Security Statement
Last Updated: August 26, 2026
Vita Asana, operated by VITA ASANA SRL, takes reasonable administrative, technical, and organizational measures intended to protect customer information and maintain the security of our online store.
This Security Statement explains the security measures supporting our website, checkout, payments, customer information, and related services. It should be read together with our Privacy Policy, Cookie Policy, and Payment Policy.
1. Our Security Approach
We seek to apply safeguards that are appropriate to the nature of the information we process, the services we provide, and the risks associated with operating an online store.
These safeguards are intended to help prevent unauthorized access, disclosure, alteration, loss, or misuse of customer information. However, no website, transmission method, payment system, or data-storage service can be guaranteed to be completely secure.
2. Shopify Hosting and Encrypted Connections
The Vita Asana online store is hosted on Shopify.
Shopify uses Transport Layer Security, commonly known as TLS, to protect connections to Shopify-powered stores. When your browser displays a padlock beside a Vita Asana address beginning with https://, the connection between your supported browser and the Shopify-hosted store is encrypted in transit.
TLS helps protect information while it is being transmitted. It cannot protect information if your device, email account, browser, or network has already been compromised.
3. Payment Security
Vita Asana currently accepts:
-
Visa
-
Mastercard
-
PayPal
-
Apple Pay
-
Google Pay
Payment-card transactions are processed through Shopify checkout and the applicable authorized payment provider.
Shopify states that its platform is certified Level 1 PCI DSS compliant and that this compliance extends to stores powered by Shopify. This certification belongs to Shopify and does not mean that VITA ASANA SRL has undergone a separate, independent Level 1 PCI DSS certification.
Vita Asana does not ordinarily receive or store complete payment-card numbers or card security codes in its standard business systems. Depending on the payment method and transaction, we may receive limited information such as:
-
Payment method and card brand
-
The last four digits of a payment card
-
Payment and authorization status
-
Billing information
-
Transaction references
-
Fraud or risk indicators supplied by payment providers
We will not ask you to send a complete card number, card security code, banking password, payment-account password, or one-time authentication code through email, telephone, chat, or our contact form.
For additional payment information, please review our Payment Policy.
4. Access and Operational Safeguards
We seek to:
-
Limit access to customer information to authorized personnel and service providers that require it for legitimate business purposes
-
Use the access controls and authentication features available through Shopify and our service providers
-
Review access when roles, applications, or service relationships change
-
Collect and retain only the information reasonably required for store operations, legal compliance, fraud prevention, and customer support
-
Review suspicious order or payment activity when appropriate
-
Respond to reported security concerns and suspected incidents
The specific safeguards used may change as our store, service providers, and available technology develop.
5. Fraud Prevention and Order Verification
Orders may be reviewed automatically or manually for indications of fraud, unauthorized payment use, inaccurate information, or other security concerns.
Where reasonably necessary, Vita Asana or an authorized payment provider may:
-
Request order-related verification
-
Temporarily hold an order while it is reviewed
-
Decline or cancel a transaction
-
Restrict activity that appears unauthorized or abusive
Any verification request will be limited to information reasonably connected to the order. We will not request your complete card number, card security code, account password, banking password, or one-time authentication code.
Additional conditions concerning transactions and order acceptance are provided in our Terms of Service.
6. Applications and Service Providers
We use third-party services to operate our store. These may include Shopify, payment providers, fraud-prevention tools, customer-support services, analytics providers, advertising platforms, review and chat applications, fulfillment partners, and shipping carriers.
These providers operate their own systems and maintain their own security practices. They may process information according to their services, permissions, contracts, and privacy terms.
We seek to limit third-party access to information reasonably required for the service being provided. More information about how personal information may be collected, used, and shared is available in our Privacy Policy and Cookie Policy.
7. Information Retention
Order, payment, customer-service, fraud-prevention, and transaction records may be retained for the periods reasonably necessary to:
-
Complete and support transactions
-
Provide customer service
-
Process returns and refunds
-
Maintain accounting and tax records
-
Prevent fraud and misuse
-
Resolve disputes
-
Enforce our agreements
-
Meet legal and regulatory obligations
Further information about retention and privacy rights is provided in our Privacy Policy.
