent any disease.