California residents can review our California Consumer Privacy Act (CCPA / CPRA) Policy and Do Not Sell or Share My Personal Information page.
8. Customer Account and Device Security
If you create or use a customer account, you are responsible for protecting your login credentials and restricting access to your device and email account.
We recommend that customers:
-
Use a strong and unique password
-
Avoid reusing passwords from other websites
-
Keep browsers and devices updated
-
Use trusted networks when entering payment information
-
Sign out when using a shared device
-
Never share passwords or one-time authentication codes
-
Contact us promptly if unauthorized activity is suspected
Vita Asana is not responsible for activity caused by a customer voluntarily sharing credentials or failing to secure a device, except where responsibility cannot lawfully be excluded.
9. Phishing and Impersonation
Before entering personal or payment information, verify that you are visiting:
Official customer-service communications may come from:
Be cautious of communications that create unusual urgency, request sensitive credentials, demand payment through an unfamiliar method, or direct you to a domain that does not belong to Vita Asana.
If you receive a suspicious message claiming to represent Vita Asana, do not click its links or provide information. Forward the message or a screenshot to contact@vita-asana.com.
10. Security Incident Response
If we become aware of a suspected security incident, the actions we may take include:
-
Investigating the nature and scope of the incident
-
Restricting or revoking affected access
-
Taking steps intended to contain further exposure
-
Preserving relevant records
-
Coordinating with Shopify, payment providers, application providers, professional advisers, insurers, or authorities
-
Taking reasonable remediation measures
-
Notifying affected individuals or regulators where required by applicable law
The appropriate response and notification timeline will depend on the nature of the incident, the information involved, and applicable legal requirements.
11. Reporting a Security Concern
If you believe you have identified a security issue involving Vita Asana, please contact us promptly:
Email: contact@vita-asana.com
Subject: Security Concern – Vita Asana
Contact Form: Contact Us
Where possible, include:
-
The relevant page address
-
A clear description of the concern
-
Steps that reproduce the issue
-
Your browser and device type
-
Screenshots that do not expose sensitive information
-
Your contact details for follow-up
Do not include passwords, complete card numbers, card security codes, authentication codes, or another person’s personal information in your report.
Our normal customer-service response time is 24–48 hours on business days. This is an acknowledgment target and is not a guaranteed investigation or remediation deadline.
12. Responsible Security Reporting
Reporting a concern does not authorize you to:
-
Access or attempt to access another person’s information
-
Download, retain, alter, or disclose data
-
Disrupt the website, checkout, or related services
-
Perform social-engineering or phishing tests
-
Introduce malicious software
-
Send spam or excessive automated requests
-
Violate applicable law or third-party rights
Vita Asana does not currently operate a public bug-bounty program and does not promise compensation for submitted reports.
13. Security Limitations
Although we take reasonable precautions and use established ecommerce service providers, absolute security cannot be guaranteed.
Customers should evaluate their own device, browser, email, account, and network security. Nothing in this Security Statement limits any rights or obligations that cannot lawfully be limited.
14. Changes to This Statement
We may update this Security Statement when our practices, technology, service providers, or legal obligations change.
The revised version will be published on this page with an updated “Last Updated” date. Material changes may also be communicated through the website or another appropriate method.
15. Related Information
For additional information, please review:
16. Contact Information
Store Name: Vita Asana
Company Name: VITA ASANA SRL
Company Number: 40630208
Company Address: Str. Izvoarelor nr. 10, Sângeorz-Băi, Bistrița-Năsăud, 425300, Romania
U.S. Fulfillment & Returns Address: 12900 W Airport Blvd, Sugar Land, TX 77478, United States
Email: contact@vita-asana.com
Phone: +1 (325) 275-0218
Contact Form: Contact Us
Customer Service Hours:
Monday–Friday: 9:00 a.m.–5:00 p.m. Eastern Time
Saturday–Sunday: Closed
Our customer support team generally responds within 24–48 hours on business days.